Skip to main content
Enterprise Edition Tasks break a case into follow-up steps, such as containment, notification, or evidence collection. Each task has its own status, priority, assignee, and optional workflow, so you can see what is left before you close the case. Case tasks

Add a task

  1. Open a case and select the tasks control in the case toolbar. It shows completed and total task counts, such as 1/4.
  2. Select Add task.
  3. Enter a Task title and an optional description.
  4. Set the status, priority, assignee with Assign to..., and workflow with Set workflow....
Add a case task

Track progress

The tasks control lists every task with its status so you can jump to open work from anywhere in the case.

Start workflows from tasks

Set a workflow on a task, then start it from the task row. If the workflow has an Input schema, Tracecat asks for those inputs. Otherwise, Tracecat passes generated case inputs; see Task triggers for the payload. Use task workflows for repeatable response steps an analyst should approve, such as Reset user credentials or Isolate host. Use a case trigger instead when the workflow should run automatically.

Manage tasks from workflows

Use core.cases.create_task, core.cases.update_task, and core.cases.list_tasks to add a response checklist when a case opens or to complete tasks as automation finishes.
Case triggers can also react to task events such as task_created, task_status_changed, and task_assignee_changed.
  • See Workflow triggers to compare task workflows with case triggers and / commands.
  • See Tasks for the task action inputs.
  • See Task triggers to reference the task trigger payload.