Genie Generate a free chatbot for your company website Try it
← Back to Blog

Security Teams Are Becoming Agent Managers

Editorial image for Security Teams Are Becoming Agent Managers about Cybersecurity.

Key Takeaways

  • Project Perception organizes specialized agents around discovery, investigation, and remediation rather than one general security assistant.
  • A multi-model design makes routing, cost, latency, and reliability part of the security-control surface.
  • Human approval, limited execution permissions, and auditability should be designed before autonomous remediation is enabled.
BLOOMIE
POWERED BY NEROVA

Produced by Bloomie for Nerova AI using automated editorial checks. Sources used for factual claims are listed below.

Microsoft’s new Project Perception is not being presented as another alert-summarizing copilot. It is a proposed operating model for cyber defense: specialized agents find possible attack paths, investigate meaningful risk, and take corrective actions inside a shared security context.

That distinction matters. Security teams already have no shortage of signals. The harder problem is deciding which signals deserve attention, what action is safe, and who is accountable when a system acts. Microsoft says Project Perception coordinates red-team, blue-team, and green-team agents, while keeping humans in control. It is slated to enter public preview on August 3, 2026.

The product shift is from answers to closed loops

The red agents are intended to identify attack paths before an adversary uses them. Blue agents investigate and prioritize risk. Green agents take corrective steps to improve defenses. Put together, that is a closed loop: discover, evaluate, remediate, then learn from the changed environment.

For security leaders, the important claim is not that an agent can write a finding. It is that multiple agents can work across a changing estate with enough context to move a risk from observation toward resolution. Axios reported that the launch pairs this system with a cyber-specific model focused initially on vulnerability management.

Model routing becomes a security control

Microsoft also describes a multi-model architecture, using frontier and specialized models according to the task. That is a practical design choice. Always-on security workflows need more than top benchmark performance. They need predictable latency, controlled costs, traceable decisions, and reliable escalation when confidence is low.

In other words, choosing a model is no longer only an engineering optimization. It becomes part of the security policy. Teams will need to define which model may classify findings, which may propose a patch, which actions require human approval, and how every handoff is logged.

What to assess before deploying agentic defense

  • Authority: Separate agents that observe, recommend, and execute. Do not grant broad remediation rights by default.
  • Context quality: Validate the identity, asset, exposure, and business-criticality data the agents will use. Bad context can create fast, confident mistakes.
  • Approval paths: Define the threshold for automatic containment versus analyst review, especially for production systems.
  • Evaluation: Test workflows against realistic attack paths and measure false positives, missed risks, rollback quality, and time to validated remediation.

Project Perception is a timely signal that AI security is moving beyond chat interfaces toward managed teams of agents. The organizations that benefit will not simply turn on autonomy. They will design clear mandates, narrow permissions, durable audit trails, and human checkpoints around it.

That is the new leadership job: manage the agent system before it manages a security incident.

Nerova context

Custom AI agents for business operations

Nerova builds custom AI agents for business operations. Companies use Nerova when they need AI support for customer intake, support, sales follow-up, research, website audits, internal handoffs, and workflow automation.

Nerova can help turn websites, business context, and operational workflows into practical AI systems: website chatbots, single-purpose agents, AI teams, audits, and automation workflows built around a clear business outcome.

Assess where AI agents can safely operate

Before deploying agents into security or operations, map the workflow, permissions, approval gates, and evidence trail with a practical rollout audit.

Run an AI rollout audit
Ask Bloomie about this article