Skip to main content

AI Agents: Bring Adaptive Intelligence Across Torq

Add AI Agents to bring intelligence and smarter decisions to every part of Torq.

Overview

AI Agents are specialized, customizable intelligence units that operate across the entire Torq platform. They are not limited to workflows. AI Agents power Socrates conversations, enrich and reason over cases in Case Management, contribute to Auto Triage decisions, and can be invoked as tools inside other agents, creating composable multi-agent systems.

AI Agents are first-class platform entities with their own lifecycle: create, configure, publish, update, and delete. Once published, an agent is available across Auto Triage, Case Management, Socrates, security automations, and future Torq experiences without additional setup. All agents are managed from a centralized page that gives full workspace visibility into every agent: its status, where it is used, and execution history.

Key benefits

AI Agents are built for tasks that require judgment, not just execution.

  • Mission-driven behavior: Define the AI Agent’s objective using a natural-language mission statement. This tells the Agent what it’s meant to do, whether it’s summarizing alerts, drafting responses, prioritizing incidents, or triaging complex cases.

  • Platform-wide reach: A published agent is immediately available across Auto Triage, Case Management, Socrates, and security automation workflows. The same agent logic runs consistently wherever it is invoked.

  • Model flexibility: Choose from a list of supported AI models (e.g., OpenAI, Google Gemini, or your AI model subscription), allowing users to tailor performance, cost, and data privacy to their organization’s needs.

  • Socrates Agents: Create custom agent roles that power Socrates with behavior tailored to your team's workflows and use cases. Once published, the agent is available to interact with directly. Select it from the agent picker in Socrates to start a chat. See Socrates Builder: Build Workflows and AI Agents.

  • AI tools: Agents call tools dynamically during execution to interact with external systems, process data, or trigger follow-up automations. Available tool types:

    • Steps: Individual automation steps.

    • Cases: Actions within a case.

    • Workflows: Full security automations, such as a predefined phishing remediation workflow.

    • Agents: Published AI Agents invoked as tools, inside other agents or Socrates, enabling composable, multi-agent systems natively within Torq.

    • Utilities: Built-in utility steps for data transformations, such as Array or String.

    • Private: Integration steps scoped to actions not publicly shared in the integration catalog. Browse by vendor and select the steps to expose to the agent.

    • MCP: Tools discovered from connected MCP servers via the Model Context Protocol.

Socrates Agents

AI Agents published in Torq are available directly inside Socrates conversations. When starting or switching a conversation, an agent picker surfaces all agents available in the workspace: system agents (Investigator and Agentic Builder) and any custom agents your team has published.

Once selected, the chosen agent's persona, instructions, tools, and knowledge govern the entire conversation. Agents can be switched mid-session without losing conversation history.

This makes every published agent immediately accessible for real-time, conversational interaction. Examples of how teams use Socrates Agents:

  • Cloud Investigator: Purpose-built with cloud tool integrations and cloud-specific runbooks for investigating AWS, GCP, and Azure environments conversationally.

  • CTI Analyst: Configured with threat intelligence tools and MITRE ATT&CK lookups to enrich IOCs and produce structured outputs like TTPs and detection recommendations.

  • Identity Investigator: Tuned for identity investigations, querying IdP logs, correlating user activity across SaaS applications, and surfacing lateral movement indicators.

  • SIEM Querier: Translates plain-language requests into SIEM queries, executes them, and returns results without requiring raw query syntax.

Custom agents built by your team appear in the picker automatically once published, with no additional configuration required.

Execution transparency

Every action taken by an AI Agent in Torq can be traced and understood:

  • Complete transparency into decision-making: Inspect instructions, tool selections, and the execution Action Flow to understand why the agent reasoned and acted the way it did.

  • Real-time streaming: Watch AI Agent actions as they happen. Open the Action Flow view during execution to stream operations live, including decisions, tool calls, and outputs.

  • Auditable records: All inputs, outputs, and interactions are logged and preserved for review and validation at any time.

  • Human-readable insights: Torq surfaces context, rationales, and step-by-step activity so users remain in control.

  • Guardrails and constraints: Clear behavioral guidelines ensure agents operate within your organization's policies and boundaries.

Bring Your Own Subscription (BYOS)

Torq supports Bring Your Own Subscription (BYOS) for AI models, giving organizations control over model selection, cost, and data privacy. For details, see AI Models: Bring Your Own Subscription (BYOS).

