Preview

Joinable Security · Runbooks

Turn your playbooks into trusted knowledge your security agents can act on.

Built on Propagator, Joinable Runbooks refines your security team’s playbooks, SOPs, and IR procedures into permission-governed knowledge, then gives you the tools to build, own, and run the security agents that reason from those approved procedures, not the open internet.

The 2-minute explainer

See how a SOC’s playbooks become governed, agent-ready knowledge, and the agents that act on it.

Key benefits

Put your security expertise to work in every investigation.

Investigate faster

Immediate access to procedures, history, and approved steps.

Respond consistently

Same standards, every analyst, every region.

Recommend approved actions

Grounded in your own playbooks and policies.

Preserve institutional knowledge

Capture senior analyst expertise before it’s lost.

Accelerate analyst onboarding

New analysts follow proven workflows from day one.

Maintain governance

Permissions, provenance, and audit trails on every request.

How it works

From static runbooks to intelligent security operations.

1

Connect your security knowledge

Integrate playbooks, SOPs, policies, and threat-hunting guides.

2

Extract operational intelligence

Identify procedures, dependencies, escalation paths, and approvals buried in your content.

3

Structure and validate

Knowledge becomes structured Data Cards. Uncertain cases go to human review, never guessed.

4

Apply permissions and provenance

Every Data Card keeps its source, access rules, and context.

5

Power your security agents

Agents access trusted knowledge via MCP or REST APIs to investigate, recommend, and guide analysts.

Agent capabilities

Power security agents that understand your organization.

Interpret security alerts and telemetry

Identify the correct investigation procedures

Guide analysts through response workflows

Recommend approved remediation actions

Apply escalation and approval policies

Surface relevant compliance requirements

Connect related incidents, systems, and entities

Document investigation steps

Capture new institutional knowledge

Support continuous operational improvement

Not generic security advice. Grounded in your own procedures, controls, and risk requirements.

Use cases

Support the full security operations lifecycle.

Alert triage

Surface the right procedure and next steps for every alert.

Incident investigation

Guide analysts through organization-specific investigation workflows.

Threat hunting

Surface hunting methods, indicators, and past incidents.

Remediation

Recommend approved containment, mitigation, and recovery actions.

Analyst assistance

An intelligent copilot grounded in trusted knowledge.

Compliance and governance

Apply policy and regulatory requirements throughout response.

Post-incident review

Capture findings and improve future response.

Analyst onboarding

Teach new hires established tools and escalation paths.

Integrations

Connect trusted knowledge to the systems your team already uses.

SIEM platformsSOAR platformsCase management systemsThreat intelligence platformsSecurity data platformsInternal documentation repositoriesEnterprise knowledge basesCustom security agents

The trusted knowledge layer behind your existing workflows and agents.

Built on the platform

Propagator for the knowledge.
The Agentic Framework for the agents.

Runbooks doesn’t reinvent the stack, it packages the Joinable Platform for security response. Propagator refines your team’s knowledge; the Agentic Framework builds the agents that act on it. Always credit the foundation.

Propagator

Refines your playbooks and SOPs into permission-governed, AI-ready knowledge, governed end to end.

Explore Propagator

Agentic Framework

Build and own the security agents that reason from that knowledge, controllable, not black boxes.

Explore the framework

Ready to turn your playbooks into trusted knowledge?