Elise's agent surfaces, triggers and confirmation policies, and the two MSP security pages
Settings > AI Assistant > Actions & Automation's Automation Controls and Action Catalog, plus Settings > Security's CyberSentry and ThreatLocker Automation pages and the Staff Roles & Permissions doorway.
What you will have
- See the two Agent Surfaces Elise can run a full tool loop on, and their on/off toggles.
- See the five groups of proactive triggers, each a simple on/off switch.
- Read the Action Catalog's confirmation-tier defaults, and why a destructive action can never be loosened.
- Turn on Security Awareness Training from Settings > Security > CyberSentry.
- Understand why CyberSentry and ThreatLocker Automation may not show up on an instance at all.
- See what the ThreatLocker Automation page looks like before ThreatLocker is connected.
- Find where staff roles and permissions are actually edited.
Why it works this way
Agent Surfaces and proactive Triggers are two different mechanisms living under one Automation Controls card. A surface runs Elise's own autonomous tool loop with a budget and a plan-then-confirm approval; a trigger only ever posts one proactive chat message and carries no tool loop or budget of its own.
The Action Catalog's confirmation tiers come from each action's own risk tier by default (read, draft, safe write, sensitive write, destructive). An admin can tighten any tier's default or loosen most of them, but a destructive action is floored at explicit no matter what an admin sets, because the runtime always re-checks the actual tier at execution time.
CyberSentry and ThreatLocker Automation both only appear for an instance provisioned with the MSP module. A different module hides both pages and their nav rows entirely, rather than showing them disabled.
ThreatLocker Automation's own fields only take effect once a ThreatLocker organization is connected and synced. Until then the page shows a single not-connected notice instead of the real controls.
Steps
Open Settings > AI Assistant > Actions & Automation and scroll to Automation Controls.
Chat - Execute Lane and Make Me A Workflow are the two Agent Surfaces on this tenant. Each shows enabled or disabled, its confirmation mode (plan-then-confirm here), and its own on/off toggle. A surface is a place Elise runs a full autonomous tool loop, not just a chat reply: Chat - Execute Lane lets execute-lane chat turns carry out actions under budget caps and job-level audit, and Make Me A Workflow drafts a workflow from a plain-language description and saves it disabled for review. Turning a surface off disables Elise's agent loop there only; the chat widget and reply assistant are separate touchpoints and keep working.
Open Settings > AI Assistant > Actions & Automation and scroll to Automation Controls. Scroll down to the proactive triggers list below the two Agent Surfaces.
7 of 7 triggers are enabled on this tenant, grouped by area: Tickets (ticket lifecycle, 1 trigger), Replies (reply-content patterns, 1 trigger), Time (timer check-ins, 2 triggers), Knowledge (KB extraction and draft hand-offs, 2 triggers) and Evaluation (ITSM evaluation surfaces, 1 trigger). Each trigger is a single on/off toggle and that is all it controls - there is no per-trigger user or role routing. Disabling one only stops that specific proactive message; the rate-limit and dedup guards that stop Elise from over-messaging still apply globally either way.
Scroll down to the proactive triggers list below the two Agent Surfaces. Open Action Catalog and read its confirmation-tier defaults.
Every Elise capability is tiered read, draft, safe write, sensitive write or destructive, and each tier has its own default confirmation level: read fires silently, draft previews, safe write asks once, sensitive write must be confirmed, and destructive must be typed out explicitly. An admin can override an individual capability to tighten its default (force a confirm on workflow.create) or loosen it (drop client.merge to optional once it is trusted), but a destructive capability such as deleting an estimate can never be loosened below explicit - the runtime always treats it as explicit regardless of what is set here.
Open Action Catalog and read its confirmation-tier defaults. Open Settings > Security > CyberSentry.
This page sets up Microsoft 365 threat triage: the confidence matrix that decides how readily an alert clears as noise, the risk posture, how alerts get ingested, the digest schedule, and the MSP's own accounts and locations. It is also where Security Awareness Training is turned on or off, at the top of the page.
Open Settings > Security > CyberSentry. Turn on Security Awareness Program and save.
On this tenant it is already on. Once on, every client gets an annual training plan authored for them, weekly micro-trainings and reminders go out, and every employee at each client is enrolled automatically without an admin adding them one by one. Clients then see a Security Training page of their own. Turned off, nothing is generated, assigned or emailed, and clients never see that page.
Turn on Security Awareness Program and save. Know why an instance might not show a CyberSentry page at all.
CyberSentry is built for the MSP module. On an instance set up for a different module, the CyberSentry page and its Security nav row stay hidden entirely - it never renders a locked or disabled version, it simply is not there. This tenant has the MSP module, which is why the page and its content show above.
Open Settings > Security > ThreatLocker Automation.
This tenant's MSP module includes the page, but no ThreatLocker organization is connected to it yet, so it shows a single not-connected notice with an Open ThreatLocker integration link instead of the real controls. Once connected and synced, this page's real fields turn on TL Auto-Approve Elevation Requests plus the checks an approval must pass: TL Max VT Detections (0 means the file must be completely clean), TL Require Valid Certificate, TL Block Script Extensions with its own blocked-extensions list, and TL Check Prior Ticket History, alongside who elevation requests escalate to and the AI prompt that judges them.
