Icite knowledge graphs aim to give security AI agents usable context
Icite CEO Wes Mullins said graph-based identity data can help AI agents investigate security issues with fewer blind spots.
By Colin Brandt · Enterprise Reporter
· 3 min read
Icite knowledge graphs are being pitched as the context layer for AI agents that can take on parts of enterprise security investigations. Wes Mullins, founder and chief executive of Icite Inc., told SiliconANGLE’s theCUBE at Neo4j GraphTalk 2026 that the company uses normalized customer data and graph traversal to support more autonomous cybersecurity workflows.
The company did not announce funding, revenue, customer counts, pricing or benchmark data. The claim is narrower: Icite says AI security agents work better when they operate over a structured knowledge layer rather than raw enterprise data.
Mullins said AI agents depend on the data, memory and context they are given. In his view, a graph-based layer gives agents a more deterministic path through enterprise information, with guardrails intended to reduce hallucinations. He said Icite ingests customer data, normalizes it into the company’s format and lets its agents move through that model.
How do Icite knowledge graphs support security agents?
A knowledge graph represents entities and relationships, such as users, groups, roles, systems and policies, in a connected model. In security operations, that structure can help software follow relationships across identity data rather than treating each alert or log entry as an isolated event.
Mullins said identity intelligence is central to Icite’s approach. The more identity-related data a company can bring together, the more useful the graph becomes for spotting deviations from expected behavior, according to Mullins.
He described the baseline as a profile built from organizational context: group membership, titles, policies and procedures. With that information, he said, a security system can compare behavior across functions such as HR, research and development, and networking teams. The company’s argument is that unusual access patterns or behavior stand out more clearly when the agent has that organizational map.
Icite also says its graph supports AI-assisted investigations. Instead of waiting for an analyst to connect identity data manually, Mullins said agents can surface links across the graph and perform routine traversal work for the security team.
That positioning lines up with a broader push in enterprise AI toward structured context systems for agents. Security teams are a logical early market because they already deal with fragmented identity, access and event data, and false positives consume analyst time. The harder question is whether graph-backed agents can reduce investigation load in production without creating new review burdens.
No independent performance figures were provided. Icite’s case rests on the idea that better context improves agent behavior, especially in security workflows where hallucinated conclusions are unacceptable. For buyers, the missing details are the usual ones: how much data integration is required, what systems are supported, and how the product performs against existing detection and investigation tools.
Mullins discussed the company during an interview with theCUBE’s John Furrier at the Neo4j GraphTalk event. SiliconANGLE disclosed that theCUBE was a paid media partner for the event and said sponsors did not have editorial control over the coverage.
This story draws on original reporting from SiliconANGLE.