Security Agent Roles
Give each security agent a clear job, boundary and handoff.
A searchable library of evidence-led cybersecurity role prompts with explicit scope, deliverables, escalation and completion criteria.
When it helps
A clear response to a specific operating problem.
Use this when an agent workflow needs specialist judgement but its authority, deliverable or handoff is ambiguous. Each role is a reusable starting point that still requires runtime scope and human accountability.
What it covers
- 46 specialist roles across eight cybersecurity tracks
- Shared operating contract and A0-A3 autonomy language
- Explicit inputs, outputs, boundaries and escalation rules
- Copy-ready prompts with validated catalog provenance
How Yefosec can help
Turn the pattern into owned improvement work.
- 01Choose the specialist judgement required for a defined decision
- 02Set inputs, expected artifacts and completion criteria
- 03Make escalation and handoff responsibilities explicit
- 04Apply the same bounded role language across SOC and CISO work
Data and decisions
What stays under your control.
- A role prompt describes judgement; it does not grant tools or authority
- Copied prompts remain versioned text and should be reviewed before reuse
- Sensitive, destructive or external actions require runtime approval
Related solutions
Continue from here.
SOC Workflow
A self-hosted workflow pattern for alert intake, enrichment, triage, investigation, response, detection engineering and quality assurance.
ExploreConnected Security
A self-hosted operating pattern for moving findings, detection gaps and risk decisions across testing, SOC and governance teams.
ExploreCISO Governance
A self-hosted workflow for keeping risk, control, supplier, incident and board evidence current between formal reviews.
Explore