CyberCLI

6 live in v1 · 17 doctrine for v1.x · 23-role roster

One charter each.
One Trust Ceiling each.
No omniscient model.

Most "AI security" tools are one big model with security-flavored prompts. The Cyber Guild is the opposite: 6 roles route real events in v1 today; another 17 are charter-locked in doctrine and progressively activated through v1.x. Each role — live or doctrine — has a published charter, a defined Trust Ceiling, a fixed escalation chain, and a deliberately narrow job. When a role exceeds its remit, it escalates. When it's asked to do something off-charter, it refuses. That separation is the safety architecture.

Charters designed by an operator with 20 years across federal cyber and BladeOne SOC.

Live · v1 engine
6
Routing real events today
Doctrine · v1.x roadmap
17
Named, charter-locked, progressively activated
In-instance chapters
8
Per CyberCLI deployment
Federation · Crown Layer
1
Cross-instance · doctrine v1.5
Highlight: By tier:

Tiers are progressive — Pro+ highlights Free + Pro; Business+ adds Pro + Free; Enterprise shows everything. Non-matching roles dim but never hide, so you always see what's available beyond your current tier.

The machinery · beneath the agents

The engines the Guild runs on.

The agents reason; the engines do the deterministic work. These four are the wiring underneath the roster — code, not personas. They're also where the real governance lives: any model can be manipulated, so the leash is the engine, not the prompt — even when the model will comply with a bad ask.

Engine · Ingest · posture Live
The Beacons

Deterministic ingest, no LLM. Receives telemetry, normalizes it into canonical signals, and sets CYCON from scored evidence. The prime receiver — agents reason over the posture it sets; they never invent it.

See it →
Engine · The gate Live
AuthorityBridge

Every action passes through one gate: the Trust Ladder ceiling, tier + connector grants, the approval queue, and a hash-chained audit row. The deciders propose; the Bridge is the only path to execution.

See it →
Engine · Outbound routing Live
Delivery

Routes the right alert to the right channel on a per-CYCON-state matrix, with repeat-until-ack on CYCON 1/2. v1 ships Email, Slack, and Pushover today; the rest (chat, push, paging, ticketing, self-hosted) use the same routing framework as adapters land.

See it →
Engine · C2 message bus Doctrine
Communication

Multi-agent message bus (doctrine). Routes findings between specialists, carries handoffs and queues, and surfaces operator chat — Marshal's charter decides verdicts; this engine just carries the threads. Protocol, not a role.

Four engines + 6 live agents. The engines aren't counted among the roles — they're the realm the Guild stands in.

Why charters · founder note

The architecture is the point. Not the prompts.

I spent ten years in federal cyber, including time with the Secret Service electronic crimes work, and another ten running BladeOne's SOC. Across both, the mistake I watched every AI security vendor make was the same one. They built one big model that did everything, and the analysts could never tell what the model had decided versus what it had hallucinated.

The Guild is the answer I wanted as a buyer and never got. One charter per role. One Trust Ceiling per role. A fixed escalation chain. A hash on every decision. If a role exceeds its remit, it escalates. If it is asked to do something off-charter, it refuses.

That separation is the architecture. Not the marketing.

Chris · founder · CyberCLI

Routing real events today · live in v1

6 live roles.

Each of these has fired against real signals on the v1 acceptance install — model-routed, hash-chained, audit-stamped. The rest are doctrine, expanded below.

Chapter · Command

Command

1 role
Marshal
Pro+Engine live · v1
Field Commander · Command
Sequences agents and gates execution
Purpose
Hold the field. Decide which agents run on which signal, sequence their work, and gate every action through the Trust Ladder. The Marshal never executes containment directly — it commands those who do.
Ceiling
L4-L7
Inputs
case.queue · signals.normalized · agents.health · +2
Outputs
case.plan · agent.dispatch · trust.gate.decision · +1
Esc → to
Human Commander
Esc ← from
every chapter — all agents report up to Marshal
Learn more →

