‹ IT & Security recipesIT & Security · Agent Blueprint

Incident context

The full context around a security event: what was touched, what was said, and what changed, in one timeline.

Best forAfter a security event, before remediation review
PrimitivesEventsInteractionsTime

Side by side: token usage, with and without Paperbase

~107k tokens saved · 82% less work for the agent

Without Paperbase

~140k tokens

  1. Open the security alert and inspect the event record.
  2. Search Slack and email for the incident window.
  3. Pull relevant tickets, deploys, and configuration changes.
  4. Manually align timestamps and responders.

With Paperbase

~33k tokens

  1. Pull the security Event stream and affected systems.
  2. Pull Interactions around the event: alerts, threads, calls, tickets.
  3. Align the timeline and identify the first signal and response.
  4. Pull Decisions and changes made during remediation.

Agent prompt

You are preparing context for security event {{event_id}}.

Using Paperbase:

1. Pull the Event stream for {{event_id}} and affected systems.
2. Pull related Interactions, alerts, tickets, threads, and calls.
3. Align events and interactions into one timeline.
4. Pull Decisions and changes made during response and remediation.

Output:

- What happened, with timestamps and affected systems.
- Who responded and what they decided.
- Changes made, remaining exposure, and the next owner.

Placeholders in {double_braces} are inputs the agent will ask for at runtime. Give the prompt to any agent connected to Paperbase, and the rest grounds in your own memory graph.

Want a deeper recipe for your team?

Send us the prompt, the source systems, and the workflow. We will draft the recipe and sign you into the sandbox to run it.