Vulnerability alert fatigue nearly swamped WHOOP. But its fix still keeps a human in charge.
The New Stack Jennifer Riggins
WHOOP was drowning in vulnerability alerts, so it built an automated response flow. The twist: it still keeps a human in the loop because its user data is too sensitive to fully trust the bots.
Based on reporting by The New Stack, Jennifer Riggins — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
Security teams are getting buried. The source says many organizations now face hundreds of thousands of alerts a day, and AI has only made the mess noisier by making it harder to spot which warnings matter. WHOOP’s engineering team was living that reality too, and it wasn’t handling it with quick clicks and a tidy dashboard. It was doing multi-day, all-hands triage sessions just to stay afloat.
That kind of process does not scale, especially for a high-growth consumer health company handling sensitive data. Missing a real issue was not an option, but neither was asking engineers to keep playing human sorting machine forever. So WHOOP built an automated vulnerability-response workflow tuned to its own technical setup, operations and trust requirements.
The system leans on Datadog Bits AI and Workflow Automation, and the point is not full autonomy. WHOOP wants the right vulnerability routed to the right engineer, with context attached, so developers can deal with real exposure instead of scanner noise. The team also used Datadog’s Software Composition Analysis to analyze runtime code execution and prioritize active threats, which is a cleaner way to separate urgent problems from the endless pile of maybes.
But the company drew a line at removing people from the loop. For WHOOP, the goal is to cut friction between developer speed and security without adding headcount, while letting security engineers spend less time gatekeeping and more time on systemic work. That’s the more interesting part here: automation as relief, not replacement.
My take — AI-written commentary, not fact-checked reporting
The smartest security teams are not the ones that automate everything; they’re the ones that stop pretending every alert deserves the same drama. Human-in-charge workflows are the grown-up answer, especially when the data is sensitive and the scanners are noisy. Full auto-remediation sounds elegant right up until it starts confidently making the wrong mess.
Read more about this at: The New Stack