Monday morning employee breach exposure briefing in Slack

By General Input

Every Monday, automatically find which employee accounts on your company domain turned up in data breaches and get a plain-English briefing in Slack.

Integrations

  • Have I Been Pwned
  • Slack Bot

Type

Agentic Task

Categories

  • Operations
  • Engineering

Every Monday at 8:00am, run an automated breach exposure audit for our company and post a plain-language security briefing to our security channel in Slack. Use a cron trigger for the Monday 8am schedule.

First, call Have I Been Pwned's Get Breached Email Addresses for a Domain against our verified company domain. This returns every breached employee alias on the domain together with the breaches each alias appears in. Our domain must be verified and subscribed in the Have I Been Pwned dashboard for this search to return data. If Have I Been Pwned responds with a 404 and an empty body, treat that as 'no exposure found', not as an error.

For the notable breaches in those results (the recurring ones and anything that looks serious), enrich them with Get a Single Breach to pull each breach's full details: what happened, when it was added, how many accounts it affected, and which data classes were exposed. Use Get All Data Classes to translate the raw data-class labels into readable descriptions, so the briefing can explain in plain words what kind of information leaked, for example email addresses, passwords, physical addresses, or payment details.

Group all findings by employee. Skip any employee who has no breaches; only include people who actually appear in a breach. Rank the affected employees by severity, most exposed first. Flag as high priority any breach that leaked passwords or financial or payment data, since those carry the most immediate risk.

Remember which employees and breaches you reported on each run. On every new run, compare against the previous week's record and clearly call out any accounts or breaches that are newly exposed since the last briefing, so the reader instantly sees what changed this week.

Deliver the summary to our security channel using Slack Bot's Send a Message operation (use the slackbot integration, not the plain Slack one). Write for a non-technical manager: open with a short headline giving how many employees are affected and how many are newly exposed this week, then a ranked list grouped by employee, each with a one-line plain explanation of what was exposed and a simple recommended action such as resetting a password or turning on two-factor authentication. Avoid technical jargon. If the domain comes back clean, still post a brief all-clear so the team knows the check ran.

Related prompts

Explore more prompts
A brand asset library your marketing team actually searchesTurn Mailjet email clicks into ranked HubSpot follow-upsClean out the Looker dashboards and Looks nobody opensLiveKit live operations console for room moderationWake up dormant Keap leads with a researched reasonLiveChat coverage board for planning next week's shiftsPhone routing control panel for LiveKit voice agentsLinkedIn Ads budget pacing dashboard for every client accountGive your team Looker numbers without buying more seatsPause marketing emails to escalated customers, then restore them