Automated Proofpoint Quarantine Triage
Every morning, WebRun signs in to Proofpoint, reviews the messages sitting in quarantine and the user-reported phishing queue, opens a Trello card for each one still awaiting an analyst decision, and updates the running decision log in Notion so nothing waits unowned.
How do I make sure quarantined emails get triaged every day?
WebRun reviews the Proofpoint quarantine and user-reported phishing queues every morning and lists every message still awaiting an analyst decision. It opens a Trello card per item with the sender, reason, and waiting time, assigns the analyst on rota, and updates the decision log in Notion.
- Every held message has a named owner by 9am
- The oldest waiting item is visible at the top of the log each day
- Read-only in Proofpoint: nothing is released, deleted, or blocked automatically
Built for security operations teams · IT admins · managed service providers · compliance teams
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
www.proofpoint.comin a real browser with your saved login - no setup, no API keys. -
1
Proofpoint - review the pending queue
WebRun opens Proofpoint to review the pending queue. - Sign in to Proofpoint and open the quarantine view
- List every message held with no analyst decision recorded, oldest first
- Open the user-reported queue and list the reports still untriaged
- For each item record the recipient, the sender domain, the subject, the reason it was held, and how long it has waited
- Read only. Never release, delete, or block a message
Done when Every pending quarantine item and user report is listed with its age and reason.
-
2
Trello - open a card per pending message
WebRun opens Trello to open a card per pending message. - Open your security triage board in Trello
- Create one card per pending message, titled with the sender domain and the hold reason
- Put the recipient, subject, and waiting time in the description
- Assign the card to the analyst on rota and set a due time for end of day
- Skip anything that already has a card so the board never doubles up
Done when Every pending item has a Trello card with an owner and a due time.
-
3
Notion - update the decision log
WebRun opens Notion to update the decision log. - Open the quarantine decision log in Notion
- Add today's pending items with their reason and assigned analyst
- Mark items resolved since the last run with the decision recorded in Proofpoint
- Add a short line at the top showing how many items are open and the age of the oldest
Done when The Notion log reflects today's queue and every decision made since yesterday.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Can it release a quarantined email?
No. WebRun only reads the queue in Proofpoint. It never releases a message to a mailbox, deletes one, blocks a sender, or changes a policy. Every decision stays with the analyst named on the Trello card.
How does it stop duplicate cards piling up?
Each run checks the board before creating anything, so a message that already has a card is skipped. Items resolved in Proofpoint since the last run are marked done in the Notion log instead.
What if the queue is empty?
No cards are created and the Notion log simply records a clear day with the count at zero, which keeps the history continuous for audit without adding noise to the board.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.