Security Incident Triage and Response

Give your team the context to act on a security alert. This Mastra template gathers evidence, checks the relevant runbook, and prepares an incident summary and response plan for review. It handles unexpected privilege changes, logins from disallowed countries, and unfamiliar devices. Containment waits for approval.

Why we built this

An alert tells you something happened. Deciding what to do takes more work: checking the account, finding the right procedure, and making sure the response targets the right session or device.

We built this template to bring that context into one review. Your team can inspect the evidence and proposed actions before approving a response. Start with the sample alerts, then connect the services you use.

The workflow combines Mastra agents and tools, parallel evidence collection, retrieval from runbooks, durable workflow suspension and resumption, and observability.

Demo

This demo runs in Mastra Studio, but you can connect this workflow to your React, Next.js, or Vue app using the Mastra Client SDK or agentic UI libraries like AI SDK UI, CopilotKit, or Assistant UI.

Prerequisites

  • OpenAI API key: set OPENAI_API_KEY to run the sample workflows in Studio with the default openai/gpt-4o-mini model.
  • Keep the local settings in .env.example. The sample workflows need no WorkOS, IPinfo, or Linear account and no approval secrets.
  • The first start downloads an embedding model and indexes the included runbooks, so allow extra time and network access for it to finish.

Quickstart 🚀

  1. Clone the template
    • Run npx create-mastra@latest template-security-incident-triage --template security-incident-triage-and-response.
    • Run cd template-security-incident-triage, then npm install.
  2. Add your API keys
    • Run cp .env.example .env and fill in the value described under Prerequisites.
  3. Start the dev server

Try it out

  • In the suspended step's Resume input, paste resolve.json to approve the local plan, then inspect the verified containment result.
  • Start a new run with the same alert and paste reject.json at approval. The run finishes without containment.
  • Compare a login from the US with a login from Brazil. The sample US policy closes the first as benign; the second prepares a response and waits for approval.
  • Try an unexpected privilege change and review the proposed role restoration before approving it.

Approval in this demo affects only local sample data. Start a new run to try an alert again. The Studio walkthrough covers each scenario. Real containment requires authenticated approval.

Making it yours

  • Open the project in your coding agent and describe a change, such as: “Adapt the allowed-country policy and its runbook to our team's procedures. Explore the code and propose a plan before making changes.” See runbooks and policy rules for edits that require corresponding policy changes.
  • Connect your identity provider, incident tracker, and evidence sources. Start with the included WorkOS, IPinfo, and Linear adapters, or replace them with your own. See provider setup for the required configuration and evidence.

Try the complete flow without credentials

After installing dependencies, run npm run demo:local -- --output /tmp/security-local-demo without an API key or a running dev server.

Use a new output directory each time. The demo runs all three alert scenarios, simulates an authorized approval, verifies local containment, and writes demo-report.json to that directory. It uses deterministic model substitutes and synthetic data. See the local demo guide to inspect the results.

About Mastra templates

Mastra templates are ready-to-use projects that show what you can build with Mastra. Clone one, try it in Studio, and adapt it to your use case. They live in the Mastra monorepo and are automatically synced to standalone repositories for easier cloning.

This template was contributed by Diego and is already published on the Mastra website.

Want to contribute? Contributions are welcome under the Apache-2.0 license.