Usage documentation not yet indexed for this tool.
Technical Documentation
VFS Recovering Reference...
The agentic security automation platform.
Introduction
Tracecat is the open source security automation platform for teams and AI agents.
Prompt-to-automations: build end-to-end automations with agents, workflows, cases, and tables from your own agent harness (e.g. Claude code, Codex, OpenCode).
Code-native: sync custom Python scripts from your Git repo into Tracecat.
All-in-one: agents, workflows, lookup tables, and case management. Everything technical teams need to automate work in one place.
Sandboxed-by-default with nsjail and run on Temporal for security, reliability, and scale.
Features
[!IMPORTANT]
Tracecat is in active development. Review the release changelog before updating.
Key Capabilities
Agents: build custom agents with prompts, tools, chat, and any MCP server (remote HTTP / OAuth or local via npx / uvx commands)
Workflows: low-code builder with complex control flow (if-conditions, loops) and durable execution (Temporal)
Case management: track, automate, and resolve work items with agents and workflows
Integrations: over 100+ pre-built connectors to enterprise tools via HTTP, SMTP, gRPC, OAuth, and more
MCP server: work with Tracecat through your own agent harness
Custom registry: turn custom Python scripts into agent tools and workflow steps
Other OSS Highlights
Sandboxed: run untrusted code and agents within nsjail sandboxes or pid runtimes.
Lookup tables: store and query structured data
Variables: reuse values across workflows and agents
No SSO tax: SAML / OIDC support
Audit logs: exportable into your SIEM
Enterprise Edition
Fine-grained access control: RBAC, ABAC, OAuth2.0 scopes for humans and agents
Human-in-the-loop: review and approve sensitive tools calls from a unified inbox, Slack, or email
Workflow version control: sync to GitHub, GitLab, Bitbucket, etc.
Metrics and monitoring: for workflows, agents, and cases
Tech Stack
Backend: Python with FastAPI, SQLAlchemy, Pydantic, uv
Frontend: Next.js with TypeScript, React Query, Shadcn UI
Durable workflows and jobs: Temporal
Sandbox: nsjail
Database: PostgreSQL
Object store: S3-compatible
Open Source vs Enterprise
This repo is available under the AGPL-3.0 license with the following exceptions:
packages/tracecat-ee directory is under Tracecat's paid EE (Enterprise Edition) license.
deployments/k8s is a git submodule under the source available PolyForm Shield License. It contains the Tracecat Helm chart and EKS deployment templates for internal use only, and its chart releases are published from that repo to public ECR.
Any code that gates ee features across the repo
Code that fall under the above exceptions must not be redistributed, sold, or otherwise commercialized without permission.
Thank you all our amazing contributors for contributing code, integrations, docs, and support. Open source is only possible because of you.
Check out our Contribution Guide for more information.