Rootly Workflows — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Rootly Workflows (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Rootly workflows automate repetitive incident response tasks. Each workflow consists of a trigger (what starts it), conditions (when it should run), and actions (what it does). Workflows can create Slack channels, page on-call, update status pages, create Jira tickets, send notifications, and more -- all automatically when incidents match specific criteria.
| Trigger | Description |
|---|---|
incident_created | Fires when a new incident is declared |
incident_updated | Fires when incident fields change |
severity_changed | Fires when severity is escalated or de-escalated |
status_changed | Fires when status transitions (started -> mitigated -> resolved) |
role_assigned | Fires when a role is assigned |
postmortem_created | Fires when a postmortem is created |
action_item_created | Fires when an action item is added |
alert_received | Fires when an alert is received from monitoring |
| Action | Description |
|---|---|
create_slack_channel | Create a dedicated incident Slack channel |
invite_to_slack_channel | Add responders to the incident channel |
send_slack_message | Post a message to a channel |
page_on_call | Page the on-call responder via PagerDuty/Opsgenie |
create_jira_ticket | Create a tracking ticket in Jira |
update_status_page | Post to Statuspage or similar |
send_email | Send email notification |
create_zoom_meeting | Start a video bridge for the incident |
run_webhook | Call a custom webhook |
assign_role | Auto-assign an incident role |
update_incident | Modify incident fields |
| Condition | Description |
|---|---|
severity_is | Match specific severity level |
severity_gte | Severity is at or above threshold |
service_is | Match specific service |
environment_is | Match specific environment |
team_is | Match specific team |
label_contains | Match incident labels |
rootly_list_workflowsParameters:
enabled -- Filter by enabled/disabled statusExample response:
{
"data": [
{
"id": "wf-001",
"type": "workflows",
"attributes": {
"name": "SEV0 Auto-Response",
"description": "Create war room and page on-call for critical incidents",
"enabled": true,
"trigger": "incident_created",
"conditions": [
{ "field": "severity", "operator": "eq", "value": "sev0" }
],
"actions": [
{ "type": "create_slack_channel" },
{ "type": "page_on_call", "target": "platform-team" },
{ "type": "create_zoom_meeting" }
],
"last_triggered_at": "2026-03-25T08:00:00Z",
"trigger_count": 12
}
}
]
}rootly_get_workflowParameters:
workflow_id -- The workflow IDrootly_create_workflowParameters:
name -- Workflow name (required)description -- What the workflow doestrigger -- Trigger event typeconditions -- Array of condition objectsactions -- Array of action objectsenabled -- Whether to enable immediatelyrootly_update_workflowParameters:
workflow_id -- The workflow IDname -- Updated nameconditions -- Updated conditionsactions -- Updated actionsrootly_enable_workflow
rootly_disable_workflowParameters:
workflow_id -- The workflow IDrootly_list_workflows to get all workflowsincident_createdCause: Invalid workflow ID or workflow deleted Solution: List workflows to verify the correct ID
Cause: Trigger type doesn't match valid options Solution: Use one of the documented trigger types
Cause: External integration (Slack, Jira, PagerDuty) returned an error Solution: Check integration credentials and permissions; review workflow logs
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.