Figma published a technical overview of an agent-based system for securing internal systems. The guide describes Figma’s agent-based system for securing internal systems.

The system grew out of a search for past reasoning by on-call engineers and now investigates alerts.

The system reads audit logs. It makes code changes and opens pull requests (PRs).

Figma says it reduced alert resolution time by 71%. After automatically lowering the severity of similar benign or duplicate alerts, the number of on-call pages fell by 20%.

Claim check:

  • Figma published a technical overview of its agent-based system for securing internal systems: it triages alerts, investigates incidents, queries a security data lake, writes code for fixes, and uses accumulated memory. (confirmed by the primary source: evidence; «Our security team built an AI agent that triages alerts, conducts forensic investigations, queries our security data lake, writes code to fix issues—and remembers what it learns.»)
  • The system grew from a layer that searched past reasoning by on-call engineers into a full agent-based system that investigates alerts, reads audit logs, makes code changes, and opens PRs. (confirmed by the primary source: evidence; «That project eventually grew into a full agentic system that investigates alerts, queries audit logs, writes code changes, opens PRs, and gets better over time through its own memory.»)
  • Figma’s first component is a retrieval-augmented classification system built on AWS Bedrock Knowledge Bases and Amazon Kendra. (confirmed by the primary source: evidence; «The first thing we built was a retrieval-augmented classification system on top of AWS Bedrock Knowledge Bases and Amazon Kendra.»)
  • For the agent layer, Figma uses Tines: routing sends a request to a specialized agent with its own tool set, authorization, and system prompt. (confirmed by the primary source: evidence; «Each classification routes to a specialized agent with its own scoped tool inventory, authorization layer, and system prompt.»)
  • Figma separates several types of agent memory because this proved important to the system’s usefulness over time. (confirmed by the primary source: evidence; «Memory ended up being the thing that had the most impact on how useful the system became over time. We have several kinds, and keeping them separate turned out to be important.»)
  • Figma says it reduced alert resolution time by 71%. (confirmed by the primary source: evidence; «Here's how we cut alert time-to-resolution by 71% and fundamentally changed how our on-call engineers work.»)
  • After automatically lowering the severity of similar benign or duplicate alerts, the number of on-call pages fell by 20%. (confirmed by the primary source: evidence; «We saw a 20% drop in on-call pages from this change alone.»)
  • In a separate overview, Figma describes using agents to prevent, detect, and fix vulnerabilities during code generation, pull request review, and historical code audits. (confirmed by the primary source: evidence; «We use agents to prevent, detect, and fix vulnerabilities at three stages: code generation, pull request review, and auditing of historical code.»)
  • Over a month, iterations on the policy brought the code reviewer’s accuracy to 80% over a two-week window. (confirmed by the primary source: evidence; «Within a month of launch, iterating on the policy pushed precision to 80% on a two-week lookback, clearing our 70% bar comfortably.»)
  • Based on evaluations with known vulnerable commits, adjudication increased pass-rate recall by about 30% compared with the baseline. (confirmed by the primary source: evidence; «In our evals with known-bad commits, adjudication raised pass-rate recall by a relative ~30%.»)
  • Figma added failover between providers and retries so that a failure of one model provider cannot let a PR pass without review. (confirmed by the primary source: evidence; «We added provider failover and retry policies, so an outage at one model vendor can't let a PR slip through unreviewed.»)

Publications:

Primary sources:

score 65.3 · kind guide · revision 1 · stories st-zfhkea