CrewAI turns a pile of prompts into a team with job titles. Install the CLI, scaffold a JSON-first crew, wire a Flow around it, and put six practical agent workflows to work this week.
See the workflow in action, tap through the tabs below:
// zero to first crew, five commands
uv tool install crewai crewai create crew sec-digest cd sec_digest crewai install crewai run
// crew.jsonc task for a daily threat-intel digest
{
"name": "research_task",
"description": "Find credible reporting from the last 24 hours on {topic}. Prefer vendor advisories and primary sources.",
"expected_output": "Markdown digest: 5 items max, each with source, one-line summary, and why it matters to a mid-size org.",
"agent": "researcher",
"output_file": "output/digest.md",
"markdown": true
}
// agents/triage.jsonc, narrow job, measurable output
{
"role": "Log Triage Analyst",
"goal": "Cluster suspicious auth events from {log_excerpt} and rank the top 3 by risk",
"backstory": "You are a blue-team analyst. You never invent hosts or IPs. If evidence is weak you say so.",
"settings": { "verbose": true }
}
// local first, then ship it to CrewAI AMP
crewai run # prove it works locally git push # AMP deploys from your GitHub repo crewai login # authenticate the CLI # create the deployment, then check status and logs # first deploy usually lands in about a minute
Python 3.10 to 3.13 only. CrewAI refuses 3.14. Check with python3 –version before blaming the tool.
Folder names get underscores. crewai create crew sec-digest scaffolds sec_digest. Your imports must match the module path.
Verbose logs leak prompts. Anything in an agent backstory or task input can end up in logs. Keep secrets in .env, never in task text.
What CrewAI Actually Is (And What It Is Not)
CrewAI is an open source Python framework for building teams of AI agents that do real work together. You define each agent with a role, a goal, and a backstory. You hand it tools, web search, file readers, or your own Python functions. Then you group agents into a crew that runs tasks in sequence or delegates hierarchically, like a tiny org chart with deadlines.
The 2026 version is JSON-first, and that changes the learning curve. Running crewai create crew now scaffolds agents as plain .jsonc files, with tasks and crew settings living in crew.jsonc, and crewai run executes straight from that definition. Less boilerplate, faster iteration, and config diffs your teammates can actually review. If you prefer the classic Python and YAML scaffold, the --classic flag still gives you crew.py and the old config files.
What it is not: a chatbot wrapper, and not magic. Think of it as a job runner where the workers happen to be LLMs. Two building blocks matter. Crews handle autonomous teamwork. Flows handle event-driven orchestration with state, routing, and persistence. Learn both, in that order.
Quick Setup: Zero To Crew In Ten Minutes
You need Python between 3.10 and 3.13 (3.14 is not supported yet), plus the uv package manager, which CrewAI uses for dependency handling. The CLI installs as a global tool, so one install serves every project on your machine.
curl -LsSf https://astral.sh/uv/install.sh | sh uv tool install crewai crewai create crew sec-digest cd sec_digest crewai install crewai run
The scaffold gives you agents/researcher.jsonc, a crew.jsonc for tasks and crew settings, folders for knowledge, tools, and skills, plus a .env for API keys. Put your model provider key there, and grab a free Serper.dev key if you want the web search tool. Windows users: if the chroma-hnswlib build fails, install Visual Studio Build Tools with the C++ workload and rerun. That one error message has burned more beginners than every prompt mistake combined.
The Mindset: Crews Do The Work, Flows Run The Show
The biggest beginner mistake is building one giant agent with a novel for a prompt. CrewAI rewards the opposite. Give each agent one narrow job, one measurable artifact, and a backstory that sets rules of engagement, not personality fluff. "You never invent hosts or IPs" is a better backstory line than three paragraphs about being a wise mentor.
Then keep the orchestration boring on purpose. A Flow decides the order of steps, holds typed state, and handles routing and persistence in plain Python. The crew inside a step does the judgment work. Deterministic skeleton, probabilistic muscles. Use {placeholder} values in agent and task text, set defaults under inputs in crew.jsonc, and the CLI will prompt for anything missing at run time. Every task should declare an expected_output and, ideally, an output_file, because a crew that produces an artifact is testable and a crew that produces vibes is not.
