sequenced.ai
Articles/Agents & support/Blueprint//7 min read

SentinelOne connects Purple AI investigations to security response

SentinelOne brings Purple AI, security data and response workflows together, with package entitlements and investigation credits to check.

By Sequenced deskAI-assisted, source-led · how we work
Visit SentinelOne website ↗
Purple AIAI analystInvestigates and explains security evidence
SingularityPlatformEndpoint, identity and cloud context
HyperautomationResponseNo-code workflows with approval gates
Singularity CreditsAI consumptionAgentic investigation uses credits
SentinelOne mark
SentinelOnesentinelone.com · independent research

Represent this company? Verify your work email to access its workspace, or send the desk a factual correction.

SentinelOne brings Purple AI, security data and response workflows together, with package entitlements and investigation credits to check.

In brief
  1. 01What it does Uses AI to investigate security signals and connect the resulting assessment to response workflows.
  2. 02Best fit SOC teams with SentinelOne telemetry or a plan to consolidate security data in Singularity.
  3. 03Commercial boundary An AI assistant in an endpoint package is distinct from a fully scoped agentic investigation and response deployment.

01 / ProductPurple AI is the investigation layer of the Singularity platform

SentinelOne offers security across endpoints, cloud workloads and identities. Purple AI is its AI analyst within Singularity, reasoning across native and integrated third-party data to investigate activity and recommend actions. This is a specific application of AI to security operations, rather than a general-purpose assistant offered separately from the systems holding the evidence.

The surrounding products matter. Singularity AI SIEM brings data ingestion, context and investigation together; Hyperautomation provides response workflows and integrations. Purple AI can produce an assessment, while workflow configuration determines what follows. That distinction gives a buyer three questions: is the necessary evidence available, is the interpretation useful, and can the approved response execute correctly?

SentinelOne describes Purple AI as reasoning over data normalised to the Open Cybersecurity Schema Framework, or OCSF. A consistent representation can make signals from different sources easier to relate, but a shared schema does not prove that every source has the same completeness. Sequenced has reviewed public documentation and product material; it has not tested the system’s detection or response performance.

02 / AudienceEvaluate it where investigation capacity limits the security team

A practical fit is an operations team whose analysts repeatedly reconstruct the same kinds of incidents. Endpoint activity, identity events and a cloud alert may belong to one sequence, yet the evidence arrives separately. Purple AI is worth assessing when the time-consuming work is connecting those observations and preparing a decision that another analyst can verify.

The case is weaker when the required logs never reach the platform, when identity mapping is inconsistent, or when the organisation has no agreed response owner. Adding a reasoning layer does not supply missing evidence or resolve responsibility. Establish the sources and the decision process before measuring whether a generated assessment sounds convincing.

For teams building their own search and investigation tooling, Elastic is a useful comparison around data and retrieval control. Organisations already invested in a broad Microsoft estate can examine Microsoft alongside their security architecture. Compare access to the relevant evidence and the cost of maintaining the workflow, rather than treating all AI assistants as interchangeable.

03 / WorkflowProposed workflow: turn correlated alerts into a reviewed case

Choose one recurring investigation, such as suspicious use of an account on a managed workstation. Build a pilot collection of analyst-reviewed cases with ordinary administration, confirmed incidents and inconclusive examples. Define an acceptable result before running the pilot: affected entities, event sequence, evidence links, unresolved gaps and a recommended next action. The workflow is proposed, not a reported deployment.

First check ingestion and normalisation. Confirm that endpoint identifiers, user identifiers and event times line up across the data sources. A name match alone may conflate a service account and a human user, or two devices with similar labels. Preserve stable identifiers and original event references so the analyst can inspect how the case was assembled.

Ask Purple AI to explain the relationship between the selected signals and identify the evidence still needed. Separate a detected event from a conclusion about malicious intent. A legitimate administrative command can appear in an attack as well as normal maintenance; the surrounding sequence and business context determine whether it warrants escalation.

SentinelOne’s Agentic Investigation announcement describes automatic investigation triggers, an auditable evidence chain and adjustable human oversight. In the pilot, retain analyst review before response. Compare the generated verdict with the reviewed case and record why they differ. A different verdict is a prompt for investigation, not automatically evidence that either the model or the original analyst was correct.

Use Hyperautomation for a narrow next step, such as preparing a ticket with the case evidence. Then add an approval gate for a response that changes the environment. The product page documents contextual enrichment and human approvals. Define the exact target and operation in that approval step, rather than authorising a vague instruction to remediate the incident.

