IT Brief UK - Technology news for CIOs & IT decision-makers
United Kingdom
Gravwell unveils five AI agents for security teams

Gravwell unveils five AI agents for security teams

Wed, 23rd Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Gravwell has released version 5.10 of its security data platform with five environment-aware AI agents. The new agents are available through an AI Agent Preview kit across all editions, including Community Edition.

The update adds specialised agents for alert triage, case investigation, system administration, daily reporting and audit checks. They can pull context directly from a customer's deployment, including telemetry, searches, detections, system state, flows and playbooks, rather than relying only on preassembled information such as alerts or cases.

The release places Gravwell among security software suppliers trying to make generative AI useful in day-to-day operations while limiting what automated tools can access and do. Here, the software is presented as a set of narrowly defined agents with specific workflows and permissions rather than a single general-purpose assistant.

Five agents

The Case Agent is designed as an investigation tool for analysts and threat hunters. It can write and validate queries, run them, interpret the results and suggest the next step in an inquiry while keeping track of the wider investigative context.

The agent is read-only by default and saves queries only when a user instructs it to do so. The aim is to help analysts with the repetitive work of moving from one data point to the next during an investigation.

The Alert Triage Agent sits earlier in the workflow. It reviews alerts, runs supporting queries, gathers relevant context and prepares an initial investigation report, giving analysts a starting point with evidence attached rather than a standalone alert.

For platform administration, the Admin Agent answers questions based on the configuration of a customer's Gravwell deployment. It can help administrators understand ingesters, access controls, storage, replication, preprocessors, resources, secrets and overall platform health.

Two further agents focus on routine review and housekeeping. The Daily Summary Agent runs overnight to review the previous day's telemetry, identify activity that may need attention and suggest areas for follow-up. The Audit Agent carries out a read-only assessment across automations, alerts, query content, infrastructure and data flows.

The Audit Agent is intended to flag issues such as stalled searches, unused alerts, duplicate extractors, missing ingesters, dead data feeds and storage problems, then combine them into a prioritised report.

Controls and visibility

A central part of the release is how the software governs and displays each agent's activity. The AI Agent Preview kit delivers prebuilt agents with defined tools, permissions and workflows. Each specification sets out what parts of the environment the agent can access, which actions it may take and which procedures it follows.

The product also includes an in-application visualisation of agent workflows. Users can see what information an agent gathered, how it applied its instructions, which tools it used and how it reached its findings.

That level of traceability addresses a main concern around AI in security operations: teams need to understand why a system reached a conclusion and whether it had access to the right evidence. The issue is especially acute in environments where security and IT teams must justify investigative steps, tune alerts and avoid automation that acts without oversight.

Gravwell is also distinguishing its approach from AI tools that work largely from limited snapshots of context. By giving agents access to live data and environmental state within the customer's deployment, it argues the software can produce investigations and recommendations more closely tied to operational reality.

That approach also makes boundaries more important. The emphasis on read-only settings, explicit instructions and visible workflows suggests Gravwell is trying to reassure customers that broader access to data does not mean unrestricted action inside sensitive security environments.

Corey Thuen, Chief Executive Officer and Co-Founder of Gravwell, framed the launch around that balance between autonomy and control.

"Autonomy without context or boundaries can create more problems than it solves," said Corey Thuen, Chief Executive Officer and Co-Founder of Gravwell. "Gravwell agents can gather the context they need from the customer's actual environment while operating within defined tools, permissions and procedures. That gives security teams a controlled path toward greater autonomy without giving AI unrestricted access to security operations."

The decision to make the AI Agent Preview kit available in Community Edition as well as paid versions also stands out in a market where AI functions are often reserved for premium tiers. Gravwell said the feature is not limited to a separate top-end AI offering.

For users, the practical test will be whether these agents reduce the manual burden of evidence gathering and routine checks without introducing new uncertainty into investigations. The product's design centres on that trade-off, with agents that can search, review and report across a live environment while remaining confined to clearly defined tools, permissions and procedures.