Full Report
Discover how Tenable Hexa AI closes the gap between exposure management and endpoint patching using intent-driven routines, smart guardrails, and human approval.Key takeawaysThe problem: A slow handoff between security workflows creates a days-long remediation gap. The solution: Tenable Hexa AI bridges this gap using intent-driven Routines that automate scoping, deployment, and verification across integrated platforms like Jamf. Safety and control: Autonomy is governed by the harness built into Tenable One, ensuring the AI operates strictly within defined user permissions and guardrails.Find the exposure. Fix it. Confirm it is gone.Those three steps are rarely executed in a single place, by a single team. Exposure management knows which assets are at risk, while endpoint management actually changes the machine and applies the fix. Between those two domains of exposure identification and remediation lies a slow, manual handoff and multi-step routine that costs security teams days or weeks while vulnerabilities remain exposed: Scope the asset group Aim the remediation policy Execute patch deployment Check status Re-scan the environment to confirm the finding was closed.Tenable Hexa AI, the agentic engine of the Tenable One Exposure Management Platform, now spans that handoff, so you don’t have to manually toggle among tools or continually restart the conversation.How does Tenable Hexa AI autonomously close the remediation loopSay there’s an actively exploited Chrome vulnerability, and a fleet of your Macs is still running the vulnerable version. Rather than navigating multiple tools, you simply tell Tenable Hexa AI to patch it. Tenable Hexa AI executes the workflow in three unified stages: Enumeration and mapping - Tenable Hexa AI enumerates the affected assets across your exposure sources and resolves them to the devices your endpoint team already manages in Jamf. Policy identification - Tenable Hexa AI maps the CVE to the version that fixes it, then finds the Jamf patch definition that delivers that version. Proposal presentation - Before writing any changes, Tenable Hexa AI stops and shows you a proposal detailing the number of devices, which devices, what policy, and what the deployment window looks like. It highlights the blast radius and it tells you plainly that the action does not roll itself back.If you need to narrow enumeration to one business unit, just tell Hexa and it will re-scope and return a new plan before executing any changes.Once you approve, Tenable Hexa AI creates a static group in Jamf holding exactly the devices you approved, then triggers the policy against it. Ask Hexa for status at any point, and it returns the rollout device by device, without you leaving the chat window. Tenable Hexa AI then schedules a re-scan for after the patch deployment window.What previously took days across multiple tools now takes minutes within a single conversation, and all you need to do is make one decision rather than coordinate the manual execution of multiple, complex steps.Hand off recurring security work to intent-driven routinesThe ultimate goal of agentic AI for security is to help security teams efficiently and effectively scale cyber defense by taking on complex manual routines. To carry out vulnerability remediation and validation routines with Tenable Hexa AI, you define three core elements in plain, natural language: An objective - State what you are trying to achieve, in the words you would use with a colleague, not a sequence of steps (e.g., “Triage and patch critical vulnerabilities across MacOS endpoints”). Guardrails - Set explicit operational limits (e.g., “Never launch a credentialed scan against anything tagged OT,” or “Open no more than twenty-five tickets in a run”).A cadence - Choose whether to run the routine on demand or tell Hexa to run it on a specific schedule.Tenable Hexa AI drafts the plan using capabilities discovered from the tools you have already connected to Tenable One. If the objective is ambiguous, Tenable Hexa AI asks for clarification instead of guessing, and if the objective and the guardrails are at odds, it tells you rather than quietly dropping one.Because routines in Tenable Hexa AI are intent-driven and not step- or script-driven, they adapt seamlessly to real-world infrastructure changes, such as new asset classes, renamed tags, or failed scans that require a restart. Scripts break when conditions change; intent survives contact with reality.Controlling AI autonomy in Tenable Hexa AITrust is not something you hand off blindly to an agentic security product. You extend it one job at a time, and it grows through demonstrated reliability.Routines allow security teams to scale autonomy at their own pace through the following attributes: Defined scope - The routine’s objective sets what Tenable Hexa AI owns, while guardrails enforce strict boundaries. Write a narrow routine and Hexa works narrowly; widen it and Hexa widens with you. Isolated decisions - Guardrails are scoped per routine so you never have to make an all-or-nothing decision for the entire platform.Human-in-the-loop gates - You retain total control to approve, narrow, widen, or