Automation Tools

Automation Tools turn a validated intent or an approved plan into action, and keep a full record of what ran and why it’s automatically retained.

Intent-Based Automation

A predefined automation tool that combines expected design and operational state to validate the network design and derive an accurate network status (error/warning/info) that can be actioned. Intent codifies what your network is supposed to do: the design rules, routing behavior, and configuration standards every agent and automation reasons from. Network Intent is where intents and their logic are defined and versioned.

Runbook Automation

A runbook is a deterministic workflow, not a static document sitting in a wiki somewhere. It’s how a senior engineer’s playbook, the exact steps they’d take to diagnose and fix a known problem, becomes something the whole team can run and reuse, not just read.

Troubleshooting runbooks integrate with ITSM tools like ServiceNow to generate a map and start diagnosis straight from a service ticket, cut down on non-actionable noise, and blend CLI, Network Intent, and AI in one workflow instead of three separate steps.

  • Change runbooks carry a network change through the same closed-loop discipline every time: pre-change validation, execution, post-change verification, comparison against the intended baseline, and documentation, protected by Triple Defense at every stage.
  • Change runbook nodes are labeled as planning, pre-change check, or post-change verification, and group related steps into named tasks that run in order. The system matches “before” and “after” data for labeled phases automatically. A change with several parts runs one section at a time instead of as one long list, and phase labels carry over when saved as a template.
  • Every generated change ships with its own paired rollback, automatically. Generation never produces one without the other, and if post-change verification turns up a mismatch, the fix-or-rollback choice is surfaced immediately instead of a manual scramble to find one — though a person still has to execute it.
  • Published runbooks, troubleshooting and change alike, land in the Runbook Library, so the fix for a known problem gets written once and reused, by the Change Agent, the Companion Agent, or an engineer, instead of rebuilt from scratch every time.
  • A detected violation can route two ways: a manual approval flow that holds it for an approver when the situation calls for caution, or a pre-approved flow your team has already signed off on for well-known, low-risk issues, so execution doesn’t wait on someone reviewing that specific instance. Either way, it runs through the same approval policies, SLA windows, and rollback triggers as every other change.
  • Change Wiki records every network change automatically, what changed, when, on which devices, and what config-level impact it had, with a short AI-written summary, drawn from both runbook executions and NetBrain’s own regular configuration scan.

Change and Task Manager both run on top of this same execution layer, closing the loop from detection to a verified, documented outcome, whether a runbook was hand-built, generated by the Change Agent, or pulled from the Assessment Library.

Live Action Tools

NetBrain Live Action Tools cover the direct, single-step operations available across the platform: running a CLI command, executing an Intent node, or running a Runbook node, without building a full workflow around it first.

  • Available inline from AI Copilot, without building a full workflow around them first.
  • Every action that changes network state still passes through the same approval and audit path as a full runbook. Common Actions include Ping, Traceroute, Path, Compare, Retrieve Live Data, Verify Application, CLI command execution, and running a pre-built Qapp or Gapp.

Agent Skills

Skills teach NetBrain’s agents your network’s own language: circuit IDs, internal WAN naming, tribal procedures, site-specific troubleshooting logic. No model retraining needed.

  • Skills Assistant builds one with you in conversation: attach a screenshot or a PDF, point it at a live data table, describe what you need, and it hands back a complete Skill document. Every refinement saves as its own version.
  • Skills are read by the agent once at the start of every agent execution, before reasoning begins, and matched by description to the task at hand. They act as guardrails.
  • Function Agents ship out of the box to cover golden config analysis, path computation, domain documentation, and parsing. Some are directly selectable in Copilot; the rest work as hidden subagents that other agents call on.
  • Subagents are services NetBrain ships specifically for delegation, called by System, Custom, and Function agents to handle a sub-task.

Agent Studio is where these Skills and agent categories get authored and governed.

Ansible Playbook Execution

Ansible is a popular provisioning, orchestration, and application deployment tool already in use across most IT organizations. Rather than treating it as a separate system, NetBrain brings it into the same governed workflow as every other action on this page.

  • Ansible Task node: define and execute an existing Ansible playbook, run a dry run before committing to changes, and get every execution result recorded automatically.
  • Syncs with source-controlled playbooks in GitHub and other SCM systems, so you’re always running the version your team maintains, not a copy pasted into NetBrain.
  • Runs through the same approval and audit path as every other Live Action Tool and Runbook node, no separate governance model to manage.

Frequently Asked Questions

What's the difference between Golden Assessment and Quick Assessment?

Golden Assessment checks your network’s design standards continuously, around the clock. Quick Assessment is a reusable template for one specific check, built once and applied on demand. 

What's the difference between a troubleshooting runbook and a change runbook?

A troubleshooting runbook drives diagnosis, often triggered straight from an ITSM ticket. A change runbook carries a network change through pre-check, execute, post-check, and verification, protected by Triple Defense. 

Does a generated runbook include a rollback plan?

Yes. Every generated change ships with its own paired rollback automatically; generation never produces one without the other. 

What is the Runbook Library?

A shared collection of published troubleshooting and change runbooks that the Change Agent, the Companion Agent, or an engineer can reuse instead of building one from scratch. 

What's the difference between a manual approval flow and a pre-approved flow?

A manual approval flow holds a task for an approver before it runs. A pre-approved flow is for well-known, low-risk issues your team has already signed off on, so an individual instance doesn’t wait on a fresh review. 

What is the Change Wiki?

An automatic record of every network change, what changed, when, and on which devices, drawn from runbook executions and NetBrain’s own configuration scan. 

What are Skills, and do they require retraining a model?

Skills are site-specific knowledge documents, like circuit naming and tribal procedures, that agents read before reasoning begins. No model retraining is required. 

verizen-1-300x120-1
tesla-1-300x120-1
cvs-1-300x120-1
capitalone-1-300x120-1
william-logo
nike-logo
scripps-health-logo
columbia-sportswear-logo

Trusted by Top Enterprises

“ Troubleshooting without NetBrain is like troubleshooting in the dark.”

Network Administrator Thomson Reuters
Testimonials & Case Studies