Overview
An action plan is a remediation worklist that Hearth builds from an investigation. When Hestia finishes an investigation and recommends follow-ups, you can convert those recommendations into one tracked plan. Examples of follow-ups include an audit of a set of sign-ins, the disablement of a token, and a confirmation with an account owner.
A plan contains a snapshot of the evidence and a checklist of steps that you can work through. The Actions page collects every open plan for your workspace, along with the gated actions that wait for a person to approve them.
Important: No part of an action plan runs on its own. Every step passes through a propose-confirm gate. Hearth proposes the step, and a person reviews and confirms the step before anything happens.
How it works
You create a plan from a finished investigation. Hearth builds a plan in one of two shapes, and it selects the correct shape for you. The following table describes the two shapes:
| Source | What Hearth builds |
|---|---|
| An investigation | The recommended follow-ups of an investigation are coordinated steps for one incident, so Hearth bundles them into a single plan. The checklist of the plan contains those recommendations. A plan of this shape displays a General checklist banner, because it comes from your investigation rather than from a curated playbook. You cannot edit the text of a step, but you can mark any step that does not fit as skipped or not applicable. |
| A dashboard recommended action | The recommended actions of a dashboard are separable, because they have different owners and scopes. As a result, each Investigate → button on a recommended action creates its own plan. When the action matches a curated playbook, the plan displays a Vetted playbook banner that names the playbook. |
Parts of a plan
The following table describes the parts of a plan:
| Part | Description |
|---|---|
| Priority | The priority that Hearth assigns to the plan. |
| Provenance recap | The record of where the plan came from. |
| Investigation snapshot | The summary and findings of the source investigation. Hearth expands this section by default. You can collapse it. |
| Checklist | The steps that you work to done. |
Note: Hestia can run some steps for you as a focused, single-step investigation. Hestia runs only the read-only, investigative kinds of steps. Any step that changes something remains a manual step that a person confirms.
What you can see and do
The following table describes the two sections of the Actions page:
| Section | Description |
|---|---|
| Open plans | Lists every action plan of your workspace that is not closed. Each row displays a step-completion count, the current state, the priority, and the owners. |
| Proposals to approve | Lists the gated actions that Hestia proposed and that wait for a person to review and confirm. Each row states that nothing runs until you confirm, and that Hearth runs the action only when your role can perform it. |
To work a single plan in the detail panel, click the plan in the Actions list or click the plan link on an investigation.
Elements of a plan
The following table describes what you can do inside a plan:
| Element | Description |
|---|---|
| Evidence | Displays the investigation summary and the findings that the plan is built on. |
| Stale-evidence banner | Appears when the evidence ages past the freshness threshold of the plan. The banner includes a Refresh investigation control, which runs the underlying investigation again and appends a new snapshot. |
| Checklist | Allows you to set the status of each item. |
| Run for me | Appears on an investigate-type or audit-type step. It sends the step to Hestia as a new chat request and marks the step as started. When Hestia finishes, the result appears under the step with a link to the full investigation. |
| State control | Appears in the footer and displays the current state of the plan and the valid next states. |
| Outbound message draft | Allows Hearth to draft the subject, body, and recipient of an email for a step that requires contact with someone. You review the draft, edit it, and send it from your own mail client. Hearth never sends mail on your behalf. |
Checklist item statuses
The following table describes the status of a checklist item:
| Status | Description |
|---|---|
| Pending | You have not started the item. |
| Step started | Hestia is working on the item or has worked on it, either through “Run for me” or “Send to composer.” Hearth sets this status for you, and you cannot select it from the status menu. |
| Done | You completed the item. |
| Blocked | Something prevents the item. This status requires a blocker note. |
| Skipped | You chose not to perform the item. |
| Not applicable | The item does not apply. This status requires a reason. |
Plan lifecycle states
A plan moves from not started, to investigating, to action proposed, and then to a resolution. The following table describes the resolutions:
| Resolution | Description |
| Resolved | You completed the work. You can reopen this plan. |
| Blocked (pending external) | Something outside Hearth prevents the work. When you select this state, you choose a reason category (customer pending, vendor pending, Hearth data gap, or analyst capacity), and you can add a note. |
| Escalated | The plan requires attention beyond your team. |
| False positive | The source finding was not a real issue. You can reopen this plan. |
| Benign true positive | The activity was real but expected. |
| Out of scope | The activity falls outside the scope of your program. |
| Duplicate | Another plan covers the same work. |
Note: Nothing in a plan runs on its own. “Run for me” performs a read-only investigation rather than a change. A gated action in “Proposals to approve” requires a person to confirm it, and Hearth performs it only when the role of that person can perform the action.
