Agent Factory
Open console

Scale cyber and risk operations with trusted AI agents.

Agent Factory helps cyber and GRC teams turn established procedures into governed, production-ready workflows. Compose pre-tested harnesses, connect enterprise systems and deploy within your cloud environment, accelerating outcomes while keeping data and controls in your tenancy.

4 daysfrom triage SOP to production
130+systems reachable through connectors
0records transferred outside your tenancy
experienceCanvasAgent builderDeploy theater
lifecycleRegistryBenchmarksDeploy stamps
Work planeJournalProvenanceArtifacts
controlGatesKill switchFinOpsEvals
knowledgeRetrievalRecordsEnginesTaint rules
partnersA2A discoverHand-offTainted replies
modelsPer-node routingLocal modelsFrontier models
foundationsVaultInjection filtersYour tenancy
journal entry no. 29approval recorded by reviewerclassified on entryusage recordedrouted to local model

An AI agent has completed a control test.

Every step it took is already on the record, available for review.

Autonomy without inspection is unmanaged risk. Agent Factory is built to be inspected, layer by layer.

01 / 08Who designs the workflows?

Your teams describe the process. The factory assembles it.

Analysts can combine approved components on a visual canvas or describe the required process in plain language. Each draft passes the same validation controls used for deployment, supporting consistent adoption without unmanaged development.

02 / 08How does a workflow reach production?

Every stage must present its own evidence.

Design, benchmark, deployment and monitoring are supported by stage-specific records, and the registry maintains a live inventory of agents, models and tools. Progress is evidenced explicitly, helping teams assess readiness rather than rely on assumptions.

03 / 08What did the agent actually do?

Each action writes its own audit record.

Execution journals record what ran, which information was accessed and what changed, together with the supporting evidence for each step, supporting forensic reconstruction of any run.

04 / 08How do people stay in control?

Approval before. Intervention during. Cost visibility throughout.

Higher-risk actions pause at defined decision points for authorized review, recording the decision and rationale. Runs can be stopped when required, with the intervention retained in the journal. Oversight is enforced at runtime, not reconstructed after the fact.

05 / 08What can an agent reach?

Access is granted per node, never assumed.

Least-privilege access is configured at each workflow node. Untrusted content is identified at entry and prevented from reaching restricted actions without the required controls.

06 / 08What about external agents?

External agents work under the same controls, without exception.

Partner agents connect through A2A, are identified through their agent card and are subject to the same journal and trust controls. Responses remain marked as untrusted until validated.

07 / 08Where does the reasoning run?

Each task runs on the model environment its sensitivity requires.

Each node defines its model requirements and the router determines where execution occurs. Sensitive tasks can be directed to locally hosted models to support privacy, policy and cost requirements.

08 / 08What does it all stand on?

Governance is the foundation, not a feature.

Identity, policy and audit controls underpin the platform, supported by credential management, prompt-injection filtering and a runtime designed for deployment within your tenancy.

One architecture, fully accountable.

Each layer contributes the evidence, oversight and operational controls required for enterprise use.

Designed to be inspected.

Deployed in your tenancy. Prepared for audit.

Turn documented procedures into governed, auditable workflows.

Explore the product through a representative DLP workflow. Define the process in plain language or configure it visually, monitor execution and review the resulting evidence, decisions and source citations.

Describe the process
typing…
SR
DLP-Triage-SOP.pdfattached
scroll to explore

Build on capabilities designed for control and consistency.

Each harness is a containerized capability with a defined contract covering inputs, outputs, permitted tools and exception handling. Every harness includes an evaluation suite to support validation before deployment.

Teams can configure and combine measured components without developing and maintaining bespoke agent infrastructure.

HarnessKindReturnsPass rate
Evidence extractionextractionTyped record + per-field citation96.4%
Control researchresearchFindings with source and recency91.0%
Policy decisiondecisionDisposition + governing clause94.1%
Report draftingdraftingDraft + change log89.3%
Assessment reviewreviewFindings with severity98.6%
Control mappingdecisionFramework crosswalk + rationale92.8%
Vendor triageresearchRisk summary + evidence links93.5%
Access certificationreviewEntitlement findings + owner95.2%
Incident summarydraftingTimeline + affected assets90.7%
Data classificationextractionLabel + matched policy terms94.9%
Human approvalgateApproval + reviewer identityn/a
Declared contract

Typed inputs and outputs, an explicit tool allowlist and defined exception paths. Nothing outside the contract is reachable at runtime.

inputsoutputstoolsexceptions
Evaluation before deployment

Every harness ships with its own evaluation suite. Releases that fall below the accepted pass rate do not reach production.

214 cases in the librarythreshold gated
Versioned releases

Behaviour changes ship as new versions with a changelog. Rollback to any prior version is a single action.

semverchangelogrollback

Connect across your existing technology environment.

