Microsoft announced Project Perception on July 27. It is a new security system built around teams of AI agents, with a public preview scheduled for August 3. The agents are meant to look for possible attack paths, investigate what deserves attention, and help correct the problem.
That sounds like enterprise technology because it is. Still, the design offers a useful lesson for smaller companies. Good security depends on seeing the whole environment, understanding what the signals mean, deciding what matters, and taking a controlled action. Most security failures happen when one of those steps is missing.
Microsoft describes the system in its official Project Perception announcement. The product details will develop after preview users begin testing it. The operating model is already clear enough to examine without pretending every Windsor business needs to buy the newest security platform.
What Project Perception does
Project Perception gathers signals from identities, computers, applications, data, cloud systems, and AI tools. It builds shared context around those signals, then gives specialized agents different jobs.
- Red team agents search for paths an attacker could use to reach systems or data.
- Blue team agents investigate activity and decide which findings represent a meaningful risk.
- Green team agents strengthen defenses and carry out approved corrections.
Microsoft also says the system can choose among several AI models instead of forcing every task through one model. Its first announced scenario uses a specialized model for software vulnerability management. Microsoft reports a 96 percent result on the CyberGym evaluation and says this configuration reduces costs compared with the version already in market. Those are vendor results, not proof of how the preview will perform in every customer environment.
The important part is not the benchmark. Project Perception separates discovery, investigation, and correction while giving every agent the same security context. A small business can use that discipline even when people, rather than AI agents, perform most of the work.
Why context matters more than another alert
A security alert rarely arrives with the whole story. A sign in from a new location might be an employee travelling, a stolen password, or a routine connection through a different network. A device with old software may be a forgotten laptop in a drawer or the computer running the front counter.
The response changes with the context. Disabling the wrong account can stop a business during its busiest hour. Ignoring the right alert can leave an intruder connected. Security software needs accurate information about the device, user, application, location, and previous activity before it can help anyone make a sound decision.
This is where many small business environments are thin. Nobody has a current list of computers. Old employee accounts remain open. Cloud applications were added on company cards and never recorded. Backups run, but nobody has tested a restore. An AI agent cannot create reliable context from records that do not exist.
Faster security decisions only help when the system knows what it is looking at and has permission to take the right action.The five controls to put in place first
Before evaluating an agent based security platform, we would check five less glamorous controls. They determine whether any monitoring tool has a fair chance of protecting the business.
- A current inventory. Record every computer, mobile device, account, cloud service, business application, and network connection. Assign an owner and remove what the company no longer uses.
- Strong identity controls. Require multifactor authentication, remove shared accounts where possible, and close access as soon as an employee or contractor no longer needs it.
- Consistent updates and endpoint coverage. Know which systems receive updates, which ones cannot, and whether every active computer reports to the security console.
- Backups that have survived a restore test. A successful status icon proves a job ran. A restore test proves the business can recover its files and systems.
- An alert owner and an incident path. Decide who receives an alert, who can disable an account, who calls the business owner, and where actions are recorded.
Our guide to business cybersecurity services covers the surrounding controls, including account protection, managed updates, endpoint security, backups, and incident response. They are not the exciting part of an AI announcement. They are the part that keeps the company recoverable.
Automation needs boundaries
Project Perception is designed to connect findings with actions. That is where security automation becomes useful, and where careless permissions become dangerous. An automated system that can isolate a computer, disable an account, remove software, or change network access can also interrupt normal work if its conclusion is wrong.
Start with recommendations. Let the system assemble the evidence, explain the likely risk, and propose an action. A person reviews the first set of cases. The team records false alarms, missing context, and corrections instead of quietly clicking past them.
Repetitive actions can move toward automation after the evidence is strong. Give each action narrow permissions. Set a threshold for when approval is required. Keep a log of the signal, reasoning, approval, action, and result. Write down the rollback step before the automation goes live.
This is the same control pattern we use for business automation outside security. The system gets a defined job and the access required for that job. Consequential decisions stay with the right person until the workflow earns more trust through real use.
How to judge the preview without getting distracted
Once Project Perception enters public preview, polished demonstrations will be easy to find. A useful evaluation needs ordinary company data and awkward cases. Give the system a known software risk on a test computer, an alert tied to a former employee, and a device whose purpose is unclear. Watch whether it gathers the right evidence before suggesting a response.
Record how often the system identifies a real issue, how often it raises a false alarm, and how much time a technician spends checking its work. A fast answer that needs a full investigation from scratch has not saved much. A slower answer with relevant evidence, a sensible priority, and a safe proposed action may be far more useful.
Pay attention to what happens when information is missing. The agent should say what it cannot establish and stop before making a consequential change. Confidence is not a substitute for evidence. This matters most in small companies where one account or computer may support several important jobs.
We would also test the record left behind. A technician should be able to see the original signal, the context used, the recommendation, who approved it, what changed, and whether the action worked. If the audit trail cannot explain a decision after the fact, the automation is not ready for production access.
What Windsor businesses should do now
There is no reason to rebuild a security plan around a product that has not entered public preview yet. There is a good reason to borrow its sequence: collect signals, add context, investigate, act, and learn from the result.
Ask for the current device list. Check whether every active account uses multifactor authentication. Confirm that updates and endpoint protection cover the same list. Review the last backup restore test. Then look at who receives security alerts and what happens after one arrives.
If those answers are scattered across several people and inboxes, the next step is not an AI agent. It is a managed operating process. Our managed IT service brings inventory, monitoring, updates, account controls, backups, and support into one accountable system. New automation can then work from trustworthy information.
For businesses in Windsor, Essex County, London, Chatham and all of Southwestern Ontario, we can assess the current environment, close the basic gaps, and decide where automated investigation or response is sensible. The newest agent should improve a working security process, not become the process.