Platform
Response as skills the agent can compose
A playbook only helps with the incident someone anticipated. SAF3AI models response as a library of atomic skills: the agent runs a predefined workflow for a known threat, and composes a new chain from the same catalogue when it meets something nobody wrote a playbook for.
Capabilities
Key Features
Skills are atomic
One skill does one thing — contain a session, enforce a guardrail, redact an output, revoke a scope, open a ticket, notify an owner. Small enough to compose, specific enough to audit.
Workflows are ordered skills
A workflow is a predefined chain for a threat you have seen before. Forty out-of-the-box workflows ship covering prompt injection, data loss, agent compromise, identity abuse and more.
The agent composes for novel threats
When nothing in the library matches, the agent assembles a chain from the live skill catalogue — constrained to real skills, never inventing an action that does not exist.
Surface-agnostic by design
Skills route to whichever enforcement plane the incident belongs to at run time. One workflow works across Copilot, Gemini, your gateway and your agents — no per-surface clones to maintain.
Reversible by default
Every reversible action records its reversal path. Irreversible ones require explicit confirmation, every time, with no setting that turns that off.
Honest about what is connected
A skill whose integration is not connected says so plainly rather than reporting a success that never happened. Readiness is visible before you rely on it, not after.
The model
Detection and response, one library
Detection rules and response playbooks used to be separate systems with separate vocabularies. They are now one catalogue: sense skills that observe, and action skills that do something about it.
Sense skills
What the platform can notice
Generated from the detection rule catalogue, each categorised by the OWASP LLM Top 10 class or MITRE ATLAS technique it belongs to. This is the sensing half of the library.
Action skills
What the platform can do
Contain, enforce, remediate, notify and utility verbs, each declaring whether it is reversible, which integration it needs, and whether it requires human confirmation.
Every skill carries a manifest
Each skill publishes what it does, what it needs, whether it can be undone and which enforcement planes it can route to — readable as structured metadata or as a plain-language document. Nothing about a skill's behaviour is implicit.
Workflow library
Forty workflows across ten threat domains
Grouped by the kind of threat they answer, not by the surface they run on — because the same workflow works wherever the incident happens to live.
Workflows are editable, and you can save one the agent composed during a live incident as a reusable workflow of your own — which is how the library grows from what actually happened rather than from what someone imagined might.
Get started with Skills & Workflows
See how Saf3AI can help secure your AI agents.