Gravwell 5.10 adds five autonomous AI agents to security platform
New agents handle investigation support, alert triage, and system audits without requiring pre-assembled context.
Security data platform gains autonomous investigation capabilities
Gravwell has launched version 5.10 of its security data platform, introducing five AI agents that operate directly within customer deployments to support security operations and administrative tasks. The agents work autonomously to gather investigation context from live telemetry, detections, and system state data without depending on pre-packaged alert information.
Three of the agents target security analyst workflows. The Case Agent guides investigations from initial detection through resolution by writing and validating queries against the data platform. The Alert Triage Agent generates preliminary reports when alerts fire, streamlining the initial response process. The Daily Summary Agent examines historical telemetry to surface actionable queries that analysts should prioritize.
Two additional agents serve platform administrators. The Admin Agent fields configuration questions and provides guidance on system setup. The Audit Agent performs automated hygiene checks across automations and data flows, flagging operational issues such as stalled searches and inactive data feeds that could compromise visibility.
Why it matters
Security teams face mounting pressure to investigate more alerts with limited staff. Autonomous agents that can independently gather context and prepare investigation materials address a critical bottleneck in security operations. By making these capabilities available across all product tiers—including the free Community Edition—Gravwell enables organizations of any size to augment analyst capacity without expanding headcount. The transparency features that show which tools agents used and how they reached conclusions also address a key concern about AI adoption: maintaining human oversight and understanding of automated decisions.
Transparency and controlled deployment
Gravwell designed the agents with visibility into their decision-making processes. Security teams can review which tools each agent invoked and trace the reasoning behind their conclusions. This transparency mechanism provides a measured approach to AI adoption, allowing organizations to grant agents greater autonomy over time as trust builds, rather than immediately providing unrestricted system access.
The five agents ship as part of the AI Agent Preview kit, available immediately across Gravwell's product line including Community, Enterprise, and cloud editions. This broad availability reflects a strategy to democratize AI-assisted security operations beyond enterprise budgets.
The details were first reported by Silicon Angle.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call