Skip to main content

Saas Security - Take Action on the Incident

This Playbook is part of the SaaS Security by Palo Alto Networks Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.0.0 and later.

This sub-playbook will send email notification to the Saas Security Admin for taking remediation action on the incident.


This playbook uses the following sub-playbooks, integrations, and scripts.


This playbook does not use any sub-playbooks.


  • SaasSecurity


This playbook does not use any scripts.


  • saas-security-incident-state-update
  • saas-security-asset-remediate

Playbook Inputs#

NameDescriptionDefault ValueRequired
emailAdmin EmailOptional
incident_idPrisma Saas Incident IdOptional
asset_idPrisma Saas Asset IdOptional
asset_namePrisma Saas Asset NameOptional

Playbook Outputs#

There are no outputs for this playbook.

Playbook Image#

Saas Security - Take Action on the incident