Security vendors are asking companies to trust AI agents with increasingly sensitive work. Almost nobody has answered the prior question: what should an agent actually be trusted to do?
“The Agentic SOC Alliance is trying to answer a question cybersecurity companies have mostly skipped in their rush to sell artificial intelligence: What should an agent actually be trusted to do?”
Ron Schmelzer, Forbes
TENEX.AI is a founding member of the Agentic SOC Alliance, which includes 15 companies, including ExtraHop, CrowdStrike, and LangChain. The Alliance formed ahead of Black Hat USA 2026 to define a shared operating model for agentic security operations and to draw a line between systems that are actually agentic and the growing category of products that just claim to be.
That second part matters more than it sounds. Agent washing is what happens when every vendor relabels automation as autonomy and buyers lose the ability to tell the difference. A standard is the only thing that fixes it, and a standard only works if the companies building the technology agree to be measured against it.
The model the Alliance landed on has three layers. Context is a continuously updated knowledge graph that agents can query. Harness is the runtime that governs how agents execute, with guardrails and an audit trail. The model is the interchangeable reasoning layer that performs the triage.
We did not have to change our architecture to align with it. TENEX agents run inside a governed harness where every query, every piece of evidence, and every disposition is auditable. And humans remain accountable for the consequential decisions.
The future of security operations is fully agentic and human-led. We would rather help write the standard for that than argue about definitions later.
Read the full article on Forbes
Running Microsoft Sentinel or Google SecOps? Try the TENEX 7 Day Challenge


