Go back

The Missing Layer in the Agentic Security Stack

The Missing Layer in the Agentic Security Stack

By Tyson Kopczynski

The security industry has been building toward agentic AI for years without calling it that. Playbooks, orchestration engines, automated response pipelines: all of it was pointing at the same idea, that security operations should not require a human to manually advance every step of every workflow with the tool.

We are now at the point where AI agents can genuinely carry multi-step work across systems. And we are also at the point where the limitations of current architectures become visible.

There is a layer missing from most agentic security deployments. It is not the reasoning capability. Modern foundation models are more than capable enough for the majority of security workflows. It is not the integrations, most stacks have APIs. The gap is the coordination and context layer: the infrastructure that allows an AI agent to hold continuous context across the full scope of a security program, understand the current state of commitments and work in flight, and operate persistently rather than as one-off query responses.

Why context continuity matters

Most current AI security tools are stateless per interaction. You ask, they answer. If you want them to know what happened last week, you have to bring that context into the prompt. This is fine for point queries but fundamentally limiting for operational work.

Security operations are not collections of isolated questions. They are ongoing programs with commitments in motion, vendors in process, tickets in various states of completion or neglect, and follow-through due on decisions that were made weeks ago. An AI agent that cannot hold that state cannot reliably run the operational layer.

The programs that are getting the most out of agentic AI right now are the ones that have solved this at the architecture level, building or deploying systems that maintain persistent context and treat the security program as a coherent operational environment rather than a series of isolated prompts.

The policy and authority model

The second gap is clearer authorization: what is the agent permitted to do, and under what conditions does it need to escalate?

Most agentic systems today handle this crudely, either requiring human approval for everything (which eliminates the throughput benefit) or operating with effectively unconstrained action scope (which is not acceptable for security). The right model is explicit, layered authorization: the agent has a defined set of things it can do autonomously, a defined set of things it escalates with a recommendation, and a defined set of things it cannot touch. These are calibrated per workflow and adjusted over time based on track record.

Building that model requires explicit design upfront. It cannot be added retroactively. Organizations that are deploying agentic security capability now should be making this a first-class design question: not just what can the agent do, but exactly under what conditions does control return to the human.

The workflow creation gap

The capability that is most underutilized in current agentic deployments is the ability to create new workflows from natural language, at the moment when a human recognizes a recurring situation that should be automated.

Most tools require a developer or engineer to formalize a new workflow in a configuration interface. That lag between recognizing the need and having the automation running means a large proportion of security work that could be systematized never is. It stays manual because the cost of automating it is too high.

The systems that close this gap allow a security practitioner to describe a recurring situation in plain language, and have the automation running as a standing process immediately, without configuration. That capability changes the economics of workflow automation in security programs substantially.

Where this is going

The agentic security stack is being built right now, across multiple layers by multiple vendors. The organizations that will get the most out of it are the ones paying attention to the missing layer: persistent context, explicit authorization architecture, and the ability to create automation from observation without engineering overhead.

Detection is not the ceiling anymore. What happens after the signal is.

__________________________________________________

Tyson Kopczynski is a security executive and advisor to Axari.

Attackers aren't going to use less AI. Defenders shouldn't either.

Prasen Shelar, Founder and CEO