Overview
AI Agents operate autonomously, using deterministic workflows as tools to carry out tasks with precision and consistency. Once set up, an agent runs on its own, using its tools, analyzing context, and taking the actions needed to reach its goal, whether that means executing a task or making a smart decision.
How to use
Agents can be created from the workflow canvas or directly from the AI Agents page. Two creation paths are available from either entry point: Build with Socrates for a guided experience, or Create in AI Agents for manual configuration.
From the canvas
Open the AI Agents panel: In the step picker, select AI Agents.
Drag onto the canvas: Drag New AI Agent onto the canvas to place a new agent step.
Choose a creation path: Click the placeholder step to select it. Two options appear above it:
Build with Socrates: Socrates guides you through defining the agent's instructions, tools, and configuration. Once complete, it saves the agent, publishes it, and replaces the placeholder step with the live agent. See Build an AI Agent with Socrates.
Create in AI Agents: Opens the AI Agents page to define the agent's instructions, tools, model, and parameters manually. Continue with the steps below.
From the AI Agents page
Open the hub: Go to Build > AI Agents.
Choose a creation path:
Create manually: Click Create in the top-right corner. A new agent opens in Draft state. Continue with the steps below.
Build with Socrates: Open an existing Draft agent or click Create, then click Build with Socrates in the top bar. See Build an AI Agent with Socrates.
Editor interface
The agent editor is where you configure the agent manually. It is split into two panels: the left panel is where you define the agent's instructions, and the right panel provides access to the following tabs.
Properties: Configure the agent's name, description, subscription, AI model, and availability.
Params: Define dynamic input parameters passed to the agent at runtime.
Tools: Add and configure the tools available to the agent during execution.
Output: Define the agent's output JSON schema.
Log: View a complete picture of the agent's execution, including inputs, outputs, reasoning, and tool calls.
Define agent instructions
Define the agent's behavior in the Instructions panel. For guidance on writing effective instructions, see AI Agent Instructions: Writing a Mission Statement.
Fill out the instructions: Complete the sections relevant to your agent:
Role: Define the agent's persona (for example, "security analyst" or "support engineer").
Supported scenario: Define the specific use case or situation in which the agent is expected to operate.
Behavior guidelines: Provide structured instructions that define how the agent should act, communicate, and make decisions, including tone, reasoning style, interaction patterns, and safety boundaries.
Context: Provide relevant context from earlier steps or external sources (for example, ticket descriptions, threat data, or user information).
(Optional) Reference a parameter: Type @ anywhere in the Instructions panel to open the parameter picker and insert a parameter reference inline. At runtime, the agent replaces each reference with the value passed by the caller. To define the parameters available for selection, see Define parameters below.
Toggle Show markdown to switch the Instructions panel between a formatted preview and the raw markdown source. Use the formatted view to review how the instructions will render, and the markdown view to edit the source directly.
Configure agent properties
Define the agent's identity and model configuration in the Properties tab.
Name: Enter a unique name for the agent.
(Optional) Description: Add a brief description of the agent's purpose (up to 500 characters).
Subscription: Choose the subscription to use, either Torq's default model or a custom AI subscription added through provider integrations.
AI model: Choose the AI model the agent will use to make decisions. The following models are available with Torq's default subscription:
GPT-5
GPT-5 Mini
GPT-5 Nano
GPT-5.1
GPT-5.2
GPT-5.4
GPT-5.4 Mini
GPT-5.4 Nano
Gemini 2.5 Pro
Gemini 2.5 Flash
Gemini 2.5 Flash Lite
Agent availability: Select where the agent can be invoked. Check Workflows to make it available in the workflow builder. Check Socrates to make it available in the Socrates chat interface.
Define parameters
Parameters allow agents to accept dynamic runtime inputs, making them reusable across different contexts and workflows. Instead of hardcoding values into agent instructions, you define a parameter schema that callers (workflows, Socrates, the API, or other agents) use to pass the right inputs at invocation time. Defined parameters can be referenced directly within the agent's instructions using double-brace syntax: {{parameter_name}}.
