March 23, 2026

ADÉ goes GA with configurable automation, broader coverage, and explainable, actionable recommendations
ADÉ (Autonomous Detection Engineer) is our AI agent that automatically generates org-specific coverage. Since its public beta in September, teams have been using ADÉ to turn novel email attacks into new detections in hours, not weeks or months.
Today, we're making ADÉ generally available for all Sublime Enterprise customers – with full autonomy, broader coverage, and complete transparency into how every detection is generated. And unlike vendor model updates that have to work across every customer, ADÉ only has to work for one: you.
"What's compelling about ADÉ is the shift from static defenses to a system that actively improves our specific coverage. The promise of an agent continuously tailoring and backtesting new protections for our environment is a force multiplier. It means our defenses don't just work, they evolve, and we get the benefit without having to do the work."
– Roger Allen, Senior Director, Global Head of Detection and Response at Sprinklr
With this GA release, ADÉ can now run end-to-end without analyst intervention – from picking up a newly reported threat to generating and accepting a high-confidence detection. With Sublime, security teams are always in control: optionally have a human-in-the-loop and customize ADÉ's efficacy acceptance thresholds. Here's how it works:
Whether you want full autonomy or human sign-off on every detection, ADÉ adapts to how your team works.

During beta, ADÉ created new coverage for malicious messages. In GA, ADÉ now generates coverage across malicious, spam, and graymail – so new threats don't slip through the noise. If auto-start is enabled, messages are automatically passed to ADÉ. Teams can also send messages to ADÉ manually.
ADÉ now surfaces its full chain of thought – an explanation of everything it considered during the detection-building process, from initial analysis through Hunt iteration. Combined with audit logs that show exactly what information ADÉ reviewed, teams can trace every step of the recommendation. This transparency helps analysts learn how ADÉ approached the problem and build trust in the output.


ADÉ labels new coverage by Attack Type, Tactics and Techniques, and Detection Methods. This makes it easy to understand what ADÉ caught, how it caught it, and where it fits in your broader coverage map.

ADÉ fits into the workflow you already have rather than creating a new one. Jobs are stored alongside your existing detection and investigation data, so there's no new tool to manage. Analysts can cancel and restart jobs, and leave comments during review to capture context for the team.
The more ADÉ runs, the tighter your coverage gets. Every new threat becomes the input for the next detection.
ADÉ is now generally available for all Sublime Enterprise customers. Book a demo to see how ADÉ turns novel threats into detections – autonomously.
Sublime releases, detections, blogs, events, and more directly to your inbox.
See how Sublime delivers autonomous protection by default, with control on demand.