Automations
Automate the busywork. Keep the receipts.
The link cleanup, the offboarding leftovers, the license chase - the work that eats your week without making anyone safer. 1Security automations run it for you: counted against your live tenant before you enable anything, staged behind a review queue you control, and recorded in a ledger you can replay. Your time goes back to actually protecting.
Nothing acts without a separate write consentThe problem
Security teams don’t drown in attacks. They drown in chores.
An ex-contractor still holds access to three sites. Four hundred “Anyone” links have quietly outlived their purpose. A dozen licenses idle on accounts that left in March. None of it is an incident, so none of it ever wins against the incident queue - and every quarter the pile grows.
The industry’s answer is a dashboard that shows you the pile. Ours is a machine that works through it - carefully, visibly, and only as far as you allow.
The number, not the promise
Every automation tells you what it would fix - before you enable it.
A curated catalog of remediations across AI safety, oversharing, hygiene and cost - each one counted live against your tenant while you browse. The first question stops being “what could this do?” and becomes “it found 1,204 - do I want them fixed?”
- Ready to run
suggested remediations
Curated policies across sites, files, users, groups, apps, devices, email and licenses - with live counts on every card.
- Preview first
the real affected resources
Every suggestion opens onto the actual list of what it would touch, the conditions used, and the arguments the action would run with.
- Yours to tune
review & customize
Open any suggestion in the policy editor - conditions, arguments, severity - and your customization survives future catalog updates.
Control
A grace period and a human review queue, by default.
Enabling an automation doesn’t fire it. It stages proposals - and the clock, the queue and the final word are yours.
- 01
Enable
The automation starts staging a proposal per resource instead of acting - by default with a 72-hour window before anything happens.
- 02
Review
Approve, reject (which snoozes the resource for 30 days), withdraw - or let the clock run out. Bulk review applies decisions by match, so proposals arriving mid-review are included.
- 03
Act
Only then does anything change - and composite actions understand the permission graph, showing the blast radius per source and asking before touching anything that would affect other people.
Breadth
One catalog for policies and one-off actions alike.
Manual actions share the same catalog and the same ledger - run an action once from a list or a resource drawer, and it is recorded exactly like a policy-driven one.
- Sites - sharing, link defaults, privacy, Copilot indexing
- Files - link removal, revoke, downgrade, delete
- Users & groups
- Apps & agents
- Devices - enable / disable
- Email actions
- Licenses
The receipts
Every action, accounted for.
Four live counters, an “engine live - last evaluation X ago” strip, per-automation firing stats, and an actions chart from one hour to one year - with click-through to the exact resources changed. When someone asks “what did the robot do?”, the answer is a list, not a shrug.
- Activeautomations, visible at a glance
- 30 daysof runs and resources remediated, counted
- 1h → 1yactions chart with click-through
- 100%of actions in the review ledger
Read-only until you say otherwise.
Detection, counting and previews run on the read-only application. Remediation requires a second, separately consented write application - and even then automations stage instead of firing. Blocked attempts are logged. Nothing in this product changes your tenant without an explicit, revocable decision.
Give the chores to the machine.
Connect read-only, browse the catalog, and see the counts for your own tenant - before anything is allowed to act.
No thanks - I’ll clean the links by hand.