SentinelOne adds human-governed controls to its AI alert response tools
SentinelOne (NYSE: S) announced new governance features for its Singularity Platform that allow security teams to set boundaries on autonomous AI-driven alert investigations and responses, according to a company press release.
The update connects the company's Purple AI and Singularity Hyperautomation tools to enable automated investigation, verdict, and response workflows. Security teams can define which actions the AI executes without human approval and which require manual sign-off before proceeding.
SentinelOne said its Purple AI Agentic Investigation feature has been running in customer environments since June and now processes more than 8,500 critical autonomous investigations daily. The company said more than a third of eligible customers have the feature active, and that Purple AI investigates nearly three times as many alerts as analysts handle manually.
"Security teams need AI they can trust to act within boundaries they set," said Chris Corde, Chief Product Officer at SentinelOne. "Human response time stretches on nights and weekends — attack timelines do not. In a single recent weekend, Purple AI investigated more than 5,000 critical alerts across our customer base, each in minutes."
The new Singularity Hyperautomation workflow capabilities allow teams to trigger investigations from any point in a workflow, pull investigation reports directly into automation logic, apply customizable reasoning actions, and reuse validated response blocks. Every AI-driven action is described as traceable, auditable, and reversible.
The Hyperautomation workflow features are expected to be generally available later this quarter. SentinelOne is demonstrating them at Black Hat USA 2026 in Las Vegas.
