Who is this for? Organizational Admins and Agent Admins who manage Security Delivery Agents and want to standardize incident classification and response procedures.
Operating Procedure Types
ContraForce supports two types of operating procedures, each designed for a different phase of incident handling.Classification Operating Procedures
Classification operating procedures define how incidents should be categorized and prioritized. These contain your organization’s specific severity definitions, escalation criteria, and triage procedures. Each AI Agent can have multiple Classification operating procedures associated with it, but only one Classification operating procedure is activated per investigation. This ensures that every incident processed by that Agent follows a single, consistent classification standard while giving you the flexibility to maintain several classification approaches for different scenarios.Response Operating Procedures
Response operating procedures cover how to respond to and remediate security incidents. These include containment steps, investigation workflows, communication protocols, and recovery steps. Each AI Agent can have multiple Response operating procedures associated with it, and each Response operating procedure can be shared across multiple Agents. This many-to-many relationship means you can assign your phishing response playbook to three different Agents without duplicating the document.Supported File Formats
You can upload the following document formats:
Additional formats (PDF, Word, HTML, RTF) are coming soon. Maximum file size is 10 MB per document.
Uploading an Operating Procedure
1
Open Operating Procedures
Navigate to Agent Center in the left navigation menu, then select Operating Procedures.
2
Start the upload
Click the Upload Operating Procedure button. The upload modal will appear.
3
Select the operating procedure type
Choose either Classification or Response to categorize the operating procedure. This determines how it can be associated with AI Agents.
4
Upload the file
Drag and drop your file into the upload area, or click to browse and select a file from your computer.
5
Add metadata
Enter a title for the operating procedure. Optionally, add tags for easier searching and organization, and map it to relevant MITRE ATT&CK techniques.
6
Save
Click Save to upload the operating procedure. ContraForce extracts and indexes the document content automatically.
Viewing Operating Procedure Content
After uploading, you can view the full content of any operating procedure directly within ContraForce without switching to an external application.- Open Agent Center → Operating Procedures.
- Click on any operating procedure in the list to open the detail view.
- The detail panel displays the extracted document content, metadata (type, tags, MITRE ATT&CK mappings, version), and timestamps.
Associating Operating Procedures with AI Agents
You can create these associations from either direction.From the operating procedure detail page
- Open the operating procedure you want to associate.
- Select the Linked Agents tab.
- Click Add Agent and select one or more AI Agents from the list.
- The association takes effect immediately.
From the Agent detail page
- Navigate to Agent Center and select the Agent you want to configure.
- Scroll to the Associated Operating Procedures section.
- Click Add Operating Procedure and select the ones you want to associate.
- You can associate multiple Classification operating procedures with an Agent, but only one will be activated per investigation.
Changes to these associations take effect immediately. There is no separate publish or deploy step.
Updating an Operating Procedure
In-place editing is not supported. To update an operating procedure, upload a new version of the file. All existing Agent associations are preserved when you update the document. Use the version field on the operating procedure to track changes over time.Searching and Filtering Operating Procedures
The operating procedure list view provides several ways to find the right document quickly:- Search by title or content keywords.
- Filter by type to show only Classification or Response operating procedures.
- Sort by last updated date, title, or associated agent count.
Roles and Permissions
Operating procedure access follows the ContraForce role-based access control model.How AI Agents Use Operating Procedures
When an AI Agent processes an incident, it retrieves the content from its associated operating procedures to inform its investigation and response decisions. This means the Agent follows your organization’s specific procedures rather than relying on generic response patterns.- Classification operating procedures guide how the Agent categorizes incident severity and priority.
- Response operating procedures guide the specific containment, investigation, and remediation steps the Agent recommends or executes.
Best Practices
Start with your most critical playbooks. Upload the operating procedures your team uses most frequently first, such as phishing response, ransomware containment, and business email compromise procedures. Use tags consistently. Apply tags likephishing, ransomware, insider-threat, or data-exfiltration so they are easy to find and can be matched to relevant incidents.
Map to MITRE ATT&CK techniques. Associating operating procedures with specific techniques helps surface the right procedure when an incident involves those techniques.
Keep each procedure focused. Rather than uploading one massive document covering everything, split your procedures by incident type or response phase. This makes Agent associations more precise and retrieval more effective.
Review and update regularly. Upload new versions as your procedures evolve. ContraForce preserves all Agent associations when you update a document.
Frequently Asked Questions
Is there a limit to how many operating procedures I can upload?
Is there a limit to how many operating procedures I can upload?
There is no hard limit on the number of operating procedures per workspace. We recommend organizing them thoughtfully and associating only the most relevant procedures with each Agent.
Can I associate one operating procedure with multiple Agents?
Can I associate one operating procedure with multiple Agents?
Yes. Both types support many-to-many associations, so a single operating procedure can be linked to multiple Agents. For Classification operating procedures, multiple can be associated with an Agent, but only one is activated per investigation.
What happens if I delete an operating procedure that is associated with an Agent?
What happens if I delete an operating procedure that is associated with an Agent?
The association is removed automatically. The Agent will continue to function but will no longer reference that procedure during incident handling.
Do I need to redeploy my Agent after associating an operating procedure?
Do I need to redeploy my Agent after associating an operating procedure?
No. These associations take effect immediately. There is no redeployment or restart required.
Related Guides
Configuring Security Delivery Agents
Set up and configure agents using the three-phase adoption model.
Agent Execution History
Monitor and audit agent activity with a complete execution trail.
Deploying Agent Center
Deploy the Azure AI Foundry infrastructure required for agents.
Incident Management
Learn how incidents flow through ContraForce.
Questions about Operating Procedures? Contact us at support@contraforce.com.