Gravwell has released a set of environment-aware AI agents in version 5.10 of its platform, giving security operations teams automated help with alert triage, threat hunting, and infrastructure management while keeping guardrails on what the AI can access and do.
The agents pull context directly from a customer's deployment - live telemetry, searches, detections, system state, flows, and playbooks - rather than relying only on preassembled context from individual alerts. This lets them investigate activity and collect supporting evidence from the actual security environment.
The release addresses a familiar problem for operations teams: analysts routinely receive alerts that still demand significant manual investigation before they can determine what happened, how serious it is, and what to do next.
What the agents do
The Alert Triage Agent runs supporting queries and gathers relevant context automatically, then delivers an investigation report to an analyst. The Case Agent works alongside analysts and threat hunters to write queries, interpret results, and recommend the next investigative pivot while maintaining context throughout an investigation.
Gravwell has also introduced agents for platform operations. The Admin Agent answers questions about deployment configuration and platform health. The Audit Agent checks automations, alerts, queries, infrastructure, and data flows for problems including stalled searches, unused alerts, missing ingesters, and dead data feeds.
A Daily Summary Agent reviews the previous day's telemetry to identify activity that may need additional investigation and provides queries analysts can use to explore its findings.
Guardrails around autonomy
The agents ship through the company's AI Agent Preview kit with predefined tools, permissions, and workflows. Gravwell 5.10 includes an in-product view of agent workflows, so users can see what information an agent accessed, which tools it used, and the steps it took to reach a conclusion.
"Autonomy without context or boundaries can create more problems than it solves," said Corey Thuen, CEO and co-founder of Gravwell. "Gravwell agents can gather the context they need from the customer's actual environment while operating within defined tools, permissions and procedures."
The approach is not designed to remove analysts from the process. Instead, it automates repetitive evidence gathering, initial analysis, and platform checks while leaving decisions requiring human judgment with security teams. For operations professionals evaluating AI for Cybersecurity Analysts, the model here is instructive: automation handles the grunt work, humans keep the decision rights.
The AI Agent Preview kit is available across Gravwell editions, including the free Community Edition.
Why this matters for operations teams
If you run a security operations workflow, the key detail is the audit trail. Gravwell 5.10 shows what an agent accessed and which tools it used before reaching a conclusion. That visibility matters when you need to explain an automated investigation to auditors, regulators, or an incident response lead. The agents also reduce the manual query-writing load that eats into analyst time, but the guardrails mean you can deploy them without handing over unrestricted control of your environment. For teams evaluating AI Agents & Automation, this release offers a concrete template for balancing autonomy with oversight.
Your membership also unlocks: