---
title: Hero AI
slug: hero-ai
docTags: 
createdAt: 2025-08-11T11:13:45.000Z
---

Use this section to learn what Hero AI is, which Turbine features use it, and where to go for chat, automation building, models, and AI SOC workflows.

**Hero AI** is a **top-level section** in the Turbine User Guide navigation (site root), alongside Quickstart and Documentation.

## What Is Hero AI?

**Hero AI** is Swimlane’s embedded artificial intelligence layer in **Turbine**. It helps security analysts and automation builders work faster by combining **natural-language interaction**, **generative AI in playbooks**, and **specialized agents** that understand your tenant data, records, and automation context.

Hero AI is not a separate product you log into. It is built into Turbine screens you already use: the **Hero AI** toolbar panel, playbook and component canvases, playbook actions, and solution workflows such as [AI SOC](https://docs.swimlane.com/solutions/ai-soc-solution).

For standard deployments, inference uses **Anthropic Claude** on **Amazon Bedrock** in Swimlane’s environment, or **Amazon Bedrock in your organization’s cloud** for dedicated or private-cloud setups. See [Hero AI Models](docId\:C1LdFGRmok-7Z2Nei_28b) for defaults and fallbacks. Account administrators can route inference through [Custom LLM](docId\:Deoy-K3jmcpdm-c-IKRQ4) on **Turbine Cloud** or **Turbine Platform**.

:::hint{type="info"}
Hero AI features are typically behind **feature flags** and require **opt-in** for your tenant. To enable Hero AI, contact Swimlane support. After enablement, users with the right permissions see the **Hero AI** icon in the Turbine toolbar.
:::

## Where Hero AI Appears

Open **Hero AI** from the Turbine toolbar on most pages ([Hero AI Companion](docId\:crQKFVnGpCz_wJ8xtHDs7)). The same panel switches to **building mode** on playbook and component canvases, runs as a **native action** in flows, and powers [AI SOC](https://docs.swimlane.com/solutions/ai-soc-solution) plans and verdicts in Case Management.

For mode names and behavior by screen, see [Hero AI Building Modes](https://docs.swimlane.com/hero-ai#hero-ai-building-modes). Hero only reads data your user can access and fields marked **Visible to Hero AI** — [Hero AI Companion](docId\:crQKFVnGpCz_wJ8xtHDs7).

## Key Capabilities

| Capability                   | What you get                                                                                         | Learn more                                                                                                        |
| ---------------------------- | ---------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------- |
| **Companion chat**           | Docked or full-screen chat on most Turbine screens; record-aware questions                           | [Hero AI Companion](docId\:crQKFVnGpCz_wJ8xtHDs7)                                                                 |
| **Text to Playbook**         | Natural-language create and edit of playbook flows on the canvas                                     | [Create and Modify Playbooks with Hero AI](docId\:TmMNjGlC0e9lIPO37KZPB)                                          |
| **Component building**       | Natural-language create and edit of components in the Component Builder                              | [Create and Modify Components with Hero AI](docId\:ikUKoTgCOrZumuwb-JDsb)                                         |
| **Run components from chat** | Hero selects and runs published components marked **Visible to Hero AI**                             | [How Hero AI Executes Components](docId\:MGZX3dKiIv_vi2MHOynEV)                                                   |
| **In-flow generative AI**    | Prompt-driven outputs inside a playbook step                                                         | [Hero AI Native Action](docId\:C4CKmT7fHXgjBtlXxOOC2)                                                             |
| **Agents**                   | Specialized agents (Playbook Generator, component agents, AI SOC plan and verdict flows, Code Agent) | [Playbook Generator Agent Reference](docId:3JkvN5yplM_U06tfjHiAC), [Hero AI Models](docId\:C1LdFGRmok-7Z2Nei_28b) |
| **Prompting guidance**       | Patterns for reliable prompts in automation and chat                                                 | [Mastering Generative AI Prompting](docId\:jmAIZzc_xEy8ywGlQ6rVO)                                                 |
| **AI SOC**                   | End-to-end SOC package with plans, verdicts, and case workflows                                      | [AI SOC Solution](https://docs.swimlane.com/solutions/ai-soc-solution)                                            |

