A different approach to AI in security
Every vendor is pushing AI right now, but CISOs are left sorting out what’s real versus what’s bolted on. Chas Clawson, Field CTO at Sumo Logic, made that distinction clear.“Most AI features we are seeing released are bolt-ons. What we are building with Dojo AI is different: it brings a modular agentic approach to our platform, so specialized agents can automate routine work, streamline investigations, and let analysts focus on the highest-value problems, all working under a new unified Dojo framework,” said Clawson.
Solving analyst bottlenecks
SOC teams know the grind: too many alerts, too much context switching, too much manual triage. These pain points add friction and stretch investigations well beyond what fast-moving threats allow. Dojo AI targets those very steps.Clawson explained, “Our approach has always been that alerts or ‘Insights’ should be entity-based and provide the full kill-chain context. Still, analysts have to spend time reviewing all of the signals to make a determination on what happened. This causes frictions that slow SOCs down: alert fatigue, context switching, manual triage, and slow responses. With Dojo AI, we are taking this a step further, with agents that automatically pull surrounding signals together, accelerate scoping and triage, and produce consistent investigation summaries - so analysts spend less time assembling context and more time deciding and acting.”The result is not a replacement for analysts but a set of workflows that allow them to move faster, spend more energy on high-value issues, and reduce repetitive manual steps that add little value.Roadmap for agentic workflows
Dojo AI is rolling out in stages to ensure quality and scalability. Today’s release includes Mobot, Query Agent, and Summary Agent, but more agents are already in the pipeline.“We’re rolling out agentic capabilities in phases to keep quality high,” Clawson said. “Starting with today’s agents - Mobot (beta), Query Agent, and Summary Agent - we will expand as additional agents complete development, with larger pushes coming around December of this year. I’m particularly excited about an agent that will assist customers in configuring and using all of the features within our platform without the need to dig through documentation.”
Creating opportunities for partners
Dojo AI is also designed with MSSPs and partners in mind. Many providers are exploring how to add AI-driven operations into their service catalogs to stand out in a crowded market. Sumo Logic aims to give them a path to do just that.Clawson pointed to the AI Model Context Protocol as a key enabler:“One area to follow is the rapid adoption of the AI Model Context Protocol. It’s designed to provide near turn-key ways to integrate Sumo Logic’s observability and security data into their own custom AI-driven workflows and agentic systems. With a standardized, well-documented interface for connecting large language models (LLMs) and custom agents to Sumo Logic, customers can soon build advanced, automated solutions that improve operational efficiency and accelerate incident response, leveraging the power of AI.”




