Models

Gravwell Deploys Five AI Agents to Automate Security Investigation Tasks

Gravwell Inc. has released version 5.10 of its security data platform, introducing five autonomous AI agents that independently gather investigation context and assist analysts and administrators through a Model Context Protocol server.

·3 min read
Gravwell adds five AI agents that gather their own investigation context
Gravwell adds five AI agents that gather their own investigation context

The Minneapolis-based security data platform vendor Gravwell Inc. unveiled Gravwell 5.10 today, bringing five artificial intelligence agents into customer deployments. These agents autonomously assemble the contextual information required for investigations without relying on preassembled data, alert bodies, or case files—the typical starting points for AI-driven security tools.

The agents gain access to their environment through a Model Context Protocol server. They can retrieve live telemetry, detections, system state and saved searches, then invoke the platform's native tools to execute queries and gather evidence until producing results suitable for analyst review.

Three agents for analysts

The Case Agent operates throughout an investigation lifecycle, authoring and validating Gravwell queries, executing them and recommending subsequent investigation directions. It functions in read-only mode unless explicitly instructed to preserve findings.

The Alert Triage Agent positions itself between incoming detections and the analysts who handle them. It runs supplementary queries and prepares an initial report before the alert reaches the analyst, preventing alerts from arriving without supporting analysis.

The Daily Summary Agent processes overnight activity, analyzing the previous day's telemetry and delivering queries that analysts can execute against its discoveries.

Two agents for administrators

The Admin Agent responds to configuration inquiries regarding deployments, addressing topics such as ingesters, access controls, storage and replication.

The Audit Agent performs read-only compliance reviews across automations, alerts, query content and data flows. It consolidates stalled searches, duplicate extractors and inactive data feeds into a single prioritized report.

Controlled autonomy through defined boundaries

All five agents ship as part of what Gravwell terms the AI Agent Preview kit. Each agent specification establishes which tools and MCP environment sections that agent can access, what actions it can perform and which procedures it follows. The release also visualizes agent activity on screen, allowing teams to track which tools were invoked, what data was accessed and how the agent reached its conclusions.

Autonomy without context or boundaries can create more problems than it solves

Corey Thuen, co-founder and Chief Executive Officer of Gravwell Inc.

Thuen elaborated that agents drawing from a customer's actual environment while operating within defined tools and permissions offer security teams a controlled approach to increased autonomy, avoiding unrestricted AI access to security operations.

The preview kit is available across all Gravwell editions, including the free Community Edition, rather than being restricted to a premium AI subscription tier.

Company background

Gravwell, established in 2017, positions its platform as a successor to conventional security information and event management systems. The platform ingests data at full fidelity and applies structure exclusively at query time. Two Bear Capital led a $15.4 million Series A funding round for the company in October of last year, with participation from Gula Tech Adventures Inc., Next Frontier Capital and Kickstart.

Agentic capabilities have emerged as a recurring theme among security operations vendors throughout the year. Blumira Inc. initiated a pilot program for its agentic investigation platform, called Kindling, in May.