Always-On Coverage
Always-On Coverage
Agents and skills that deliver Always-On Coverage.
Everything tagged with this outcome.
Acronis Cyber Protect
Handle Acronis Cyber Protect alerts: separate a backup failure from an Active Protection anti-ransomware detection and run the matching triage discipline.
After-Hours Coverage Handoff
Build the end-of-business handoff to on-call or after-hours coverage — open urgent work, expected client callbacks, and site notes the night crew needs.
After-Hours Voicemail Digest
Build a morning digest of overnight voicemails and after-hours calls — urgent items first, callbacks owed with deadlines, and which tickets were created.
APC UPS Alerts
Work APC UPS alerts: on-battery events, low runtime, self-test failure, or replace-battery indicators. Separate utility issues from UPS hardware faults.
AV/EDR Agent Offline Alert
Triage an AV/EDR agent-offline alert — decide if the device is off or up with a dead agent, quantify unprotected time, and route on the protection gap.
Axcient Backup Alerts
Triage Axcient x360Recover alerts: distinguish appliance vs Direct-to-Cloud failure families, verify retention, and state the last recoverable point.
Backup Missed vs Failed Alert
Distinguish a backup that never ran (missed) from one that ran and errored (failed) — two different routes — and always state exposure via last-known-good.
Certificate Expiry Alert
Triage a certificate expiry alert — tier urgency by days remaining, identify what the cert secures and who owns renewal, and route into renewal work.
Connector Degradation
Base skill defining how a skill behaves when an integration it wants isn't connected — do the job with what's native, name the gap, never fake the missing source.
Cove Data Protection Alerts
Work N-able Cove Data Protection backup tickets: classify the failure family, verify recoverability, and keep archive and retention sessions straight.
Dark Web Alert Lifecycle
Work dark-web and credential-exposure alerts: age stale exposures, document closure notes, and notify affected users with rotation guidance.
Datto BCDR Verification
Work Datto BCDR alerts: screenshot-verification failures, local vs cloud sync lag, virtualization tests. Separate backup-ran from backup-boots and verify.
Disk Space Alert
Triage a low-disk-space alert from any monitor — separate threshold noise from real pressure, read growth rate from history, rank consumer hypotheses.
Domain Expiry Alert Lifecycle
Handle registrar expiry and renewal notices safely: verify the sender is the real registrar, confirm the expiry date, and route to the renewal owner.
Email Header Analysis
Parse raw email headers for a spoofing verdict: analyze authentication results, the received path, and spoof indicators with explicit confidence.
High CPU/Memory Alert
Triage a CPU or memory threshold alert — separate a transient spike from sustained pressure via history, and route servers versus workstations differently.
Kaseya Dark Web Monitoring
Work Kaseya Dark Web ID compromise alerts: parse alert anatomy (source, date, data classes) and run the age-and-notify lifecycle with a no-crack policy.
M365 SaaS Backup
Work M365 and Google Workspace SaaS backup tickets: point-in-time restores, license and seat reconciliation, and job failures with authorization checks.
M365 Tenant Health Report
Produce an advisory digest of Microsoft 365 Service Health incidents and Message Center posts for a client tenant as a plain-language brief.
MDR Client Onboarding
Onboard a client to a new MDR or SOC service: scope assets, wire alert routing into the desk, record escalation contacts, and set noise expectations.
Notion Client Runbook Database
Create and maintain a Notion client-runbooks database, one entry per client per system, updating entries when tickets reveal environment changes.
Patch Failure Alert
Triage a patch-failure alert — separate a one-off from a repeat offender, detect reboot-pending as the usual culprit, correlate against the patch window.
Quarantine Release Request
Handle a quarantined email release request: verify the requester, assess why the filter caught it, and recommend release or refusal with reasoning.
RAID Degradation Alert
Triage a RAID degraded or failed-member alert with zero-margin urgency — one failure from data loss — and enforce the verify-backups-BEFORE-rebuild rule.
SD-WAN / Multi-Circuit Monitoring
Review a multi-circuit or SD-WAN site — confirm each circuit is up, failover works, and open the right ISP escalation when a link is down or degraded.
Supporting Logistics and Trucking Clients
Trucking and 3PL pack covering McLeod and Trimble TMS, Samsara and Motive ELDs, DOT/HOS compliance, EDI, and 24/7 dispatch operations.
Supporting Medical Clinics
Medical clinic pack for eClinicalWorks and Athenahealth EMR, e-prescribing, lab interfaces, telehealth, and HIPAA PHI ticket hygiene.
Supporting Senior Living Communities
Senior living and skilled-nursing pack covering PointClickCare and MatrixCare EHR/eMAR, nurse-call systems, resident wifi split, and HIPAA.
Synology NAS Alerts
Work Synology NAS alerts: degraded RAID or storage pool, disk-health warnings, full volumes, DSM updates. Treat a degraded array as near data loss.
Typosquat Domain Alert
Work a typosquat or lookalike domain alert impersonating a client: gather registrar and DNS facts without visiting, gauge capability, draft a warning.
Veeam Job Failures
Diagnose Veeam backup job failures: classify by taxonomy (VSS, credentials, repository, network), apply retry discipline, and state the last restore point.
Voicemail to Ticket
Convert a voicemail transcription into a ticket with a callback commitment — urgency read from what the caller actually said, not from tone guesses.
Zapier PagerDuty On-Call
Page the on-call engineer for a P1 via PagerDuty, tell the requester who was paged, and mirror the ack/resolve loop back to the ticket.
Was this page helpful?
⌘I