APPLICATION AREA / SECURITY OPERATIONSCONFIGURED PER DEPLOYMENT
Triage at machine speed. Containment at human speed.
A security operations centre is the clearest case for bounded autonomy on the platform: the investigative work is enormous and repetitive, and the containment actions are exactly the ones nobody should automate carelessly. Isolating a host, disabling an account and blocking a range are irreversible in the way that matters — they take production down as effectively as an attacker does.
This area has no pack yet, so the vocabulary and the measures are configured per deployment. What is described below is the platform behaviour that decides whether the work is safe to automate at all, and that part is already built.
The useful question is never “can it do this” — it is “what does it do without asking, and what does it bring to a person”. Each card answers both.
TASKgoverned
Work a tier-one alert queue.
The assistant: Enriches each alert from the sources it is assigned, correlates it against recent activity, and writes the finding with the evidence it used — including the alerts it judged benign and why.
The person: Nobody, for reading. The analyst inherits a queue that has been read rather than a queue that has been counted.
Proposed by the agent, decided by its policy
TASKgoverned
Investigate a suspected compromise.
The assistant: Follows the trail across the systems it may reach, assembles the timeline, and stages the containment it would recommend — without performing it.
The person: The responder authorises containment. Investigation and authority are different permissions here precisely because the second one takes systems offline.
Proposed by the agent, decided by its policy
TASKgoverned
Answer the question an auditor asks afterwards.
The assistant: Produces the sequence: what was seen, what was decided, by whom, and what was done — from the tenant’s own hash-chained record rather than from anyone’s memory.
The person: Whoever signs the report. The evidence they sign is verifiable rather than reconstructed.
Proposed by the agent, decided by its policy
04 / WHAT MUST NOT HAPPEN
The edges decide whether this ships.
Every deployment in this industry fails the same few ways. These are the ones the platform is built to make impossible rather than discouraged.
BOUNDARYenforced
Containment is never the agent’s to take
Isolation, account disablement and network blocks are declared destructive, and a destructive tool intent requires the approval its policy demands. An agent that could quarantine a subnet on a hunch is an outage with extra steps.
Refused, not discouraged
BOUNDARYenforced
The loop has an end it can reach
An investigation is bounded by iterations and time, and the reason it stopped is recorded. An agent chasing an alert forever is not thorough — it is a resource leak that looks like diligence.
Refused, not discouraged
BOUNDARYenforced
Where it may reach is resolved once and pinned
Outbound targets are validated and then pinned to the checked address, and loopback, private ranges and the cloud metadata endpoint are refused. A security tool that can be talked into fetching an internal URL is the vulnerability it was bought to find.
Refused, not discouraged
BOUNDARYenforced
The analyst is not asked to trust a verdict
Findings carry what they relied on, so a responder can disagree with the reasoning rather than with the conclusion — which is the difference between a tool that helps and a tool people quietly stop reading.
Refused, not discouraged
Starting here: There is no industry pack for security operations yet — the vocabulary and the measures are configured per deployment, which is a day of work rather than a project, and a pack is on the direction list. What is already here is the part that decides whether this is deployable at all: bounded execution, destructive actions behind approval, egress that cannot be redirected, and a record an auditor can verify.
05 / THE REST OF THE ANSWER
Same platform, whichever industry you run.
Everything on this page is configuration on top of one runtime. The controls underneath it are the same for every client, and they are written out in full on the platform page.
The first scope that works is a process somebody already owns, with a decision worth keeping human. Bring that, and we will map the agents, the integrations and the approval roles around it.