Cybersecurity × Agentic AI
Opening
⌂00:00
Session 3 · Working product

One request.
A governed delivery pack.

Inside the cybersecurity orchestrator: specialist skills, deterministic gates, evidence, architecture and client-ready outputs.

Live capabilitiesCurrent architectureFuture governance
Greenfield
security request
HLD · LLD
Project plan
Editable diagram
Findings
Manifest
space / click to reveal
The delivery problem

The expertise exists.
The delivery system is fragmented.

Manual hand-offs

Context is copied

Specialists receive incomplete or stale assumptions.

Silent conflict

Designs disagree

Collection, detection, architecture and documents drift apart.

Assembly effort

Packs are rebuilt

HLD, LLD, diagram and plan formatting repeats.

Weak lineage

Decisions are opaque

Evidence, producer, version and approval are hard to trace.

No resume

Interruptions cost work

Recovery depends on human memory and copied files.

The gap

Governed orchestration

Sequence, state, gates, evidence and reproducible output.

Three value levers

The value is bigger than faster writing.

↓

Assembly effort

Reusable skills and deterministic rendering reduce repeated production work.
⊘

Defect classes

Mechanical convergence and schema gates catch conflicts every run.
∴

Evidence

Journal, lineage, validation and approvals make decisions reviewable.
Cycle timeIntake → review-ready pack
ReworkConflicts caught before approval
TraceabilityClaims linked to evidence

Pilot rule: baseline first, measure across real engagements, then claim savings.

Separation of concerns

The orchestrator owns control.
Skills own expertise.

Orchestrator

Order · state · gates

Runs the graph, owns journal and manifest, routes findings, pauses and resumes.

↔
Skills hub

Cybersecurity knowledge

Intake, architecture, detection, cost, documents, compliance and SOC procedures.

↔
ArchStudio

Diagram assurance

Architecture IR validation, editable draw.io and deterministic exports.

Provider-neutral expertiseTyped contractsDeterministic artifacts
Current state · 17 Aug 2026

Four capabilities are already wired into the product.

Input → output

Security architecture review

Diagram, HLD or design document → structured findings, evidence checklist and enterprise HTML/PDF report.

security-architectschema gatereport renderer
Repository-derived status

Proven by workflows—not roadmap labels.

Live

Architecture review

Structured findings and complete report produced from a real design artifact.

Live

Sentinel pack

Four specialists, 40-use-case matrix and a full deterministic document pack.

Live · 17 Aug

Defender for Cloud

Fact drift caught; coverage gate passed; independent review routed a blocking issue.

Live

KQL Studio

Model-declared verification replaced by mechanical table and column checks.

Capability claims are derived from the graph, available skills and render packs.
Purpose-led technology

One pick. One purpose. One upgrade trigger.

UIserver-rendered HTML console · 5 tabs
APIFastAPI · uploads · OpenAPI
OrchestrationLangGraph default · owned kernel fallback
Agent runtimeOpenAI Responses · Anthropic adapter
SkillsSKILL.md · references · scripts
Tools / evidencefunction tools · MS Learn MCP · AWS MCP
Stateengagement files · journal.jsonl · manifest
Observabilitytracer port · Langfuse adapter
Guardrailsschemas · G1–G6 · HITL · allowlists
ArtifactsArchStudio · docx · xlsx · draw.io · JSON
The common engine

One request travels through a governed control spine.

Intakenormalize scope
Scope gateapprove intent
Specialistsbounded expertise
Convergemechanical checks
Reviewindependent
Builddeterministic
Final gatefail closed
Append-only journalResume at node boundariesRevision capArtifact lineage
Microsoft Sentinel delivery

Make specialists disagree safely.

Intakescope + sources
Ingestiontables · tiers · cost
Detectionqueries · MITRE
G3 convergecollection ↔ detection
Architectureindependent design
PackHLD · LLD · plan
Observed live run: G3 found five collection-to-detection conflicts, routed them to the owner, and the second design cycle converged.
The convergence defect

A rule that deploys but never fires is a delivery failure.

The detection specialist cites an event source. The ingestion design must collect it into a compatible destination and tier.

Detection: suspicious PowerShell chain
Requires: DeviceProcessEvents

Collection design: source not onboarded

G3 finding: DET-COL-017 · blocking
Owner: ingestion specialist
Route: revise collection design

Cycle 2: source added · query dependency satisfied · finding retained for audit
Newest live capability

Different domain.
Different design graph.

Intakeworkloads · scope
G2 factsvendor drift
DfC designplans · coverage
G3dcoverage consistency
G4 reviewindependent architect
PackHLD · LLD · plan
G2 observed

A real product-fact drift was flagged instead of silently copied into documents.

G3d observed

Plan and workload coverage passed its mechanical design check.

G4 observed

An independent review routed one blocking finding for revision.

Security architecture review

One reasoning step.
Deterministic controls around it.

Intakeartifact + scope
Assesssecurity-architect
Schema gatefindings contract
HTMLstable renderer
PDFdegrades safely
Final gateno open tokens
Assemblemanifest + pack
Use reasoning where context matters. Use code where repeatability matters.
KQL Studio

The model may propose.
It may not self-certify.

Each table and column is checked mechanically before the query is handed to an analyst.

verifiedunverifiederror
query: Password spray across Entra ID
table: SigninLogs ✓ known
columns:
  UserPrincipalName ✓
  IPAddress ✓
  ResultType ✓
  LegacyRiskScore ✕ absent

G5 blocked: replace unsupported column, then revalidate
ArchStudio via MCP

Architecture intent becomes editable, validated artifacts.

Cyber orchestrator

Scope, specialist decisions and run context.

→

generate_architecture

Fast generation workflow → validated Architecture IR.

→

export_architecture

.drawioSVGPNGmanifest
Typed hand-offs

Agents exchange artifacts.
The journal explains the run.

engagement-context.json
domain spine
fragments/node.json
owned writes
journal.jsonl
events + resume
manifest.json
hash + lineage
ProducerInput hashSkill versionEvidenceValidationApproval
Interactive product simulation

Watch the control plane turn scope into artifacts.

Design a greenfield Microsoft Sentinel platform for a hybrid customer. Produce the HLD, LLD, project plan and editable architecture.

Ready.

Intake
Scope
Design
Converge
ArchStudio
Pack
Roadmap with boundaries

Current proves delivery.
Future hardens scale.

Current
  • FastAPI and server-rendered console
  • LangGraph with kernel fallback
  • File state, journal and manifest
  • MS Learn and AWS MCP evidence
  • Schema gates, revision caps and HITL
  • Sentinel, DfC, review and KQL capabilities
Next
  • React/Next.js multi-user surface
  • PostgreSQL checkpointer and tenant isolation
  • Self-hosted Langfuse operating surface
  • LLM-as-judge attached to golden datasets
  • NeMo content rails + OPA/Cedar policy
  • OTel decision records exported to SIEM
Every future layer must answer a specific risk or scale trigger—not simply add another framework.
Session 3 synthesis

The model is replaceable.
The governed system is the asset.

Expertise

Skills

Provider-neutral procedures, references and scripts.

Control

Graph + gates

State, routing, limits, approval and safe failure.

Trust

Evidence + artifacts

Validated outputs with lineage and review.

Next: build a bounded cybersecurity agent, attack it, and decide whether it may ship.

Presenter controls

Space / →Reveal or advance←PreviousMSession mapNSpeaker notesRReferencesFFull screen