Mate Security Launches Gamebooks as a New Architecture for Trusted AI Security Investigations

Wait 5 sec.

Security teams have spent years trying to automate investigations without losing the judgment and controls that make those investigations reliable. Traditional playbooks provide structure but can become outdated as environments change, while fully autonomous AI agents introduce a different concern: whether organizations can trust them to make consequential decisions. SiliconANGLE first reported on Mate Security’s Gamebooks, a new approach designed to give AI agents more freedom to investigate while keeping them grounded in organizational procedures and guardrails.The Problem With Both Playbooks and AI Agents** **Security investigations are rarely as predictable as the workflows built to automate them. Threats change, companies alter their technology environments, security products are replaced and business processes evolve. Traditional SOAR playbooks can struggle to keep up because their predefined execution paths require ongoing maintenance.AI SOC platforms have attempted to address that limitation by allowing agents to reason through investigations rather than follow static scripts. But greater autonomy introduces its own risks. An agent operating without structured procedures could make decisions that fall outside an organization's processes or take actions with serious operational consequences.Mate's answer is not to choose between automation and control. The company is positioning Gamebooks around what it calls controlled autonomy: allowing agents to reason, pivot and act while ensuring that investigations remain within the organization's methodology, context and guardrails.Defining What an Investigation Should AccomplishGamebooks are structured investigation procedures designed specifically for AI agents. Instead of prescribing every step an agent must follow, they establish the objectives and boundaries of an investigation.They define what needs to be investigated, what evidence must be established, which conditions should change the course of an investigation, what actions are permitted and when an agent should stop, escalate or request approval.That makes Gamebooks different from traditional playbooks. Their purpose is to define investigative intent rather than a fixed execution path. Agents can determine how to accomplish the objective based on the evidence available and the organization's most current context.Mate describes this as an architecture that is deterministic where necessary but dynamic where adaptability provides value.Separating Investigation Logic From Execution** **The Gamebooks architecture divides an investigation into several layers.An orchestrator reads the investigation and selects the appropriate Gamebooks. The Gamebooks establish investigative intent, required evidence and boundaries. Capabilities provide reusable, vendor-neutral security skills that agents can apply as evidence emerges.The Security Context Graph provides shared state and organizational context, while Flows control how agents interact with specific tools and systems.The separation is intended to keep investigation logic independent of particular security products, APIs or predefined execution paths. That means the methodology can remain consistent even when the mechanisms used to execute an investigation change.Gamebooks build on Mate's Security Context Graph and its Continuous Detection / Continuous Response, or CD/CR, framework. The company introduced those components as architectural foundations for agentic security operations, with the Context Graph providing context for agent reasoning and CD/CR connecting detection, investigation and response into a continuous loop.Built for Changing Security EnvironmentsEnterprise security environments rarely stay still, and Mate is designing Gamebooks around that reality.Organizations can replace security tools, acquire companies with different security stacks or lose experienced analysts. In a conventional playbook system, these events can require investigation workflows to be rebuilt.With Gamebooks, Mate says the investigative intent can remain intact while execution adapts to the new environment. The Security Context Graph can also preserve previous decisions, reasoning and context when analysts leave, allowing that institutional knowledge to remain part of the investigation process.Organizations can customize Gamebooks as well. Security teams can translate existing playbooks into investigative intent, extend Mate's Gamebooks with organization-specific requirements, connect proprietary tools and data, and define new investigation procedures in natural language.Toward Trusted Agentic Security OperationsThe broader idea behind Gamebooks is that autonomous security operations require more than increasingly capable AI models. Agents need enough freedom to respond at machine speed, but that freedom has to exist within a structure the organization can trust.“AI is changing the speed and scale of both attack and defense, but security teams cannot trade control for speed,” said Oren Saban, Co-Founder and Chief Product Officer at Mate. “The shift to agentic investigations requires a different architecture, one that gives AI the freedom to reason and adapt while keeping it grounded in how each organization actually investigates. Gamebooks give agents that structure, so organizations can move toward autonomous security operations without giving up trust.”Mate says Gamebooks are generally available as part of its platform and will be showcased at CrowdStrike Fal.Con 2026. The company sees the technology as another step in its broader architectural shift from scripted security automation toward agentic investigations that can adapt to changing evidence without abandoning organizational controls.**This story was published on HackerNoon under our Business Blogging Program