Quick Links

Action plans in Hearth

Overview

An action plan is a remediation worklist that Hearth builds from an investigation. When Hestia finishes an investigation and recommends follow-ups, you can convert those recommendations into one tracked plan. Examples of follow-ups include an audit of a set of sign-ins, the disablement of a token, and a confirmation with an account owner.

A plan contains a snapshot of the evidence and a checklist of steps that you can work through. The Actions page collects every open plan for your workspace, along with the gated actions that wait for a person to approve them.

Important: No part of an action plan runs on its own. Every step passes through a propose-confirm gate. Hearth proposes the step, and a person reviews and confirms the step before anything happens.

How it works

You create a plan from a finished investigation. Hearth builds a plan in one of two shapes, and it selects the correct shape for you. The following table describes the two shapes:

SourceWhat Hearth builds
An investigationThe recommended follow-ups of an investigation are coordinated steps for one incident, so Hearth bundles them into a single plan. The checklist of the plan contains those recommendations. A plan of this shape displays a General checklist banner, because it comes from your investigation rather than from a curated playbook. You cannot edit the text of a step, but you can mark any step that does not fit as skipped or not applicable.
A dashboard recommended actionThe recommended actions of a dashboard are separable, because they have different owners and scopes. As a result, each Investigate → button on a recommended action creates its own plan. When the action matches a curated playbook, the plan displays a Vetted playbook banner that names the playbook.

Parts of a plan

The following table describes the parts of a plan:

PartDescription
PriorityThe priority that Hearth assigns to the plan.
Provenance recapThe record of where the plan came from.
Investigation snapshotThe summary and findings of the source investigation. Hearth expands this section by default. You can collapse it.
ChecklistThe steps that you work to done.

Note: Hestia can run some steps for you as a focused, single-step investigation. Hestia runs only the read-only, investigative kinds of steps. Any step that changes something remains a manual step that a person confirms.

What you can see and do

The following table describes the two sections of the Actions page:

SectionDescription
Open plansLists every action plan of your workspace that is not closed. Each row displays a step-completion count, the current state, the priority, and the owners.
Proposals to approveLists the gated actions that Hestia proposed and that wait for a person to review and confirm. Each row states that nothing runs until you confirm, and that Hearth runs the action only when your role can perform it.

To work a single plan in the detail panel, click the plan in the Actions list or click the plan link on an investigation.

Elements of a plan

The following table describes what you can do inside a plan:

ElementDescription
EvidenceDisplays the investigation summary and the findings that the plan is built on.
Stale-evidence bannerAppears when the evidence ages past the freshness threshold of the plan. The banner includes a Refresh investigation control, which runs the underlying investigation again and appends a new snapshot.
ChecklistAllows you to set the status of each item.
Run for meAppears on an investigate-type or audit-type step. It sends the step to Hestia as a new chat request and marks the step as started. When Hestia finishes, the result appears under the step with a link to the full investigation.
State controlAppears in the footer and displays the current state of the plan and the valid next states.
Outbound message draftAllows Hearth to draft the subject, body, and recipient of an email for a step that requires contact with someone. You review the draft, edit it, and send it from your own mail client. Hearth never sends mail on your behalf.

Checklist item statuses

The following table describes the status of a checklist item:

StatusDescription
PendingYou have not started the item.
Step startedHestia is working on the item or has worked on it, either through “Run for me” or “Send to composer.” Hearth sets this status for you, and you cannot select it from the status menu.
DoneYou completed the item.
BlockedSomething prevents the item. This status requires a blocker note.
SkippedYou chose not to perform the item.
Not applicableThe item does not apply. This status requires a reason.

Plan lifecycle states

A plan moves from not started, to investigating, to action proposed, and then to a resolution. The following table describes the resolutions:

ResolutionDescription
ResolvedYou completed the work. You can reopen this plan.
Blocked (pending external)Something outside Hearth prevents the work. When you select this state, you choose a reason category (customer pending, vendor pending, Hearth data gap, or analyst capacity), and you can add a note.
EscalatedThe plan requires attention beyond your team.
False positiveThe source finding was not a real issue. You can reopen this plan.
Benign true positiveThe activity was real but expected.
Out of scopeThe activity falls outside the scope of your program.
DuplicateAnother plan covers the same work.

Note: Nothing in a plan runs on its own. “Run for me” performs a read-only investigation rather than a change. A gated action in “Proposals to approve” requires a person to confirm it, and Hearth performs it only when the role of that person can perform the action.

Creating an action plan

To create a plan from an investigation, do the following:

  1. Open a Hestia investigation that contains recommended actions.
  2. Click Turn into an action plan. Hearth bundles the recommendations into one plan and opens it.

Note: When you repeat this procedure on the same investigation, Hearth returns the existing plan rather than a duplicate.

Reviewing the evidence and the checklist

To review a plan before you work it:

  1. At the top of the plan, read the investigation snapshot.
  2. Review the checklist.
  3. If Hearth marked the plan generic, edit the steps, skip them, or mark them not applicable, so that the list reflects the work that you perform.

Working the steps

To work the checklist:

  1. Set the status of each item by clicking the status pill and then selecting the status.
  2. On an investigate-type or audit-type step, click Run for me. Hestia runs the step, advances it to done, saves the result as an investigation artifact, and records the step in the history of the plan.
  3. Review the result, and then mark the step done.
  4. Type a blocker note on any item that you cannot finish.
  5. Type a reason on any item that does not apply.

Moving the plan forward

To advance a plan, do the following:

  1. In the footer of the plan, click the state you want to apply. Hearth displays only the states that are valid transitions from the current state.
    Note: When you first set the status of any step, Hearth moves the plan from not started to investigating for you.
  2. (Optional) To pause the plan on something outside Hearth, select blocked (pending external), and then type a reason.

Approving or dismissing a proposal

To act on a gated action that Hestia proposed:

  1. Navigate to the Actions page (Workspace > Actions).
  2. In the Proposals to approve section, review the proposed action.
  3. Do one of the following:
    • Click Review & confirm to perform the action.
    • Click Dismiss to close the proposal.

Refreshing stale evidence

When the evidence of a plan ages past the freshness threshold, a stale-evidence banner appears. To clear the banner, click Refresh investigation. Hearth runs the underlying investigation again and appends a new snapshot.

Closing a plan

To close a plan, select resolved or the disposition that applies. Hearth records every close. You can reopen a plan that you resolved or marked as a false positive.

Troubleshooting common issues

IssueWhat to do
The Actions page shows an error message instead of the list of action plansViewing action plans requires the “View artifacts” permission. Confirm your permissions with an administrator.
“Turn into an action plan” has no effect or returns an errorThe investigation must contain recommended actions. Hearth cannot bundle an investigation that has no recommendations into a plan.
A step has no “Run for me” buttonOnly investigate-type and audit-type steps run through Hestia. A communicate-type (for example, "contact" or "verify with") displays "Draft outbound" instead. A remediate-type (for example, "disable" or "revoke") or decide-type step requires manual work and confirmation by a person.
A step returns the message "Step is already running."A step accepts a new run only from the pending status. When a run wedges, set the status of the step to pending, and then run it again.
You are unsure whether Hearth remediates automatically after it builds a planHearth does not. Action plans are propose-only from end to end. "Run for me" performs a read-only investigation. Hearth proposes every change for a person to confirm, and it performs the change only when the role of that person can perform it.
The stale-evidence banner does not clearClick "Refresh investigation" to run the underlying investigation again. The banner clears when the new snapshot is fresh. This action requires the run_investigations permission.