This discussion examines knowledge graphs and agent-driven artificial intelligence for identity and security detection. Wes Mullins of iCite, chief executive officer, participates at Neo4j GraphTalk San Francisco on theCUBE. John Furrier of theCUBE Research hosts a focused conversation on using Neo4j as a knowledge layer, architecting agent-driven workflows and consolidating human resources information system, Okta, Active Directory and software as a service telemetry to improve analyst productivity and detection fidelity.
Mullins draws on their experience in managed detection and response, MDR and security operations center, SOC roles to describe building a canonical identity by combining time series, relational and graph data. They explain how agent-driven AI supports normalized identity data and real-time context, and how integrating human resources information system, HRIS signals with Okta and legacy Active Directory into a Neo4j graph produces lower-volume higher-efficacy detections and accelerates SOC investigations. They describe how graph-based lineage, explainability and agent orchestration reduce false positives and accelerate incident response while preserving necessary human oversight.
Key takeaways emphasize deterministic knowledge layers, real-time context and normalized identity telemetry for improved security analytics and identity security workflows.
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
theCUBE + NYSE Wired: Data + AI: Turning Data Into Knowledge for Autonomous Systems. If you don’t think you received an email check your
spam folder.
Sign in to theCUBE + NYSE Wired: Data + AI: Turning Data Into Knowledge for Autonomous Systems.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open the link to automatically sign into the site.
Register for theCUBE + NYSE Wired: Data + AI: Turning Data Into Knowledge for Autonomous Systems
Please fill out the information below. You will receive an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for theCUBE + NYSE Wired: Data + AI: Turning Data Into Knowledge for Autonomous Systems.
Thanks for confirming your account. Now you can access theCUBE + NYSE Wired: Data + AI: Turning Data Into Knowledge for Autonomous Systems with this email address.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
theCUBE + NYSE Wired: Data + AI: Turning Data Into Knowledge for Autonomous Systems. If you don’t think you received an email check your
spam folder.
Sign in to theCUBE + NYSE Wired: Data + AI: Turning Data Into Knowledge for Autonomous Systems.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open the link to automatically sign into the site.
Sign in to gain access to theCUBE + NYSE Wired: Data + AI: Turning Data Into Knowledge for Autonomous Systems
Please sign in with LinkedIn to continue to theCUBE + NYSE Wired: Data + AI: Turning Data Into Knowledge for Autonomous Systems. Signing in with LinkedIn ensures a professional environment.
Are you sure you want to remove access rights for this user?
Details
Manage Access
email address
Community Invitation
Wes Mullins, iCite
This discussion examines knowledge graphs and agent-driven artificial intelligence for identity and security detection. Wes Mullins of iCite, chief executive officer, participates at Neo4j GraphTalk San Francisco on theCUBE. John Furrier of theCUBE Research hosts a focused conversation on using Neo4j as a knowledge layer, architecting agent-driven workflows and consolidating human resources information system, Okta, Active Directory and software as a service telemetry to improve analyst productivity and detection fidelity.
Mullins draws on their experience in managed detection and response, MDR and security operations center, SOC roles to describe building a canonical identity by combining time series, relational and graph data. They explain how agent-driven AI supports normalized identity data and real-time context, and how integrating human resources information system, HRIS signals with Okta and legacy Active Directory into a Neo4j graph produces lower-volume higher-efficacy detections and accelerates SOC investigations. They describe how graph-based lineage, explainability and agent orchestration reduce false positives and accelerate incident response while preserving necessary human oversight.
Key takeaways emphasize deterministic knowledge layers, real-time context and normalized identity telemetry for improved security analytics and identity security workflows.
>> Welcome back. I'm John Furrier, your host of theCUBE. We are here in San Francisco for GraphTalk with Neo4j in San Francisco. We have a September event in New York City. I'll be there as well. Of course, we have our CUBE's New York Stock Exchange studio getting all the action in San Francisco and New York, where all the top practitioners are here. Talk about graph databases, graph systems, knowledge graphs, ontologies. This is the hottest area in AI. If you're in the data software layers that are evolving around the huge build-out in AI push, this is where it all's happened. Our next guest is Wes Mullins, CEO of Icite, a seed-based pre-series A startup, really cracking the code on AI and knowledge layer, semantic layer around security data, around identity and detection. And of course, once you have that done, you can move very fast. This is a new model in AI. Wes, thanks for coming on.
Wes Mullins
>> Appreciate you having me. Grateful to be here.
John Furrier
>> I love the fact that you're in a startup. So first question is with AI, it's so easy now to do startups. You just can be a couple people, you don't need the big money, but you're in security, huge market opportunity. Explain what you guys do. What was the origination story? What are you building?
