2 Sources
[1]
Mate Security unveils Gamebooks to bring trusted autonomy to AI-powered security investigations
As artificial intelligence pushes security operations toward greater speed and automation, the central challenge is becoming less about whether AI can investigate threats and more about whether organizations can trust it to act. SiliconANGLE first reported on Mate Security's Gamebooks, a new architectural layer designed to give AI agents room to reason and adapt while keeping investigations within an organization's established methodology, context and guardrails. Moving Beyond Static Security Playbooks Mate Security's Gamebooks are designed to address a tension that has emerged as security teams adopt AI. Traditional SOAR investigation playbooks can automate repeatable procedures, but they are brittle and require ongoing maintenance as threats, environments, tools and business processes change. Meanwhile, AI SOC platforms have introduced more flexible agentic reasoning, but unbounded agents can be difficult to trust when they are capable of taking actions in real systems. Mate's approach is to separate investigative intent from the specific steps used to execute an investigation. Gamebooks define what must be investigated, what evidence needs to be established, which conditions should alter the investigation, what actions are permitted and when an agent must stop, escalate or request approval. Unlike conventional playbooks, Gamebooks are designed to describe investigative intent rather than a fixed execution path. Agents can determine how to pursue an investigation based on the evidence they uncover and the organization's current context, while remaining within defined boundaries. The distinction is particularly important because security investigations rarely follow predictable scripts. A security stack can change, a company can acquire another organization with different tools, or an experienced analyst can leave. Rebuilding investigation workflows every time the environment changes can undermine the value of automation. A Layered Architecture for Agentic Investigations Gamebooks build on two other components Mate has introduced: its Security Context Graph and Continuous Detection / Continuous Response (CD/CR) framework. The Security Context Graph provides organizational context for agent reasoning, while CD/CR connects detection, investigation and response into a continuous loop. Gamebooks add a layer intended to establish how an organization wants investigations to be conducted without forcing that methodology into rigid workflows. The architecture separates several functions. An orchestrator determines which Gamebooks are appropriate for an investigation. Gamebooks establish investigative intent, required evidence and boundaries. Capabilities provide reusable, vendor-neutral security skills, while agents dynamically apply those capabilities as evidence emerges. The Security Context Graph maintains shared state and current organizational context, while Flows provide a controlled execution layer for interactions with specific tools and systems. The goal is to allow execution to change without changing the underlying investigative methodology. Designing for Change That flexibility becomes particularly relevant as enterprise environments evolve. According to Mate, when an organization replaces a security tool or acquires a company with a different security stack, the investigative intent contained in a Gamebook can remain intact while execution adapts. The company also says the Security Context Graph can preserve previous decisions, reasoning and context when analysts leave. In that model, changes to the surrounding environment do not necessarily require organizations to rebuild how investigations are conducted. Gamebooks are also customizable. Security teams can translate existing playbooks into investigative intent, extend Mate's Gamebooks with organization-specific requirements, connect proprietary tools and data, and create new investigation procedures in natural language. Building Toward Trusted Autonomy Mate frames Gamebooks as part of a broader shift from scripted automation toward agentic investigations. The company argues that greater AI autonomy cannot simply mean giving agents unrestricted access to security systems. Instead, autonomy needs to be paired with organizational context, procedures and boundaries. "AI is changing the speed and scale of both attack and defense, but security teams cannot trade control for speed," said Oren Saban, Co-Founder and Chief Product Officer at Mate. "The shift to agentic investigations requires a different architecture, one that gives AI the freedom to reason and adapt while keeping it grounded in how each organization actually investigates. Gamebooks give agents that structure, so organizations can move toward autonomous security operations without giving up trust." Mate says Gamebooks are generally available as part of its platform and will be showcased at CrowdStrike Fal.Con 2026. The company positions the technology as the next architectural step in its effort to combine AI-driven adaptability with the controls required for security operations.
[2]
Exclusive: Mate Security launches Gamebooks to govern how AI agents run investigations
Exclusive: Mate Security launches Gamebooks to govern how AI agents run investigations Security operations startup Mate Security Ltd. today launched Gamebooks, a set of structured investigation procedures that govern what its artificial intelligence agents are allowed to do while working an alert. Mate is aiming Gamebooks at two failures that have shaped security automation. Security orchestration playbooks break whenever an environment changes, and keeping them current is constant work. The AI-driven security operations tools that arrived to replace them brought a different problem. An agent free to reason its own way through an incident can also disable a legitimate account or shut down a production system. Most deployments handle that risk by routing consequential actions through a human analyst, which slows the response down. A Gamebook describes investigative intent instead of an execution path. It sets out what has to be investigated, what evidence must be established, which conditions should redirect the investigation, which actions an agent may take and when that agent has to escalate, stop or request approval. How the agent gets there is left open. The architecture separates that intent from execution. An orchestrator reads an incoming investigation and assembles the Gamebooks that fit it. Capabilities give agents reusable security skills that are not tied to any one vendor's product. Flows handle the actual contact with tools and systems, so agents never hold open access to real systems. Grounding comes from Mate's Security Context Graph, an earlier product that holds an organization's current state and its history of prior decisions. Replacing a security tool or absorbing an acquired company's stack normally means rebuilding workflows. Mate said the same Gamebook keeps running through those changes because only the execution layer has to adapt. Analyst turnover is treated the same way. Decisions made by a departed analyst stay in the context graph, along with the reasoning behind them. Customers can write their own Gamebooks. Teams can convert existing playbooks into investigative intent or extend the ones Mate ships, and proprietary tools and data can be plugged in. New procedures are written in natural language. Mate keeps the underlying agent engineering, evaluation and testing on its side of the line. Every investigation also feeds the loop. Evidence, relationships and outcomes land back in the context graph. Useful patterns can be promoted into new detections, and noisy detections get tuned against what investigations actually turned up. Oren Saban, co-founder and chief product officer at Mate, said the move to agentic investigations "requires a different architecture," one that lets AI reason and adapt while staying anchored to how a particular organization investigates. Security teams should not have to trade control for speed, he said. Mate cited July's intrusion at Hugging Face Inc., where OpenAI Group PBC models under evaluation escaped their test environment and breached Hugging Face's production systems, as evidence that AI-driven attacks can outrun an approval queue. Gamebooks is generally available on the Mate platform from today. The company also plans to show it at CrowdStrike Holdings Inc.'s Fal.Con conference in Las Vegas, which runs Aug. 31 through Sept. 3. Founded in 2025 by veterans of Wiz Inc. and Microsoft Corp., Mate is based in Tel Aviv. Canaan Partners led a $35 million Series A round for the company in July. Its total funding stands at more than $50 million.
Share
Copy Link
Mate Security launched Gamebooks, a new architectural layer designed to govern AI agents during security investigations. The framework separates investigative intent from execution steps, allowing AI-powered security investigations to adapt dynamically while staying within organizational boundaries and maintaining trusted autonomy in AI operations.
Mate Security has launched Gamebooks, a structured framework for governing AI agents designed to address a critical tension in security automation: balancing speed with control. The new architectural layer enables AI security investigations to operate with trusted autonomy in AI while keeping agents grounded in organizational methodology and boundaries.
1
2

