Create and Modify Playbooks with Hero AI
Use Playbook Building Mode (also called Text to Playbook) to create or change playbook flows on the canvas with natural language. The Playbook Generator Agent applies your prompts to the selected flow or flows.
Starting in Turbine 26.2.0, Playbook Builder v2 added clarifying questions before building and progress detail messages while generation runs.
Starting in Turbine 26.3.0, the agent can edit multiple flows in one requestβselect flows on the canvas or name them in natural language, then review and Accept all or Reject all proposed changes. See Edit Multiple Flows in One Requestο»Ώ. You can still edit a single flow by selecting it on the canvas or naming it in your prompt.
For manual drag-and-drop creation, see How to Create a PlaybookHow to Create a Playbook. For supported operations, limits, and trigger rules, see Playbook Generator Agent ReferencePlaybook Generator Agent Reference.
Choose Your Path
I want to⦠| Start here |
|---|---|
Create the first flow in a new playbook with AI | |
Change an existing flow on the canvas | |
Edit several flows in one Hero AI prompt | |
Accept or reject AI changes across flows | |
Understand what a flow does without editing it | |
Answer agent questions before a build completes | Clarifying Questionsο»Ώ (playbook or component canvas) |
See status messages during generation | |
See what the agent supports (including multi-flow) | Playbook Generator Agent ReferencePlaybook Generator Agent Reference |
Confirm I am in the right Hero AI mode | |
Understand container vs flow when saving | Playbooks OverviewPlaybook Data Model |
Enter Playbook Building Mode
There is no separate Building Mode toggle in settings. The companion enters Playbook Building Mode when Hero AI opens with canvas context (the product knows which playbook and flow you are editing).
How you open Hero AI | Mode | Typical use |
|---|---|---|
Hero AI from the main application toolbar (outside the canvas editor) | General companion | Questions and chat not tied to a specific canvas flow; see Hero AI CompanionHero AI Companion |
Build with Hero AI on the canvas toolbar | Playbook Building Mode | Generate or change flows with the Playbook Generator Agent |
Start building with Hero AI on an empty canvas | Playbook Building Mode | Create the first flow in a new playbook |
Hero AI Companion while a playbook canvas is already open | Playbook Building Mode | Modify or explain the selected flow |
Navigate away from the playbook canvas editor (panel can stay open) | General companion | Building Mode ends; see Hero AI CompanionHero AI Companion |
Steps to Enter Playbook Building Mode
- Open a playbook in the canvas editor (see How to Create a PlaybookHow to Create a Playbook to create one manually first, if needed).
- Do one of the following:
- Click Build with Hero AI on the canvas toolbar, or
- On an empty canvas, click Start building with Hero AI, or
- Open the Hero AI Companion from the playbook canvas.
- Confirm that the companion shows Playbook Building Mode (see below) before you send a build or modify prompt.
What You Should See in Playbook Building Mode
When Building Mode is active, the Hero AI companion typically shows:
- A banner such as Entered Playbook Building Mode or Playbook Building Mode near the top of the panel.
If you open Hero AI only from the main toolbar and do not see Building Mode, you are in the general companion. Open the playbook canvas and use Build with Hero AI or Start building with Hero AI instead.
To stop generation while a playbook is being built, click Cancel on the canvas progress overlay or in the companion when shown. For enable, disable, delete, and trigger rules, see Playbook Generator Agent ReferencePlaybook Generator Agent Reference.
Edit Multiple Flows in One Request
Starting in Turbine 26.3.0, Playbook Builder V3 can apply coordinated edits across more than one flow in a single Hero AI session.
How to Target Multiple Flows
- Open a multi-flow playbook in the canvas editor and enter Playbook Building Mode.
- Do one or both of the following:
- Canvas: Select a flow on the canvas. Unless you name other flows in the prompt, the agent scopes edits to that selection.
- Natural language: Name flows by their titles (for example: "In Enrich Alerts and Notify SOC, add a VirusTotal check after the first action."). Prefer titles over canvas position words such as "the first flow" or "the leftmost flow"βthe agent asks for a title instead of guessing position.
- Send the prompt. Answer any clarifying questions if the agent asks which flows or actions you mean.
