Security
Send GCP Security Command Center alerts to on-call with CallHeim.
GCP Security Command Center findings, posted as {finding:{...}} JSON by a small relay you build that unwraps the Pub/Sub push envelope. CallHeim maps the payload, collapses repeats within five minutes, and pages whoever is on call for the service it belongs to.
You build the connection
GCP Security Command Center has no native outbound webhook for this. It requires a forwarder, script or template that you set up; CallHeim provides the ingest URL and understands the payload shape once it arrives.
Setting it up
Export findings to a Pub/Sub topic, then have a small relay (for example a Cloud Function) decode the Pub/Sub push envelope and POST the unwrapped finding JSON to your CallHeim URL.
Create an Integration in CallHeim and choose GCP Security Command Center from the Catalog. You get an ingest URL for that integration — paste it into GCP Security Command Center’s webhook configuration. The snippet beside this is the shape it expects, with {{WEBHOOK_URL}} replaced by your real URL.
If you enable request signing on this integration, CallHeim requires a valid HMAC-SHA256 signature in the X-ItOnCall-Signature or X-Hub-Signature-256 header on every request to it. Without a signing secret, the ingest URL itself is the credential.
CallHeim includes a payload mapping for GCP Security Command Center’s webhook format, built and tested against sample payloads.
# SCC → Notifications → export findings to a Pub/Sub topic.
# A real Pub/Sub push wraps the finding as base64 in message.data — CallHeim reads an
# unwrapped {finding:{...}} body, so point the push subscription at a small relay
# (for example a Cloud Function) that decodes the message and POSTs the result to {{WEBHOOK_URL}}.After it arrives
What CallHeim does with GCP Security Command Center alerts.
Detection alerts are the case where sending content to an external model is least acceptable. Severity and correlation for these alerts are computed by rule-based code inside our own AWS environment; no finding is sent to an external AI model. An optional Amazon Bedrock path exists in the code and is switched off.
CallHeim maps GCP Security Command Center’s own severity to a P1–P5 level and shows a separate, explainable severity suggestion — a published keyword ruleset plus your own resolved-incident history — that a person can apply. How severity is suggested →
Each alert source is bound to a service, and the service’s escalation policy (or its team’s) sets who is paged. Alerting and escalation →
CallHeim closes an incident on a recovery event only for sources whose recovery payload it recognises (or that you map). For the others, a person resolves the incident.
The thresholds it passes through
- Dedup window
- 300s
- Flap threshold
- 4 transitions / 600s
- Title correlation
- similarity ≥ 0.6, same source and service
- Group window default
- 600s
All defaults are published. You can turn title correlation off or change its threshold, and set the window on your own noise rules; the dedup window and the flap settings are fixed. How alerts are processed →
Point GCP Security Command Center at CallHeim and see what it does with your alerts.
Explore the platform, connect one source, and send yourself a test page by e-mail (early access).
Early access · every workspace starts with a 14-day trial for up to 5 seats, no card required