Use cases / Risk, legal and compliance
AI Cybersecurity
Triage at machine speed, containment with human sign-off.
01
Problem
Analysts drown in alerts. An agent with broad write access to production is itself an attack surface.
02
AI capability
Enrich and triage alerts, correlate events, draft investigation timelines and propose containment steps.
03
Data
The agent works from the context you connect, not from the open internet by default.
- SIEM and EDR alerts
- Asset and identity inventory
- Threat intelligence
- Runbooks
04
Agent
SecOps Agent
Triages alerts and investigates, proposing actions to the on-call analyst.
05
Workflow
- 1. Alert fires
- 2. Enrich context
- 3. Correlate events
- 4. Assess severity
- 5. Propose containment
- 6. Analyst approval
- 7. Execute and record
06
Governance
Governance runs inside the agent at runtime: policy changes what it can actually do.
Can
- Read alerts and logs
- Enrich with threat intel
- Draft timelines
- Open and update incidents
Cannot
- Disable accounts or isolate hosts unattended on critical assets
- Delete logs
- Change its own access
- Query data outside security scope
Requires approval
- Host isolation
- Account suspension
- Firewall rule changes
Records
Agent identity, Data accessed, Model used, Output, Tools called, Policy applied, Decision, Approval, Action, Outcome.
Suggested starting autonomy: L2 Approve
Start at L2 for containment; reading and triage can run at L3 under monitoring.
07
Outcome
What you measure, so the agent earns more autonomy on evidence:
- Time to triage
- Alerts closed with a recorded reason
- False-positive rate after review
- Containment actions with approval on record
Questions
Can it isolate a host by itself?
Not by default. Containment requires approval until your team deliberately raises the autonomy level for specific actions.
What identity does it use?
Its own, with least-privilege permissions defined in its Trust Profile.
Build it on the platform
Related use cases
- AI RiskKnow which AI is running, at what risk, under which controls.
- AI Compliance AutomationCollect evidence and monitor controls continuously instead of at audit time.
- AI OperationsTurn AI into operational execution, inside defined limits.
- AI CodingFaster engineering without giving agents the keys to production.