Wes Mullins
>> Yeah, so background was at an MDR provider, so managed a lot of SIEMs, a lot of SOAR combinations. And through the years, basically the metrics for identity were really the only key indicator that was going the wrong way. Endpoint was doing really well. Cloud was doing really well. Once you had the Wiz's and the Lacework's and the Orca's, network was in a good place. But as COVID happened, the world went SASE, world went zero trust. That concept of a firewall in your network where you just had active directory got skewed. And people started writing hundreds of detections for identities, extremely high volumetric alert, but very, very high false positive. So we saw that at that company and we decided to go build something to try to solve for it, really to help the analysts out. So our product at Icite really tries to combine the concept of time series data, relational data, and craft data to create a centralized singularity of an identity that we call a canonical ID. So who is Wes in this system versus that system versus a local account versus a service account, maybe versus an API key that he owns. It allows us to create very, very low volume detections, extremely high efficacy, and analysts in the SOC have the ability to get data that they otherwise would have to rely on another team to go and get.
John Furrier
>> Okay. So on the problem that you saw, what is the key thing? Because obviously, AI is going to give you things that are going to make you go faster, but what is the core problem that you saw? And what's the before and old way, new way outcome?
Wes Mullins
>> Let's say it's two things, context and speed. So there's anyone who's got a MDR provider, MSSP, a SOC, a SIEM, they get a ton of alerts. Those alerts don't have context. They don't know who Wes is. They don't know what he has access to, how he got that access. Is he an employee? Is he a contractor? Is he full-time? Is he part-time? Where does he live? Where should he be logging in from? What types of devices are he logging in from?
John Furrier
>> What patterns has he done in the past?
Wes Mullins
>> Behavior. Behavior is a big thing. We do a lot of behavior, a lot of baseline, a lot of trending through 30, 60, 90, six months. But then there's also the aspect of speed in the SOC. Most individuals in the SOC, they can pivot to their CrowdStrike, their Wiz, their Palo Alto, their Check Point, their Cisco. They're never admins in Okta. They're never admins in Microsoft Active Directory. So they're reliant on other teams to get information they need to be successful. We dabbled in that space with SOAR, trying to hook up a little bit of the context there, but a lot of it becomes flat files. It's out of date the second that it's there. So we do real-time context analysis. And we can tie a SAML token to a OWA token, to a user's email, to a local account that's inside of GitHub that generates a log that has nothing to do with the email. And that's really what we want to be able to do.
John Furrier
>> All right. So what are some of the results you're seeing? What's the feedback you're getting? What's the key secret sauce? Graphs play a big role. Obviously, you're here at GraphTalk. This is where, again, a lot of the alpha and alpha engineers are here. People who are really taking advantage of it, you've seen this first wave of knowledge graphs that aren't your yesterday's version of a knowledge system. It's a whole nother ... I mean, it's a data structure for AI. That's the way I like to look at it. And it's compatible on the computer science side as well. So what's the secret sauce in all this?
Wes Mullins
>> I would say for us, because we are very agent driven, not to go on the hoopla of agents, but I think it's reality now. It's not just marketing. It's not theater. So having a knowledge layer to where your agent's success is based off of how you feed it data, what your analogy is, what your memory is, and the data that you give it. So we build that in graph. We use Neo4j, that is our knowledge layer. And our agents that are trained in time series relational and graph data, and then our orchestrator, that is how they do what they do. You can't just take an agent and say, "Here, go to Okta, go find all these compromised identities." Or, "Here's a bunch of data that's over here in a regular SQL database."
John Furrier
>> They technically could go and poke around, but they're not going to actually do anything.
Wes Mullins
>> They could.
John Furrier
>> That's just taking up space.
Wes Mullins
>> When you give an agent that type of data, that's how you encourage hallucinations. And what you want to be able to do is give them data that they can traverse in a very deterministic manner that is very deliberate that has guardrails. And that is really how the core of what the Icite product does what it does is because of that ability to have the knowledge layer, have our agents traverse it. We consume all of our customers' data, but we normalize it. We massage it in our format that we want, and that's how our agents are able to do it.
John Furrier
>> So you basically build a brain.
Wes Mullins
>> 100%.
John Furrier
>> And you give all the elements, here's your time series.
Wes Mullins
>> Plug in.
John Furrier
>> And then it learns and then you probably got techniques behind it.
Wes Mullins
>> Oh, yeah.
John Furrier
>> What other supporting data are you feeding the brain? Obviously, there's real-time data. You have potentially other things you're mapping into the identity patterns.
Wes Mullins
>> Not to say something cliche, but the more data we get, the better. So we like to start with the HRIS. So your Paylocity, your Workday, your SAP. It is the true core concept of, "Is someone an employee? Are they getting a paycheck?" And a lot of places will skip that because of complexities on getting that data and risk in privacy.
