Autonomy, built for real environments

Most teams don't jump straight to full automation. The safer path is earned autonomy: start with recommendations and review, then expand what the system can do as trust grows.

HTo$wR  aFu@t4oJnOoRmIyO  s7cJaFlReQsR

HVoAw%  aVuLtQo@nFo%m2yQ  s3cTa3lJe#sF

H8oCwB  a2uRtOo4nPoBmMy1  sWcMa&l%e6sE

Autonomy is earned, not switched on

Full autopilot isn’t the right starting point. AI can move faster than your organization can trust it. Successful teams start small, validate outcomes, and expand autonomy deliberately.

Trust before automation

Security teams must validate outputs before routing work to engineering.

Trust before automation

Security teams must validate outputs before routing work to engineering.

Confidence to deploy

Engineering teams need confidence that AI fixes won’t introduce new issues.

Confidence to deploy

Engineering teams need confidence that AI fixes won’t introduce new issues.

Approval and auditability

High-impact changes require human approval and a clear audit trail.

Approval and auditability

High-impact changes require human approval and a clear audit trail.

Context
matters

Development and production environments require different levels of autonomy.

Context
matters

Development and production environments require different levels of autonomy.

FSRYAWM7E%WWORRGK&

FER3A5MVELWQOFR6K&

FJR1ARM8EHW1O$RBKX

A practical autonomy model for vulnerability management

This framework shows how teams can progress from manual workflows to self-healing infrastructure. Each level builds on the last.

TI

Threat Intel

AGENT

FG-IR-26-118

Human-Gated

3

Inbox

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

Disable TLS 1.0/1.1 on customer-facing API gateway

7.7

Awaiting approval

Platform team

Agent-Managed

Enable MFA enforcement for 28 Okta accounts missing second factor | In progress

5.8

Identity team

Human-Gated

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

220

In Progress

36

Deferred

1,840

Resolved

3 more closed

1,847

Resolved automatically today

11 min

Median TTR

281

human approvals

48h

Ahead of scanners

TI

Threat Intel

AGENT

FG-IR-26-118

Human-Gated

3

Inbox

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

Disable TLS 1.0/1.1 on customer-facing API gateway

7.7

Awaiting approval

Platform team

Agent-Managed

Enable MFA enforcement for 28 Okta accounts missing second factor | In progress

5.8

Identity team

Human-Gated

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

220

In Progress

36

Deferred

1,840

Resolved

3 more closed

1,847

Resolved automatically today

11 min

Median TTR

281

human approvals

48h

Ahead of scanners

TI

Threat Intel

AGENT

FG-IR-26-118

Human-Gated

3

Inbox

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

Disable TLS 1.0/1.1 on customer-facing API gateway

7.7

Awaiting approval

Platform team

Agent-Managed

Enable MFA enforcement for 28 Okta accounts missing second factor | In progress

5.8

Identity team

Human-Gated

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

220

In Progress

36

Deferred

1,840

Resolved

3 more closed

1,847

Resolved automatically today

11 min

Median TTR

281

human approvals

48h

Ahead of scanners

L@eXvHeYlX  02

LGeZvTeHlN  00

LKeHv2e8lK  02

Manual vulnerability management 

Humans do everything. Vulnerability scanners report findings, but all investigation and coordination is manual.

What humans control

  • Security analysts review scanner outputs manually

  • Ownership determined by asking or checking stale CMDBs

  • Generic tickets created one-by-one

  • No systematic verification that fixes worked

TI

Threat Intel

AGENT

FG-IR-26-118

Human-Gated

3

Inbox

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

Disable TLS 1.0/1.1 on customer-facing API gateway

7.7

Awaiting approval

Platform team

Agent-Managed

Enable MFA enforcement for 28 Okta accounts missing second factor | In progress

5.8

Identity team

Human-Gated

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

220

In Progress

36

Deferred

1,840

Resolved

3 more closed

1,847

Resolved automatically today

11 min

Median TTR

281

human approvals

48h

Ahead of scanners

LOEXV%E3LT  1T

L&ELVVE@L&  1$

LVEOVFE8LH  11

AI-Assisted Investigation

The platform validates which findings are real and relevant in your environment and autonomously investigates and enriches data (e.g. asset ownership). 

