Keep secret exposure response guidance at hand
A detected secret needs prompt, consistent handling. Keep the bot's response guidance aligned with your approved steps.
Trigger
New Secret Scanning Alert Detected
Triggers when a new secret scanning alert is detected in a GitHub repository. Monitors open secret scanning alerts and fires an event for each newly detected alert. Supports filtering by secret type (e.g., personal access tokens, AWS keys) and by token validity status (active, inactive, unknown). The payload includes the alert number, secret type, validity status, resolution state, timestamps, URLs, and flags for push protection bypass, public exposure, and multi-repo detection.
Action
Update Bot
Tool to update specific fields for a bot (e.g., name, description, settings). use after confirming valid team and bot ids.
Why this helps
In a security incident, people can lose time searching for the right response instructions and expose sensitive details in the process.
- Make approved response steps easier to find.
- Reduce time spent locating incident guidance.
- Avoid placing the secret value in the bot description.
Setup
Build it in a few focused steps.
- 1Connect GitHub and Docsbot ai once in the Notis portal.
- 2Create an automation and describe how to update the bot with approved steps without including secret values.
- 3Pick the New Secret Scanning Alert Detected trigger for the repository.
- 4Choose where run reports go, then test with one real alert or a safe representative example.
Questions about this workflow
Will the secret value be added to Docsbot?
The instruction should explicitly exclude secret values. Use the alert context only to choose approved response guidance.
Does this remediate or close the alert?
No. The available Docsbot action updates a bot field; it does not change the GitHub alert or rotate a credential.
When this happens · Trigger
Do this · Action
Supported Triggers and Actions
Notis builds workflows that link GitHub to Docsbot ai. A trigger fires from one place; an action lands in another.
GitHub triggers
Docsbot ai actions
Recurring trigger
Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.
Create Bot
Tool to create a new bot within a team. use when you have a valid team id and want to provision a new bot.
Webhook trigger
Notis starts this workflow when an external tool or custom backend sends an HTTP request.
Delete Bot
Tool to delete a specific bot by its id. use after confirming the bot id is correct to permanently remove a bot from the system.
New Workflow Artifact Created
Triggers when a new workflow artifact is created in a GitHub repository. Monitors for newly created GitHub Actions workflow artifacts. Optionally filters by artifact name to restrict monitoring to specific artifacts.
Generate Conversation Ticket
Tool to generate a structured support ticket from a chat agent conversation. use when you need to convert an existing conversation into a ready-to-submit helpdesk ticket.
Branch Changed
Triggers when a GitHub branch changes. Monitors a specific branch for: - New commits pushed (head commit SHA changes) - Protection status toggled (branch becomes protected or unprotected) - Protection settings changed, including: required status checks and their enforcement level, admin enforcement, required pull request reviews (dismiss stale reviews, code owner reviews, approving review count, last push approval), required linear history, force push allowance, deletion allowance, conversation resolution, branch locking, and fork syncing.
Get Bot Details
Tool to fetch details of a specific bot by id within a team. use after confirming valid team and bot ids.
New Branch Created
Triggers when a new branch is created in a GitHub repository. Detects newly created branches. Deleted branches do not fire events.
Get Team Details
Tool to fetch details of a specific team by its id. use when you need full team info including members and settings after confirming the team id.
Check Run Status / Conclusion Changed
Triggers when a specific GitHub check run changes its status or conclusion. Monitors a single check run for changes to: status (queued, in_progress, completed, etc.), conclusion (success, failure, neutral, cancelled, skipped, timed_out, action_required), started_at, and completed_at.
List Team Bots
Tool to list all bots for a given team. use after confirming the team id to retrieve all associated bots for that team.
Check Suite Status / Conclusion Changed
Triggers when a GitHub check suite changes its status or conclusion for a given ref. Monitors all check suites associated with a git reference (branch, tag, or commit SHA) for changes to status (queued, in_progress, completed, etc.) and conclusion (success, failure, neutral, cancelled, skipped, timed_out, action_required, startup_failure, stale). Optionally filters by GitHub App ID.
List Questions
Tool to list all questions asked of a specific bot. use after confirming the bot's identifier. example: "list questions for bot abc123 with status 'unanswered'."
New Code Scanning Alert Created
Triggers when a new code scanning alert is created in a repository. Fires an event for each newly created code scanning alert detected in the configured repository. Alerts can be filtered by Git reference, scanning tool, state, and severity. The payload includes the alert number, rule details, tool information, state, severity, and the location of the most recent instance.
List Bot Sources
Tool to list all sources for a specific bot. use when you need to retrieve paginated source lists after confirming the bot's identifier.
Connect any two apps with Notis in the middle.
GitHub and Docsbot ai, or any other combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Docsbot ai.