In Flashduty On-call
You can obtain an integration push URL in either of the following ways.
Use a dedicated integration
- In the Flashduty console, select Channel and open a channel
- Select Settings → Integrations → Dedicated integrations, then click Add an integration
- Select SecurityScorecard and click Save
- Open the generated integration card and copy the Push URL
Use a shared integration
- In the Flashduty console, go to Integration Center → Alert events
- Select SecurityScorecard and enter an integration name
- Configure the default route and choose a channel. You can add more rules under Routes after the integration is created
- Click Save and copy the generated Push URL
Configure SecurityScorecard
Rule Builder requires a paid SecurityScorecard plan, and each user can create up to 25 rules.
1
Create a rule
- Sign in to the SecurityScorecard platform, go to Automation → Rule Builder, and click Create Rule (in the older interface: avatar in the upper-right corner → My Settings → Rules)
- Select Events so the rule runs when an event occurs
- Enter a rule name, for example
Flashduty: vendor score drop - Choose the Scorecards the rule monitors: your organization’s Scorecard, a single Scorecard, or a portfolio
- Choose the triggering event, for example the overall score dropping below a threshold, a new issue of a given severity, or a reported breach
2
Add the Send a web request action
- Select Send a web request as the action
- Paste the full Flashduty push URL, including the
integration_keyparameter, as the URL. SecurityScorecard only sends to HTTPS URLs and does not support custom headers, sointegration_keymust stay in the URL - Review the rule and click Save
trigger, execution_id, scorecard_id and domain.3
Verify
Rule Builder has no button that sends a test request. SecurityScorecard evaluates Scorecard events once a day, and the rule runs after an event meets its conditions. To verify right away, simulate an event with the SecurityScorecard API Simulate Actions (include the rule’s
rule_id in the request) and check that the alert arrives in Flashduty. The simulation creates a real alert; close it by hand afterwards.Alert Key
Flashduty computes the Alert Key from
execution_id, scorecard_id and trigger.type. The SecurityScorecard article Rule Builder: Webhooks defines execution_id as the unique identifier of one rule execution, and it stays the same when a failed request is retried. A retry of the same execution therefore merges into the same alert, and every other rule execution becomes its own alert.
When a request has no execution_id, Flashduty generates a random Alert Key and every request becomes a new alert. A request without trigger.type returns a parameter error.
Severity
Field mapping
The
retries and webhooks (responses of earlier webhooks in the rule) fields are not copied to the alert. SecurityScorecard marks this request body as beta; if the structure of the issue or breach details changes, Flashduty ignores the parts it cannot parse and still creates the alert.
Alerts do not recover
Score changes, new issues and breaches are one-shot events, and SecurityScorecard sends no recovery notification. Turn on auto-resolve timeout in the channel that receives this integration. 24 hours is a reasonable start; adjust it to how long your team takes to handle security rating events.
Troubleshooting
The rule ran but no alert arrives
The rule ran but no alert arrives
Check that the rule action is Send a web request and the URL is the full push URL starting with
https://. SecurityScorecard evaluates events once a day, so a rule does not run at the moment a Scorecard changes. A score rule fires only when the change is greater than the configured value, not equal to it.You receive an [Action Required] Failed Webhook Request email
You receive an [Action Required] Failed Webhook Request email
SecurityScorecard retries on network errors and 5xx responses and emails the rule owner when the request still fails after 36 hours. Check that the push URL is complete and that the integration has not been deleted.
Flashduty returns a parameter error
Flashduty returns a parameter error
The request body must be JSON of at most 1 MiB with a non-empty
trigger.type, and the integration_key in the push URL must belong to a SecurityScorecard integration.