← Back to all sparks
T

Tracecat

PM
Velocity6.3

Open-source workflow automation and case management platform.

Tracecat merges AI agents into case management—agents can now be @mentioned, mutate cases, and run on audit trails

soarsecurity-automationai-agentscase-managementintegrations
Current state
Tracecat is a security automation platform (SOAR-adjacent) built around workflows, case management, and a growing integration library. The beta.52 release represents a major capability expansion: agents are now deeply wired into the case lifecycle—they can be mentioned in comments, run workflows from slash commands, have their mutations recorded and displayed in the case timeline, and be configured with tool access from skills. The platform dropped pydantic-ai as a dependency in the same release, taking tighter ownership of the agent runtime.
Where it's heading
Tracecat is evolving from a workflow automation tool into an agent-native security operations platform. The depth of agent integration in beta.52—@mentions, session provenance, Claude Opus 5 in the model catalog, OTel instrumentation for agents, air-gapped deployment docs—signals that agents are now a first-class runtime, not a feature. The integration library is expanding rapidly (Databricks, Snowflake, 1Password, Microsoft Graph, Google Chronicle) and the MCP tooling is maturing.
Prediction
The next major capability push will likely be around agent autonomy—agents that can run multi-step investigations without human triggers, surfacing findings directly into cases. The aggregation compiler work (group-by, case field resolver, table row aggregation) suggests structured query over case data will become an agent-native operation.

Recent moves

  1. 1d ago

    Tracecat 1.0.0-beta.53-rc.1: agent skill tools, case aggregation

    beta.53-rc.1 adds case and table row aggregation, and agents can now be granted tools declared by attached skills—expanding what an agent can do based on which skills are configured. Vercel Security firewall templates land as a new integration.

    View source ↗
  2. 1d ago

    Tracecat 1.0.0-beta.52

    ⚡ SPARK

    beta.52 is the release where agents became a core part of case management: rich text comments, case version history with restore, agent @mentions in comments, agent session provenance tracking, and agent mutation recording. Claude Opus 5 joins the model catalog and pydantic-ai is removed.

    View source ↗
  3. 4d ago

    Tracecat 1.0.0-beta.52-rc.24

    RC.24 adds case field resolver and rich text comments (both landed in the full beta.52), with engine fixes for sandbox resource limits and secret-dependent error handling. Pre-release maintenance.

    View source ↗
  4. 9d ago

    Tracecat 1.0.0-beta.52-rc.23

    RC.23 hardens nsjail bind mount handoffs (a security-relevant sandbox fix) and adds the Splunk remote MCP server. The security hardening reinforces Tracecat's positioning as an enterprise-grade platform with proper execution isolation.

    View source ↗
  5. 9d ago

    Tracecat 1.0.0-beta.52-rc.22

    RC.22 adds Claude Opus 5 to the model catalog, drops pydantic-ai for a native runtime, and introduces group-by aggregation for agents. Air-gapped deployment documentation also lands, addressing enterprise self-hosted requirements.

    View source ↗
  6. 10d ago

    Tracecat 1.0.0-beta.52-rc.21

    RC.21 fixes table NULL handling, workflow failure attribution, and CI commit-convention enforcement. Release process and bug fixes only.

    View source ↗