Skip to content
Changefy Research — State of Governed AI Operations 2026Read it
Changefy

SOLUTIONS

Security Operations

Investigate security issues and execute remediation without losing human control.

Changefy connects security findings to the systems that need to change, turning investigations into controlled, verifiable remediation.

Security investigation

  • Investigate suspicious infrastructure activity
  • Analyze security alerts
  • Correlate events across systems
  • Investigate unusual authentication behavior
  • Identify affected users, workloads, and resources
  • Determine likely attack paths
  • Identify recent configuration changes
  • Collect supporting evidence
  • Determine potential blast radius
  • Recommend containment and remediation

SIEM operations

  • Investigate missing security logs
  • Troubleshoot Microsoft Sentinel connectors
  • Diagnose ingestion failures
  • Repair logging pipelines
  • Validate data connector health
  • Investigate delayed logs
  • Troubleshoot Syslog and CEF ingestion
  • Validate analytics rule dependencies
  • Investigate telemetry gaps
  • Confirm ingestion after remediation

IAM remediation

  • Investigate excessive permissions
  • Remove inappropriate access
  • Restore missing permissions
  • Disable compromised credentials
  • Rotate service credentials
  • Update cloud IAM policies
  • Investigate privileged accounts
  • Validate least-privilege configurations
  • Troubleshoot conditional access
  • Verify access after security changes

Cloud security

  • Investigate insecure configurations
  • Correct security group rules
  • Modify firewall policies
  • Restrict exposed services
  • Remove public access
  • Remediate configuration drift
  • Apply approved hardening changes
  • Investigate security posture findings
  • Validate remediation against policy

Vulnerability remediation

  • Investigate vulnerable infrastructure
  • Identify affected systems
  • Determine remediation options
  • Plan patching
  • Apply approved configuration fixes
  • Coordinate infrastructure changes
  • Verify vulnerabilities are remediated
  • Capture evidence of remediation

Incident containment

  • Isolate compromised workloads
  • Disable credentials
  • Restrict network access
  • Modify firewall rules
  • Stop affected services
  • Rotate secrets
  • Contain compromised resources
  • Restore safe configurations
  • Validate containment measures

Security policy enforcement

  • Detect changes that violate security policy
  • Prevent prohibited infrastructure changes
  • Require additional approval for high-risk work
  • Validate production changes against security controls
  • Identify destructive or dangerous actions
  • Enforce environment-specific guardrails
  • Stop execution if a plan deviates from approved scope

Audit and evidence

  • Record investigation findings
  • Record AI-generated recommendations
  • Capture human approvals
  • Log executed actions
  • Capture API responses and execution results
  • Record verification outcomes
  • Link changes to affected resources
  • Export evidence for audit and compliance

EXAMPLE REQUESTS

  • Why did Sentinel stop receiving firewall logs?
  • Investigate this critical cloud security alert and propose remediation.
  • Remove public access from the affected storage accounts after approval.
  • Rotate every service account credential expiring this month, environment by environment, before any of them lapse.

ONE OPERATING MODEL ACROSS EVERY SOLUTION

Every solution runs on the same governed loop.

  1. InvestigateChangefy connects to the systems involved and gathers the information required to understand the request or incident.
  2. DiagnoseIt correlates infrastructure state, telemetry, configuration, and recent changes to determine the likely root cause.
  3. PlanChangefy produces a clear execution plan: actions, affected resources, risk, blast radius, dependencies, rollback, maintenance requirements, and verification checks.
  4. ReviewHumans remain in control. Teams can approve, request changes, reject, require peer review, restrict execution scope, or enforce organizational policy.
  5. ExecuteOnce authorized, Changefy performs the approved actions using connected systems and controlled execution runners.
  6. VerifyChangefy checks whether the requested outcome actually occurred. It does not assume success because an API returned 200.
  7. AuditEvery investigation, plan, approval, action, and verification result is retained as evidence.

AI proposes. Humans authorize.
Changefy executes. The system proves the result.