Breach ManagementWorkflows and Scoring Rules

Workflows and Scoring Rules

Build the stages and tasks a breach incident moves through, route incidents to workflows from intake form rules, automate with basic and advanced rules, and tune the risk score with scoring rules.

A breach workflow is the response plan an incident follows once it is reported: an ordered set of stages, the tasks inside each stage, who works on them, and how long they have. Neostra creates a copy of the workflow for every incident that matches it, and the owner and assignees work through it from the incident and under Breach Management > Tasks. Handling a live incident is covered in Incidents. This page covers designing the workflow, routing and automation rules, and risk scoring rules.

Open Breach Management > Breach Workflows. Each card shows a System or Custom chip, the name, description, Version, Last Updated, and Tags. Use Search and Sort By to find a workflow. View Published opens a read-only view of the live version. Edit and the card menu's Delete are available on custom workflows only; system workflows are templates you copy from.

How an incident reaches a workflow

Routing is decided by the breach intake form the incident came through. Open the form under Breach Management > Breach Intake Forms and choose Workflow Rules. Click Add Rule and give it a Rule Name.

Under If, choose All or Any, then add conditions. Each condition pairs a form field (breach type, country, state, or any select field) with Is or Is Not and a value. Under Then the following action will be triggered, set the Workflow, Brand with optional Process and Sub Process, the Owner (Assign to me fills in your account), and Due in Days as calendar days or business days. This due date is the workflow's own; the regulatory notification deadline is calculated separately from the regulations that apply.

Every form has one default rule, marked "If none of the other rules will match", which cannot be deleted and always matches. Every matching rule creates its own workflow copy, so one incident can run several workflows in parallel. Click Save Changes, then Publish to make the rules live.

Create a workflow

Under Breach Workflows, click Add New and fill in the drawer:

FieldNotes
Default WorkflowThe system or published workflow to copy stages, tasks, and rules from.
Workflow NameRequired, up to 50 characters, unique within your account.
DescriptionRequired.
RegulationOne or more regulations this workflow is designed for.
Managing BrandTask assignees are chosen from users with access to this brand.
TagOptional tags shown on the card.

Click Add. The workflow opens with three tabs: Details, Builder, and Rules.

Details

The Details tab shows Name, Brand, Version, Description, Regulations, Tags, Author, Last Updated At, and Last Updated By. Click Edit to open Edit Workflow Details and change the Name, Description, Brand, Regulations, or Tags, then click Update.

Draft, Publish, and Discard Draft

A new workflow starts as a draft. On a published workflow, your first change in any tab creates a draft automatically, and Discard Draft and Publish become active in the header. Publish replaces the live version immediately. Discard Draft asks for confirmation, then removes every change since the last publish.

Each publish stamps a new Version, shown on the card and in Details. Incidents already running the workflow keep the version they started with. There is no rollback; to revert, change the configuration and publish again.

Builder: stages

The Builder tab, Manage Stages, shows the stages as a stepper. Click a stage to see its settings and tasks.

Click Add Stage and fill in the drawer:

  • Stage Name: required, up to 25 characters.
  • Auto Advance Stage: when on, the incident moves to the next stage as soon as every task in this stage is completed. When off, the owner clicks Advance Stage on the incident.

Click Save. Select a stage and click Edit Stage to change it, or Order Stages to drag stages into sequence or delete one. When the last stage completes, the workflow copy is marked completed.

Builder: tasks

Under Tasks in Stage, click Add task in stage:

FieldNotes
Task titleRequired, up to 200 characters.
DescriptionInstructions shown to the assignee.
Response TypeText, Date, Single Select, or Multiple Select. For the select types, add and drag Options; these become the answers you can test in rules.
Due In DaysRequired, greater than 0, as Calendar Days or Business Days.
AssigneesUsers with access to the workflow's brand. Each assignee gets their own copy of the task; the owner selects one response as the official answer.
NotesRequired, Optional, or None.
UploadRequired, Optional, or None.

Click Save. The task table lists Task, Type, Response Type, and Assignee with edit and delete actions. Order Tasks lets you drag tasks into sequence.

Rules

The Rules tab has two tables, Basic and Advanced. Basic rules shape the workflow by switching tasks and stages on or off and by tightening evidence requirements. Advanced rules react to progress by tagging, emailing, or calling an external API. Each row offers view, edit, and delete.

Basic rules

Click Add Basic Rule, enter a Name, and choose the Trigger Action:

  • Target: enable or disable other tasks or stages.
  • Requirement: make notes or uploads mandatory on a task.