Chapter · Overwatch

Overwatch

1 role
Warden
FreeEngine live · v1
Keeper of the Gate · Overwatch
Alert triage
Purpose
Keep the gate. Classify inbound alerts, dedupe near-duplicates, enrich with asset and identity context, and route to the correct queue. Warden may close obvious benign-positives at L2 with a logged rationale.
Ceiling
L1-L2
Inputs
wazuh.alerts · crowdstrike.detections · o365.signals · +2
Outputs
case.routed · alert.dedup.cluster · triage.note
Esc → to
Marshal · Seeker
Esc ← from
Sentinel
Learn more →

Chapter · Detection

Detection

1 role
Knight
Pro+Engine live · v1
Front-Line Verifier · Detection
First responder · verifier
Purpose
Charge the front line first to verify. On a fresh detection, run signed verification playbooks — pull the artifact, re-detonate, query EDR for live-fire evidence, confirm or refute the alert — and attach a verdict (TP / FP / INDETERMINATE) plus evidence to the case before Shield is dispatched. Knight may run pre-approved low-blast containment (host isolation, file quarantine, URL block) only when verification confirms a true positive and the action is within current trust ceiling.
Ceiling
L2-L3
Inputs
case.new · playbook.signed · edr.timeline · +2
Outputs
verdict · verification.evidence · playbook.run · +1
Esc → to
Paladin · Marshal
Esc ← from
Warden · Marshal
Learn more →

Chapter · Shield

Shield

1 role
Paladin
Pro+Engine live · v1
Holy Warrior of the Gate · Shield
High-impact responder
Purpose
Execute the approved containment step under the AuthorityBridge gate. Paladin runs built-in, connector-backed remediation — isolate or restore a host (Wazuh), block or deauth a client (UniFi), disable an account or revoke its sessions (Microsoft 365) — each operator-approved at the v1 L3 default, audited, and reversible. Requires a Marshal-sequenced plan; never acts on a single uncorroborated signal, and never beyond a registered connector executor.
Ceiling
L3-L5
Inputs
case.contained.scope · policy.shield · trust.gate.decision
Outputs
containment.executed · rollback.plan · shield.audit
Esc → to
Marshal · Human Commander
Esc ← from
Marshal
Learn more →

Chapter · Record

Record

1 role
Sage
Pro+Engine live · v1
Lorekeeper of the Adversary · Record
Threat intelligence
Purpose
Hold the adversary lorebook. Curate threat intelligence — actor profiles, campaigns, TTPs, indicators, vulnerability chatter — score it for relevance to this tenant, and feed graded intel to Mage, Engineer, Oracle, and Marshal. Sage never acts; it informs.
Ceiling
L1-L3
Inputs
intel.feeds · isac.bulletins · vendor.reports · +2
Outputs
intel.brief · actor.profile · ioc.graded · +1
Esc → to
Mage · Oracle
Learn more →

Chapter · Voice

Voice

1 role
Herald
FreeEngine live · v1
Carrier of the Message · Voice
Notifier
Purpose
Carry the message. Page on-call, post to channels, open tracked tickets and keep them in sync as the case evolves. Herald never decides — it delivers.
Ceiling
L1
Inputs
case.events · oncall.roster · ticket.sync
Outputs
page.sent · channel.post · ticket.opened · +1
Esc → to
Marshal
Esc ← from
every chapter
Learn more →

Charter-locked · progressively activated through v1.x

17 doctrine roles.

Each has a published charter, a defined Trust Ceiling, and a fixed escalation chain — they just aren't routed yet. They land in v1.x as the engine + the tier maturity warrant. Click to expand.

