Skip to content

Intake (Machine Reports)

Intake groups receive machine-generated reports — vulnerability scans, billing summaries, DMARC reports, compliance feeds, and vendor status updates. They’re designed for archiving and periodic human review, not real-time action.

prv-{owner}-intake-{source}[-{topic}]@{domain}
FlavorSenderVolumeModeration
Vendor feedSaaS/vendor systemScheduled (daily/weekly)Allowlisted senders
Audit logInternal systemsContinuous/batchedAllowlisted senders
ComplianceScanners, GRC toolsPeriodicAllowlisted + moderated
EmailPurpose
prv-sec-intake-wks-dlpWorkspace DLP scan results
prv-sec-intake-dmarcDMARC aggregate reports
prv-plt-intake-aws-billingAWS billing/cost reports
prv-plt-intake-wks-adminWorkspace admin notifications
prv-sec-intake-op-events1Password audit events
prv-ops-intake-vendor-statusVendor status page updates
  • Who can post: Anyone + MODERATE_ALL_MESSAGES + allowlisted senders
  • Members: Minimal (often archive-only with no human subscribers)
  • External posting: ON (senders are external systems)
  • External members: ON (for sender allowlisting, not actual membership)
  • Archive: ON (always — intake archives are audit records)
  • Security label: OFF
  • Subject prefix: Recommended (e.g., [DLP], [DMARC], [BILLING])

Intake groups are often the first hop in a processing chain:

Vendor system → Intake (archive + classify)
Digest script → Mail (humans review weekly)

For urgent items that come through intake but need escalation:

Intake → Filter/classifier → Alerts (on-call)
  1. Identify the source system and expected sender addresses/domains.
  2. Set email/name/description.
  3. Labels: Mailing=ON, Security=OFF.
  4. Set MODERATE_ALL_MESSAGES + seed allowlisted senders.
  5. Add minimum 2 owners (PLT + relevant team).
  6. Add subject prefix.
  • Monitor: blocked/quarantined messages (new sender not yet allowlisted).
  • Quarterly: review allowlist, add/remove senders as vendor landscape changes.
  • Archive maintenance: ensure retention policy matches compliance needs.
  • Disable external posting. Export archive per policy. Delete after hold.
  • Humans subscribing to high-volume intake lists (noise exhaustion)
  • Using intake groups on ACLs
  • Skipping allowlisting (spam floods the archive)
  • Mixing intake and alerts in one group (different urgency models)
MetricTarget
Blocked/quarantined messages (allowlist gap)< 5% of volume
Archive completeness (no gaps in feed)100%
Allowlist review cadenceQuarterly