Natural-language security workflow compilation
Compile an analyst-authored procedure into a testable automation with bounded tools.
What this workflow does
Compile an analyst-authored procedure into a testable automation with bounded tools. It coordinates dependencies across connected systems, pauses at exception boundaries, and records the state of every approved sub-step.
What you gain
Versioned, tested automation pending activation
What the AI agent changes
How this worked before
A fixed workflow required every system and input to behave exactly as expected; one exception stopped the entire chain.
What the AI agent changes
The agent chooses the next tool from the current state, recovers from common exceptions, and asks for a decision at the right boundary.
Agent trigger
An analyst submits an approved procedure and representative test cases.
Inputs
- Process context: procedure, schemas, connector permissions, and test fixtures
- Approved policies, ownership, and exception rules
Agent flow
- 1
Build the dependency graph and verify every connector permission.
- 2
Coordinate read-only sub-steps and surface blocked dependencies.
- 3
Prepare a least-privilege executable workflow and test report with state, exceptions, and rollback points.
- 4
Execute approved sub-steps idempotently and verify the final state.
Human decisions
After step 3
The accountable process owner approves a least-privilege executable workflow and test report.
Outcome
- Versioned, tested automation pending activation
- Evidence, exceptions, and audit trail
Guardrails
- Pause when a dependency or approval is missing.
- Record before-and-after state for every system write.
Risks and mitigations
A partial multi-system execution can leave records in conflicting states.
Use idempotency keys, checkpoints, and explicit compensation for every write step.
Sources and evidence
Sources establish feasibility or impact. Not every metric comes from an identical implementation.