John Furrier
>> Yeah. Do they get a W-2?
Wes Mullins
>> Yeah.
John Furrier
>> What's their employee number?
Wes Mullins
>> Are they enabled? But then there's a lot of the big threats that happen now aren't necessarily just from bad actors. It's malicious employees. People that are just-
John Furrier
>> Insider threat.
Wes Mullins
>> They're leaving. Insider threat is extremely prevalent in the enterprise. So knowing if someone's given their two-week notice and being able to turn that flag on from Workday and know, "Oh, well, they've submitted their notice. We now need to monitor them differently the next two weeks than we have in the previous six months. And what's that deviation in that timeframe?"
Obviously, we want all the identity data that we can get that's coming from Okta, Ontra ping. We want all your SaaS apps. We actually get a lot of value out of people that still have legacy on-prem Active Directory. So we have a collector, we'll ship you a binary. Most people have no idea what's going on in AD in 2026, because they've bridged up to the cloud, but they've got that payroll app that was written in Java 15 years ago that still runs and it's hidden AD. But being able to tie that back to a workflow that's all about-
John Furrier
>> I men, to your point, all data is data for you. You don't care.
Wes Mullins
>> It's all important.
John Furrier
>> Okay. You got the payroll using Active Director, little legacy or some IOT app running Windows, whatever, for workgroup. You need to know that.
Wes Mullins
>> Well, the more data you have, the more you can build on the graph. And really, the visualizations start to stick out. And you can see the patterns, especially when if a company has a mature group structure, policies, procedures, who goes in what groups, titles, you build these profiles. It's like a CIA person profiling someone. You can build these profiles for HR versus R&D versus networking. And spotting deviations in that becomes a lot easier the more you have to build that baseline.
John Furrier
>> Well, you got a startup being the founder, CEO. You're there. You made a bet on Neo4j. What was the reason? Why Neo4j?
Wes Mullins
>> Speed.
John Furrier
>> That's a pretty significant part of your architecture.
Wes Mullins
>> I don't want to sit up here and act like I'm the smartest person in the room. I hired really smart guys. And I had a data guy who worked with me in my previous company, and we went down a route there. Cloud route, we were all AWS. Everyone kind of knows what the typical stack is. And as we started to look at the roadmap and we saw how fast things were happening with agents, it was brought up like, "Look, we're going to have to go the agent route. It's the only way the platform's going to really scale, and graph is built to allow us to do this. If we don't do it now, it's going to be really hard to do in a year or two."
John Furrier
>> So you really built from the ground up.
Wes Mullins
>> So we built from the ground up with the expectation that agents were going to become a real thing, and they have just in the past 16 months. Yeah.
John Furrier
>> It's funny, deterministic is back, right?
Wes Mullins
>> It is.
John Furrier
>> First, non-deterministic was the way. "Oh, yeah, you don't know the answer." Well, that's what it spits out an answer, either it's hallucinated or not. But it's interesting, all the agents need deterministic behavior because gut governance.
Wes Mullins
>> Relationships.
John Furrier
>> And that's a feature, that's not a bug. You can take non-deterministic and make it deterministic and say, "Physical AI, robotics, you got to have safety. Don't do that. Be deterministic."
Wes Mullins
>> When you look at just things in your day-to-day life, how you do banking, how you cook in the kitchen, a recipe, it's all about a relationship. And once you stop thinking about tables and how things are in tables and you start thinking about relationships, graph becomes very easy and it becomes kind of a very natural thing. And going from a 300-line SQL statement to a 22-line Cypher query to accomplish the same thing and half the speed is, that's value.
John Furrier
>> Yeah. And also, it is super compatible from the CS, computer science perspective with AI and DeepMind and just overall thinking of what graphs do in any computer science theory, whether it's building compilers or operating systems. You've seen graphs been around for years.
Wes Mullins
>> Right, right.
John Furrier
>> So it's not new, but in this high speed game of thinking like a brain, I mean, all the AI has changed the user interface to the user. So it's like GUIs are going to go away. You've got to see natural language.
Wes Mullins
>> Headless.
John Furrier
>> Okay, you need to have full horizontal scale of data. You got to have ontology, you got to have data structures that are going to be compatible and fast, low latency that can do inference and not big GPU, unless you're doing training. So it's clear there's compatibility. The question people have is, "Okay, I'm getting the big picture now. What do I do? Do I choose this or that? And I got an open source graph, but it doesn't scale. It doesn't after a few nodes. It shits the bed." Those kinds of things that are happening. I shouldn't have said that on the camera, but we're in GraphTalk, it's tech talk. But when things crash and burn, you don't want to be out over your skis and say, "Well, I just got now 200 nodes and it crashes and then we've got two million nodes."
