I Didn’t Jump on the Bandwagon. I Built It.
Oct 2, 2026 · @Craig Brown
Reflex was ready for the AI agent problem before the problem had a name.
I have watched the same pattern since the beginning of the software industry. A topic suddenly becomes important, and dozens of companies rush to build a solution. Today that topic is AI agents: programs that act on their own, with real access to real systems, and that sometimes do things they shouldn’t.
Most of the companies now racing to control agents are starting from scratch. Reflex is not. Everything needed to keep people in charge of agents is already in the product, and has been for years.
A rogue agent is an incident, not an AI problem
CISOware, the company behind Reflex, is not an AI company. Its people are established experts in information security and incident response. That difference matters more than any feature.
The companies now working on agent control mostly approach it as AI companies. They ask how to make the model behave. But when an agent goes rogue, the first question is not about the model. It is the question every incident responder asks: what is happening, who needs to know, and what do we do now?
That is an incident response problem, and our field has been working on it for decades. How a team responds, starting with how its members communicate with each other under pressure, has been refined through years of real incidents. That knowledge cannot be researched in a few months. I know it because I have lived it for all those decades, and it is built into every part of Reflex.
Built in, not bolted on
This is not a pivot, and it is not new functionality retrofitted into an old product. Reflex was designed from the start to work with participants that are not people.
I built artificial participants into Reflex years ago. I call them NPCs, for non-player characters, as in video games. They were designed to be treated exactly like people on a response team. In early versions, NPCs took part in hypothetical incidents, and their job was to cause mischief so teams could practice handling it. I later removed that ability, because it introduced the risk of an NPC accidentally acting in a real incident. That decision reflects the same caution the industry is only now learning to apply to agents.
What that means today:
- Agents are steps in a plan. An Orchestrator adds an agent call to a plan in the same editor used for every other plan. On a team member’s phone, it appears as a named item with a document explaining why the agent is used and exactly what it does.
- Human in the loop is automatic. The steps before an agent call must be completed first. The agent can then run automatically, or Reflex can ask whether to activate it. If the answer is no, the plan moves on.
- People make the decision. A team can finish a plan without ever calling the agent, or consult an expert before activating a risky one.
- The work after the agent is planned too. When an agent closes a firewall port, someone must decide whether it stays closed. Reflex keeps that follow-up on the plan.
Fifteen years of real use
Reflex has been in development and use for close to 15 years. Over that time, it has gone through iteration after iteration as people actually used it and reported what worked and what did not.
Its learning approach goes back further still. About 30 years ago, I released one of the first commercial products to call itself AI. It never claimed to think on its own. Today I call it YouI, for “your intelligence”: it learns how the person who configures it would want decisions made, and people take every important step. That principle is exactly what the agent era needs, and Reflex has been practicing it for three decades.
Why no one else built it, and what comes next
Reflex is the kind of product venture capital does not fund. It required too many new inventions, and no amount of money could make the timeline predictable. No investor would pay a staff for years to build a product that had not yet proven it had users. So it was built the only way it could be: patiently, by someone with the experience to know what it needed.
The same qualities that kept investors away are what make Reflex hard to replicate now. A competitor can hire engineers. It cannot hire decades of incident response experience or 15 years of iteration with real users.
Reflex has now outgrown the way it was built. Its potential calls for an organization with the reach and resources to deploy it at scale: a large technology company, or a government entering the field of AI. I have an MBA and have run software companies, and I know what that next stage requires. Reflex is ready for it.
The right place at the right time
I am not chasing a trend. The world has arrived at a problem I have been working on for most of my career:
- The expertise comes from decades of incident response, not from a new AI venture.
- The design treated non-human participants as team members from the beginning.
- The safeguards that keep people in charge of agents are already in the product.
- The proof is 15 years of iteration with people actually using it.
Dozens of companies are now trying to figure out how to control agents. Reflex already does. I didn’t jump on the bandwagon. I built it.
