Documentation Index

Fetch the complete documentation index at: https://docs.safe.security/llms.txt

Use this file to discover all available pages before exploring further.

Customize the Data Model with Tag Automation

Prev Next

Overview

This article explains how to assign an impact level or network zone to a specific set of filtered assets by creating and applying tags. The purpose of this process is to ensure that critical context, such as business impact or network exposure, is consistently and automatically associated with the right assets. This helps maintain accurate risk scoring, supports better prioritization of security actions, and reduces manual effort in asset classification. By following this process, you can automate the application of tags such as High Impact Servers, Externally Facing VMs, or Low Impact Workstations, and ensure they remain correctly assigned through ongoing evaluations.

Step 1: Identify the Assets in Scope

Use filters to identify the set of assets that require a specific impact level or network zone. The filter should isolate only the devices you intend to tag.

Step 2: Create a Tag Mapped to the Desired Attribute

Follow this procedure:


Step 3: Create an Automation to Apply the Tag

Follow this procedure:


The impact levels get set based on these buckets:

  • Low <= 30

  • Medium 31 - 60

  • High 61-80

  • Critical 81-99

  • Mission critical 100

Step 4: Create a Parallel Automation to Remove the Tag if Conditions Change

To ensure accuracy over time, create a second automation that removes the tag from assets that no longer match the filter.

By combining these automations, you can maintain accurate impact level and asset zone tagging without manual intervention.