Skip to main content

Approvals and Needs you

Scout plans steps, but in Guide and Collaborator it asks before it runs anything that matters. On this page you approve or reject the steps Scout proposes, decide checkpoints, use Needs you to clear what the hunt is waiting on, and run the whole hunt with Run all.

What Scout stops for​

How much Scout asks depends on the hunt's Scout mode, shown in the header as Scout: Guide, Scout: Collaborator or Scout: Operator:

ModeWhat waits for you
GuideEvery finding. You drive each step, and nothing in a plan runs until you approve its checkpoint.
CollaboratorActions. Scout runs low-risk queries itself, but a plan still waits for its checkpoint.
OperatorLittle. Scout runs the investigation and you review the report.

Only the hunt's owner and contributors can approve or reject. Anyone else sees Review in place of the buttons.

Approve a step Scout proposed​

Steps Scout proposes. When Scout plans a task, query, collection, detection or action that needs a go-ahead, the cell says Scout proposed this step — waiting for approval. and has its own buttons. Approve & run approves and runs a query or collection, and Approve approves a task or detection. Reject turns the step down. An action shows Review instead, which opens its panel, because approving some actions needs a confirmation note. If you can't edit the hunt, you only see Review.

To decide a proposed step:

  1. Find it in the notebook, or click it under Needs you in the details pane.
  2. Read what it will do: the query text, the task, or the action and its target.
  3. Click Approve & run (a query or collection) or Approve (a task or detection) to go ahead, or Reject to turn it down.

An approved query runs straight away. An approved task becomes work for your team: mark it done with Mark done when it's finished.

Decide a checkpoint​

A Checkpoint cell stops the plan until a person decides. When Scout plans a hunt in Guide or Collaborator, one checkpoint approves the whole plan, and nothing in it runs until you do. Under Your approval is needed the checkpoint offers:

ButtonWhat it does
Approve stepApproves the checkpoint. The next steps start.
RefineOpens Refine the hunt: steer the hypothesis or add context, and Scout replans from the checkpoint.
AbortAsks first (Abort this hunt?), then stops the hunt and closes it.

Checkpoints can also be approved from Needs you, and Scout's chat shows the same choice on an Approval required — auto-hunt card. See Chatting with Scout.

Endpoint actions and watches​

An Endpoint action or Endpoint watch is approved on its own approval card, which checks your organization's approval rules first. By default someone other than the person who asked has to approve it, and a proposal lapses if nobody approves it in time. See Approve an action or a watch.

Work through Needs you​

The details pane's Outline tab ends with Needs you: everything the hunt is waiting on, in notebook order.

ItemWhat to do
A failed cellOpen it and run it again or fix it. See What a cell found.
A checkpointApprove step from the list, or open the cell to refine or abort.
A step Scout proposedApprove it from the list with the same button as on the cell.
A query that needs parametersFill in parameters takes you to the cell's inputs.
An action or endpoint proposalReview takes you to the cell and its approval card.
The verdictAlways last. See Record a verdict and close.

To clear the list:

  1. Open the details pane's Outline tab. If the pane is hidden, click Show details in the notebook header.
  2. Click Next under Needs you to jump to the first item.
  3. Act on it, from the list or in its cell, then click Next again.

The hunt's needs-you count also shows beside it in the dock's Workspace tree and in the Activity Feed.

Run the whole hunt​

Run all (N) in the header runs every step that can run. When some steps will stop for approval, the button says so instead, for example Run 2 · 6 need approval, and its tooltip lists the steps it will pause at. While it runs, it becomes Cancel (n/m) with the step in progress.

Endpoint cells and telemetry view cells never run as part of Run all.

Closing a hunt settles what's still waiting: steps waiting for approval are rejected and running queries stop. After you reopen it, you can run them again. See What closing does.

Next steps​