> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/build-your-playbook/add-objects-from-the-task-library/add-sub-playbooks.md).

# Add sub-playbooks

Sub-playbooks are playbooks that are nested under other playbooks. They appear as tasks in the parent playbook flow and are indicated by the sub-playbook icon ![sub-playbook-icon-2.png](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAACcAAAAnCAYAAACMo1E1AAAACXBIWXMAABJ0AAASdAHeZh94AAAAB3RJTUUH6QMfCzMatxmuWAAAAVRJREFUWIXtlrFKw1AUhr+KpEpFSE1R6BCFSoWCips4d9DFTXEQcRQcfARfwGdwUBAHB4sgBXERXAsu6uIqOBRjh1prjUOGcAmE9iTBIPfbcvhz8t17uJdkqruuS0oZ+muBMLScFC0nRctJ0XJStJyU4SgvH+7DWE6tvb7B0XGUrj6R5JYqMJJVa5MTUTqqpHqsWk5KJLneT7DW/Y7SUSUTx5/w3ha8t+DsKg4ln4FPa24USrZas/LeqV2YU+tPL9D5kssNvHMHOzBfhqYTnivk4eYeTi7lcqKdO7+G+l14bnMNLFOq5dG33JQF1RWYLoJhQMGE01owlzVgYxUqs95CttehdgtOK0G5ku19CMAuwvIiXNSh3VFz5rifAyjPQONRJvd/77mk6XusTQcenv1n14VuL5hrf6o5gA/BSCGmSzgpUj1WLSdFy0nRclK0nBQtJ+UXE5dDtjamJVQAAAAASUVORK5CYII=). A sub-playbook can also be a parent playbook in a different use case.

For example, [IP Enrichment - Generic v2](https://xsoar.pan.dev/docs/reference/playbooks/ip-enrichment---generic-v2) and [Retrieve File From Endpoint - Generic v3](https://xsoar.pan.dev/docs/reference/playbooks/retrieve-file-from-endpoint---generic-v3) playbooks are usually used as part of a bigger investigation.

Since sub-playbooks are building blocks that can be used in other playbooks and use cases, you should define generic inputs for them.

Inputs can be passed to sub-playbooks from the parent playbook, used and processed in the sub-playbook, and sent as output to the parent playbook.

{% hint style="info" %}
To modify the settings or task configurations for system playbooks (out-of-the-box playbooks), your role must have the Edit Public Playbooks permission enabled. If this permission is not enabled, system playbooks will remain read-only. For more information, see [Manage access to playbooks and scripts](/cortex-xsiam/onboard-cortex-xsiam/post-deployment/manage-user-roles-and-access-management.md).
{% endhint %}

{% stepper %}
{% step %}
From the **Task Library** pane, click **Playbooks**.
{% endstep %}

{% step %}
Find the relevant sub-playbook.

Search for a playbook by name in the **Org Playbooks** tab. You can also adopt one from the **Playbook Catalog** tab.

You can sort alphabetically (ABC) or by Last Modified.
{% endstep %}

{% step %}
Hover over the playbook you want and drag it onto the playbook editor.

When you adopt a playbook from the Playbook Catalog, installation may take some time.

When you adopt a system playbook, it is locked and you can only make limited changes to the playbook settings from the Playbook Starts task. For full editing capabilities, click ![three-dots.png](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAABoAAAAeCAYAAAAy2w7YAAAACXBIWXMAABJ0AAASdAHeZh94AAAAB3RJTUUH6QMfDSo09EJ2PQAAAIBJREFUSIntlCEOwCAMRf8WNMfpNXrWmt4IhwFNYI5NTKxmWUaf+qLJS5ufbmOMgRfY35C4yEUuOhEREBGICCJiEgXLcCkFvfeZLZg2CiHc5idsa/86L8OVxcugqmBmMDNU1SQyHTrnjJTSzBa+WYbWGmqtAIAYo0m2eOtc9G/RAX7QRNu0LuROAAAAAElFTkSuQmCC) and select either **Duplicate** (create a copy of the playbook to edit) or **Edit Playbook** (detach the playbook). A detached playbook does not receive updates in future content releases. If you reattach the playbook, the latest content updates will be applied and any edits you made will be overridden.<br>

