Manage actions that can be used by agents.
Actions wrap diverse capabilities (such as playbooks, scripts, AI prompts, and commands) to make them accessible and executable by an agent. You can use out-of-the-box system actions or register new actions.
Note
To manage actions in the Agents Hub, you must have the correct permissions. For more information, see Agentic Assistant role-based access control.
There are two types of actions in the Agents Hub:
System actions: Cortex Cloud contains more than 50 out-of-the-box system actions that can be disabled or enabled, but cannot be edited or deleted.
To find and install additional content packs that include actions, go to Marketplace and select Content pack includes and Actions.
Tip
System actions may rely on content packs that need to be installed and configured.
Custom actions: Users can register existing or new scripts, commands, and AI prompts as actions. Custom actions can be edited, deleted, enabled, or disabled.
Any action marked as sensitive to require user approval requires explicit user approval before execution. This is particularly crucial for operations that might alter system reality or affect an organization’s budget, such as isolating an endpoint or revoking user access. System actions are marked sensitive if they affect system reality. When creating custom actions, you decide which actions should be marked as sensitive for your organization.
The execution of system or custom actions that are based on integration commands can be restricted using integration permissions.
From the Actions tab of the Agents Hub, click for an action to edit, delete, or disable an existing custom action. System actions can be enabled or disabled and you can change them from sensitive to non-sensitive or from non-sensitive to sensitive.
You can use the dropdown filter to search all actions, custom actions, system actions, enabled actions, disabled actions, sensitive actions, or non-sensitive actions. You can also filter by source types: command, script, or playbook.
You can sort actions by creation time or update time.