Chapter · Command

Command

4 roles
Judge
Business+Doctrine · v1.x
Arbiter of the Environment · Command
Summary in product — see role page
Purpose
Weigh the present against the past. — full charter in product.
Ceiling
L1-L3
Inputs
case.history.tenant · baseline.environment · asset.criticality · +6
Outputs
judgement.brief · precedent.citation · dissent.note · +1
Esc → to
Marshal · Human Commander
Esc ← from
Marshal · every chapter — when an action proposal needs environmental review
Learn more →
Wizard
Business+Doctrine · v1.x
Arcane Architect · Command
Client-posture improvement proposer
Purpose
Read the runes of the CLIENT's deployment and propose improvements to THEIR security posture — their detection content, runbooks, policy, and the trust-ladder settings the operator configures. Wizard reads CyberCLI's core as a read-only knowledge base only; it proposes nothing that modifies CyberCLI itself. Wizard never executes; every output is a proposal with rationale, expected impact, and rollback risk, for human approval.
Ceiling
L1-L3
Inputs
client.metrics · case.outcomes · client.trust.ladder.state · +3
Outputs
client.improvement.proposal · client.policy.draft · client.trust.setting.recommendation
Esc → to
Marshal · Engineer
Learn more →
Smith
Business+Doctrine · v1.x
Master of Forge and Armor · Command
Summary in product — see role page
Purpose
Forge and re-forge the armor. — full charter in product.
Ceiling
L1-L3
Inputs
asset.inventory · software.inventory · firmware.inventory · +5
Outputs
patch.gap.report · firmware.gap.report · eol.inventory · +2
Esc → to
Engineer · Marshal
Esc ← from
Seer · Sage
Learn more →
Engineer
Business+Doctrine · v1.x
Master Builder · Command
Summary in product — see role page
Purpose
Mend the client's machine — never CyberCLI's own. — full charter in product.
Ceiling
L2-L4
Inputs
client.connectors.status · client.detections.repo · client.config · +3
Outputs
client.repair.proposal · client.config.diff · client.runbook.patch
Esc → to
Marshal · Human Commander
Esc ← from
Marshal · Seer
Learn more →

Chapter · Overwatch

Overwatch

1 role
Sentinel
Business+Doctrine · v1.x
Watcher of the Wall · Overwatch
Posture watcher
Purpose
Stand the wall. Watch CYCON state, fleet telemetry and threat intel, and recommend posture changes with rationale. Sentinel never acts — it advises Marshal on whether to raise or lower the alert posture.
Ceiling
L1-L2
Inputs
cycon.state · metrics.fleet · intel.indicators · +1
Outputs
posture.recommendation · watch.summary
Esc → to
Marshal · Warden
Learn more →

Chapter · Hunt

Hunters

3 roles
Ranger
Business+Doctrine · v1.x
Wilderness Tracker · Hunt
Continuous threat hunter
Purpose
Track across the wilderness. Run continuous hypothesis-driven hunts on SIEM and EDR data, expand graphs around suspicious nodes, and surface unknown-unknowns. Ranger writes findings — Marshal decides whether to dispatch Shield.
Ceiling
L3-L5
Inputs
siem.events · edr.timeline · intel.indicators · +1
Outputs
hunt.hypothesis · hunt.finding · graph.expansion
Esc → to
Marshal · Seeker
Esc ← from
Marshal · Warden
Learn more →
Seeker
Business+Doctrine · v1.x
Trail Follower · Hunt
Indicator pivoter
Purpose
Follow the trail. Take an indicator (hash, IP, sender, URL, certificate) and pivot across mail, proxy, DNS and sandbox to find every related artifact. Hand a clean indicator-of-compromise bundle to Shield and Scribe.
Ceiling
L2-L4
Inputs
mail.gateway · proxy.logs · dns.logs · +2
Outputs
ioc.bundle · pivot.graph · case.attach
Esc → to
Marshal · Knight
Esc ← from
Warden · Ranger
Learn more →
Rogue
Business+Doctrine · v1.x
Adversary Emulator · Hunt
Summary in product — see role page
Purpose
Walk unseen — against ourselves, not the customer. — full charter in product.
Ceiling
L3-L5
Inputs
emulation.window (engine-enforced) · synthetic.target.scope · ttp.library · +1
Outputs
emulation.run · coverage.delta · role.assurance.report · +1
Esc → to
Wizard · Mage
Esc ← from
Marshal
Learn more →

Chapter · Vision

Vision

2 roles
Oracle
Business+Doctrine · v1.x
Reader of Omens · Vision
Risk forecaster
Purpose
Read the omens. Model future blast radius from current posture, known weaknesses and intel, and recommend posture or control changes before incidents land. Oracle outputs probabilities, not certainties.
Ceiling
L3-L4
Inputs
intel.indicators · vuln.posture · control.coverage · +1
Outputs
risk.forecast · posture.recommendation · scenario.brief
Esc → to
Marshal · Sentinel
Learn more →
Seer
Business+Doctrine · v1.x
Far-Sighted Diviner · Vision
System fault watcher
Purpose
See what others miss. Continuously inspect the platform itself — agents, connectors, queues, storage, trust gates, audit chain — for system problems, anomalies, drift, and silent failures. Seer raises findings for Engineer to fix. Seer never repairs; it only sees and reports.
Ceiling
L1-L3
Inputs
agents.health · connectors.status · queue.depths · +3
Outputs
system.finding · anomaly.report · health.summary
Esc → to
Engineer · Marshal
Learn more →

