The market for AI in the security operations center has spent the past two years working through a single design question. How much latitude should an agent have when it is touching production systems? Mate Security put its answer into a product this week with Gamebooks, a launch first reported by SiliconANGLE, and the company is positioning the release as an architectural advance rather than a feature addition.
Where This Sits in Mate’s Roadmap
Gamebooks is the third architectural foundation Mate has introduced in recent months.
The first was the Security Context Graph, which captures organizational context and serves as the basis for agent reasoning. The second was a framework in which detection, investigation, and response operate as one continuous loop. Gamebooks complete the set by supplying the layer for controlled autonomy, giving agents room to reason, adapt, and act at machine speed inside the organization’s methodology, context, and guardrails.
Mate has been explicit that each release built toward the next. The open question after the first two was how an AI system could follow an organization’s investigative approach without that approach hardening into another fixed workflow.
The Category Context
Two lines of development lead into this launch.
SOAR investigation playbooks gave teams automation for investigation procedures. They also came with maintenance obligations, since environments, threats, security stacks, and business processes all keep moving while the script stays where it was written.
AI SOC platforms took the next swing, replacing static workflows with agentic reasoning. That solved the rigidity. It surfaced a different requirement, which is that agents operating with real access benefit from structured investigation procedures and clear rules if organizations are going to extend trust to them.
Mate’s read on both is that the answer is not better playbooks or more capable models. It is architecture.
The Product Itself
Mate Security’s Gamebooks are structured investigation procedures built for AI agents.
Each one defines what must be investigated, what evidence must be established, which conditions should change the investigation, which actions are permitted, and when an agent must escalate, stop, or request approval. Where a playbook prescribes a path, a Gamebook prescribes intent. The agent decides how to reach the objective based on the evidence it finds and the organization’s most current context.

Mate characterizes the balance as deterministic where it matters and dynamic where it helps.
The Buyer’s Calculation
For security leaders, the pitch centers on the value of the last ten percent. High accuracy is table stakes. The consequences of the exceptions are what shape procurement conversations, since a wrong call can disable a legitimate account, revoke an executive’s access, or shut down a critical production system.
The industry’s default safeguard has been to limit AI autonomy through human approval. Mate frames the timing consideration plainly. An agent waiting for approval cannot defend at machine speed. The company references the recent Hugging Face incident to show that AI-driven attacks operate continuously, in parallel, and adapt as defenders respond, meaning an attack can move on while an analyst is still validating evidence.
Controlled autonomy is Mate’s alternative, and Gamebooks are the mechanism.
Reducing Switching Costs
There is a portfolio argument embedded in the design that will matter to buyers with heterogeneous environments.
Investigation logic in a Gamebook is not tied to specific tools, APIs, or predefined execution paths. When an organization replaces a security tool or acquires a company running an entirely different stack, the same Gamebook continues to operate. New alert types from vendors do not require rebuilds. When an experienced analyst leaves, the Security Context Graph retains previous decisions along with the reasoning and context behind them.

For teams that have historically rebuilt workflows after every tooling change, that continuity is the practical value.
Build Alongside, Not Around
Gamebooks are extensible and customizable, which lets organizations adapt agentic investigations to their own processes, tools, and institutional knowledge without taking on the complexity of building, testing, and operating agentic systems.
Existing playbooks can be translated into investigative intent. Mate’s expert-designed Gamebooks can be extended with organization-specific requirements. Proprietary tools and data can be connected. New investigation procedures can be defined in natural language. Mate owns the agent engineering, evaluations, testing, and execution underneath, and continues validating and evolving the system as models, tools, and environments change while customers retain their investigation logic and customizations.
Mate’s framing is that customers build with the platform rather than around it.
Compounding Returns
Under the Continuous Detection / Continuous Response framework, each investigation adds evidence, relationships, outcomes, and reasoning to the Security Context Graph. Useful patterns can improve capabilities, update Gamebooks, or become new detections. Noisy detections can be tuned against actual investigation results. The system’s value accrues with use.
“AI is changing the speed and scale of both attack and defense, but security teams cannot trade control for speed,” said Oren Saban, Co-Founder and Chief Product Officer at Mate. “The shift to agentic investigations requires a different architecture, one that gives AI the freedom to reason and adapt while keeping it grounded in how each organization actually investigates. Gamebooks give agents that structure, so organizations can move toward autonomous security operations without giving up trust.”
Gamebooks are generally available as part of the Mate platform. The company will showcase them at CrowdStrike Fal.Con 2026.
