Native automation where your security data lives
Elastic Workflows brings automation directly into Elastic Security, an agentic security operations platform. You can use playbooks to handle defined tasks with consistency and reliability, while AI agents step in to reason through investigations that fall outside your standard scripts. No separate SOAR tool to buy, integrate, or maintain.

Blog
From the automation tax to native Workflows, read how Elastic Workflows makes standalone SOAR obsolete for security teams.

Documentation
Get started with Elastic Workflows. Explore triggers, steps, connectors, and AI capabilities for security automation.
Guided Demo
One engine for alert triage and AI investigation
Playbooks handle enrichment, escalation, and response. AI agents reason when investigations go off-script. Both run where your security data lives.
AUTOMATE THE SOC
From alert to response in Elastic Security
Automate the work your analysts repeat daily and investigate the unknown, all without leaving the platform.

Built in vs. bolted on
Elastic Workflows delivers native automation built directly into Elastic Security, an agentic security operations platform. By bringing automation to where your security data lives, Workflows eliminates the need for separate tools, brittle integrations, and unnecessary data movement.
Elastic Workflows
Stand-alone SOAR solutions
Elastic Workflows
Stand-alone SOAR solutions
Getting started
Everything you need to start building intelligent Workflows
Find the tools, tutorials, and technical insights you need to launch your first Workflow and scale your automation.
Blog
From alert to AI investigation, follow a step-by-step guide to building security playbooks with Elastic Workflows.
Agent Builder
Learn how to use Agent Builder to create custom AI agents that think, interpret, and act directly with your environment.
Blog
See how Attack Discovery, Workflows, and Agent Builder detected, confirmed, and triaged an APT-level attack in under four minutes.