Creating an action plan
To create a plan from an investigation, do the following:
- Open a Hestia investigation that contains recommended actions.
- Click Turn into an action plan. Hearth bundles the recommendations into one plan and opens it.
Note: When you repeat this procedure on the same investigation, Hearth returns the existing plan rather than a duplicate.
Reviewing the evidence and the checklist
To review a plan before you work it:
- At the top of the plan, read the investigation snapshot.
- Review the checklist.
- If Hearth marked the plan generic, edit the steps, skip them, or mark them not applicable, so that the list reflects the work that you perform.
Working the steps
To work the checklist:
- Set the status of each item by clicking the status pill and then selecting the status.
- On an investigate-type or audit-type step, click Run for me. Hestia runs the step, advances it to done, saves the result as an investigation artifact, and records the step in the history of the plan.
- Review the result, and then mark the step done.
- Type a blocker note on any item that you cannot finish.
- Type a reason on any item that does not apply.
Moving the plan forward
To advance a plan, do the following:
- In the footer of the plan, click the state you want to apply. Hearth displays only the states that are valid transitions from the current state.
Note: When you first set the status of any step, Hearth moves the plan from not started to investigating for you. - (Optional) To pause the plan on something outside Hearth, select blocked (pending external), and then type a reason.
Approving or dismissing a proposal
To act on a gated action that Hestia proposed:
- Navigate to the Actions page (Workspace > Actions).
- In the Proposals to approve section, review the proposed action.
- Do one of the following:
- Click Review & confirm to perform the action.
- Click Dismiss to close the proposal.
Refreshing stale evidence
When the evidence of a plan ages past the freshness threshold, a stale-evidence banner appears. To clear the banner, click Refresh investigation. Hearth runs the underlying investigation again and appends a new snapshot.
Closing a plan
To close a plan, select resolved or the disposition that applies. Hearth records every close. You can reopen a plan that you resolved or marked as a false positive.
Troubleshooting common issues
| Issue | What to do |
|---|---|
| The Actions page shows an error message instead of the list of action plans | Viewing action plans requires the “View artifacts” permission. Confirm your permissions with an administrator. |
| “Turn into an action plan” has no effect or returns an error | The investigation must contain recommended actions. Hearth cannot bundle an investigation that has no recommendations into a plan. |
| A step has no “Run for me” button | Only investigate-type and audit-type steps run through Hestia. A communicate-type (for example, "contact" or "verify with") displays "Draft outbound" instead. A remediate-type (for example, "disable" or "revoke") or decide-type step requires manual work and confirmation by a person. |
| A step returns the message "Step is already running." | A step accepts a new run only from the pending status. When a run wedges, set the status of the step to pending, and then run it again. |
| You are unsure whether Hearth remediates automatically after it builds a plan | Hearth does not. Action plans are propose-only from end to end. "Run for me" performs a read-only investigation. Hearth proposes every change for a person to confirm, and it performs the change only when the role of that person can perform it. |
| The stale-evidence banner does not clear | Click "Refresh investigation" to run the underlying investigation again. The banner clears when the new snapshot is fresh. This action requires the run_investigations permission. |