Under If, choose All or Any, then add conditions. Each condition is a Single or Multiple Select Task with a Response, or a Stage that is started or is completed.

For a Target rule, add one or more targets, each with an Action (Enable or Disable), a Target Type (Task or Stage), and the Target. A disabled task or stage is skipped for that incident. For a Requirement rule, pick the Requirement Action: Notes Required, Uploads Required, Both Notes & Uploads Required, or Either Notes or Uploads Required. Basic rules run each time a task or stage completes.

Advanced rules

Click Add Advanced Rule, enter a Name, and set When the rule fires:

TypeFires when
Task is completedThe chosen task is completed by the Owner or by an Assignee.
Stage startedThe chosen stage begins.
Stage is completedThe chosen stage finishes.
Breach workflow startsThe workflow copy is created for the incident.
Breach workflow is completedThe final stage finishes.

Add one or more Actions:

  • Add Tag and Remove Tag: pick tags to apply to or clear from the incident.
  • Send Email: tick To the requestor to email the person who reported the breach, or enter Recipients and optional CC. Write a Subject and Body. Both accept the variables listed below.
  • Call API: choose an API Configuration Name from Settings > API Configuration, where the endpoint and authentication live. Under Headers, add name and value pairs; a value can be a literal or a variable. Under Content, define the JSON Request Body. Click a variable in Available Content to copy it. See Webhooks for the receiving side.

Under But Only If, optionally add conditions on task responses with Is or Is Not, joined by All or Any. Leave it empty to run the actions every time.

Variables available in the email subject and body and in the API request body: {{incidentId}}, {{incidentRef}}, {{status}}, {{locale}}, {{tenantId}}, {{brandId}}, {{reporterName}}, {{reporterEmail}}, {{reporterPhone}}, {{reporterOrganization}}, {{affectedGeographies}}, {{regulatoryDeadlineAt}}, and {{tags}}. Headers accept only {{tenantId}}, {{brandId}}, {{incidentId}}, and {{incidentRef}}.

Scoring Rules

Every incident receives a risk score from 0 to 100 and a classification: LOW (0 to 29), MEDIUM (30 to 59), HIGH (60 to 79), or SEVERE (80 to 100). The score is calculated on submission from the intake form answers, so you tell Neostra which fields and options feed it. Open the form and choose Scoring Rules.

Form Field to Scoring Dimension Mapping

Each panel is one scoring dimension. Expand it, pick a field from Select a form field to add, and click Add. For each Form option, choose the matching Scoring key. Options without a key do not score.

DimensionScoring keysEffect
Data SensitivityContact Information (5), Financial Data (15), Government ID (20), Health / Medical (25), Biometric (30), Children Data (+10), Profiling Data (+10)Only the highest of the first five counts; Children Data and Profiling Data are added on top.
Exposure SeverityInternal (5), Unauthorised Limited (10), Public Disclosure (20), Ransomware (20), Dark Web (25)Highest matching key.
Harm ProbabilityLow (5), Moderate (15), High (25)Highest matching key.
MitigationRapid Containment (5), Pseudonymisation (10), Strong Encryption (15)Deducted from the total, up to 20 points in all.
Encryption Key CompromisedYes, NoWhen Yes, the Strong Encryption deduction is skipped.
Individuals Affected (count)noneMap the numeric field; the value is read directly and used in escalation rules.

Data Sensitivity and Mitigation accept several fields; the other dimensions accept one.

Score Values

Override the default points for any scoring key. Each field shows the platform default as a placeholder. Leave a field blank to keep the default, or click Reset to defaults to clear every override on this form.

Escalation Rules

An escalation rule forces the classification to SEVERE whenever all of its conditions match, regardless of the score. Rules marked SYSTEM are supplied by Neostra and can be switched off with the toggle; editing one turns it into a CUSTOM rule that you own and can delete. Click Add Custom Rule and enter a Rule Name, Description, and conditions under Conditions (ALL must match). Each condition names a Dimension, an Operator (Contains, Does not contain, Equals, Greater than, or Less than), and a Value: a scoring key, or a number for Individuals Affected. Click Save Rule.

Scoring configuration is per form. Save it with Save Changes in the form header; it applies to incidents submitted after that.

The classification sets incident priority but does not change the regulatory deadline. Neostra calculates that deadline from the regulations that apply to the incident and defaults to 72 hours, matching GDPR Article 33, when none match.