Glossary

Agents and Actions

Actionable Insights

Insights surfaced by an investigation or enrichment that warrant a response. They link to the relevant remediation or follow-up action. Analysts control the execution.

Actions

Activities executed against connected tools, like isolating a host. They can be manual, agent-assisted with analyst confirmation, or automated.

Agents 

Pre-built agents delivered with the product and designed for common workflows. 

Configurable Agents

Customer-built agents defined by role, guidance, instructions, and scope – including connectors, documentation, and queries the agent can use.

Playbooks

Structured workflows that orchestrate agents and actions to deliver detection, triage, enrichment, and remediation. Playbooks can invoke Configurable Agents and be initiated by analysts or triggered in response to an event.

Features that Optimize AI Efficiency and Reduce Token Spend

Connector Auto Scoping

Narrows the queries to the connectors that hold meaningful context for a specific investigation. This lowers AI spend while reducing noise and accelerating response time.

Context Awareness

Arms agents with context-specific insights so they can know what alerts and threat intel inputs matter to an organization’s specific risk profile, and which don’t.

Context Compaction

Summarizes the conversation history into a compressed representation, preserving the most relevant information without retaining every raw token exchanged.

Data Dictionary

As the index of all connected data sources, it offers a view of every dataset, field, and path across connectors, helping SOC teams understand what data is available and how to use it.

Persistent Memory

Our product learns from context and from experience. It can self-correct and self-heal, so previous events inform current developments, saving enrichment and investigation time.

Planning Mode

Enables SOC teams to know in real time what assumptions the AI is making, allowing analysts to guide and edit agent-led workflows before using tokens to embark on the wrong initiative.

Human-AI Collaboration

Human-AI SOC

In Andesite’s Human-AI collaboration model, cyber defenders manage and configure their agents and playbooks, and guide AI-driven triage, enrichment, investigation, and response.

Humans at the Helm

Human analysts direct the machine-speed work of the SOC, oversee evidence validation, and make the critical decisions they are accountable for.

Humans in the Loop

The ground-level collaboration in which humans and agents interact within workflows, meeting at key checkpoints as the work proceeds.

Product Architecture

Decision Fabric

The centerpiece of Andesite’s technology is the layer where disparate data sources are connected, organizational context is established, and actionable insights are made. Flexible and domain-agnostic, it adapts to customers’ use cases, tools, and workflows.

Modern Data Architecture

Andesite is built on a modern, composable architecture that separates the data layer from the analytical layer, and captures only the data that’s worth keeping in a specific context. It scales across large, complex organizations and analyzes data near the source, enabling close to real-time triage and response.

NO ETL

ETL (Extract, Transform, Load) processes data by standardizing it and loading it into a central repository. Andesite works with heterogeneous structured and unstructured data in place, so there’s no costly migration or extraction, and less delay, complexity, and exposure.

Safe AI Architecture™

Andesite’s architecture protects customers’ applications and data with single-tenant SaaS and air-gapped self-managed deployments, secure access and identity via IDP and CAC/PIV, and end-to-end encryption at rest, in transit, and in storage.