The safety business has spent years attempting to automate investigations, first via more and more refined playbooks and extra not too long ago via AI brokers able to reasoning via incidents. The issue is that every strategy has a tradeoff: conventional automation might be too inflexible, whereas unrestricted AI might be troublesome to belief with consequential safety actions. SiliconANGLE was among the many first to report on Mate Safety’s Gamebooks, which the corporate says are designed to deal with that hole.
The Limits of Safety Automation

Safety investigations hardly ever unfold in line with a predetermined sequence. Threats evolve, enterprise environments change, safety instruments are changed and enterprise processes are up to date. But typical SOAR playbooks depend upon predefined workflows that may require important upkeep when these situations change.
AI SOC platforms have provided a unique mannequin by permitting brokers to purpose via investigations fairly than merely comply with scripts. However that flexibility creates one other downside. An agent that may independently determine what to do might also function outdoors a corporation’s established processes or take an motion that was by no means supposed.
Mate argues that the business shouldn’t body this as a alternative between autonomy and management. As a substitute, it’s a query of methods to construct managed autonomy into the structure of safety operations.
That’s the place Gamebooks are available.
From Execution Paths to Investigative Intent
Mate describes Gamebooks as structured investigation procedures constructed particularly for AI brokers. Quite than prescribing each step an agent should take, they set up what an investigation wants to perform and the boundaries inside which the agent can function.
A Gamebook can outline what proof must be collected, what situations ought to change an investigation, which actions are allowed and when an agent ought to escalate, cease or request approval. The agent retains the power to purpose and adapt based mostly on what it finds.
This creates a distinction between investigative intent and execution. The group determines how an investigation needs to be approached, whereas the agent determines methods to navigate the precise circumstances of an incident.
Mate describes the outcome as deterministic the place it issues and dynamic the place flexibility is helpful.
How Gamebooks Match Into Mate’s Structure

Gamebooks will not be being launched as a standalone automation characteristic. They construct on two architectural parts Mate has beforehand launched: its Safety Context Graph and Steady Detection / Steady Response framework.
The Safety Context Graph captures organizational context and gives a basis for agent reasoning. The CD/CR framework connects detection, investigation and response right into a steady loop.
Gamebooks add the procedural layer. An orchestrator determines which Gamebooks apply to an investigation, whereas the Gamebooks set up intent, required proof and bounds. Brokers use reusable, vendor-neutral capabilities as proof emerges, with the Safety Context Graph sustaining shared state and present context.
Flows then present the managed execution layer via which brokers work together with particular instruments and programs.
The separation is designed to stop investigative logic from turning into depending on particular person instruments, APIs or predetermined execution paths.
Retaining Investigations Intact as Environments Change
For enterprise safety groups, one of many extra necessary implications is what occurs when the setting itself modifications.
A corporation may exchange a safety product, purchase an organization with a wholly completely different expertise stack or lose an skilled analyst. Beneath a conventional playbook mannequin, these modifications can require investigation workflows to be rebuilt.
Mate’s mannequin is meant to maintain the investigative intent intact whereas permitting execution to adapt. The corporate says its Safety Context Graph may also protect earlier selections, reasoning and context, permitting organizational data to stay a part of the system at the same time as personnel and environments change.
That strategy additionally extends to customization. Organizations can convert present playbooks into investigative intent, add their very own necessities to Mate’s Gamebooks, join proprietary instruments and information, and outline new procedures utilizing pure language.
A Totally different Path to Autonomous Safety
The underlying argument behind Gamebooks is that making AI brokers extra succesful will not be sufficient. Safety operations require brokers that may function rapidly with out stepping outdoors the processes and controls established by the group.
“AI is altering the pace and scale of each assault and protection, however safety groups can’t commerce management for pace,” mentioned Oren Saban, Co-Founder and Chief Product Officer at Mate. “The shift to agentic investigations requires a unique structure, one that offers AI the liberty to purpose and adapt whereas conserving it grounded in how every group really investigates. Gamebooks give brokers that construction, so organizations can transfer towards autonomous safety operations with out giving up belief.”
Mate says Gamebooks are actually typically accessible as a part of its platform. The corporate may even showcase the expertise at CrowdStrike Fal.Con 2026.
For Mate, the broader goal is a shift away from safety automation constructed round fastened scripts and towards investigations by which AI can adapt to altering proof whereas remaining anchored to organizational context, methodology and guardrails.

