AI agents are giving security teams a new way to investigate threats, but greater autonomy also creates a difficult question: how much freedom can an organization safely give an AI system? SiliconANGLE first reported on Mate Security’s Gamebooks, a new architectural layer designed to let agents reason and adapt during investigations while keeping them within defined organizational procedures and guardrails.
Moving Beyond Static Playbooks
Security teams have traditionally used SOAR playbooks to automate investigations. The problem is that investigations rarely follow the same path for long. Threats change, security environments evolve, tools are replaced and business processes are updated, forcing teams to continually maintain workflows.
AI SOC platforms have attempted to solve that problem by replacing fixed workflows with agentic reasoning. But removing structure entirely introduces a different risk. An AI agent with broad autonomy can potentially make decisions outside an organization’s processes, even when the intent is to automate security operations.
Mate describes the solution as controlled autonomy. Instead of forcing agents to follow rigid scripts or allowing them to operate without meaningful boundaries, Gamebooks provide structured investigation procedures that define what agents need to accomplish and where they must stop.
Defining Investigative Intent
Gamebooks establish what must be investigated, what evidence needs to be established, which conditions should change an investigation, what actions are permitted and when an agent must escalate, stop or request approval.
The important distinction from traditional playbooks is that Gamebooks define investigative intent rather than a fixed execution path.
An agent can determine how to pursue an investigation based on the evidence it uncovers and the organization’s most current context. Mate describes the resulting approach as deterministic where it matters and dynamic where adaptability is useful.
The architecture also separates investigation logic from the specific technologies used to execute it. Investigation procedures are not tied to particular tools, APIs or predefined execution paths.
How the Architecture Works
Gamebooks are part of a broader architecture Mate has been developing for agentic security operations.
The company’s Security Context Graph captures organizational context and provides a foundation for agent reasoning. Its Continuous Detection / Continuous Response framework connects detection, investigation and response into a continuous loop.
Gamebooks add the procedural layer. An orchestrator selects the appropriate Gamebooks for an investigation, while Gamebooks establish investigative intent, required evidence and boundaries. Capabilities provide reusable, vendor-neutral security skills that agents can apply as evidence emerges.
The Security Context Graph maintains shared state and current context, while Flows provide the controlled execution layer for interactions with specific tools and systems.
This separation is designed to let investigative intent remain consistent even when execution needs to change.
Designed for Changing Environments
That flexibility becomes important when organizations change their security environments.
A company might replace a security tool, acquire another organization with a different technology stack or lose an experienced analyst. Traditional playbooks can require significant rebuilding under those circumstances.
Mate says Gamebooks allow investigative intent to remain intact while execution adapts. The Security Context Graph can also preserve previous decisions, reasoning and context, helping retain institutional knowledge when personnel change.
Organizations can customize the system as well. Security teams can translate existing playbooks into investigative intent, extend Mate’s Gamebooks with organization-specific requirements, connect proprietary tools and data, and define new investigation procedures in natural language.
Mate handles the underlying agent engineering, evaluations, testing and execution while customers retain their investigation logic and customizations.
Toward Trusted Agentic Investigations
The launch reflects Mate’s broader argument that AI-powered security operations require a different architecture rather than simply more capable models.
“AI is changing the speed and scale of both attack and defense, but security teams cannot trade control for speed,” said Oren Saban, Co-Founder and Chief Product Officer at Mate. “The shift to agentic investigations requires a different architecture, one that gives AI the freedom to reason and adapt while keeping it grounded in how each organization actually investigates. Gamebooks give agents that structure, so organizations can move toward autonomous security operations without giving up trust.”
Mate says Gamebooks are generally available as part of its platform and will be showcased at CrowdStrike Fal.Con 2026. The company positions the technology as a step toward moving security operations from scripted automation to agentic investigations that can adapt while remaining grounded in organizational methodology, context and guardrails.



