Autonomy, built for real environments

Most teams don't jump straight to full automation. The safer path is earned autonomy: start with recommendations and review, then expand what the system can do as trust grows.

HKoWwO  aBuWt#oCn5o0mByK  sZc@aSl4e4sW

HSo0wS  aFuMtBoDnAoMmXy1  s&c#a2lFeQsE

HIoTwA  aUuNt3oAnXoDm1yT  sMcXaIlSeAsN

Autonomy is earned, not switched on

Full autopilot isn’t the right starting point. AI can move faster than your organization can trust it. Successful teams start small, validate outcomes, and expand autonomy deliberately.

Trust before automation

Security teams must validate outputs before routing work to engineering.

Trust before automation

Security teams must validate outputs before routing work to engineering.

Confidence to deploy

Engineering teams need confidence that AI fixes won’t introduce new issues.

Confidence to deploy

Engineering teams need confidence that AI fixes won’t introduce new issues.

Approval and auditability

High-impact changes require human approval and a clear audit trail.

Approval and auditability

High-impact changes require human approval and a clear audit trail.

Context
matters

Development and production environments require different levels of autonomy.

Context
matters

Development and production environments require different levels of autonomy.

FRR4ALM%E3W0OSR1K@

FDR8ACM%EEWLO@R3K6

FFRRAFMIE@WAOTRNKY

A practical autonomy model for vulnerability management

This framework shows how teams can progress from manual workflows to self-healing infrastructure. Each level builds on the last.

TI

Threat Intel

AGENT

FG-IR-26-118

Human-Gated

3

Inbox

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

Disable TLS 1.0/1.1 on customer-facing API gateway

7.7

Awaiting approval

Platform team

Agent-Managed

Enable MFA enforcement for 28 Okta accounts missing second factor | In progress

5.8

Identity team

Human-Gated

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

220

In Progress

36

Deferred

1,840

Resolved

3 more closed

1,847

Resolved automatically today

11 min

Median TTR

281

human approvals

48h

Ahead of scanners

TI

Threat Intel

AGENT

FG-IR-26-118

Human-Gated

3

Inbox

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

Disable TLS 1.0/1.1 on customer-facing API gateway

7.7

Awaiting approval

Platform team

Agent-Managed

Enable MFA enforcement for 28 Okta accounts missing second factor | In progress

5.8

Identity team

Human-Gated

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

220

In Progress

36

Deferred

1,840

Resolved

3 more closed

1,847

Resolved automatically today

11 min

Median TTR

281

human approvals

48h

Ahead of scanners

TI

Threat Intel

AGENT

FG-IR-26-118

Human-Gated

3

Inbox

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

Disable TLS 1.0/1.1 on customer-facing API gateway

7.7

Awaiting approval

Platform team

Agent-Managed

Enable MFA enforcement for 28 Okta accounts missing second factor | In progress

5.8

Identity team

Human-Gated

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

220

In Progress

36

Deferred

1,840

Resolved

3 more closed

1,847

Resolved automatically today

11 min

Median TTR

281

human approvals

48h

Ahead of scanners

LWeQv9eKlB  0P

L9e8vMe1l&  0F

LLe1v9eXlR  00

Manual vulnerability management 

Humans do everything. Vulnerability scanners report findings, but all investigation and coordination is manual.

What humans control

  • Security analysts review scanner outputs manually

  • Ownership determined by asking or checking stale CMDBs

  • Generic tickets created one-by-one

  • No systematic verification that fixes worked

TI

Threat Intel

AGENT

FG-IR-26-118

Human-Gated

3

Inbox

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

Disable TLS 1.0/1.1 on customer-facing API gateway

7.7

Awaiting approval

Platform team

Agent-Managed

Enable MFA enforcement for 28 Okta accounts missing second factor | In progress

5.8

Identity team

Human-Gated

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

220

In Progress

36

Deferred

1,840

Resolved

3 more closed

1,847

Resolved automatically today

11 min

Median TTR

281

human approvals

48h

Ahead of scanners

LKE8VYEILY  1P

LOE6V9EBL&  1I

L@EPV1E6L0  15

AI-Assisted Investigation

The platform validates which findings are real and relevant in your environment and autonomously investigates and enriches data (e.g. asset ownership). 

