Platform

Tasks: use cases and wiring tips

Practical routines that use Tasks, and how Tasks connect to the rest of Hunto. Everything here works with the features as they exist today. Where something has to be done by hand, the page says so.

Run a weekly remediation stand-up

Goal: in 15 minutes, everyone knows what is late, who is stuck and what is due next.

  1. Open Task Analytics with the scope on Everyone and the window on 7 days. Read the tiles left to right: Overdue, Due this week, Unassigned, then Completed against created (are you keeping up?).
  2. Click Overdue to jump to the list. Group by Assignee (Group > Assignee) so each person's late items sit together. Go person by person; for each item decide one of: done (complete it), new date (edit the due date), blocked (comment and set In review or reassign), or not needed (archive).
  3. Click back and open Unassigned & severe. Assign every Critical or High item before the meeting ends. Select several and use Assign in the bulk bar.
  4. Open Going stale. Anything untouched for 14 days is either done, blocked or forgotten; ask which.
  5. Switch to the Board view and drag anything that moved during the meeting.

Wiring tips:

  • Save the filtered address in your team chat. For example the overdue list is the Tasks page with due=overdue in the address. There are no saved views, so a bookmark is your saved view.
  • Do the stand-up from My Tasks if you only want your own queue.
  • Give tasks a Team so the Team filter answers "what is the platform team behind on?".
  • Record what was decided as a comment on the task. It stays in the activity feed.

Turn the top score issues into an owner-assigned plan

Goal: the order in your security score's "what to fix first" list becomes tasks with names and dates.

The score's action plan does not create tasks by itself, so do this once when you first read the plan, and again after each score review.

  1. Open the action plan and note the top items, in order. See What to fix first.
  2. For each, open Tasks > Add task. Use the item as the title ("Enable DMARC enforcement on example.com"), write the reason in the description, choose the Assignee, a Due date, and set Severity to match how urgent the item is. Put the team in Team.
  3. For many items at once, use Import with a spreadsheet: one row per item, with Title, Description, Due Date, Priority, and, if you want to link a related record, Ref. Imported tasks are Not assigned, so select them all afterwards and use the bulk Assign and Due date actions.
  4. Where a fix relates to a finding (a subdomain, an exposed service), create the task from that finding's Tasks tab or from Assign on the gap, so the link back is kept.
  5. In Task Analytics watch Completed and On time to see the plan move.

Wiring tips:

  • Give each task a Due date. A task without a date never appears in Overdue or Due this week, so it never gets attention.
  • Use Points for effort and read the Workload table to spot overloaded owners.
  • Use subtasks for multi-step fixes ("request certificate", "deploy", "verify").
  • When the fix is done, use Ask for a check on the finding with Check it is fixed, and put the answer in a comment on the task.

Escalate a brand incident

Goal: a phishing site or fake profile is in front of a decision-maker with a deadline.

  1. Open the detection. On its Tasks tab choose New task. Title it as an action ("Approve takedown of login-example[.]com"), set Severity to Critical, choose the decision-maker as Assignee and a Due date of today or tomorrow. Because you created it from the detection, it is linked.
  2. The assignee gets a "New Task Assigned" email with a direct link, unless you assigned it to yourself.
  3. If you want extra people told when this task changes, ask an administrator to set up a notification model with a stage for the escalation contacts and triggers such as Status: In Progress and Status: Completed, then choose that model in the task's Notify field. See Task notifications.
  4. Comment with the evidence. Tick Notify only if the whole organisation should be told.
  5. If you are not sure it is real, use Ask for a check > Validate this threat on the detection first. See Asking Hunto to check a finding.
  6. If the situation changes, add a comment and update the Severity or Status; everything is in the activity feed for the post-mortem.

Wiring tips:

  • For a takedown case, incident and takedown records also list their tasks on the record's collaboration panel (for organisation administrators and security staff).
  • Filter the Tasks page by severity Critical and status not Completed as your "open escalations" view.

Produce an SLA ageing report for the board

Goal: how long does remediation work stay open, and are we within our promises?

Quick version, from the page. Open Task Analytics on 90 days. Three tiles carry the message: On time (share of dated completions that met their due date), Cycle time (median days to complete) and Overdue (what is late right now). Use your browser's print function to keep the page as a PDF; Task Analytics has no export button.

Ageing buckets, from the API. For a table of how overdue each open item is:

  1. Create an API key with tasks:read (see Tasks from an AI assistant or script).
  2. Call query with scope: "all" and a limit, and page with skip until you have every open task. Each row carries the severity, status, due date and assignee. Completed tasks are left out unless you ask for them, which is what you want here.
  3. For each open task with a due date in the past, compute days overdue as today minus the due date, then count the tasks in buckets such as 1-7, 8-14, 15-30, 31+ days, by severity. A task without a due date counts as "no date" in its own bucket, which is worth showing the board.

An AI assistant can do steps 2 and 3 for you: ask for "a table of open tasks by severity and days overdue, in 0-7, 8-14, 15-30 and 31+ day buckets".

Wiring tips:

  • Numbers describe tasks as they are now. If you need a trend for a board pack, capture the tiles on the same day each month and keep them in a slide.
  • Due dates are the promise. If you have an SLA per severity, apply it when creating the task (for example Critical: 3 days, High: 14) so On time measures what you actually promised.
  • Use Team to report by business unit.

Let an assistant open and triage tasks

Goal: an AI assistant with narrow access opens tasks for you and keeps the queue tidy.

  1. Create an API key (or sign-in connection) with the **tasks:write** scope and, if you want it to raise review requests, Monitoring access. Give the key an expiry. See Tasks from an AI assistant or script.
  2. Connect the assistant to your region's MCP address.
  3. Ask in plain language, giving it the IDs and the rules: "For each of these ten domains, create a task titled 'Renew certificate for ', severity High, assigned to alice, due 2026-10-31." Ask it to show you the plan first.
  4. For triage: "List my unassigned tasks and suggest an owner for each based on the title" is a read, and safe. "Now assign them as you suggested" is a write; review the list before it does so.
  5. To get Hunto to look at a finding: "Ask for a check on detection DDT-... : validate this threat, because the page looks like our login."

Wiring tips:

  • Remember statuses and severities are sent as digits in text form ("0" is Critical, "2" is Medium).
  • The assistant can create but not archive tasks. Archiving stays in your hands.
  • Keep one key per assistant so you can revoke it independently.
  • Assistants act as the key owner and are not limited to tasks they created; the scope is the only guard. Do not give tasks:write to an assistant you would not trust with a bulk edit.

How Tasks connect to the rest of Hunto

Area The connection
Detections and Brand Protection The threat pane has a Tasks tab that lists the tasks about that detection and creates new ones linked to it. A linked task shows a chip that opens the detection. Ask for a check sits in the same pane.
Incidents and takedowns The incident pane lists tasks linked to the incident (for organisation administrators and security staff), and the task's linked-record chip opens the incident.
Assets Each asset has a Tasks tab. The linked chip opens the asset.
Discovery and attack surface Assign on a gap or exposure creates a task about it.
Advisories Assign task and the Your tasks list on the advisory's Remediation tab.
Security score The action plan lists what to fix but does not create tasks. Turn it into tasks by hand or by import, as above.
Home A My tasks tile on the dashboard lists your recent tasks.
Notifications Assignment emails, comment notifications and notification models; see Task notifications.
Reports Task figures are not part of a scheduled report today. Use Task Analytics (print) or the API.
CLI The command-line tool has no Tasks commands.
MCP and API Read and write tasks, and request reviews. See Tasks from an AI assistant or script.