Security Incident Triage and Response
Give your team the context to act on a security alert. This Mastra template gathers evidence, checks the relevant runbook, and prepares an incident summary and response plan for review. It handles unexpected privilege changes, logins from disallowed countries, and unfamiliar devices. Containment waits for approval.
Why we built this
An alert tells you something happened. Deciding what to do takes more work: checking the account, finding the right procedure, and making sure the response targets the right session or device.
We built this template to bring that context into one review. Your team can inspect the evidence and proposed actions before approving a response. Start with the sample alerts, then connect the services you use.
The workflow combines Mastra agents and tools, parallel evidence collection, retrieval from runbooks, durable workflow suspension and resumption, and observability.
Demo
This demo runs in Mastra Studio, but you can connect this workflow to your React, Next.js, or Vue app using the Mastra Client SDK or agentic UI libraries like AI SDK UI, CopilotKit, or Assistant UI.
Prerequisites
- OpenAI API key: set
OPENAI_API_KEYto run the sample workflows in Studio with the defaultopenai/gpt-4o-minimodel. - Keep the local settings in
.env.example. The sample workflows need no WorkOS, IPinfo, or Linear account and no approval secrets. - The first start downloads an embedding model and indexes the included runbooks, so allow extra time and network access for it to finish.
Quickstart 🚀
- Clone the template
- Run
npx create-mastra@latest template-security-incident-triage --template security-incident-triage-and-response. - Run
cd template-security-incident-triage, thennpm install.
- Run
- Add your API keys
- Run
cp .env.example .envand fill in the value described under Prerequisites.
- Run
- Start the dev server
- Run
npm run dev. - Open Mastra Studio, select Workflows → securityIncidentWorkflow, and paste the sample alert for an unfamiliar device into the input. Inspect the incident summary and plan when the run pauses at
await-approval.
- Run
Try it out
- In the suspended step's Resume input, paste resolve.json to approve the local plan, then inspect the verified containment result.
- Start a new run with the same alert and paste reject.json at approval. The run finishes without containment.
- Compare a login from the US with a login from Brazil. The sample US policy closes the first as benign; the second prepares a response and waits for approval.
- Try an unexpected privilege change and review the proposed role restoration before approving it.
Approval in this demo affects only local sample data. Start a new run to try an alert again. The Studio walkthrough covers each scenario. Real containment requires authenticated approval.
Making it yours
- Open the project in your coding agent and describe a change, such as: “Adapt the allowed-country policy and its runbook to our team's procedures. Explore the code and propose a plan before making changes.” See runbooks and policy rules for edits that require corresponding policy changes.
- Connect your identity provider, incident tracker, and evidence sources. Start with the included WorkOS, IPinfo, and Linear adapters, or replace them with your own. See provider setup for the required configuration and evidence.
Try the complete flow without credentials
After installing dependencies, run npm run demo:local -- --output /tmp/security-local-demo without an API key or a running dev server.
Use a new output directory each time. The demo runs all three alert scenarios, simulates an authorized approval, verifies local containment, and writes demo-report.json to that directory. It uses deterministic model substitutes and synthetic data. See the local demo guide to inspect the results.
About Mastra templates
Mastra templates are ready-to-use projects that show what you can build with Mastra. Clone one, try it in Studio, and adapt it to your use case. They live in the Mastra monorepo and are automatically synced to standalone repositories for easier cloning.
This template was contributed by Diego and is already published on the Mastra website.
Want to contribute? Contributions are welcome under the Apache-2.0 license.
