> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/use-the-work-plan-in-an-investigation.md).

# Use the Work Plan in an investigation

The Work Plan is a visual representation of the running playbook assigned to the issue. Playbooks enable you to automate many security processes, such as managing your investigations and handling tickets. Work Plans enable you to monitor and manage a playbook workflow, and add new tasks to tailor the playbook to a specific investigation.

In an investigation, when you open the **Work Plan** tab you can see the playbook, the playbook name, and navigation tools.

By default, the **Follow** checkbox is checked, which allows you to see the playbook executing in real-time. The playbook moves when a task is completed.

In the Work Plan you can do the following:

| Action                      | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| --------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Change the default playbook | <p>On the left-hand side of the window, select the playbook you want to run.</p><p>When changing the playbook, all completed tasks are removed and the new playbook will run. If you select playbooks several times you can view the history of which playbooks ran.</p>                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Rerun the playbook          | When changing the playbook, select the current playbook to run again.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| View inputs and outputs     | View the inputs and outputs of each task that has run. You can't view inputs and outputs of any task that hasn't run.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Manage tasks                | <p>View, create, and edit a playbook task. For each task, you can do the following:</p><ul><li>Designate tasks as complete either manually or by running a script.</li><li>Assign an owner.</li><li>Set a due date.</li><li>Add comments and completed notes, as required.</li><li>View any automation exclusion policies that affected the task execution. Automation exclusion policies prevent automated remediation on critical assets specified by admins. The <strong>Policies</strong> tab only appears if the task includes a command or script affected by an automation exclusion policy.</li></ul><p>You can manage these tasks in the CLI by using the <code>/task</code> command.</p> |
| Export to a PNG             | Export the Work plan to a PNG format for easy analysis.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |

Example

For a phishing investigation, after the initial playbook run parses the email and extracts email addresses, as part of the manual investigation, you could use the **Email Address Enrichment - Generic v2.1** playbook as an ad-hoc playbook task to get more information about these email addresses.

The color coding and symbols in the Work Plan help you to easily troubleshoot errors or respond to manual steps. The following table displays the playbook tasks and icons in the Work Plan.

{% hint style="info" %}

### Important

A playbook will not continue its execution path if a prior task has failed; you must resolve the failed task before subsequent tasks can run.
{% endhint %}

