Slack's Security Engineering team built an agentic AI system to automate security alert investigations. The system uses multiple AI personas (Director, Expert, and Critic agents) working collaboratively through structured outputs and defined phases (Discovery, Trace, Conclude). Over 7,500 investigations were performed in the first quarter, with agents making spontaneous discoveries like credential exposures that human analysts might miss. The architecture includes a Hub API, scalable Workers, and a real-time Dashboard, enabling security analysts to supervise investigations rather than manually gather evidence.

10m read timeFrom slack.engineering
Post cover image
Table of contents
The Development ProcessFrom Prototype to ProductionService ArchitectureExample ReportConclusion

Sort: