CISO dinner in Vancouver, Sept 9RSVP
Alaris
Pricing

Autonomous security operations · Healthcare

A 250-Node Phishing Playbook, Migrated off XSOAR to Under 25

A top-ten U.S. federally qualified health center replaced its end-to-end phishing workflow while preserving the email intake path its staff already trusted.

SOC Efficiency4 min readEthan GlennyJuly 2026United States
Open the 4-page PDF

Outcomes · platform-reported

<25Workflow NodesRebuilt from 250 nodes
1SOAR Platforms RetiredPhishing runs on Alaris Workflows
0Process ChangesExisting email intake preserved
<1 hrRebuild TimePreviously took weeks
IndustryHealthcare / federally qualified health center
Environment90+ care sites
Integrations in scope

Email Intake

01

The situation

One of the ten largest federally qualified health centers in the United States operates more than 90 care sites and serves hundreds of thousands of patients each year. Its small security team owns detection, response, and audit readiness across an environment that never closes. Phishing was its most mature automation: every reported email entered a 250-node Palo Alto XSOAR playbook that gathered context, scored the message, and routed the response.

The pressure

The effective 250-node XSOAR playbook had become one of the most complex systems the team owned. Every update required branching-logic changes and full-path regression testing, plus a dedicated full-time maintenance role.

The operating change

Alaris replaced the playbook end to end with fewer than 25 workflow nodes and several AI agents, preserving the existing intake while attaching evidence to every verdict.

02

The Pressure: Effective Automation That Was Too Heavy to Own

Two hundred and fifty nodes meant two hundred and fifty places for a change to break. Every new phishing pattern required edits to branching logic and regression testing across the entire path, while the team also had to retain platform-specific skills.

Keeping the playbook running consumed a dedicated full-time role. Even then, its branching depth made it difficult to explain why a particular message had received a particular verdict.

The requirement was not a new process. The team wanted the same phishing response with far less to maintain, no change to how staff reported suspicious email, and a verdict it could clearly explain.

03

The Migration: Preserve the Behavior, Remove the Complexity

The phishing response moved completely off Palo Alto XSOAR and onto Alaris Workflows. This was a full replacement rather than a partial integration.

01Captured intent

Documented the XSOAR playbook and the exact behavior the replacement had to preserve.

02Mapped the flow

Traced every data source, integration, and step in the email intake path.

03Held the intake

Confirmed that nothing about how staff submitted phishing reports needed to change.

04Combined nodes and agents

Recreated the response as a small number of workflow nodes, with AI agents supplying evidence-based judgment.

The nodes carry the process flow. Several AI agents reason about each reported email and return an evidence-based conclusion about its source and intent. The 250-node playbook became fewer than 25 nodes, and work that previously took weeks was rebuilt in under an hour.

<25 nodesPlaybook Complexity

Before: 250 nodes

<1 hourBuild Time

Before: weeks

0Dedicated Upkeep Role

Before: one full-time role

UnchangedEmail Intake

Migration invisible to staff

04

The Result: The Behavior Survived; the Complexity Did Not

Phishing response now runs in fewer than 25 nodes. Reported messages still arrive through the same trusted path, while AI agents return an evidence-based reading of source and intent. Palo Alto XSOAR is retired for this workflow, and the team's dedicated maintenance effort is no longer spent on upkeep.

  1. 01

    A change now touches a handful of steps instead of a sprawling decision tree.

  2. 02

    AI agents attach the evidence behind each verdict rather than burying the decision inside branching logic.

  3. 03

    No one outside the security team had to change how suspicious email was reported.

Methodology: node counts and scope are platform-reported from the migration record.