oolak / Features / Workflows
Workflows

Let routine security work run itself.

Build workflows by filling in a form, without writing code. A workflow can sync data, launch a scan, open a ticket, ask an AI model for a summary or wait for someone's approval, and you can watch every step as it runs.

Every workflow run, step by step, as it happens.

No code needed

Triggers, conditions and steps are chosen from lists, and a code view is there for those who want it.

Safe by design

Steps that change a system wait for approval, and every workflow can be tried out before it goes live.

Fully visible

Each run is recorded step by step, so you always know what happened and when.

Workflows

What's included

  • Workflows start on a schedule, by hand, on an event or from a webhook.
  • Conditions, success and failure branches, loops and waits decide where a workflow goes next.
  • Steps sync connectors, launch scans, update tickets, send notifications and run discovery.
  • Local or API-hosted AI models run as workflow steps to summarise findings or suggest decisions.
  • Approval steps can be answered directly from Microsoft Teams or Slack.
  • A drag-and-drop canvas shows the workflow as a diagram, and version differences are highlighted.
  • Run logs stream live while a workflow is running.
  • Workflows can trigger CI/CD pipelines such as Jenkins.
  • Tasks can be opened in Jira, ServiceNow, OpenText SM, Monday and Trello.
  • A dry run executes only the read-only steps and describes the rest.
  • Ready-made templates cover the daily data refresh and other common routines.

See oolak on your own data in 14 days.

We install oolak in your environment, connect your tools and show you your real risk picture. You keep everything it finds.

Start a free 14-day trial → Try the live demo
For engineers

Technical details

How are workflows defined?
Every workflow is a strict, validated document in JSON or YAML. Conditions use CEL and data selection uses JMESPath, so no arbitrary code is ever executed. The form editor and the code editor change the same document.
What stops a workflow from doing damage?
Disabled workflows never run. Steps that change an external system need an approved approval step before them, and publishing a workflow is a separate permission from editing one.
Which AI models can be used?
Any model you can reach: a local model running inside your network or a commercial model through its API. The data a step may send is limited to what that step needs.