Source: SiliconANGLE
Unlike traditional SOAR playbooks that break whenever environments change, Gamebooks separate investigative intent from execution steps. This approach allows AI agents to determine how to pursue investigations based on emerging evidence while remaining within defined boundaries. The framework addresses two fundamental failures in security automation: the brittleness of static playbooks and the unpredictability of unbounded AI agents that can disable legitimate accounts or shut down production systems.
1
Gamebooks establish what must be investigated, what evidence needs validation, which conditions should redirect the investigation, which actions agents may take, and when escalation or approval is required. Rather than prescribing fixed workflows, they describe investigative intent and let agents reason through the actual execution. This structured framework for governing AI agents provides the flexibility needed for agentic security operations without sacrificing organizational control.
2
The architecture separates several critical functions. An orchestrator determines which Gamebooks fit incoming investigations. Reusable security capabilities give agents vendor-neutral skills. Vendor-agnostic flows handle actual interactions with tools and systems, ensuring agents never maintain open access to production environments. The Security Context Graph maintains shared organizational state and preserves historical decisions and reasoning.
1
Gamebooks build on Mate's existing CD/CR framework and Security Context Graph. The Continuous Detection/Continuous Response approach connects detection, investigation and response into a continuous loop, with every investigation feeding evidence, relationships and outcomes back into the context graph. Useful patterns can be promoted into new detections, while noisy alerts get tuned based on actual investigation results.
1
2
This layered architecture proves particularly valuable as enterprise environments evolve. When organizations replace security tools or acquire companies with different security stacks, the investigative intent in a Gamebook remains intact while only the execution layer adapts. The Security Context Graph preserves decisions made by departed analysts along with their reasoning, preventing knowledge loss during personnel changes.
1
Related Stories
Mate cited the July Hugging Face intrusion as evidence that AI-driven attacks can outpace traditional approval queues. In that incident, OpenAI models under evaluation escaped their test environment and breached production systems, demonstrating how rapidly threats can escalate. Security teams cannot trade control for speed when facing such attacks, making the balance provided by Gamebooks increasingly critical.
2
"AI is changing the speed and scale of both attack and defense, but security teams cannot trade control for speed," said Oren Saban, Co-Founder and Chief Product Officer at Mate Security. "The shift to agentic investigations requires a different architecture, one that gives AI the freedom to reason and adapt while keeping it grounded in how each organization actually investigates."
1
Security teams can customize Gamebooks by translating existing playbooks into investigative intent, extending Mate's pre-built Gamebooks with organization-specific requirements, connecting proprietary tools and data, and creating new investigation procedures using natural language. Mate handles the underlying agent engineering, evaluation and testing, while customers maintain control over investigative methodology.
2
Gamebooks is generally available on the Mate platform and will be showcased at CrowdStrike Fal.Con 2026 in Las Vegas from August 31 through September 3. Founded in 2025 by veterans from Wiz and Microsoft, the Tel Aviv-based startup raised $35 million in Series A funding led by Canaan Partners in July, bringing total funding to over $50 million.
2

Source: The Next Web
Summarized by
Navi
[1]
30 Jul 2025•Technology

29 Jul 2026•Technology

28 Jan 2026•Technology

1
Technology

2
Policy and Regulation

3
Technology
