Where we're headed
A transparent look at what we've shipped, what we're building, and where we're going next.
Q2 2026
April – June 2026Graph-based attack path detection
Correlation Agent upgraded with a graph neural network model to detect lateral movement paths with 40% improved accuracy.
Microsoft Copilot for Security integration
urgentic investigation reports surfaced directly inside Microsoft Copilot for Security for a unified analyst experience.
Phishing URL detonation sandbox
Automated sandbox detonation of suspicious URLs embedded in phishing investigation workflows.
Learning Agent analyst feedback UI
Structured feedback interface inside investigation reports feeding the Learning Agent in real-time.
Q3 2026
July – September 2026Multi-tenant SOC workspace isolation
Full data and configuration isolation between tenants for MSSP deployments without any performance trade-off.
Splunk SIEM connector
Native bidirectional integration with Splunk Enterprise Security — alert ingestion and automated response write-back.
Custom agent playbook editor
A no-code editor that lets SOC teams define custom investigation steps per alert type without writing any code.
Insider threat behavioural baseline
Entity behavioural analytics model that builds per-user baselines and flags statistical anomalies automatically.
Q4 2026
October – December 2026ServiceNow ITSM ticket auto-creation
Verified high-severity incidents automatically open and populate ServiceNow tickets with full investigation context.
Evidence chain-of-custody logging
Immutable, timestamped evidence trail for every investigation action — exportable for regulatory and legal review.
Real-time threat actor attribution
Live threat intelligence feeds enriching attacker profiles with known campaigns, TTPs, and nation-state attribution signals.
Mobile analyst companion app
iOS and Android app for on-call analysts — push alerts, approve containment actions, and view live investigation summaries.
2027 & Beyond
Exploring and validatingAutonomous red team simulation
AI agents that continuously probe your environment for exploitable paths and feed findings back into the detection pipeline.
Voice-driven investigation queries
Natural language voice interface for hands-free investigation status queries and analyst briefings.
Cross-organisation threat sharing
Opt-in anonymised threat intelligence sharing network across the urgentic customer base.
Automated regulatory reporting
One-click generation of NIS2, DORA, and GDPR-compliant incident reports from investigation data.
Shape the roadmap
Have a feature request or a use case we haven't covered? We read every submission and prioritise based on real customer needs.
Submit feedbackReady to transform your security operations?
See how urgentic's autonomous AI analysts can cut investigation time by 90% and reduce alert fatigue.