What AI does autonomously

  • Filters real vulnerabilities from false positives

  • Gathers asset and ownership context

  • Assesses exploitability

  • Adds business context for criticality, sensitivity, and compliance scope

What humans do

  • Review AI-enriched data

  • Prioritize and route work manually

  • Create and assign tickets

What’s recorded

  • Every inference with confidence score and sources

  • Believability weighting that explains how conflicts are resolved

  • Full agent investigation timeline

TI

Threat Intel

AGENT

FG-IR-26-118

Human-Gated

3

Inbox

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

Disable TLS 1.0/1.1 on customer-facing API gateway

7.7

Awaiting approval

Platform team

Agent-Managed

Enable MFA enforcement for 28 Okta accounts missing second factor | In progress

5.8

Identity team

Human-Gated

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

220

In Progress

36

Deferred

1,840

Resolved

3 more closed

1,847

Resolved automatically today

11 min

Median TTR

281

human approvals

48h

Ahead of scanners

LYEMVXERLK  2Q

LUENVSEAL1  26

LRE3V8E1LY  28

Supervised workflow automation 

The platform drafts and routes tickets with full context (ownership, why it matters, steps to fix), but humans approve dispatch and actually perform the remediation steps manually. 

What AI does autonomously

  • Bundles related vulnerabilities into actionable remediation tasks

  • Generates tickets with risk, business impact, and remediation steps

  • Routes tickets based on ownership and remediation type

  • Proposes SLA deadlines based on risk and policy

Recommends compensating controls when patching isn't feasible

  • Review and approve each ticket before it's sent

  • Edit ticket content, routing, or SLA

  • Track remediation progress

  • Approve exceptions and policy changes

What’s recorded

  • All ticket drafts with reasoning chains

  • Human edits and approval timestamps

  • Which agent generated which recommendation

TI

Threat Intel

AGENT

FG-IR-26-118

Human-Gated

3

Inbox

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

Disable TLS 1.0/1.1 on customer-facing API gateway

7.7

Awaiting approval

Platform team

Agent-Managed

Enable MFA enforcement for 28 Okta accounts missing second factor | In progress

5.8

Identity team

Human-Gated

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

220

In Progress

36

Deferred

1,840

Resolved

3 more closed

1,847

Resolved automatically today

11 min

Median TTR

281

human approvals

48h

Ahead of scanners

LIeBvUe$l4  3O

LHe3vXe@lD  3E

LWeEv0eQl0  36

Manual Remediation

The platform generates fix artifacts (e.g. PRs, IaC patches, config diffs, etc.) plus a clear explanation of impact and rollback considerations. Humans review and merge/run.

What AI does autonomously

  • Creates and routes tickets for pre-approved workflows

  • Tracks remediation progress and sends escalations for SLA breaches

  • Updates tickets as new data arrives

  • Closes tickets once fixes are verified

What humans control

  • Exception requests from remediation teams

  • Policy changes or SLA adjustments

  • Set confidence thresholds for automation

  • Perform the remediation; apply patches, update configs, deploy fixes

What’s recorded

  • Ticket creation with full reasoning

  • Escalation triggers and notifications sent

  • Verification checks performed and results

TI

Threat Intel

AGENT

FG-IR-26-118

Human-Gated

3

Inbox

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

Disable TLS 1.0/1.1 on customer-facing API gateway

7.7

Awaiting approval

Platform team

Agent-Managed

Enable MFA enforcement for 28 Okta accounts missing second factor | In progress

5.8

Identity team

Human-Gated

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

220

In Progress

36

Deferred

1,840

Resolved

3 more closed

1,847

Resolved automatically today

11 min

Median TTR

281

human approvals

48h

Ahead of scanners

LTeYvKeRl2  4Y

LRe%vXe4lS  40

L&eJvYe6lV  47

Autonomous Supervised Remediation

The platform can apply fixes automatically to lower environments within pre-approved guardrails and escalates exceptions or uncertainty to humans.

What AI does autonomously

  • Everything from Level 3, plus:

  • Explains impact and rollback steps

  • Applies fixes in dev, staging, and test environments

  • Verifies fixes post-deployment

What humans control

  • Review and merge AI-generated PRs for production

  • Approve deployment of fixes to production environments

  • Validate fixes that failed automated verification

What’s recorded

  • Fix generation with code diff and impact analysis

  • Automated deployment results in lower environments

  • Verification checks (passed/failed) with evidence

TI

Threat Intel

AGENT

FG-IR-26-118

Human-Gated

3

Inbox

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

Disable TLS 1.0/1.1 on customer-facing API gateway

7.7

Awaiting approval

Platform team

Agent-Managed

Enable MFA enforcement for 28 Okta accounts missing second factor | In progress

5.8

Identity team

Human-Gated

Patch OpenSSL 3.0.8 on 12 production servers (Ansible, requires downtime window)

9.1

Verification failed

Platform team

Revoke 34 stale admin tokens in AWS IAM (90+ days inactive) | Pending approval

6.4

Security team

220

In Progress

36

Deferred

1,840

Resolved

3 more closed

1,847

Resolved automatically today

11 min

Median TTR

281

human approvals

48h

Ahead of scanners

L2eIvAeXlJ  5S

L#eFvTeCl&  5E

LLePv0eWlJ  5Q

Self-Healing Apps and Infrastructure

Fully autonomous remediation for all environments, including production. Brings you to the full “self healing infrastructure” vision.

