Security · Colleague: Sig

JIT access, incident triage, access reviews — grounded in your live directory

Sig, your Security Colleague, runs the loop from Grafana alert to resolved incident, from access request to time-boxed grant, from vulnerability scan to remediation ticket.

Phase 5 · Q3
Capability 01

26 pre-built Security playbooks

UAR · offboarding · alert triage · incident orchestration · phishing triage · restricted-country access · vuln assessment · endpoint compliance · IOC enrichment · compromised credentials · anomalous login · GitHub outside-collaborator review · cloud IAM reviews · secret rotation · certificate expiry · public exposure · vendor security review · exception handling · compliance training · SOC 2 / Vanta evidence · privacy / DSAR · tool migration.
grounded answer · sources
answer

Priya’s Okta lockout can be cleared via self-serve MFA challenge — no IT intervention required. If MFA fails, escalate to IT on-call.

cited from
01
IT · Okta account lockout policy
runbook · updated 4d ago
02
HR · Emergency access procedure
policy · updated 2w ago
03
Ticket #48211 · priya · resolved
past ticket · similar match
Capability 02

JIT elevation with auto-expiry

Chat request from Slack or Teams: role, justification, duration. Routed to owner + security per your Approval Policy with step-up MFA on the reviewer. Scoped role grants with a valid_until edge in Context Graph. Scheduled revoke fires the moment the edge expires. Every grant and revoke lands in audit.
approvals · pending 4
unlock okta account
priya.sharma · self-serve · read-only
denyapprove
refund $128.40
stripe · ord_A4b2c · manager approval
denyapprove
revoke prod IAM role
aws · role/analyst · step-up MFA
denyapprove
reset zoom SSO
kiran.mehta · self-serve
denyapprove
Capability 03

Incident auto-investigation

Grafana / Datadog / Splunk alert fires the playbook. Sig pulls the user, device, and auth context from Context Graph, correlates with recent identity + deploy events, drafts a summary + candidate root cause, and posts to the incident channel. Analyst reads in 2 minutes instead of grepping across 5 systems.
context · priya.sharma
priyateamon-calloktagithubworkday
Capability 04

Access reviews on schedule

Quarterly campaigns. Reviewer packets generated per manager — one row per employee, one column per entitlement, approve/revoke/delegate. Auto-revoke on 'revoke' decisions and missed deadlines. Evidence bundled for SOC 2 / ISO 27001 audit. Continuous audit-readiness, not a scramble in the last week.
reports · this week
Auto-resolved
78.4%
+4.1 pt
Avg. loop time
11.4s
-2.1s
Approvals pending
12
-3
Coverage
94%
+1.2 pt
monsun
Capability 05

Every action grounded in the graph and source-traceable

The Context Graph asserts the entity path (this identity → this group → this role → this resource); Knowledge Studio shows the source paragraph for the policy that justified the decision. Every write in the audit log carries both. No gaps between action and evidence.
grounded answer · sources
answer

Priya’s Okta lockout can be cleared via self-serve MFA challenge — no IT intervention required. If MFA fails, escalate to IT on-call.

cited from
01
IT · Okta account lockout policy
runbook · updated 4d ago
02
HR · Emergency access procedure
policy · updated 2w ago
03
Ticket #48211 · priya · resolved
past ticket · similar match
Capability 06

Security questionnaire response

New vendor questionnaire arrives; Sig matches each question against your answer library (Vanta / Drata + your own), drafts responses, routes for security-team review, and returns the completed doc within 2 days — down from the industry-standard 2 weeks.
approvals · pending 4
unlock okta account
priya.sharma · self-serve · read-only
denyapprove
refund $128.40
stripe · ord_A4b2c · manager approval
denyapprove
revoke prod IAM role
aws · role/analyst · step-up MFA
denyapprove
reset zoom SSO
kiran.mehta · self-serve
denyapprove
The BeforeQuery method

Visibility. Reasoning. Action.

Every playbook, every action, every answer follows the same three-beat rhythm — one that keeps every write behind evidence and every decision behind policy.

