How Figma Uses AI Agents for Security

| Source: InfoQ AI/ML

Tags: Claude Opus, Figma, AI agents, security automation, AWS Bedrock, agentic systems, Panther SIEM

Figma's security team deployed a Claude Opus-powered agent system on AWS Bedrock that cut complex alert resolution time by 70%, reduced on-call pages by 20%, and discovered 100+ previously unknown vulnerabilities — including two critical flaws traditional scanning tools missed.

Details

Figma's security engineering team deployed a multi-agent system built on Panther SIEM that automates alert triage across AWS, Okta, GitHub, GCP, and osquery, querying over 100 data sources and opening draft PRs for code fixes when needed. The system was built by Matthew Sullivan and Brad Girardeau while both worked at Figma. The core alert triage agent runs Claude Opus via AWS Bedrock and receives full Slack thread history alongside three types of persistent memory: records of past alert investigations, behavioral steering guidance, and learned database schemas. The team calls memory design "the thing that had the most impact on how useful the system became over time" — keeping the three memory types separate was key to enabling compounding improvement over time. Measured results are concrete: 70% faster resolution for complex alerts, 20% fewer on-call pages, 100+ previously unknown vulnerabilities discovered (including two critical issues traditional scanners missed entirely), and 80% precision from a code review agent within its first month. Safety is enforced at the tool layer rather than through prompt instructions: agent-created PRs default to draft status, and tool scopes prevent sensitive data from leaking into public Slack channels. Human review remains mandatory throughout — the agents augment security engineers rather than replacing them.