Skip to main content

Action Types Reference

Ascend supports 56+ enterprise action types with automatic CVSS scoring, NIST mapping, and MITRE ATT&CK alignment.

Action Type Categories

CategoryCountRisk RangeDescription
Read Operations5LowData retrieval actions
Write Operations4MediumData modification actions
Delete Operations3HighData removal actions
Data Movement3High-CriticalData transfer actions
Financial Services8High-CriticalBanking and trading actions
Healthcare/HIPAA5High-CriticalPHI access and modification
PII/GDPR4HighPersonal data operations
System/Infrastructure6CriticalSystem-level actions
Communication3MediumMessaging and notifications
HR/Employee Data4HighHR system operations
Legal/Contracts3HighLegal document operations
MCP Server Tools8High-CriticalMCP protocol actions

Read Operations (Low Risk)

Basic data retrieval operations with minimal security impact.

Action TypeCVSSRisk LevelNIST ControlMITRE Tactic
database_read2.5LowAC-3TA0009
file_read2.5LowAC-3TA0009
api_read2.5LowAC-3TA0009
analytics_query2.5LowAC-3TA0009
api_call3.0LowAC-3TA0009

CVSS Metrics (Read Operations)

{
"database_read": {
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"privileges_required": "LOW",
"user_interaction": "NONE",
"scope": "UNCHANGED",
"confidentiality_impact": "LOW",
"integrity_impact": "NONE",
"availability_impact": "NONE"
}
}

Write Operations (Medium Risk)

Data modification operations requiring standard access controls.

Action TypeCVSSRisk LevelNIST ControlMITRE Tactic
database_write5.0MediumAC-3TA0003
file_write5.0MediumAC-3TA0003
api_write5.0MediumAC-3TA0003
record_update4.5MediumAC-3TA0003

CVSS Metrics (Write Operations)

{
"database_write": {
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"privileges_required": "LOW",
"user_interaction": "NONE",
"scope": "UNCHANGED",
"confidentiality_impact": "LOW",
"integrity_impact": "LOW",
"availability_impact": "NONE"
}
}

Delete Operations (High Risk)

Data removal operations requiring elevated approval.

Action TypeCVSSRisk LevelNIST ControlMITRE Tactic
database_delete7.5HighAC-6TA0040
file_delete7.5HighAC-6TA0040
record_delete7.0HighAC-6TA0040

CVSS Metrics (Delete Operations)

{
"database_delete": {
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"privileges_required": "LOW",
"user_interaction": "NONE",
"scope": "UNCHANGED",
"confidentiality_impact": "NONE",
"integrity_impact": "HIGH",
"availability_impact": "HIGH"
}
}

Data Movement (High-Critical Risk)

Data transfer operations with exfiltration detection.

Action TypeCVSSRisk LevelNIST ControlMITRE Tactic
data_export7.5HighSI-12TA0010
data_exfiltration9.0CriticalAC-4TA0010
bulk_transfer8.0HighSI-12TA0010

CVSS Metrics (Data Movement)

{
"data_exfiltration": {
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"privileges_required": "LOW",
"user_interaction": "NONE",
"scope": "CHANGED",
"confidentiality_impact": "HIGH",
"integrity_impact": "NONE",
"availability_impact": "NONE"
}
}

Financial Services (High-Critical Risk)

Banking and trading operations with strict compliance requirements.

Action TypeCVSSRisk LevelNIST ControlCompliance
execute_trade8.5CriticalAC-3, AU-2SOX, PCI-DSS
funds_transfer9.0CriticalAC-3, AU-2PCI-DSS
payment_process8.5CriticalAC-3PCI-DSS
wire_transfer9.0CriticalAC-3, AU-9SOX
account_modify7.5HighAC-3, CM-3SOX
transaction_void7.5HighAC-3, AU-9SOX
credit_approval8.0HighAC-3SOX
limit_override8.5CriticalAC-6SOX

CVSS Metrics (Financial)

{
"funds_transfer": {
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"privileges_required": "HIGH",
"user_interaction": "NONE",
"scope": "CHANGED",
"confidentiality_impact": "HIGH",
"integrity_impact": "HIGH",
"availability_impact": "LOW"
}
}

Healthcare/HIPAA (High-Critical Risk)

Protected Health Information (PHI) operations.

Action TypeCVSSRisk LevelHIPAA ControlMITRE Tactic
phi_access6.5High164.312(a)(1)TA0009
phi_modify8.1Critical164.312(c)(1)TA0040
phi_export8.5Critical164.312(e)(1)TA0010
prescription_write8.5Critical164.312(c)(1)TA0003
diagnosis_modify8.5Critical164.312(c)(1)TA0040

CVSS Metrics (Healthcare)

{
"phi_access": {
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"privileges_required": "HIGH",
"user_interaction": "NONE",
"scope": "UNCHANGED",
"confidentiality_impact": "HIGH",
"integrity_impact": "NONE",
"availability_impact": "NONE"
}
}

PII/GDPR (High Risk)

Personal Identifiable Information operations.

