SentinelOne Opens Purple AI Agentic Investigation to All Customers
SentinelOne, the AI security leader opened Purple AI Agentic Investigation to its customers and introduced Singularity Credits, a unified currency for running AI-powered work across the Singularity Platform.
Starting this week, customers can opt into a complimentary trial of the newest capability from Purple AI, SentinelOne’s autonomous security reasoning for the agentic SOC.
That capability — ‘zero-click,’ autonomously initiated investigations — detects, investigates, verifies, and responds to threats without human dependencies. When a threat crosses a defined threshold, Purple AI investigates, renders a verdict, and stops it at machine speed, while analysts keep full visibility and control.
The capability arrives as security teams confront a hard limit, not detection, but investigation capacity.
Also Read: Cyber Security: Hope for the Best and Be Prepared for the Worst
Detections climb with every new tool and every expansion of the attack surface, alerts queue for attention, and verdicts wait on analyst availability, with coverage thinning on nights, weekends, and during surges. Frontier-AI-powered threats are poised to widen that gap further.
“Today’s security teams face more critical alerts than any staffing plan could investigate, and AI-powered threats are only going to make that worse,” said Chris Corde, Chief Product Officer of SentinelOne.
Activation is admin-controlled, role-based, and reversible at any time, and consumption guardrails keep usage and downstream cost in the hands of those with the right authority
Also Read: India's First Private Rs.14,000 Crore Semiconductor Facility in Andhra Pradesh
Why SOC Teams Are Adopting Purple AI Agentic Investigation
• Seamlessly integrated — zero configuration, working from day one
Purple AI is built into the Singularity Platform, not bolted onto it. The new Agentic Investigation capability runs on telemetry already in the platform across endpoint, identity, cloud, and third-party security data, as well as inside the automated workflows customers already use. There is nothing to deploy, integrate, or tune, and no data leaves the platform. Activation is a single click.
• A force multiplier for every analyst
Purple AI does the investigation work, collecting evidence, correlating telemetry, and building the attack timeline, so analysts start at the verdict instead of the alert. It scales a team’s investigation capacity without scaling headcount, and frees analysts for the judgment, threat hunting, and response decisions that need a human. It is designed as an extension of the analyst: amplifying human defenders, not replacing them.
•Fully audited — governed autonomy, no black box
Every verdict carries a complete, auditable evidence chain, so analysts can review each AI step and outcome with confidence. Customers set the degree of autonomy through an adjustable human-in-the-loop approach that scales to their confidence and SOC maturity. Verdicts can trigger automated, policy-driven responses, or prompt an analyst with recommended actions. Activation is admin-controlled, role-based, and reversible at any time, and consumption guardrails keep usage and downstream cost in the hands of those with the right authority.
Also Read: Madhya Pradesh Government Approves New Semiconductor Policy
•Built on the most advanced reasoning in cybersecurity
Purple AI is the reasoning brain and interface for the entire Singularity Platform. It brings human-level reasoning from advanced frontier-AI models to bear through a multi-model approach, combining Anthropic’s Claude, OpenAI’s GPT, and SentinelOne’s proprietary “Ultraviolet” models to compress investigations that once took hours or days into minutes and seconds. For critical threats, investigations trigger automatically and deliver verdicts that can be acted on autonomously or by an analyst.



