Playbook runs

The record of every run: trigger, steps, verdict, actions, evidence.

The list

Response › Playbook runs lists runs across your scope with the alert, the playbook and version, the trigger, the mode, the outcome and the duration. Filter by playbook, organization, outcome or time.

A run

Opening a run shows its trace: each block in order, what it received, what it produced, how long it took, and for the advisory verdict block the full verdict. Actions show whether they were staged or executed, by whom they were confirmed, and the result reported by the agent or connector.

Retention

Run traces are kept for 90 days by default, and the executed-action records for the audit trail's retention. See Retention.