Action TypeCVSSRisk LevelNIST ControlCompliance
pii_access6.5HighAC-3GDPR Art. 6
pii_modify7.5HighAC-3, AU-9GDPR Art. 17
pii_delete7.5HighSI-12GDPR Art. 17
consent_modify6.5HighAC-3GDPR Art. 7

CVSS Metrics (PII)

{
"pii_access": {
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"privileges_required": "LOW",
"user_interaction": "NONE",
"scope": "UNCHANGED",
"confidentiality_impact": "HIGH",
"integrity_impact": "NONE",
"availability_impact": "NONE"
}
}

System/Infrastructure (Critical Risk)

System-level operations requiring maximum security controls.

Action TypeCVSSRisk LevelNIST ControlMITRE Tactic
system_modification9.0CriticalCM-3TA0003
config_change8.5CriticalCM-3TA0005
credential_access9.0CriticalIA-5TA0006
privilege_escalation9.5CriticalAC-6TA0004
service_restart7.5HighCM-3TA0040
schema_change8.5CriticalCM-3TA0003

CVSS Metrics (System)

{
"privilege_escalation": {
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"privileges_required": "LOW",
"user_interaction": "NONE",
"scope": "CHANGED",
"confidentiality_impact": "HIGH",
"integrity_impact": "HIGH",
"availability_impact": "HIGH"
}
}

Communication (Medium Risk)

Messaging and notification operations.

Action TypeCVSSRisk LevelNIST ControlMITRE Tactic
email_send4.5MediumAU-2TA0010
notification_send3.5LowAU-2TA0011
message_send4.0MediumAU-2TA0011

CVSS Metrics (Communication)

{
"email_send": {
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"privileges_required": "LOW",
"user_interaction": "NONE",
"scope": "UNCHANGED",
"confidentiality_impact": "LOW",
"integrity_impact": "LOW",
"availability_impact": "NONE"
}
}

HR/Employee Data (High Risk)

Human resources system operations.

Action TypeCVSSRisk LevelNIST ControlCompliance
employee_record_access6.5HighAC-3GDPR
payroll_modify8.0HighAC-3, AU-9SOX
benefits_change7.0HighAC-3ERISA
termination_process7.5HighAC-2SOX

Legal/Contracts (High Risk)

Legal document and contract operations.

Action TypeCVSSRisk LevelNIST ControlCompliance
contract_sign7.5HighAC-3, AU-9SOX
contract_modify7.5HighAC-3, CM-3SOX
legal_hold7.0HighAU-9eDiscovery

MCP Server Tools (High-Critical Risk)

Model Context Protocol (MCP) server operations.

Action TypeCVSSRisk LevelNIST ControlMITRE Tactic
execute_query6.5HighAC-3TA0009
execute_command9.0CriticalAC-3TA0002
shell_execute9.5CriticalAC-3, CM-3TA0002
code_execute9.5CriticalAC-3TA0002
file_system_access7.0HighAC-3TA0009
network_request6.5HighSC-7TA0011
process_spawn8.5CriticalAC-3TA0002
memory_access8.0HighAC-3TA0006

CVSS Metrics (MCP Server)

{
"shell_execute": {
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"privileges_required": "LOW",
"user_interaction": "NONE",
"scope": "CHANGED",
"confidentiality_impact": "HIGH",
"integrity_impact": "HIGH",
"availability_impact": "HIGH"
}
}

Custom Action Types

Register custom action types for your organization:

# Register custom action type
curl -X POST "https://pilot.owkai.app/api/registry/action-types" \
-H "Cookie: access_token=your_session_cookie" \
-H "Content-Type: application/json" \
-d '{
"action_type": "custom_approval",
"display_name": "Custom Approval Process",
"category": "workflow",
"default_risk_score": 45,
"cvss_metrics": {
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"privileges_required": "LOW",
"confidentiality_impact": "LOW",
"integrity_impact": "LOW",
"availability_impact": "NONE"
},
"nist_control": "AC-3",
"mitre_tactic": "TA0003"
}'

Action Type Submission

Submit an action with proper typing:

curl -X POST "https://pilot.owkai.app/api/v1/actions/submit" \
-H "X-API-Key: your_api_key" \
-H "Content-Type: application/json" \
-d '{
"agent_id": "customer-service-agent",
"action_type": "database_write",
"description": "Update customer email address",
"tool_name": "postgresql",
"target_system": "customers_db"
}'

Response with Automatic Enrichment

{
"id": 1547,
"status": "approved",
"risk_score": 45,
"risk_level": "medium",
"cvss_score": 5.0,
"cvss_severity": "medium",
"nist_control": "AC-3",
"nist_description": "Access Enforcement",
"mitre_tactic": "TA0003",
"mitre_technique": "T1098"
}

Risk Score Calculation

Risk scores are calculated from CVSS metrics:

Risk Score = CVSS Base Score × 10 + Context Modifiers

Context Modifiers:
- After hours: +10
- Sensitive data: +15
- External target: +10
- Bulk operation: +15
- First time action: +5

For action type questions, contact support@owkai.app