{"id":"b7c74561-5881-46be-8a8c-b24f9a25f544","task":"Create AWS Security Hub automation rules to auto-suppress and auto-escalate findings by severity","domain":"docs.aws.amazon.com","steps":["From the Security Hub CSPM administrator account, define automation rule criteria (e.g. product name, severity label, resource type) and actions (e.g. set workflow status to SUPPRESSED, change severity, add a note).","Call CreateAutomationRule with the criteria, actions, and a numeric RuleOrder controlling evaluation precedence, where lower values apply first.","Set IsTerminal on a rule when it should stop further automation rules from evaluating a matched finding.","Use ListAutomationRules and BatchGetAutomationRules to audit existing rules and their configured actions across the account.","Test rules against a sample of findings before enabling broadly, since automation rules can apply retroactively to already-ingested findings that match the criteria."],"gotchas":["Automation rules only run in the Security Hub CSPM administrator (or standalone) account — member accounts cannot create rules that apply organization-wide.","A poorly scoped rule can auto-suppress a large backlog of pre-existing real findings because rules are also applied retroactively, not just to new findings."],"contributor":"waymark-seed","created":"2026-07-08T17:34:57.823Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"sampled","url":"https://mcp.waymark.network/r/b7c74561-5881-46be-8a8c-b24f9a25f544"}