Datadog · Bits AI

Bits Security Analyst

An autonomous AI agent that investigates eligible Cloud SIEM security signals by querying signals and logs, and produces investigative findings and a recommended verdict for a human analyst.

Recorded characteristics

Function
Datadog describes Bits Security Analyst as an autonomous AI agent that investigates Cloud SIEM signals end to end. It queries security signals and logs and uses data-based reasoning to help security engineers investigate threat alerts and make a recommendation on the verdict of each alert signal. Investigated signals appear on a Bits Security Analyst tab in the Cloud SIEM Signals Explorer, where a Bits AI status displays as Investigating until the signal is marked Benign or Suspicious. The investigation side panel presents an overall conclusion, the key evidence used, suggested next steps to remediate the issue or suppress detection rules with specific attributes, the investigative steps showing Bits AI's data queries with embedded results and links to full queries, and analysis of each step.
Data access
Datadog states Bits Security Analyst queries security signals and logs. Investigations are scoped to signals from eligible Cloud SIEM detection rules, and Datadog lists the supported security log sources, including Amazon GuardDuty (with specified finding types), AWS CloudTrail, Azure, Cloudflare, CrowdStrike, GCP, Kubernetes, Microsoft Entra ID, Okta, Google Workspace, Microsoft 365, GitLab, GitHub, JumpCloud, Salesforce, Slack, Snowflake, SentinelOne, Windows and email phishing. Datadog also states that some log sources require credentials, configured as Actions Catalog connections, to run or enhance investigations by accessing logs, telemetry or other data that is not in Datadog, and that administrators can supply organisation-level knowledge sources (a general Bits.md org context and dated situational context entries) that the agent applies to investigations. No wider Datadog telemetry access is documented for this capability, and data access recorded here is not generalised from other Bits AI products.
Actions
Read only
External actions
Conditional
Human confirmation
Not required
Permission basis
Not established
Administrative control
Setting up Bits Security Analyst requires the Bits AI Security Analyst Config Write permission; Datadog's RBAC reference also lists Bits AI Security Analyst Investigations Write for running Bits AI security investigations, both currently marked Preview and attached to the Datadog Admin Role. The feature is turned on with an Enable Bits Security Analyst toggle under Security > Settings > Bits Security Analyst > Analyst Configuration. Administrators can optionally configure which rules and severities are automatically investigated, either through Rule Settings (changing the minimum severity and enabling or disabling individual rules) or a Query Filter that restricts investigation to signals matching the filter. Administrators also manage the stored connections used for external log sources, add or expire knowledge-source entries, and can create security notification rules that fire when an investigation completes using the tag @workflow.bits_investigator.state:*. The capability can be turned off from the same settings page, and Datadog warns that disabling it permanently resets all configuration settings. Separately, Datadog documents an organisation-level AI Credits toggle in Plan & Usage that enables or disables AI products powered by AI Credits.
Default state
Disabled
Availability
Datadog documents Bits Security Analyst in its product documentation without a general availability label, while the two associated RBAC permissions are marked Preview and noted as not yet enforced. The documentation states the product is not supported on the app.ddog-gov.com and us2.ddog-gov.com Datadog sites. Prerequisites are a non-legacy version of Cloud SIEM and the Bits AI Security Analyst Config Write permission. Datadog states that 14 days or more of log history is needed to view investigations: setup is still possible with a shorter history, but no investigations are visible until that much history exists.
Licensing
Datadog's AI Credits documentation lists Bits Chat, Bits Investigation, Bits Code and Bits Agent Builder as the products that consume AI Credits and does not list Bits Security Analyst; no separate plan, licence or price for Bits Security Analyst is stated in the reviewed documentation beyond the non-legacy Cloud SIEM prerequisite.
External model or provider
Not established. The reviewed Datadog documentation does not name a model or provider used by Bits Security Analyst, and model information has not been generalised from other Datadog AI products.
Limitations and uncertainty
Action capability is recorded as read_only: Datadog documents the agent querying data, reasoning, producing findings and recommending a verdict, and the Bits AI status shown against a signal (Investigating, then Benign or Suspicious) is presented as the agent's investigation state and assessment displayed in the Signals Explorer rather than a documented Cloud SIEM triage action such as resolving or archiving. The operational controls exposed beside an investigation — create a work item pre-populated with the investigation results, run a workflow with a SOAR blueprint, declare an incident, add a rule suppression, and archive the signal — are documented as steps a person takes from the side panel, and are not attributed to the agent. External action capability is recorded as conditional on one documented behaviour: where Cloud SIEM notifications send new signal alerts to Slack or Jira, Datadog states Bits AI automatically updates those notifications with replies containing its investigative conclusion and a link to the full investigation; no other external state change by this agent is documented, and SOAR workflows and integrations are not attributed to it. Human confirmation is recorded as not_required for the investigation itself, because Datadog states investigations are autonomous and that if a detection rule is enabled Bits AI autonomously investigates signals associated with it, with no documented per-signal approval; enabling and scoping the feature remains a human administrative step. Permission basis is recorded as not_established: the documented Bits AI Security Analyst permissions govern human configuration and running of investigations, and Datadog does not state whose identity or permissions the autonomous agent uses when querying signals and logs inside Datadog; for some external log sources the agent uses administrator-supplied credentials stored in Actions Catalog, which is a configured connection rather than a documented runtime identity model, and the Bits Chat user-permission model has not been applied here. Default state is recorded as disabled because Datadog documents that autonomous investigation begins when Bits Security Analyst is enabled, at which point Datadog analyses the organisation's rules, including custom rules, and starts investigating signals for all eligible rules above medium severity. Further boundaries: only signals from eligible detection rules are investigated, and eligibility depends on whether Datadog has built the investigation capability for the log source and whether the agent can investigate the specific rule, with unlisted or ineligible custom rules requiring contact with Datadog support; investigations below the configured minimum severity are excluded; and investigation findings are analysis and suggestions rather than automatic remediation.

Evidence