> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tracecat.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Workflow triggers

> Run workflows from cases automatically on case events, from case tasks, or with a / command in a comment.

<Badge icon="lock" color="blue" size="lg" shape="pill">Enterprise Edition</Badge>

Cases can start workflows in three ways.
Pick the one that matches who decides when the workflow runs.

| Trigger | Who starts it | Use it for |
| - | - | - |
| Case trigger | Tracecat, when a selected case event happens | Enrichment, routing, and notifications that should always run |
| Task workflow | An analyst, from a case task | Response steps that need a human decision, such as resetting credentials |
| `/` command | An analyst, from a case comment or reply | Ad hoc lookups and actions during an investigation |

## Run workflows on case events

Open a workflow, select the trigger, and open the `Case triggers` tab.
Select one or more case events, optionally add a tag allowlist, and turn the trigger on.
Publish the workflow before you turn on its case trigger.

<img src="https://mintcdn.com/tracecat/9IEnC4OWdnuB3EvN/img/triggers/case-triggers.png?fit=max&auto=format&n=9IEnC4OWdnuB3EvN&q=85&s=3dc9f58afc561be691b110f4cace6fd5" alt="Case trigger" width="2870" height="1342" data-path="img/triggers/case-triggers.png" />

| Event family | Events |
| - | - |
| Case | `case_created`, `case_updated`, `case_closed`, `case_reopened`, `case_viewed` |
| Properties | `status_changed`, `priority_changed`, `severity_changed`, `assignee_changed`, `payload_changed` |
| Fields and dropdowns | `fields_changed`, `dropdown_value_changed` |
| Tags | `tag_added`, `tag_removed` |
| Tasks | `task_created`, `task_deleted`, `task_status_changed`, `task_priority_changed`, `task_assignee_changed`, `task_workflow_changed` |
| Comments | `comment_created`, `comment_updated`, `comment_deleted`, `comment_reply_created`, `comment_reply_updated`, `comment_reply_deleted` |
| Attachments | `attachment_created`, `attachment_deleted` |
| Linked rows | `table_row_linked`, `table_row_unlinked` |

The tag allowlist limits runs to cases that currently have at least one matching tag, such as `phishing`.
An empty allowlist runs the workflow for every case.

Tracecat ignores case events caused by workflows, so a workflow that updates a case does not trigger itself or other case-triggered workflows.
See [Case triggers](/automations/triggers/case-triggers) for the trigger payload.

## Run workflows from tasks

Set a workflow on a case task, then start it from the task row.
Tracecat asks for the workflow's Input schema values or passes generated case inputs.

<img src="https://mintcdn.com/tracecat/9IEnC4OWdnuB3EvN/img/triggers/task-trigger.png?fit=max&auto=format&n=9IEnC4OWdnuB3EvN&q=85&s=91e3aafea3ea19a100dd0bdfbf177629" alt="Task trigger" width="3440" height="1848" data-path="img/triggers/task-trigger.png" />

See [Case tasks](/automations/cases/tasks) to set up tasks and [Task triggers](/automations/triggers/task-triggers) for the trigger payload.

## Run workflows from comments

Type `/` in a case comment or reply, select a published workflow, and submit the comment.
Tracecat removes the `/` command from the saved comment and runs the workflow with the case and comment context.

<img src="https://mintcdn.com/tracecat/8itO_PQnIbTWMIj4/img/triggers/comment-triggers.png?fit=max&auto=format&n=8itO_PQnIbTWMIj4&q=85&s=823fc5385e7c1d0ee28ce920531b9561" alt="Comment trigger" width="2560" height="1440" data-path="img/triggers/comment-triggers.png" />

See [Comment triggers](/automations/triggers/comment-triggers) for required roles and the trigger payload.

## Related pages

* See [Agent mentions](/automations/cases/agent-mentions) to have a preset agent investigate a case instead of running a fixed workflow.
* See [Case triggers](/automations/triggers/case-triggers) for the full case trigger payload.
* See [Cases](/automations/core-actions/case-actions/cases) for the case actions your triggered workflows can call.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.