1. If after adopting a playbook you see a warning ![sub-playbook-icon-warning.png](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAADoAAAAzCAYAAADGtBvgAAAACXBIWXMAABJ0AAASdAHeZh94AAAAB3RJTUUH6QMfDDEf8Aou0AAAA1pJREFUaIHtml1IFFEUx39bthVq5mei0Boplkma9JJBICloEFqEUWEQ0UMfRA9BHy8VPkr4IPTmChWUDxJJKUaE5MdbJFFUKyTC0ppUtCpaVnt7mJWdaWa31e5V9+P3MnvOnMs9/7ln7507MzYhhCAGWLHUCSwWCcFOuMeg/wWMfV7MdEKzKgEKN0Fl+fzb2qxK9/5jcHbISE0Njhy4eFITHS6m0u1+vrxFAox+hMZbMP09/DYmoe1dMlNSx/gXePAk/HiDUPcYfByXnZI6ht6FH2sQOvNDdipqmZ4JPzZmlpe40GgjLjTaiAuNNuJCo42g2zQZXD8HSYlGn2ccbrap7NUapULLtsGa1UbfhnSVPQYnZko3LjTaUCr0t8/s+/lLZY/BUToZHTirHU8fgW+TcO+Ryt5CI11o4lrIdxh9GWna7Fuyxeh/9wF+zMrOwBrpQk/Vw/ZC+Oo1+lOSoKE2YGemwdNBuPNQdgbWKBnR9m7o6Qsdd3gfZKTK7j040oRmZ0DVbsjLBbsdMlPhbqc5brUd6mtgW4F2URpqofMZeCdlZWKNNKH5jkBpOnJhVyl09JgfuKWuM5Zw4SZ4+Va90Pg6Gm1IK92vXnj1PmALAT9/m+NmvhvjACYUly389ZJpeBTO3lDfqQwy06C+Gmorw4tXemekivT10HwFsuax5Yu4/6jNBo0X5icSIlBozR7I3+g3JiYQly+Dy/XPdhElNHEtnDgYsEVrK2JoCF9zszb7hSCihDbUQUqy33C5ED092u+REURX6Be7ESM0Jwvq9voNIbRR1CHa2mBqKmj7iBF6/jis8GcrurthZATsdmyXLkFODkxNIZzOoO0jQmj5Digr8ht6QQ4HtooKbCUlgO4CWLDshSashDNHA7ZwOgMl+vfRoqTnMAhNSZKe539zqFq3Zg4PGycdjwdx9SqiT7f51U9SOgxCs9Jh62YV6S6MlGQ4tt9vCIGvpcUYYLdDVZX2H9VhGHU/ptLV7xWXmt1l2kYd0EbJ6sbA5zOvoV4v4vZtg8skdGcxXDsH2ZnS8l0wO4p0Rn+/OWB2FtHUBB6P6ZQYGDDYlp/IzfHiNXz6suA8/5uCPCiYe6LodiN6e8NuaystheLigB3/jDXKiB2hbwaXOoXF4Q+zd/VUlZcBewAAAABJRU5ErkJggg==) indicating the sub-playbook is not ready to use, click the playbook to open its Task Details pane.
2. In the error message, click the **Open it** link to view the sub-playbook in a new tab in the playbook editor.
3. Scroll through the sub-playbook. If there is a task that requires integration setup, click the task to open the **Task Details** pane and click the **Create an instance now** link.
4. In the integration instance settings pane, enter values for the settings fields.
5. Click **Save & Exit** for the integration instance.
   {% endstep %}

{% step %}
Configure the sub-playbook.

1. In your main playbook editor, click the sub-playbook you added. The **Task Details** pane opens.
2. Click the **Open sub-playbook** link to open the sub-playbook in a new tab. You can then view and edit its tasks.
3. Click the curly brackets next to the sub-playbook name to select the data source.
4. Configure the sub-playbook settings from the following tabs.

| Tab           | Settings                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| ------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Inputs        | Any required input arguments for the sub-playbook.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Outputs       | Any outputs defined for the sub-playbook.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Advanced      | <ul><li><strong>Register as case timeline record</strong>: If enabled, the results of the sub-playbook execution appear as a record in the case timeline. If enabled, you must enter a <strong>Record name.</strong> You have the option of adding an <strong>Effective time</strong>, <strong>Description</strong>, <strong>Tags</strong>, and marking the record as evidence and adding an evidence comment.<br>NOTE: Only enter an <strong>Effective time</strong> if you want the same exact time recorded every time the sub-playbook executes.</li><li>Skip this branch if this script/playbook is unavailable</li><li>Quiet Mode: Determines whether this task uses the playbook default setting for quiet mode. When in quiet mode, tasks do not display inputs and outputs or extract indicators. Errors and warnings are still documented. You can turn quiet mode on or off at the task or playbook level.</li></ul>                                                                                                                                                                                                                                                                                                                                                                 |
| Loop          | <p>Click one of the following options to define loop settings:</p><ul><li>None: (Default) The sub-playbook does not loop.</li><li><p>Built-in: Use built-in functions to define loop settings:</p><ul><li>Exit when: Enables you to define when to exit the loop. Click {} and expand the source category. Hover over the required source and click <strong>Filter & Transform</strong> to the left of the source to manipulate the data.</li><li>Equals (String): Select the operator to define how the values should be evaluated.</li><li><p>Max Iterations: The number of times the loop should run.</p><p>Balance between the number of iterations and the interval so you do not overload the server.</p></li><li><p>Sleep: The number of seconds to wait between iterations.</p><p>We recommend that you balance between the number of iterations and the number of seconds to wait between iterations so you don't overload the server.<br></p></li></ul></li><li>For each input: Runs the sub-playbook based on defined inputs. Enter the number of seconds to wait between iterations.</li><li>Choose Loop automation: Select the automation from the drop-down list to define when to exit the loop. The parameters that appear are applicable to the selected automation.</li></ul> |
| Details       | Task description (Markdown supported): Displays a description for this playbook (if one exists).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| Timers        | <ul><li>Timer.start: The trigger for starting to send a message or survey to recipients. You can change this trigger or add a trigger for Timer.stop or Timer.pause. Select the trigger timer field from the drop down.</li><li>Add Trigger: You can add other trigger timer fields from the drop down.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| {% endstep %} |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |

{% step %}
Select whether the outputs of the sub-playbook are Shared globally or Private to sub-playbook (default).
{% endstep %}

{% step %}
Click **OK**.
{% endstep %}

{% step %}
Connect the sub-playbook you've added by dragging and dropping a wire.
{% endstep %}
{% endstepper %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/automations/playbooks/build-your-playbook/add-objects-from-the-task-library/add-sub-playbooks.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