01

Visibility

Read the full context — who is asking, what they own, what they can access, what breaks if we touch it. Nothing acts on incomplete signal.

02

Reasoning

Match the request to a grounded answer or a playbook. Cite the source paragraph, weigh the risk tier, and route to the correct approver where policy demands it.

03

Action

Execute the write on your systems with an audit-log id, an entity list, and a rollback path. Confirm the outcome with the requester in the same thread.

How every request flows

From ask to resolution in one loop

Six stages every request travels. What changes is how many stages policy lets the agent execute without waiting on a human.

01
Request

In Slack, email, widget, MCP, or the helpdesk. Same voice, same context.

Slack · Teams · Zendesk · Widget · MCP
02
Retrieve

Grounded lookup against your knowledge with source paragraphs held aside.

Knowledge Studio
03
Reason

Read the Context Graph — who, what they own, what breaks if we touch it.

Context Graph
04
Approve

Route to the correct approver per policy. Reversible writes gated, destructive step-up.

Approval matrix
05
Execute

Act on Okta, Stripe, Workday, GitHub, or your own systems. Logged and attributable.

Actions runtime
06
Verify

Confirm the outcome with the requester. Feed the result back into future decisions.

Feedback loop
Watch it work

Suspicious login → contained in under 60 seconds

Sig runs the fusion score, executes containment, notifies out-of-band. Analyst arrives to a fully-enriched incident, not a raw alert.

slack · #it-help
live
$okta · 02:14:login from Kyiv on priya.sharma — impossible travel
·
sig fusion score: 0.94 (device fingerprint new + TLS mismatch + no travel booked) score.matrix
·
sig revoke all active sessions across 47 SSO-connected apps okta.sessions#revoke
·
sig lock account pending MFA re-enrolment okta.lock
·
sig SMS out-of-band to Priya's verified phone with callback link twilio.oob
·
sig file P1 incident + page on-call security jira#INC-4211 · pagerduty
contained · 44s · analyst notified with full evidence bundle·traceable · reversible

Same 20 alerts / hour that used to reach a human now get auto-closed with a reason line. Only the ones that need judgment escalate.

Enterprise-grade by default

The controls your security team is going to ask about

SOC 2 Type II
audited annually
GDPR
EU data residency
HIPAA-ready
BAA available
SSO / SAML
Okta · Entra · Google
SCIM 2.0
auto-provision
Audit log
every write, traceable
Bring your key
AES-256-GCM at rest
Bring your model
Anthropic · OpenAI · self-host
Zero training
your data stays yours
Rollback
every write reversible
TLS 1.3
in transit
99.9% uptime
SLA on Enterprise

Frequently asked questions

Common questions about Agentic Security

Grafana + Datadog for monitoring alerts, Splunk + Sumo Logic for SIEM ingest, CrowdStrike + SentinelOne + Wiz + Snyk for endpoint / vulnerability. All ship in Phase 5. Custom SIEM support via webhook + HTTP action.
Yes for scheduled revoke (JIT expiry, quarterly-review 'revoke' decision, offboarding termination). Manual approval required for any ad-hoc revoke that would remove a user's currently-active session. Every revoke logged with the trigger + approver identity.
The monitoring alert lands as a webhook. Sig extracts the identity + resource + timestamp, queries Context Graph for the user's team / access history / recent changes, correlates with the SIEM feed for related events, and drafts a summary. The analyst opens the incident channel to a ready-to-triage brief, not a blank page.
It coexists. If you have Sailpoint / Saviynt / Okta Identity Governance, Sig runs the daily-driver flows on top: quick JIT, ticket-based access requests, quarterly review campaigns. The IGA remains the compliance system of record. If you don't have an IGA, Sig covers the mid-market use cases end-to-end.
Sig Colleague + 26 Security playbooks + Wiz / Snyk / CrowdStrike / Splunk / 1Password / HashiCorp Vault integrations + incident auto-investigation + JIT + access reviews. ISO 42001 audit kicks off in the same window.

Run security on BeforeQuery

Book a demo and see what Agentic Security does on your own data — usually within 45 days.