SOLUTIONS
Security Operations
Investigate security issues and execute remediation without losing human control.
Changefy connects security findings to the systems that need to change, turning investigations into controlled, verifiable remediation.
Security investigation
- Investigate suspicious infrastructure activity
- Analyze security alerts
- Correlate events across systems
- Investigate unusual authentication behavior
- Identify affected users, workloads, and resources
- Determine likely attack paths
- Identify recent configuration changes
- Collect supporting evidence
- Determine potential blast radius
- Recommend containment and remediation
SIEM operations
- Investigate missing security logs
- Troubleshoot Microsoft Sentinel connectors
- Diagnose ingestion failures
- Repair logging pipelines
- Validate data connector health
- Investigate delayed logs
- Troubleshoot Syslog and CEF ingestion
- Validate analytics rule dependencies
- Investigate telemetry gaps
- Confirm ingestion after remediation
IAM remediation
- Investigate excessive permissions
- Remove inappropriate access
- Restore missing permissions
- Disable compromised credentials
- Rotate service credentials
- Update cloud IAM policies
- Investigate privileged accounts
- Validate least-privilege configurations
- Troubleshoot conditional access
- Verify access after security changes
Cloud security
- Investigate insecure configurations
- Correct security group rules
- Modify firewall policies
- Restrict exposed services
- Remove public access
- Remediate configuration drift
- Apply approved hardening changes
- Investigate security posture findings
- Validate remediation against policy
Vulnerability remediation
- Investigate vulnerable infrastructure
- Identify affected systems
- Determine remediation options
- Plan patching
- Apply approved configuration fixes
- Coordinate infrastructure changes
- Verify vulnerabilities are remediated
- Capture evidence of remediation
Incident containment
- Isolate compromised workloads
- Disable credentials
- Restrict network access
- Modify firewall rules
- Stop affected services
- Rotate secrets
- Contain compromised resources
- Restore safe configurations
- Validate containment measures
Security policy enforcement
- Detect changes that violate security policy
- Prevent prohibited infrastructure changes
- Require additional approval for high-risk work
- Validate production changes against security controls
- Identify destructive or dangerous actions
- Enforce environment-specific guardrails
- Stop execution if a plan deviates from approved scope
Audit and evidence
- Record investigation findings
- Record AI-generated recommendations
- Capture human approvals
- Log executed actions
- Capture API responses and execution results
- Record verification outcomes
- Link changes to affected resources
- Export evidence for audit and compliance
EXAMPLE REQUESTS
- “Why did Sentinel stop receiving firewall logs?”
- “Investigate this critical cloud security alert and propose remediation.”
- “Remove public access from the affected storage accounts after approval.”
- “Rotate every service account credential expiring this month, environment by environment, before any of them lapse.”
ONE OPERATING MODEL ACROSS EVERY SOLUTION
Every solution runs on the same governed loop.
- InvestigateChangefy connects to the systems involved and gathers the information required to understand the request or incident.
- DiagnoseIt correlates infrastructure state, telemetry, configuration, and recent changes to determine the likely root cause.
- PlanChangefy produces a clear execution plan: actions, affected resources, risk, blast radius, dependencies, rollback, maintenance requirements, and verification checks.
- ReviewHumans remain in control. Teams can approve, request changes, reject, require peer review, restrict execution scope, or enforce organizational policy.
- ExecuteOnce authorized, Changefy performs the approved actions using connected systems and controlled execution runners.
- VerifyChangefy checks whether the requested outcome actually occurred. It does not assume success because an API returned 200.
- AuditEvery investigation, plan, approval, action, and verification result is retained as evidence.
AI proposes. Humans authorize.
Changefy executes. The system proves the result.