After an approved action, verify the state of the affected system and attach the result to the case. If one part of a multi-system response fails, leave the case visibly incomplete. This helps avoid a common operational confusion: the investigation may be finished while containment is still only partially applied.

Measure analyst corrections, missing evidence, review time and repeated investigations of the same event. Track Singularity Credits alongside those outcomes. The useful economic unit is a satisfactorily completed case, including necessary follow-ups, rather than the number of AI requests. A faster first answer can still create more work if the evidence package requires extensive reconstruction.

04 / PricingPublished endpoint packages do not settle the AI consumption bill

The package page displays Complete at US$179.99 per endpoint annually and Commercial at US$229.99 per endpoint annually. It qualifies these figures for 5–100 workstations, with final pricing agreed through an authorised partner and regional availability limitations. Complete lists an AI security assistant; Enterprise separately lists an agentic AI SOC analyst and requires a quote.

OfferCommercial basisImportant boundary
Singularity CompleteUS$179.99 per endpoint/year; displayed for 5–100 workstationsAI security assistant and 14-day data retention listed; partner quote governs
Singularity CommercialUS$229.99 per endpoint/year; same displayed size basisAdds identity detection, managed threat hunting and 90-day retention
Singularity EnterpriseContact salesLists agentic AI SOC analyst plus broader services and visibility
Agentic InvestigationSingularity Credits; opt-in trial announcedTrial credits are not a permanent unlimited AI allowance

Displayed USD package prices and conditions from SentinelOne pricing; trial and credit structure from the Agentic Investigation announcement, consulted 17 September 2026.

The June 2026 announcement says new and existing customers can opt into an Agentic Investigation trial through the Singularity console, with no charge or payment method during that trial. It also describes purchasing credits afterward. The announcement does not establish a universal credit price, trial duration or production allowance for every package. Confirm those items for the proposed account.

Keep the annual endpoint subscription, data retention and AI consumption distinct in a budget. A larger retention window can matter if the investigation needs events from several weeks earlier. The public figures are a starting point for a scoped partner proposal; they should not be multiplied into a complete SOC price while omitting third-party telemetry, response workflows or operational support.

05 / DistinctionsInvestigation and execution have an explicit handoff

The product design makes a useful division visible: Purple AI reasons about the evidence and Hyperautomation performs configured response steps. That creates a place to compare an AI recommendation with organisational policy. Teams can start with preparation and enrichment before deciding which narrowly defined responses merit automatic execution.

Normalised native and third-party telemetry is another practical distinction. It offers a route to investigating a sequence across tools rather than asking a model separate questions about unrelated exports. The benefit still depends on the quality of the mapping. The pilot should demonstrate a coherent timeline from original events, including what the platform could not observe.

06 / QuestionsInspect model boundaries, retained evidence and trial terms

SentinelOne says customer data is not used to train Purple AI models and describes privacy controls on the product page. Buyers should still inspect the relevant deployment agreement and data flow, including retained investigation records and connected systems. A statement about model training does not answer how long an operational case or its source logs remain available.

Ask which actions are available to an ordinary analyst, who can enable autonomous investigation and who can change response policy. The trial announcement describes administrator-controlled, reversible activation and consumption guardrails. Demonstrate those controls in the actual console and ensure that disabling a feature does not leave scheduled or downstream actions unexplained.

Finally, distinguish the trial from the continuing entitlement. A demonstration may expose features beyond the eventual package. Record the capability, consumption and retention available during the evaluation, then compare them with the proposed order. This prevents a successful trial from being followed by a production workflow that lacks a required feature or evidence window.

07 / DecisionChoose SentinelOne against the quality of completed investigations

SentinelOne is a useful candidate for teams seeking an AI investigation layer close to their operational security data. A good pilot produces cases analysts can audit and responses they can control. Purchase decisions should follow the measured workflow and its continuing entitlement, with vendor speed and efficiency claims treated as hypotheses to test locally.

Existing Singularity

Your analysts repeat context-gathering work

Pilot Purple AI on reviewed cases and measure corrections, source completeness and credits.

Start with investigation quality
Response expansion

You want approved verdicts to trigger action

Scope Hyperautomation integrations and verify approvals, target selection and state read-back.

Test the handoff
Endpoint buying

You only need a defined protection package

Use the current package matrix and partner quote without assuming unlimited agentic features.

Separate the purchasing decisions
What should we explore next?

A business worth understanding.

Suggest your business or one you find interesting. Tell us what you want to understand about its product, positioning, design or workflows.

Suggestions are free. Selection and publication stay with the desk.

Sources
Filed under Agents & supportCompany SentinelOneNot affiliated with SentinelOneRequest a correctionRequest a refresh by email

Continue reading

All in this category