cancel proposals as many times as you want, before any action is written to your production environment.So the pace is yours. Start by handing off a routine weekly report, then move to automated overnight triage once you have watched the report run successfully a few times. Expand autonomy one routine at a time as you build confidence in the agentic engine. Tenable Hexa AI moves as fast as you let it.Agent Center, the home page for agentic activity in Tenable OneAutonomy you cannot see is not autonomy you can inherently trust. Agent Center serves as the primary dashboard for agentic activity within Tenable One. It answers four critical operational questions the moment you log in: What needs my attention? What is currently running?What did Hexa already handle?What routines are scheduled?Agent Center transforms your daily security routine. While you were offline, Tenable Hexa AI ran overnight sweeps, triaged findings, and prepared scoped proposals. Instead of starting your day with work, you begin with an auditable, and evidence-backed decision — with a ledger behind it recording what happened, who approved it, and when. The Agent Center dashboard in Tenable One The agentic AI harness under every routineNone of what makes the routines safe is a property of the model. It comes from the harness Tenable One puts around any model or agent working in a customer environment. The harness starts from a blunt assumption: models and agents are untrusted participants. Permissions, context boundaries, approval gates, validation, and auditability all sit outside the model, and a routine never reaches past the permissions of the person who created it.You can see this today in Tenable Hexa AI. The objective resolves against Tenable’s Exposure Data Fabric — your real environment, priorities, and prior context — not the internet. Tenable Hexa AI picks capabilities so you never wire steps; the approval gate defines what runs; and a separate check validates every state change before it leaves the queue. The audit log makes it verifiable after the fact, and failures, fallbacks, model changes, and latency are the harness’s problem rather than your own.This is why a proposal to write into your endpoint management tool is something you can reasonably approve at 8 AM. Access to a frontier model is not what makes agentic security work; everything around the model does. The Exposure Data Fabric makes the answers relevant to your environment, and the harness makes the actions taken against it trustworthy.The model reasons. Tenable Hexa AI coordinates. Agents do the specialized work. The harness holds the boundary.How to get started with Tenable Hexa AITo begin automating exposure management with Tenable Hexa AI, follow these three simple steps: Identify a repetitive task - Pick the job you are tired of starting. Define your objective and guardrails - Write down what you want Tenable Hexa AI to do and set the limits you would want if you were handing the routine to a new analyst. Set the cadence - Observe the first few runs of the routine to make sure it’s executing properly. When you’re ready, put the routine on a schedule.Delegating your first routine does more than save you a couple of hours. It gives you back nights and weekends while closing exposures in minutes. Frequently asked questions (FAQs)What is Tenable Hexa AI?Tenable Hexa AI is an agentic security automation capability within Tenable One that automates vulnerability triage, asset scoping, endpoint patch deployment, and post-remediation verification across integrated tools like Jamf.What are routines in Tenable Hexa AI?Routines are intent-driven automations defined in natural language. They consist of an objective (what to accomplish), guardrails (operational constraints), and a schedule. Unlike traditional scripts, routines adapt dynamically to changes in your infrastructure.How does Tenable Hexa AI prevent unauthorized changes to endpoints?Tenable Hexa AI enforces human-in-the-loop approval gates before any changes are committed to endpoint tools. Furthermore, the Tenable One harness guarantees that a routine can never exceed the strict access permissions of the security professional who created it.What is the Tenable One Exposure Data Fabric?The Exposure Data Fabric is the underlying data architecture in Tenable One that provides real-time asset context, priorities, and environment data to Hexa AI. This ensures AI reasoning is anchored in actual enterprise context rather than external data.Learn moreMeet Tenable Hexa AI: Agentic AI for exposure managementImplement agentic AI in cybersecurity with Tenable Hexa AIBeating the Mythos clock: Automate patching with Tenable Hexa AI
Analysis Summary
# Industry News: Tenable Launches Hexa AI to Close the Remediation Gap
## Summary
Tenable has announced the launch of Hexa AI, an agentic AI engine integrated into the Tenable One Exposure Management Platform designed to automate the handoff between vulnerability identification and endpoint patching. By bridging the gap between security and IT operations through natural-language "routines," the tool aims to reduce the time-to-remediate from days to minutes.
