Video

TITAN Watch – Rule Builder Agent

TITAN Watch – Rule Builder Agent
Learn how SecurityScorecard's Rule Builder agent automates vendor risk alerting, from breach monitoring to score threshold triggers. This step-by-step walkthrough shows how to set up a fully configured alert in minutes, without manual rule-building or risk of duplication.

Hello. Today, I’m going to be going over the Rule Builder agent within the Security Scorecard platform. It is one of a multitude of agents that we have to help automate and speed up daily tasks within our platform to help support self monitoring or third party risk management. Primarily, your team needs to know the moment a vendor drops below a scoring threshold, a specific issue or risk may be surfaced or identified, or if a breach event takes place. That early onset warning helps your team be proactive versus reactive against risk. Ultimately, manually setting up alerts and triggers in automation can be tedious. There’s risk of duplication, and that is where the AI agent really excels. So today I’m going to be showing you how to create an alert via the rule builder, but ultimately use this as a framework to build whatever rules and alerts that you would like to via the agent itself. First, you’ll navigate down to the sparkly circle in the bottom right hand corner, and then you’ll have the ability to view and peruse all of the agents that we have available, but specifically select rule builder agent. It is going to greet you with a couple potential options that you can create alerts from. These are not the only five options that are available. You can create an alert over any data point in our platform. I am going to give and ask the agent to create a breach alert for any of the vendors that I am monitoring because I want to be alerted on when those incidents take place so I can have the proper steps and actions that follow. So I will simply ask the agent to create a breach monitoring alert. It is now going to work on my request, primarily analyze the existing rules that I have within my platform instance so that there is no duplication. It’s going to confirm that I don’t have any existing alerts and ask me for a couple details to ensure that the alert is specific to my needs. I would like to apply this monitoring alert to all followed vendors and receive an email alert and a report. This has now given the agent guidance on what needs to be monitored and what that outcome will be. As you can see, it’s going to ask a bit more clarification. Please provide a detailed report. That is a key step when using the alerting agent is that it will catch maybe a misstep in your alert confirmation or setup to ensure that the alert is meaningful and created properly. It’s now going to ask one final confirmation in terms of breach name. I will give it the breach monitoring all vendors. And please just email myself with security scorecard branding. From here, it’ll confirm and review the the alert, show me the end result so I can do one last pass to ensure that it is set up to my my specific needs, and everything looks great. I will tell the agent it looks amazing, and now we’ll we’ll create the alert in my instance. The alert has now been created. I can now navigate to automation to the rule builder where I can now see that alert has been created. It has not been triggered, but of course, once it does trigger, this will move to a successful trigger. I hope this was helpful. If you have any questions, please reach out to the security scorecard team. We’ll be happy to support or answer any questions that you may have. Thank you.

Rule Builder Agent: Automating Alerts in SecurityScorecard

Today we’re going over the Rule Builder agent within the SecurityScorecard platform one of a multitude of agents available to help automate and speed up daily tasks in support of self-monitoring and third-party risk management.

Why Automated Alerting Matters

Your team needs to know the moment a vendor drops below a scoring threshold, a specific issue or risk is identified, or a breach event takes place. That early warning helps your team be proactive instead of reactive against risk.

Manually setting up alerts and triggers can be tedious, and there’s a real risk of duplication that’s where the AI agent excels. This walkthrough shows how to create an alert via the Rule Builder agent, but it’s meant as a framework you can use to build any rule or alert you need.

Step 1: Open the Rule Builder Agent

Navigate to the sparkly circle in the bottom right-hand corner to view and browse all available agents, then select the Rule Builder agent.

Step 2: Choose What to Monitor

The agent greets you with a few potential starting options for creating alerts. These aren’t the only options available you can create an alert over any data point in the platform.

In this example, the request is to create a breach alert for any vendors being monitored, in order to be notified the moment an incident takes place and take the proper next steps.

Step 3: Let the Agent Check for Duplicates

After asking the agent to create a breach monitoring alert, it works on the request by first analyzing existing rules in the platform instance to avoid duplication. It confirms there are no existing alerts of this type, then asks for a few more details to make sure the alert fits the specific need.

Step 4: Define the Alert Scope and Output

The request: apply the monitoring alert to all followed vendors, and receive both an email alert and a report.

This gives the agent guidance on what to monitor and what the output should look like. The agent asks for one more clarification in this case, requesting a detailed report. This is a key strength of the alerting agent: it catches gaps in the alert setup to make sure the final alert is meaningful and configured correctly.

Step 5: Confirm Naming and Branding

The agent asks for a final confirmation on the breach name in this case, “Breach Monitoring All Vendors” and a request to email with SecurityScorecard branding.

Step 6: Review and Create the Alert

The agent confirms and reviews the alert, showing the end result for one last check to ensure everything is set up correctly. Once confirmed, the agent creates the alert in the platform instance.

Step 7: Verify in Rule Builder

Navigate to Automation → Rule Builder to see the newly created alert. It hasn’t been triggered yet, but once it is, it will move to a successful trigger state.

If you have any questions, please reach out to the SecurityScorecard team we’re happy to support or answer any questions you may have. Thank you.