Bits Security Analyst
An autonomous AI agent that investigates eligible Cloud SIEM security signals by querying signals and logs, and produces investigative findings and a recommended verdict for a human analyst.
Recorded characteristics
- Function
- Datadog describes Bits Security Analyst as an autonomous AI agent that investigates Cloud SIEM signals end to end. It queries security signals and logs and uses data-based reasoning to help security engineers investigate threat alerts and make a recommendation on the verdict of each alert signal. Investigated signals appear on a Bits Security Analyst tab in the Cloud SIEM Signals Explorer, where a Bits AI status displays as Investigating until the signal is marked Benign or Suspicious. The investigation side panel presents an overall conclusion, the key evidence used, suggested next steps to remediate the issue or suppress detection rules with specific attributes, the investigative steps showing Bits AI's data queries with embedded results and links to full queries, and analysis of each step.
- Data access
- Datadog states Bits Security Analyst queries security signals and logs. Investigations are scoped to signals from eligible Cloud SIEM detection rules, and Datadog lists the supported security log sources, including Amazon GuardDuty (with specified finding types), AWS CloudTrail, Azure, Cloudflare, CrowdStrike, GCP, Kubernetes, Microsoft Entra ID, Okta, Google Workspace, Microsoft 365, GitLab, GitHub, JumpCloud, Salesforce, Slack, Snowflake, SentinelOne, Windows and email phishing. Datadog also states that some log sources require credentials, configured as Actions Catalog connections, to run or enhance investigations by accessing logs, telemetry or other data that is not in Datadog, and that administrators can supply organisation-level knowledge sources (a general Bits.md org context and dated situational context entries) that the agent applies to investigations. No wider Datadog telemetry access is documented for this capability, and data access recorded here is not generalised from other Bits AI products.
- Actions
- Read only
- External actions
- Conditional
- Human confirmation
- Not required
- Permission basis
- Not established
- Administrative control
- Setting up Bits Security Analyst requires the Bits AI Security Analyst Config Write permission; Datadog's RBAC reference also lists Bits AI Security Analyst Investigations Write for running Bits AI security investigations, both currently marked Preview and attached to the Datadog Admin Role. The feature is turned on with an Enable Bits Security Analyst toggle under Security > Settings > Bits Security Analyst > Analyst Configuration. Administrators can optionally configure which rules and severities are automatically investigated, either through Rule Settings (changing the minimum severity and enabling or disabling individual rules) or a Query Filter that restricts investigation to signals matching the filter. Administrators also manage the stored connections used for external log sources, add or expire knowledge-source entries, and can create security notification rules that fire when an investigation completes using the tag @workflow.bits_investigator.state:*. The capability can be turned off from the same settings page, and Datadog warns that disabling it permanently resets all configuration settings. Separately, Datadog documents an organisation-level AI Credits toggle in Plan & Usage that enables or disables AI products powered by AI Credits.
- Default state
- Disabled
- Availability
- Datadog documents Bits Security Analyst in its product documentation without a general availability label, while the two associated RBAC permissions are marked Preview and noted as not yet enforced. The documentation states the product is not supported on the app.ddog-gov.com and us2.ddog-gov.com Datadog sites. Prerequisites are a non-legacy version of Cloud SIEM and the Bits AI Security Analyst Config Write permission. Datadog states that 14 days or more of log history is needed to view investigations: setup is still possible with a shorter history, but no investigations are visible until that much history exists.
- Licensing
- Datadog's AI Credits documentation lists Bits Chat, Bits Investigation, Bits Code and Bits Agent Builder as the products that consume AI Credits and does not list Bits Security Analyst; no separate plan, licence or price for Bits Security Analyst is stated in the reviewed documentation beyond the non-legacy Cloud SIEM prerequisite.
- External model or provider
- Not established. The reviewed Datadog documentation does not name a model or provider used by Bits Security Analyst, and model information has not been generalised from other Datadog AI products.
- Limitations and uncertainty
- Action capability is recorded as read_only: Datadog documents the agent querying data, reasoning, producing findings and recommending a verdict, and the Bits AI status shown against a signal (Investigating, then Benign or Suspicious) is presented as the agent's investigation state and assessment displayed in the Signals Explorer rather than a documented Cloud SIEM triage action such as resolving or archiving. The operational controls exposed beside an investigation — create a work item pre-populated with the investigation results, run a workflow with a SOAR blueprint, declare an incident, add a rule suppression, and archive the signal — are documented as steps a person takes from the side panel, and are not attributed to the agent. External action capability is recorded as conditional on one documented behaviour: where Cloud SIEM notifications send new signal alerts to Slack or Jira, Datadog states Bits AI automatically updates those notifications with replies containing its investigative conclusion and a link to the full investigation; no other external state change by this agent is documented, and SOAR workflows and integrations are not attributed to it. Human confirmation is recorded as not_required for the investigation itself, because Datadog states investigations are autonomous and that if a detection rule is enabled Bits AI autonomously investigates signals associated with it, with no documented per-signal approval; enabling and scoping the feature remains a human administrative step. Permission basis is recorded as not_established: the documented Bits AI Security Analyst permissions govern human configuration and running of investigations, and Datadog does not state whose identity or permissions the autonomous agent uses when querying signals and logs inside Datadog; for some external log sources the agent uses administrator-supplied credentials stored in Actions Catalog, which is a configured connection rather than a documented runtime identity model, and the Bits Chat user-permission model has not been applied here. Default state is recorded as disabled because Datadog documents that autonomous investigation begins when Bits Security Analyst is enabled, at which point Datadog analyses the organisation's rules, including custom rules, and starts investigating signals for all eligible rules above medium severity. Further boundaries: only signals from eligible detection rules are investigated, and eligibility depends on whether Datadog has built the investigation capability for the log source and whether the agent can investigate the specific rule, with unlisted or ineligible custom rules requiring contact with Datadog support; investigations below the configured minimum severity are excluded; and investigation findings are analysis and suggestions rather than automatic remediation.
