- Retirement income & withdrawal strategy
- Tax: Roth/RRSP, loss harvesting, rule changes
- Estate, insurance & cross-border planning
- Advisor tools: meeting prep, compliance pre-screen
21,500+ skills & agents. Every one governed.
5,814 pre-built agents and 15,654 library skills across 24 industries and 12 roles per industry — installable from the catalog, connected to your systems, and run through the same fail-closed gate chain as everything else on Cortex.
21,511 governed library items · counted live from the catalog, not a marketing number
Start from a curated collection.
Hand-built suites for the jobs enterprises automate first — every collection ships governed, with policies and audit built in.
- Service, Sales & Customer Success
- IT Service Desk, HR & Finance Ops
- Legal Intake, Procurement & Field Ops
- Risk & Compliance
- Inbox triage & email drafting
- Meeting prep, notes & follow-up
- Smart scheduling & daily brief
- Executive assistant orchestration
- Smart claims, actuarial & AML
- Audit, GRC & ESG reporting
- ITAM / ITSM & security operations
- Data & analytics workbenches
Find the skill your team needs.
Search 21,500+ governed skills and agents, or filter by industry and type — every result installs from the catalog and runs through the same gates.
648 results · Cybersecurity · skills
Search approved knowledge — Security Operations Lead, Cybersecurity
Search approved knowledge for Security Operations Lead teams in Cybersecurity, delivered by the Q&A Assistant pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Draft a grounded response — Security Operations Lead, Cybersecurity
Draft a grounded response for Security Operations Lead teams in Cybersecurity, delivered by the Q&A Assistant pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Prepare a review-ready answer — Security Operations Lead, Cybersecurity
Prepare a review-ready answer for Security Operations Lead teams in Cybersecurity, delivered by the Q&A Assistant pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Draft from supplied context — Security Operations Lead, Cybersecurity
Draft from supplied context for Security Operations Lead teams in Cybersecurity, delivered by the Drafting & Generation pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Follow configured behavior guidance — Security Operations Lead, Cybersecurity
Follow configured behavior guidance for Security Operations Lead teams in Cybersecurity, delivered by the Drafting & Generation pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Prepare copy for revision — Security Operations Lead, Cybersecurity
Prepare copy for revision for Security Operations Lead teams in Cybersecurity, delivered by the Drafting & Generation pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Summarize a supplied record — Security Operations Lead, Cybersecurity
Summarize a supplied record for Security Operations Lead teams in Cybersecurity, delivered by the Record Review pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Assess possible risk — Security Operations Lead, Cybersecurity
Assess possible risk for Security Operations Lead teams in Cybersecurity, delivered by the Record Review pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Flag items for human review — Security Operations Lead, Cybersecurity
Flag items for human review for Security Operations Lead teams in Cybersecurity, delivered by the Record Review pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Run a parameterized read query — Security Operations Lead, Cybersecurity
Run a parameterized read query for Security Operations Lead teams in Cybersecurity, delivered by the Data Query & Summary pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Summarize returned records — Security Operations Lead, Cybersecurity
Summarize returned records for Security Operations Lead teams in Cybersecurity, delivered by the Data Query & Summary pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Prepare a result-set overview — Security Operations Lead, Cybersecurity
Prepare a result-set overview for Security Operations Lead teams in Cybersecurity, delivered by the Data Query & Summary pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Check supplied context against policy — Security Operations Lead, Cybersecurity
Check supplied context against policy for Security Operations Lead teams in Cybersecurity, delivered by the Compliance Checker pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Surface potential policy issues — Security Operations Lead, Cybersecurity
Surface potential policy issues for Security Operations Lead teams in Cybersecurity, delivered by the Compliance Checker pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Recommend review items — Security Operations Lead, Cybersecurity
Recommend review items for Security Operations Lead teams in Cybersecurity, delivered by the Compliance Checker pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Assess supplied risk context — Security Operations Lead, Cybersecurity
Assess supplied risk context for Security Operations Lead teams in Cybersecurity, delivered by the Risk Assessment pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Explain assessment drivers — Security Operations Lead, Cybersecurity
Explain assessment drivers for Security Operations Lead teams in Cybersecurity, delivered by the Risk Assessment pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Recommend human review — Security Operations Lead, Cybersecurity
Recommend human review for Security Operations Lead teams in Cybersecurity, delivered by the Risk Assessment pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Query supplied record data — Security Operations Lead, Cybersecurity
Query supplied record data for Security Operations Lead teams in Cybersecurity, delivered by the Reconciliation Brief pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Summarize potential discrepancies — Security Operations Lead, Cybersecurity
Summarize potential discrepancies for Security Operations Lead teams in Cybersecurity, delivered by the Reconciliation Brief pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Prepare a reconciliation brief — Security Operations Lead, Cybersecurity
Prepare a reconciliation brief for Security Operations Lead teams in Cybersecurity, delivered by the Reconciliation Brief pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Assess a supplied exception — Security Operations Lead, Cybersecurity
Assess a supplied exception for Security Operations Lead teams in Cybersecurity, delivered by the Exception Review pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Summarize the assessment — Security Operations Lead, Cybersecurity
Summarize the assessment for Security Operations Lead teams in Cybersecurity, delivered by the Exception Review pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Recommend follow-up review — Security Operations Lead, Cybersecurity
Recommend follow-up review for Security Operations Lead teams in Cybersecurity, delivered by the Exception Review pattern from supplied context. Splunk and CrowdStrike are possible integration contexts that must be configured separately. Runs governed by policy, budgets, and the audit ledger.
Install is the easy part. Governance comes with it.
Library agents aren't scripts — they're governed identities. Installing one registers it with an owner, a budget, allowed models and actions, and a place in the audit ledger.
Choose from the catalog
Filter by your industry and role; every item lists the systems it connects to and the skills it invokes.
Wire it to your stack
Connectors, MCP servers, and OpenAPI imports — scoped by allowlists and DLP at the gateway.
Every run through the gates
Identity, budget, guardrails, policy, oversight — then a signed receipt in the Trust Ledger. On every plan.
Don't see the skill you need?
The visual skill builder ships new skills without code — or tell us what's missing and we'll point you at the closest governed pattern.