Open Settings > Security > ThreatLocker Automation. Know how to actually let ThreatLocker elevation requests auto-approve once connected.
Go to Settings > Security > ThreatLocker Automation, turn on TL Auto-Approve Elevation Requests, set the approval-criteria checks described in the previous step, then save. With auto-approve off, every elevation request still creates a ticket with the AI's recommendation on it instead of acting on its own - nothing is silently dropped either way.
Note: This tenant has no ThreatLocker organization connected, so this step is described from the page's own configuration keys rather than pictured - the previous step's screenshot is the honest state of this page today.Know why an instance might not show a ThreatLocker Automation page at all.
Same rule as CyberSentry: ThreatLocker Automation is built for the MSP module, and an instance set up for a different module hides the page and its nav row completely rather than showing it locked.
Open Settings > Security > Staff Roles & Permissions to find where roles are actually edited.
This page is a doorway, not an editor: roles and their permissions are managed with staff in the Team area instead, since they govern who on the whole team can do what. Open Team, then Staff Roles. Pick a role to edit or create a new one, set its permission groups and access tier - view, edit or admin - per nav area, then assign staff to that role from their own user record.
Open Settings > Security > Staff Roles & Permissions to find where roles are actually edited.
If it did not work
- If Security Awareness Program will not save, confirm your account has edit access to Settings - a view-only account can read the page but not change it.
- If CyberSentry or ThreatLocker Automation are missing from Security entirely, the instance is not on the MSP module - check with whoever set the instance up.
- If ThreatLocker Automation shows the not-connected notice, connect a ThreatLocker organization from the Open ThreatLocker integration link first; the automation fields only take effect once one is synced.
Questions this page answers
What is an Agent Surface?
An Agent Surface is a place where Elise runs a full autonomous tool loop, not just a chat reply. Today there are two: Make Me A Workflow (drafts a workflow from a plain-language description, saved disabled for your review) and the Chat Execute lane (chat turns that can carry out actions with plan-then-confirm approval and budget caps). Each surface has an on/off toggle, plus seed-time hard caps and a default budget you can view but not edit. Turning a surface off disables Elise's agent loop there; it does not remove the chat widget or reply assistant, which are separate touchpoints. Use it to roll agent behavior out gradually.
What are Elise Triggers?
Pre-built proactive behaviors where Elise speaks first, grouped by area (ticket lifecycle, replies, time, knowledge, and evaluation). Each trigger is a simple on/off toggle, and that is all it controls, there is no per-trigger user or role routing here, only whether it fires. Triggers are enabled by default; flip one off to silence it without removing the underlying behavior, so you can turn it back on later. Use it during rollout to introduce proactive Elise gradually.
What are Confirmation Policies?
For each Elise capability (for example replying to a ticket, or deploying a workflow), pick how aggressively the portal makes you confirm the action: none (silent), preview (show what will happen), optional (ask once), required (must click confirm), or explicit (must type a confirmation). Destructive capabilities such as deleting a workflow are floored to explicit, any lower setting is ignored and rejected.
What is the CyberSentry settings page for?
This page sets up Microsoft 365 threat triage. It sets how alerts get scored, your risk levels, how alerts come in, and your digest schedule. It also turns Security Awareness Training on or off.
How do I turn on Security Awareness Training?
Go to Settings → Security → CyberSentry. Turn on Security Awareness Program. Then save. Once it is on, each client gets an annual training plan. Weekly micro-trainings and reminders go out. Every employee at each client gets enrolled on their own. Clients then see a Security Training page. When it's off, nothing gets sent.
Why don't I see a CyberSentry page at all?
CyberSentry is a feature for the MSP module. On an instance set up for a different module, the page and its nav row stay hidden. It never shows and fails.
What is the ThreatLocker Automation page for?
This page sets up AI handling of ThreatLocker elevation requests. It picks whether they auto-approve, the checks an approval must pass, who gets escalated requests, and the AI prompt that judges them.
How do I let ThreatLocker elevation requests auto-approve?
Go to Settings → Security → ThreatLocker Automation. Turn on TL Auto-Approve Elevation Requests. Set your checks: TL Max VT Detections (0 means the file must be clean), TL Require Valid Certificate, TL Block Script Extensions with its blocked list, and TL Check Prior Ticket History. Then save. With auto-approve off, each request just creates a ticket with a note instead.
Why don't I see a ThreatLocker Automation page at all?
ThreatLocker Automation is a feature for the MSP module. CyberSentry is too. A different module hides this page and its nav row.
How do I create or edit a permission group?
Click "Open Staff Roles" on this page, or go straight to Team → Staff Roles. Pick a role to edit, or create a new one. Set its permission groups and access tier, view, edit, or admin, per nav area. Then assign staff to it from their user record.
Was this helpful?