Understand available security actions and the approval workflow
Hiro can propose and execute remediation actions across your connected integrations. All high-impact actions require explicit approval, ensuring you maintain full control over your security response.
PROPOSED ACTION: Suspend Okta User─────────────────────────────────Target: john@company.comReason: Account compromise detectedEvidence: • Login from Tor exit node (185.220.101.1) • Session created from previously unseen device • Unusual app access pattern (7 apps in 2 minutes)Confidence: High (88%)Impact: User will be locked out of all SSO applications[Approve] [Reject] [More Info]
When an integration doesn’t support API-based remediation, Hiro provides manual instructions:
MANUAL ACTION REQUIRED─────────────────────Hiro cannot automatically suspend users in your Okta configuration.To suspend john@company.com manually:1. Log in to Okta Admin Console2. Navigate to Directory > People3. Search for "john@company.com"4. Click the user, then Actions > Suspend5. Confirm the suspensionOnce complete, mark this action as done in Hiro.[Mark as Complete] [Need Help]
Every action (proposed, approved, rejected, executed) is logged:
ACTION AUDIT LOG────────────────2024-01-15 14:32:15 | PROPOSED | Suspend Okta user john@company.com2024-01-15 14:32:45 | APPROVED | by admin@company.com2024-01-15 14:32:46 | EXECUTED | Okta API returned success2024-01-15 14:32:47 | VERIFIED | User status confirmed as SUSPENDED
Access the full audit trail in Settings > Audit Log or export from any Fight Mode session.