About automation entities

2026-09-02Last updated

An automation entity is a repeatable process in Security Center SaaS. It consists of two parts: a trigger that defines what starts the automation, and a response that defines the actions that follow.

Automation capabilities

Automation entities provide the following capabilities:

Feature Description
Conditional triggering
  • Trigger automations based on event data, sequence, or frequency
  • Use AND or OR logic to define how events are evaluated together
  • Include or exclude specific entities as event sources
Response actions
  • Run multiple response actions in a single automation, with or without configured delays
  • Run event-dependent actions
  • Tailor actions using event data
Scheduling
  • Set earliest and latest trigger dates
  • Apply active and exception schedules
  • Define reactivation rules
  • Ignore obsolete events
Map positioning
  • Trigger automations from maps manually
Organization
  • Sort automations using folders and partitions
Reuse
  • Reuse automation logic throughout system deployment

Automation limitations

Automation entities have the following limitations:

  • Audit trails show that a change occurred, but don’t show what was changed in triggers or responses.
  • Some invalid settings may not be detected during configuration.
  • The Use source time zone option is not yet supported for event-based automations. This option is currently only available to event-to-actions.
  • Activity trails are unavailable.
  • You cannot set Source to "any related entity".
  • The Execute response as option is restricted to the user who created the automation.