Who This Topic Is For
Teams operationalizing recurring security checks and downstream follow-up routing.
Move from one-off scans to recurring operational security workflows with supported automation features.
Teams operationalizing recurring security checks and downstream follow-up routing.
Use this checklist to make sure the workflow guidance applies cleanly to your current task.
Use this section to set the right outcome before you start the workflow.
Website Watch bills per site and runs daily pulse plus weekly Standard or Deep without using credits. Scheduled Scans remain the Pro-plus path for custom calendar and Comprehensive.
Keys create scans with POST /api/api-access/v1/scans, poll GET /api/api-access/v1/scans/:id, and download GET /api/api-access/v1/scans/:id/report. Identity ping remains GET /api/api-access/v1/me. Organization owners can manage webhooks on all plans. Secrets are shown once at creation.
If Slack or Jira is already connected, Watch can emit a watch.alert event for the same change that triggered email. Connect those integrations in account settings first.
Follow these steps in order for a reliable and repeatable outcome.
Establish frequency and target scope aligned with release cadence and risk tolerance.
Use supported API key and webhook capabilities for workflow integration, and store secrets securely at creation.
Use supported integrations such as Slack and Jira where available for workspace-level follow-through and visibility.
Automation reduces manual effort but still requires periodic policy and signal quality review. Website Watch is the always-on per-site SKU for change alerts; pick Standard or Deep when you add the site.
Scheduled Scans remain the credit path for custom cadence and Comprehensive.
These scenarios show how the workflow looks in practice, including the result you should see.
An agency adds five HTTPS origins to Watch, picking Standard or Deep per site. Occupied seats are five. They also keep a Monday Comprehensive Scheduled Scan on the highest-risk shop using credits.
The owner creates a webhook, stores the secret, then waits for production findings. No delivery is proven. They send a verification event first.
Use this checklist to confirm the workflow was completed correctly.
If something does not match expectation, check these common failure modes first.
Assign clear owners for incoming findings so automated volume does not create unattended risk backlog.
Run verification events and confirm downstream receipt before treating the integration as production-ready.
Watch included coverage is daily pulse plus weekly Standard or Deep at the locked seat depth. Custom calendar and Comprehensive remain Scheduled Scans.
Use these links to continue your workflow without losing context.
Open Help: Account And Access to continue this workflow.
Open Help: Running Scans to continue this workflow.
Open Features to continue this workflow.
Open Plans, Credits, And Billing to continue this workflow.
Open Website Watch to continue this workflow.
Common questions for this topic.
Integration and automation capabilities are tied to supported account tiers and workspace roles.
Continue to the best next page based on where you are in your workflow.