Governance has been the quiet gating factor on AI adoption in the security operations center. Security leaders can articulate the upside of agents that reason and act at machine speed. They also carry accountability for what those agents do to production systems. Mate Security‘s launch of Gamebooks, first reported by SiliconANGLE, is aimed squarely at that accountability question.
The Governance Problem, Stated Plainly
Organizations need AI agents to get it right. Mate’s framing of the standard is specific: 90 percent accuracy is not sufficient when the remaining margin can disable a legitimate account, revoke an executive’s access, or shut down a critical production system.
The industry’s response has been to limit AI autonomy, generally by placing a human at every decision point. That preserves control. It also caps the speed of the defense, because an agent waiting for human approval cannot operate at machine speed. Mate cites the recent Hugging Face incident as a demonstration that AI-driven attacks run continuously, in parallel, and adapt as defenders respond.
Mate’s position is that the choice is not autonomy versus control. It is controlled autonomy, which means letting agents reason, pivot, and act while keeping them inside the organization’s methodology, policies, and guardrails.
Encoding Methodology Into Software
A Gamebook is where an organization’s investigative approach becomes something an agent can follow.
Mate Security’s Gamebooks each define what must be investigated, what evidence must be established, which conditions should change the investigation, which actions are permitted, and when an agent must escalate, stop, or request approval. That last element is the governance hook. Escalation points, stop conditions, and approval requirements are properties of the Gamebook rather than judgment calls the agent makes on its own.
Gamebooks define investigative intent rather than a fixed execution path. The agent is told what to accomplish and which boundaries apply. It determines the route from the evidence and the organization’s most current context.
Separation of Powers
The architecture reinforces the governance model through layering.
An orchestrator reads the investigation and composes the appropriate Gamebooks. Gamebooks carry investigative intent, required evidence, and boundaries. Capabilities give agents reusable, vendor-neutral security skills. Agents apply those capabilities dynamically as evidence emerges. The Security Context Graph keeps everything grounded in shared state and current organizational context. Flows form the controlled execution layer that governs how agents interact with specific tools and systems.
Mate makes a point of what this separation achieves for risk owners. Investigative intent stays consistent while execution adapts, and agents never receive unrestricted access to real systems.
Continuity as a Control
Change is a governance risk in its own right. Organizations replace security tools. They acquire companies with different security stacks. Vendors introduce new alert types. Experienced analysts leave.
Under a traditional playbook model, each of those events means rebuilding workflows, and every rebuild is an opportunity for drift away from approved procedure. With Gamebooks, investigative intent remains intact while execution adapts. The same Gamebook continues to operate through a tool change or an acquisition. When an analyst leaves, the Security Context Graph preserves previous decisions along with the reasoning and context behind them. The world changes. The investigation methodology does not have to be rebuilt.
Ownership of the Method
Gamebooks are extensible and customizable, which matters for organizations that treat their investigative methodology as proprietary. Teams can adapt agentic investigations to their own processes, tools, and institutional knowledge without taking on the complexity of building, testing, and operating agentic systems.
Existing playbooks can be translated into investigative intent. Mate’s expert-designed Gamebooks can be extended with organization-specific requirements. Proprietary tools and data can be connected. New investigation procedures can be written in natural language.
Mate owns the underlying agent engineering, evaluations, testing, and execution. As models, tools, and environments change, Mate continuously validates and evolves the system while customers retain their investigation logic and customizations. The division is clear. Organizations define how they investigate. Mate ensures the agents execute it reliably. Customers build with Mate rather than around it.
An Audit Trail That Improves the System
Gamebooks operate inside Mate’s Continuous Detection / Continuous Response loop, where detection, investigation, and response function as one continuous process.
Every investigation adds evidence, relationships, outcomes, and reasoning to the Security Context Graph. That record does double duty. It preserves the basis for decisions, and it feeds improvement, since useful investigation patterns can strengthen capabilities, update Gamebooks, or become new detections. Noisy detections can be tuned based on actual investigation results.
The Direction of Travel
“AI is changing the speed and scale of both attack and defense, but security teams cannot trade control for speed,” said Oren Saban, Co-Founder and Chief Product Officer at Mate. “The shift to agentic investigations requires a different architecture, one that gives AI the freedom to reason and adapt while keeping it grounded in how each organization actually investigates. Gamebooks give agents that structure, so organizations can move toward autonomous security operations without giving up trust.”
Gamebooks join the Security Context Graph and CD/CR as Mate’s architecture for agentic security operations, moving investigations from scripted automation toward trusted agentic work. Gamebooks are generally available as part of the Mate platform, and the company will showcase them at CrowdStrike Fal.Con 2026.



