Skip to content

Product1 publisher3 min readPublished

Cohesity backs up AI agent memory so admins can roll a misbehaving agent back

Agent Resilience snapshots an agent's memory and configuration and maps the systems it can reach, so an administrator can restore a point from before the trouble started. At launch it covers only AWS Bedrock agents, and only for select customers.

The Product Desk · Product desk

Illustration accompanying Cohesity backs up AI agent memory so admins can roll a misbehaving agent back

What happened

  • Cohesity introduced Agent Resilience at its Catalyst conference, a Data Cloud capability that backs up the memory and configuration of enterprise AI agents so they can be rolled back to a trusted state.
  • Coverage is limited to agents built on Amazon Web Services' Bedrock, including Bedrock AgentCore and Bedrock Agents, with Microsoft and Google agent platforms on the roadmap.
  • Only select customers have access for now, and Cohesity expects general availability by the end of the year.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • decision The per-agent topology map turns this from a backup purchase into an inventory assignment: someone has to own the list of systems each agent can reach before anyone can approve a rollback.
  • constraint Restoring agent memory does not undo writes the agent made into shared production stores, so the harder recovery call still lands on a database owner who has other writers to answer for.
  • exposure Because a prompt-injected agent can look normal while acting on bad input, detection lag sets how far back recovery points have to reach to be worth anything.
  • cost The only piece a buyer can turn on today is gated behind Data Cloud Enterprise Edition plus DSPM, so even the cheapest step carries a licensing prerequisite.

An agent with privileged credentials has been querying databases and acting on the answers, and nobody has been reviewing each step [2]. A governance tool flags behavior that looks wrong. Cohesity's case is that the flag is where those tools stop: they can spot unexpected behavior but cannot restore the data or systems an agent has changed, corrupted or deleted [3]. "Detection can tell you an AI agent went off course," said Vasu Murthy, Cohesity's chief product officer [4]. "It cannot undo the changes." [5]

Four capabilities came out of Catalyst, and one of them is generally available now [19]. Agent Resilience is with select customers, with general availability expected by the end of the year [14]. Maestro, which will let customers reach Cohesity's protection and recovery functions from Anthropic's Claude, OpenAI's ChatGPT and Google's Gemini, is expected later this year [16]. Autonomous Cyber Resilience is a plan: an administrator would give Cohesity Copilot a goal such as every application the business needs during a cyberattack meeting set recovery time and recovery point objectives, and Data Cloud would recommend protection policies, threat scans and recovery rehearsals, with nothing running without approval [15]. The one thing a customer can switch on now is automatic protection of newly discovered sensitive data, for anyone running Data Cloud Enterprise Edition with Cohesity DSPM [17].

Memory and configuration are what Agent Resilience covers at launch, protected by the immutable backups and clean-room recovery Cohesity already runs for on-premises, cloud and software-as-a-service workloads [9]. The restore is narrow: an administrator picks a recovery point from before the suspicious behavior started, and only the affected memory or settings come back [10]. A second function finds the databases, file systems and vector stores the agent works with and protects those as well [11]. Putting an agent's memory back to Tuesday does not unwrite what it did to a shared production database on Wednesday, and the launch description covers scoping for memory and settings without saying whether a restore of one of those data stores can be limited to the agent's own writes [20].

Each agent also gets a topology map listing the systems it connects to and the data it can reach. Cohesity says the map is meant to expose protection gaps and recovery dependencies before anything breaks [12]. I would expect the first useful output for most buyers to be the list itself, since the company also says most organizations are not protecting agent state today [6].

For now this works only on agents built on Amazon Web Services' Bedrock, covering both Bedrock AgentCore and Bedrock Agents, with Microsoft and Google platforms on the roadmap [13]. Teams standardized elsewhere are waiting either way.

A rollout plan needs three columns per production agent, and two of them cost nothing to fill: the newest recovery point for the agent's memory and configuration, every system it can write to, and who authorizes a rollback and how long that takes. Cohesity says a prompt injection can leave an agent that looks normal on the surface while acting on information it should never have trusted [7]. When the alert lands days after the injection, the recovery point an administrator needs is older than the behavior that prompted the search, and an agent with no clean recovery point may have to be wiped and rebuilt [8].

What to watch

  • Whether Microsoft and Google agent platform support arrives before or after the Bedrock general availability Cohesity expects by year end.
  • Whether Maestro ships this year with Claude, ChatGPT and Gemini access to Cohesity's protection and recovery functions.
  • Whether Cohesity documents agent-scoped restore for shared databases and vector stores, not only for agent memory and configuration.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories