The headline is not the authority boundary
Vendors use autonomous, agentic, and closed-loop language for systems with materially different permissions. The governed record shows four distinct patterns: read-only investigation, recommendation, approval-gated writes, and bounded autonomous writes. Those patterns are not interchangeable, and none is a production-effectiveness claim.
What actually differs?
| System | Documented boundary | Buyer consequence |
|---|---|---|
| Google Threat Hunt Agent | Read-only, analyst initiated | Useful for evidence gathering; response remains outside the agent |
| Google Detection Engineering Agent | Draft only; manual rule creation | Generated detection logic cannot silently become production policy |
| Cortex AgentiX | Sensitive actions require manual approval | Governance depends on correct action classification and RBAC |
| Purple AI | Teams choose autonomous versus sign-off paths | Buyers must inspect configured workflow boundaries, not marketing language |
| Simbian NetSecOps | Vendor claims firewall changes without human intervention | Highest claimed authority here, but public constraint details remain UNKNOWN |
Decision rule
Compare the strongest documented action an agent can execute, who configures the boundary, whether each action is logged, and how quickly an operator can stop or reverse it. Treat missing constraint documentation as UNKNOWN. Do not convert it into either a safety assurance or a negative capability finding.
Evidence limit
The corpus contains canonical vendor documentation and vendor claims. It contains no qualifying independent validation of these action boundaries in production.