Tines is an intelligent workflow platform focused on security, IT operations, and engineering teams. It provides a visual builder for automation, rich case management, and an AI copilot layer that connects to internal tools and external APIs. Teams use it to turn manual runbooks into governed, auditable workflows that range from human-in-the-loop processes to fully agentic automation.
Tines
Convert security and IT runbooks into AI-powered, governed workflows.
What is Tines?
Core Features
- Storyboard Automation Builder: Drag-and-drop “stories” composed of core actions such as webhooks, HTTP requests, email, triggers, event transforms, AI Agent actions, and reusable sub-stories. All with real-time execution badges.
- AI Workbench Copilot: Natural language chat interface that lets builders query internal data, trigger stories, and orchestrate workflows in real time. Conversations respect tenant permissions and stay private to the user.
- Integrated Case Management: Purpose-built cases module for SOC and IT incidents that links alerts, evidence, comments, and automated actions, with metrics like SLA timers and time-to-detect or respond.
- Vendor-Agnostic Integrations: Connects to almost any product with an API. Includes MCP server templates that expose workflows as tools to other AI clients while retaining access control and auditability.
- Governance and Security Controls: SSO, granular permissions, audit logs, AI usage controls, self-hosting options, and a dedicated trust center geared toward regulated and federal environments.
- Extensive Workflow Library & Tines University: A large collection of pre-built workflows plus comprehensive educational resources help teams ramp up quickly without deep coding knowledge.
Use Cases & Considerations
- Security Operations Centers (SOCs): Automating alert triage, phishing response, threat intelligence enrichment, and incident workflows to reduce manual toil and speed up response times.
- IT Operations Teams: Handling access requests, password resets, device lockdowns, and ticket routing across systems like Okta, Jamf, and Jira, ensuring consistent, auditable processes.
- Infrastructure and DevOps Teams: Orchestrating cloud changes, on-call runbooks, monitoring responses, and approvals, integrating tightly with infrastructure APIs and tools.
- Product and Engineering Teams: Wiring together internal tools, customer operations, and release or deployment workflows, often bridging gaps between business and technical stacks.
- Managed Security Service Providers (MSSPs): Delivering standardized detection and response playbooks across many clients, with multi-tenancy controls and audit trails.
- Regulated and Federal Organizations: Adopting Tines for zero trust initiatives, internal app flows, and case-driven processes, leveraging strict governance and self-hosting options.
- Overkill for simple tasks: Very small teams or individuals seeking only basic, linear automations may find the platform’s governance and structure heavier than a simpler tool like Zapier.
- Learning curve at depth: While visual, mastering advanced stories, MCP server templates, and strict permission models requires time and deliberate onboarding.
- AI credit limits: AI Workbench and Agent actions consume run‑time credits, and lower‑tier plans have limited monthly allowances that could bottleneck heavy usage.
- Builder and flow restrictions on lower tiers: Community and Starter plans cap the number of builders and flows, potentially hindering growth if not planned for.
- Custom pricing beyond Starter: The jump to Business or Enterprise is custom‑quoted, making it harder to predict costs for small‑ to medium‑sized teams before talking to sales.
- Hosting dependency for self‑hosting: Self‑hosting requires infrastructure management and may not include the same level of automated updates as the cloud version.
How to use Tines
- Sign up and access the platform: Create an account on tines.com, choose a plan, and log in to the web-based workspace.
- Build a story: Use the drag-and-drop builder to add actions (e.g., webhook, HTTP request, email, AI Agent action) and connect them in a sequence. Each action can be configured with API credentials, parameters, and conditions.
- Configure triggers and branches: Set webhook triggers, time-based triggers, or manual triggers. Add conditional logic and event transforms to route workflows intelligently.
- Incorporate human steps or AI: Insert human-in-the-loop actions (e.g., approval requests) or AI Workbench interactions to augment decision-making directly in the story.
- Test and publish: Run the story in real time, review execution badges and logs, then publish it. Monitor ongoing runs via the dashboard and case management views.
- Use Workbench copilot: From the chat interface, query internal data, trigger stories, or ask the copilot to orchestrate multi‑step actions using natural language, all within user‑specific permissions.
Pricing & Plans
Tines offers a freemium model with transparent Community and Starter plans, while Business and Enterprise tiers are custom‑quoted. The Community edition is free forever with unlimited viewers, unlimited parallel workflow runs, and essential controls but limited to one builder and three flows. Starter unlocks more capacity and AI credits for $600 per month (billed monthly or annually with a 16% discount). Higher tiers add advanced features, multi‑team support, unlimited builders, and dedicated resources. For precise, up‑to‑date pricing always check the official Tines website.
