AI has made it possible to rethink how security investigations are conducted, but faster automation does not automatically translate into safer automation. Security teams still need to know why an AI agent took a particular path, what boundaries it is following and when it should stop. SiliconANGLE first reported on Mate Security’s Gamebooks, which the company has introduced as a way to give AI agents more freedom without removing the structure organizations depend on.
The launch comes as security teams face an increasingly difficult choice. Traditional automation can be too rigid to keep up with changing environments, while unrestricted agents can be too unpredictable to receive broad operational access. Mate’s Gamebooks are designed to occupy the space between those approaches by combining structured investigation procedures with agentic reasoning.
The Core Idea: Intent Over Instructions

At the center of Gamebooks is a change in how security investigations are defined. Instead of telling an agent exactly which sequence of actions to execute, a Gamebook establishes what the investigation must accomplish and the conditions under which the agent can operate.
That includes defining required evidence, investigation-changing conditions, permitted actions and situations in which the agent must escalate, stop or request approval. The agent can then determine how to reach the objective based on the evidence it discovers and the organization’s current context.
Mate calls this investigative intent, distinguishing it from the fixed execution paths used by traditional playbooks. The approach is intended to make investigations dynamic without making them unrestricted.
Why the Distinction Matters
SOAR playbooks have traditionally provided security teams with a way to automate repeatable investigation procedures. But those procedures can become brittle as organizations replace tools, change their environments, encounter new alert types or modify business processes.
AI SOC platforms introduced more adaptable agents that can reason through those changing circumstances. The tradeoff is that an agent with too much freedom can operate outside an organization’s methodology or make an action that has unintended consequences.
Mate argues that security teams therefore need controlled autonomy rather than choosing between complete human oversight and unrestricted AI. The company’s example is straightforward: an AI system that is wrong even part of the time could disable a legitimate account, revoke executive access or shut down a critical production system.
Where Gamebooks Fit

Gamebooks are part of a larger architecture Mate has been developing for agentic security operations. The Security Context Graph provides organizational context and shared state for agent reasoning, while the company’s Continuous Detection / Continuous Response framework connects detection, investigation and response into a continuous loop.
Gamebooks add the procedural layer. An orchestrator selects the appropriate Gamebooks for a particular investigation, while capabilities provide reusable, vendor-neutral security skills. Agents apply those capabilities as evidence emerges, with the Security Context Graph keeping the investigation grounded in current organizational context.
Flows then control interactions with specific tools and systems. By separating intent from execution, Mate says investigation logic does not have to be tied to particular products, APIs or predefined paths.
What Happens When Things Change?
The architecture is designed around the reality that enterprise environments do not remain static. A security team may replace a tool, integrate a different technology stack following an acquisition or lose an analyst with years of experience.
Under the Gamebooks model, the investigative methodology can remain intact while execution adapts to the new environment. Mate also says the Security Context Graph preserves previous decisions, reasoning and context, allowing knowledge from earlier investigations to remain available.
The system is also designed to be extended by customers. Organizations can translate existing playbooks into investigative intent, add organization-specific requirements, connect proprietary tools and data, and define new procedures in natural language. Mate handles the underlying agent engineering, evaluations, testing and execution while customers retain their investigation logic and customizations.
The Larger Shift
Gamebooks represent the latest component in Mate’s effort to build an architecture for agentic security operations rather than simply adding AI to existing automation. The company says its Security Context Graph and CD/CR framework provide the context and continuous operational loop, while Gamebooks establish how investigations should be conducted.
“AI is changing the speed and scale of both attack and defense, but security teams cannot trade control for speed,” said Oren Saban, Co-Founder and Chief Product Officer at Mate. “The shift to agentic investigations requires a different architecture, one that gives AI the freedom to reason and adapt while keeping it grounded in how each organization actually investigates. Gamebooks give agents that structure, so organizations can move toward autonomous security operations without giving up trust.”
Gamebooks are generally available as part of the Mate platform, with Mate set to showcase the technology at CrowdStrike Fal.Con 2026. The company’s broader proposition is that security teams can move toward machine-speed investigations without having to choose between rigid automation and unchecked AI autonomy.
