Hero AI
Use this section to learn what Hero AI is, which Turbine features use it, and where to go for chat, automation building, models, and AI SOC workflows.
Hero AI is a top-level section in the Turbine User Guide navigation (site root), alongside Quickstart and Documentation.
What Is Hero AI?
Hero AI is Swimlane’s embedded artificial intelligence layer in Turbine. It helps security analysts and automation builders work faster by combining natural-language interaction, generative AI in playbooks, and specialized agents that understand your tenant data, records, and automation context.
Hero AI is not a separate product you log into. It is built into Turbine screens you already use: the Hero AI toolbar panel, playbook and component canvases, playbook actions, and solution workflows such as AI SOC.
For standard deployments, inference uses Anthropic Claude on Amazon Bedrock in Swimlane’s environment, or Amazon Bedrock in your organization’s cloud for dedicated or private-cloud setups. See Hero AI ModelsHero AI Models for defaults and fallbacks. Account administrators can route inference through Custom LLMCustom LLM on Turbine Cloud or Turbine Platform.
Hero AI features are typically behind feature flags and require opt-in for your tenant. To enable Hero AI, contact Swimlane support. After enablement, users with the right permissions see the Hero AI icon in the Turbine toolbar.
Where Hero AI Appears
Open Hero AI from the Turbine toolbar on most pages (Hero AI Companioncompanion chat). The same panel switches to building mode on playbook and component canvases, runs as a native action in flows, and powers AI SOC plans and verdicts in Case Management.
For mode names and behavior by screen, see Hero AI Building Modes. Hero only reads data your user can access and fields marked Visible to Hero AI — Hero AI Companionvisibility settings.
Key Capabilities
Capability | What you get | Learn more |
|---|---|---|
Companion chat | Docked or full-screen chat on most Turbine screens; record-aware questions | Hero AI CompanionHero AI Companion |
Text to Playbook | Natural-language create and edit of playbook flows on the canvas | Create and Modify Playbooks with Hero AICreate and Modify Playbooks with Hero AI |
Component building | Natural-language create and edit of components in the Component Builder | Create and Modify Components with Hero AICreate and Modify Components with Hero AI |
Run components from chat | Hero selects and runs published components marked Visible to Hero AI | How Hero AI Executes ComponentsHow Hero AI Executes Components |
In-flow generative AI | Prompt-driven outputs inside a playbook step | Hero AI Native ActionHero AI Native Action |
Agents | Specialized agents (Playbook Generator, component agents, AI SOC plan and verdict flows, Code Agent) | Playbook Generator Agent ReferencePlaybook Generator Agent Reference, Hero AI ModelsHero AI Models |
Prompting guidance | Patterns for reliable prompts in automation and chat | Mastering Generative AI PromptingMastering Generative AI Prompting |
AI SOC | End-to-end SOC package with plans, verdicts, and case workflows |
Choose Your Path
I want to… | Start here |
|---|---|
Chat with Hero on any screen | Hero AI CompanionHero AI Companion |
Build or change a playbook flow with AI (Text to Playbook) | Create and Modify Playbooks with Hero AICreate and Modify Playbooks with Hero AI |
Build or change a component on the canvas with AI | Create and Modify Components with Hero AICreate and Modify Components with Hero AI |
Build or change a widget with AI | Build Widgets with Hero AIBuild Widgets with Hero AI |
Run a published component from chat | How Hero AI Executes ComponentsHow Hero AI Executes Components |
Use generative AI inside a playbook action | Hero AI Native ActionHero AI Native Action |
See default models and fallbacks | Native Action defaults to Claude Haiku 4.5; Companion and Agents default to Claude Sonnet 4.5 — Hero AI ModelsHero AI Models |
Route Hero AI through your own LLM provider | Custom LLMCustom LLM |
Monitor Hero AI usage (credits, prompts, tokens) | Hero AI CreditsHero AI Credits, Hero AI PromptsHero AI Prompts, Hero AI TokensHero AI Tokens |
Write better prompts | Mastering Generative AI PromptingMastering Generative AI Prompting |
Design components Hero can run or build | AI-Friendly Component Best PracticesAI-Friendly Component Best Practices |
Use Hero AI in AI SOC investigations | |
Watch Hero AI in action |
Hero AI Building Modes
When the Hero AI panel is open, Turbine picks a mode from your current screen. You do not switch modes from a settings menu.