Create a parameter: In the Params tab, click + Create and configure the following fields:
Name: Enter a unique name for the parameter using
snake_case(for example,incident_id,target_email). This is the key used to reference the parameter in instructions and API calls.Type: Select the parameter type: Short text, Long text, JSON, Integration, Number, Integer, Boolean, or Array.
(Optional) Description: Add a human-readable explanation of what the parameter represents, shown to callers in the workflow builder.
(Optional) Default value: Set a fallback value used when no input is provided at invocation time.
Required: Toggle on to make the parameter mandatory. Required parameters must have a value for the agent to run.
A maximum of 20 parameters is supported per agent. Parameter names must be unique within the agent. Changing a required parameter to optional, or removing a parameter entirely, is considered a breaking change; the platform will warn you and surface a list of affected workflows and callers before you publish.
Reference a parameter in instructions
Once a parameter is defined, reference it in the Instructions panel.
Place the cursor: Click in the Instructions panel where the parameter value should appear.
Type @: Open the parameter picker.
Select the parameter: Choose the parameter from the list.
The reference is inserted inline. At runtime, the agent replaces each reference with the value passed by the caller.
Add tools
The Tools tab is where you define what actions the agent can take during execution. Tools are the functional building blocks that allow the agent to interact with external systems, process data, and trigger automations, enabling the agent to assess situations in real time and choose the best action for the task rather than relying on rigid, pre-scripted logic.
Open the tool picker: Click Create to open the Create AI tools dialog. Select a tool type from the left panel.
For each tool type, select a category or vendor from the middle panel to view available tools on the right. Click a tool to select it: a checkmark appears on the card. You can select multiple tools at once. When ready, click Create to add them to the agent's toolbox. To deselect all tools without closing the dialog, click Clear Selection.Steps: Browse integration steps by vendor and select the actions you want the agent to be able to take.
Cases: Browse case management steps by category, including Torq Cases, Attachments, Case Lifecycle, Case Linking, etc.
Workflows: Pick a full workflow to make available as a tool. For example, if a SecOps analyst wants their AI Agent to assist with phishing response, select a predefined remediation workflow as an available tool.
Agents: Select a published AI agent from your workspace to use as a tool. The calling agent can invoke it during execution to delegate a specific subtask. For example, passing an enriched alert to a specialized analysis agent. This enables agent chaining, where multiple focused agents work together on a single workflow.
Utilities: Browse built-in utility steps by type (Cryptographic Utils, Math Utils, etc.) to let the agent perform operations like hashing, encoding, or generating values inline.
Private: Browse private integration steps by vendor and select the actions you want to expose to the agent. Private steps work the same way as Steps but are scoped to steps that are not publicly shared in the integration catalog.
MCP: Select tools discovered from connected MCP servers, allowing the agent to invoke vendor-defined tools exposed through the Model Context Protocol. See Model Context Protocol (MCP) tools below for setup details.
Configure tool details: For each tool, provide the following:
Name: A clear, recognizable name for the tool.
Description: A natural-language explanation of what the tool does, when it should be used, and what outcomes it produces. For example, "Use this tool to quarantine phishing emails and notify the SOC." If the agent instructions and a tool description contain conflicting guidance, the tool description takes precedence.
Integration instance (if required): Select the external system connection. If the integration is missing, configure it before continuing. Missing integrations are flagged with a warning icon.
(Optional) Remote runner: Select a registered runner to execute the tool in a specific environment, such as an on-premises network or restricted infrastructure.
(Optional) Parameters: Some tools expose built-in parameters that can be configured directly on the tool. These are distinct from the agent-level parameters defined in the Params tab.
Required parameters must have a value for the tool to run. They can be set by the AI agent, provided as a static value, or mapped from a dynamic reference.
Optional parameters are not mandatory. Disable them by switching them Off. If enabled, configure them the same way as required parameters: AI-decided, static value, or dynamic reference.
Once configured, the agent will autonomously determine whether and when to use each tool during execution.
When the tool type is Agent, the configuration dialog includes an Agent Details panel showing the selected agent's name and description. There is no integration instance or remote runner to configure; the agent runs using its own published configuration. Only the tool Name and Description fields apply.
