Example: Continuous weekly scan setup
User: "Set up automated weekly security scanning for production.example.com."
Tool-call blueprint
- Confirm authorization to run recurring scans in production (different from one-shot).
- Discuss blackbox-only vs greybox with service account; greybox in prod requires stable test tenant.
- Run one baseline scan now: invoke
workflows/blackbox_single_domain.mdand save output asbaseline.json. Write→ cron or GitHub Actions config. For GitHub, copyexamples/github_actions_dast.ymlinto the target repo.Write→ alerting config: where to page on new Critical/High (email, Slack webhook, PagerDuty integration key).- Return to operator:
- Baseline summary (severity counts).
- Schedule configured.
- Location of baseline artifact.
- Who will receive alerts.
Baseline artifact
results/continuous/production.example.com/
baseline.json # schemas/finding.json array
baseline.date.txt # ISO-8601 timestamp
baseline.commit.txt # git SHA of scan configDiff rules
See workflows/continuous_scanning.md → "Diff rules" table. Only new Critical/High page; new Medium is digested weekly.
Operator questions to ask up front
- Production or staging?
- Preferred alert channel and recipients?
- Weekly, nightly, or post-deploy cadence?
- Scope changes per release (new subdomains, new API versions)?
- Who owns baseline-bump reviews?