Skip to Workflow Atlas
Event-Driven AutomationAI systemAdvanced

Suspicious Login Detection Workflow

Suspicious Login Detection Workflow is a 33-node automation blueprint connecting PostgreSQL, Gmail, Slack. Inspect its trigger, execution graph, branches, and implementation requirements.

Interactive system map

Follow the runtime. Inspect what supports it.

Solid horizontal paths show main-channel execution. Violet dependencies sit beneath the exact step they configure or empower.

33

Nodes

40

Links

1

Run groups

Connected tools

6 integrations

  • PostgreSQL
  • Gmail
  • Slack
  • IP API
  • User Agent API
  • GreyNoise API

Canvas controls

Fit wide systems, then zoom into any run group.

Suspicious Login Detection Workflow execution lanes1 run groups containing 32 workflow nodes and 39 visible links. Solid horizontal lines are main-channel runtime links. Violet dashed lines connect typed dependencies beneath the runtime step they support. Focus any node to inspect its immediate path.New /login event. trigger node, webhook. 0 incoming and 1 outgoing connections.STARTNew /login eventTRIGGERWEBHOOK0 IN / 1 OUTWhen clicking "Execute Workflow". trigger node, manualTrigger. 0 incoming and 1 outgoing connections.STARTWhen clicking "Execute Wo…TRIGGERMANUALTRIGGER0 IN / 1 OUTExample event. transform node, code. 1 incoming and 1 outgoing connections.STEP 02Example eventTRANSFORMCODE1 IN / 1 OUTExtract relevant data. transform node, set. 2 incoming and 3 outgoing connections.STEP 03Extract relevant dataTRANSFORMSET2 IN / 3 OUTGreyNoise. integration node, httpRequest. 1 incoming and 2 outgoing connections.STEP 04GreyNoiseINTEGRATIONHTTPREQUEST1 IN / 2 OUTIP API. integration node, httpRequest. 1 incoming and 1 outgoing connections.STEP 04IP APIINTEGRATIONHTTPREQUEST1 IN / 1 OUTUserParser. integration node, httpRequest. 1 incoming and 1 outgoing connections.STEP 04UserParserINTEGRATIONHTTPREQUEST1 IN / 1 OUTnoise?. decision node, if. 1 incoming and 2 outgoing connections.STEP 05noise?DECISIONIF1 IN / 2 OUTMerge. decision node, merge. 2 incoming and 1 outgoing connections.STEP 05MergeDECISIONMERGE2 IN / 1 OUTCheck classification. decision node, switch. 1 incoming and 3 outgoing connections.STEP 06Check classificationDECISIONSWITCH1 IN / 3 OUTriot?. decision node, if. 1 incoming and 1 outgoing connections.STEP 06riot?DECISIONIF1 IN / 1 OUTComplete login info. decision node, merge. 2 incoming and 1 outgoing connections.STEP 06Complete login infoDECISIONMERGE2 IN / 1 OUTCheck trust level. decision node, switch. 1 incoming and 3 outgoing connections.STEP 07Check trust levelDECISIONSWITCH1 IN / 3 OUTUnknown threat?. decision node, if. 1 incoming and 2 outgoing connections.STEP 07Unknown threat?DECISIONIF1 IN / 2 OUT🔴 Priority: HIGH. transform node, set. 2 incoming and 1 outgoing connections.STEP 08🔴 Priority: HIGHTRANSFORMSET2 IN / 1 OUT🟡 Priority: MEDIUM. transform node, set. 2 incoming and 1 outgoing connections.STEP 08🟡 Priority: MEDIUMTRANSFORMSET2 IN / 1 OUT🟢 Priority: LOW. transform node, set. 2 incoming and 1 outgoing connections.STEP 08🟢 Priority: LOWTRANSFORMSET2 IN / 1 OUTGet last 10 logins from the same user. PostgreSQL node, postgres. 1 incoming and 2 outgoing connections.STEP 08Get last 10 logins from t…POSTGRESQLPOSTGRES1 IN / 2 OUTKnown, Do Nothing. integration node, noOp. 1 incoming and 0 outgoing connections.STEP 08Known, Do NothingINTEGRATIONNOOP1 IN / 0 OUTSlack. Slack node, slack. 3 incoming and 0 outgoing connections.STEP 09SlackSLACKSLACK3 IN / 0 OUTQuery IP API1. integration node, httpRequest. 1 incoming and 1 outgoing connections.STEP 09Query IP API1INTEGRATIONHTTPREQUEST1 IN / 1 OUTParse User Agent. integration node, httpRequest. 1 incoming and 1 outgoing connections.STEP 09Parse User AgentINTEGRATIONHTTPREQUEST1 IN / 1 OUTNew location?. decision node, if. 1 incoming and 2 outgoing connections.STEP 10New location?DECISIONIF1 IN / 2 OUTNew Device/Browser?. decision node, if. 1 incoming and 2 outgoing connections.STEP 10New Device/Browser?DECISIONIF1 IN / 2 OUTNew Location. integration node, noOp. 1 incoming and 1 outgoing connections.STEP 11New LocationINTEGRATIONNOOP1 IN / 1 OUTKnown Location. integration node, noOp. 1 incoming and 0 outgoing connections.STEP 11Known LocationINTEGRATIONNOOP1 IN / 0 OUTNew Device/Browser. integration node, noOp. 1 incoming and 1 outgoing connections.STEP 11New Device/BrowserINTEGRATIONNOOP1 IN / 1 OUTOld Device/Browser. integration node, noOp. 1 incoming and 0 outgoing connections.STEP 11Old Device/BrowserINTEGRATIONNOOP1 IN / 0 OUTQuery user by ID. PostgreSQL node, postgres. 2 incoming and 1 outgoing connections.STEP 12Query user by IDPOSTGRESQLPOSTGRES2 IN / 1 OUTUser has email?. decision node, if. 1 incoming and 1 outgoing connections.STEP 13User has email?DECISIONIF1 IN / 1 OUTHTML. integration node, html. 1 incoming and 1 outgoing connections.STEP 14HTMLINTEGRATIONHTML1 IN / 1 OUTInform user. Gmail node, gmail. 1 incoming and 0 outgoing connections.OUTCOMEInform userGMAILGMAIL1 IN / 0 OUT

