Gravwell has released Gravwell 5.10, adding environment-aware AI agents that execute multi-step security and operational workflows directly within customer deployments. The specialized agents can investigate alerts, assist with threat hunting, and monitor platform health while using context from an organization’s environment.
Rather than reasoning primarily from limited, preassembled context such as alerts, cases, or preconfigured integrations, Gravwell agents can gather the context they need directly from the environment, including live telemetry, searches, detections, system state, flows, and playbooks.
Using that context, agents can call the appropriate Gravwell tools to investigate activity, gather supporting evidence, troubleshoot issues, and surface findings that require human attention.
Agentic Security Built for Security and IT Operations
Gravwell 5.10 introduces a set of specialized agents designed to support different areas of security analysis and platform operations. They include:
-
Case Agent: Acts as an interactive investigation partner for analysts and threat hunters. It can write and validate Gravwell queries, run them, interpret the results and recommend the next investigative pivot while maintaining context throughout the investigation. The agent is read-only by default and saves queries only when explicitly instructed.
-
Alert Triage Agent: Operates between the detection and the analyst, reviewing alerts, running supporting queries, collecting relevant context and preparing an initial investigation report. Analysts receive supporting evidence and a clearer starting point rather than an isolated alert.
-
Admin Agent: Answers questions based on the configuration of an organization’s Gravwell deployment. It can help administrators understand ingesters, access controls, storage, replication, preprocessors, resources, secrets, and overall platform health.
-
Daily Summary Agent: Runs nightly to review the previous day’s telemetry, identify activity that may warrant attention, and suggest areas for further investigation. It also provides queries analysts can use to explore its findings.
-
Audit Agent: Performs a read-only health and hygiene assessment across automations, alerts, query content, infrastructure, and data flows. It identifies issues such as stalled searches, unused alerts, duplicate extractors, missing ingesters, dead data feeds, and storage problems, then consolidates them into a prioritized report.
Together, the agents handle repetitive evidence gathering, initial analysis and platform checks, giving analysts and administrators a more informed starting point and allowing them to focus on work that requires human judgment.
Controlled and Auditable AI Workflows
The agents are delivered through the AI Agent Preview kit, which provides prebuilt agents with defined tools, permissions, and workflows. Each agent specification defines which tools and portions of the MCP environment it can access, which actions it can perform, and which procedures it follows.
Gravwell 5.10 also features an in-product visualization of agent workflows. Users can see how an agent gathers information, applies its instructions, interacts with available tools, and progresses toward an outcome. This gives teams visibility into what an agent accessed, what steps it took and how it reached its conclusions.
“Autonomy without context or boundaries can create more problems than it solves,” said Corey Thuen, CEO and co-founder of Gravwell. “Gravwell agents can gather the context they need from the customer’s actual environment while operating within defined tools, permissions and procedures. That gives security teams a controlled path toward greater autonomy without giving AI unrestricted access to security operations.”
The AI Agent Preview kit is available across Gravwell editions, including Community Edition, rather than being restricted to a separate premium AI tier. Read more about Gravwell 5.10 in the blog post here.
Take a deeper look at platform features, and for more information, visit: www.gravwell.io/ce.
Related News:
JumpCloud Expands Agentic IAM to Govern AI Agent Access
Silent Push 6.1 Enhances Brand and Infrastructure Impersonation