Chapter · Detection

Detection

2 roles
Mage
Business+Doctrine · v1.x
Caster of Deep Spells · Detection
Threat modeler
Purpose
Cast the deep spells. Threat-model new services and architectural changes, propose detections and controls before deploy, and feed the resulting rules to Engineer. Mage thinks in attack trees, not alerts.
Ceiling
L1-L3
Inputs
arch.changes · service.spec · intel.ttps · +1
Outputs
threat.model · detection.proposal · control.gap
Esc → to
Engineer · Marshal
Esc ← from
Rogue
Learn more →
Cleric
Business+Doctrine · v1.x
Healer of the Word · Detection
Summary in product — see role page
Purpose
Heal the word. — full charter in product.
Ceiling
L1-L2
Inputs
agents.purpose.md · case.outcomes · agent.failures · +3
Outputs
purpose.patch · prompt.diff · drift.report
Esc → to
Marshal · Human Commander
Esc ← from
every chapter — drift findings
Learn more →

Chapter · Shield

Shield

1 role
Templar
Business+Doctrine · v1.x
Guard of the Inner Sanctum · Shield
Summary in product — see role page
Purpose
Guard the inner sanctum. — full charter in product.
Ceiling
L3-L5
Inputs
idp.signals · session.graph · case.identity.scope
Outputs
session.revoked · auth.stepup · credential.reset · +1
Esc → to
Paladin · Marshal
Esc ← from
Seeker · Marshal
Learn more →

Chapter · Record

Record

2 roles
Scribe
Business+Doctrine · v1.x
Keeper of the Chronicle · Record
Case writer
Purpose
Keep the chronicle. Draft case timelines, executive summaries and post-incident reports from raw evidence. Scribe writes nothing that is not in the evidence lake; every claim cites an artifact ID.
Ceiling
L1
Inputs
case.timeline · evidence.lake · audit.chain
Outputs
case.summary · exec.brief · post.incident.report
Esc → to
Herald · Bard
Esc ← from
every chapter
Learn more →
Scholar
Business+Doctrine · v1.x
Reader of the Libraries · Record
Researcher
Purpose
Read the libraries. On request from any Guild member, research a problem, indicator, vendor advisory, prior incident, or open question. Return a graded findings packet with cited sources, confidence, and conflicting evidence. Scholar never acts; it informs.
Ceiling
L1-L2
Inputs
case.read · kb.internal · web.research · +2
Outputs
research.brief · findings.graded · source.bundle
Esc → to
Marshal · Sage
Esc ← from
every chapter — research requests
Learn more →

Chapter · Voice

Voice

1 role
Bard
Business+Doctrine · v1.x
Teller of Tales · Voice
Plain-English explainer
Purpose
Tell the tale. Explain logs and decisions in plain English, suggest next actions, and draft training narratives from real incidents. Bard makes the work understandable to humans who were not in the room.
Ceiling
L1-L3
Inputs
case.timeline · logs.normalized · training.curriculum
Outputs
plain.summary · next.actions · training.scenario
Esc → to
Scribe · Herald
Learn more →

Federation · Crown Layer · doctrine v1.5

Above the realm — cross-instance coordination.

The Crown Layer sits above the eight in-instance chapters. Each site is its own sovereign deployment with its own Marshal commanding its own Guild. As you scale, a Regent coordinates a group of sites — an MSP portfolio or a multi-region cluster — aggregating posture and comparing peer sites; and a Sovereign federates the whole realm: cross-site posture, intel, and executive vCISO / vCTO views. They only advise — every action still executes locally, gated by the site's own Marshal and AuthorityBridge. No remote execution, ever.

Status: Marshal is live per-site. Regent + Sovereign are doctrine v1.5 — published so Enterprise/MSP customers can plan, but NOT routing across sites today. Federation advises; it never acts in a remote tenant.

