Security data platform Gravwell has released version 5.10, embedding five AI agents within customer environments that independently collect and analyze investigation context through a Model Context Protocol server, enhancing how security teams gather and prioritize relevant data.
- Five AI agents autonomously gather investigative context in real time
- Agents operate within defined boundaries to ensure security and transparency
- Preview kit available across all editions, including free Community Edition
What happened
Gravwell Inc. has released Gravwell 5.10, an update embedding five artificial intelligence agents that autonomously collect investigative context by accessing live telemetry, system states, detections, and saved searches through a Model Context Protocol (MCP) server. These agents put in motion queries and evidence collection efforts without relying on preassembled alerts or case files, a departure from typical security AI workflows.
The five agents serve different roles: three assist analysts by managing investigations, triaging alerts, and summarizing daily telemetry; two support administrators by answering deployment configuration questions and performing read-only audit checks to identify automation gaps or inefficiencies. The agents’ activities are visualized on-screen so security teams can monitor the tools used and steps taken.
Why it matters
Gravwell’s agent design emphasizes autonomous operation within a customer’s real environment but with strict boundaries on permissions and tools available, reducing risks associated with AI having unrestricted security operation access. This approach allows security teams to benefit from AI-powered context gathering while maintaining control and transparency over the investigation process.
Unlike many AI-powered security tools that depend on existing alert bodies or case files as starting points, Gravwell’s agents independently generate context, improving early investigation efficiency. Making this AI-enhanced capability freely available, including in the Community Edition, democratizes access to advanced investigation automation that could accelerate threat detection and response.
What to watch next
Security operations teams and organizations adopting Gravwell should monitor how the autonomous AI agents impact analyst workload and investigation quality. Observing agent performance and the effectiveness of their recommendations or reports will be critical to refining workflows and tuning agent configurations.
The AI Agent Preview kit’s transparent operation model and integration across Gravwell editions may influence broader industry adoption of agentic tooling approaches. Continued developments in agent roles, permissions management, and cross-platform interoperability will be key to expanding AI-driven investigation support in security platforms.