Mate Security introduces Gamebooks to provide reliable autonomy in AI-driven security investigations.
As artificial intelligence accelerates security operations toward enhanced speed and automation, the primary challenge is shifting from whether AI can investigate threats to whether organizations can trust AI to take action. SiliconANGLE initially reported on Mate Security’s Gamebooks, a new architectural layer aimed at allowing AI agents to reason and adapt while ensuring investigations align with an organization’s established methodology, context, and constraints.
**Evolving Beyond Rigid Security Playbooks**
Credit: Mate Security
Mate Security’s Gamebooks are crafted to resolve a tension that has surfaced as security teams incorporate AI. Traditional SOAR investigation playbooks can automate repetitive procedures, yet they are fragile and require continual updates as threats, environments, tools, and business operations evolve. In contrast, AI SOC platforms offer more adaptable agent reasoning; however, agents lacking boundaries can be hard to trust when they are capable of executing actions within real systems.
Mate’s strategy is to distinguish investigative intent from the specific actions taken during an investigation. Gamebooks outline what needs investigation, the evidence that must be gathered, the conditions that might change the investigation, permissible actions, and when an agent should halt, escalate, or seek approval.
Unlike standard playbooks, Gamebooks focus on indicating investigative intent rather than prescribing a fixed sequence of actions. Agents can decide how to pursue an investigation based on the evidence they find and the current context of the organization, all while adhering to defined constraints.
This differentiation is crucial since security investigations rarely conform to predictable patterns. Changes in the security stack, acquisition of a different organization with alternative tools, or the departure of a seasoned analyst can all disrupt workflows. Reconstructing investigation processes each time the environment changes can diminish the benefits of automation.
**A Multi-Layered Framework for Agent-Led Investigations**
Credit: Mate Security
Gamebooks build upon two additional components introduced by Mate: its Security Context Graph and Continuous Detection / Continuous Response (CD/CR) framework. The Security Context Graph supplies organizational context to support agent reasoning, while CD/CR links detection, investigation, and response in a seamless cycle. Gamebooks provide a layer that defines how an organization wishes to conduct investigations without rigidly imposing that methodology into workflows.
The architecture divides several functions: An orchestrator selects appropriate Gamebooks for a given investigation. Gamebooks specify investigative intent, necessary evidence, and limits. Capabilities offer reusable, vendor-agnostic security skills, while agents flexibly apply those skills as evidence surfaces. The Security Context Graph maintains a shared state and reflects the current organizational context, whereas Flows create a controlled execution layer for interactions with specific tools and systems.
The aim is to enable execution to evolve without altering the core investigative methodology.
**Designing to Accommodate Change**
This adaptability is particularly significant as enterprise environments advance. According to Mate, when an organization updates a security tool or acquires a company with a different security framework, the investigative intent within a Gamebook can remain unchanged even as execution adjusts.
The company asserts that the Security Context Graph can retain prior decisions, rationale, and context even when analysts change roles. In this model, environmental alterations do not necessarily compel organizations to reinvent their investigative processes.
Gamebooks are also customizable; security teams can adapt existing playbooks into investigative intent, enhance Mate’s Gamebooks with organization-specific criteria, link proprietary tools and data, and formulate new investigative procedures using natural language.
**Progressing Towards Trusted Autonomy**
Mate positions Gamebooks as part of a broader transition from scripted automation to agent-led investigations. The company contends that increased AI autonomy must not merely involve granting agents unrestricted access to security systems. Instead, such autonomy should be supplemented by organizational context, procedures, and boundaries.
“AI is altering the speed and scale of both attacks and defenses, yet security teams cannot sacrifice control for speed,” stated Oren Saban, Co-Founder and Chief Product Officer at Mate. “The transition to agent-led investigations demands a different architecture, one that empowers AI to reason and adapt while remaining grounded in an organization’s actual investigative practices. Gamebooks provide that framework, enabling organizations to advance toward autonomous security operations without losing trust.”
Mate announces that Gamebooks are generally available as part of its platform and will be highlighted at CrowdStrike Fal.Con 2026. The company frames this technology as a crucial architectural progression in its mission to merge AI-driven adaptability with the necessary controls for security operations.
Other articles
Mate Security introduces Gamebooks to provide reliable autonomy in AI-driven security investigations.
Mate Security has introduced Gamebooks, a feature that distinguishes investigative intent from execution steps, allowing AI agents to adjust to evolving security stacks without the need to modify investigation logic. It is now generally available and was highlighted at Fal.Con 2026.