What AI does autonomously

  • Filters real vulnerabilities from false positives

  • Gathers asset and ownership context

  • Assesses exploitability

  • Adds business context for criticality, sensitivity, and compliance scope

What humans do

  • Review AI-enriched data

  • Prioritize and route work manually

  • Create and assign tickets

What’s recorded

  • Every inference with confidence score and sources

  • Believability weighting that explains how conflicts are resolved

  • Full agent investigation timeline

TI

Threat Intel

AGENT

FG-IR-26-118

Human-Gated

3

Inbox

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

Disable TLS 1.0/1.1 on customer-facing API gateway

7.7

Awaiting approval

Platform team

Agent-Managed

Enable MFA enforcement for 28 Okta accounts missing second factor | In progress

5.8

Identity team

Human-Gated

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

220

In Progress

36

Deferred

1,840

Resolved

3 more closed

1,847

Resolved automatically today

11 min

Median TTR

281

human approvals

48h

Ahead of scanners

LPEBV$EYLQ  2V

L&EDVLE5LP  2H

L0EDV8E3L$  2F

Supervised workflow automation 

The platform drafts and routes tickets with full context (ownership, why it matters, steps to fix), but humans approve dispatch and actually perform the remediation steps manually. 

What AI does autonomously

  • Bundles related vulnerabilities into actionable remediation tasks

  • Generates tickets with risk, business impact, and remediation steps

  • Routes tickets based on ownership and remediation type

  • Proposes SLA deadlines based on risk and policy

Recommends compensating controls when patching isn't feasible

  • Review and approve each ticket before it's sent

  • Edit ticket content, routing, or SLA

  • Track remediation progress

  • Approve exceptions and policy changes

What’s recorded

  • All ticket drafts with reasoning chains

  • Human edits and approval timestamps

  • Which agent generated which recommendation

TI

Threat Intel

AGENT

FG-IR-26-118

Human-Gated

3

Inbox

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

Disable TLS 1.0/1.1 on customer-facing API gateway

7.7

Awaiting approval

Platform team

Agent-Managed

Enable MFA enforcement for 28 Okta accounts missing second factor | In progress

5.8

Identity team

Human-Gated

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

220

In Progress

36

Deferred

1,840

Resolved

3 more closed

1,847

Resolved automatically today

11 min

Median TTR

281

human approvals

48h

Ahead of scanners

LLe7v9e4lC  3Q

L$e9vAeVlH  3R

LCeFvCe8l7  39

Manual Remediation

The platform generates fix artifacts (e.g. PRs, IaC patches, config diffs, etc.) plus a clear explanation of impact and rollback considerations. Humans review and merge/run.

What AI does autonomously

  • Creates and routes tickets for pre-approved workflows

  • Tracks remediation progress and sends escalations for SLA breaches

  • Updates tickets as new data arrives

  • Closes tickets once fixes are verified

What humans control

  • Exception requests from remediation teams

  • Policy changes or SLA adjustments

  • Set confidence thresholds for automation

  • Perform the remediation; apply patches, update configs, deploy fixes

What’s recorded

  • Ticket creation with full reasoning

  • Escalation triggers and notifications sent

  • Verification checks performed and results

TI

Threat Intel

AGENT

FG-IR-26-118

Human-Gated

3

Inbox

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

Disable TLS 1.0/1.1 on customer-facing API gateway

7.7

Awaiting approval

Platform team

Agent-Managed

Enable MFA enforcement for 28 Okta accounts missing second factor | In progress

5.8

Identity team

Human-Gated

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

220

In Progress

36

Deferred

1,840

Resolved

3 more closed

1,847

Resolved automatically today

11 min

Median TTR

281

human approvals

48h

Ahead of scanners

LIe6vCeIlI  4&

LHe7vYePlB  4U

LLeAvUeIlY  4H

Autonomous Supervised Remediation

The platform can apply fixes automatically to lower environments within pre-approved guardrails and escalates exceptions or uncertainty to humans.

What AI does autonomously

  • Everything from Level 3, plus:

  • Explains impact and rollback steps

  • Applies fixes in dev, staging, and test environments

  • Verifies fixes post-deployment

What humans control

  • Review and merge AI-generated PRs for production

  • Approve deployment of fixes to production environments

  • Validate fixes that failed automated verification

What’s recorded

  • Fix generation with code diff and impact analysis

  • Automated deployment results in lower environments

  • Verification checks (passed/failed) with evidence

TI

Threat Intel

AGENT

FG-IR-26-118

Human-Gated

3

Inbox

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

Disable TLS 1.0/1.1 on customer-facing API gateway

7.7

Awaiting approval

Platform team

Agent-Managed

Enable MFA enforcement for 28 Okta accounts missing second factor | In progress

5.8

Identity team

Human-Gated

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

220

In Progress

36

Deferred

1,840

Resolved

3 more closed

1,847

Resolved automatically today

11 min

Median TTR

281

human approvals

48h

Ahead of scanners

LZeRv&e@l7  52

LEeOvTeOl5  5Q

LYeHv3eVlZ  5S

Self-Healing Apps and Infrastructure

Fully autonomous remediation for all environments, including production. Brings you to the full “self healing infrastructure” vision.

