Today’s Security and IT teams have to do more than fix issues; they have to prove what happened, what changed, who was impacted, and what to do next. That’s the hard part of cyber resilience: stitching together signals across backups, identities, configurations, telemetry, and audit artifacts, before turning it all into something you can confidently share with leadership, compliance, or operations.
That’s exactly why Druva is advancing DruAI beyond a conversational copilot and into fully agentic workflows, so teams can delegate investigative work (and the reporting that comes with it) instead of spending days on manual correlation and write-ups.
Introducing fully agentic AI built for real cyber resilience work
The latest DruAI advancements are designed around a simple promise: Think Deeper. Act Faster.. Built on Dru MetaGraph (Druva’s tenant-specific, graph-powered intelligence layer), DruAI now has the foundation to understand “what’s connected to what,” and, more importantly, act on it with continuity and context.
This momentum matters because it’s not theoretical. DruAI has crossed a trust milestone: 3,000+ customers actively engaging, with 17,000+ total conversations, and a 67% case resolution rate, contributing to a 12.6% drop in support case volume (550 fewer cases QoQ). That adoption curve signals something important: teams are using DruAI to understand product state, interpret signals, and decide next actions without immediately opening a ticket.
So what’s new in this launch? Three major advancements, plus new multimodal capabilities, push DruAI from “helpful chat” to “delegated work.”
1) Deep Analysis Agents: Delegate multi-day investigations and get a finished report in minutes
First and foremost is Deep Analysis Agents: long-running AI agents that can independently work through complex, multi-step investigations. Instead of answering a single question and stopping, these agents:
- Break the task into steps
- Coordinate with tools and other agents
- Connect evidence across telemetry, identity, logs, configurations, and historical signals
- Synthesize findings into a clear, actionable, ready-to-share report
In practical terms, that means investigations that used to take days can now be completed in ~8–10 minutes, with results formatted for direct use by security, compliance, or operations teams.
This is especially meaningful for the “prove it” workloads that drain time: incident response documentation, forensic reconstruction, audit prep, and operational reviews. Teams often spend more time assembling evidence and reporting than executing remediation, and DruAI is designed to reverse that equation.
“Notify Me” workflows: Start the analysis, walk away, get the report
Deep investigations don’t always fit into an interactive back-and-forth. That’s why we’re proud to introduce Notify Me workflows: trigger deep analysis, step away, and receive an emailed synthesized report when it’s complete. For teams juggling active incidents, this is the difference between “I’ll get to that later” and “the work is already done.”
Customer benefit: this means faster closure, fewer handoffs, and fewer follow-up questions. With Dru, the output is a report you can actually share without rewriting.
2) Agentic Memory: DruAI remembers what matters, so you don’t have to repeat yourself
Most AI experiences forget everything the moment the session ends. That’s a non-starter for enterprise operations, where consistency and context are everything.
With Agentic Memory, DruAI stores, summarizes, recalls, and intelligently uses information over time, across both short-term session context and structured long-term organizational knowledge.
Two parts of this are particularly impactful:
- Cognitive continuity: DruAI maintains context from your current work and what’s been learned about your environment over time.
- Semantic learning: DruAI learns your organization’s unique lexicon (grounded in metadata). For example, understanding that “Project Titan” refers to a specific server group, without you needing to map it manually.
Customer benefit: fewer repetitive setup steps, faster time-to-answer, and investigations that get smarter the more you use them.
3) Personalized Intelligence: Role-aware, preference-aware, and permission-safe
Agentic Memory unlocks the next leap: Personalized Intelligence: an experience that adapts to who you are, how you work, and what you care about, without compromising privacy or permissions.
DruAI tailors dashboards, responses, and reports based on role, whether you’re an IT admin, SOC analyst, or compliance officer. Over time, it can also learn preferences such as:
- How you like reports formatted (summaries vs. detail, graphs/charts, historical comparisons)
- What areas you commonly investigate
- Which follow-up actions you typically take
This matters because it reduces “blank page syndrome.” Instead of starting from scratch, you get context-aware starter prompts and directed flows that reflect what you’ve done before and what’s most relevant now.
Customer benefit: a faster path from alert → understanding → decision, with less manual navigation and fewer unnecessary pivots.
4) Multimodal, context-aware guidance: Bring screenshots to the investigation
Troubleshooting often starts with a screenshot: an error message, an alert, a config screen, or weird system behavior. DruAI now supports image-based assistance, allowing users to upload screenshots directly into the console so DruAI can interpret the image and provide guided steps to resolve the issue.
Customer benefit: faster troubleshooting and fewer dead ends, especially when the “signal” lives in a UI, not a log file.
5) External context and intelligence: Stop chasing phantom misconfigurations
A key theme of these advancements is moving from “inside-the-product” help to “real-world” diagnostic intelligence. Planned enhancements include awareness of external signals, like cloud service health events and common ransomware techniques, so Dru can correlate what you’re seeing in backup outcomes with what’s happening outside your environment.
Two examples illustrate the impact:
- If S3/IAM/STS disruptions are causing backup failures, DruAI can correlate spikes to regional cloud service events and recommend appropriate next steps (like pausing retries briefly instead of burning hours on false misconfiguration hunts).
- If object storage shows patterns consistent with ransomware-style behavior (mass overwrite/delete/encryption waves), DruAI can flag the likelihood and guide validation steps immediately, shifting the conversation from “backup failed” to “possible active attack.”
Customer benefit: faster triage, higher confidence decisions, and less time wasted diagnosing the wrong problem.
How these advancements build on DruAI’s existing capabilities
These advancements don’t replace what DruAI already does well; they amplify them.
DruAI has been evolving into an in-product experience that helps teams ask natural-language questions, investigate threats inside their backup environment, and simplify day-to-day workflows across IT, Security, and Compliance.
Here’s how the broader portfolio comes together:
- Ask & Understand (Conversational Intelligence): Explore backup health, posture, trends, and change history through natural language without building complex queries or hunting through dashboards.
- Troubleshoot with Guidance: Move from an environment-wide view to root cause quickly, with guided next steps and actionable recommendations.
- Investigate Backup Threats Translate security questions into targeted searches across backup metadata and telemetry to produce clear findings and summaries. Watch this video for a look at how Dru remedies backup errors.
- Support that Scales (Dru Assist): AI-powered, in-product support with guided troubleshooting and seamless escalation when needed. Explore Dru Assist in this video.
- From Insight to Action (Agentic Workflows): Multiple collaborating agent types: data, help, action, insights, lifecycle, work together to interpret intent, analyze signals, and help take meaningful action. See a demo of the Lifecycle Agent and Insights Agent.
The takeaway
DruAI’s latest agentic advancements reflect a shift customers have been waiting for: AI that does more than explain what happened; it completes the work and moves you forward. With Deep Analysis Agents, Agentic Memory, Personalized Intelligence, and multimodal troubleshooting, DruAI is turning backup metadata into an always-on intelligence layer that helps teams respond faster, report cleaner, and operate with greater confidence, all without adding more dashboards or manual effort.
- Download the datasheet for a comprehensive look at our AI capabilities
- Set up a 30-day free trial of the Druva product and try Dru for yourself