Skip to main content
Enterprise Edition Cases can start workflows in three ways. Pick the one that matches who decides when the workflow runs.

Run workflows on case events

Open a workflow, select the trigger, and open the Case triggers tab. Select one or more case events, optionally add a tag allowlist, and turn the trigger on. Publish the workflow before you turn on its case trigger. Case trigger The tag allowlist limits runs to cases that currently have at least one matching tag, such as phishing. An empty allowlist runs the workflow for every case. Tracecat ignores case events caused by workflows, so a workflow that updates a case does not trigger itself or other case-triggered workflows. See Case triggers for the trigger payload.

Run workflows from tasks

Set a workflow on a case task, then start it from the task row. Tracecat asks for the workflow’s Input schema values or passes generated case inputs. Task trigger See Case tasks to set up tasks and Task triggers for the trigger payload.

Run workflows from comments

Type / in a case comment or reply, select a published workflow, and submit the comment. Tracecat removes the / command from the saved comment and runs the workflow with the case and comment context. Comment trigger See Comment triggers for required roles and the trigger payload.
  • See Agent mentions to have a preset agent investigate a case instead of running a fixed workflow.
  • See Case triggers for the full case trigger payload.
  • See Cases for the case actions your triggered workflows can call.