Product Release: Workflows
Today, depthfirst adds Workflows to our platform: an automation layer that turns security events into repeatable actions across the tools, teams, and processes your organization already uses.
.png)
Security Is a Team Sport
Modern security programs depend on signals from many places: code scanning, dependency analysis, secrets detection, PR reviews, and pentesting. The list goes on. Each signal has context, but the right response often depends on details outside the finding itself, including context on the source, escalation processes, and who owns the fix.
Without automation, teams answer those questions manually. They copy details between tools, rebuild the same routing rules in different places, and rely on humans to remember which events matter to which teams. Some of the most sophisticated teams often end up rebuilding and maintaining these automations internally for every new tool.
That works when volume is low but breaks as the surface area scales.
The Cost of Manual Handoffs
Security teams need findings to move from detection to remediation.
A vulnerability can’t sit in a backlog for two weeks because nobody kicked off a coding agent or created a ticket. This situation isn’t an edge case. It’s what happens by default when triage relies on someone remembering to do it manually.
While depthfirst already helps teams move directly from finding to auto-remediation, many organizations may still need the platform to fit into their existing tools and workflows. Engineering teams may plan in Jira or Linear. Security teams may coordinate in Slack. Approvals may happen over email and exception processes may live in internal systems.
The fix may start in depthfirst, but the surrounding process vary from company to company and team to team.
That gap creates predictable failure modes:
- High-signal events land in the same channel as everything else
- Tickets are created inconsistently or without enough context
- Internal workflows depend on brittle glue from custom integrations
The result is slower remediation and more operational drag around work that should be repeatable.
Workflows Turns Security Events Into Action
Workflows gives teams a simple way to compose security automation directly in depthfirst.
Each workflow starts with a triggering event from the depthfirst platform. From there, teams can add conditions to filter by attributes such as the severity or repository, then define the desired set of parallel or sequential actions that send the right information to the right destination.
A workflow can notify Slack when a repair is created, open a Linear issue for newly introduced high-severity vulnerabilities, create a Jira ticket for dependency regressions in a specific repository, email a team when a review completes, POST a structured payload to an internal incident system, open a direct PR, or kick off a coding agent for eligible remediation work.
Because workflows are built as graphs, teams can branch from one event into different paths. A critical issue can jump straight to an escalation path while everything else queues into a backlog. And the same finding might route to a different team depending on which repo it showed up in.
Direct Remediation, Existing Process
Workflows are not meant to force every team into a new operating model. The teams combine agentic remediation with the systems they already trust.
Some teams want depthfirst to move quickly: detect a finding, open a PR, notify the channel, and track the repair through merge. Others want a more controlled path such as creating a Jira ticket first to route to the appropriate owner before touching any code.
Workflows supports both. That enables security automation to fit the organization around it. The best workflow is the one that dependably gets the right work to the right place with the right context at the right time.
Available Now
Workflows is now available in depthfirst. If you want to turn security insights into automated triage across direct remediation and the tools your team already rely on, book a demo below.