Black Hat USA Aug 4-6, Mandalay Bay. Book time with us
Cast

Spells

What a spell is, how it is cast, and where to start from a template.

Updated 2026-07-15
In short

A spell is a saved response, written as plain-English steps instead of a flowchart. When a threat calls for it, a spell is cast (run). Safe steps run on their own; any risky step stops and waits for your approval. Your spells live together in the Spellbook.

A spell is a response playbook written in plain English. Your spells live together in the Spellbook. When a response is warranted, a spell is cast: you describe the steps, and the agent engine wires your tools and runs them. There is no drag-and-drop flowchart to maintain, and an existing SOP or runbook usually pastes straight in.

The Spellbook holds every spell your org has, however it was made: the ones you wrote by hand and the ones the Familiar assembled from an outcome you stated, side by side. A spell the Familiar built is labeled with that origin so it is never in doubt, and from there it reads, edits, and runs exactly like any other.

The Spellbook list of spells, some carrying a Built by Familiar badge.
The Spellbook holds every spell your org has, hand-written and Familiar-built, side by side.

The Spellbook

The Spellbook is ordered by what needs you first. When a spell carries a failure signal it surfaces at the top; then come the spells actively in service, then any you have switched off, then your drafts, then the rest. A switched-off spell is parked, not deleted: none of its triggers fire, and trying to run it tells you to enable it first. If a switched-off spell's tool connection is missing or unhealthy, enabling it again stays blocked until the connection is fixed. The page opens with a live count of how many spells are active out of the total, how many are failing right now, and how many drafts are waiting: the failing and draft counts are doorways that narrow the list to exactly that slice, and the status filter counts the switched-off spells whenever any exist. A spell you no longer need can be deleted here too: one still in service is taken out of service first, and a spell you already retired can instead be turned back into a draft to build on again.

To find one spell on a big shelf, search by name or description, or narrow with the filter rail: status, run health, origin (hand-built or assembled by the Familiar), and whether a spell is private to you or shared with the org, wherever the underlying signal exists. As on the tickets page, the attention group renders as full cards while the quieter groups stay compact rows, and you can force either treatment: the choice sticks with you between visits.

The Spellbook keeps its two doorways outward in reach: adopt more from the Bazaar, or ask the Familiar to build the next one.

How a spell reads

In short

Numbered lines are the main steps. Indented bullets are sub-steps. Put a word in parentheses in front of a sub-step and it only runs when the step above it mentions that word.

Numbered lines are the main steps, run in order. Indented bullets under a numbered step are its sub-steps. A sub-step can be conditional: prefix it with a word in parentheses and it only runs when the parent step's result contains that word. Where a step should use a specific tool, reference it inline and the editor turns it into a chip. That is the whole language: a phishing response that took a forty-node flowchart elsewhere is a dozen plain sentences here. The Familiar sits inside the editor too: open its panel to draft instructions from a description, refine existing steps, or suggest tools.

How a spell is cast

  • It casts automatically when a ticket warrants the response.
  • You cast it by hand against a ticket, or run it from the spell's own page.
  • The Familiar proposes it when you ask for a response in plain English.

The seal in the middle of a cast

A spell runs its safe, reversible steps freely, but any destructive or high-blast-radius step does not get to execute directly: it pauses at a Seal with its rationale and a reversible plan, and waits for a human yes. This is the one law applied inside automation, not a setting you can switch off. A run can also pause for human input through a form when a judgment call is needed; the run waits, the assignee answers, and execution resumes where it left off.

While it runs

Every cast records each step's input, output, and timing, plus the tool calls it made, and the whole run lands on the ticket timeline. Edits to a spell are versioned, so you can always see what was live when a cast happened. The record and any linked ticket stay in sync as the cast runs.

Start from a template

The Bazaar holds ready-made spells, called Scrolls, adapted from response procedures the security community has already refined. Browse it, adopt one, and adjust the steps to your environment: see The Bazaar for the marketplace, what the provenance line means, and how planned tool chips work.

More guides

Everything you can teach your Familiar.