## Choose Your Path

| I want to…                                                 | Start here                                                                                                                                             |
| ---------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Chat with Hero on any screen                               | [Hero AI Companion](docId\:crQKFVnGpCz_wJ8xtHDs7)                                                                                                      |
| Build or change a playbook flow with AI (Text to Playbook) | [Create and Modify Playbooks with Hero AI](docId\:TmMNjGlC0e9lIPO37KZPB)                                                                               |
| Build or change a component on the canvas with AI          | [Create and Modify Components with Hero AI](docId\:ikUKoTgCOrZumuwb-JDsb)                                                                              |
| Build or change a widget with AI                           | [Build Widgets with Hero AI](docId\:QEu5rG5RnOmE41WK1cxpT)                                                                                             |
| Run a published component from chat                        | [How Hero AI Executes Components](docId\:MGZX3dKiIv_vi2MHOynEV)                                                                                        |
| Use generative AI inside a playbook action                 | [Hero AI Native Action](docId\:C4CKmT7fHXgjBtlXxOOC2)                                                                                                  |
| See default models and fallbacks                           | Native Action defaults to **Claude Haiku 4.5**; Companion and Agents default to **Claude Sonnet 4.5** — [Hero AI Models](docId\:C1LdFGRmok-7Z2Nei_28b) |
| Route Hero AI through your own LLM provider                | [Custom LLM](docId\:Deoy-K3jmcpdm-c-IKRQ4)                                                                                                             |
| Monitor Hero AI usage (credits, prompts, tokens)           | [Hero AI Credits](docId\:FPBH2J8Xm1TfDvEjnc8KB), [Hero AI Prompts](docId\:RV7WVN3wx2Uwa_bCHY7uR), [Hero AI Tokens](docId:8g7pp4ZUIwUisuVyQ32s9)        |
| Write better prompts                                       | [Mastering Generative AI Prompting](docId\:jmAIZzc_xEy8ywGlQ6rVO)                                                                                      |
| Design components Hero can run or build                    | [AI-Friendly Component Best Practices](docId:3pKnx5VXkQsJlLTojRO7b)                                                                                    |
| Use Hero AI in AI SOC investigations                       | [AI SOC Solution](https://docs.swimlane.com/solutions/ai-soc-solution)                                                                                 |
| Watch Hero AI in action                                    | [Hero AI Companion demo](https://swimlane.com/resources/videos/demo-hero-agentic-ai-secops-companion/)                                                 |

## Hero AI Building Modes

When the **Hero AI** panel is open, Turbine picks a **mode** from your current screen. You do not switch modes from a settings menu.

| Where you are                                     | Hero AI mode                | What it does                                                                                                                        |
| ------------------------------------------------- | --------------------------- | ----------------------------------------------------------------------------------------------------------------------------------- |
| Most screens (records, reports, lists, and so on) | **General companion**       | Questions about tenant data, records, reports, and cybersecurity topics; can **run** components marked **Visible to Hero AI**       |
| **Playbook** open in the canvas editor            | **Playbook Building Mode**  | Create or modify flows with the Playbook Generator Agent — [Create and Modify Playbooks with Hero AI](docId\:TmMNjGlC0e9lIPO37KZPB) |
| **Component** open in the Component Builder       | **Component Building Mode** | Create or modify the component on the canvas — [Create and Modify Components with Hero AI](docId\:ikUKoTgCOrZumuwb-JDsb)            |
| **Widget editor** open (record or report widget)  | **Widget Building Mode**    | Edit widget **Code** with the widget builder agent — [Build Widgets with Hero AI](docId\:QEu5rG5RnOmE41WK1cxpT)                     |

For mode switching when you navigate, see [Hero AI Companion](docId\:crQKFVnGpCz_wJ8xtHDs7).

:::hint{type="info"}
**Playbook Building Mode**, **Component Building Mode**, and **Widget Building Mode** edit automation or widget code on the canvas. [How Hero AI Executes Components](docId\:MGZX3dKiIv_vi2MHOynEV) describes **running** published components from the general companion when **Visible to Hero AI** is enabled — not editing the component definition.
:::

## Hero AI Features

| Feature                                                                   | Description                                                                                          |
| ------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- |
| [Hero AI Companion](docId\:crQKFVnGpCz_wJ8xtHDs7)                         | Agentic AI chat on every page of Turbine                                                             |
| [Create and Modify Playbooks with Hero AI](docId\:TmMNjGlC0e9lIPO37KZPB)  | Text to Playbook and Playbook Building Mode on the canvas                                            |
| [Playbook Generator Agent Reference](docId:3JkvN5yplM_U06tfjHiAC)         | What the Playbook Generator Agent supports and its limits                                            |
| [Create and Modify Components with Hero AI](docId\:ikUKoTgCOrZumuwb-JDsb) | Component Building Mode in the Component Builder                                                     |
| [Build Widgets with Hero AI](docId\:QEu5rG5RnOmE41WK1cxpT)                | Edit record and report widgets with the widget builder agent                                         |
| [How Hero AI Executes Components](docId\:MGZX3dKiIv_vi2MHOynEV)           | Run published components from companion chat                                                         |
| [Hero AI Native Action](docId\:C4CKmT7fHXgjBtlXxOOC2)                     | No-code generative AI in playbook automation                                                         |
| [Hero AI Models](docId\:C1LdFGRmok-7Z2Nei_28b)                            | Native Action default is **Claude Haiku 4.5**; Companion and Agents default to **Claude Sonnet 4.5** |
| [Custom LLM](docId\:Deoy-K3jmcpdm-c-IKRQ4)                                | Route Hero AI through LiteLLM or Custom Bedrock                                                      |
| [Hero AI Credits](docId\:FPBH2J8Xm1TfDvEjnc8KB)                           | Credit consumption and contract usage caps under Admin Panel                                         |
| [Hero AI Prompts](docId\:RV7WVN3wx2Uwa_bCHY7uR)                           | Prompt counts by playbook, component, or user                                                        |
| [Hero AI Tokens](docId:8g7pp4ZUIwUisuVyQ32s9)                             | Token volume by category under Admin Panel                                                           |
| [Mastering Generative AI Prompting](docId\:jmAIZzc_xEy8ywGlQ6rVO)         | Prompt patterns for Hero AI workflows                                                                |
| [AI-Friendly Component Best Practices](docId:3pKnx5VXkQsJlLTojRO7b)       | Naming, inputs, outputs, and AI SOC mapping for components                                           |

