Quick Links

Briefings in Hearth

Overview

A briefing is a pre-written prompt that Hestia runs in one click and turns into an artifact. An artifact is a finished report that you can read, share, and run again to track a trend over time. Instead of typing the same question every week, such as "give me this month's CISO scorecard" or "map my asset inventory," you run a briefing and receive a consistent, structured result each time.

Hearth includes two types of briefings:

  • Built-in briefings: Blumira maintains a catalog of role-based reports. Each briefing is tied to a security role and produces a specific recurring deliverable, such as a posture scorecard, an asset inventory, or a compliance summary. The roles are CISO, DFIR, IT Director, GRC, Threat Hunter, and Account Watch. MSP accounts also include MSP Operations and MSP Owner.
  • Custom briefings: These are prompts that you save. When a prompt produces a good answer, save it as a reusable briefing for your workspace, so that you and your team can run it again in one click.

Every briefing produces an artifact, exactly as if you typed the prompt yourself. A run that you start in the app also appears in Conversations, so that you can return to the thread later.

Note: Some built-in briefings appear only when they apply to your workspace. MSP-specific briefings appear on MSP accounts, and provider-specific briefings appear after you connect that integration. For more information, see "Troubleshooting common issues."

How it works

Using Hearth briefings entails the following:

  1. You select a briefing. Select a built-in briefing from the catalog, or a briefing that you saved.
  2. Hestia runs the briefing. The prompt goes through the same agent loop as a question that you type yourself. This loop includes read-only queries, enrichment, and analysis.
  3. Hestia returns an artifact. The artifact is a finished, structured report. When a briefing tracks a trend, Hestia adds your most recent prior artifact of the same type. As a result, consecutive runs read as a series instead of separate snapshots.
  4. Hearth saves the artifact. The artifact appears in Artifacts. A run that you start in the app also appears in Conversations, so that you can resume it.

What you can see and do

The Briefings page lists the briefings that are available to your workspace. The following table describes the groups on the page:

GroupDescription
Recommended todayA short, ranked list of briefings that are worth running now, based on your workspace.
By roleThe full catalog, grouped by role, such as CISO, DFIR, and GRC. This section also includes your custom briefings.

Each row includes a Run button. A custom briefing also includes a Delete option. You cannot delete a built-in briefing, because it is part of the product.

Note: Deletion of a custom briefing is permanent, and the confirmation states this. However, the artifacts that the briefing already produced remain in Artifacts.

Running a briefing

To run a briefing, do the following:

  1. Navigate to More > Briefings.
    Note: If you have saved or scheduled briefings, those also appear on the Home page.
  2. On the Briefings page, find the briefing that you want to run.
  3. Click Run.

Hestia runs the briefing and produces an artifact. The run also appears in Conversations.

Saving a prompt as a briefing

When a prompt produces a result that is worth repeating, save it as a briefing. You save a briefing from the finished artifact, not from the composer.

To save a prompt as a briefing, do the following:

  1. Open the artifact from Conversations, from Artifacts, or directly after a run.
  2. In the side panel of the artifact, click Save as briefing.
  3. Type a title.
  4. Click OK.

Hearth saves the briefing as a custom briefing for your entire workspace and confirms where to run it. Each workspace can save up to 50 custom briefings.

Note: The option to save a briefing appears only on the side panel of an artifact. Hearth does not offer this option on the general chat view, on action-plan panels, or on cohort views, because there is no saved prompt to codify.

Re-running a briefing to track a trend

Run the same briefing again later. For a briefing that tracks a trend, Hearth links the new artifact to the prior artifact, so that you can compare the runs.

Scheduling a briefing to run automatically

You can run a briefing on a recurring cadence of hourly, daily, or weekly, so that a report is ready when you need it. For example, you can schedule a daily fleet report or a weekly Monday review.

Recurring schedules live on the Automations page, not on the Briefings page. Hearth consolidates every recurring run into the Automations map, under the Schedules group. 

To create or manage a schedule, do the following:

  1. Navigate to More > Automations.
  2. Click + New automation, then do one of the following:
    • If using the Guided Builder:
      1. In the Automation type box, select briefing schedule – runs on a cadence.
      2. Under Briefing, select the saved or built-in briefing that you want to schedule.
      3. Select the relevant Cadence, Hour, and Day values.
    • If using Ask Hestia:
      1. In the chat box, type a description for the automation in plain language.
      2. Click Ask Hestia to draft this.
      3. Review the draft and edit as necessary.
  3. Click Save automation.

Troubleshooting common issues

IssueWhat to do
A briefing that you expected is not in the listSome built-in briefings are conditional. MSP-specific briefings appear only on MSP accounts, and a briefing that depends on an integration appears only after you connect that provider. A brief service interruption can also hide a conditional briefing until the check runs again. Reload the page.
A briefing that you expected does not runA message states that the briefing is not available for your workspace. This message means that the briefing does not apply here. For example, you ran an MSP-only briefing on a standalone account, or a briefing that requires an integration that you have not connected. Connect the required integration, or select a briefing that fits your workspace.
You cannot save another custom briefingEach workspace is limited to 50 custom briefings. Delete a briefing that you no longer use, and then save the new one.
A scheduled briefing does not appear in ConversationsThis behavior is expected. Hearth saves recurring, automatic runs as artifacts only, so that they do not crowd your Conversations list. An interactive run that you start yourself does appear in Conversations.
You deleted a custom briefing and want its reportsDeletion removes the reusable prompt only. Every artifact that the briefing already produced remains in Artifacts.
You can view briefings but cannot run or save themThe run briefings permission allows you to run and save a briefing. Blumira intends this permission for analyst roles and above. Hearth always blocks a read-only support account. If you are a workspace member and cannot run a briefing, contact your tenant admin.