Skip to content

AI transformation · AIOps

Attackers move at machine speed. Now operations must too.

Exploits arrive within hours of a patch, and routine tickets wait days in queues and hand-offs. Silex puts AI agents into your L1 and L2 queues. They investigate every alert and request, draft the fix, and apply it through Ansible Automation Platform. People approve and audit instead of executing each step.

Why now

The window between patch and exploit has closed.

Turning a patch into an attack once took weeks. In 2026 it takes hours, and a frontier model can write a working exploit from a patch in under an hour. Remediation still runs on a monthly cycle.

  1. 2018 to 201963 daysMandiant average
  2. 2021 to 202232 daysMandiant average
  3. 20235 daysMandiant average
  4. 2026Under 24 hoursIvanti Sentry, after public PoC
  5. 20268 hoursRails, after the patch
  6. 2026Under 1 hourAI-written exploit from a patch
Time from patch or proof of concept to first exploitation, log scale. Sources: Mandiant (2018 to 2023 averages); Dark Reading (Ivanti Sentry, June 2026); Rietta (Rails, July 2026); Anthropic (June 2026).
29%of vulnerabilities newly exploited in 2025 were attacked on or before the day they were disclosed.VulnCheck, 2026
43 daysmedian time to fully remediate a known exploited vulnerability. CISA now gives agencies 3 days for the most severe.Verizon DBIR 2026; CISA BOD 26-04
195 a daynew CVEs published in the first half of 2026, up 50 percent from a year earlier. Headcount does not grow with CVE volume.CVE data review, mid-year 2026

The L1 and L2 queue

Minutes of work, days in the queue.

Most operational tickets need an hour of work or less. They wait to be picked up, then wait again at every hand-off. For an outage, the waiting is the cost.

Requests

Access, database, build, and release requests wait days for what is typically an hour of work, and the teams behind them wait too.

Hand-offs

Every pass between L1, L2, and the teams behind them adds its own wait. Across a queue, the waiting adds up to far more than the work.

Exposure

A patch that waits in a queue leaves the exposure open. An agent that has already read the logs and staged the fix turns days of waiting into minutes.

Machine speed

From a monthly cycle to a continuous loop.

The person does not disappear. Their role changes from executing each step to approving and auditing.

Human speed · the monthly cycleMachine speed · the continuous loop

Trigger

Human speedWaits for Patch Tuesday or the quarterly scan.

Machine speed

An advisory or known-exploited listing starts a run in minutes.

Playbook authoring

Human speedEngineers write and test scripts by hand, over days.

Machine speed

The agent drafts, lints, and canary-tests the playbook in the same run.

Baseline

Human speedRarely taken. Drift is found by the outage.

Machine speed

Every host is recorded before each change: packages, services, trust stores, SELinux settings.

Approval

Human speedA change board that meets weekly.

Machine speed

Pre-approved paths. A person approves each action in the ticket, with a full audit trail.

Verification

Human speedRescan next cycle. A failed fix waits a month.

Machine speed

Rescan in the same run. A failed fix is rolled back or reopened at once.

Exposure window

Human speedWeeks, from advisory to fix.

Machine speed

Hours, matching the attacker's clock.

Where agents help first

Start where the queue is deepest.

Each workflow starts read-only and earns more autonomy as it proves itself.

L1 and L2

Alert and incident triage

The agent correlates monitoring, logs, and the CMDB and posts a first diagnosis before an engineer looks. It is read-only, so it is the lowest-risk place to start.

Remediation

Alert remediation and lifecycle

Disk, service, and configuration fixes, patching, and decommission run through approved job templates after one-step approval, with a dependency check first.

Patching

Patch and vulnerability campaigns

An advisory starts a run: the agent plans the change and its window, drafts and tests the playbook, records a baseline, and verifies the fix in the same run.

Requests

Requests and provisioning

Access, database, and build requests map to a catalog of standard builds. The agent generates the automation and an engineer approves the merge.

Knowledge

Runbooks and documentation

The agent maps tickets to documentation, flags stale pages, and grows a runbook library from ticket history.

Security

Security remediation and evidence

Per-host remediation and CVE campaigns, with the audit evidence drafted alongside the fix and ready for approval.

How it works

One loop, with a person at the approval step.

The same loop drives triage, remediation, and provisioning. A supervisor agent checks each proposed change against policy, the maintenance window, and the CMDB, and escalates when the evidence does not support the next step.

1Detect2Orchestrate3Investigate4Draft5Approve6Execute and verifyOne loopminutes, not weeks
  1. 01

    Detect

    Event-Driven Ansible receives the alert, ticket, or advisory.

  2. 02

    Orchestrate

    An Ansible Automation Platform workflow starts the agent with the ticket context.

  3. 03

    Investigate

    The agent reads monitoring, logs, and the CMDB with read-only access through MCP.

  4. 04

    Draft

    It writes the diagnosis and the fix, and proposes new automation as a pull request.

