Ask questions about the environment you operate

Start with a node, a service, or a change you need to understand. Agents can inspect authorized current signals, selected raw observations, feed schemas, retained signal history, and dependency paths to answer questions in operational context.

Ask what changed, which observations support a finding, or how a dependency contributes to a score. Historical answers use returned samples, their timestamps, units, and coverage. Missing, denied, or truncated evidence should remain visible rather than becoming an invented trend.

Bring complementary agents into the investigation

CyberStitch includes a Model Agent, a Network Analyst, and an Impact Analysis Agent. Their roles, provider bindings, context packages, dataset access, and connector tools determine the work each can perform.

Agent Teams use configured consultations and handoffs between agents within a CyberStitch instance. A coordinator can ask an applicable specialist to investigate a bounded question, then inspect the result and collaboration trace. Each participant uses its own current authorization; delegation does not grant new credentials or data access.

Collaboration is opt-in and bounded by task depth, parallel work, time, and token budgets. Agent Teams do not imply unrestricted background activity or cross-instance agent delegation.

Give the agents relevant domain skills

Assign signed context packages containing domain references, skills, playbooks, and methodology. Package domains include model authoring, cybersecurity risk, threat hunting, network traffic analysis, security configuration, infrastructure reliability, Cisco networking, and Juniper networking.

An agent can select a relevant assigned skill and load its knowledge body with package and version provenance. The skill supplies guidance; it does not grant executable capabilities or override current observations, access controls, or approval requirements.

Draft models and expressions you can inspect

The Model Agent can propose a new model or an edit to an identified model version. Review the proposed content, explanation, and diff. Applying an approved proposal creates a disabled model version so activation remains a separate decision.

For a signal expression, the agent uses available authorized input keys, types, units, and model context. The runtime can compile and evaluate the exact proposed Tengo source against a pinned snapshot and return validation evidence. Validation is read-only: it does not apply the expression or establish that a proposed risk formula is calibrated.

Connect a finding to a possible improvement

The Impact Analysis Agent uses native counterfactual analysis to inspect low-scoring nodes, their observed contributors, and candidate improvements. It can consult an applicable specialist with relevant connector evidence and context-package guidance.

A simulated score change explains what the current model predicts. It is not a measurement of future recovery. Review the baseline, assumptions, dependency scope, and evidence before choosing an operational change.

Turn a useful recommendation into a controlled action

Where an installed connector and current grants support a change, an agent can prepare an exact proposed action. Connector mutations enter the approval workflow rather than executing from a conversational suggestion. Missing required inputs must be supplied explicitly.

Approval is tied to the action and its scope. The system rechecks authority before execution and records the outcome. Supported signed remediation contracts also reread the applicable state before the change and verify the expected state afterward. An executed command alone is not proof that the problem is resolved.

Use interactive and configured background analysis

Investigate interactively in a node conversation, or configure continuous and reactive analysis where the agent and assignment support it. Inspect runs, findings, tool activity, and collaboration status to understand how a result was produced.

Background analysis can surface recommendations; it does not remove the approval boundary for changes. An unavailable provider, missing grant, or insufficient evidence can prevent a requested investigation from completing.

Choose the inference environment deliberately

Use the supervised local llama-server integration with prepositioned, checksum-verified runtime and model files for offline inference. Or configure supported OpenAI, Anthropic, or OpenAI-compatible providers when your policies permit external processing.

Provider selection can vary by agent. Generation and embedding destinations have separate egress checks, and package or dataset policy can prevent protected material from leaving the local environment. Model capability, context capacity, available tools, and hardware affect what a configured agent can accomplish.

AI remains optional. The core graph, collection, and operational interface do not require it. Evaluate recommendations against your own evidence and domain expertise; the software does not guarantee expert correctness or a successful remediation.