Skip to main content

Playbooks

Use these playbooks as starting points for common initiatives such as establishing inventory baselines, improving metadata completeness, identifying control gaps, investigating change impact, and building application-focused views. Adapt each playbook to your environment, scope, tooling and workflows.

Inventory & Visibility Baseline

Goal: Establish a trusted inventory for a target scope (for example, production cloud accounts) and validate that CMDB coverage is complete.

  • Use Ingestion and Requirements to ensure all relevant accounts, regions, and integrations are connected.
  • Build CMDB queries that list active CIs by provider, account, region, and object type.
  • Compare counts against cloud consoles or existing inventories to confirm alignment.
  • Save baseline views and dashboards to monitor growth and changes over time.

Tag and Ownership Completeness

Goal: Ensure that all in‑scope assets have required metadata (owner, application, environment, cost center) for reporting and automation.

  • Use Customization (calculated attributes and enrichment rules) to normalize tags into standardized fields.
  • Create CMDB queries that identify CIs with missing or conflicting ownership and classification fields.
  • Build dashboards showing completeness by account, business unit, or team.
  • Optionally, attach workflows or tickets to route missing‑metadata items to the responsible owners.

Coverage Gaps (Monitoring, Backup, Vulnerability)

Goal: Detect resources that are not monitored, not backed up, or not included in vulnerability scanning and drive remediation.

  • Combine CMDB attributes with signals from Monitoring, Vulnerability Management, and Backup & Replication modules to identify uncovered CIs.
  • Create saved views and reports that highlight gaps by environment and owner.
  • Use Change Tracking and Alerts & Notifications to surface when coverage is removed or new uncovered assets appear.
  • Feed gap lists into automation or ticketing workflows for remediation.

Change Impact and Drift Investigation

Goal: Quickly understand “what changed” around an incident or compliance drift and assess blast radius.

  • Use Change Tracking to review recent change events and history for affected CIs and their dependencies.
  • Build queries that correlate change windows with incident or alert timelines.
  • Create simple dashboards showing high‑risk change types (for example, network or security configuration changes on critical systems).
  • Link findings back into Change Management processes and post‑incident reviews.

Application‑Centric Views

Goal: Present application owners with end‑to‑end views of their services and underlying infrastructure.

  • Use Custom Objects and Enrichment Rules to model Applications and attach infrastructure CIs.
  • Define CMDB queries and dashboards scoped to each application, showing inventory, coverage, risk, and recent changes.
  • Share these views with application teams and incorporate them into regular operational reviews.