Wes Mullins
>> I mean, in my mind, it's go what is battle proven and that's out there. And yeah, there are a lot of up and comers that are there. I mean, Neo's battle tested. It is there. It will scale. It is going to continue to expand. Some of the amazing talks we saw today, I mean, they're releasing faster than I think a lot of the world's ready to keep up with.
John Furrier
>> And the community, what I love, I was talking to Philip about this because we just saw each other in France, and I wanted to get his perspective because there's a euphoria in the graph community because it's almost like relief and freedom. Like, "Okay, I'm not the grind on tables." He calls it 3D.
Wes Mullins
>> We're finally real. People are accepting us.
John Furrier
>> But then there's a third thing where there's self-actualization of data nerds actually moving the needle on company's most important projects. And they have to kind of sandbag it. They have to sneak it in there. "Oh, look what I just did by accident." But no one really is getting it, but now everyone's starting to get it. So you're starting to see the community of practitioners saying, "Wow, this is the secret sauce."
And that's why I wanted to ask you about your company, because you're making a bet. You're tackling a huge market opportunity where you can consolidate multiple data categories into one single pane of query prompt and provide that as a service at a very low latency. That's a game changer. So you got a knowledge there. This the center of your piece there, centerpiece of your value proposition.
Wes Mullins
>> Yeah. It's the single identity and the ability to track all identities and all relationships to identity.
John Furrier
>> Talk about the company. Who's on the team? How big are you guys? Do you have customers?
Wes Mullins
>> Yeah.
John Furrier
>> Obviously, I'm sure it's going to be a series A hot prospect soon because security, I'm expecting a huge event at Black Hat. Obviously, RSA was big this year again.
Wes Mullins
>> Oh, yeah.
John Furrier
>> And a lot of people were talking about everyone's staying in their lane. I've seen many examples of stuff getting through CrowdStrike and Palo Alto and malware landing and then activating all the time.
Wes Mullins
>> And it's only going to get worse with all the new models coming out and all the new offensive security tools. So we're a small group, so we're seed stage. We got a couple customers. We're a team of eight, so we're really small. I'm the only non-engineer, even though I still try to commit code, although they don't like it when I do it, but I'm the CFO, the CTO, the CEO, the therapist on the side.
John Furrier
>> You do your celebrity coding. I call it celebrity coding.
Wes Mullins
>> Yeah. Every now and then, I'll do a Slackbot. It's world I've got myself.
John Furrier
>> It's like beer pong, celebrity shot, my kids are playing.
Wes Mullins
>> We're all over the US, so we're based in the US. We're a remote workforce. Try to hire talent where talent is, not where talent lives.
John Furrier
>> And what's your goals? Obviously, you're going to get momentum, you have momentum now. Funding is eminent. What are you looking for in a partner? What's the culture like? I should say. How would you describe the culture?
Wes Mullins
>> Heavy tech culture. We're nerds. We've all grew up in what I would say the cybersecurity background. So we are very pro analyst, pro-incident responder, pro threat hunter. We've all lived in it. We've gone through the stress, and that space is crowded. And there's a lot of tools that tell everyone that they're going to make their life easier. In a lot of cases, it just becomes another complex tool.
John Furrier
>> Yeah, another tool, another platform. Platforms are emerging. And the customers, they cannot not buy, they have to buy everything. The threats are coming out of massive .
Wes Mullins
>> Well, you mentioned it earlier, the UI and the interface is going to go away. And I think that's really where we're probably going to head down and want to continue to partner with people that want to run autonomous systems that are okay with headless. Let's expose the Icite MCP. We have our own MCP. It gives you everything from the graph, everything from the record, everything from the baseline, everything from the blast radius, and bake it into all of the other stuff that your org already has.
John Furrier
>> Yeah. I mean, the thing that I think about, what I like about what you're doing is that there's so many wins because if you crack the code, the benefits are multifold. For example, lineage, explainability, tracking, tracing, reports. You can run an agent to say, "Oh, we had a little blip. We took care of it. Little incident, quarantine, let's shut down that segment of the network. It's all done, and here's the report." That's coming, right? Or is that there now?
Wes Mullins
>> It's funny you say that as one of our current customers, we actually got on with them and we ended up onboarding some of their cloud team because they were doing some NHI stuff and service accounts and ended up having an outage. And we have a natural language interface. You go in, you ask the questions. And you basically walked us through going in and saying, "Hey, who took down Prod yesterday at 5:00?"
And what it'll do though is because it's got all of those relationships, it pulled all the commits that happened in GitHub, everything that went with the release inside of AWS, all the CloudTrail errors that were there, tied it all back to a single person, but they had already given us their Zoom logs. So then we could see, "Oh, these three people jumped on an unscheduled Zoom together that wasn't on their calendar." And then 10 minutes later, another code push happened and it just lays out the entire timeline.