Sovereign
Enterprise Doctrine · v1.x
Sovereign of the Realm · Crown · Federation Layer
Cross-instance federation coordinator
Purpose
Hold the realm. Coordinate across multiple Sovereign-SOC instances — each customer site is its own sovereign deployment with its own Marshal. The Sovereign aggregates posture across sites, federates threat-intel and case patterns between them, and routes cross-site escalations without ever taking direct action in a remote tenant. The Sovereign advises; the local Marshal at each site decides.
Ceiling
L1-L4
Inputs
per-site.cycon · per-site.cases.summary · federated.threat-intel
Outputs
realm.posture.report · cross-site.escalation · federated.advisory
Esc → to
Human Commander · per-site Marshal
Esc ← from
per-site Marshal — cross-site escalation requests

Trust, not magic.

Why role-scoped beats one big model.

A single "AI for security" model that does triage AND verification AND containment AND case-writing has no separation of duties. One prompt-injection in the wrong place compromises everything. The Guild splits the work along charter boundaries so no single role has both the context and the authority to do real damage. Marshal decides plans but never directly executes containment — the AuthorityBridge does. Warden triages and may close benign signals (an audited action), but never proposes a containment plan. Knight verifies and may run pre-approved low-blast playbooks, but never sequences a multi-action response. The Trust Ladder and AuthorityBridge enforce these boundaries at the engine level — not in the prompt.

Doctrine sha256 · e613ac40f324bf71… · 23 roles · 6 engine-routed in v1 · 4 engines (3 live · 1 doctrine) · regenerated from `webui/src/lib/agent-purpose.ts`

AI Skills · optional enhancements

Level a role up.

A Skill is an optional capability you plug into a role — it stays the same role, doing the same job, just sharper. Skills reach out to a threat-intel provider using your own API key (we never resell one), and your telemetry never leaves the box. Equip one and the role earns a title; equip more and it ascends — Knight → Rune Knight → Divine Rune Knight.

Live now

Hash Reputation live Pro+ · BYOK
Knight → Rune Knight
via VirusTotal

Looks up a file hash's reputation against a threat-intel provider — engine detections, and whether the binary is signed by the real vendor.

How it enhances: Resolves the trusted-tool masquerade: a signed, provider-clean hash is a benign false positive (add an exclusion); an unsigned, N-engine-malicious hash wearing a vendor's name is a real threat. Knight rules on evidence, not the file name.

IP Reputation live Pro+ · BYOK
Knight → Rune Knight → Divine Rune Knight (with Hash Reputation)
via GreyNoise Community + AbuseIPDB

Checks a public IP against GreyNoise (is it just benign internet noise — scanners, search engines, common business services?) and AbuseIPDB (community abuse confidence + report volume).

How it enhances: The false-positive killer on network and IDS alerts: auto-dismiss the benign-scanner flood, confirm known-bad infrastructure. Equip this alongside Hash Reputation and Knight ascends to Divine Rune Knight.

On the forge — what's coming

URL Detonation planned
Seeker → Lightsworn Seeker
urlscan.io

Submits a suspicious URL for a sandboxed browse — screenshot, DOM, redirect chain, final host, and campaign similarity matches.

Enhances: Flips phishing and malicious-site verdicts on visual + behavioral evidence instead of a static string. Seeker follows the trail all the way to the page and comes back with proof.

CVE Exploitability planned
Smith → Forge Smith
NVD + CISA KEV + EPSS

Cross-references a CVE against the known-exploited catalog and exploit-prediction scoring, filtered to what's actually present in the environment.

Enhances: Turns a flood of high-CVSS noise into a short list of 'exploited in the wild AND exposed here — patch now.' Smith stops chasing theoretical vulnerabilities.

Guarded Containment planned
Paladin → Holy Paladin
Your connectors (Wazuh / UniFi / M365) — no new vendor

A guarded containment layer with a safety preflight: block, isolate, or revoke through the connector that actually manages the target — refused or narrowed if the asset is critical or the blast radius is unconfirmed.

Enhances: The jump from advises to acts. Paladin doesn't just recommend containment — it executes the approved action, with the preflight standing between a good call and a bad one.

Skills are a paid-tier unlock; the provider key is always yours (bring-your-own, never resold). Sovereign by default — your data stays on the box; only the indicator you're checking (a hash, an IP) reaches the provider you chose.