Manage actions - Manage actions that can be used by agents. - Administrator Guide - Cortex CLOUD

Cortex Cloud Runtime Security Documentation

Product
Cortex Cloud Application Security > Cortex CLOUD
License
Cloud Runtime Security
Creation date
2024-12-24
Last date published
2026-06-10
Category
Administrator Guide
Abstract

Manage actions that can be used by agents.

Actions wrap diverse capabilities (such as playbooks, scripts, AI prompts, and commands) to make them accessible and executable by an agent. You can use out-of-the-box system actions or register new actions.

Note

To manage actions in the Agents Hub, you must have the correct permissions. For more information, see Agentic Assistant role-based access control.

There are two types of actions in the Agents Hub:

  • System actions: Cortex Cloud contains more than 50 out-of-the-box system actions that can be disabled or enabled, but cannot be edited or deleted. 

    To find and install additional content packs that include actions, go to Marketplace and select Content pack includes and Actions.

    Tip

    System actions may rely on content packs that need to be installed and configured.

  • Custom actions: Users can register existing or new scripts, commands, and AI prompts as actions. Custom actions can be edited, deleted, enabled, or disabled.

Any action marked as sensitive to require user approval requires explicit user approval before execution.  This is particularly crucial for operations that might alter system reality or affect an organization’s budget, such as isolating an endpoint or revoking user access. System actions are marked sensitive if they affect system reality. When creating custom actions, you decide which actions should be marked as sensitive for your organization.

The execution of system or custom actions that are based on integration commands can be restricted using integration permissions.

Manage existing actions

From the Actions tab of the Agents Hub, click three-dots.png for an action to edit, delete, or disable an existing custom action. System actions can be enabled or disabled and you can change them from sensitive to non-sensitive or from non-sensitive to sensitive.

Search, filter, and sort actions

You can use the dropdown filter to search all actions, custom actions, system actions, enabled actions, disabled actions, sensitive actions, or non-sensitive actions. You can also filter by source types: command, script, or playbook.

You can sort actions by creation time or update time.