Mate Positions Gamebooks as the Next Step in Agentic Security Operations

Mate Security’s Gamebooks combine AI agent reasoning with guardrails, bringing controlled autonomy to security investigations.
Mate Security founders Mate Security founders

Security automation has moved through recognizable phases. Scripts came first, encoding what a good analyst would do in a given situation. Reasoning came next, with AI agents able to adapt rather than follow. The current phase is about combining the two, and Mate Security‘s release of Gamebooks, first reported by SiliconANGLE, is a clear marker of where that combination is heading.

From Scripted Automation to Agentic Investigation

Gamebooks chess analogy

The value of the playbook era was consistency. An investigation procedure could be captured once and applied every time.

Advertisement

The limitation of any script is that it assumes the world it was written for will stay in place. Threats change. Environments change. Security stacks and business processes change. That is simply the nature of the domain, and it is why the industry moved toward agentic reasoning in the first place.

Mate’s contribution is a way to keep the consistency of the first phase while retaining the adaptability of the second. The company describes Mate Security’s Gamebooks as the shift from scripting investigations in advance to giving AI the context, procedures, and boundaries to investigate and act dynamically.

The Design Principle

Gamebooks define investigative intent rather than a fixed execution path.

Each one sets out what must be investigated, what evidence must be established, which conditions should change the investigation, which actions are permitted, and when an agent must escalate, stop, or request approval. Agents are told what needs to be accomplished and which boundaries apply. They determine how based on the evidence they uncover and the organization’s most current context.

Mate’s shorthand for this is deterministic where it matters, dynamic where it helps.

Three Pieces, One Architecture

Gamebooks did not arrive alone. They are the third architectural foundation Mate has introduced over recent months.

The Security Context Graph came first, capturing organizational context as a foundation for agent reasoning. A continuous framework for detection, investigation, and response followed, establishing the three as one loop. Gamebooks supply the layer for controlled autonomy, which lets agents reason, adapt, and act at machine speed while every investigation stays within the organization’s methodology, context, and guardrails.

The question Gamebooks answer is how an AI system can follow the way an organization investigates without reducing that approach to another rigid workflow.

Why Timing Drives the Architecture

The speed argument sits underneath the whole design. AI-driven attacks operate continuously, in parallel, and adapt as defenders respond. Mate references the recent Hugging Face incident as an illustration. By the time an analyst validates evidence and approves containment, an attack may already have moved.

At the same time, the actions available to a security agent carry weight. Getting it right matters when the alternative can disable a legitimate account, revoke an executive’s access, or shut down a critical production system. Mate’s framing is that 90 percent accuracy is not enough at that level of consequence.

Controlled autonomy is the reconciliation. Agents reason, pivot, and act. The organization’s methodology, policies, and guardrails stay in force.

The Layers That Make It Work

Gamebooks deliver a layered architecture that separates investigative intent from execution, which keeps investigations adaptable, customizable, and resilient to changes in threats, environments, and security stacks.

An orchestrator reads the investigation and composes the right Gamebooks for the situation. Gamebooks define investigative intent, required evidence, and boundaries. Capabilities give agents reusable, vendor-neutral security skills. Agents dynamically apply those capabilities as evidence emerges. The Security Context Graph grounds the work in shared state and current organizational context. Flows provide the controlled execution layer for how agents interact with specific tools and systems.

Gamebooks architecture

Investigation logic stays free of any dependency on specific tools, APIs, or predefined execution paths.

Durability Through Transitions

That independence shows its value when the environment shifts. Organizations replace security tools. They acquire companies with entirely different stacks. Vendors introduce new alert types. Experienced analysts move on.

With Gamebooks, investigative intent remains intact while execution adapts. The same Gamebook continues operating through a tool change or an acquisition. The Security Context Graph preserves previous decisions along with the reasoning and context behind them when analysts leave.

Organizations Bring Their Own Method

Gamebooks are extensible and customizable, letting organizations adapt agentic investigations to their own processes, tools, and institutional knowledge without taking on the complexity of building, testing, and operating agentic systems.

Teams can translate existing playbooks into investigative intent, extend Mate’s expert-designed Gamebooks with organization-specific requirements, connect proprietary tools and data, and define new investigation procedures in natural language. Mate owns the underlying agent engineering, evaluations, testing, and execution, continuously validating and evolving the system as models, tools, and environments change while customers keep their investigation logic and customizations.

Compounding Over Time

Within the Continuous Detection / Continuous Response loop, every investigation adds evidence, relationships, outcomes, and reasoning to the Security Context Graph. Useful investigation patterns can improve capabilities, update Gamebooks, or become new detections. Noisy detections can be tuned based on actual investigation results. Each investigation improves the next.

“AI is changing the speed and scale of both attack and defense, but security teams cannot trade control for speed,” said Oren Saban, Co-Founder and Chief Product Officer at Mate. “The shift to agentic investigations requires a different architecture, one that gives AI the freedom to reason and adapt while keeping it grounded in how each organization actually investigates. Gamebooks give agents that structure, so organizations can move toward autonomous security operations without giving up trust.”

Gamebooks are generally available as part of the Mate platform, and Mate will showcase them at CrowdStrike Fal.Con 2026.

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use
Advertisement

Pin It on Pinterest

Share This