Better AI starts with a clearer map
Why Setu's resolved entity graph can help turn growing AI capability into better enterprise decisions.
Better AI starts with a clearer map
There is a practical reason to be optimistic about AI in enterprise security. More capable models give defenders new ways to investigate, understand and explain what is happening. Connecting those capabilities to a trustworthy view of the enterprise can make them useful in the decisions teams face every day.
That is the opportunity we are building toward with Setu.
The recent Interconnects essay, The Cyber Risk Discourse is Broken, argues that debates about model access should account for the benefits to defenders alongside the risks of misuse. It also highlights environments where running models on private infrastructure matters. We take a practical lesson from that discussion: better AI should become easier for enterprises to put to work on their own evidence. This is our interpretation; the publication is not affiliated with Samyoga and does not endorse Setu.
Consider a familiar investigation. An endpoint tool reports a suspicious process. An identity system records a login. A network device sees a connection. An asset register names an owner. Each source contributes something useful, but each may use a different identifier for the same device or person.
Before a team can decide what matters, someone has to establish which records belong together.
Setu's resolved entity graph brings identities, assets and activity into a connected view. Resolution means reconciling records that refer to the same real entity. Relationships then help a team examine how that entity connects to the rest of its environment.
This gives an investigation a firmer starting point. A hostname becomes part of an asset's history. An account becomes connected to observed activity. Available ownership and business context help explain why a finding deserves attention. The value grows as supported sources provide better coverage and teams validate the relationships that matter.
Imagine two similar findings on two different machines. One has a known access path toward a sensitive application. The other has no such path in the available evidence. A connected view helps the analyst investigate that difference and explain the resulting priority. Missing evidence still requires care: an unobserved path cannot be treated as proof of safety.
AI can help summarize the findings, organize the evidence and make the explanation easier to follow. The graph supplies context specific to the customer's organization. Together, they can help teams spend more of their attention on the decision itself.
This is why improving models are an opportunity for Setu. Each improvement in reasoning can be evaluated against the same enterprise context. The useful question is whether a model helps a team reach a better-supported conclusion, with fewer mistakes and less reconstruction work.
Setu already combines graph analysis with incident clustering, evidence-linked briefings and playbook recommendations. Its architecture supports multiple model providers, including local models. That creates a practical route for customers to evaluate AI assistance within their deployment constraints. Model quality, hardware requirements and enabled integrations still determine what works in each environment.
The same context also creates room to grow. A reconciled asset view could help IT operations investigate conflicting inventories. Validated service dependencies could support continuity planning. Connecting agent identities, credentials and tools could help teams understand the access available to automated systems. These are extensions to develop and validate with customers, each building on the work of understanding the enterprise.
As agents take on more tasks, that understanding becomes especially useful. An organization should be able to establish which resource an agent means, what evidence supports its proposal, and who can authorize the next step. Setu's current contribution is to help teams read and reason about their environment. Broader agent authorization and verified execution are directions to prove through bounded workflows.
Our optimism rests on a measurable customer outcome: a team can understand its own environment more clearly and make a better-supported decision. We want to measure that through investigation time, resolution accuracy, evidence quality and the results customers can verify.
Better AI gives us more ways to reason. A clearer map gives that reasoning somewhere useful to begin.
Explore the Setu thesis or start a conversation with Samyoga.
Samyoga
Setu Security Research