Independent product guide · August 2, 2026

Project Perception coordinates security agents from finding to reviewed action

Use this guide to separate Microsoft's announced public preview, red-blue-green roles, shared security context, multi-model routing, actuators, human signoff, and SCU billing. Start with one bounded Defender workflow and prove evidence, permissions, and rollback.

System map

Four decisions connect telemetry to a controlled security outcome

Signals & sensors

Visibility across endpoints, identities, clouds, applications, data, and AI systems. Confirm connector scope and freshness.

Security context

A shared view of assets, relationships, risks, activities, policy, and history. Require source provenance and stale-data handling.

Models & harness

Specialized and frontier models are routed and coordinated for quality, reliability, latency, and cost.

Agents & actuators

Red, blue, and green agents reason over context; actuators connect an approved decision to a real defensive action.

Agent roles

A finding becomes useful only when the handoff preserves evidence and authority

Expose paths to compromise

Red agents

Keep probing inside an authorized scope and require reproducible evidence before escalation.

Investigate and prioritize

Blue agents

Preserve source signals, contradictions, confidence, and analyst review rather than treating correlation as compromise.

Remediate and harden

Green agents

Use least privilege, explicit approval, a bounded change, verification, and a tested rollback path.

Evaluation path

Test one workflow before enabling an autonomous action loop

01

Select one non-production security workflow with analyst-reviewed ground truth.

02

Record tenant, region, Defender surface, roles, connectors, and data boundaries.

03

Run red and blue investigation before enabling any green actuator action.

04

Inspect evidence, handoffs, human signoff, action logs, and rollback.

05

Measure validated outcomes, false positives, overrides, analyst time, and SCUs.

Project Perception questions, answered

Project Perception is Microsoft's agentic security system. It coordinates red, blue, and green agents over security context, multiple models, an orchestration harness, and actuators while keeping people responsible for critical decisions.
No. Microsoft describes Project Perception as the agentic system containing security agents that act, and Security Copilot as the generative AI-assisted chat interface. They are designed to work together.
Microsoft's July 27 announcement says Project Perception enters public preview on August 3, 2026. Verify the signed-in Defender portal and current documentation because tenant and scenario rollout can vary.
Microsoft says the launch brings coordinated multi-agent defense into Microsoft Defender, with expansion across Microsoft Security products over time. Confirm current tenant, product, region, and scenario access.
Microsoft's current product page describes pay-as-you-go consumption measured in Security Compute Units. Different agents can consume SCUs at different rates depending on task intensity; verify the live rate and reporting.
This is an independent, source-checked product guide. It does not embed Project Perception, grant Microsoft access, or establish a Flowith integration. Use Microsoft Defender and official Microsoft documentation for product access.

This page is an independent information guide, not an embedded Microsoft tool or a Flowith integration. Source check: August 2, 2026. Verify live Microsoft Defender access, preview terms, SCU pricing, roles, connectors, approvals, and data controls.