  5. 05

    Approve

    An engineer approves in one step, in the ticket or in chat.

  6. 06

    Execute and verify

    Ansible applies the fix, checks the result, and closes the ticket.

Works with ServiceNow · Jira · Tenable · Qualys · Rapid7 · Red Hat Lightspeed · Splunk · Datadog · Dynatrace · vendor agents such as Tanium through their MCP servers

The Silex AIOps Platform

Five components and one trusted execution layer.

The Silex AIOps Platform runs the loop above. Its components investigate, check, record, and evaluate the work, and Red Hat Ansible Automation Platform is the only path to production.

Agent runtime

Runs the agents that investigate, diagnose, and draft fixes, each with the model and tools chosen for its workflow.

Supervisor agent

Checks each proposed change against policy, the maintenance window, and the CMDB, and escalates when the evidence falls short.

Console

Records every run with its evidence and approvals, and gives each workflow a stop control.

Evaluation service

Grades runs against platform records and re-tests models before a change to a workflow goes live.

Connector library

Connects agents to your ITSM, CMDB, monitoring, and vulnerability tools through MCP, with read-only access by default.

Trusted execution layer

Red Hat Ansible Automation Platform

Agents propose and Ansible Automation Platform executes. Every change runs as an approved job template under role-based access and policy, agents never log in to hosts or hold secrets, and every action lands in the ticket and the audit log.

Autonomy ladder

Human-in-the-loop by default.

A workflow moves from Assist to Act with approval, and then to Self-heal, only when its diagnoses match how your engineers resolved the same tickets and it passes its failure tests.

  • Agents act only through approved Ansible job templates.
  • Agents never log in to hosts and never hold secrets.
  • Every change needs an approved change record until the workflow is promoted.
  • A console records every run, and each workflow has a stop control.
  • Every model call passes through the AI gateway for redaction and audit.
  1. Level 1

    Assist

    Agents investigate with read-only access and draft a diagnosis and a fix.

  2. Level 2

    Act with approval

    A person approves each change in one step; Ansible executes and verifies it.

  3. Level 3

    Self-heal

    Workflows that passed their failure tests run on their own, with a stop control.

Evaluation

Evaluate before you trust.

An agent that closes tickets has to be trusted with production. Silex tests models and agent harnesses in a lab built like an enterprise environment, with Ansible Automation Platform, ServiceNow change control, a runbook repository, and a blue-green three-tier application with UAT gates.

We test models from Anthropic, OpenAI, Google, and open-weight families, pick the model, reasoning level, and harness for each workflow, and re-test whenever a model changes.

What every run is graded on

  • Did the agent find the real cause?
  • Did it stay inside approved job templates and the maintenance window?
  • Did it cite evidence for each conclusion?
  • Did it reach the right answer without causing an outage on the way?

Runs are graded from platform records, not from what the agent reports about itself.

Foundation

Automation is how AI acts safely.

Agents reach production only through Ansible Automation Platform job templates, under its role-based access and policy, and every action lands in the ticket and the audit log. Silex has run enterprise Ansible programs since 2019, so the automation library the agents use is one our engineers build and maintain.

Red Hat Ansible Automation Platform · Event-Driven Ansible · AAP MCP server · Terraform · OpenShift · Kong AI Gateway

Automation and Platform Engineering

How we engage

From assessment to self-healing.

  1. 01

    Assess

    A Patch Window Assessment or discovery workshop measures your advisory-to-fix time and maps the queue.

  2. 02

    Pilot

    A triage agent works a test queue, then a share of live tickets, with read-only access.

  3. 03

    Act with approval

    Remediation, patching, and provisioning execute through job templates on one-step approval.

  4. 04

    Self-heal

    Workflows with a clean record run without per-change approval.

  5. 05

    Operate

    Monthly service reviews, quarterly governance reviews, model re-tests, and inference cost tracking.

Questions buyers ask

Questions

Will agents change production systems without approval?

No. Every workflow starts at Assist with read-only access. Changes need one-step human approval until a workflow has a clean record on your own tickets and passes its failure tests. You can stop any workflow at any time.

Do we need Ansible Automation Platform?

Agents act only through approved automation, so an automation platform is required. Silex builds on Red Hat Ansible Automation Platform and can stand it up or extend an existing installation.

Which models do you use?

We test models from Anthropic, OpenAI, Google, and open-weight families on scenarios built from your ticket history, then pick the model for each workflow. Model traffic runs through your AI gateway, so it is governed and audited.

Which tools do the agents work with?

Your ITSM and CMDB (for example ServiceNow or Jira), your monitoring and observability tools, and your vulnerability scanners. Vendor agents such as Tanium can be called through their MCP servers.

How do we measure whether it works?

The assessment records your current advisory-to-fix time and queue wait times. Each phase reports time to resolve and the share of tickets the agents handle against that baseline.

Next step

Measure your advisory-to-fix time.

The Patch Window Assessment measures how long a fix takes to reach production in your environment today and identifies the workflows where agents will shorten it first.