<details>

<summary>Playbook tasks and icons in the Work Plan</summary>

| Task                                                       | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| ---------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| ![standard\_task.png](/files/xPdlteG50hTQgD2jIfcy)         | <p><img src="/files/s5SSeI9QSQItc3MXwIgm" alt="arrow.png"><strong>Standard manual task</strong></p><p>An arrow with a light blue square background indicates a standard manual task. The following are kinds of standard tasks.</p><ul><li><p>Manual Standard task (no lightning bolt logo):</p><p>These tasks are used where usually it's not possible to automate them. You can add comments, assign them to an owner, and set a due date. The analyst who is responsible for the investigation needs to complete the task before the Work Plan can continue. A user icon ( <img src="/files/V6sRBAp8mb5rdx1gtuRj" alt="user_icon.png">) indicates the task requires manual inputs.</p></li><li><p>Automated Standard task (with lightning bolt script logo):</p><p>A single command or script that is set to automatically run when the Work Plan execution reaches this step. Some scripts need arguments in order to run - make sure to set them up properly. If left empty, the analyst who is responsible for the investigation will need to complete them so the script will run and the Work Plan can continue.</p></li><li><p>Automated Standard task (with Builtin logo):</p><p>A single system command or script that is set to automatically run when the Work Plan reaches this step. Some scripts need arguments in order to run - make sure to set them up properly. If left empty, the analyst who is responsible for the investigation will need to complete them so the script will run and the Work Plan can continue.</p></li><li><p>Automated Standard task (with Multi Command logo):</p><p>A generic single command or script that can be used with multiple integrations is set to automatically run when the Work Plan reaches this step. Some scripts need arguments in order to run - make sure to set them up properly. If left empty, the analyst who is responsible for the investigation will need to complete them so the script will run and the Work Plan can continue.</p></li></ul> |
| ![condition\_task.png](/files/rCY6LYCo3J9V5x2qsXwR)        | <p><img src="/files/WWzXt6aTeCKfmq7zJvKv" alt="conditional_icon.png"><strong>Conditional task</strong></p><p>A diamond icon in a purple square background indicates a conditional task used as decision trees in your Work Plan. The following are kinds of conditional tasks.</p><ul><li>Manual conditional task. A user icon ( <img src="/files/V6sRBAp8mb5rdx1gtuRj" alt="user_icon.png">) indicates the task requires manual inputs.a</li><li>Automated conditional task (with the lightning bolt script logo).</li><li>Automated conditional task that uses a system script (with the Builtin logo).</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| ![data\_collection\_task.png](/files/qnFNphOWqQwwkf9ScOUr) | <p><img src="/files/NeepCth9UU1stHfCN45T" alt="data_collection_icon.png"><strong>Data collection task / Communication task</strong></p><p>The speech bubble in a turquoise background indicates a data collection task. This task prompts the receivers to respond to a multi-question form and submit replies, even if they are not Cortex users. A user icon ( <img src="/files/V6sRBAp8mb5rdx1gtuRj" alt="user_icon.png">) indicates the task requires manual inputs.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| ![sub-playbook\_task.png](/files/jEWMWvhDVQWPJ256VK5w)     | <p><img src="/files/6sIxGr37fk8zIF7mjKzD" alt="sub-playbook_icon.png"><strong>Sub-playbook task</strong></p><p>The workflow icon in a blue background indicates that the task is a playbook nested within the parent playbook. You can view the playbook by opening the task and selecting <strong>Open sub-playbook</strong>.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| ![task-error-new-logo.png](/files/tMxe6xZreUbKe1vABWbZ)    | <p><strong>Task containing an error</strong></p><p>Scripts or sub-playbooks that have errors are designated by a red triangle. You need to open the script or sub-playbook to review the errors.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ![update\_scripts.png](/files/k0sciYx2l3Vl3iyYjGeW)        | <p><strong>Task containing a deprecated script or needs to be updated</strong></p><p>Scripts or sub-playbooks that have updates or are deprecated are designated by a yellow triangle. You need to update the scripts, integration commands, or sub-playbook tasks to their most current version.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| ![skip.png](/files/evOFHMZws0qaVaUoGL7f)                   | <p><img src="/files/e674vE1P2LgmDqSBx3F3" alt="skip_icon.png"><strong>Set to skip</strong></p><p>When a task is set to skip, the skip icon will be orange.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| ![breakpoint.png](/files/xpWQhyyHgajrC2pFRrly)             | <p><img src="/files/nG4bOE12EssBemCV7nzK" alt="breakpoint_icon.png"><strong>Breakpoint</strong></p><p>When the Work Plan reaches a breakpoint, the task has an orange line at the top to indicate the breakpoint.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| ![overriden.png](/files/ZQh0PdNopYl3EfX47fqB)              | <p><img src="/files/Ww1haMd3pdOe0txrU3e5" alt="overidden_icon.png"><strong>Overridden inputs or outputs</strong></p><p>When a task is set to have overridden inputs or outputs, the word Input or Output appears in orange.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| ![pending.png](/files/guvdwsVVyrM31oD93P5P)                | <p><img src="/files/cUunEI6S9v9JSTIH4syF" alt="pending_icon.png"><strong>Pending/in queue task</strong></p><p>When the Work Plan starts to run, all tasks that are about to be performed are gray.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| ![running.png](/files/Gywky1pYAZeJc1IRIFPi)                | <p><img src="/files/c0pAe0nhreeoptz9vjyX" alt="running_icon.png"><strong>Running/ in progress task</strong></p><p>A spinning circle inside the gray square indicates a running/in progress task.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ![completed.png](/files/AJkIPXPZfAbJKOAKdOzm)              | <p><img src="/files/KKxkQ3RGylgl9D3gpgEK" alt="completed_icon.png"><strong>Completed task</strong></p><p>The green square indicates a completed task.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| ![waiting.png](/files/5lgTP8FDUzEx2qLzaqzx)                | <p><img src="/files/n5cfnoN4TVD3mmfzUqDK" alt="waiting_icon.png"><strong>Waiting task</strong></p><p>The orange square indicates that the task is pending action.</p><p>If you hover over the icon on the top left corner, details about the reason the task is in waiting mode appear.</p><p>The user icon ( <img src="/files/V6sRBAp8mb5rdx1gtuRj" alt="user_icon.png">) indicates the task requires you to open it and manually mark it as complete.</p><p>A speech bubble icon (<img src="/files/nhKLWPk8E5tVdsWZMSHy" alt="bubble_icon.png">) indicates the task is waiting for a questionnaire to be completed.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| ![failed.png](/files/34XKDnor6whwolsj0hTc)                 | <p><strong>Failed task</strong></p><p>The red warning icon indicates that the task failed to complete as expected and requires manual inspection and troubleshooting. Contact your Cortex AgentiX administrator.</p><p>If you hover on the icon on the top left corner, details about the specific problem appear.</p><p>If a red warning icon is paired with the clock icon (<img src="/files/kZOHJzrfx2tuQAn7FedB" alt="hourglass_icon.png">), the task’s SLA is overdue.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| ![skipped.png](/files/VE5ad7HO2M6w4vBLKbI4)                | <p><img src="/files/ymHxGT00qI4nI31l2DIs" alt="skipped_icon.png"><strong>Skipped task</strong></p><p>The task will look faded to indicate it was not executed. This can happen if this task was set to be skipped when an error occurs, or if it is in a branch that was not executed if a condition wasn’t met.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |

</details>

<details>

<summary>Add ad-hoc tasks to the Work Plan</summary>

As part of your issue investigation, within the Work Plan you can create tasks for a specific iteration of a playbook. The task type can be an automation or another playbook. For example, within a manual task, you might need to enrich some data and run an investigation playbook.

When you create a task, add a name, automation, and description. The name and description should be meaningful so that the task corresponds to the data that you are collecting.

1. In the **Cases** page, select the case to update.
2. In the **Issues & Insights** tab, click the issue to add the task to and then click the **Work Plan** tab.
3. In the Work Plan, go to the task where you want to add a new task and click the + sign at the bottom right-hand corner of the task.

   The ad-hoc task is added after the task you clicked.
4. Select the task type.
   * **Standard**: Runs a single automation.
   * **Playbook**: Runs a playbook to enhance the investigation.

     The playbook functions as any playbook would and requires you to define the inputs and outputs, as well as any other details.
   * Click **Save**.
5. To run the Work Plan again click the **Run Again** icon.

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/use-the-work-plan-in-an-investigation.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
