Skip to main content
Hiro can propose and execute remediation actions across your connected integrations. All high-impact actions require explicit approval, ensuring you maintain full control over your security response.

How Remediation Works

When Hiro identifies a threat, it:
  1. Analyzes the situation — Correlates evidence from multiple sources
  2. Determines appropriate actions — Based on threat type and severity
  3. Calculates confidence — How certain it is the action is warranted
  4. Proposes the action — Presents it for your review
  5. Awaits approval — Executes only after you confirm
  6. Logs the result — Maintains a complete audit trail
Hiro will never execute a destructive action without explicit approval. You always see what will happen before it happens.

Approval Levels

Hiro uses a tiered approval system:

No Approval Required

Read-only operations that don’t modify state:
  • Querying logs and events
  • Listing users, groups, and resources
  • Reading configuration
  • Fetching audit trails

Approval Required

Actions that modify state or could impact users require explicit approval before execution. Both Admin and Member roles can approve actions in Hiro.

Available Actions by Integration

Okta

Example proposal:

AWS

CrowdStrike

GitHub

Google Workspace

Slack

Confidence Scores

Hiro provides confidence scores for proposed actions:
Confidence scores are based on the quantity and quality of evidence, consistency across sources, and historical patterns.

The Approval Interface

When Hiro proposes an action, you’ll see:

Action Details

  • What: The specific action to be taken
  • Target: The affected user, resource, or system
  • Why: Reason for the recommendation
  • Evidence: Supporting findings with timestamps
  • Confidence: How certain Hiro is
  • Impact: What will happen when executed

Available Responses

Manual Instructions

When an integration doesn’t support API-based remediation, Hiro provides manual instructions:

Audit Trail

Every action (proposed, approved, rejected, executed) is logged:
Access the full audit trail in Settings > Audit Log or export from any Fight Mode session.

Rollback and Recovery

Some actions support rollback:
Destructive actions (delete, terminate) cannot be rolled back. Hiro will warn you before proposing irreversible actions.

Best Practices

Review Evidence Before Approving

Even with high confidence, take a moment to understand why Hiro is recommending an action.

Start with Reversible Actions

When possible, prefer suspending over deleting, containing over terminating.

Document Your Decisions

Use the notes feature to record why you approved or rejected an action.

Verify After Execution

Hiro verifies actions automatically, but you can also confirm manually.

Next Steps

Fight Mode

Use remediation in continuous threat hunting.

Integrations

Connect more systems for broader remediation coverage.