The situation
One of the ten largest federally qualified health centers in the United States operates more than 90 care sites and serves hundreds of thousands of patients each year. Its small security team owns detection, response, and audit readiness across an environment that never closes. Phishing was its most mature automation: every reported email entered a 250-node Palo Alto XSOAR playbook that gathered context, scored the message, and routed the response.
The effective 250-node XSOAR playbook had become one of the most complex systems the team owned. Every update required branching-logic changes and full-path regression testing, plus a dedicated full-time maintenance role.
Alaris replaced the playbook end to end with fewer than 25 workflow nodes and several AI agents, preserving the existing intake while attaching evidence to every verdict.
The Pressure: Effective Automation That Was Too Heavy to Own
Two hundred and fifty nodes meant two hundred and fifty places for a change to break. Every new phishing pattern required edits to branching logic and regression testing across the entire path, while the team also had to retain platform-specific skills.
Keeping the playbook running consumed a dedicated full-time role. Even then, its branching depth made it difficult to explain why a particular message had received a particular verdict.
The requirement was not a new process. The team wanted the same phishing response with far less to maintain, no change to how staff reported suspicious email, and a verdict it could clearly explain.
The Migration: Preserve the Behavior, Remove the Complexity
The phishing response moved completely off Palo Alto XSOAR and onto Alaris Workflows. This was a full replacement rather than a partial integration.
Documented the XSOAR playbook and the exact behavior the replacement had to preserve.
Traced every data source, integration, and step in the email intake path.
Confirmed that nothing about how staff submitted phishing reports needed to change.
Recreated the response as a small number of workflow nodes, with AI agents supplying evidence-based judgment.
The nodes carry the process flow. Several AI agents reason about each reported email and return an evidence-based conclusion about its source and intent. The 250-node playbook became fewer than 25 nodes, and work that previously took weeks was rebuilt in under an hour.
Before: 250 nodes
Before: weeks
Before: one full-time role
Migration invisible to staff
The Result: The Behavior Survived; the Complexity Did Not
Phishing response now runs in fewer than 25 nodes. Reported messages still arrive through the same trusted path, while AI agents return an evidence-based reading of source and intent. Palo Alto XSOAR is retired for this workflow, and the team's dedicated maintenance effort is no longer spent on upkeep.
- 01
A change now touches a handful of steps instead of a sprawling decision tree.
- 02
AI agents attach the evidence behind each verdict rather than burying the decision inside branching logic.
- 03
No one outside the security team had to change how suspicious email was reported.
Methodology: node counts and scope are platform-reported from the migration record.
Palo Alto XSOAR
Manage Engine