Security operations are moving toward a model in which AI agents can investigate and respond to threats with far less human intervention. But that transition creates a difficult balance: agents need enough freedom to adapt to an incident, while security teams still need confidence that those systems will follow established processes. SiliconANGLE first reported on Mate Security’s Gamebooks, a new layer designed to address that challenge.
Mate says Gamebooks are built around the idea of controlled autonomy. Rather than forcing AI agents through rigid investigation playbooks or allowing them to operate without meaningful constraints, the technology provides structured procedures that define investigative goals, evidence requirements and boundaries.
The launch builds on Mate’s Security Context Graph and Continuous Detection / Continuous Response framework. Together, the technologies form the foundation of the company’s broader approach to agentic security operations, with Gamebooks providing a way for agents to follow an organization’s investigation methodology while adapting their actions to the circumstances of an incident.
The Problem With Traditional Playbooks

Security teams have long used SOAR playbooks to automate investigation procedures, but those workflows depend on assumptions about the environment in which they operate. When security tools change, new alert types appear or business processes evolve, those assumptions can become outdated, requiring teams to maintain or rebuild their automation.
AI SOC platforms have approached the problem differently by giving agents the ability to reason through investigations. That flexibility can make investigations more adaptable, but Mate argues that unbounded autonomy creates a trust problem. An agent may be capable of taking actions that fall outside an organization’s established methodology or policies.
The company points to the stakes involved in giving AI real operational access. A system that is wrong even a fraction of the time could potentially disable a legitimate account, revoke an executive’s access or shut down a critical production system. At the same time, requiring human approval for every action can prevent defenders from responding at the speed of an AI-driven attack.
Mate’s position is that the industry needs to move beyond the autonomy-versus-control debate. Gamebooks are intended to provide a middle layer in which agents can reason and pivot during investigations while remaining constrained by organizational procedures, context and guardrails.
Gamebooks Change How Investigations Are Defined
The central concept behind Gamebooks is a distinction between investigative intent and execution. A traditional playbook generally specifies the sequence of actions an automation system should take. A Gamebook instead establishes what needs to be investigated, what evidence must be established and which conditions should influence the investigation.
The agent retains flexibility over how it reaches those objectives. Gamebooks also specify which actions are permitted and when an agent must stop, escalate or request approval. Mate describes the resulting model as deterministic where it matters but dynamic where adaptability is useful.
The architecture separates investigation logic from specific security products, APIs and predefined execution paths. An orchestrator selects the appropriate Gamebooks for an investigation, while capabilities provide reusable, vendor-neutral security skills that agents can apply as evidence develops.
The Security Context Graph keeps the investigation grounded in shared organizational state and current context, while Flows provide the controlled execution layer for interactions with specific tools and systems. This separation is intended to allow execution to change without forcing organizations to rebuild their underlying investigative methodology.
Built for Environments That Keep Changing
The approach is particularly relevant to enterprises where security environments rarely remain static. An organization could replace a security product, acquire another company with a different technology stack or lose an experienced analyst who carries important institutional knowledge.
Mate says Gamebooks allow the investigative intent to remain intact as those conditions change. The same procedure can continue to guide an investigation while its execution adapts to the tools and environment available at the time.
The company also says its Security Context Graph preserves previous decisions, reasoning and context. That gives organizations a way to retain information from earlier investigations even when personnel or surrounding systems change.
Gamebooks are customizable as well. Organizations can translate existing playbooks into investigative intent, add organization-specific requirements, connect proprietary tools and data, and define new investigation procedures in natural language. Mate handles the underlying agent engineering, evaluations, testing and execution while customers retain their investigation logic and customizations.
A Foundation for More Autonomous Security Operations
Mate is positioning Gamebooks as another step in its larger architectural shift toward agentic security operations. Its Security Context Graph provides the context for agent reasoning, while Continuous Detection / Continuous Response connects detection, investigation and response into a continuous loop. Gamebooks add the structured methodology that tells agents how an organization wants investigations conducted.
“AI is changing the speed and scale of both attack and defense, but security teams cannot trade control for speed,” said Oren Saban, Co-Founder and Chief Product Officer at Mate. “The shift to agentic investigations requires a different architecture, one that gives AI the freedom to reason and adapt while keeping it grounded in how each organization actually investigates. Gamebooks give agents that structure, so organizations can move toward autonomous security operations without giving up trust.”
Gamebooks are generally available as part of the Mate platform, and the company plans to showcase the technology at CrowdStrike Fal.Con 2026. The broader objective is to replace rigid investigation scripting with a model in which AI agents can adapt to evidence and changing environments without operating outside the boundaries established by the organizations they defend.