Back to workflows
Security & ITOrchestrate multiple stepsTeam

Natural-language security workflow compilation

Compile an analyst-authored procedure into a testable automation with bounded tools.

What this workflow does

Compile an analyst-authored procedure into a testable automation with bounded tools. It coordinates dependencies across connected systems, pauses at exception boundaries, and records the state of every approved sub-step.

What you gain

Versioned, tested automation pending activation

What the AI agent changes

How this worked before

A fixed workflow required every system and input to behave exactly as expected; one exception stopped the entire chain.

What the AI agent changes

The agent chooses the next tool from the current state, recovers from common exceptions, and asks for a decision at the right boundary.

Agent trigger

An analyst submits an approved procedure and representative test cases.

Inputs

  • Process context: procedure, schemas, connector permissions, and test fixtures
  • Approved policies, ownership, and exception rules

Agent flow

  1. 1

    Build the dependency graph and verify every connector permission.

  2. 2

    Coordinate read-only sub-steps and surface blocked dependencies.

  3. 3

    Prepare a least-privilege executable workflow and test report with state, exceptions, and rollback points.

  4. 4

    Execute approved sub-steps idempotently and verify the final state.

Human decisions

After step 3

The accountable process owner approves a least-privilege executable workflow and test report.

Outcome

  • Versioned, tested automation pending activation
  • Evidence, exceptions, and audit trail

Guardrails

  • Pause when a dependency or approval is missing.
  • Record before-and-after state for every system write.

Risks and mitigations

A partial multi-system execution can leave records in conflicting states.

Use idempotency keys, checkpoints, and explicit compensation for every write step.

Sources and evidence