-->

Friends of Enterprise AI World! Register NOW for KMWorld 2026 & Enterprise AI World 2026, November 16-19.

SentinelOne Turns Security Decisions into Automated Action with Governed, Closed Loop Responses

SentinelOne, an AI Security leader, is introducing a governed, closed-loop response across the Singularity Platform to provide trustworthy automation for security operations.

Purple AI and Singularity Hyperautomation now autonomously investigate alerts, reach verdicts, and execute responses. Security teams set the boundaries first, deciding where AI acts on its own and where it stops for human sign-off. The Autonomous SOC now runs from alert to action, at the speed and scale of AI, with the confidence and control of human defenders, according to SentinelOne.

Purple AI Agentic Investigation has been running in customer environments since June and now handles more than 8,500 critical autonomous investigations every day. More than a third of the eligible customer base has it running. Across that base, Purple AI investigates nearly three times as many alerts as analysts reach by hand. Alerts that would have aged in a queue get investigated, and analysts spend their hours on the decisions that need judgment, the company said.

“Security teams need AI they can trust to act within boundaries they set,” said Chris Corde, chief product officer, SentinelOne. “With this release, teams decide exactly where Purple AI is permitted to execute autonomously, and where it pauses for a human. That governance is what makes autonomous response viable in a live SOC. Human response time stretches on nights and weekends—attack timelines do not. In a single recent weekend, Purple AI investigated more than 5,000 critical alerts across our customer base, each in minutes. Nothing waited for Monday.”

What decides whether an SOC can adopt autonomous response based on agentic reasoning is whether a human can see the action, trace it, and take it back. Every AI-driven action in the Singularity Platform is traceable, auditable, and overrideable by the team that authorized it. These capabilities are built into core components of the Singularity Platform. SOC teams get AI reasoning and automated execution inside the workflows, tools, and approval chains they already run. There is no integration work and no additional tooling required, said SentinelOne.

Building on Purple AI Agentic Investigation, the new capabilities use Singularity Hyperautomation workflows to:

  • Trigger a Purple AI Agentic Investigation from any point in a workflow, not only the initial alert.
  • Pull the full investigation report, with verdict and evidence, directly into automation logic.
  • Apply customizable LLM Actions to reason over the findings and call the right next step.
  • Call validated response snippets, reusable action blocks teams build once and use repeatedly.

The Hyperautomation workflow capabilities are expected to be generally available later this quarter.

For more information about this news, visit www.sentinelone.com.

EAIWorld Covers
Free
for qualified subscribers
Subscribe Now Current Issue Past Issues