Signal inspector

Focus, hover, or select a step to isolate its runtime and support links.

Main-channel runtimeTyped dependencytriggeraidecisiontransformintegration
Scroll horizontally to follow every connected flow.Showing 32 of 33 connected nodesEnter or click to lock · Escape to clear

Runtime breakdown

Read the execution spine before its dependencies.

Each run group separates main-channel steps from the models, tools, retrievers, and data services that support them. Start and outcome labels apply only to runtime nodes.

01

Run Group

New /login event

39 Execution Links
  1. Start

    New /login event

    Trigger

    When clicking "Execute Workflow"

    Trigger

  2. Step 2

    Example event

    Transform

  3. Step 3

    Extract relevant data

    Transform

  4. Step 4

    GreyNoise

    Integration

    IP API

    Integration

    UserParser

    Integration

  5. Step 5

    noise?

    Decision

    Merge

    Decision

  6. Step 6

    Check classification

    Decision

    riot?

    Decision

    Complete login info

    Decision

  7. Step 7

    Check trust level

    Decision

    Unknown threat?

    Decision

  8. Step 8

    🔴 Priority: HIGH

    Transform

    🟡 Priority: MEDIUM

    Transform

    🟢 Priority: LOW

    Transform

    Get last 10 logins from the same user

    Integration

    Known, Do Nothing

    Integration

  9. Step 9

    Slack

    Integration

    Query IP API1

    Integration

    Parse User Agent

    Integration

  10. Step 10

    New location?

    Decision

    New Device/Browser?

    Decision

  11. Step 11

    New Location

    Integration

    Known Location

    Integration

    New Device/Browser

    Integration

    Old Device/Browser

    Integration

  12. Step 12

    Query user by ID

    Integration

  13. Step 13

    User has email?

    Decision

  14. Step 14

    HTML

    Integration

  15. Outcome

    Inform user

    Integration

Turn the map into a plan

Adapt this blueprint to your company.

Bring the system shape into a workspace, then define the production controls, data boundaries, owners, and delivery sequence around your context.