Features

Everything a tier-1 analyst does.
Done by an agent.

Five specialist agents that collaborate the way a senior SOC team does — with bounded retries, verifier loops, and human-in-the-loop gates on every consequential action.

The agent fleet

A team of five.

Planner

Reads the alert, queries policy, drafts an investigation plan with stop conditions and budget.

Investigator

Pivots through SIEM, EDR, identity, cloud, and threat intel — collecting evidence into a structured case.

Verifier

Independent model that audits the investigator. Abstains when confidence is low. Triggers escalation.

Responder

Executes containment within policy: isolate host, revoke session, disable identity, block hash, file ticket.

Scribe

Writes the incident note: timeline, IOCs, MITRE mapping, evidence, and recommended hardening.

Eval Conductor

Continuously replays golden cases against the live fleet — catches regressions before customers do.

Operations

Control plane for a 24×7 fleet.

Approval policies

Budget caps, two-person rules on disable / contain, escalation paths by severity, hour, and tenant. Versioned, diffable, auditable.

# policy.yaml
on: ransomware_contain
  requires: ["sec_lead", "secops_oncall"]
  budget_minutes: 15
  escalate_if: confidence < 0.85

Observability

Latency, cost, accuracy, override rate, abstention rate — per workflow, per agent, per tenant. OpenTelemetry export to Datadog, Honeycomb, Grafana.

fleet.live
04:17:02PLANalert id=A-9482 → 6 steps · budget=$0.04
04:17:13INVESTok 198.51.100.42 enriched · risk=7.4
04:17:19VERIFYconf=0.91 · pass
04:17:21RESOLVEbenign · notify · step-up MFA

RBAC + SSO/SCIM

SAML, OIDC, Okta, Azure AD, Google. Per-action permissions, per-tenant key.

Slack + Teams + Inbox

Investigations stream to the channel of your choice. Approve from your phone.

Search across history

"Show me every alert tied to 198.51.100.42 in the last 90 days." Done.

AI capabilities

Models, tuned to defense.

Threat-tuned reasoning

Foundation models fine-tuned on a proprietary attack-trace dataset and on your own production verdicts (opt-in, federated).

  • Claude 4.x
  • GPT-5
  • Llama 4 70B
  • Triago-Tuned Verifier v3

Confidence-aware abstention

Triago publishes a confidence score on every verdict and abstains when it would be wrong. You define the threshold per category.

Long-context investigation memory

Episodic memory per host, identity, and tenant. The agent that closed yesterday's case is the same one that opens today's.

Tool-use across 200+ APIs

MCP-compatible tool registry. Per-tool authz. Sandboxed execution. Failure-tolerant retries.

See it on your data.

A pilot takes a week. We promise a verdict accuracy number you'll trust by Friday.

Start free pilot