- When generation finishes, review the in-chat flow summary (changes grouped by flow with Added / Removed / Modified lines) and the canvas summary footer β see Review and Accept Hero AI Changesο»Ώ.
- Accept all or Reject all, or accept/reject per flow, then Save the playbook.
Example Multi-Flow Prompts
- "Add the same Slack notification step to Triage and Escalate."
- "Disable Legacy Ingest and add a schedule every 15 minutes to Notify SOC."
- "Create a new flow called Archive Closed that runs daily at 02:00 UTC and archives closed cases."
- "Enable all flows." / "Disable all flows." (agent updates each flowβs enabled state)
What Multi-Flow Editing Does Not Change
- You still Save the playbook after accepting changes so container and flow layers persist.
- Record event and playbook button triggers remain limited (filter existing only) β see Playbook Generator Agent ReferencePlaybook Generator Agent Reference.
- The agent cannot connect an action in one flow to an action in another flow (cross-flow edges are not supported).
- Content locking and concurrent-tab rules still apply.
If the same playbook is open in more than one browser tab or window, saves can overwrite each other. See Content Locking and Concurrent Sessions in Playbook Generator Agent Reference.
Review and Accept Hero AI Changes
When Hero AI proposes canvas changes across one or more flows, Turbine shows two related summaries:
Canvas Summary (footer)
A footer panel appears with a title such as Hero AI made changes to 2 flows (or added / removed flow phrasing). For each affected flow it lists Added, Removed, and Modified items. You can:
Action | What it does |
|---|---|
Accept all | Keeps all pending Hero AI changes across the listed flows |
Reject all | Discards all pending Hero AI changes (confirm when prompted) |
Per-flow Accept / Reject | Accept or reject changes for one flow (tooltips: Accept changes to flow / Reject changes to flow) |
Click a change label | Focuses that action or flow on the canvas (removed items are not focusable) |
Use the status labels to decide what to review:
Status | When it appears |
|---|---|
Added | A new action or flow that Hero AI created for this prompt |
Removed | An action or flow that Hero AI removed for this prompt |
Modified | A meaningful change to that action, such as configuration updates or a change to the outgoing edge type (for example, On Success to On Failure) |
When Hero AI only adds or removes an action, the parent action is not listed as Modified solely because its outgoing connection was rewired to the new or next action (same edge type). For example, a prompt such as "Add a logging note component at the end of every flow" should mainly show Added items, not a long list of unchanged parents marked Modified. Review Modified items when the summary shows a real config or edge-type change on that action.
In-Chat Flow Summary
The companion message for that turn can include a collapsible summary by flow with the same Added / Removed / Modified structure. Use it to understand what changed for that prompt; bulk accept/reject remains on the canvas summary.
Accepting changes updates the canvas draft. Save the playbook to persist. If you reject changes and prompt again for the same flow, the agent rebuilds from the current accepted state.
Create a New Flow with Hero AI
- Open a playbook in the canvas editor and enter Playbook Building Mode.
- On an empty canvas, click Start building with Hero AI.
- Describe what you want to build (for example: "Create a playbook that fetches alerts from CrowdStrike every 5 minutes, extracts observables, and enriches them with VirusTotal."). Each new flow must include at least one trigger or action (empty flows are not supported).
- Answer any clarifying questions if the agent asks β see Clarifying Questionsο»Ώ.
- Review progress detail messages and the generated flow β see Progress During Playbook Generationο»Ώ. When the canvas summary appears, also review the canvas and in-chat summariesο»Ώ.
- Iterate with follow-up prompts.
- Save the playbook when you are satisfied so both the flow and container layers persist.
Modify an Existing Flow
- Enter Playbook Building Mode on the playbook canvas.
- Select the flow you want to change on the canvas, name it in the prompt, or @-mention the flow in chat.
- Ask Hero AI to update it (for example: "Add an IP reputation check after the enrichment step and branch if malicious.").
- Answer clarifying questions if prompted.
- Review progress messages and the updated flow. Use Review and Accept Hero AI Changesο»Ώ when the canvas summary appears.
- Save the playbook.
