
We’ve recently shown how Mobot, Sumo Logic’s AI assistant, has evolved from a search assistant into a true thinking partner, introducing natural language to log analysis and monitors. Today, we’re bringing that same conversational reasoning to one of the most powerful parts of the platform: playbooks in Automation Service.
Historically, playbook authoring has been a highly manual process that required deep organizational and Sumo Logic platform knowledge. Most teams relied on a handful of power users or Sumo Logic Professional Services just to build and maintain playbooks, which reduced adoption and automation opportunities. Not because teams didn’t need it, but because building it themselves felt out of reach.
Conversational playbooks also mark a milestone for Mobot itself. Instead of living only in the Mobot tab, it now shows up directly in the page where the work happens (in this case, the playbook canvas) with full context of what you’re building. Expect Mobot to keep showing up in more places like this.
What’s new
Mobot now supports three conversational capabilities in Automation Service:
- Create: Describe a workflow in plain language and Mobot drafts an org-context-aware playbook. Where an LLM could give you generic YAML, Mobot uses your actual integrations and environment to deliver a bespoke playbook that’s ready to review and deploy with confidence.
- Edit: Request changes to an existing playbook conversationally, with your organization’s role-based access controls fully enforced.
- Summarize: Ask Mobot to explain what a playbook does and get a plain-language answer without tracing through every node yourself.
Conversational playbooks keep humans in control at every step. The same RBAC controls that govern playbook creation, editing, and viewing on the playbook canvas apply to Mobot, and every playbook Mobot drafts requires your confirmation before it publishes.
Build and understand a playbook in minutes
The clearest way to see the shift is to watch someone who’d normally be blocked by the canvas get unblocked by a conversation.
Example one: Building a ransomware response playbook
Context: A security engineer needs a ransomware response playbook, but doesn’t know the platform’s node and integration model well enough to build one solo. In the old workflow, that likely meant opening a ticket with Sumo Logic Professional Services or waiting on a more senior teammate, then a multi-hour build even once someone experienced picks it up.
Starting prompt: “Create a playbook that isolates an infected host, notifies the SOC channel, and opens an incident ticket when ransomware is detected.”
How Mobot tackles it: Mobot drafts a complete playbook structure using the organization’s existing context. It picks up the affected host from the triggering alert’s entity payload then sequences isolation, notification, and ticketing steps with the right integrations. The engineer reviews the draft, asks Mobot to adjust the notification routing, and has a working playbook to test in minutes.
The result: What used to take four to eight hours of manual mapping, and often required someone else’s expertise to even start, now takes a conversation. The engineer didn’t need to know the builder’s node logic to get a solid first draft.
Example two: Understanding a playbook someone else built
Context: A SOC analyst inherits a playbook built by a colleague who’s since moved teams. Before making any changes, they need to know what it actually does, and manually tracing every node and condition is slow and easy to get wrong.
Starting prompt: “What does this playbook do?”
How Mobot tackles it: Mobot reads the playbook’s structure and returns a plain-language summary of its logic, trigger conditions, and integrations, without the analyst needing to open the canvas at all.
The result: The analyst gets oriented in seconds instead of piecing the logic together node by node, and can move straight to deciding what, if anything, needs to change.
From idea to automation faster than ever
Playbook management has always required either deep platform expertise or help from someone who has it. Mobot closes that gap so more of the team can create, adjust, and understand automation independently, cutting the four-to-eight-hour build we talked about above down to minutes, and making it easier than ever to keep playbooks current as infrastructure evolves.
That time savings compounds where it matters most. A playbook that’s fast to build is one thing; a playbook that’s actually built, current, and understood by more than one person is what shortens mean time to resolution (MTTR) when a real incident hits. The easier playbooks are to create and maintain before an incident, the less your response depends on who happens to be on call, and the more of it runs on automation instead of tribal memory.
Try it for yourself
Conversational playbook management is available today for most Sumo Logic customers. Check out the help docs for instructions on how to get started.
Not yet a customer? Schedule a demo with our team.



