AI-augmented workflows
Workflows and Elastic Agent Builder are complementary. Workflows give you deterministic, auditable, event-driven automation: the steps always run in the same order and produce the same kind of result. Elastic Agent Builder agents give you reasoning: the ability to interpret unstructured context, classify signals, and generate natural-language summaries. Combining the two lets you build automation that's both reliable and intelligent.
The integration runs in both directions: a workflow can call an agent as a step, and an agent can trigger a workflow as a tool.
-
Create a workflow using natural language. Describe the automation in the Workflows app or in Agent Chat and review the generated YAML before you save. Refer to Author workflows with natural language and Create skills and workflows in chat. - Call an agent from a workflow. Use the
ai.agentstep to invoke any agent built in Elastic Agent Builder. The agent sees the workflow's data through template variables, performs its reasoning, and returns a response that subsequent steps can act on. Refer to Call Elastic Agent Builder agents from Elastic Workflows for the fullai.agentreference and examples. - Trigger a workflow from an agent. Create a workflow tool in Elastic Agent Builder and assign it to an agent. The agent can then invoke the workflow from a conversation, extracting the needed inputs from the user's message and surfacing the workflow's output in chat.
- Classify and route with AI. Pair
ai.classifywithswitchto send each alert, ticket, or signal down a different branch based on a model's categorization. - Summarize evidence before action. Use
ai.summarizeto turn gathered evidence into a concise summary for a case description, notification body, or reviewer prompt. - Gate AI decisions on human review. Pair AI classification with human-in-the-loop to show the model's output to an analyst before the workflow takes action.
- Send structured prompts to an LLM. Use the
ai.promptstep with any configured AI connector to run classification, extraction, or summarization without going through an agent. - Compose reusable AI building blocks. Extract repeated AI step sequences into a child workflow that parent workflows invoke with
workflow.execute.
- Use agent-from-workflow when the workflow already knows what it's doing and needs AI only to reason over a specific data set. For example, summarizing an alert, classifying severity, or extracting fields from unstructured text.
- Use workflow-from-agent when the user (or another agent) is in a conversation and wants to trigger a deterministic procedure. For example, isolating a host, opening a case, or running a set of enrichment queries.
Step-by-step guides for AI-augmented workflows:
- Classify and route mixed items with AI: Use
ai.classifywithforeachandifto send each item down a different branch based on a model's categorization, and summarize withai.summarize.
- Author workflows with natural language: Create and edit workflows from a plain-language description.
- AI steps reference:
ai.prompt,ai.classify,ai.summarize, andai.agentparameters and output structure. - Composition steps: Invoke child workflows and emit outputs.
- Human-in-the-loop: Pause a workflow for reviewer input.
- Call Elastic Agent Builder agents from Elastic Workflows: End-to-end guide for invoking agents from workflow steps.
- Workflow tools in Elastic Agent Builder: Configure an agent to trigger a workflow.
- Elastic Agent Builder overview: Concepts, tools, and agent types.