Six Workflows Worth Stealing
1. The Daily Threat-Intel Digest
One researcher agent with the Serper web search tool, one task, one markdown artifact. Scope the task to the last 24 hours, cap it at five items, and demand a "why it matters" line per item. Run it every morning and you have a briefing that beats most paid newsletters. The exact task JSON is in the widget above, tab 02.
2. The Log Triage Summarizer
Feed a sanitized log excerpt in as a {log_excerpt} input and let a triage agent cluster suspicious auth events and rank the top three by risk. Do not wire it to production log APIs on day one. Copy excerpts in, judge the output for a week, then decide how much rope it earns.
3. CVE Watchlist To Patch Notes
Two agents: a watcher that searches for new advisories affecting your stack, and a writer that turns findings into a short action note, what we run, what is affected, what to do. Always verify CVE IDs before they hit a ticket. Agents are great at prose and mediocre at citations.
4. Runbook First Drafts
Paste shell history or messy incident notes into a writer agent whose goal is numbered steps, preconditions, and rollback. You still edit it, but you start from 80 percent instead of a blank page. Tribal knowledge dies in DMs; this drags it into the repo.
5. The Release Notes Crew
Pipe merged PR titles and descriptions in as input, have one agent group changes by audience impact and another rewrite them in customer language. Ten minutes of setup kills a recurring hour of Friday drudgery.
6. The Incident Timeline Builder
This one earns a real Flow: an ingest step normalizes alerts into state, a correlate step runs a crew to group related events, a narrative step writes the timeline. Because Flows persist state and can resume, a long incident does not mean starting over. Add a router step later to branch on severity.
Safety And Gotchas
Tools are the blast radius. An agent with file, shell, or HTTP tools will eventually do something you did not intend, so give it least privilege, run it in a container or throwaway VM, and never hand a crew production credentials just to see if it works. Keep a human between agent output and anything that mutates a real system.
Two quieter risks. First, verbose mode logs prompts and intermediate reasoning, which means anything you put in task inputs can land in log storage; keep secrets in .env and out of task text. Second, supply chain: CrewAI ships a sensible default that refuses transitive packages released in the last three days, but you should still pin your own direct dependencies. And treat every CVE number, URL, and version string an agent gives you as unverified until you check it yourself.
Cost And Usage Tips
The framework costs nothing to run locally; your bill is LLM tokens. Assign models per agent: a cheap fast model for watcher and triage roles, a strong model only for synthesis and writing. Tight expected_output definitions cap output tokens better than any pleading. Artifacts written via output_file mean you rerun a failed step, not the whole pipeline. Serper.dev has a free tier that covers the quickstart comfortably. When you outgrow your laptop, CrewAI AMP (the managed platform, free signup) or the self-hosted CrewAI Factory are the official routes, and the first AMP deploy from a GitHub repo typically lands in about a minute.
FAQ
Is CrewAI free to use?
The Python framework is open source and free to run anywhere. You pay for the LLM API calls your agents make. CrewAI AMP, the managed cloud platform, has a free signup at app.crewai.com, and CrewAI Factory is the self-hosted enterprise option.
How is CrewAI different from n8n or Flowise?
n8n and Flowise are visual builders where AI is one node among many. CrewAI is code-first Python where agent collaboration is the core primitive. If you enjoyed our Flowise for DevSecOps guide, CrewAI is the natural next step once your workflows need judgment, not just routing.
Do I need to be a Python expert to use CrewAI?
No. The JSON-first scaffold means your first crews are mostly editing role, goal, and task text in .jsonc files. Flows require some Python, but the quickstart pattern is copy-paste friendly and small enough to read in one sitting.
Your Move
Tonight: install the CLI, scaffold sec-digest, wire the threat-intel task from the widget, and put it on a schedule before Friday. Thirty minutes of setup buys you a briefing that shows up every morning. If you want structured, career-focused practice building agent systems for DevOps and security roles, our courses go deeper than any blog post can.

