HomeOur Blog
Blog Posts

Introducing Evidence Graph

Amir Boldo

Amir Boldo

Aviv Nahum

Aviv Nahum

Table of contents
Evidence Graph — a diagram showing people, AI agents, and applications connected as objects and relationships in Above's investigation graph
Amir Boldo

Amir Boldo

Aviv Nahum

Aviv Nahum

Today we're launching Evidence Graph, a new way for Above to understand and investigate activity across people, agents, applications, and data.

Security teams have more visibility into their organizations than ever. Endpoint tools see processes and files, identity systems see authentication, SaaS applications record user activity, and a growing number of AI systems can expose prompts, tool calls, and agent actions.

The information is there, but it still arrives as separate events produced by separate systems. An investigator is left to work out which events refer to the same thing, how they relate, and whether the relationship changes what the activity means.

This problem gets harder as work becomes more agentic. An employee might ask an agent to complete a task, the agent authenticates to Salesforce, reads a particular field from an opportunity, pulls supporting context from Gong, creates a document, and sends the result somewhere else. The individual systems can each record their part of the sequence. None of them necessarily understands the whole thing.

Evidence Graph gives Above a way to build that understanding as the investigation unfolds.

The graph follows the evidence

Most graphs begin with an ontology: decide which kinds of objects exist, decide which relationships are allowed between them, and then map incoming data onto that structure.

That works well for things you can model in advance.

Investigations are less predictable.

The object that becomes important might be an employee, but it could just as easily be a company they applied to, an AI agent acting for them, an MCP server the agent connected through, a Salesforce opportunity, a field inside that opportunity, a paragraph in a call transcript, an attachment, a personal account, or a domain that appeared for the first time ten minutes ago.

With Evidence Graph, those objects do not all need to exist in a predefined security schema.

Above creates them when they become relevant.

If an employee applies to another company, Above can represent the employee, the application, and the company and connect them. If an agent later acts for that employee, the agent becomes another object. If it reads the pricing field of a Salesforce opportunity, the application, opportunity, field, and action become part of the same graph.

As more evidence arrives, the graph changes with it.

From events to objects

An event tells you that someone accessed Salesforce.

An investigation usually needs to know much more.

Which identity was used? Was the action performed directly by the person or by an agent acting for them? Which Salesforce object was accessed? Which account did it belong to? Which fields were read? What information did those fields contain? Where else did the same information appear? What happened to it afterwards?

Evidence Graph lets Above move between those levels of detail without forcing everything into one generic event format.

A Salesforce account can be an object. So can an opportunity underneath it and the pricing field inside that opportunity.

A Gong call can be an object. So can the customer discussed in the call and a specific piece of commercial information contained in the transcript.

An AI conversation can be an object. So can the agent, prompt, attachment, tool call, and system the agent reached.

This means Above can reason about the actual things involved in an investigation rather than only the applications that generated the telemetry.

The same thing can appear in many places

One of the harder parts of an investigation is realizing that two pieces of activity are about the same thing.

A company name appears in a job application. The same company appears in a LinkedIn conversation. Its domain later appears as an external destination.

A customer is referenced in a Gong transcript. The same customer has an account in Salesforce. A document written several hours later contains information derived from both.

Two employees may never communicate directly, but both interact with the same external organization, the same business object, or even the same external AI account.

Evidence Graph gives Above a place to resolve those relationships.

Instead of treating each appearance as unrelated text or metadata, Above can understand that they refer to the same underlying object and connect the surrounding activity to it.

That is often where an investigation starts to make sense.

Agents are part of the chain

Agents make this especially important because the actor performing an action and the person responsible for it are no longer necessarily the same thing.

An employee can delegate a task to an agent. That agent can use the employee's authority to access another application. It can read information, transform it, call another tool, and produce a new artifact.

Collapsing that sequence into “employee accessed application” throws away useful evidence.

Evidence Graph keeps the delegation chain intact.

Above can understand that an agent acts on behalf of a person, authenticates to an application, reads an object, extracts a field, creates another object, and shares it with a destination.

The human still matters. The agent now matters too.

As agents gain access to more of the enterprise, we think this distinction will become fundamental to how security teams understand activity.

Related: See Evidence Graph in action

Book a demo

No fixed path through an investigation

Traditional detection asks teams to decide what combinations of activity matter before they happen.

Define the data. Define the application. Define the destination. Define the threshold. Define the sequence that should trigger an alert.

That remains useful for deterministic controls, but it is a poor description of how many investigations actually develop.

You rarely know at the beginning which detail will become important later.

A recruiter contact can look irrelevant until the recruiter is connected to a competitor. A large Salesforce read can look unusual but benign until you learn which records were accessed. An AI agent using an MCP server can be ordinary automation until its downstream actions connect to an external destination.

Evidence Graph allows Above to follow those relationships rather than requiring the full path to be specified ahead of time.

The investigation determines which objects matter, and the graph gives Above more context for deciding where to look next.

A graph built from how work actually happens

This also means that useful security context is no longer limited to traditional security telemetry.

Modern work happens inside CRM records, documents, conversations, support tickets, code repositories, AI prompts, browser sessions, meeting transcripts, and dozens of SaaS applications. Some of that information is structured. Much of it is not.

Above can interpret those interactions as they happen and turn the relevant parts into objects and relationships that can participate in an investigation.

A sentence in a transcript can connect to an account in Salesforce. A company mentioned in an application can connect to an email domain. An agent action can connect a human identity to a system they never opened themselves.

Instead of flattening all of that context away, Evidence Graph preserves it.

A different foundation for investigations

We started building Above around insider risk because insider investigations expose this problem particularly well.

The person is usually authorized. The applications are legitimate. The individual actions often look normal. The risk only becomes visible when enough context is assembled around them.

But this is becoming a broader security problem.

Humans and agents are working across the same systems. Agents are inheriting identities and permissions. Business data moves through applications that were never designed to produce security telemetry. Increasingly, understanding what happened means understanding relationships between all of them.

Evidence Graph gives Above a foundation for doing that.

It can answer which person was involved, which agent acted for them, which identity was used, which application was reached, which object was touched, which field mattered, what information moved, what it was derived from, where it went, and which other people or organizations were connected to it.

And when the next piece of evidence introduces something we did not know mattered yet, the graph can grow around that too.

Evidence Graph is available today in Above.

Share

Contact us

You've made a great move.
We'll be in touch shortly

Close
Watch Now