Overview
AI Agents are specialized, customizable intelligence units that operate across the entire Torq platform. They are not limited to workflows. AI Agents power Socrates conversations, enrich and reason over cases in Case Management, contribute to Auto Triage decisions, and can be invoked as tools inside other agents, creating composable multi-agent systems.
AI Agents are first-class platform entities with their own lifecycle: create, configure, publish, update, and delete. Once published, an agent is available across Auto Triage, Case Management, Socrates, security automations, and future Torq experiences without additional setup. All agents are managed from a centralized page that gives full workspace visibility into every agent: its status, where it is used, and execution history.
Key benefits
AI Agents are built for tasks that require judgment, not just execution.
Mission-driven behavior: Define the AI Agent’s objective using a natural-language mission statement. This tells the Agent what it’s meant to do, whether it’s summarizing alerts, drafting responses, prioritizing incidents, or triaging complex cases.
Platform-wide reach: A published agent is immediately available across Auto Triage, Case Management, Socrates, and security automation workflows. The same agent logic runs consistently wherever it is invoked.
Model flexibility: Choose from a list of supported AI models (e.g., OpenAI, Google Gemini, or your AI model subscription), allowing users to tailor performance, cost, and data privacy to their organization’s needs.
Socrates Agents: Create custom agent roles that power Socrates with behavior tailored to your team's workflows and use cases. Once published, the agent is available to interact with directly. Select it from the agent picker in Socrates to start a chat. See Socrates Builder: Build Workflows and AI Agents.
AI tools: Agents call tools dynamically during execution to interact with external systems, process data, or trigger follow-up automations. Available tool types:
Steps: Individual automation steps.
Cases: Actions within a case.
Workflows: Full security automations, such as a predefined phishing remediation workflow.
Agents: Published AI Agents invoked as tools, inside other agents or Socrates, enabling composable, multi-agent systems natively within Torq.
Utilities: Built-in utility steps for data transformations, such as Array or String.
Private: Integration steps scoped to actions not publicly shared in the integration catalog. Browse by vendor and select the steps to expose to the agent.
MCP: Tools discovered from connected MCP servers via the Model Context Protocol.
Socrates Agents
AI Agents published in Torq are available directly inside Socrates conversations. When starting or switching a conversation, an agent picker surfaces all agents available in the workspace: system agents (Investigator and Agentic Builder) and any custom agents your team has published.
Once selected, the chosen agent's persona, instructions, tools, and knowledge govern the entire conversation. Agents can be switched mid-session without losing conversation history.
This makes every published agent immediately accessible for real-time, conversational interaction. Examples of how teams use Socrates Agents:
Cloud Investigator: Purpose-built with cloud tool integrations and cloud-specific runbooks for investigating AWS, GCP, and Azure environments conversationally.
CTI Analyst: Configured with threat intelligence tools and MITRE ATT&CK lookups to enrich IOCs and produce structured outputs like TTPs and detection recommendations.
Identity Investigator: Tuned for identity investigations, querying IdP logs, correlating user activity across SaaS applications, and surfacing lateral movement indicators.
SIEM Querier: Translates plain-language requests into SIEM queries, executes them, and returns results without requiring raw query syntax.
Custom agents built by your team appear in the picker automatically once published, with no additional configuration required.
Execution transparency
Every action taken by an AI Agent in Torq can be traced and understood:
Complete transparency into decision-making: Inspect instructions, tool selections, and the execution Action Flow to understand why the agent reasoned and acted the way it did.
Real-time streaming: Watch AI Agent actions as they happen. Open the Action Flow view during execution to stream operations live, including decisions, tool calls, and outputs.
Auditable records: All inputs, outputs, and interactions are logged and preserved for review and validation at any time.
Human-readable insights: Torq surfaces context, rationales, and step-by-step activity so users remain in control.
Guardrails and constraints: Clear behavioral guidelines ensure agents operate within your organization's policies and boundaries.
Bring Your Own Subscription (BYOS)
Torq supports Bring Your Own Subscription (BYOS) for AI models, giving organizations control over model selection, cost, and data privacy. For details, see AI Models: Bring Your Own Subscription (BYOS).
Templates and custom AI Agents
Torq empowers security teams to build and customize AI Agents that handle key SOC tasks, from enrichment and analysis to end-user interaction.
Agent templates
Agent templates are preconfigured AI Agents designed to automate and streamline common security operations use cases out of the box. Torq provides a wide range of templates, each with a predefined role, purpose, and basic configuration, which you can further adapt or extend to fit your environment. Below are some examples of available templates.
End User Interviewer
Delivers structured end-user interviews. The End User Interviewer is an AI Agent that guides users through clear, friendly Q&A to validate suspicious activity and security alerts. It helps SOC teams collect accurate, consistent incident context with minimal effort by generating ready-to-use interview transcripts.