Templates and custom AI Agents

Torq empowers security teams to build and customize AI Agents that handle key SOC tasks, from enrichment and analysis to end-user interaction.

Agent templates

Agent templates are preconfigured AI Agents designed to automate and streamline common security operations use cases out of the box. Torq provides a wide range of templates, each with a predefined role, purpose, and basic configuration, which you can further adapt or extend to fit your environment. Below are some examples of available templates.

End User Interviewer

Delivers structured end-user interviews. The End User Interviewer is an AI Agent that guides users through clear, friendly Q&A to validate suspicious activity and security alerts. It helps SOC teams collect accurate, consistent incident context with minimal effort by generating ready-to-use interview transcripts.

VirusTotal IOC Enricher

Enhances incident context by enriching Indicators of Compromise (IOCs) through the VirusTotal API. For educational and analytical purposes, this agent automatically extracts IOCs from alerts and enriches them with VirusTotal data. It provides deeper visibility into threat context, helping analysts assess and prioritize alerts more efficiently.

SOC Posture Report Generator

Delivers daily operational summaries and insights directly within Slack. The SOC Posture Report Generator is an AI Agent that tracks and summarizes case activity, produces actionable insights, and highlights emerging trends. It helps SOC leads and CISOs stay informed with minimal effort by providing daily updates.

Custom agents

A custom agent is created from the workflow canvas or directly from the AI Agents hub, either from scratch or by starting from a template. Use Build with Socrates for a guided experience: Socrates works through the agent's configuration by asking questions and builds it automatically. For full manual control, open the hub editor to define the agent's instructions, tools, model, and parameters yourself. Once published, the agent is available for reuse across workflows, Socrates sessions, and cases.

How to use

AI Agents in Torq are a shared capability across the platform. Build an agent once and use it in Auto Triage enrichment, Socrates sessions, case investigations, and security automations. Agents can also invoke other published agents as tools, enabling multi-agent collaboration within a single workspace.

Migrate agents to the hub

Agents built inside workflows are moving to the AI Agents Hub, where they live in one shared place and can be reused across the workspace. To keep workflows running, migrate each flagged agent to the hub and replace the legacy step on the canvas. For details, see AI Agents: Migrate Workflow Agents to the AI Agents Hub.

Create an agent

Agents can be created from the workflow canvas or directly from the AI Agents page. We recommend using Build with Socrates: it guides you through the agent's role, instructions, tools, and output automatically, and publishes the agent when complete.

  • Build with Socrates from the canvas: Drag New AI Agent onto the canvas, then click Build with Socrates. Socrates opens in Builder mode and guides you through the agent's role, instructions, tools, and output through a series of questions. Once complete, it saves the agent to the hub, publishes it, and replaces the placeholder step with the live agent. For a full walkthrough, see Build an AI Agent with Socrates.

  • Build with Socrates from the AI Agents page: Go to Build > AI Agents, open an existing draft agent or click Create. Then click Build with Socrates in the top bar. Socrates guides you through the agent's role, instructions, tools, and output, and publishes the agent when complete. For a full walkthrough, see Build an AI Agent with Socrates.

  • Create manually from the canvas: Drag New AI Agent onto the canvas, then click Create in AI Agents. The hub editor opens in a new tab for manual configuration.

  • Create from the hub: Go to Build > AI Agents and click Create to open the hub editor directly, without a workflow context.

When configuring an agent, define the following:

  • Define agent properties: Set the agent name, description, model, and availability.

  • Pass parameters: Provide dynamic inputs to control execution and supply runtime context.

  • Add tools: Enable the agent to call integrations and enrich data using external sources.

  • Configure output: Define the response format, such as a structured JSON schema.

  • Test and review: Run the agent and review results in the log. Agents are saved in Draft status until explicitly published.

For a full walkthrough, see AI Agent Setup.

View and manage AI Agents

Go to Build > AI Agents to view, search, and manage all agents in one place.

The page shows every agent in the workspace with its status, AI model, assigned tools, and who created or last modified it. From here, you can edit configurations, review version history, and monitor changes. Before deleting an agent, the platform performs a dependency check and surfaces all automations, sessions, or cases that currently invoke it, preventing accidental breakage.

For more details, see Manage AI Agents.

Additional documentation

Now that you have an overview of AI Agents and how to create, configure, and manage them in the AI Agents hub, explore the following resources to deepen your understanding and improve your implementations:

These guides will help you go from basic setup to confident, advanced usage of AI Agents in Torq.

Did this answer your question?