John Furrier
>> It's like the chalk.
Wes Mullins
>> It sounds scary.
John Furrier
>> The body of the chalk is on the ground. You're like, "Okay, six feet tall."
Wes Mullins
>> That's not our use case, but that's an example.
John Furrier
>> If that's an example, you would've missed it. That would've been a miss.
Wes Mullins
>> They would've spent probably two days trying to figure out what actually happened and the individual ... It's large org, lots of code getting pushed.
John Furrier
>> Yeah, this is where the whole job going away, BS hits, because that is where you need humans in there. The investigative-
Wes Mullins
>> 100%.
John Furrier
>> I was talking to a friend who's in cybersecurity and he drew a joke. He's like, "You're kidding me? We're hiring more gamers because the new use cases, they're playing multiplayer gaming with all the agents. It's an orchestration game. It's a human intelligence game. And the grunt work just in the grind goes away." That's where the-
Wes Mullins
>> Yeah. You become more focused, more precision.
John Furrier
>> Well, Wes, congratulations on your startup opportunity. I wish your team the best of luck. Thanks for coming in-
Wes Mullins
>> Absolutely....
John Furrier
>> sharing on theCUBE here. Hopefully some investors watching want to give you outreach. Again, when you have a new way of thinking, you misunderstood for a long time until people get it, so I know how it feels.
Wes Mullins
>> We'll get graphed out.
John Furrier
>> We'll write a graph for that. Thanks for coming up. Appreciate it.
Wes Mullins
>> Yeah, absolutely. Thank you.
John Furrier
>> I'm John Furrier with the theCUBE. We're at the Neo4j GraphTalk in San Francisco. We got one coming up in New York City in September. Thanks for watching. Clip, we have a video-
>> Welcome back. I'm John Furrier, your host of theCUBE. We are here in San Francisco for GraphTalk with Neo4j in San Francisco. We have a September event in New York City. I'll be there as well. Of course, we have our CUBE's New York Stock Exchange studio getting all the action in San Francisco and New York, where all the top practitioners are here. Talk about graph databases, graph systems, knowledge graphs, ontologies. This is the hottest area in AI. If you're in the data software layers that are evolving around the huge build-out in AI push, this is where it all's happened. Our next guest is Wes Mullins, CEO of Icite, a seed-based pre-series A startup, really cracking the code on AI and knowledge layer, semantic layer around security data, around identity and detection. And of course, once you have that done, you can move very fast. This is a new model in AI. Wes, thanks for coming on.
Wes Mullins
>> Appreciate you having me. Grateful to be here.
John Furrier
>> I love the fact that you're in a startup. So first question is with AI, it's so easy now to do startups. You just can be a couple people, you don't need the big money, but you're in security, huge market opportunity. Explain what you guys do. What was the origination story? What are you building?
Wes Mullins
>> Yeah, so background was at an MDR provider, so managed a lot of SIEMs, a lot of SOAR combinations. And through the years, basically the metrics for identity were really the only key indicator that was going the wrong way. Endpoint was doing really well. Cloud was doing really well. Once you had the Wiz's and the Lacework's and the Orca's, network was in a good place. But as COVID happened, the world went SASE, world went zero trust. That concept of a firewall in your network where you just had active directory got skewed. And people started writing hundreds of detections for identities, extremely high volumetric alert, but very, very high false positive. So we saw that at that company and we decided to go build something to try to solve for it, really to help the analysts out. So our product at Icite really tries to combine the concept of time series data, relational data, and craft data to create a centralized singularity of an identity that we call a canonical ID. So who is Wes in this system versus that system versus a local account versus a service account, maybe versus an API key that he owns. It allows us to create very, very low volume detections, extremely high efficacy, and analysts in the SOC have the ability to get data that they otherwise would have to rely on another team to go and get.
John Furrier
>> Okay. So on the problem that you saw, what is the key thing? Because obviously, AI is going to give you things that are going to make you go faster, but what is the core problem that you saw? And what's the before and old way, new way outcome?
Wes Mullins
>> Let's say it's two things, context and speed. So there's anyone who's got a MDR provider, MSSP, a SOC, a SIEM, they get a ton of alerts. Those alerts don't have context. They don't know who Wes is. They don't know what he has access to, how he got that access. Is he an employee? Is he a contractor? Is he full-time? Is he part-time? Where does he live? Where should he be logging in from? What types of devices are he logging in from?
John Furrier
>> What patterns has he done in the past?
