Use cases / Risk, legal and compliance

AI Cybersecurity

Triage at machine speed, containment with human sign-off.

01

Problem

Analysts drown in alerts. An agent with broad write access to production is itself an attack surface.

02

AI capability

Enrich and triage alerts, correlate events, draft investigation timelines and propose containment steps.

03

Data

The agent works from the context you connect, not from the open internet by default.

  • SIEM and EDR alerts
  • Asset and identity inventory
  • Threat intelligence
  • Runbooks

04

Agent

SecOps Agent

Triages alerts and investigates, proposing actions to the on-call analyst.

05

Workflow

  1. 1. Alert fires
  2. 2. Enrich context
  3. 3. Correlate events
  4. 4. Assess severity
  5. 5. Propose containment
  6. 6. Analyst approval
  7. 7. Execute and record

06

Governance

Governance runs inside the agent at runtime: policy changes what it can actually do.

Can

  • Read alerts and logs
  • Enrich with threat intel
  • Draft timelines
  • Open and update incidents

Cannot

  • Disable accounts or isolate hosts unattended on critical assets
  • Delete logs
  • Change its own access
  • Query data outside security scope

Requires approval

  • Host isolation
  • Account suspension
  • Firewall rule changes

Records

Agent identity, Data accessed, Model used, Output, Tools called, Policy applied, Decision, Approval, Action, Outcome.

Suggested starting autonomy: L2 Approve

Start at L2 for containment; reading and triage can run at L3 under monitoring.

How controlled autonomy works

07

Outcome

What you measure, so the agent earns more autonomy on evidence:

  • Time to triage
  • Alerts closed with a recorded reason
  • False-positive rate after review
  • Containment actions with approval on record

Questions

Can it isolate a host by itself?

Not by default. Containment requires approval until your team deliberately raises the autonomy level for specific actions.

What identity does it use?

Its own, with least-privilege permissions defined in its Trust Profile.

Build it on the platform

Related use cases

Automate the response with SecOps Agents

Autonomous security orchestration: triage, investigation and containment, with a full audit trail.