Evidence
- Bits Security Analyst
Supports: Function · General · Data access · Human confirmation · Actions · Limitations · External actions · Default state · Admin controls · Permission basis · Availability · Primary source
States Bits Security Analyst is an autonomous AI agent that investigates Cloud SIEM signals end to end, queries security signals and logs, and uses data-based reasoning to help security engineers investigate threat alerts and make a recommendation on the verdict of each alert signal.
Describes the investigation side panel contents (overall conclusion, key evidence, suggested next steps to remediate or suppress detection rules, investigative steps showing data queries with embedded results and links, and analysis of each step), and documents knowledge sources: a general org context (Bits.md) applied to all investigations and situational context entries with status and optional expiry.
States the agent queries security signals and logs, and lists the supported security log sources including Amazon GuardDuty, AWS CloudTrail, Azure, Cloudflare, CrowdStrike, GCP, Kubernetes, Microsoft Entra ID, Okta, Google Workspace, Microsoft 365, GitLab, GitHub, JumpCloud, Salesforce, Slack, Snowflake, SentinelOne, Windows and email phishing.
States Bits Security Analyst investigations are autonomous and that if a detection rule is enabled, Bits AI autonomously investigates signals associated with it.
States a Bits AI status displays in the Severity column as Investigating until marking the signal as either Benign or Suspicious, presenting the agent output as an investigation state and assessment shown in the Signals Explorer.
Documents that the further steps available from the side panel — creating a work item with pre-populated results, running a workflow with a SOAR blueprint, declaring an incident, adding a rule suppression, archiving the signal, and giving feedback — are actions the user takes, described separately from the agent's findings; and states rule eligibility depends on whether Datadog has built the investigation capability for the log source and whether the agent can investigate the specific rule, directing users to Datadog support for new custom rules or rules not made eligible.
States that when Cloud SIEM notifications send new signal alerts to Slack or Jira, Bits AI automatically updates those notifications with replies showing the investigative conclusion and a link to the full investigation.
States that when you enable Bits Security Analyst, Datadog analyses your rules, including custom rules, to determine whether it can confidently investigate associated signals, and that for all eligible rules above medium severity it starts autonomously investigating signals.
Documents the Analyst Configuration page with an Enable Bits Security Analyst toggle, optional Rule Settings for per-rule enablement and minimum severity, a Query Filter restricting which signals are investigated, credential connections for external log sources, knowledge-source management, notification rules using the tag @workflow.bits_investigator.state:*, and a disable toggle that permanently resets all configuration settings.
States that setting up Bits Security Analyst requires the Bits Security Analyst Config Write permission, and that some log sources require credentials stored and restricted through Actions Catalog connections to access logs, telemetry or other data that is not in Datadog.
States the prerequisites: a non-legacy version of Cloud SIEM, the Bits Security Analyst Config Write permission, and 14 days or more of log history to view investigations, noting setup is possible with shorter history but no investigations appear until that history exists. Also states the product is not supported on the app.ddog-gov.com and us2.ddog-gov.com sites.
- Bits AI
Supports: General · Primary source
Describes Bits AI as an agentic teammate in Datadog built to automate development, security and operational workflows, and lists Bits Security Analyst as the feature for triaging security threat signals alongside separate Bits Investigation, Bits Code, Bits Chat, Bits Data Analysis, Bits Detection and Bits Remediation features.
- Datadog Role Permissions
Supports: Permission basis · Availability · Primary source
Lists Bits AI Security Analyst Investigations Write (run Bits AI security investigations) and Bits AI Security Analyst Config Write (edit Bits AI Security Analyst settings), both attached to the Datadog Admin Role, establishing these as controls over human configuration and running rather than a documented runtime agent identity.
Marks both Bits AI Security Analyst permissions as Preview, noting they will be enforced soon.
- AI Credits
Supports: Licensing · Admin controls · Primary source
Lists Bits Chat, Bits Investigation, Bits Code and Bits Agent Builder as the AI products that consume AI Credits, without listing Bits Security Analyst.
States admins manage AI usage in Plan & Usage > AI Credits, where a single organisation-level toggle controls all AI products powered by AI Credits and blocks new requests when disabled.