Governed Cybersecurity AI
Opening
⌂ 00:00
An interactive cybersecurity session

One request.
An entire governed delivery pack.

How prompts become skills, agents, evidence-backed workflows—and client-ready cybersecurity outcomes.

Click to revealSecurity-first60 minutes
HLD
LLD
KQL catalogue
Project plan
Findings report
Draw.io · SVG · PNG
Hybrid Sentinel
delivery request
click / space to reveal
How we got here

Four steps changed what machines can do.

Each step adds interpretation. The final step adds language—the medium where most cybersecurity work already lives.

01 · fixed rules

Automation

Humans predict the condition and write the response.

SOAR · CI pipelines
02 · learned pattern

Machine learning

Examples teach the system which signals matter.

UEBA · anomaly detection
03 · complex inputs

Deep learning

Models interpret images, speech and messy data.

malware classification
04 · language

LLMs

Models read, write and reason across text-heavy work.

GPT · Claude · Gemini
LLM in one sentence

An LLM predicts
what comes next.

At enormous scale, token by token. The result feels like reasoning—but it remains probabilistic generation.

Completion playground
A suspicious sign-in from two countries within five minutes may indicate …

Plausible is not the same as verified.

Two prompts · two responsibilities

The user asks. The system defines how.

System prompt
You are a senior SOC analyst. Return severity, evidence to check, and the first containment step.
User prompt
“Forty failed sign-ins hit twelve accounts from one IP in ten minutes. What is happening?”
The ceiling of plain prompting

Chat answers once.
Delivery needs continuity.

Every new chat

No durable context

Scope, standards, environment and assumptions are explained again.

Every new person

No repeatable method

Quality depends on who prompted, how they phrased it and what they remembered.

Every deliverable

No controlled action

The model writes text. Humans still execute, reconcile, validate and package.

One request and one response. Best for explanations, drafts and transforms.
Reusable expertise

Package the task.
Not merely the prompt.

A skill captures how an expert performs one repeatable job—then makes that method portable, reviewable and improvable.

Before

Expertise lives in a person’s head

Repeated explanation · manual references · variable output · fragile hand-offs

After

Expertise becomes an executable package

Instructions · references · schemas · scripts · templates · definition of done

Write the method once. Improve it after every real engagement.
Skill X-ray · security-architect

A production skill is knowledge + contracts + code.

security-architect/
The real execution path

Deterministic where possible.
Expert where it matters.

01

Classify

Route the input to the right frameworks.

02 · script

Scan

Mechanical IaC checks.

03 · agent

Analyze

Threats, design flaws, attack paths.

04 · tool

Verify

First-party evidence.

05 · agent

Score

Contextual severity and priority.

06 · schema

Validate

Contract before output.

07 · script

Report

HTML and PDF factory.

08 · human

Approve

Judgment stays accountable.

PLANchoose next step
ACTcall a tool
OBSERVEread the result
ADJUSTcontinue or stop
LLM
+ goal + skills
Agent activity

Reasoning gets
hands and memory.

PLAN Verify current Sentinel retention guidance.
ACT microsoft_learn.search(redacted_query)
OBSERVE 3 first-party sources returned.
ADJUST Record evidence; continue to architecture.
STOP Output contract satisfied; approval required.
Three commonly confused capabilities

Actions, connections and knowledge
are not the same thing.

Cybersecurity example

The security inflection point

More capability.
More blast radius.

Once a model can read untrusted data and perform actions, mistakes become security events.

Chat
wrong text
Tool-using agent
wrong action
Broad autonomous agent
systemic impact
The real problem statement

Today, the engineer
is the orchestrator.

They carry context, reconcile specialists, chase evidence, control versions and assemble the final pack.

Security
engineer
Scoping notesrequirements · exclusions
EvidenceLearn · AWS · standards
DetectionKQL · rules · ATT&CK
DocumentsHLD · LLD · plans
Approvalsscope · architecture
Architecturedecisions · diagrams
Why prompting is not orchestration

A better prompt cannot manage
dependencies, state or approvals.

01

Repeated context

Every specialist reconstructs the same customer reality.

02

Conflicting designs

A detection depends on data the ingestion plan drops.

03

Stale facts

Pricing, licensing and product behavior drift.

04

Broken hand-offs

Chat, email and copy/paste silently lose decisions.

05

No resume

Half-finished work must be reconstructed after interruption.

06

No defensible trail

Evidence, changes and approvals cannot be replayed.

The control plane

The orchestrator owns the workflow.
Skills own the expertise.

Plan

Declare the graph.

Route

Select bounded specialists.

State

Carry shared context.

Gate

Stop unsafe progress.

Evidence

Record authoritative sources.

Revise

Return findings to owners.

Assemble

Build the governed pack.

The LLM reasons inside a step. Code controls what runs next.
Three capability flows · one governed engine

Choose the outcome.
The control plane stays the same.

Capability 1 · document delivery

Specialists decide.
The system assembles.