Wes Mullins
>> Behavior. Behavior is a big thing. We do a lot of behavior, a lot of baseline, a lot of trending through 30, 60, 90, six months. But then there's also the aspect of speed in the SOC. Most individuals in the SOC, they can pivot to their CrowdStrike, their Wiz, their Palo Alto, their Check Point, their Cisco. They're never admins in Okta. They're never admins in Microsoft Active Directory. So they're reliant on other teams to get information they need to be successful. We dabbled in that space with SOAR, trying to hook up a little bit of the context there, but a lot of it becomes flat files. It's out of date the second that it's there. So we do real-time context analysis. And we can tie a SAML token to a OWA token, to a user's email, to a local account that's inside of GitHub that generates a log that has nothing to do with the email. And that's really what we want to be able to do.
John Furrier
>> All right. So what are some of the results you're seeing? What's the feedback you're getting? What's the key secret sauce? Graphs play a big role. Obviously, you're here at GraphTalk. This is where, again, a lot of the alpha and alpha engineers are here. People who are really taking advantage of it, you've seen this first wave of knowledge graphs that aren't your yesterday's version of a knowledge system. It's a whole nother ... I mean, it's a data structure for AI. That's the way I like to look at it. And it's compatible on the computer science side as well. So what's the secret sauce in all this?
Wes Mullins
>> I would say for us, because we are very agent driven, not to go on the hoopla of agents, but I think it's reality now. It's not just marketing. It's not theater. So having a knowledge layer to where your agent's success is based off of how you feed it data, what your analogy is, what your memory is, and the data that you give it. So we build that in graph. We use Neo4j, that is our knowledge layer. And our agents that are trained in time series relational and graph data, and then our orchestrator, that is how they do what they do. You can't just take an agent and say, "Here, go to Okta, go find all these compromised identities." Or, "Here's a bunch of data that's over here in a regular SQL database."
John Furrier
>> They technically could go and poke around, but they're not going to actually do anything.
Wes Mullins
>> They could.
John Furrier
>> That's just taking up space.
Wes Mullins
>> When you give an agent that type of data, that's how you encourage hallucinations. And what you want to be able to do is give them data that they can traverse in a very deterministic manner that is very deliberate that has guardrails. And that is really how the core of what the Icite product does what it does is because of that ability to have the knowledge layer, have our agents traverse it. We consume all of our customers' data, but we normalize it. We massage it in our format that we want, and that's how our agents are able to do it.
John Furrier
>> So you basically build a brain.
Wes Mullins
>> 100%.
John Furrier
>> And you give all the elements, here's your time series.
Wes Mullins
>> Plug in.
John Furrier
>> And then it learns and then you probably got techniques behind it.
Wes Mullins
>> Oh, yeah.
John Furrier
>> What other supporting data are you feeding the brain? Obviously, there's real-time data. You have potentially other things you're mapping into the identity patterns.
Wes Mullins
>> Not to say something cliche, but the more data we get, the better. So we like to start with the HRIS. So your Paylocity, your Workday, your SAP. It is the true core concept of, "Is someone an employee? Are they getting a paycheck?" And a lot of places will skip that because of complexities on getting that data and risk in privacy.
John Furrier
>> Yeah. Do they get a W-2?
Wes Mullins
>> Yeah.
John Furrier
>> What's their employee number?
Wes Mullins
>> Are they enabled? But then there's a lot of the big threats that happen now aren't necessarily just from bad actors. It's malicious employees. People that are just-
John Furrier
>> Insider threat.
Wes Mullins
>> They're leaving. Insider threat is extremely prevalent in the enterprise. So knowing if someone's given their two-week notice and being able to turn that flag on from Workday and know, "Oh, well, they've submitted their notice. We now need to monitor them differently the next two weeks than we have in the previous six months. And what's that deviation in that timeframe?"
Obviously, we want all the identity data that we can get that's coming from Okta, Ontra ping. We want all your SaaS apps. We actually get a lot of value out of people that still have legacy on-prem Active Directory. So we have a collector, we'll ship you a binary. Most people have no idea what's going on in AD in 2026, because they've bridged up to the cloud, but they've got that payroll app that was written in Java 15 years ago that still runs and it's hidden AD. But being able to tie that back to a workflow that's all about-
John Furrier
>> I men, to your point, all data is data for you. You don't care.
Wes Mullins
>> It's all important.
John Furrier
>> Okay. You got the payroll using Active Director, little legacy or some IOT app running Windows, whatever, for workgroup. You need to know that.
Wes Mullins
>> Well, the more data you have, the more you can build on the graph. And really, the visualizations start to stick out. And you can see the patterns, especially when if a company has a mature group structure, policies, procedures, who goes in what groups, titles, you build these profiles. It's like a CIA person profiling someone. You can build these profiles for HR versus R&D versus networking. And spotting deviations in that becomes a lot easier the more you have to build that baseline.
