Agents are AI-powered responders that investigate every issue. They pick the right skill to follow, run tools to gather context, and either close the issue, escalate it to your on-call members, or ask a human for approval to continue.
What an agent is
An agent is a configured responder defined by:- Monitors: The event sources it pays attention to.
- Skills: A skill is a reusable playbook that teaches the agent how to perform a specific class of tasks to a known standard, along with the tools available to investigate and remediate security issues.
- Tools: The actions it can execute, assigned through skills (Slack, DNS, Jira, AWS, and more).
- Notification preferences: How it requests human approval or clarification.
What an agent does
- Triages issues: Produces a summary, report, recommendations, and risk assessment for every issue that matches its monitors.
- Digs in on escalations: Runs deeper analysis once an issue is escalated.
- Executes response: Calls tools to remediate (revoke a token, change a DNS record, post to Slack, file a Jira ticket).
- Asks for approval: Requests human approval before sensitive actions, or clarification when input is needed to proceed.
- Resumes: Suspended or paused investigations resume automatically once a human responds.
Creating agents
Build an agent from a template or from scratch.
Monitors
Configure the event sources your agents pay attention to.