Model Context Protocol (MCP) tools
MCP tools let Torq AI Agents connect to external platforms using the Model Context Protocol (MCP), enabling agents to discover and invoke vendor-defined capabilities without manual API integration. By acting as MCP clients, AI Agents can reason over tools exposed by supported MCP servers and use them directly in workflows, making it easier to integrate with modern security platforms while relying on interfaces designed specifically for AI-driven automation.
When importing a workflow that includes an AI Agent using an MCP-based tool, the import will succeed even if the relevant MCP server is not connected in the target workspace. However, the MCP server connection will not be created automatically. To ensure MCP-based tools function as expected, you must first connect the required MCP server in the importing workspace.
Supported providers
Users can manually select capabilities from the following MCP providers: GitHub, Wiz, and Splunk.
Requirements
Integrations
The following integrations must be configured in Torq before setting up the corresponding MCP server connection:
GitHub: GitHub
Wiz: Wiz (not Wiz MCP Server)
Splunk: Splunk Enterprise
Network (Splunk only)
When connecting Torq AI Agents to Splunk, outbound traffic from Torq originates from a set of static public IP addresses (CloudNAT IPs). If your Splunk environment restricts API access by source IP, you must allowlist the following addresses:
US instance: 146.148.96.182, 34.72.118.25
EU instance: 35.246.211.3, 34.159.64.155
Adding these IP addresses to Splunk's source IP allowlist lets AI Agents interact with Splunk via MCP.
Connect an MCP server
Add an MCP server connection: Click Connect MCP server to create a new server connection.
Name the MCP server: Enter a clear, friendly name to identify the server in Torq.
Provide the MCP endpoint: Paste the MCP URL for the server (for example,
https://api.githubcopilot.com/mcp/).Select an integration instance: Choose the integration instance that Torq will use to authenticate and communicate with the MCP server.
Save and validate the connection: Click Connect to validate connectivity and make the server's capabilities available to AI Agents. Once connected, Torq displays the list of vendor-specific MCP tools discovered from the server, available for selection and use by AI Agents.
Define output schema
Define the structure of the agent's output in the Output tab. For guidance on structuring agent output effectively, see AI Agent Instructions: Writing a Mission Statement.
(Optional) Define a JSON schema: Specify the JSON schema the agent must follow for its output, ensuring the result is valid JSON and conforms to the JSON Schema specification.
View execution logs
The Log tab provides a complete record of every agent execution, inputs, reasoning, tool calls, and outputs. Use it to verify agent behavior, debug unexpected results, and review what the agent decided to do and why.
The Activity log panel on the right lists all past executions, showing the date, duration, and the user or component that triggered each run. Click any entry to open its Action flow.
Action flow
The Action flow gives a step-by-step breakdown of a single execution. The left panel shows the sequence of steps the agent took, from receiving input, through its reasoning, to any tool calls it made, and finally its output. Steps marked with a green checkmark completed successfully; a red icon indicates a failure.
The right panel shows the data for each step:
Input: The instructions and parameters passed to the agent at the start of execution.
Reasoning: The agent's internal decision-making, including what it assessed and why it chose each action.
Step: The inputs and outputs of each tool call the agent made.
Output: The final result returned by the agent.
Save and publish the agent
Once the agent is configured, save and publish it to make it available across Torq.
Save: Click Save to apply your configuration. Changes take effect the next time the agent runs.
(Optional) Test: Click Test Run to run the agent immediately and verify behavior before publishing.
Review the run: Open the Log tab to inspect the execution flow, validate the agent's reasoning, verify tool selection, and confirm expected behavior.
Publish: Click Publish to make the agent available across Torq, including in workflows, Socrates, and other agents.
Return to the canvas
After publishing, navigate back to the workflow using the breadcrumb at the top of the editor.
Click the workflow name in the breadcrumb at the top of the editor.
Review the canvas: The placeholder step is replaced with the published agent.
AI Agent steps support Execution Options, configured per step instance on the canvas. The same agent can run with different options in different workflows.
Ignore failure: Allows the workflow to continue running if the step fails.
Retry after: Automatically retries the step after a failure.
Discard data: Drops the step's output data after execution.