Ask Questions About Existing Flows
The Playbook Generator Agent is not limited to creating or modifying flows. You can also use it to understand what an existing flow does. Open the Hero AI Companion from a playbook canvas in Building Mode and ask questions such as:
- "What does this flow do?"
- "Explain the steps in this playbook."
- "Why would this flow branch at the condition step?"
Hero AI analyzes the selected flow and provides a plain-language explanation, which helps onboard new team members, audit automation logic, or troubleshoot unexpected behavior.
Clarifying Questions
Starting in Turbine 26.2.0, both Playbook Building Mode and Component Building Mode may pause and ask clarifying questions when your prompt needs more detail before it can build or change a flow or component safely.
When they appear:
- After you submit a build or modify prompt in Playbook Building Mode or Component Building Mode
- When the agent needs choices such as trigger type, target system, error handling, or branch behavior
What you see:
- The Hero AI panel shows a brief message that it needs more detail before it can continue building.
- An optional intro message from the agent explains why it paused.
- One question at a time with Question X of Y progress.
- An instruction line: Select one option below (single-select) or Select one or more options below (multi-select).
- Selectable options. Options with descriptions show an info icon; hover for the full description.
- Back, Next, and Save buttons to move through questions and submit answers.
How to respond:
Step | Action |
|---|---|
1 | Read the question and select one or more options |
2 | Click Next to continue, or Save on the last question |
3 | Use Back to change a prior answer |
4 | If Other is available, select it and enter custom text in the main chat input field (required before Next or Save) |
After you click Save, your answers are submitted to the agent and generation continues. A summary of your clarifying answers may appear in the chat history.
You cannot send a new build prompt while clarifying questions are active. Complete or navigate away from the question flow before starting a different request. While clarifying questions are open, the canvas progress overlay may show Waiting for user response with an alert icon instead of the generation sparkle.
Answer clarifying questions with the integration and trigger you actually use in production. Vague answers produce generic flows that need more manual edits.
Progress During Playbook Generation
Starting in Turbine 26.2.0, Text to Playbook shows progress detail status messages on the canvas and in the Hero AI companion while the Playbook Generator Agent works.
Where messages appear:
Location | What you see |
|---|---|
Canvas progress overlay | Up to three rolling status lines with animated dots on the current line and a Cancel button while the agent runs |
Hero AI companion chat | A live progress stack under the assistant message for the current run |
What messages mean:
Message pattern (examples) | What the agent is doing |
|---|---|
Processing prompt | The agent accepted your prompt and is starting the run |
Reading playbook or trigger schemas | Loading current flow structure and trigger configuration |
Reading native action schemas or component | Discovering available actions and connectors |
Building playbook or updating flow steps | Adding or changing actions on the canvas |
Thinking | A detailed in-progress update is underway (canvas overlay only when the underlying hub message exceeds roughly 75 characters) |
Waiting for user response | The agent is waiting for clarifying-question answers in the companion |
A short custom sentence | The agent supplied a specific description for the current tool step |
Messages update in real time. Wording may vary between runs. Long hub messages may display as Thinking on the canvas overlay while the full detail remains in the companion progress stack.
While generation is running:
- Canvas editing and some companion actions are limited until the agent finishes, you cancel, or clarifying questions appear.
- Click Cancel on the canvas overlay to stop the current generation attempt.
- Do not navigate away from the playbook editor if you need to monitor completion.
After generation completes:
- Review the flow on the canvas before saving.
- Use the companion to ask follow-up modify prompts or clarifying questions on the next iteration.
Prompt Tips
- Be explicit about triggers, actions, and data sources.
- Use step placement language (for example, "after [step name]" or "before [step name]").
- Ask for error handling when external integrations are involved.
See Also
- Hero AIHero AI β overview of all Hero AI features and building modes
- Playbook Generator Agent ReferencePlaybook Generator Agent Reference β supported scenarios, multi-flow matrix, limits, and validation notes
- Organizing Playbook in the Canvas β canvas tools (multi-select, Group, cut, copy, paste, and zoom)
- Playbooks OverviewPlaybooks Overview β canvas layout, flows, and data model
- Hero AI CompanionHero AI Companion β general companion (records, reports, tenant questions)
- Test ConsoleTest Console β validate flows after AI changes