John Furrier
>> Well, you got a startup being the founder, CEO. You're there. You made a bet on Neo4j. What was the reason? Why Neo4j?
Wes Mullins
>> Speed.
John Furrier
>> That's a pretty significant part of your architecture.
Wes Mullins
>> I don't want to sit up here and act like I'm the smartest person in the room. I hired really smart guys. And I had a data guy who worked with me in my previous company, and we went down a route there. Cloud route, we were all AWS. Everyone kind of knows what the typical stack is. And as we started to look at the roadmap and we saw how fast things were happening with agents, it was brought up like, "Look, we're going to have to go the agent route. It's the only way the platform's going to really scale, and graph is built to allow us to do this. If we don't do it now, it's going to be really hard to do in a year or two."
John Furrier
>> So you really built from the ground up.
Wes Mullins
>> So we built from the ground up with the expectation that agents were going to become a real thing, and they have just in the past 16 months. Yeah.
John Furrier
>> It's funny, deterministic is back, right?
Wes Mullins
>> It is.
John Furrier
>> First, non-deterministic was the way. "Oh, yeah, you don't know the answer." Well, that's what it spits out an answer, either it's hallucinated or not. But it's interesting, all the agents need deterministic behavior because gut governance.
Wes Mullins
>> Relationships.
John Furrier
>> And that's a feature, that's not a bug. You can take non-deterministic and make it deterministic and say, "Physical AI, robotics, you got to have safety. Don't do that. Be deterministic."
Wes Mullins
>> When you look at just things in your day-to-day life, how you do banking, how you cook in the kitchen, a recipe, it's all about a relationship. And once you stop thinking about tables and how things are in tables and you start thinking about relationships, graph becomes very easy and it becomes kind of a very natural thing. And going from a 300-line SQL statement to a 22-line Cypher query to accomplish the same thing and half the speed is, that's value.
John Furrier
>> Yeah. And also, it is super compatible from the CS, computer science perspective with AI and DeepMind and just overall thinking of what graphs do in any computer science theory, whether it's building compilers or operating systems. You've seen graphs been around for years.
Wes Mullins
>> Right, right.
John Furrier
>> So it's not new, but in this high speed game of thinking like a brain, I mean, all the AI has changed the user interface to the user. So it's like GUIs are going to go away. You've got to see natural language.
Wes Mullins
>> Headless.
John Furrier
>> Okay, you need to have full horizontal scale of data. You got to have ontology, you got to have data structures that are going to be compatible and fast, low latency that can do inference and not big GPU, unless you're doing training. So it's clear there's compatibility. The question people have is, "Okay, I'm getting the big picture now. What do I do? Do I choose this or that? And I got an open source graph, but it doesn't scale. It doesn't after a few nodes. It shits the bed." Those kinds of things that are happening. I shouldn't have said that on the camera, but we're in GraphTalk, it's tech talk. But when things crash and burn, you don't want to be out over your skis and say, "Well, I just got now 200 nodes and it crashes and then we've got two million nodes."
Wes Mullins
>> I mean, in my mind, it's go what is battle proven and that's out there. And yeah, there are a lot of up and comers that are there. I mean, Neo's battle tested. It is there. It will scale. It is going to continue to expand. Some of the amazing talks we saw today, I mean, they're releasing faster than I think a lot of the world's ready to keep up with.
John Furrier
>> And the community, what I love, I was talking to Philip about this because we just saw each other in France, and I wanted to get his perspective because there's a euphoria in the graph community because it's almost like relief and freedom. Like, "Okay, I'm not the grind on tables." He calls it 3D.
Wes Mullins
>> We're finally real. People are accepting us.
John Furrier
>> But then there's a third thing where there's self-actualization of data nerds actually moving the needle on company's most important projects. And they have to kind of sandbag it. They have to sneak it in there. "Oh, look what I just did by accident." But no one really is getting it, but now everyone's starting to get it. So you're starting to see the community of practitioners saying, "Wow, this is the secret sauce."
And that's why I wanted to ask you about your company, because you're making a bet. You're tackling a huge market opportunity where you can consolidate multiple data categories into one single pane of query prompt and provide that as a service at a very low latency. That's a game changer. So you got a knowledge there. This the center of your piece there, centerpiece of your value proposition.
Wes Mullins
>> Yeah. It's the single identity and the ability to track all identities and all relationships to identity.
John Furrier
>> Talk about the company. Who's on the team? How big are you guys? Do you have customers?
Wes Mullins
>> Yeah.
John Furrier
>> Obviously, I'm sure it's going to be a series A hot prospect soon because security, I'm expecting a huge event at Black Hat. Obviously, RSA was big this year again.
Wes Mullins
>> Oh, yeah.
John Furrier
>> And a lot of people were talking about everyone's staying in their lane. I've seen many examples of stuff getting through CrowdStrike and Palo Alto and malware landing and then activating all the time.