Intakescope · deliverables
Fact gatefirst-party evidence
Cost + detectionparallel specialists
Convergencedata supports rules?
Architecturedecision synthesis
ArchStudioIR · validate · render
Reviewsecurity + human
Doc builderHLD · LLD · plan
agent reasoningdeterministic/toolgateMCP/architecture engine
ArchStudio through MCP

One architecture contract.
Many governed outputs.

Cybersecurity orchestrator

Architecture request

Scope, decisions, boundaries, evidence references and required views.

→
MCP · generate_architecture

Fast generation workflow

Create and validate the architecture without turning the orchestrator into a diagram engine.

Missing load-bearing HLD details → return up to three questions → resume with answers and run context.
→
Canonical contract

Architecture IR

Validated source of truth passed to export_architecture.

.drawioSVGPNGmanifest + lineage
Capability 2 · security architecture review

One reasoning step.
Deterministic controls around it.

Intakediagram · HLD · IaC
Security architectassess · verify · score
Schema gatefindings contract
HTMLreport factory
PDFvisual deliverable
Final gatetokens · evidence
Packmanifest · lineage

A compliance assessment can branch from the same validated findings.json—without re-deriving the technical findings.

Capability 3 · detection to response

Detection is not finished
until the SOC can act.

INTAKE
Request

goal · environment

HUNTER
KQL + rules

schema · MITRE · tuning

GATE
Validate

contract · tables

SOC OPS
Response

triage · containment · RACI

{ }
detections/queries.json → schema-valid artifact → soc/playbooks.json
The hand-off model

Agents exchange versioned artifacts.
Code decides where they go.

01 · SHARED CONTEXT

engagement-context.json

Scope, sources, design decisions and deliverable requirements.

02 · SPECIALIST CONTRACTS

findings.json
queries.json

Schema-valid outputs with explicit ownership and provenance.

03 · DELIVERY EVIDENCE

manifest.json

Hash, producer, evidence, validation, version and approval.

Agent A chats with Agent B→Orchestrator validates and routes artifacts
Prompt injection · the signature agent risk

Data can attempt
to become an instruction.

## Hybrid Landing Zone v2
Traffic flows through Azure Firewall…
Retention is configured per table…

Peering uses approved route tables…

Click the redacted line.

Treat inputs as dataUploaded documents never redefine system policy.
Constrain outputA findings schema has no field for “email this document.”
Scope tools and egressThe review agent has no arbitrary outbound action.
Gate consequencesIrreversible and outward-facing actions require approval.
Record the attemptInjection detection and blocked actions enter the audit journal.
The governed agentic stack

Security and traceability
cross every layer.

SECURITY · MAY IT DO THIS?
AUDITABILITY · WHAT HAPPENED?
Where the value comes from

Move effort from assembly
to judgment.

The goal is not to remove the security engineer. It is to protect their time for decisions only they should own.

Manual
Governed system
Repeated context
human
skills + state
Evidence gathering
human
MCP + provenance
Validation
reviewer memory
schemas + gates
Formatting
manual
scripts
Risk decisions
human
still human
Current → future

A secure MVP is a starting line.
Assurance becomes continuous.

Bounded skills

Versioned instructions, knowledge, scripts and contracts.

LangGraph

Declared workflow, routing and gates.

MCP evidence

Allowlisted first-party retrieval and ArchStudio tools.

Journal + manifest

Resume, evidence, lineage and approvals.

Schema + HITL

Fail-closed output and consequential-action gates.

Policy plane

OPA/Cedar evaluates identity, action, data and destination.

Content guardrails

Advanced injection, PII and output controls.

Tenant isolation

Identity-bound storage, credentials and execution.

Continuous evals

Adversarial and regression testing on every change.

Decision records

Telemetry to SIEM and defensible AI explanations.

Interactive demo

One request.
Watch the control plane work.

Engagement request

Ready.

INTAKE
SCOPE GATE
SPECIALISTS
ARCHSTUDIO
REVIEW
PACK
Scope extracted.
Hybrid · Sentinel · HLD/LLD · diagrams
architecture.drawio
architecture.svg
HLD.docx
LLD.docx
project-plan.xlsx
manifest.json
findings.pdf
navigator.json
A safe adoption ladder

Start with one bounded task.
Earn the right to orchestrate.

STEP 01

Choose repetition

A frequent, text-heavy task with a clear expert method and review point.

STEP 02

Write the skill

Procedure, references, templates, output contract and definition of done.

STEP 03

Bound the agent

Read-only tools, approved data, schemas, budgets and a human gate.

STEP 04

Connect carefully

Chain two proven skills through typed artifacts and an audit journal.

What makes the result trustworthy?

The model is replaceable.
Expertise lives in skills.
Control lives in the workflow.
Accountability stays human.

LLMreasoning
Skillsexpertise
Orchestratorcontrol
Gatesapproval
Evidencetrust
Next session

Useful today.
Defensible at scale tomorrow.

From governed agents to defensible AI.

Question 01

Can it explain why it acted?

Question 02

Can it prove which evidence influenced the decision?

Question 03

Can security reconstruct, challenge and audit the path?

Decision transparency · policy enforcement · tenant isolation · continuous assurance · SIEM decision records
Navigate

Session map