Cyber / defensive workflows

AI-assisted remediation.
Human-authorized change.

A proposed integration path for defensive security work: scope the finding, prepare a change, validate it and keep consequential execution behind explicit authority.

Governed remediation

A good patch is not
deployment permission.

A model can produce a plausible remediation. Tests can add evidence about its technical behavior. Neither, on its own, establishes the right to change a production system.

The proposed pilot separates change preparation from authorization, using an agreed repository scope and a non-production validation environment.

  1. 01 / SCOPEAuthorized finding

    Named owner, selected repository and allowed task.

  2. 02 / PREPAREReviewable change

    An AI-assisted proposal, not an automatic production change.

  3. 03 / VALIDATETechnical evidence

    Agreed checks and explicit coverage limits.

  4. 04 / AUTHORIZEHuman final gate

    Permission before any agreed merge or deployment step.

Conceptual pilot workflow. No model-provider partnership, approved integration or production deployment is implied.

In scope

Defensive, bounded evaluation

One authorized repository, one finding class and a clear review boundary. Evaluate both the proposed correction and the ability to refuse a consequential action.

Out of scope

Autonomous production changes

No automatic merge, deployment or third-party testing is part of this proposed pilot scope. Access and any external action need their own explicit authorization.

For security teams & technical partners

Start with the change you need to control.

Start with one workflow

Where does AI output become action?

Define the action, name the authority and agree what evidence would demonstrate control.

Discuss a pilot