Black Hat USA Aug 4-6, Mandalay Bay. Book time with us
Choosing a platform

Soarcery vs Tines. One agent that investigates, compared to a workflow platform with AI added in.

Tines built its reputation on a no-code Storyboard for deterministic workflows, then layered Workbench, an AI chat copilot, and Agents, an autonomous mode, on top: three separate ways to run a process, chosen per workflow. Soarcery is a single accountable agent, the Familiar, that investigates every case the same way, with automation that runs only after a human reviews the plan. Here is where each earns its place, sourced from Tines' own materials.

Tines
Soarcery
Core idea
A no-code Storyboard for building workflows ("stories"), with three selectable modes per workflow: human-led, deterministic, and agentic, plus Workbench as an AI chat layer and Cases for case management.12
One agent, the Familiar, investigates a case end to end, the same way every time. Spells are plan-first automations a human reviews before they run.
The thinking
Reasoning is split by mode: deterministic workflows follow pre-built logic, Workbench lets a user "instruct an LLM in real-time to access proprietary data and take action,"3 and Agents (added in 2025) "reason, communicate and act based on inputs and tools you control."4 Which one reasons through a given case depends on which mode was chosen for it.
The Familiar reasons through the full Investigation itself, every time, informed by a native multi-engine verdict spread rather than a single scan result.
The acting
Deterministic workflows execute exactly as built. Agents can act with what Tines describes as "full AI autonomy" as one of three configurable levels, alongside human-in-the-loop copilot and deterministic-only modes.5 Workbench includes "built-in controls like confirmation, data security, audit logs, RBAC."3
The Seal is the default gate: consequential actions wait on explicit human approval, every time, with a receipt. It is not one mode among several.
Maintenance
Storyboard is no-code, and Workbench can "create flows at the speed of conversation using natural language," but a Tines deployment is still, at its core, a library of workflows built and maintained on the Storyboard.13
Spells are described in plain language. There is no flowchart to redraw when a connected tool changes shape.
Auditability
Tines states: "We automatically capture an audit log any time a user changes any piece of data in your Tines tenant. All of the logged operations are available both via the UI and API."6 Its own governance writing adds that "the AI's decision and reasoning should be recorded in the audit trail itself, not in a separate system that auditors cannot access," and that "every consequential agent action needs a traceable chain from the agent's decision to the human who authorized that level of autonomy."7
The Seal's approval receipts form one replayable trail per Investigation: evidence, reasoning, the approver, and the action, in one place, by default rather than by design choice.
Where it wins
A large, mature integration ecosystem built on a vendor-agnostic, API-first Storyboard, a genuinely transparent published pricing page with a real free Community tier, and a security posture backed by SOC 2 Type II and a published Trust Center.89
Investigation depth from a single accountable agent, a native multi-engine verdict spread, and an approval gate that ships as the default rather than a mode you select per workflow.
Honest risk
Three different execution modes (deterministic, copilot, full autonomy) mean the actual behavior of "Tines" varies by which mode a given workflow was built in, worth asking, workflow by workflow, which mode handles your highest-stakes actions and whether that was a deliberate choice or a default nobody revisited. Tines' own governance writing makes this exact case for careful mode selection.7
Soarcery is a newer platform. It has not run at Tines' scale (named large-enterprise customers) or built out Tines' integration maturity yet, and that gap is real.1
The architectural difference

Where the two platforms actually diverge.

One agent versus three modes you choose between

Tines' own positioning is explicit that it offers three different ways to run a process: "Human-led workflows... for strategy, judgment calls, communication, risk assessment, and context-based decisions. Deterministic workflows... for volume, mission-critical processes, predictability, compliance. Agentic workflows... for flexibility, ambiguity, simplicity."1 That flexibility is a real strength for a platform that has to serve IT, security, and general business automation all at once. But it also means the investigation behavior on any given case depends on which mode that particular workflow happens to be built in. Soarcery does not ask a builder to pick a mode. The Familiar investigates every case the same way, end to end, as one agent with one reasoning trail.

