| BASTION | cybersecurity | Detect, contain and preserve evidence | cyber.respond, cyber.forensics, intel.read | active | 0.93 |
| CATALYST | autonomy | Run governed workflows and collapse sub-agent results | agent.delegate, intel.read, intel.ingest | active | 0.93 |
| DEEPTRACE | threat-intel | Correlate external threat data with internal telemetry | threat.analyze, intel.read, telemetry.read | active | 0.93 |
| IRONGATE | cybersecurity | Enforce segmentation and access policy | cyber.respond, telemetry.read | active | 0.93 |
| MERIDIAN | intelligence | Turn observations into intelligence packets | intel.read, intel.ingest, intel.analyze, intel.publish, graph.write | active | 0.93 |
| ORACLE | executive | Translate objectives into policy-constrained missions | executive.command, intel.read, telemetry.read, agent.delegate | active | 0.97 |
| PRISM | intelligence | Maintain the knowledge graph and contradiction record | intel.read, graph.write | active | 0.93 |
| PULSE | operations | Metrics, traces and anomaly surfacing | telemetry.read, intel.read | active | 0.93 |
| WATCHTOWER | threat-intel | Track actors, exposures and emerging attack surface | threat.analyze, threat.curate, intel.read | active | 0.93 |