Mate Security has introduced Gamebooks, a new layer in its platform that gives AI agents structured investigation procedures to follow while they reason, pivot, and act on live security events. The launch, first reported by SiliconANGLE, represents an architectural shift in how security investigations are designed and carried out, and Mate Security’s Gamebooks are generally available now as part of the Mate platform.
What a Gamebook Actually Defines
A Gamebook sets out what must be investigated, what evidence must be established, which conditions should change the direction of an investigation, which actions an agent is permitted to take, and when that agent must escalate, stop, or request approval.
The distinction from a traditional playbook sits in that framing. Playbooks describe a fixed execution path. Gamebooks describe investigative intent. They tell an agent what needs to be accomplished and the boundaries it must respect. How the agent gets there depends on the evidence it uncovers and on the organization’s most current context.
Mate describes the outcome as deterministic where it matters and dynamic where it helps.
The Case for Controlled Autonomy
Security teams have consistently asked AI systems for a high bar of correctness. Mate’s position is that 90 percent accuracy leaves too much on the table when the remaining fraction can disable a legitimate account, revoke an executive’s access, or shut down a production system that a business depends on.
One response has been to keep humans in the approval loop at every step. That approach preserves oversight. It also sets a pace. An agent waiting for sign-off operates at human speed, while AI-driven attacks can run continuously, in parallel, and adapt as defenders respond. Mate points to the recent Hugging Face incident as an illustration of that dynamic. By the time an analyst validates evidence and approves containment, the situation may have already moved.
Mate frames the real question as controlled autonomy rather than autonomy versus control. Agents get room to reason and act. The organization’s methodology, policies, and guardrails stay in force throughout.

The Layers Underneath
Gamebooks arrive as part of a layered design that separates investigative intent from execution.
An orchestrator reads the investigation and composes the right Gamebooks for the situation. The Gamebooks themselves define intent, required evidence, and boundaries. Capabilities give agents reusable, vendor-neutral security skills. Agents apply those capabilities dynamically as evidence emerges. Mate’s Security Context Graph keeps the work grounded in shared state and in the organization’s most current context. Flows sit at the controlled execution layer and define how agents interact with specific tools and systems.
Because investigation logic is not bound to particular tools, APIs, or predefined execution paths, intent stays consistent while execution adapts. Agents gain reach without gaining unrestricted access to real systems.

Holding Steady Through Change
Environments move constantly. Organizations replace security tools. They acquire companies that arrive with entirely different stacks. Vendors introduce new alert types. Experienced analysts move on to other roles.
Gamebooks are built so that investigative intent survives those transitions. A tool swap or an acquisition does not require rebuilding the investigation. The same Gamebook continues to operate while the execution layer adjusts underneath it. When an analyst departs, the Security Context Graph preserves prior decisions along with the reasoning and context behind them. The world changes. The methodology stays intact.
Giving Teams Room to Build
Gamebooks are extensible and customizable, which lets organizations shape agentic investigations around their own processes, tools, and institutional knowledge without absorbing the complexity of building, testing, and operating agentic systems themselves.
Teams can translate existing playbooks into investigative intent. They can extend the Gamebooks that Mate’s security experts designed, layer in organization-specific requirements, connect proprietary tools and data, and define new investigation procedures in natural language. Mate handles the underlying agent engineering, evaluations, testing, and execution. As models, tools, and environments evolve, Mate validates and evolves the system while customers keep their investigation logic and customizations in place.
Mate’s summary of the arrangement is direct. Organizations define how they investigate. Mate makes sure the agents execute it reliably. Customers build with Mate rather than around it.
A Compounding Loop
Gamebooks also participate in Mate’s Continuous Detection / Continuous Response framework, where detection, investigation, and response operate as a single loop.
Each investigation contributes evidence, relationships, outcomes, and reasoning to the Security Context Graph. Investigation patterns that prove useful can sharpen capabilities, update Gamebooks, or graduate into new detections. Detections that generate noise can be tuned against what investigations actually found. Every investigation improves the one that follows.
What Mate Says About the Shift
“AI is changing the speed and scale of both attack and defense, but security teams cannot trade control for speed,” said Oren Saban, Co-Founder and Chief Product Officer at Mate. “The shift to agentic investigations requires a different architecture, one that gives AI the freedom to reason and adapt while keeping it grounded in how each organization actually investigates. Gamebooks give agents that structure, so organizations can move toward autonomous security operations without giving up trust.”
Gamebooks join the Security Context Graph and CD/CR as the three architectural pieces Mate has assembled over recent months. Mate will showcase Gamebooks at CrowdStrike Fal.Con 2026.
John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.

