Skip to main content
{ Vulnerability Management } Featured agent

Wiz Issue Triage

Writes an evidence-based triage judgment for each open Wiz issue and rejects the ones cloud checks prove are false positives.

What this agent does

This agent triages open High and Critical Wiz issues. It reads each issue's evidence from Wiz, and it can run read-only checks against the affected cloud account. It writes a judgment for each issue: what an attacker could actually reach, how to verify it, when it is not worth fixing now, and the recommended fix. It rejects an issue in Wiz only when its checks prove the detection wrong.

The challenge

Wiz raises more High and Critical issues than a cloud security team can investigate. Each one arrives as a detection, and some of them depend on a classifier guess or on a fact Wiz cannot see, such as a bucket that is public on purpose or an external account the organization owns. Triagers spend their time rebuilding the context for each issue before they can decide anything.

The solution

The agent does the investigation a triager would do and writes it up so the triager can agree or disagree quickly. It keeps what Wiz observed separate from what Wiz inferred, and it checks the most common alternative explanation for each kind of issue. It rejects only proven false positives, with the evidence in the rejection note. Provides a ready-to-act judgment on every issue it reviews.

Workflow

  1. 01

    Pick issues

    Take a bounded number of open High and Critical issues from the largest issue group that still has untriaged issues.

  2. 02

    Gather evidence

    Read each issue's resource, attack paths, findings, and suggested owners from Wiz.

  3. 03

    Verify

    Run read-only checks against the cloud account to test the detection and its alternative explanation.

  4. 04

    Judge and act

    Write the judgment for each issue, and reject it in Wiz only when the checks prove it is a false positive.

Agent template

# Wiz Issue Triage

## Measurable outcomes

Every issue the agent reviews has a triage judgment a triager can act on. Every false positive it proves is rejected in Wiz with the evidence in the note. Track how many issues were triaged and rejected, and how many open questions remain, on each run.

## Procedure

Each run, take a bounded number of open High and Critical Wiz issues in the projects I set. Work through one issue group at a time, starting with the group that has the most issues, and skip issues already triaged. Let me choose which kinds of issues it covers: external exposure, sensitive data, identity and permissions, exploitable vulnerabilities, misconfigurations, secrets, and threat detections. For each issue, read the resource, its attack paths, its findings, and its suggested owners from Wiz. Treat every detection as a claim, not a fact. Write "Wiz classified these objects as containing PII", not "the bucket holds PII". Check the common alternative explanation for each kind of issue, such as a synthetic dataset that looks like PII, a site that is public on purpose, an external account the organization owns, or a vulnerable package on a code path that never runs. Never soften a finding the evidence supports. For each issue, write what an attacker could actually reach, two or three verification checks with the real resource names, the conditions that would make it not worth fixing now, the remediation options with one recommended, and the questions the evidence cannot answer. When I give it read-only access to the cloud account, run those checks. For a vulnerability on a workload, check the workload's source code to see whether the vulnerable code path runs. The source code provider and repository for each workload are set when the agent is built. Without them, list the code path as an open question. Test public access without credentials, and never print sensitive data. Reject an issue in Wiz only when the checks prove the detection is wrong, and put the evidence in the rejection note. Never reject an issue the team might accept as a risk, and never reject a threat detection. Without cloud access, write the judgment and reject nothing. Start in a report-only mode so I can review its judgments before it rejects anything.

## Requirements

It needs Wiz API access to read issues and their evidence and to reject issues, optional read-only access to the cloud accounts in scope, and optional read access to the workloads' repositories in GitHub, GitLab, or Bitbucket, and nothing more. It never changes cloud resources, and it changes nothing in Wiz except the rejections.