Manage actions
Manage Cortex Cloud actions that automate security tasks and operational workflows.
Actions wrap diverse capabilities (such as playbooks, scripts, AI prompts, and commands) to make them accessible and executable by an agent. You can use out-of-the-box system actions or register new actions.
There are two types of actions in the Agentic Assistant Hub:
System actions: Cortex Cloud contains more than 50 out-of-the-box system actions that can be disabled or enabled, but cannot be edited or deleted.
To find and install additional content packs that include actions, go to Marketplace and select Content pack includes and Actions.
Custom actions: Users can register existing or new scripts, commands, and AI prompts as actions. Custom actions can be edited, deleted, enabled, or disabled.
Any action marked as sensitive to require user approval requires explicit user approval before execution. This is particularly crucial for operations that might alter system reality or affect an organization’s budget, such as isolating an endpoint or revoking user access. System actions are marked sensitive if they affect system reality. When creating custom actions, you decide which actions should be marked as sensitive for your organization.
The execution of system or custom actions that are based on integration commands can be restricted using integration permissions.
Manage existing actions
From the Actions tab of the Agentic Assistant Hub, click
for an action to edit, delete, or disable an existing custom action. System actions can be enabled or disabled and you can change them from sensitive to non-sensitive or from non-sensitive to sensitive.
Search, filter, and sort actions
You can use the dropdown filter to search all actions, custom actions, system actions, enabled actions, disabled actions, sensitive actions, or non-sensitive actions. You can also filter by source types: command, script, or playbook.
You can sort actions by creation time or update time.
Last updated
Was this helpful?
