Solutions / Centeye Praxis™

Centeye Praxis™ — agentic security orchestration, governed.

Praxis is the orchestration layer under every Centeye solution: two bounded security agents — Kavach™, the analyst on shift, and Argus™, the advisor on record — working one governed loop across every tenant. Agentic where it earns speed. Accountable everywhere.

  • Every action policy-scoped, attributable, and reversible wherever the platform allows
  • Engagement modes per action, per tenant — Watch · Advise · Approve · Pre-authorized
  • Tamper-evident audit log on every step: who, what, why
The loop

One governed loop, from first signal to verified outcome.

Praxis runs six stages on every incident. No stage is skippable, no action is unlogged, and the loop doesn’t close until the fix is verified against real system state.

  1. Detect

    Signals from endpoint, identity, email, DNS, and AI-usage telemetry land in one correlation engine, keyed to the same user, host, and tenant.

  2. Triage

    Kavach™ scores and correlates — deterministic checks first, learning models next, deep reasoning only where a case is genuinely ambiguous. Cost-governed by design.

  3. Propose

    The agent stages a specific play — isolate, revoke sessions, quarantine, remove the rule — with the evidence chain attached to every proposed action.

  4. Approve / Auto

    Your engagement mode decides: pre-authorized plays execute at machine speed; everything else routes to the role you designate — your analyst, or the client’s IT lead.

  5. Execute

    Actions run against the provider or the host — reversible where the platform allows, never outside policy, never silently.

  6. Verify

    Praxis re-reads the actual system state — the identity provider, the machine — to confirm the door is shut. “Done” means verified, not assumed.

The agents

Two agents. Distinct jobs. Explicit bounds.

Praxis agents are built like staff, not chatbots: a defined role, a defined scope, and a defined line they do not cross.

Kavach™

The analyst on shift

Kavach carries the tier-1 and tier-2 load across every tenant: it triages every alert, correlates email, identity, and endpoint signals into one incident, proposes the fix with evidence, executes within the policy you set, and verifies the result against live system state. Conversational at tenant and fleet scope — ask it why, and it shows the chain.

What it does not do: make judgment calls, act outside its engagement mode, or touch anything destructive without a designated human’s approval.

Argus™

The advisor on record

Argus turns what Kavach did into the record your business runs on: plain-English incident narratives, per-client digests, QBR-ready reporting, and the cyber-insurance readiness story — kept current continuously, delivered in-app or over email, Slack, Teams, and SMS. Ask “was that safe?” and it answers with the evidence.

What it does not do: take response actions. Argus explains, documents, and advises — the acting agent is Kavach, and the authority is your policy.

The control surface

Engagement modes are the contract.

Every action class carries its own mode, set per tenant. This is how a cautious client, a pre-authorized client, and a client with its own SOC all run on the same platform.

Level 0 — Watch

Detection and full incident narrative only. Complete visibility, no action taken.

Level 1 — Advise

Centeye proposes the exact remediation with evidence. Your team — or the client’s — executes.

Level 2 — Approve

Centeye stages the action with the evidence attached; it executes on a one-tap approval from the role you designate.

Level 3 — Pre-authorized

Containment pre-authorized per threat class — executed in minutes, verified against live state, and reported.

Straight answers

What buyers ask about agentic orchestration.

What is agentic security orchestration?

Software agents that carry a security workflow end to end — triage, correlation, staged response, verification — rather than emitting alerts for humans to chase. The difference between agentic orchestration and automation scripts is judgment scope: Praxis agents decide within an explicit policy envelope and hand everything else to a designated human.

Is this the same thing as an "autonomous SOC"?

No — deliberately. Praxis is bounded autonomy: every action is policy-scoped, attributable, reversible where the platform allows, and written to a tamper-evident audit log. The judgment calls stay with your team; the agents carry the load.

Do Kavach and Argus act on their own?

Only as far as the engagement mode you set — per action class, per tenant. Watch and Advise never act. Approve stages the action and waits for the role you designate. Pre-authorized executes only the threat classes you explicitly granted, then reports with evidence.

Does Praxis require all four Centeye solutions?

No. Praxis orchestrates whatever you run — Ironwatch™ (EDR & XDR), Gatewatch™ (ITDR), Lighthouse™ (email security), Lumen™ (shadow AI) — but correlation compounds: every added surface gives the agents more of the attack chain to read, so one incident per attack gets sharper as coverage grows.

How is the AI cost governed?

The reasoning cascade is layered by design: deterministic checks first, learning models next, deep reasoning only where a case is genuinely ambiguous. The economics are part of the architecture — no metering surprises passed to you or your clients.

Watch the loop run on a real incident.

A guided demo of Praxis working an attack end to end — triage, staged response, one-tap approval, verified outcome — with the audit trail on screen.