M ManySignal

Product Tour

Agent Builder — Custom AI Agents for Your Workflows

Step 6 of 8

app.manysignal.io/agent-builder/custom-phishing-triage

Tool Palette

check_domain_rep

Threat Intel

expand_urls

Analysis

lookup_sender

History

get_entity

Platform

set_verdict

Output

add_case_note

Platform

Workflow DAG — custom-phishing-triage

Trigger: finding_created [phishing]
check_domain_rep
expand_urls
lookup_sender_history
get_entity_context
set_triage_verdict

Agent Config

Model

claude-3-5-sonnet

Max tool calls

20

Timeout

60s

Memory

persistent

Status

Deployed · active

1

Compose agents from tools

Drag tools from the palette onto the DAG canvas. Tools can be platform built-ins (entity lookup, threat intel) or custom TypeScript implementations you write and deploy.

2

YAML and visual in sync

The visual editor and the YAML spec are always in sync. Edit in either mode — changes reflect immediately in the other. Version-control the YAML spec alongside your detection rules.

3

Deploy in minutes

Deploy a custom agent to your tenant with a single click or CLI command. The agent starts receiving findings matching the trigger within seconds, running alongside the built-in agents.