Documentation

Automation And Integrations

Move from one-off scans to recurring operational security workflows with supported automation features.

Who This Topic Is For

Teams operationalizing recurring security checks and downstream follow-up routing.

Prerequisites

Before You Start

Use this checklist to make sure the workflow guidance applies cleanly to your current task.

  • A supported account/workspace with the required role and plan capabilities.
  • Defined scan cadence expectations and ownership model.
  • An integration endpoint or workflow target for outgoing updates.
Expectations

What To Expect

Use this section to set the right outcome before you start the workflow.

Watch is change detection. Scheduled Scans are a credit calendar

Website Watch bills per site and runs daily pulse plus weekly Standard or Deep without using credits. Scheduled Scans remain the Pro-plus path for custom calendar and Comprehensive.

API keys are Team and Enterprise

Keys create scans with POST /api/api-access/v1/scans, poll GET /api/api-access/v1/scans/:id, and download GET /api/api-access/v1/scans/:id/report. Identity ping remains GET /api/api-access/v1/me. Organization owners can manage webhooks on all plans. Secrets are shown once at creation.

Slack and Jira can receive Watch alerts

If Slack or Jira is already connected, Watch can emit a watch.alert event for the same change that triggered email. Connect those integrations in account settings first.

Playbook

Step-By-Step Guidance

Follow these steps in order for a reliable and repeatable outcome.

  1. Define recurring scan policy.

    Establish frequency and target scope aligned with release cadence and risk tolerance.

  2. Configure automation hooks.

    Use supported API key and webhook capabilities for workflow integration, and store secrets securely at creation.

  3. Connect team systems.

    Use supported integrations such as Slack and Jira where available for workspace-level follow-through and visibility.

  4. Review automation outputs regularly.

    Automation reduces manual effort but still requires periodic policy and signal quality review. Website Watch is the always-on per-site SKU for change alerts; pick Standard or Deep when you add the site.

    Scheduled Scans remain the credit path for custom cadence and Comprehensive.

Examples

Worked Examples

These scenarios show how the workflow looks in practice, including the result you should see.

Five shops on Watch plus one Comprehensive schedule

An agency adds five HTTPS origins to Watch, picking Standard or Deep per site. Occupied seats are five. They also keep a Monday Comprehensive Scheduled Scan on the highest-risk shop using credits.

Watch emails deltas without deducting credits. The Comprehensive schedule still spends credits. Slack receives watch.alert when connected.

Webhook without a test event

The owner creates a webhook, stores the secret, then waits for production findings. No delivery is proven. They send a verification event first.

Downstream receipt is confirmed before the integration is treated as live.
Validation

Validation Checklist

Use this checklist to confirm the workflow was completed correctly.

  • Scheduled scan targets and cadence are documented.
  • API/webhook credentials are stored securely and rotated as needed.
  • Integration delivery paths are tested end-to-end.
  • Ownership for triaging automated findings is defined.
Troubleshooting

Common Problems And Fixes

If something does not match expectation, check these common failure modes first.

Automation without triage ownership

Assign clear owners for incoming findings so automated volume does not create unattended risk backlog.

Common failure mode

Webhook setup without delivery validation

Run verification events and confirm downstream receipt before treating the integration as production-ready.

Common failure mode

Expecting Watch to fire Comprehensive on a custom weekday

Watch included coverage is daily pulse plus weekly Standard or Deep at the locked seat depth. Custom calendar and Comprehensive remain Scheduled Scans.

Common failure mode
FAQ

Automation And Integrations FAQs

Common questions for this topic.

Integration and automation capabilities are tied to supported account tiers and workspace roles.

Next Recommended Action

Continue to the best next page based on where you are in your workflow.