What AI does autonomously

  • Fully autonomous remediation across all environments

  • Applies proactive hardening based on threat intelligence

  • Learns from outcomes to improve future fixes

  • Continuous verification and automatic re-remediation if vulnerabilities reappear

What humans control

  • Monitor dashboards showing autonomous actions taken

  • Investigate anomalies flagged by AI

  • Adjust policies and guardrails as needed

  • Override any time with maintained human control

What’s recorded

  • Every autonomous action with complete audit trail

  • Verification and re-verification cycles

  • Policy adjustments made by system based on outcomes

c9oEnAt1eNx4tHuMaGl$  aOuPt8o%n1oAmWy7  

cHoHnCt2eAxYtMuLaElA  a6uYtDoWnAoDmLyU  

cEo$nAtJeJxAt8u5a4lW  aAuGtPoLnZoAmAyL  

Autonomy isn’t one setting

Autonomy doesn’t have to be binary across your whole environment. Teams apply different levels based on risk, environment, and impact.

Environment or context

Environment or context

Suggested autonomy level

Suggested autonomy level

Rationale

Rationale

Development

Development

Suggested autonomy level

Level 4-5

Rationale

Low business impact, fast feedback loops valuable

Staging or Test

Staging or Test

Suggested autonomy level

Level 3-4

Rationale

Moderate risk, good for piloting autonomous fixes

Production - Internal tools

Production - Internal tools

Suggested autonomy level

Level 3

Rationale

Higher risk, but lower impact to customers

Production - Customer-facing

Production - Customer-facing

Suggested autonomy level

Level 2-3

Rationale

High risk, requires approval

Execution

Execution

Suggested autonomy level

Level 3-4

Rationale

Low risk, reversible action

Workflows

Workflows

Suggested autonomy level

Level 2-3

Rationale

Well-understood, irreversible action

Transparency

Transparency

Suggested autonomy level

Level 2

Rationale

High impact, requires review

CCo4m&mLo#nO  mNi7s1tOaMk9eKs3

C&oTmWm4oAn5  mTiFs#tWa$k1e%sX

CAoBmZm%o7n5  mQi#s8t7a1kCe0sW

Where teams get autonomy wrong

Automating before validating

Bad data scales bad decisions. If enrichment and routing are wrong, autonomous actions amplify those errors. Build trust in data quality first.

Automating before validating

Bad data scales bad decisions. If enrichment and routing are wrong, autonomous actions amplify those errors. Build trust in data quality first.

Same rules everywhere

Context matters. Development environments can handle more autonomy than production. Compliance-scoped assets need stricter controls.

Same rules everywhere

Context matters. Development environments can handle more autonomy than production. Compliance-scoped assets need stricter controls.

No confidence thresholds

Low-confidence recommendations should escalate to humans. Without thresholds, incorrect actions get taken automatically.

No confidence thresholds

Low-confidence recommendations should escalate to humans. Without thresholds, incorrect actions get taken automatically.

Insufficient audit trail

Without trust, there will be no adoption. If something goes wrong, you need to understand what happened and why. Audit trails are non-negotiable

Insufficient audit trail

Without trust, there will be no adoption. If something goes wrong, you need to understand what happened and why. Audit trails are non-negotiable

Every security vendor claims AI but Cogent delivers on that promise. We built our AI strategy on Cogent because its the platform where we actually achieve the breakthrough risk reduction and efficiency improvements we expect from AI investment.

Justin Yoshimura

CEO, CSC Generation

Every security vendor claims AI but Cogent delivers on that promise. We built our AI strategy on Cogent because its the platform where we actually achieve the breakthrough risk reduction and efficiency improvements we expect from AI investment.

Justin Yoshimura

CEO, CSC Generation

Every security vendor claims AI but Cogent delivers on that promise. We built our AI strategy on Cogent because its the platform where we actually achieve the breakthrough risk reduction and efficiency improvements we expect from AI investment.

Justin Yoshimura

CEO, CSC Generation

Start where you are. Scale as you trust.

Move from manual workflows to self-healing systems. One step at a time.