Skip to Workflow Atlas
ETL PipelineAI systemIntermediate

Email Incident Management Workflow

Email Incident Management Workflow is a 15-node automation blueprint connecting IMAP Email, TheHive, Cortex. Inspect its trigger, execution graph, branches, and implementation requirements.

Interactive system map

Follow the runtime. Inspect what supports it.

Solid horizontal paths show main-channel execution. Violet dependencies sit beneath the exact step they configure or empower.

15

Nodes

14

Links

1

Run groups

Connected tools

3 integrations

  • IMAP Email
  • TheHive
  • Cortex

Canvas controls

Fit wide systems, then zoom into any run group.

Email Incident Management Workflow execution lanes1 run groups containing 15 workflow nodes and 14 visible links. Solid horizontal lines are main-channel runtime links. Violet dashed lines connect typed dependencies beneath the runtime step they support. Focus any node to inspect its immediate path.IMAP Email. integration node, emailReadImap. 0 incoming and 1 outgoing connections.STARTIMAP EmailINTEGRATIONEMAILREADIMAP0 IN / 1 OUTTheHive. integration node, theHive. 1 incoming and 1 outgoing connections.STEP 02TheHiveINTEGRATIONTHEHIVE1 IN / 1 OUTCreate Case. integration node, theHive. 1 incoming and 1 outgoing connections.STEP 03Create CaseINTEGRATIONTHEHIVE1 IN / 1 OUTCase. integration node, theHive. 1 incoming and 1 outgoing connections.STEP 04CaseINTEGRATIONTHEHIVE1 IN / 1 OUTWait. integration node, wait. 1 incoming and 1 outgoing connections.STEP 05WaitINTEGRATIONWAIT1 IN / 1 OUTObservable. integration node, theHive. 1 incoming and 1 outgoing connections.STEP 06ObservableINTEGRATIONTHEHIVE1 IN / 1 OUTAnalyzer Email. integration node, theHive. 1 incoming and 1 outgoing connections.STEP 07Analyzer EmailINTEGRATIONTHEHIVE1 IN / 1 OUTCortex. integration node, cortex. 1 incoming and 1 outgoing connections.STEP 08CortexINTEGRATIONCORTEX1 IN / 1 OUTIF. decision node, if. 1 incoming and 3 outgoing connections.STEP 09IFDECISIONIF1 IN / 3 OUTUpdate Case Domain. integration node, theHive. 1 incoming and 1 outgoing connections.STEP 10Update Case DomainINTEGRATIONTHEHIVE1 IN / 1 OUTUpdate Case Email. integration node, theHive. 1 incoming and 1 outgoing connections.STEP 10Update Case EmailINTEGRATIONTHEHIVE1 IN / 1 OUTUpdate Case Ip. integration node, theHive. 1 incoming and 1 outgoing connections.STEP 10Update Case IpINTEGRATIONTHEHIVE1 IN / 1 OUTOTX DOMAIN. integration node, theHive. 1 incoming and 0 outgoing connections.OUTCOMEOTX DOMAININTEGRATIONTHEHIVE1 IN / 0 OUTEmail Reputation. integration node, theHive. 1 incoming and 0 outgoing connections.OUTCOMEEmail ReputationINTEGRATIONTHEHIVE1 IN / 0 OUTOTX IP. integration node, theHive. 1 incoming and 0 outgoing connections.OUTCOMEOTX IPINTEGRATIONTHEHIVE1 IN / 0 OUT

Signal inspector

Focus, hover, or select a step to isolate its runtime and support links.

Main-channel runtimeTyped dependencytriggeraidecisiontransformintegration
Scroll horizontally to follow every connected flow.15 connected nodesEnter or click to lock · Escape to clear

Runtime breakdown

Read the execution spine before its dependencies.

Each run group separates main-channel steps from the models, tools, retrievers, and data services that support them. Start and outcome labels apply only to runtime nodes.

01

Run Group

IMAP Email

14 Execution Links
  1. Start

    IMAP Email

    Integration

  2. Step 2

    TheHive

    Integration

  3. Step 3

    Create Case

    Integration

  4. Step 4

    Case

    Integration

  5. Step 5

    Wait

    Integration

  6. Step 6

    Observable

    Integration

  7. Step 7

    Analyzer Email

    Integration

  8. Step 8

    Cortex

    Integration

  9. Step 9

    IF

    Decision

  10. Step 10

    Update Case Domain

    Integration

    Update Case Email

    Integration

    Update Case Ip

    Integration

  11. Outcome

    OTX DOMAIN

    Integration

    Email Reputation

    Integration

    OTX IP

    Integration

Turn the map into a plan

Adapt this blueprint to your company.

Bring the system shape into a workspace, then define the production controls, data boundaries, owners, and delivery sequence around your context.