Skip to content
Notis

See the domains behind an emailed access concern

Make it easier to investigate an access concern by bringing the profile's top domains into the run report.

Trigger

New Email Received

Trigger for new emails in an AgentMail inbox

Action

Get Profile Analytics Top Domains

Tool to fetch top domains accessed within a specific profile. Use after confirming profile ID.

Why this helps

An access concern in email often sends someone searching separately for network activity context.

  • Bring a profile's top domains into the same workflow run as the incoming concern.
  • Give the reviewer context for deciding what to inspect next.
  • Avoid manually navigating from email to Control D analytics.

Setup

Build it in a few focused steps.

  • 1Connect AgentMail and Control D once in the Notis portal.
  • 2Create an automation in Automations, New Automation, and give it a clear name.
  • 3In one instruction, ask Notis to identify the Control D profile named in an access concern email and retrieve its top domains for review.
  • 4Pick AgentMail New Email Received as the trigger and choose where run reports go.
  • 5Test with one real email that identifies a profile and review the returned domain list.

Questions about this workflow

Does the workflow block any domains?

No. It retrieves top domains for review and does not change profile rules.

What profile details should the email contain?

Include the Control D profile identifier or another unambiguous profile reference that Notis can use to find the profile.

When this happens · Trigger

Do this · Action

Supported Triggers and Actions

Notis builds workflows that link Agent mail to Control d. A trigger fires from one place; an action lands in another.

Agent mail triggers

Control d actions

Recurring trigger

Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.

TriggerScheduled

Delete Device by ID

Tool to delete a Control-D device. Use when you need to remove a device by its identifier after confirming the device_id.

ActionInstant

Webhook trigger

Notis starts this workflow when an external tool or custom backend sends an HTTP request.

TriggerInstant

Delete Profile by ID

Tool to delete a profile. Use when you need to remove a profile by its ID after ensuring it is not enforced by any device.

ActionInstant

New Email Received

Trigger for new emails in an AgentMail inbox

TriggerPolling

Delete Profile Rule by Hostname

Tool to delete a specific custom rule by hostname from a profile. Use after confirming profile_id and hostname.

ActionInstant

Delete Profile Rule by Rule ID

Tool to delete a specific custom rule by its ID within a profile. Use after confirming profile_id and rule_id.

ActionInstant

Delete Profile Rule in Folder

Tool to delete a specific custom rule within a folder. Use after confirming profile_id, rule_id, and folder_id.

ActionInstant

Delete Profile Schedule

Tool to delete a specific schedule within a profile. Use after confirming profile_id and schedule_id.

ActionInstant

List Known Access IPs

Tool to list known IPs associated with the account. Use when you need to retrieve recent access IPs for device resolver queries.

ActionInstant

Get Analytics Endpoints

Tool to list analytics storage regions and their endpoints. Use after authenticating to retrieve available analytics regions.

ActionInstant

Connect any two apps with Notis in the middle.

Agent mail and Control d, or any other combination from 1,000+ integrations.

When this happens · Trigger

Do this · Action

Save your first hour today.

7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Control d.