Agent Team template
A security workflow that watches alerts, gathers evidence from code and runtime systems, ranks blast radius, and prepares a human-approved remediation plan before any production action.
One-message setup · 3 specialists · Managed browser · Live after setup
Designed for
AI startups and small security-conscious engineering teams that need fast alert triage without noisy automation
Outcome
Reduce security alert investigation time while preserving evidence quality, approval gates, and incident audit trails.
Say what should be true when the work is done.
Codelit runs one labeled Sample with no account, model, or external App calls.
Review the evidence, then reuse the same brief with your data when it is useful.
Classifies the alert and identifies likely affected systems.
Fast classification model
Collects source-linked facts without mutating systems.
Long-context tool-use model
Drafts containment, remediation, and owner handoff.
Reasoning model
Loads the workflow goal, allowed actions, escalation policy, and output contract before the agent plans work.
A workflow skill that captures the operating contract, tool boundaries, and escalation rules for Sentinel: Security Triage Agent.
Centralizes high-risk action checks for writes, secrets, customer data, billing, deploys, and public communications.
Exposes task resources, prompt templates, connector tools, and audit records behind a permission-aware boundary.
tools · resources · prompts
Determine severity, affected service, and owner.
Read traces, diffs, dependency state, and secret scan summaries.
Draft containment, remediation, and communication plan.
Approve rollback, revocation, disclosure, or production mitigation.
Open it in Codelit and describe the result. Codelit handles common setup while Flow stays available for direct editing and Activity keeps the proof.
Use this teamTurns one scoped release request into a reviewed branch artifact, preview deployment, browser-verified result, pull request, production promotion, and Slack proof using the accounts the team already owns.
Correlates Sentry, Datadog, PagerDuty, and deployment evidence, proposes one bounded mitigation, pauses on the exact actions, and leaves status proof for responders.
A controlled workflow for small teams that want an internal agent to answer operational questions, create tickets, inspect connected apps, and prepare approved actions across the company stack.