How does Tines compare to other SOAR platforms for a first-time SOAR buyer?

I’m in the early stages of evaluating SOAR platforms for my team and Tines keeps coming up in conversations. I haven’t used any SOAR tool before, so I don’t have a strong baseline for comparison. From the perspective of someone who’s used other platforms - or made this same decision before - what makes Tines stand out, and are there things it doesn’t do as well?

Fair warning that you’re asking this on a Tines community, so take the bias into account. :grinning_face_with_smiling_eyes: That said, here’s what tends to come up in these comparisons.

The biggest difference most people notice is that Tines doesn’t charge per action, per run, or per integration, which is a pricing model that can make other SOAR platforms unpredictable as usage scales. Tines also doesn’t require you to use a proprietary scripting language. Everything is built visually with a drag-and-drop storyboard, and the formula language is lightweight enough that you don’t need a development background to use it.

Where Tines is intentionally different from traditional SOAR platforms is scope. It’s a general-purpose automation platform, not a security-only tool. That means it doesn’t ship with prebuilt case management taxonomies or compliance frameworks specific to security operations the way some dedicated SOAR tools do. Whether that’s a pro or a con depends on how opinionated you want your tooling to be.

If you want to dig in a bit, Docs are worth exploring to get a sense of the platform’s capabilities, and working through Tines Foundations on Tines University will give you a practical feel for the builder experience pretty quickly. Or if you prefer “getting your hands dirty”, you can always sign up for a free Community edition of Tines!

Great points from @Marijana above, especially on pricing, since per-action/per-run models are a common pain point with legacy SOAR.

A few things I’d add as a first-time buyer specifically:

Tines being general-purpose means more flexibility than security-only tools, since you’re not boxed into a fixed case taxonomy or playbook structure. It’s a bigger commitment up front in terms of set up, but it pays off long-term, since you and your team get to define that structure yourselves rather than inheriting someone else’s opinion of how a SOC should be organized. That also means you can adapt it as your organization’s needs change, rather than being locked into someone else’s framework.

Tines connects to anything with an API rather than a fixed catalog, so it tends to hold up well even if your current stack includes niche or homegrown tools. You don’t have to change what works for you to work with Tines.

Since you have no SOAR baseline yet, I’d lean on the free Community edition Marijana mentioned. Building one real workflow yourself will give you a much better feel for the platform than any comparison page will.