Announcement · April 2026

Introducing
Investigation Agents.

Autonomous case files in minutes. The platform writes the story, humans decide.

Product launchGA · April 14By Ganesh Krishnan, Co-founder & CEO

For a decade, the dominant ritual of security operations has been triage. A human analyst stares at a queue, opens an alert, pivots to four tools, reads ten events, forms a hypothesis, writes a note, closes the ticket, and moves to the next one. By the end of a shift, they have made perhaps twenty decisions, half of them about alerts that should never have reached them.

We have spent two years asking a simple question: what if the first draft of the case file was already written?

A different shape of work

The Anzenna Investigation Agent runs continuously on your graph. When a signal crosses the threshold of interest, it pulls the relevant threads, identity history, device posture, SaaS activity, peer-group baselines, and composes a case file. Not an alert. A case file. With a narrative, evidence, a confidence score, and a recommended next step.

The analyst arrives to a short list of decisions to make, each with the homework already done.

09:12, anomaly detected on vault_prod
09:12, correlating identity history
09:13, peer-group baseline drift: +4.8σ
09:14, SaaS egress: 2.1 GB to unmanaged drive
09:15, case INS-2026-0891 ready for review

Why now

The threshold for useful autonomy in security has quietly moved. Models are now good enough to hold a dozen signals in context, reason over them, and produce an explanation an analyst will accept as a starting point. But the model alone is not the product. The product is the surrounding machinery, the graph of identities and devices and data, the peer-group baselines, the audit trail, the human-in-the-loop ceremony.

That is what we have built.

A case file, reviewable in minutes, auditable forever, that is the artifact the old SIEM could never produce.

The analyst stays in control.

People. Investigation Agents do not take action on your environment without human approval. Every step the agent takes is logged. Every decision is inspectable. Every recommendation can be rolled back.

We are not replacing the analyst. We are giving them back the first ninety minutes of their morning.

Available today

Investigation Agents are generally available starting today for all Anzenna customers on the Platform tier and above. Existing customers will see the new case-file inbox in their workspace on their next login. New customers can request a walkthrough, we'll show it to you on data that looks like yours.

The short version

Investigation Agents, in plain terms.

  • Investigation Agents autonomously build security case files in minutes.
  • They correlate identity, endpoint, SaaS, and behavioral data, then hand your analyst a decision, not a search.
  • Agentless and part of the Anzenna platform, with a transparent audit trail a CISO can defend.
Questions

Answered, plainly.

What are Investigation Agents?

Autonomous AI agents that build a defensible security case file from correlated signals, in under 2 minutes median, so analysts decide instead of investigating from scratch.

How do Investigation Agents work?

They gather evidence across identity, endpoint, SaaS, and behavioral data, weigh it against a 90-day baseline, and produce a case file with a recommended action and a full audit trail.

Are they agentless?

Yes. They run on Anzenna's agentless platform, which connects through APIs with nothing to install on endpoints.