Skip to main content

Runbooks in Torq Cases: Standardize Investigation Management

Learn how to use and manage runbooks in Torq for efficient and standardized investigations.

Overview

A runbook associated with a case provides analysts with step-by-step investigative guidance, helping keep cases consistent with organizational standards.

You can also manage runbooks automatically using steps in a workflow.

How to use

Access a case runbook

  1. Navigate to the case: Open the Cases page and select the relevant case.

  2. Select the Runbook tab: Click the Runbook tab within the full case view.

    • If a runbook is associated with the case, the content and instructions will be displayed here.

    • If no runbook is linked, you'll have the option to associate one.

    • For Socrates-assigned cases, you can generate an Actionplan from the Runbooks page.

Manage runbooks in the Runbooks page

Use the Investigate > Runbooks page to view and manage all the runbooks available in your workspace. ​

Search, filter, create, edit, and delete runbooks from the Runbooks page

  • Search for runbooks: Search by title or ID using the search bar.

  • Filter runbooks: Filter by Created date, Creator, Last editor, Last updated date, Source, or Locked/Unlocked.

  • Add a new runbook:

    1. Click Create to write a new runbook.

    2. Enter a descriptive title.

    3. Enter runbook instructions directly in the editor, or paste from elsewhere.

  • Edit runbooks: Open the runbook and make changes directly in the editor. Click Save to confirm your changes.

    • Locked runbooks cannot be edited manually on the Runbooks page—they must be unlocked with the Update a runbook step in a workflow. Once unlocked, they can be edited from the Runbooks page.

  • Delete runbooks: Open the runbook and click the trashcan icon in the top right.

Runbook editor

Locked runbooks cannot be edited in the Runbooks page and must first be unlocked using the Update a runbook step in a workflow. Once unlocked, they can be edited from the Runbooks page.

Learn how to automate runbook management using runbook steps.

On the Runbooks page, select a runbook to open the editor. Click the runbook title to edit it in rich text. The top menu bar shows all users currently viewing the runbook.

Runbooks created by workflows can be in Markdown, HTML, or plain text, and appear in the editor in rich text. Runbooks created or edited in the editor are saved as HTML.

Editing or deleting a runbook affects every case it is associated with. Deleting a runbook cannot be undone.

Did this answer your question?