The security industry has spent years trying to automate investigations, first through increasingly sophisticated playbooks and more recently through AI agents capable of reasoning through incidents. The problem is that each approach has a tradeoff: traditional automation can be too rigid, while unrestricted AI can be difficult to trust with consequential security actions. SiliconANGLE was among the first to report on Mate Security’s Gamebooks, which the company says are designed to address that gap.
The Limits of Security Automation
Security investigations rarely unfold according to a predetermined sequence. Threats evolve, enterprise environments change, security tools are replaced and business processes are updated. Yet conventional SOAR playbooks depend on predefined workflows that can require significant maintenance when those conditions change.
AI SOC platforms have offered a different model by allowing agents to reason through investigations rather than simply follow scripts. But that flexibility creates another problem. An agent that can independently decide what to do may also operate outside an organization’s established processes or take an action that was never intended.
Mate argues that the industry should not frame this as a choice between autonomy and control. Instead, it is a question of how to build controlled autonomy into the architecture of security operations.
That is where Gamebooks come in.
From Execution Paths to Investigative Intent
Mate describes Gamebooks as structured investigation procedures built specifically for AI agents. Rather than prescribing every step an agent must take, they establish what an investigation needs to accomplish and the boundaries within which the agent can operate.
A Gamebook can define what evidence needs to be collected, what conditions should change an investigation, which actions are allowed and when an agent should escalate, stop or request approval. The agent retains the ability to reason and adapt based on what it finds.
This creates a distinction between investigative intent and execution. The organization determines how an investigation should be approached, while the agent determines how to navigate the specific circumstances of an incident.
Mate describes the result as deterministic where it matters and dynamic where flexibility is useful.
How Gamebooks Fit Into Mate’s Architecture
Gamebooks are not being introduced as a standalone automation feature. They build on two architectural components Mate has previously introduced: its Security Context Graph and Continuous Detection / Continuous Response framework.
The Security Context Graph captures organizational context and provides a foundation for agent reasoning. The CD/CR framework connects detection, investigation and response into a continuous loop.
Gamebooks add the procedural layer. An orchestrator determines which Gamebooks apply to an investigation, while the Gamebooks establish intent, required evidence and boundaries. Agents use reusable, vendor-neutral capabilities as evidence emerges, with the Security Context Graph maintaining shared state and current context.
Flows then provide the controlled execution layer through which agents interact with specific tools and systems.
The separation is designed to prevent investigative logic from becoming dependent on individual tools, APIs or predetermined execution paths.
Keeping Investigations Intact as Environments Change
For enterprise security teams, one of the more important implications is what happens when the environment itself changes.
An organization might replace a security product, acquire a company with an entirely different technology stack or lose an experienced analyst. Under a traditional playbook model, those changes can require investigation workflows to be rebuilt.
Mate’s model is intended to keep the investigative intent intact while allowing execution to adapt. The company says its Security Context Graph can also preserve previous decisions, reasoning and context, allowing organizational knowledge to remain part of the system even as personnel and environments change.
That approach also extends to customization. Organizations can convert existing playbooks into investigative intent, add their own requirements to Mate’s Gamebooks, connect proprietary tools and data, and define new procedures using natural language.
A Different Path to Autonomous Security
The underlying argument behind Gamebooks is that making AI agents more capable is not enough. Security operations require agents that can operate quickly without stepping outside the processes and controls established by the organization.
“AI is changing the speed and scale of both attack and defense, but security teams cannot trade control for speed,” said Oren Saban, Co-Founder and Chief Product Officer at Mate. “The shift to agentic investigations requires a different architecture, one that gives AI the freedom to reason and adapt while keeping it grounded in how each organization actually investigates. Gamebooks give agents that structure, so organizations can move toward autonomous security operations without giving up trust.”
Mate says Gamebooks are now generally available as part of its platform. The company will also showcase the technology at CrowdStrike Fal.Con 2026.
For Mate, the broader objective is a shift away from security automation built around fixed scripts and toward investigations in which AI can adapt to changing evidence while remaining anchored to organizational context, methodology and guardrails.
