Actions
An Action is a saved, versioned response, such as Isolate endpoint or Initiate patch. People run it without seeing or choosing the script underneath. Each Action sets:
- what runs: a script (a pinned version, or the latest published one) or a built-in Scout verb such as kill;
- the form people fill in when they run it, with presets;
- which endpoints it can target (platforms, required tags);
- its risk level and approval policy;
- its default rollout and how long a run waits for offline endpoints;
- optionally, the Action that undoes it.
Beta
This feature is currently rolling out and may not be enabled for your organization.
Starter Actions
Every organization starts with these. They wrap the Huntbase pack.
| Action | Runs | Risk | Approval | Notes |
|---|---|---|---|---|
| Isolate endpoint | isolate-host | High | Two people | Undone by Release endpoint. See Isolate an endpoint. |
| Release endpoint | release-host | Low | None | |
| Initiate patch | patch-package | High | Organization admin | Parameters: package, minimum version, reboot. Starts with a canary. |
| Collect triage bundle | triage-bundle | Medium | None | |
| Kill process by name | Built-in kill | Medium | None | Scout's own processes and system processes are still protected. |
| Disable local account | disable-local-user | High | Two people |
Create an Action
- Open Library › Actions and click New action, then choose Endpoint.
- Pick the script and how it's pinned: Latest published, or a specific version.
- Build the run form from the script's arguments. Give each a label and default. Mark an argument Fixed to always use its default; it isn't asked at run time. Add Presets for common combinations.
- Optionally limit targets to some platforms or to endpoints carrying a tag.
- Set the risk level and approval policy: Organization default, None, Two people or Organization admin.
- Choose the default rollout and the run expiry (1 to 24 hours).
- Optionally choose the Action that undoes this one.
- Click Create action.
You can also start from an ad-hoc script run. On an endpoint's Actions tab, click Save as Action on the run.
Editing an Action saves a new version. Every run records the version it used.
The Action page
| Tab | Shows |
|---|---|
| Endpoints | The latest outcome of this Action on every endpoint it has run on. For a paired Action it shows the current state, for example how many endpoints are isolated right now. Export it as CSV. |
| Runs | Every run of this Action. Each opens in Activity › Actions. |
| Definition | What runs, the form, constraints, risk, approval and rollout. |
| Versions | Each saved version and who saved it. |
| Access | Who can edit, run and approve it. |
Who can do what
| To | You need |
|---|---|
| Run an Action | Runner on the Action (or organization admin) and response access to every targeted endpoint, on the fleet or on a tag they carry. |
| Approve a run | Approver on the Action, or organization admin. Two-person approval never accepts the requester. |
| Create or edit | Editor on the Action, plus Runner on the script it wraps. |
Running an Action does not need access to the script inside it.