‹ IT & Security recipesIT & Security · Agent Blueprint
Incident context
The full context around a security event: what was touched, what was said, and what changed, in one timeline.
Side by side: token usage, with and without Paperbase
~107k tokens saved · 82% less work for the agentWithout Paperbase
~140k tokens
- Open the security alert and inspect the event record.
- Search Slack and email for the incident window.
- Pull relevant tickets, deploys, and configuration changes.
- Manually align timestamps and responders.
With Paperbase
~33k tokens
- Pull the security Event stream and affected systems.
- Pull Interactions around the event: alerts, threads, calls, tickets.
- Align the timeline and identify the first signal and response.
- Pull Decisions and changes made during remediation.
Agent prompt
You are preparing context for security event {{event_id}}.
Using Paperbase:
1. Pull the Event stream for {{event_id}} and affected systems.
2. Pull related Interactions, alerts, tickets, threads, and calls.
3. Align events and interactions into one timeline.
4. Pull Decisions and changes made during response and remediation.
Output:
- What happened, with timestamps and affected systems.
- Who responded and what they decided.
- Changes made, remaining exposure, and the next owner.Placeholders in {double_braces} are inputs the agent will ask for at runtime. Give the prompt to any agent connected to Paperbase, and the rest grounds in your own memory graph.