Tines
Tines is an intelligent workflow platform focused on security, IT operations, and engineering teams. It provides a visual builder for automation, rich case management, and an AI copilot layer that connects to internal tools and external APIs. Teams use it to turn manual runbooks into governed, auditable workflows that range from human-in-the-loop processes to fully agentic automation.
Make a decision about Tines
- Already use it? Add Tines to Stack Autopsy — check cost, overlap and safe cancellations.
- Thinking about buying it? Ask AI Advisor — compare fit, alternatives and trade-offs.
- Want to leave it? Find a replacement — see feature losses and migration risks.
Pricing
- Community Edition: $0 per month; includes unlimited viewers, unlimited parallel workflow runs, unlimited integrations, workflow essentials and controls, SSO, 1 builder, and 3 flows.
- Starter: $600 per month; includes everything in Community, plus 2,500 AI run-time credits, 1M monthly events, 7 days event retention, flexible billing (monthly or annually with 16% discount), 2 builders, and 5 flows.
- Business: Custom pricing; includes everything in Starter, plus extended product capabilities, increased capacity, support and training access, flexible hosting options, and multiple teams.
- Enterprise: Custom pricing; includes everything in Business, plus enterprise tenant management, unlimited builders, extended product capacity, and dedicated Tines resources.
Features
- Storyboard Automation Builder: Drag-and-drop “stories” composed of core actions such as webhooks, HTTP requests, email, triggers, event transforms, AI Agent actions, and reusable sub-stories, all with real-time execution badges.
- AI Workbench Copilot: Natural language chat interface that lets builders query internal data, trigger stories, and orchestrate workflows in real time while respecting tenant permissions and keeping conversations private to the user.
- Integrated Case Management: Purpose-built cases module for SOC and IT incidents that links alerts, evidence, comments, and automated actions, with metrics like SLA timers and time-to-detect or respond.
- Vendor-Agnostic Integrations: Connects to almost any product with an API, plus MCP server templates that expose workflows as tools to other AI clients while retaining access control and auditability.
- Governance and Security Controls: SSO, granular permissions, audit logs, AI usage controls, self-hosting options, and a dedicated trust center geared toward regulated and federal environments.
Use cases
- Security Operations Centers (SOCs): Automating alert triage, phishing response, threat intelligence enrichment, and incident workflows.
- IT Operations Teams: Handling access requests, password resets, device lockdowns, and ticket routing across systems like Okta, Jamf, and Jira.
- Infrastructure and DevOps Teams: Orchestrating cloud changes, on-call runbooks, monitoring responses, and approvals.
- Product and Engineering Teams: Wiring together internal tools, customer operations, and release or deployment workflows.
- Managed Security Service Providers (MSSPs): Delivering standardized detection and response playbooks across many clients.
- Uncommon Use Cases: Used by federal and highly regulated organizations pursuing zero trust initiatives; adopted by business operations teams to build internal apps and request flows on top of cases and apps.