Bring company details into secret alert review
A detected secret deserves prompt attention. Include relevant Affinity company details when the alert names a company you track.
Trigger
New Secret Scanning Alert Detected
Triggers when a new secret scanning alert is detected in a GitHub repository. Monitors open secret scanning alerts and fires an event for each newly detected alert. Supports filtering by secret type (e.g., personal access tokens, AWS keys) and by token validity status (active, inactive, unknown). The payload includes the alert number, secret type, validity status, resolution state, timestamps, URLs, and flags for push protection bypass, public exposure, and multi-repo detection.
Action
Get a single company
Retrieve basic company info and specific field data by using `fieldids` or `fieldtypes` parameters. multiple fields can be queried. no field data if parameters aren't specified. requires "export all organizations directory" permission.
Why this helps
Responding to a secret exposure takes focus, and relationship context can be hard to find while coordinating next steps.
- Review available company details alongside the alert.
- Keep security response context in the run report.
- Avoid unsupported matches by having Notis flag missing identifying information.
Setup
Build it in a few focused steps.
- 1Connect GitHub and Affinity once in the Notis portal.
- 2Create an automation in Automations, New Automation, and give it a name.
- 3In one instruction, ask Notis to retrieve a single Affinity company record only when the alert gives a reliable company identity.
- 4Pick the New Secret Scanning Alert Detected GitHub trigger.
- 5Choose a report channel, then test with one real alert.
Questions about this workflow
Will Affinity tell me whether a secret was used by a company?
No. This action retrieves company details. Any connection between the alert and a company must be supported by alert data or context you provide.
Can the workflow revoke or rotate the secret?
No. The available Affinity action only retrieves a company record.
When this happens · Trigger
Do this · Action
Supported Triggers and Actions
Notis builds workflows that link GitHub to Affinity. A trigger fires from one place; an action lands in another.
GitHub triggers
Affinity actions
Recurring trigger
Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.
Get a company s list entries
Summarize company data across all lists, including list-specific fields and metadata like creation date and author. access requires "export data from lists" permission.
Webhook trigger
Notis starts this workflow when an external tool or custom backend sends an HTTP request.
Get a company s lists
Returns metadata for all the lists on which the given company appears.
New Workflow Artifact Created
Triggers when a new workflow artifact is created in a GitHub repository. Monitors for newly created GitHub Actions workflow artifacts. Optionally filters by artifact name to restrict monitoring to specific artifacts.
Get all companies
Affinity api allows paginated access to company info and custom fields. use `fieldids` or `fieldtypes` to specify data in a request. retrieve field ids/types via get `/v2/companies/fields`. export permission needed.
Branch Changed
Triggers when a GitHub branch changes. Monitors a specific branch for: - New commits pushed (head commit SHA changes) - Protection status toggled (branch becomes protected or unprotected) - Protection settings changed, including: required status checks and their enforcement level, admin enforcement, required pull request reviews (dismiss stale reviews, code owner reviews, approving review count, last push approval), required linear history, force push allowance, deletion allowance, conversation resolution, branch locking, and fork syncing.
Get all list entries on a list
Access and export essential data and metadata for companies, persons, or opportunities from a list, specifying data via `fieldids` or `fieldtypes`. "export data from lists" permission is necessary.
New Branch Created
Triggers when a new branch is created in a GitHub repository. Detects newly created branches. Deleted branches do not fire events.
Get all list entries on a saved view
Use the endpoint to access rows in a saved view with specific filters and selected fields from a web app. it doesn't maintain sort order, supports only sheet-type views, and requires export permissions.
Check Run Status / Conclusion Changed
Triggers when a specific GitHub check run changes its status or conclusion. Monitors a single check run for changes to: status (queued, in_progress, completed, etc.), conclusion (success, failure, neutral, cancelled, skipped, timed_out, action_required), started_at, and completed_at.
Get all opportunities
Pagination through opportunities in affinity yields basic info but excludes field data. for field data, use specified get endpoints. "export data from lists" permission needed.
Check Suite Status / Conclusion Changed
Triggers when a GitHub check suite changes its status or conclusion for a given ref. Monitors all check suites associated with a git reference (branch, tag, or commit SHA) for changes to status (queued, in_progress, completed, etc.) and conclusion (success, failure, neutral, cancelled, skipped, timed_out, action_required, startup_failure, stale). Optionally filters by GitHub App ID.
Get all persons
The affinity api offers paginated access to person data using `fieldids` or `fieldtypes`. bulk extraction needs special permissions and supports multiple parameters.
New Code Scanning Alert Created
Triggers when a new code scanning alert is created in a repository. Fires an event for each newly created code scanning alert detected in the configured repository. Alerts can be filtered by Git reference, scanning tool, state, and severity. The payload includes the alert number, rule details, tool information, state, severity, and the location of the most recent instance.
Get a person s list entries
Summary: browse rows for a person in all lists, showing field data and entry metadata like creation time and author. requires "export data from lists" permission.
Connect any two apps with Notis in the middle.
GitHub and Affinity, or any other combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Affinity.