What is a Story in Tines?

Quick Answer: A Story in Tines is a single automation workflow built as a directed graph of Actions. Stories are the Tines equivalent of a Zap in Zapier or a Playbook in traditional SOAR products, composed of six Action types: HTTP Request, Send Email, IMAP, Trigger, Event Transform, and Webhook.

What Is a Story in Tines

In Tines, a Story is the name for a single automation workflow. It is the Tines equivalent of a Zap in Zapier, a Scenario in Make, or a Playbook in traditional SOAR vendors such as Splunk SOAR. A Story is a directed graph of Actions connected by event flow: when an Action produces an event, downstream Actions receive it and process it according to their configuration.

Stories Are Composed of Actions

Every Story is built from six core Action types. As of April 2026, Tines deliberately keeps the Action catalog small so that analysts master the full toolkit:

  • HTTP Request — Calls any REST API (GET, POST, PUT, PATCH, DELETE). This is the most-used Action; most SaaS integrations are HTTP Requests against the vendor API.
  • Send Email — Sends outbound email via Tines' SMTP relay or a configured mail server. Used for notifications, approvals, and analyst updates.
  • IMAP — Polls a mailbox and emits events for new messages. Common in phishing triage workflows where users forward suspicious emails to a shared inbox.
  • Trigger — Branches event flow based on conditions. A Trigger evaluates rules (equality, regex, JSONPath) and only emits events that match, filtering the Story's downstream logic.
  • Event Transform — Reshapes event data: explode arrays into individual events, aggregate events over time, deduplicate, or map fields.
  • Webhook — Receives inbound HTTP requests from external systems, turning Tines into a webhook receiver. This is how external alerts (SIEM, ticketing, monitoring) kick off a Story.

Event Flow and Story Execution

Actions in a Story are connected by links. When an Action emits an event, it is queued and delivered to each downstream Action. Events are JSON objects and can reference fields from any prior event in the Story via a Jinja-style template syntax ({{ .received_event.body.subject }}). Because Stories are asynchronous event graphs rather than sequential scripts, multiple events can flow through the same Story concurrently.

Stories vs Resources, Credentials, and Tenants

Stories live inside a Team, which groups related work. Teams share Credentials (stored secrets for API authentication) and Resources (shared reference data such as lookup tables or configuration constants). A Tenant is the top-level Tines account; large organizations can run multiple Tenants for separation between environments or business units.

Typical Story Size

Production Stories commonly contain 10-40 Actions. Complex SOAR playbooks with multiple enrichment steps, conditional branching, and approval loops can reach 100+ Actions, but Tines recommends splitting very large Stories into smaller Stories connected by Webhooks for maintainability.

Exporting and Versioning Stories

Stories export to JSON and can be version-controlled in Git. Tines provides a Story Library where teams share reusable patterns, and the platform includes a change history view that shows recent edits to each Action within a Story.

Related Questions

Written & reviewed by Rafal Fila · Last updated:

Related Tools

Related Rankings

Dive Deeper

comparison

Keystroke vs n8n in 2026: Agent-Built TypeScript vs the Visual Canvas

Keystroke, launched in July 2026 by Y Combinator W24 company Sprint Labs, is a code-first automation platform where AI coding agents write workflows as TypeScript in the user's repository. n8n, founded in 2019, is the most widely deployed source-available visual workflow platform, with 200,000+ users and a $2.5 billion valuation. This comparison covers the agent-authored versus canvas building models, durable execution, licensing (Elastic License 2.0 vs the Sustainable Use License), verified July 2026 pricing including Keystroke's usage metering, and the maturity gap between a days-old platform and an established ecosystem.

comparison

QuantumBPM vs Camunda 2026: Single-Binary Challenger vs the BPMN Incumbent

QuantumBPM (launched 2026, Coroid s.r.o., Slovakia) packages a BPMN 2.0 runtime and DMN 1.5 decision engine into one Go binary backed by Temporal and PostgreSQL. Camunda (Berlin, founded 2013) is the category incumbent: Camunda 7 (Apache 2.0, in maintenance) and the Zeebe-based Camunda 8 platform. This comparison covers product structure, architecture, DMN TCK conformance with recording dates, deployment, pricing, and vendor maturity, verified July 2026.

case-study

Migrating 23 Make Scenarios to Self-Hosted n8n: a 3-Week Breakdown

Anonymized retrospective of a DTC ecommerce brand migrating 23 Make scenarios to a self-hosted n8n instance over three weeks. Tooling cost dropped from $348/month on Make Teams to roughly $12/month on a Hetzner VPS, but credential and webhook recreation consumed about 40% of total project time.