How AI Agents Help Figma's Security Team Resolve Alerts Faster

Figma's security team built AI agents that learn from past investigations, and the results are worth noting.

3 min readInfoQ
How AI Agents Help Figma's Security Team Resolve Alerts Faster

Figma's engineering team recently shared how they've put AI agents to work on their security operations, and the results are worth pausing over. The agents investigate alerts, search past incidents, check internal systems, and even draft code fixes. They learn from previous investigations, which means the more they're used, the less repetitive work lands on human plates. Figma reports that engineers now resolve complex alerts about 70% faster. That number is striking, but the real story isn't the speed. It's what this tells us about how work itself is changing inside modern software teams.

For our readers, this is a concrete glimpse into a future that's already arriving. We've spent years talking about the potential of AI to assist with data tasks, but Figma's approach shows something more practical: agents that act as junior investigators, not just chat assistants. They don't replace the security team. They shrink the distance between an alert and an answer. That's a meaningful distinction. It means the human still owns the judgment, while the agent handles the legwork of searching logs, correlating context, and proposing fixes. For anyone wrestling with the complexity of spreadsheets or the flood of notifications in their own workflows, this is a useful model. It suggests that the next wave of productivity tools won't just automate keystrokes. They'll learn from your past decisions and bring that memory to bear on the next problem.

What we would tell a reader who asked us about this is simple: pay attention to how Figma framed the learning loop. The agents improve because they study previous investigations. That's the same principle that makes a well-structured spreadsheet so powerful. Every formula, every pivot, every carefully named range is a tiny piece of learning baked into a tool. The difference here is that the tool is now doing some of its own studying. That's not a reason to hand over the keys. It's a reason to start thinking about where your own team's repetitive work lives and whether an agent could carry part of it. For a security team, that might mean faster triage. For a finance or operations team, it might mean fewer manual reconciliations. The pattern transfers.

The open question is about trust and oversight. If agents learn from past incidents, how do you prevent them from learning the wrong lessons? Figma's documentation suggests a collaborative loop, but that's a design choice, not a given. We'd watch how they handle edge cases and false positives, because that's where the real complexity hides. The 70% faster number is compelling, but the remaining 30% is where human expertise still matters most. Here's the takeaway we'd offer: start small, pick a narrow workflow, and let the agent learn from a few months of your team's decisions. Don't chase the broad promise. Chase the specific problem you already know how to describe. That's how you turn an interesting experiment into a durable advantage.

From InfoQ

The engineering team at software company Figma recently documented how they built AI agents to help their security team investigate alerts, search past incidents, check company systems, and even prepare code fixes. The agents learn from previous investigations, reducing repetitive work and helping engineers resolve complex alerts about 70% faster.

Read the original at InfoQ