- Community: $0/month – unlimited viewers and integrations, SSO, 1 builder, 3 flows, core workflow controls.
- Starter: $600/month – 2,500 AI run‑time credits, 1M monthly events, 7‑day retention, 2 builders, 5 flows, flexible billing.
- Business: Custom pricing – extended product capabilities, increased capacity, support & training, multi‑team hosting options.
- Enterprise: Custom pricing – tenant management, unlimited builders, extended capacity, dedicated Tines resources.
Platforms
- Web application: Full-featured browser-based interface for building, monitoring, and managing workflows.
- REST API: Allows programmatic integration and custom management of stories, actions, and cases.
- MCP server templates: Exposes Tines workflows as tools that can be consumed by other AI clients (e.g., Claude, Copilot) while preserving access control.
- Self-hosting options: Available for organizations that need to run Tines entirely within their own infrastructure, including air‑gapped environments.
Tips & Best Practices
- Start with templates: Leverage the built-in workflow library and Tines University content to accelerate learning and avoid reinventing common patterns.
- Use sub-stories for reusability: Encapsulate recurring logic (e.g., enrichment, notification) into sub-stories that can be called from multiple parent stories, reducing duplication.
- Test in a sandbox: Before connecting to production systems, validate stories with test webhooks and dummy payloads to ensure actions behave as expected.
- Apply granular permissions early: Use role-based access and audit logs from the start, especially when multiple teams or MSSPs will operate within the same tenant.
- Set AI usage controls: Even with the AI Workbench, configure tenant-wide AI permissions to restrict which models or data sources can be used, aligning with security policies.
- Monitor case metrics: Integrate case management with story actions so that SLA timers and time-to-respond are tracked automatically, improving operational visibility.
Who is Tines for?
- Security Operations teams seeking to replace manual playbooks with controlled, AI‑assisted automation that ties directly into threat intel and incident response.
- IT Operations professionals who need to streamline repetitive tasks like user provisioning, device management, and ticket handling without writing code.
- DevOps and infrastructure engineers looking to orchestrate cloud and on-premise runbooks with full API access and auditability.
- Product and engineering leads who want to wire internal tools together and build custom internal workflows without diverting development resources.
- Managed Security Service Providers requiring multi‑tenant, governed automation they can deploy across diverse client environments.
- Regulated enterprises and federal agencies that demand strict data sovereignty, self-hosting, and comprehensive audit trails for all automated actions.
Alternatives
View allSecurity automation platform focused on SOAR, with low‑code playbooks and extensive case management, suitable for MSSPs and large SOCs.
Generalist automation tools that connect hundreds of apps, but lack the deep case management and AI governance core to Tines.
Developer-friendly workflow builder with code‑level control and many integrations, lighter on out‑of‑the‑box case management features.
Open‑source, self‑hosted workflow automation that can be highly customized, appealing to technical teams wanting full control over data and hosting.
SOAR tool with strong threat intelligence integration, now part of Google Cloud, but tightly coupled to the Google ecosystem.
Comprehensive security orchestration and response platform with case management, best suited for Fortinet‑heavy environments.
FAQ
Q1. What exactly is a “Story” in Tines?
A Story is a visual automation workflow built from drag‑and‑drop actions like webhooks, HTTP requests, emails, and AI Agent actions. Stories can range from simple alert enrichment to complex multi‑step incident response with human approvals.
Q2. Can I connect Tines to any tool my organization uses?
Yes. Tines is vendor‑agnostic and connects to any product with an API. It also provides MCP server templates to expose workflows as tools to other AI clients, and supports standard integrations with major security, IT, and DevOps platforms.
Q3. How does AI Workbench handle data privacy?
The AI Workbench respects tenant permissions and keeps all conversations private to the authenticated user. Organizations can also configure AI usage controls, choose from managed models, or bring their own keys for providers like Anthropic or OpenAI to maintain data sovereignty.
Q4. Is there a free version of Tines I can start with?
Yes, the Community edition is free forever and includes unlimited viewers, unlimited workflow runs, essential controls, and SSO. It’s limited to one builder and three flows, so you can evaluate core capabilities before upgrading.
Q5. What are MCP server templates, and why should I use them?
MCP (Model Context Protocol) server templates allow you to expose Tines workflows as secure, auditable tools that other AI clients—like coding assistants or chatbots—can invoke. This extends automation beyond the Tines UI while keeping access control and governance in place.
Know a similar tool?
Help others discover great AI tools by submitting it
Submit Tool