Where the AI sits relative to the workflow

Tines added AI in layers on top of an existing no-code workflow product. Workbench is "a Tines-powered AI chat interface where you can take action and access proprietary data in real-time,"3 and Agents, launched in 2025, let a workflow "act independently, suggest next steps, and collaborate with users in real time," with customers choosing between "deterministic logic, human-in-the-loop copilots, or full AI autonomy" per workflow.5 Soarcery inverts that order. Investigation is not a mode layered onto a workflow builder, it is the product: the Familiar investigates first, and Spells (the automation layer) exist to execute a reviewed plan afterward, not to be the thing AI gets added to.

Governance as policy versus governance as default

Tines' own writing on agentic workflows is unusually candid about the governance work this flexibility requires: "Every consequential agent action needs a traceable chain from the agent's decision to the human who authorized that level of autonomy," and "agents must be granted purpose-specific entitlements rather than broad persistent access, and those permission boundaries must be enforced through technical controls."7 That is sound advice, and it is advice a Tines admin has to actively implement, workflow by workflow, as they choose autonomy levels. Soarcery's Seal is not a policy an admin configures per workflow, it is the default behavior on consequential actions, with the receipt generated automatically rather than as a governance practice someone has to design in.

Where Tines wins

To be fair to a platform with real maturity and a genuinely different set of strengths.

  • A large, mature, vendor-agnostic integration ecosystem. Storyboard connects to "any tool with an API," and the platform has years of production use across security and IT automation, with named large-enterprise customers.1
  • The most transparent pricing in this comparison. Tines publishes an actual pricing page with a genuine free Community tier (1 builder, 3 flows, unlimited integrations, unlimited parallel workflow runs, no credit card required) before a prospect ever talks to sales.8 That is a meaningfully lower-friction way to try the product than a demo-gated enterprise sale.
  • A well-documented security and compliance posture. SOC 2 Type II with annual audits, a public Trust Center, and (per Tines' own blog) ISO 27001, 27701, and 42001 certification give risk and compliance teams a lot to work with early in a deal.69

Fair fight

If what you need is a general-purpose, vendor-agnostic automation platform that spans security and IT, where different teams pick the right mode (human-led, deterministic, or agentic) for each individual workflow, that is Tines' home ground. Soarcery is a narrower bet by design: it does not try to be a general workflow platform with AI added on. It is built around one agent that investigates every security case the same way, with a native multi-engine verdict spread and an approval gate that is the default, not a per-workflow setting.

Settle it with evidence

Watch the difference on a real case.

Three minutes, ungated. Then bring your own alerts and compare for real.

Sources

Where this comparison comes from.

Every claim about Tines above traces back to one of these, almost entirely Tines' own site and product pages, confirmed by direct fetch where noted.

  1. 1Tines homepage, tines.com. "The intelligent workflow platform" tagline, three workflow modes, Storyboard, Workbench, and Cases, customer logos including named large-enterprise customers.
  2. 2Tines, "Tines Workbench, AI chat for secure workflow automation", tines.com/platform/workbench. Workbench and Cases description.
  3. 3Tines, Workbench platform page (same as above). AI chat interface definition, "Create flows at the speed of conversation," built-in confirmation, audit, and RBAC controls.
  4. 4Tines, "Agents" platform page, tines.com/platform/agents. Agents definition, Task Mode and Chat Mode, autonomy-and-control framing.
  5. 5PR Newswire, "Tines Launches Agents to Deliver Full-Spectrum Workflow Automation" (June 25, 2025), prnewswire.com. Three-mode autonomy spectrum, data security claims.
  6. 6Tines, "Security at Tines", tines.com/security. Audit log claim, SOC 2 Type II, annual audits, data retention philosophy.
  7. 7Tines blog, "Agentic Workflows: What they are and how to govern them", tines.com/blog. Agent and workflow relationship definition, audit and governance requirements, entitlement scoping. Confirmed by direct fetch.
  8. 8Tines, "Pricing", tines.com/pricing. Community free tier details, Business and Enterprise custom tiers.
  9. 9Tines blog, "Tines sets the AI governance standard with ISO 42001, 27001, and 27701", tines.com/blog, plus tines.com/security for SOC 2 Type II and the Trust Center.