If your dark web alerts always enter a dedicated queue/board, you can rely on the workflow trigger or filtering by that queue and skip explicit “is this dark web?” checks. If not, add a brief detection step in the triage instructions to confirm it’s a dark web alert before proceeding.
Workflow 1: Triage Company and Contact
Basic Configuration
1
Create the workflow
- Name: “Dark Web Alert - Triage”
- Type: Triggered
- Trigger Conditions:
- Ticket created
2
Add Ticket Triage action
Action: Ticket TriageFocus fields: Company, Contact (and optionally Type/Subtype if you want)This action will identify the correct Company and Contact from the alert details.
3
Add Update Ticket Fields action
Action: Update Ticket FieldsAdd this action in the Write to PSA section so Company and Contact are set in your PSA.
Workflow 2: Build Message and Close/Update Status
Basic Configuration
1
Create the workflow
- Name: “Dark Web Alert - Notify and Close”
- Type: Triggered
- Trigger Type: Add “Workflow Finished” trigger and select the previous Triage workflow
2
Add Build Message action
Action: Build Message
- Message Type: Customer Facing
- Instructions (plain English; describe the style and content, not a fixed template):
3
Add Update Ticket Fields action
Action: Update Ticket Fields
- Add Update Ticket Fields in Write to PSA section
- Mark the checkbox “Update Additional Fields”
- A dropdown for the New Status will appear
- Select the new
Status(e.g., “Customer Notified” or “Closed - Notified”) to move the ticket to
4
Add Notify Ticket's Contact action
Action: Notify Ticket’s Contact
- Uses the message generated by
Build Message - Selects the ticket contact as the recipient
Tips
- Start with note-only runs to validate messaging and status changes
- Need different wording for one client? Pin a company memory for them. Pinned memories are included when a workflow’s Smart Actions run for that company.