MCP-compatible connectors give each harness governed access through declared tool contracts. Use the growing connector library or extend the platform for organization-specific systems and APIs.

130+reachable systems
weeklyconnector release cadence
134 of 134
Microsoft Sentinel
Microsoft Defender
Splunk
CrowdStrikeCrowdStrike
SentinelOneSentinelOne
Palo Alto Networks
Fortinet
CiscoCisco
Check PointCheck Point
Trend MicroTrend Micro
SophosSophos
DarktraceDarktrace
Elastic
Sumo LogicSumo Logic
Microsoft Purview
ForcepointForcepoint
ZscalerZscaler
NetskopeNetskope
ProofpointProofpoint
MimecastMimecast
CloudflareCloudflare
AkamaiAkamai
F5F5
ServiceNowServiceNow
ArcherArcher
OneTrustOneTrust
AuditBoardAuditBoard
MetricStreamMetricStream
LogicGateLogicGate
VantaVanta
DrataDrata
HyperproofHyperproof
WorkivaWorkiva
DiligentDiligent
Jira
Confluence
Okta
Entra ID
Ping IdentityPing Identity
Auth0
SailPointSailPoint
DuoDuo
CyberArkCyberArk
BeyondTrustBeyondTrust
DelineaDelinea
JumpCloudJumpCloud
1Password1Password
HashiCorp Vault
Qualys
TenableTenable
Rapid7Rapid7
WizWiz
Snyk
VeracodeVeracode
SemgrepSemgrep
CheckmarxCheckmarx
SonarSonar
JFrogJFrog
Aqua SecurityAqua Security
Orca SecurityOrca Security
GitHub
GitLab
BitbucketBitbucket
Azure DevOps
BitSightBitSight
SecurityScorecard
UpGuardUpGuard
RiskReconRiskRecon
PanoraysPanorays
SAP
SalesforceSalesforce
OracleOracle
NetSuiteNetSuite
WorkdayWorkday
Dynamics 365
CoupaCoupa
ConcurConcur
Stripe
QuickBooks
Xero
BloombergBloomberg
RefinitivRefinitiv
GuidewireGuidewire
Duck CreekDuck Creek
SharePoint
OneDrive
Google Drive
Box
Dropbox
iManageiManage
DocuSignDocuSign
Adobe SignAdobe Sign
Amazon S3Amazon S3
Azure Blob
Snowflake
Databricks
BigQuery
RedshiftRedshift
Postgres
SQL Server
MongoDB
Elasticsearch
Kafka
FivetranFivetran
dbtdbt
TableauTableau
Power BI
Notion
Google Cloud
KubernetesKubernetes
DockerDocker
TerraformTerraform
AnsibleAnsible
JenkinsJenkins
CircleCICircleCI
DatadogDatadog
GrafanaGrafana
New RelicNew Relic
PagerDutyPagerDuty
UiPath
Outlook
Gmail
SlackSlack
Teams
ZoomZoom
WebexWebex
Zendesk
Intercom
GenesysGenesys
Five9Five9
TwilioTwilio
Asana
Monday.comMonday.com
SmartsheetSmartsheet

Deploy in your cloud and operate within your controls.

Terraform modules support deployment to AWS, Azure and Google Cloud. Harnesses run as containers within your account and connect to model providers through your approved endpoints. Operational data remains within your defined environment.

Private networkingVPC endpoints with no public egress path
Your model providerBedrock, Microsoft Foundry or Vertex under your contract
Audit integrationRun records and citations written to your designated repository
Amazon S3Your AWS account· eu-west-2
VPC · private subnets
ECS Fargate
harness containers
Amazon Bedrock
via VPC endpoint
S3 + KMS
audit records and artifacts
IAM roles
static keys not required
VPC endpoints, no internet gateway
external to your tenancy
Agent Factory control plane
workflow definitions and release metadata only
Your systems of record
accessed through declared connectors

Alert evidence, extracted fields and dispositions remain within the defined boundary. Agent Factory provides the workflow definitions; execution occurs in your account.

terraform init~1 min
terraform apply~14 min
First workflow availablesame business day
Terraform ≥ 1.6OpenTofu supportedAir-gapped variant available

Trace decisions and outputs to the evidence that supports them.

Harnesses are designed to support claims with citations. Each run produces a reviewable timeline, links statements to source material and routes defined outcomes to an authorized reviewer before release.

Reviewers examining alert evidence together
Review each run with end-to-end traceabilityExamine the execution timeline and trace each disposition statement to the relevant policy clause, business record or telemetry source.
SOC 2 Type IIIndependent annual audit
ISO 27001Information security
ISO 42001AI management systems
GDPR & UK DPAData residency supported through in-tenancy deployment
EU AI ActTraceability and human oversight by design