GitLab's Signals Engineering team automated post-incident detection gap analysis using GitLab Duo Agent Platform. The workflow uses two agents: the built-in Security Analyst Agent for quick first-pass reviews, and a custom Detection Engineering Assistant built with a detailed system prompt encoding team-specific context
Table of contents
The detection gap problemWhat is GitLab Duo Agent Platform?1. Security Analyst Agent2. Building the Detection Engineering AssistantRunning gap analysis on incidentsWhat we've learnedGet startedSort: