The push to automate security operations with AI has exposed a problem that traditional automation never fully solved. Security teams need systems that can respond quickly as threats evolve, but they also need those systems to operate within established processes and controls. SiliconANGLE first reported on Mate Security’s introduction of Gamebooks, which are designed to give AI agents more flexibility during investigations without removing organizational guardrails.
Rather than treating autonomy and control as competing objectives, Mate is building Gamebooks around what it calls controlled autonomy. The technology gives agents structured investigation procedures that define objectives, evidence requirements and boundaries, while leaving the agent room to determine how an investigation should proceed.
A Different Approach to Security Playbooks
Traditional SOAR playbooks automate investigations through predefined workflows. That model can become difficult to maintain when organizations change security products, modify their environments or encounter new types of threats. The workflows may still reflect the assumptions under which they were created even after the environment has moved on.
AI SOC platforms introduced a more adaptable model by allowing agents to reason through investigations. But Mate argues that flexibility without structure creates a separate trust problem, particularly when agents have access to real systems and can take consequential actions. Gamebooks are intended to provide the structure without forcing investigations back into rigid scripts.
Giving Agents Boundaries Instead of Scripts
Gamebooks define what an investigation must establish, what evidence is required and what conditions should change its direction. They also establish permitted actions and identify when an agent needs to stop, escalate or request approval.
The distinction is that Gamebooks describe investigative intent rather than a fixed execution path. Agents can decide how to pursue an investigation based on the evidence they find and the organization’s current context. Mate says this makes the system deterministic where it needs to be while preserving flexibility where investigations require it.
The architecture separates this intent from execution. An orchestrator selects the relevant Gamebooks, capabilities provide reusable vendor-neutral security skills, and the Security Context Graph maintains shared organizational context. Flows control how agents interact with specific tools and systems, keeping the underlying investigation logic separate from individual technologies.
Keeping Methodology Intact as Environments Change

Enterprise security environments are constantly being modified, which can create significant maintenance work for traditional automation. Replacing a security tool or acquiring an organization with a different security stack can mean rebuilding investigation workflows. Changes in personnel can also result in the loss of institutional knowledge.
Mate says Gamebooks are designed to keep investigative intent intact while allowing execution to adapt to those changes. The Security Context Graph can preserve previous decisions, reasoning and context, helping retain information from earlier investigations even when analysts leave.
Organizations can also extend the system with their own requirements. Teams can translate existing playbooks into investigative intent, connect proprietary tools and data, and define new investigation procedures in natural language. Mate manages the underlying agent engineering, evaluations, testing and execution while customers retain their investigation logic and customizations.
Building Toward Autonomous Security Operations
Gamebooks form part of Mate’s broader architecture for agentic security operations. The company’s Security Context Graph provides context for agent reasoning, while its Continuous Detection / Continuous Response framework connects detection, investigation and response into one continuous loop. Gamebooks add the investigation procedures and boundaries needed to connect that architecture with controlled agent action.
“AI is changing the speed and scale of both attack and defense, but security teams cannot trade control for speed,” said Oren Saban, Co-Founder and Chief Product Officer at Mate. “The shift to agentic investigations requires a different architecture, one that gives AI the freedom to reason and adapt while keeping it grounded in how each organization actually investigates. Gamebooks give agents that structure, so organizations can move toward autonomous security operations without giving up trust.”
Gamebooks are generally available as part of the Mate platform, and Mate plans to showcase them at CrowdStrike Fal.Con 2026. The company is positioning the launch as a move away from scripted investigation automation toward a model where AI agents can adapt to changing circumstances while remaining grounded in organizational methodology and controls.

















