Workflows Overview

Prev Next

Introduction

Workflows in SAFE help you automate repetitive CTEM activities across your findings and assets. Instead of manually reviewing findings, creating tickets, creating exceptions, or generating reports each time, you can configure a workflow once and allow SAFE to perform those actions automatically based on a schedule or supported event.

With Workflows for CTEM, you can automate common activities such as:

  • Generating scheduled findings or asset reports

  • Creating tickets automatically for findings matching defined criteria

  • Creating exceptions for findings matching defined criteria

  • Sending generated reports through email

  • Looking up tickets and exceptions created earlier in a workflow

  • Applying conditions and branching logic to determine what a workflow should do next

SAFE provides a visual, drag-and-drop workflow builder along with workflow management capabilities such as Draft, Live, Archive, Starred, search, tags, notes, duplication, version history, Run Now, and JSON download.

Accessing Workflows

To access Workflows:

  1. From the left navigation, select Agentic Workflows.

  2. The Workflows page displays the workflows available for your organization.

  3. If Agentic Workflows does not appear in the navigation or you do not see the expected CTEM nodes, contact your SAFE administrator.

Understanding First-Party and Third-Party Workflows

In environments using both CTEM and TPRM, SAFE separates workflows according to their applicability. A single workflow cannot contain both CTEM and TPRM-specific nodes.

For example, if you need automation for both first-party findings and third-party activities, create two separate workflows. SAFE prevents a workflow containing both CTEM and TPRM nodes from being saved.

Create a Workflow

You can create a workflow either:

  • From Scratch,

  • From Template, or

  • By importing a workflow file

Recommended Workflows option is not available in the CTEM workflow creation flow.

To build a workflow from scratch:

  1. Navigate to Agentic Workflows.

  2. Select the option to create a workflow.

  3. Select From Scratch or form a Temaplate.

  4. Enter the Name and Description.

  5. Add a trigger to define when the workflow should execute.

  6. Add the required action nodes to the workflow canvas.

  7. Connect the nodes in the sequence in which they should execute.

  8. Configure each node.

  9. Save the workflow.

  10. Review the workflow configuration and make it Live when it is ready for use.

  11. You can also use Run Now to execute a workflow manually when you need to test or immediately run the configured automation.

CTEM Workflow Nodes

A workflow is built using nodes. Each node performs a particular activity or controls how the workflow progresses.

The CTEM nodes include:

Node

What It does

Create Ticket

Creates tickets from a findings filter, using a saved ticketing rule

Create Exception

Accepts risk or marks false-positive on findings from a filter

Generate Report

Requests a CSV findings or asset report and waits for it to be ready

Get Ticket by ID / Get Exception by ID

Reads back a ticket or exception, usually one an earlier node created

Send Email

Existing node; the template list it offers is now use-case scoped

On Schedule

Manage Your Workflows

The Workflows page provides different views to help organize workflows:

  • All

  • Live

  • Draft

  • Archive

  • Starred

You can also:

  • Search workflows

  • Edit a workflow

  • Delete a workflow

  • Duplicate a workflow

  • Star frequently used workflows

  • Add tags

  • Add notes

  • View version history

  • Download a workflow as JSON

  • Run a workflow immediately using Run Now

  • Group workflows by status or applicability

For environments containing both First-Party and Third-Party use cases, workflows also display their applicability.