## AI SOC Solution

The [AI SOC Solution](https://docs.swimlane.com/solutions/ai-soc-solution) is Swimlane’s end-to-end security operations package powered by Hero AI. It combines alert and phishing triage, threat intelligence enrichment, case management, and automation with Hero AI **investigation plans**, **verdicts**, and analyst workflows in **Case Management**.

:::hint{type="info"}
AI SOC Solution documentation lives in the **Solutions guide** ([AI SOC Solution overview](https://docs.swimlane.com/solutions/ai-soc-solution)). The Turbine User Guide [AI SOC Solution](docId\:pf--Gsd2bMOb0VydARyEi) summarizes why to start with the solution.
:::

### Hero AI in AI SOC

| Hero AI capability   | Where it appears in AI SOC                                                                                                           |
| -------------------- | ------------------------------------------------------------------------------------------------------------------------------------ |
| Investigation plans  | Generated from case context and knowledge base articles; analysts run plan steps from **Case Management**                            |
| Verdicts             | **Generate Verdict** in the Determination phase (Malicious, Suspicious, Benign, Unknown)                                             |
| Companion and agents | Same Hero AI models as Companion and agent workflows; see [Hero AI Models](docId\:C1LdFGRmok-7Z2Nei_28b)                             |
| Component selection  | AI SOC selects and maps components from investigation plans; see [AI-Friendly Component Best Practices](docId:3pKnx5VXkQsJlLTojRO7b) |
| Ingestion builder    | **AI Ingestion** workspace uses Hero AI–assisted Turbine Schema mapping for new alert sources                                        |

### Choose Your Path (AI SOC)

| I want to…                                   | Start here                                                                                                                   |
| -------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- |
| Overview of the solution and package         | [AI SOC Solution](https://docs.swimlane.com/solutions/ai-soc-solution)                                                       |
| Install and configure Hero AI for AI SOC     | [Installing and Configuring AI SOC Solution](https://docs.swimlane.com/solutions/installing-and-configuring-ai-soc-solution) |
| Run my first investigation                   | [Getting Started (AI SOC)](https://docs.swimlane.com/solutions/getting-started)                                              |
| Understand how Hero AI produces verdicts     | [Understanding Verdict Generation](https://docs.swimlane.com/solutions/understanding-verdict-generation)                     |
| Follow investigation plan workflows          | [Investigation Plan Workflow](https://docs.swimlane.com/solutions/investigation-plan-workflow)                               |
| Learn case layout and AI Analysis widget     | [AI SOC Applications](https://docs.swimlane.com/solutions/ai-soc-applications)                                               |
| Design components for plan and verdict flows | [AI-Friendly Component Best Practices](docId:3pKnx5VXkQsJlLTojRO7b)                                                          |

Additional Hero AI capabilities in solutions and marketplace content:

- [Clear summarization and recommended actions in the Case and Incident Management application](https://docs.swimlane.com/solutions/configure-custom-case-and-incident-management-data-mappings)
- [Crafted AI Prompts — templates for Hero AI in daily workflows](https://docs.swimlane.com/solutions/crafted-ai-prompts)

## Artificial Intelligence Data Privacy and Security

Swimlane does not collect or store sensitive customer data in centralized storage locations. Only metadata about model usage and performance is retained centrally. Customer data processed by AI or machine learning (ML) models is stored exclusively in the customer’s dedicated database instance, which is logically separated from other customer instances. Prompts and context required for a response are sent to models hosted on Swimlane's AWS Bedrock instance and are not used to train or fine-tune models. Customers must opt in to use Hero AI in their instance of Turbine. Individual risk assessments are conducted on all AI and LLM projects before deployment.

## Next Steps

- New to Hero AI chat → [Hero AI Companion](docId\:crQKFVnGpCz_wJ8xtHDs7)
- Building automation with AI → [Create and Modify Playbooks with Hero AI](docId\:TmMNjGlC0e9lIPO37KZPB)
- Hero AI in security operations → [AI SOC Solution](https://docs.swimlane.com/solutions/ai-soc-solution)
- Manual playbook creation → [How to Create a Playbook](docId:0-KvG5p4LTHw75ItmpUWp)
