As artificial intelligence pushes security operations toward greater speed and automation, the central challenge is becoming less about whether AI can investigate threats and more about whether organizations can trust it to act. SiliconANGLE first reported on Mate Security’s Gamebooks, a new architectural layer designed to give AI agents room to reason and adapt while keeping investigations within an organization’s established methodology, context and guardrails.
Moving Beyond Static Security Playbooks

Mate Security’s Gamebooks are designed to address a tension that has emerged as security teams adopt AI. Traditional SOAR investigation playbooks can automate repeatable procedures, but they are brittle and require ongoing maintenance as threats, environments, tools and business processes change. Meanwhile, AI SOC platforms have introduced more flexible agentic reasoning, but unbounded agents can be difficult to trust when they are capable of taking actions in real systems.
Mate’s approach is to separate investigative intent from the specific steps used to execute an investigation. Gamebooks define what must be investigated, what evidence needs to be established, which conditions should alter the investigation, what actions are permitted and when an agent must stop, escalate or request approval.
Unlike conventional playbooks, Gamebooks are designed to describe investigative intent rather than a fixed execution path. Agents can determine how to pursue an investigation based on the evidence they uncover and the organization’s current context, while remaining within defined boundaries.
The distinction is particularly important because security investigations rarely follow predictable scripts. A security stack can change, a company can acquire another organization with different tools, or an experienced analyst can leave. Rebuilding investigation workflows every time the environment changes can undermine the value of automation.
A Layered Architecture for Agentic Investigations

Gamebooks build on two other components Mate has introduced: its Security Context Graph and Continuous Detection / Continuous Response (CD/CR) framework.
The Security Context Graph provides organizational context for agent reasoning, while CD/CR connects detection, investigation and response into a continuous loop. Gamebooks add a layer intended to establish how an organization wants investigations to be conducted without forcing that methodology into rigid workflows.
The architecture separates several functions. An orchestrator determines which Gamebooks are appropriate for an investigation. Gamebooks establish investigative intent, required evidence and boundaries. Capabilities provide reusable, vendor-neutral security skills, while agents dynamically apply those capabilities as evidence emerges. The Security Context Graph maintains shared state and current organizational context, while Flows provide a controlled execution layer for interactions with specific tools and systems.
The goal is to allow execution to change without changing the underlying investigative methodology.
Designing for Change
That flexibility becomes particularly relevant as enterprise environments evolve. According to Mate, when an organization replaces a security tool or acquires a company with a different security stack, the investigative intent contained in a Gamebook can remain intact while execution adapts.
The company also says the Security Context Graph can preserve previous decisions, reasoning and context when analysts leave. In that model, changes to the surrounding environment do not necessarily require organizations to rebuild how investigations are conducted.
Gamebooks are also customizable. Security teams can translate existing playbooks into investigative intent, extend Mate’s Gamebooks with organization-specific requirements, connect proprietary tools and data, and create new investigation procedures in natural language.
Building Toward Trusted Autonomy
Mate frames Gamebooks as part of a broader shift from scripted automation toward agentic investigations. The company argues that greater AI autonomy cannot simply mean giving agents unrestricted access to security systems. Instead, autonomy needs to be paired with organizational context, procedures and boundaries.
“AI is changing the speed and scale of both attack and defense, but security teams cannot trade control for speed,” said Oren Saban, Co-Founder and Chief Product Officer at Mate. “The shift to agentic investigations requires a different architecture, one that gives AI the freedom to reason and adapt while keeping it grounded in how each organization actually investigates. Gamebooks give agents that structure, so organizations can move toward autonomous security operations without giving up trust.”
Mate says Gamebooks are generally available as part of its platform and will be showcased at CrowdStrike Fal.Con 2026. The company positions the technology as the next architectural step in its effort to combine AI-driven adaptability with the controls required for security operations.
Get the TNW newsletter
Get the most important tech news in your inbox each week.
Contributed article. Not produced by the TNW newsroom and does not reflect the editorial stance of TNW.