Bring IP hazard reports into incident review
Keep the report beside the incident details, so you can assess the signal without switching tools.
Trigger
Page Properties Updated
Triggers when properties of a Notion page are updated. Customer optionally scopes with at most one of: - data_source_id: any row in this data source - page_id: this specific page - parent_page_id: any page whose immediate parent is this page With none set, fires for any property change in the workspace the integration has access to. Adding a column to a data source fires this trigger once per existing row. Customers can branch on `data.updated_properties` (array of property IDs) to filter downstream.
Action
Hazard Report API
Tool to fetch a cybersecurity hazard report for a specified ip address. use when assessing an ip's threat profile (vpn, proxy, blacklists, hosting risk).
Why this helps
Investigating an IP in a separate service adds friction when you are already juggling incident response.
- Retrieve cybersecurity hazard context for an IP.
- Keep the lookup result close to incident details.
- Help reviewers decide which records need additional investigation.
Setup
Build it in a few focused steps.
- 1Connect Notion and Big data cloud to Notis once in the portal.
- 2Create an automation in the portal, or ask Notis to retrieve a hazard report when an incident record's IP address is updated.
- 3Choose the Notion Page Properties Updated trigger for the incident records.
- 4Choose where run reports should appear, then test with one real incident record containing an IP address.
Questions about this workflow
What does the hazard report assess?
It provides a cybersecurity hazard report for a specified IP, including signals such as VPN, proxy, blacklists, and hosting risk.
Should the result be treated as a final verdict?
Use it as context for review; the workflow prompt can ask Notis to summarize the signal without making an automatic judgment.
When this happens · Trigger
Do this · Action
Supported Triggers and Actions
Notis builds workflows that link Notion to Big data cloud. A trigger fires from one place; an action lands in another.
Notion triggers
Big data cloud actions
Recurring trigger
Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.
Am I Roaming API
Tool to determine if the user is roaming based on their ip address and gps coordinates. use after obtaining device location to verify roaming status before mobile actions.
Webhook trigger
Notis starts this workflow when an external tool or custom backend sends an HTTP request.
ASN Extended Receiving From Info API
Tool to return upstream providers (receivingfrom) for a given asn. use when you need a paginated list of ases feeding traffic for the specified asn.
All Page Events
Triggers when any Notion page is created or updated across the workspace.
ASN Extended Transit To Info API
Tool to return downstream customers (transitto) for a given asn. use when you need a paginated list of ases receiving traffic from a specific asn.
Comment Created
Triggers when a new comment is created in Notion. Optional `page_id` filter scopes to comments on a specific page. When omitted, fires for any new comment in the workspace the integration has access to. Requires the 'Read comments' capability on the Notion integration. If a connection was authorized before that capability was enabled, the user must re-authorize the connection for comment events to flow.
ASN Rank List API
Tool to fetch a ranked list of autonomous systems by ipv4 announcement volumes. use after you need to compare or analyze as ranks.
New Comment
Triggers when a new comment is added to a specified Notion block or page.
BGP Active Prefixes API
Tool to retrieve ipv4 or ipv6 prefixes currently announced on bgp. use when inspecting bgp routing announcements for a given asn.
Database Created
Triggers when a new Notion database (the container) is created. A database is the post-2025-09-03 container that holds one or more data sources. This trigger fires for the container's creation event (`database.created`), distinct from `NOTION_DATASOURCE_CREATED` which fires when a new data source is added to an existing database. Most customers calling Notion's `POST /v1/databases` (the legacy API) or creating a database via the Notion UI will see this event. Adding a new data source to an existing database fires `data_source.created` instead — use `NOTION_DATASOURCE_CREATED` for that. Notion's payload puts `entity.type: "block"` (the container is a `child_database` block in the content tree) and `entity.id` is the database id.
Reverse Geocoding With Timezone API
Tool to return reverse geocoding and time zone info for given coordinates. use when you need both locality details and timezone data in one call.
Data Source Created
Triggers when a new Notion data source is created. Fires workspace-wide. The payload's `data.parent` carries the data source's tree parent (typically the teamspace) for downstream filtering. A single template-based database creation can fire multiple `data_source.created` events at once — one per data source the template instantiates.
Country by IP Address API
Tool to geolocate an ip address and retrieve country details and demographics. use when you need country-level data after obtaining the target ip address.
Data Source Schema Updated
Triggers when a Notion data source's schema is updated. Fires on column add / remove / rename. Payload includes `data.updated_properties: [{id, name, action}]` so consumers can discriminate the kind of change downstream. Optional `data_source_id` filter scopes to schema changes on a single data source. When omitted, fires for any schema change in the workspace the integration has access to. Note: adding a column also fires `page.properties_updated` once per existing row in the data source. Customers wanting a single structural-change signal should use this trigger.
Country Info API
Tool to fetch detailed country information by iso code. use when you need localized names, currencies, regions, and other metadata for a country.
Connect any two apps with Notis in the middle.
Notion and Big data cloud, or any other combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Big data cloud.