Where you are | Hero AI mode | What it does |
|---|---|---|
Most screens (records, reports, lists, and so on) | General companion | Questions about tenant data, records, reports, and cybersecurity topics; can run components marked Visible to Hero AI |
Playbook open in the canvas editor | Playbook Building Mode | Create or modify flows with the Playbook Generator Agent — Create and Modify Playbooks with Hero AICreate and Modify Playbooks with Hero AI |
Component open in the Component Builder | Component Building Mode | Create or modify the component on the canvas — Create and Modify Components with Hero AICreate and Modify Components with Hero AI |
Widget editor open (record or report widget) | Widget Building Mode | Edit widget Code with the widget builder agent — Build Widgets with Hero AIBuild Widgets with Hero AI |
For mode switching when you navigate, see Hero AI CompanionHero AI Companion — Hero AI Modes and Context.
Playbook Building Mode, Component Building Mode, and Widget Building Mode edit automation or widget code on the canvas. How Hero AI Executes ComponentsHow Hero AI Executes Components describes running published components from the general companion when Visible to Hero AI is enabled — not editing the component definition.
Hero AI Features
Feature | Description |
|---|---|
Hero AI CompanionHero AI Companion | Agentic AI chat on every page of Turbine |
Create and Modify Playbooks with Hero AICreate and Modify Playbooks with Hero AI | Text to Playbook and Playbook Building Mode on the canvas |
Playbook Generator Agent ReferencePlaybook Generator Agent Reference | What the Playbook Generator Agent supports and its limits |
Create and Modify Components with Hero AICreate and Modify Components with Hero AI | Component Building Mode in the Component Builder |
Build Widgets with Hero AIBuild Widgets with Hero AI | Edit record and report widgets with the widget builder agent |
How Hero AI Executes ComponentsHow Hero AI Executes Components | Run published components from companion chat |
Hero AI Native ActionHero AI Native Action | No-code generative AI in playbook automation |
Hero AI ModelsHero AI Models | Native Action default is Claude Haiku 4.5; Companion and Agents default to Claude Sonnet 4.5 |
Custom LLMCustom LLM | Route Hero AI through LiteLLM or Custom Bedrock |
Hero AI CreditsHero AI Credits | Credit consumption and contract usage caps under Admin Panel |
Hero AI PromptsHero AI Prompts | Prompt counts by playbook, component, or user |
Hero AI TokensHero AI Tokens | Token volume by category under Admin Panel |
Mastering Generative AI PromptingMastering Generative AI Prompting | Prompt patterns for Hero AI workflows |
AI-Friendly Component Best PracticesAI-Friendly Component Best Practices | Naming, inputs, outputs, and AI SOC mapping for components |
AI SOC Solution
The AI SOC Solution is Swimlane’s end-to-end security operations package powered by Hero AI. It combines alert and phishing triage, threat intelligence enrichment, case management, and automation with Hero AI investigation plans, verdicts, and analyst workflows in Case Management.
AI SOC Solution documentation lives in the Solutions guide (AI SOC Solution overview). The Turbine User Guide AI SOC SolutionQuickstart AI SOC topic summarizes why to start with the solution.
Hero AI in AI SOC
Hero AI capability | Where it appears in AI SOC |
|---|---|
Investigation plans | Generated from case context and knowledge base articles; analysts run plan steps from Case Management |
Verdicts | Generate Verdict in the Determination phase (Malicious, Suspicious, Benign, Unknown) |
Companion and agents | Same Hero AI models as Companion and agent workflows; see Hero AI ModelsHero AI Models |
Component selection | AI SOC selects and maps components from investigation plans; see AI-Friendly Component Best PracticesAI-Friendly Component Best Practices |
Ingestion builder | AI Ingestion workspace uses Hero AI–assisted Turbine Schema mapping for new alert sources |
Choose Your Path (AI SOC)
I want to… | Start here |
|---|---|
Overview of the solution and package | |
Install and configure Hero AI for AI SOC | |
Run my first investigation | |
Understand how Hero AI produces verdicts | |
Follow investigation plan workflows | |
Learn case layout and AI Analysis widget | |
Design components for plan and verdict flows | AI-Friendly Component Best PracticesAI-Friendly Component Best Practices — AI SOC Considerations |
Additional Hero AI capabilities in solutions and marketplace content:
Artificial Intelligence Data Privacy and Security
Swimlane does not collect or store sensitive customer data in centralized storage locations. Only metadata about model usage and performance is retained centrally. Customer data processed by AI or machine learning (ML) models is stored exclusively in the customer’s dedicated database instance, which is logically separated from other customer instances. Prompts and context required for a response are sent to models hosted on Swimlane's AWS Bedrock instance and are not used to train or fine-tune models. Customers must opt in to use Hero AI in their instance of Turbine. Individual risk assessments are conducted on all AI and LLM projects before deployment.
Next Steps
- New to Hero AI chat → Hero AI CompanionHero AI Companion
- Building automation with AI → Create and Modify Playbooks with Hero AICreate and Modify Playbooks with Hero AI
- Hero AI in security operations → AI SOC Solution
- Manual playbook creation → How to Create a PlaybookHow to Create a Playbook