BlogsGleanSecurity AI Agents

Security AI Agents

Security AI Agents

9
posts
2025–2026

Glean's security AI agents framework has evolved to address the challenges of traditional security architectures by providing a structured approach to evaluating and governing AI agents. This includes the AWARE framework, which offers shared decision criteria for CIOs and CISOs, focusing on intent, context, guardrails, runtime risk, and observability. The framework enables a repeatable process for assessing agent risk, moving from 'risk is too high for now' to approval by establishing clear technical and operational guardrails. This post details seven essential guardrail decisions for deploying enterprise AI agents successfully, covering model choice and hosting, decision architecture and retrieval-augmented generation, tool permissions and role-based access control, human-in-the-loop and risk tiers, observability and audit logging, input and output validation with content safety, and cost controls and financial operations.

2026

Glean AI Gateway: One control plane beneath every AI front door

7/7/2026

This post introduces Glean AI Gateway, a new control plane that sits between AI surfaces and models/tools. It enables centralized governance of model/MCP access, token usage, and security across multiple AI front doors. Key technical contributions include cost control mechanisms (budget limits, quotas, model fallback), enhanced visibility into token/tool usage and performance metrics, consistent application of data permissions and granular access controls, and integration with Glean's enterprise graph for improved context. It also details initial LLM and MCP support.

The enterprise AI copilot playbook for business leaders

7/7/2026

This post introduces the concept of an enterprise AI copilot and details its architecture, emphasizing the integration of AI assistants, AI agents, and agentic AI. It elaborates on secure data integration using RAG, permission-aware access, and the importance of governance controls like RBAC and audit trails. The post also clarifies the distinctions between AI assistants, AI agents, and agentic AI, and how they contribute to a secure and effective enterprise AI deployment. It builds upon the existing 'Security AI Agents' thread by contextualizing these agents within a broader copilot framework and detailing the underlying RAG architecture for secure data access.

How to get your CISO’s green light on AI agents

6/10/2026

This post details the practical application of the AWARE framework for AI agent governance, emphasizing the collaboration between CIOs and CISOs. It highlights how Cvent used the framework to achieve security buy-in for over 6,000 AI agents by inverting the typical enterprise sequence: encouraging broad creation early while implementing foundational security controls. Key strategies include introducing ROI gates for new agent projects, a sandbox-first deployment model, and leveraging platforms like Glean with built-in fine-grained security controls. The post argues that getting CISO approval involves demonstrating a clear understanding of who is acting, their context, guardrails, risk spikes, and traceability, rather than eliminating all risk.

7 essential guardrail decisions for deploying enterprise AI agents successfully

4/1/2026

This post details seven essential guardrail decisions for deploying enterprise AI agents successfully. It covers model choice and hosting (managed APIs, private cloud, on-premises), decision architecture and retrieval-augmented generation (intelligence, decision, execution, action, learned layers), tool permissions and role-based access control (RBAC, default deny, credential scoping), human-in-the-loop and risk tiers (low, medium, high risk tiers with corresponding oversight types), observability and audit logging (instrumentation frameworks like OpenTelemetry), input and output validation with content safety, and cost controls and financial operations (FinOps, per-session/agent budgets, circuit breakers). It also highlights how Glean's platform incorporates these principles.

How to Deploy AI Agents With Confidence: Introducing AWARE and New Glean Protect Capabilities

3/10/2026

This post introduces the AWARE framework (Actor Intent, Work Context, Autonomous Guardrails, Real-Time Risk Scoring & Blocking, Ecosystem Observability) for secure AI agent deployment. It details new Glean Protect capabilities including restricted topics policies, agent alignment models that pre-scan agent actions, and enhanced sensitive content policies with out-of-the-box templates. It also highlights a triage workflow for sensitive content findings and integrations with Tines SOAR and Cortex Cloud DSPM. Finally, it announces customer-managed deployment options for Glean, offering greater control over code deployment, private connectivity, and customer-managed keys.

8 AI agents to help software engineering teams ship and fix faster

2/19/2026

This post introduces eight new AI agents for software engineering teams: Pull Request Review, Resolve GitHub PR Feedback, Resolve Jira Ticket, Spec to Implementation PR, Engineering Project Onboarding, Launch Documentation, Engineering Self-Evaluation, and Engineering Standup. These agents are designed to automate and streamline common, time-consuming engineering tasks by leveraging context from various development tools.

Using AI to Administer AI: Meet Glean’s New Insights and Admin Chats

2/18/2026

Introduces Insights Chat and Admin Chat, two new Glean features. Insights Chat allows users to query adoption metrics and usage data using natural language, translating queries into Python and SQL. Admin Chat provides AI-powered assistance for Glean administration by querying public documentation and Gleaniverse content, offering step-by-step instructions for configuration and troubleshooting.

2025

5 metrics to measure AI-generated answers' decision-making impact

11/18/2025

This post details five metrics (accuracy, relevance, coherence, helpfulness, and user trust) for measuring the impact of AI-generated answers on decision-making. It provides technical details on how to measure these metrics, including specific scores like faithfulness, BLEU, ROUGE, perplexity, and readability, as well as user feedback mechanisms and structured scoring rubrics. The post also discusses the importance of retrieval augmented generation for grounding answers in company data and outlines strategies for continuous monitoring and improvement.

11 AI agents powering every stage of security operations

11/2/2025

This post introduces a new capability area: Security AI Agents. It details the core functionalities and benefits of these agents, providing specific examples of 11 agents that automate and enhance different stages of the security operations alert lifecycle. The post highlights how these agents integrate with existing security tools and leverage Glean's platform for context, governance, and data access.