Wes Mullins
>> And it's only going to get worse with all the new models coming out and all the new offensive security tools. So we're a small group, so we're seed stage. We got a couple customers. We're a team of eight, so we're really small. I'm the only non-engineer, even though I still try to commit code, although they don't like it when I do it, but I'm the CFO, the CTO, the CEO, the therapist on the side.
John Furrier
>> You do your celebrity coding. I call it celebrity coding.
Wes Mullins
>> Yeah. Every now and then, I'll do a Slackbot. It's world I've got myself.
John Furrier
>> It's like beer pong, celebrity shot, my kids are playing.
Wes Mullins
>> We're all over the US, so we're based in the US. We're a remote workforce. Try to hire talent where talent is, not where talent lives.
John Furrier
>> And what's your goals? Obviously, you're going to get momentum, you have momentum now. Funding is eminent. What are you looking for in a partner? What's the culture like? I should say. How would you describe the culture?
Wes Mullins
>> Heavy tech culture. We're nerds. We've all grew up in what I would say the cybersecurity background. So we are very pro analyst, pro-incident responder, pro threat hunter. We've all lived in it. We've gone through the stress, and that space is crowded. And there's a lot of tools that tell everyone that they're going to make their life easier. In a lot of cases, it just becomes another complex tool.
John Furrier
>> Yeah, another tool, another platform. Platforms are emerging. And the customers, they cannot not buy, they have to buy everything. The threats are coming out of massive .
Wes Mullins
>> Well, you mentioned it earlier, the UI and the interface is going to go away. And I think that's really where we're probably going to head down and want to continue to partner with people that want to run autonomous systems that are okay with headless. Let's expose the Icite MCP. We have our own MCP. It gives you everything from the graph, everything from the record, everything from the baseline, everything from the blast radius, and bake it into all of the other stuff that your org already has.
John Furrier
>> Yeah. I mean, the thing that I think about, what I like about what you're doing is that there's so many wins because if you crack the code, the benefits are multifold. For example, lineage, explainability, tracking, tracing, reports. You can run an agent to say, "Oh, we had a little blip. We took care of it. Little incident, quarantine, let's shut down that segment of the network. It's all done, and here's the report." That's coming, right? Or is that there now?
Wes Mullins
>> It's funny you say that as one of our current customers, we actually got on with them and we ended up onboarding some of their cloud team because they were doing some NHI stuff and service accounts and ended up having an outage. And we have a natural language interface. You go in, you ask the questions. And you basically walked us through going in and saying, "Hey, who took down Prod yesterday at 5:00?"
And what it'll do though is because it's got all of those relationships, it pulled all the commits that happened in GitHub, everything that went with the release inside of AWS, all the CloudTrail errors that were there, tied it all back to a single person, but they had already given us their Zoom logs. So then we could see, "Oh, these three people jumped on an unscheduled Zoom together that wasn't on their calendar." And then 10 minutes later, another code push happened and it just lays out the entire timeline.
John Furrier
>> It's like the chalk.
Wes Mullins
>> It sounds scary.
John Furrier
>> The body of the chalk is on the ground. You're like, "Okay, six feet tall."
Wes Mullins
>> That's not our use case, but that's an example.
John Furrier
>> If that's an example, you would've missed it. That would've been a miss.
Wes Mullins
>> They would've spent probably two days trying to figure out what actually happened and the individual ... It's large org, lots of code getting pushed.
John Furrier
>> Yeah, this is where the whole job going away, BS hits, because that is where you need humans in there. The investigative-
Wes Mullins
>> 100%.
John Furrier
>> I was talking to a friend who's in cybersecurity and he drew a joke. He's like, "You're kidding me? We're hiring more gamers because the new use cases, they're playing multiplayer gaming with all the agents. It's an orchestration game. It's a human intelligence game. And the grunt work just in the grind goes away." That's where the-
Wes Mullins
>> Yeah. You become more focused, more precision.
John Furrier
>> Well, Wes, congratulations on your startup opportunity. I wish your team the best of luck. Thanks for coming in-
Wes Mullins
>> Absolutely....
John Furrier
>> sharing on theCUBE here. Hopefully some investors watching want to give you outreach. Again, when you have a new way of thinking, you misunderstood for a long time until people get it, so I know how it feels.
Wes Mullins
>> We'll get graphed out.
John Furrier
>> We'll write a graph for that. Thanks for coming up. Appreciate it.
Wes Mullins
>> Yeah, absolutely. Thank you.
John Furrier
>> I'm John Furrier with the theCUBE. We're at the Neo4j GraphTalk in San Francisco. We got one coming up in New York City in September. Thanks for watching. Clip, we have a video-