Joinable Security · Runbooks
Turn your playbooks into trusted knowledge your security agents can act on.
Built on Propagator, Joinable Runbooks refines your security team’s playbooks, SOPs, and IR procedures into permission-governed knowledge, then gives you the tools to build, own, and run the security agents that reason from those approved procedures, not the open internet.
The 2-minute explainer
See how a SOC’s playbooks become governed, agent-ready knowledge, and the agents that act on it.
Key benefits
Put your security expertise to work in every investigation.
Investigate faster
Immediate access to procedures, history, and approved steps.
Respond consistently
Same standards, every analyst, every region.
Recommend approved actions
Grounded in your own playbooks and policies.
Preserve institutional knowledge
Capture senior analyst expertise before it’s lost.
Accelerate analyst onboarding
New analysts follow proven workflows from day one.
Maintain governance
Permissions, provenance, and audit trails on every request.
How it works
From static runbooks to intelligent security operations.
Connect your security knowledge
Integrate playbooks, SOPs, policies, and threat-hunting guides.
Extract operational intelligence
Identify procedures, dependencies, escalation paths, and approvals buried in your content.
Structure and validate
Knowledge becomes structured Data Cards. Uncertain cases go to human review, never guessed.
Apply permissions and provenance
Every Data Card keeps its source, access rules, and context.
Power your security agents
Agents access trusted knowledge via MCP or REST APIs to investigate, recommend, and guide analysts.
Agent capabilities
Power security agents that understand your organization.
Interpret security alerts and telemetry
Identify the correct investigation procedures
Guide analysts through response workflows
Recommend approved remediation actions
Apply escalation and approval policies
Surface relevant compliance requirements
Connect related incidents, systems, and entities
Document investigation steps
Capture new institutional knowledge
Support continuous operational improvement
Not generic security advice. Grounded in your own procedures, controls, and risk requirements.
Use cases
Support the full security operations lifecycle.
Alert triage
Surface the right procedure and next steps for every alert.
Incident investigation
Guide analysts through organization-specific investigation workflows.
Threat hunting
Surface hunting methods, indicators, and past incidents.
Remediation
Recommend approved containment, mitigation, and recovery actions.
Analyst assistance
An intelligent copilot grounded in trusted knowledge.
Compliance and governance
Apply policy and regulatory requirements throughout response.
Post-incident review
Capture findings and improve future response.
Analyst onboarding
Teach new hires established tools and escalation paths.
Integrations
Connect trusted knowledge to the systems your team already uses.
The trusted knowledge layer behind your existing workflows and agents.
Built on the platform
Propagator for the knowledge.
The Agentic Framework for the agents.
Runbooks doesn’t reinvent the stack, it packages the Joinable Platform for security response. Propagator refines your team’s knowledge; the Agentic Framework builds the agents that act on it. Always credit the foundation.
Propagator
Refines your playbooks and SOPs into permission-governed, AI-ready knowledge, governed end to end.
Agentic Framework
Build and own the security agents that reason from that knowledge, controllable, not black boxes.