## Key Details
- **Date:** February 2025 (Recent Industry Announcement)
- **Companies Involved:** Tenable, Jamf (Initial Integration Partner)
- **Category:** Product Launch | AI Automation
## The Story
The traditional "find-to-fix" pipeline in cybersecurity is notoriously fragmented. Security teams identify vulnerabilities, but IT operations teams (using different tools) are responsible for patching. This results in a manual, multi-step handoff involving asset scoping, policy identification, and deployment verification that often leaves systems exposed for days.
Tenable Hexa AI introduces "Agentic AI" to solve this. Unlike traditional chatbots, Hexa AI is an execution engine that uses natural language "intent" to perform tasks. For example, an analyst can instruct Hexa to "patch critical Chrome vulnerabilities on all Macs." Hexa then maps the CVE to the correct patch, identifies the affected assets within management tools like Jamf, and presents a remediation proposal. Once a human approves the proposal, Hexa executes the patch and schedules a re-scan to verify the fix—all within a single workflow.
## Business Impact
### For the Companies Involved
- **Tenable:** Solidifies its transition from a vulnerability scanner to a comprehensive "Exposure Management" platform that influences the remediation stage, increasing its stickiness in the enterprise stack.
- **Jamf:** Benefits from deeper integration into the security lifecycle, making it an essential component of automated risk reduction for Mac-heavy environments.
### For Competitors
- **Vulnerability Management (VM) Rivals:** Puts pressure on competitors like Qualys and Rapid7 to move beyond "prioritization" and into "automated execution" using similar agentic AI frameworks.
- **SOAR Vendors:** Directly challenges traditional Security Orchestration, Automation, and Response (SOAR) platforms by offering built-in, low-code automation that doesn't require complex playbook scripting.
### For Customers
- **Operational Efficiency:** Drastically reduces the "Mean Time to Remediate" (MTTR).
- **Labor Savings:** Frees up high-cost security analysts and IT admins from repetitive, manual coordination tasks.
### For the Market
- **The "Agentic" Shift:** Signals a broader trend where AI in security is moving from "Assistance" (summarizing data) to "Agency" (performing actions).
## Technical Implications
Hexa AI utilizes the **Tenable One Exposure Data Fabric** to ground its reasoning in the customer’s actual environment rather than generic internet data. A key innovation is the "Harness," a security layer that keeps the AI model outside of the trust boundary. The AI cannot exceed the permissions of the user who created the routine, and every state change requires an "approval gate," mitigating the risk of AI-driven system crashes or unauthorized changes.
## Strategic Analysis
- **Market Positioning:** Tenable is positioning itself as the "orchestrator" of remediation, moving horizontally across the security and IT silo.
- **Competitive Advantage:** The use of "intent-driven" routines over "script-driven" automation. Scripts are fragile and break when tags or asset names change; Hexa’s intent-based model adapts to environment changes dynamically.
- **Challenges:** The primary obstacle is the "Trust Gap." Organizations are historically hesitant to let any automated tool—let alone an AI—make changes to production endpoints.
## Industry Reactions
- **Analyst Opinions:** Analysts view this as a necessary evolution of Vulnerability Management. The move toward "human-in-the-loop" autonomy is seen as the correct middle ground for enterprise risk management.
- **Market Response:** There is high interest in "Agentic AI" as organizations struggle with the global cybersecurity talent shortage.
## Future Outlook
- **Broader Integrations:** Expect Tenable to announce similar integrations with Microsoft Intune, Ivanti, and HCL BigFix to cover Windows and Linux ecosystems.
- **Autonomous Triage:** Predictions suggest that within 18–24 months, routine low-risk patching may move from "Human-in-the-loop" to "Human-on-the-loop" (fully autonomous with audit oversight).
## For Security Professionals
Practitioners should view Hexa AI as a force multiplier for the Security Operations Center (SOC). It removes the administrative burden of "chasing patches" across departments. However, professionals must focus on defining clear **guardrails** (e.g., "do not patch OT systems during business hours") to ensure the agentic engine operates safely within the organization's risk tolerance.