VirusTotal IOC Enricher
Enhances incident context by enriching Indicators of Compromise (IOCs) through the VirusTotal API. For educational and analytical purposes, this agent automatically extracts IOCs from alerts and enriches them with VirusTotal data. It provides deeper visibility into threat context, helping analysts assess and prioritize alerts more efficiently.
SOC Posture Report Generator
Delivers daily operational summaries and insights directly within Slack. The SOC Posture Report Generator is an AI Agent that tracks and summarizes case activity, produces actionable insights, and highlights emerging trends. It helps SOC leads and CISOs stay informed with minimal effort by providing daily updates.
Custom agents
A custom agent is created from the workflow canvas or directly from the AI Agents hub, either from scratch or by starting from a template. Use Build with Socrates for a guided experience: Socrates works through the agent's configuration by asking questions and builds it automatically. For full manual control, open the hub editor to define the agent's instructions, tools, model, and parameters yourself. Once published, the agent is available for reuse across workflows, Socrates sessions, and cases.
How to use
AI Agents in Torq are a shared capability across the platform. Build an agent once and use it in Auto Triage enrichment, Socrates sessions, case investigations, and security automations. Agents can also invoke other published agents as tools, enabling multi-agent collaboration within a single workspace.
Migrate agents to the hub
Agents built inside workflows are moving to the AI Agents Hub, where they live in one shared place and can be reused across the workspace. To keep workflows running, migrate each flagged agent to the hub and replace the legacy step on the canvas. For details, see AI Agents: Migrate Workflow Agents to the AI Agents Hub.
Create an agent
Agents can be created from the workflow canvas or directly from the AI Agents page. We recommend using Build with Socrates: it guides you through the agent's role, instructions, tools, and output automatically, and publishes the agent when complete.
Build with Socrates from the canvas: Drag New AI Agent onto the canvas, then click Build with Socrates. Socrates opens in Builder mode and guides you through the agent's role, instructions, tools, and output through a series of questions. Once complete, it saves the agent to the hub, publishes it, and replaces the placeholder step with the live agent. For a full walkthrough, see Build an AI Agent with Socrates.
Build with Socrates from the AI Agents page: Go to Build > AI Agents, open an existing draft agent or click Create. Then click Build with Socrates in the top bar. Socrates guides you through the agent's role, instructions, tools, and output, and publishes the agent when complete. For a full walkthrough, see Build an AI Agent with Socrates.
Create manually from the canvas: Drag New AI Agent onto the canvas, then click Create in AI Agents. The hub editor opens in a new tab for manual configuration.
Create from the hub: Go to Build > AI Agents and click Create to open the hub editor directly, without a workflow context.
When configuring an agent, define the following:
Define agent properties: Set the agent name, description, model, and availability.
Pass parameters: Provide dynamic inputs to control execution and supply runtime context.
Add tools: Enable the agent to call integrations and enrich data using external sources.
Configure output: Define the response format, such as a structured JSON schema.
Test and review: Run the agent and review results in the log. Agents are saved in Draft status until explicitly published.
For a full walkthrough, see AI Agent Setup.
View and manage AI Agents
Go to Build > AI Agents to view, search, and manage all agents in one place.
The page shows every agent in the workspace with its status, AI model, assigned tools, and who created or last modified it. From here, you can edit configurations, review version history, and monitor changes. Before deleting an agent, the platform performs a dependency check and surfaces all automations, sessions, or cases that currently invoke it, preventing accidental breakage.
For more details, see Manage AI Agents.
Additional documentation
Now that you have an overview of AI Agents and how to create, configure, and manage them in the AI Agents hub, explore the following resources to deepen your understanding and improve your implementations:
Manage AI Agents: View, manage, publish, and monitor all agents in your workspace from one place.
AI Agent Setup: Configure an agent's instructions, model, tools, output schema, and parameters.
AI Agent Instructions: Learn how to define your AI Agent’s role, goal, and scope in natural language.
Build an AI Agent with Socrates: Learn how to create and configure an AI Agent using Socrates Builder.
Use Case: Post-Verdict Investigation with AI Agents: Walk through a real-world example to see how AI Agents are used in a complete workflow.
Migrate Workflow Agents to the AI Agents Hub: Move agents from individual workflows to the hub for shared, reusable access across the platform.
Bring Your Own Subscription (BYOS): Learn how to use your own AI provider subscriptions to power agents with the models, pricing, and compliance controls that fit your organization.
AI Agent FAQs: Find answers to common questions around capabilities, guardrails, and troubleshooting.
These guides will help you go from basic setup to confident, advanced usage of AI Agents in Torq.


