Opens in a new tab
vmblog logo 2024 wht (updated)

Gravwell Brings Environment-Aware AI Agents to Security Operations

Share: 

David Marshall | Published: September 10, 2026

Security data platform Gravwell has introduced a new set of environment-aware AI agents designed to investigate alerts, support threat hunting and monitor the health of security infrastructure.

Released as part of Gravwell 5.10, the agents differ from AI security tools that primarily reason from preassembled context such as an individual alert or case. Instead, they can gather information directly from a customer’s environment, drawing on live telemetry, searches, detections, system state, flows and playbooks to build context around an issue.

From there, the agents can use available Gravwell tools to investigate suspicious activity, collect supporting evidence, troubleshoot operational issues and surface findings that warrant human attention.

The release comes as security teams increasingly explore how agentic AI can take on more of the repetitive work involved in security operations without handing over unrestricted control.

Five Agents Target Different SecOps Workflows

Gravwell 5.10 introduces five specialized agents covering security analysis and platform operations.

The Case Agent serves as an interactive investigation partner, helping analysts write and validate queries, interpret results and determine the next investigative step. An Alert Triage Agent investigates detections before they reach an analyst, running supporting queries and compiling relevant evidence into an initial report.

On the operational side, the Admin Agent can answer questions about an organization’s Gravwell deployment, including access controls, storage, replication, ingesters and overall platform health.

A Daily Summary Agent reviews the previous day’s telemetry for activity that may deserve further investigation, while the Audit Agent conducts read-only assessments across alerts, automations, queries, infrastructure and data flows. It can flag problems including stalled searches, unused alerts, duplicate extractors, missing ingesters, dead data feeds and storage issues.

Together, the agents are intended to automate some of the evidence gathering, initial investigation and platform maintenance that can consume analysts’ time while keeping humans responsible for higher-level judgment.

Putting Guardrails Around Agentic AI

The agents are delivered through Gravwell’s AI Agent Preview kit, with each agent operating under predefined tools, permissions and workflows.

Gravwell has also added an in-product visualization that lets users see how an agent works through a task, including what information it gathers, which tools it accesses and the steps it takes before reaching a conclusion.

“Autonomy without context or boundaries can create more problems than it solves,” said Corey Thuen, CEO and co-founder of Gravwell. “Gravwell agents can gather the context they need from the customer’s actual environment while operating within defined tools, permissions and procedures.”

The approach reflects a broader challenge facing security teams experimenting with agentic AI: giving AI systems enough access and context to perform useful work while maintaining visibility and control over what they can actually do.

Gravwell is making the AI Agent Preview kit available across its editions, including its free Community Edition, rather than offering the capabilities exclusively through a separate premium AI tier.