Surprisingly Useful AI Article Enhancements
SentinelOne has opened its Purple AI Agentic Investigation capability to customers, introducing autonomously initiated threat investigations that run inside the company’s existing Singularity Platform.
The feature is designed to address what SentinelOne describes as a growing investigation capacity gap in security operations centres (SOCs), where rising alert volumes and expanding attack surfaces are outpacing the ability of analysts to investigate and respond to threats.
The release lands at a point of sustained pressure on Australian cyber security teams. The Australian Information Security Association (AISA) has warned that more than half of Australian Government agencies face critical cyber security skills shortages. The Australian Signals Directorate (ASD) responded to more than 1,200 cyber security incidents in 2024/25, an 11 per cent increase year-on-year, while the Australian Cyber Security Centre (ACSC) has flagged that AI-driven cyber threats are expected to increase over the next 12 to 18 months.
SentinelOne’s position is that the core bottleneck in the modern SOC is no longer detection but investigation. Security tools are surfacing more alerts than ever, but analysts lack the hours to work through them all – particularly during after-hours periods, weekends and surge events when coverage thins out.
How Purple AI Agentic Investigation works
Purple AI Agentic Investigation operates on telemetry already collected within the Singularity Platform, spanning endpoint, identity, cloud and third-party security data sources. It also runs inside the automated workflows customers already have in place.
When an alert crosses a defined threshold, the system automatically launches an investigation without manual intervention. It collects and correlates evidence across data sources, constructs an attack timeline, renders a verdict and can trigger policy-based response workflows – all without an analyst needing to initiate or supervise each step.
SentinelOne describes the capability as zero-configuration, requiring no additional deployment, integration or tuning on top of an existing Singularity Platform instance. Activation is handled through the platform console and no data leaves the platform during the process.
Under the hood, Purple AI draws on a multi-model AI architecture. It combines Anthropic’s Claude, OpenAI’s GPT and SentinelOne’s proprietary Ultraviolet models to process and reason across security telemetry. SentinelOne claims this approach can compress investigations that previously took hours or days into minutes.
Chris Corde, Chief Product Officer at SentinelOne, pointed to investigation capacity as the binding constraint in modern security operations.
“Today’s security teams face more critical alerts than any staffing plan could investigate, and AI-powered threats are only going to make that worse,” Corde explained. “Investigation capacity has become the binding constraint of the modern SOC: detections climb, alerts queue and verdicts wait on analyst availability. Purple AI’s Agentic Investigation capability is designed to remove that constraint by making investigations automatic, continuous and immediate.”
Keeping humans in the loop
A central design principle of the system is that analysts retain visibility and control throughout the investigation process. Every verdict produced by Purple AI carries a complete, auditable evidence chain, allowing analysts to review each step the AI took and how it reached its conclusion.
Customers can adjust the degree of autonomy through human-in-the-loop settings that scale with their confidence level and SOC maturity. At one end of the spectrum, verdicts can trigger fully automated, policy-driven responses. At the other, the system can surface its findings and recommend actions for an analyst to approve before anything is executed.
Activation is admin-controlled, role-based and reversible at any time. SentinelOne has also built in consumption guardrails to keep usage and any downstream costs under the control of authorised administrators.
The company frames Purple AI as a force multiplier rather than a replacement for human analysts. The intent is that analysts spend less time on the evidence-gathering and correlation work that precedes a verdict, and more time on judgement calls, threat hunting and response decisions that require human expertise.
Singularity Credits
Alongside the investigation capability, SentinelOne has introduced Singularity Credits – a unified consumption currency for running AI-powered workloads across the Singularity Platform.
Related: Best Business Laptops for work & school
Related: Best Gaming Laptops
Related: Best Portable Laptop
Purple AI Agentic Investigation consumes Credits when it runs. To lower the barrier to entry, SentinelOne is granting customers a complimentary allotment of Credits to trial the feature. During the trial, no charges apply and no payment method is required.
Once the trial concludes, customers can purchase additional Singularity Credits through channel partners, direct billing or eCommerce.
The broader agentic SOC vision
SentinelOne positions Purple AI Agentic Investigation as a step toward what it calls the “agentic SOC” – a security operations model where AI reasoning works alongside human defenders at scale rather than operating as a separate, disconnected layer.
Purple AI serves as the reasoning and interface layer for the Singularity Platform more broadly, handling tasks from natural language querying of security data through to autonomous detection, triage and response. Because it operates natively on telemetry already flowing into the Singularity Platform, SentinelOne argues it aligns with what Gartner has defined as the integrated security operations centre (ISOC) category.
Availability
The Purple AI Agentic Investigation trial is available now in Singularity Platform consoles. Both new and existing Singularity customers can opt in and begin running agentic investigations immediately.
Last Updated on June 22, 2026 by Nick Ross