What AI does autonomously

  • Fully autonomous remediation across all environments

  • Applies proactive hardening based on threat intelligence

  • Learns from outcomes to improve future fixes

  • Continuous verification and automatic re-remediation if vulnerabilities reappear

What humans control

  • Monitor dashboards showing autonomous actions taken

  • Investigate anomalies flagged by AI

  • Adjust policies and guardrails as needed

  • Override any time with maintained human control

What’s recorded

  • Every autonomous action with complete audit trail

  • Verification and re-verification cycles

  • Policy adjustments made by system based on outcomes

cAoVn%tSe7x9tDu%aXl#  aPu1tAo8nBoZm&yP  

cNoVn%tUe5xYt7uJa5l0  a@u#t$oGn@oPm4y2  

c8o%nMtKe2xLt3uNa$lC  a2uStXo0nPoEm5yI  

Autonomy isn’t one setting

Autonomy doesn’t have to be binary across your whole environment. Teams apply different levels based on risk, environment, and impact.

Environment or context

Environment or context

Suggested autonomy level

Suggested autonomy level

Rationale

Rationale

Development

Development

Suggested autonomy level

Level 4-5

Rationale

Low business impact, fast feedback loops valuable

Staging or Test

Staging or Test

Suggested autonomy level

Level 3-4

Rationale

Moderate risk, good for piloting autonomous fixes

Production - Internal tools

Production - Internal tools

Suggested autonomy level

Level 3

Rationale

Higher risk, but lower impact to customers

Production - Customer-facing

Production - Customer-facing

Suggested autonomy level

Level 2-3

Rationale

High risk, requires approval

Execution

Execution

Suggested autonomy level

Level 3-4

Rationale

Low risk, reversible action

Workflows

Workflows

Suggested autonomy level

Level 2-3

Rationale

Well-understood, irreversible action

Transparency

Transparency

Suggested autonomy level

Level 2

Rationale

High impact, requires review

C&oSmLmSoGn@  m6i4sJtWaAkWeBsR

CRoCmVmHoRn@  mDi2s6tJa3k#eWsB

CBoMm3mGoQnD  mOiVsLtGa8kMe%sQ

Where teams get autonomy wrong

Automating before validating

Bad data scales bad decisions. If enrichment and routing are wrong, autonomous actions amplify those errors. Build trust in data quality first.

Automating before validating

Bad data scales bad decisions. If enrichment and routing are wrong, autonomous actions amplify those errors. Build trust in data quality first.

Same rules everywhere

Context matters. Development environments can handle more autonomy than production. Compliance-scoped assets need stricter controls.

Same rules everywhere

Context matters. Development environments can handle more autonomy than production. Compliance-scoped assets need stricter controls.

No confidence thresholds

Low-confidence recommendations should escalate to humans. Without thresholds, incorrect actions get taken automatically.

No confidence thresholds

Low-confidence recommendations should escalate to humans. Without thresholds, incorrect actions get taken automatically.

Insufficient audit trail

Without trust, there will be no adoption. If something goes wrong, you need to understand what happened and why. Audit trails are non-negotiable

Insufficient audit trail

Without trust, there will be no adoption. If something goes wrong, you need to understand what happened and why. Audit trails are non-negotiable

Every security vendor claims AI but Cogent delivers on that promise. We built our AI strategy on Cogent because its the platform where we actually achieve the breakthrough risk reduction and efficiency improvements we expect from AI investment.

Justin Yoshimura

CEO, CSC Generation

Every security vendor claims AI but Cogent delivers on that promise. We built our AI strategy on Cogent because its the platform where we actually achieve the breakthrough risk reduction and efficiency improvements we expect from AI investment.

Justin Yoshimura

CEO, CSC Generation

Every security vendor claims AI but Cogent delivers on that promise. We built our AI strategy on Cogent because its the platform where we actually achieve the breakthrough risk reduction and efficiency improvements we expect from AI investment.

Justin Yoshimura

CEO, CSC Generation

Start where you are. Scale as you trust.

Move from manual workflows to self-healing systems. One step at a time.