Glossary
Agents and Actions
Actionable Insights
Insights surfaced by an investigation or enrichment that warrant a response. They link to the relevant remediation or follow-up action. Analysts control the execution.
Actions
Activities executed against connected tools, like isolating a host. They can be manual, agent-assisted with analyst confirmation, or automated.
Agents
Pre-built agents delivered with the product and designed for common workflows.
Configurable Agents
Customer-built agents defined by role, guidance, instructions, and scope – including connectors, documentation, and queries the agent can use.
Playbooks
Structured workflows that orchestrate agents and actions to deliver detection, triage, enrichment, and remediation. Playbooks can invoke Configurable Agents and be initiated by analysts or triggered in response to an event.
Features that Optimize AI Efficiency and Reduce Token Spend
Connector Auto Scoping
Narrows the queries to the connectors that hold meaningful context for a specific investigation. This lowers AI spend while reducing noise and accelerating response time.
Context Awareness
Arms agents with context-specific insights so they can know what alerts and threat intel inputs matter to an organization’s specific risk profile, and which don’t.
Context Compaction
Summarizes the conversation history into a compressed representation, preserving the most relevant information without retaining every raw token exchanged.
Data Dictionary
As the index of all connected data sources, it offers a view of every dataset, field, and path across connectors, helping SOC teams understand what data is available and how to use it.
Persistent Memory
Our product learns from context and from experience. It can self-correct and self-heal, so previous events inform current developments, saving enrichment and investigation time.
Planning Mode
Enables SOC teams to know in real time what assumptions the AI is making, allowing analysts to guide and edit agent-led workflows before using tokens to embark on the wrong initiative.
Human-AI Collaboration
Human-AI SOC
In Andesite’s Human-AI collaboration model, cyber defenders manage and configure their agents and playbooks, and guide AI-driven triage, enrichment, investigation, and response.
Humans at the Helm
Human analysts direct the machine-speed work of the SOC, oversee evidence validation, and make the critical decisions they are accountable for.
Humans in the Loop
The ground-level collaboration in which humans and agents interact within workflows, meeting at key checkpoints as the work proceeds.
Product Architecture
Decision Fabric
The centerpiece of Andesite’s technology is the layer where disparate data sources are connected, organizational context is established, and actionable insights are made. Flexible and domain-agnostic, it adapts to customers’ use cases, tools, and workflows.
Modern Data Architecture
Andesite is built on a modern, composable architecture that separates the data layer from the analytical layer, and captures only the data that’s worth keeping in a specific context. It scales across large, complex organizations and analyzes data near the source, enabling close to real-time triage and response.
NO ETL
ETL (Extract, Transform, Load) processes data by standardizing it and loading it into a central repository. Andesite works with heterogeneous structured and unstructured data in place, so there’s no costly migration or extraction, and less delay, complexity, and exposure.
Safe AI Architecture™
Andesite’s architecture protects customers’ applications and data with single-tenant SaaS and air-gapped self-managed deployments, secure access and identity via IDP and CAC/PIV, and end-to-end encryption at rest, in transit, and in storage.