The headline is not the authority boundary

Vendors use autonomous, agentic, and closed-loop language for systems with materially different permissions. The governed record shows four distinct patterns: read-only investigation, recommendation, approval-gated writes, and bounded autonomous writes. Those patterns are not interchangeable, and none is a production-effectiveness claim.

What actually differs?

SystemDocumented boundaryBuyer consequence
Google Threat Hunt AgentRead-only, analyst initiatedUseful for evidence gathering; response remains outside the agent
Google Detection Engineering AgentDraft only; manual rule creationGenerated detection logic cannot silently become production policy
Cortex AgentiXSensitive actions require manual approvalGovernance depends on correct action classification and RBAC
Purple AITeams choose autonomous versus sign-off pathsBuyers must inspect configured workflow boundaries, not marketing language
Simbian NetSecOpsVendor claims firewall changes without human interventionHighest claimed authority here, but public constraint details remain UNKNOWN

Decision rule

Compare the strongest documented action an agent can execute, who configures the boundary, whether each action is logged, and how quickly an operator can stop or reverse it. Treat missing constraint documentation as UNKNOWN. Do not convert it into either a safety assurance or a negative capability finding.

Evidence limit

The corpus contains canonical vendor documentation and vendor claims. It contains no qualifying independent validation of these action boundaries in production.