Summary
- Open Systems has organised its SASE offering around self service, AI assisted, and fully managed operating models.
- Customers retain the same underlying platform while changing who performs operational work.
- The model puts approval, auditability, and responsibility alongside automation as AI begins acting on security systems.
Open Systems is reorganising its secure access and networking business around three operating models that allow customers to run the platform themselves, share operational work with AI, or hand day-to-day management to the vendor without replacing the underlying technology.
Zurich based Open Systems is applying the model to its SASE platform, which combines networking, secure access, policy management, and threat defence. Its fully managed Mission Control service is already available, while self service and AIOps variants are being rolled out.
The distinction lies in responsibility rather than a different security stack. An organisation can retain internal operation, introduce AI into selected work, or move towards a managed service while keeping the same underlying platform and policies.
Open Systems has built the AIOps option around an AI operator called Lucy and specialised agents that can analyse conditions, diagnose problems, propose changes, and initiate some actions. Approval remains with the customer or Open Systems engineers where the deployment requires it.
Automation is moving from alerts into actions
Security products have used machine learning for years to classify malware, detect unusual activity, and prioritise alerts. Agentic systems go further because they can interact with operational tools and recommend or make changes to the environment being protected.
A mistaken classification is inconvenient; an incorrect automated policy change can interrupt access or weaken a control. Governance therefore becomes part of the operating architecture once AI moves from advising an engineer towards manipulating systems.
Open Systems says its design uses bounded autonomy, with critical actions remaining traceable and subject to approval where appropriate. Markus Ehrenmann, chief technology officer at Open Systems, said: “The goal is not maximum autonomy. Security teams are right to ask what AI can access, what it is allowed to change and what happens when it gets something wrong. We want AI to take more operational work off their hands, but autonomy has to be earned. Guardrails first, autonomy second.”
Procurement consequently begins to include questions that sit beyond the conventional feature list: which decisions the agent can make, which require approval, how actions are logged, whether changes are reversible, and who remains responsible when automation creates an outage or weakens security.
AI creates a middle ground between internal and managed operations
SASE consolidated networking and security functions into a cloud delivered architecture, although customers have continued to differ over who should operate it. Large enterprises may retain specialist teams, while organisations with fewer staff can rely heavily on managed providers for policy changes, monitoring, and incident response.
AI offers a position between those models. An internal team can retain authority while software performs part of the routine operational work, which is different from transferring the whole service to an external provider.
Open Systems is turning that division of labour into the commercial structure of the product. Self service provides portal and API access, AIOps adds the agent layer, and Mission Control combines the same platform with around-the-clock operations and senior engineering support.
Keeping the platform constant could reduce migration work when an organisation changes how it operates the service, although it does not remove the broader switching cost of replacing Open Systems itself. Policies, skills, workflows, and integrations can still become tied to the vendor over time.
The company has been part of Swiss Post since 2024 and says it generates more than $100 million in annual revenue while supporting customers operating in more than 180 countries. It has not yet published comparative evidence showing how much analyst time or operating cost the new AIOps model removes.
Those measures will determine whether AI operation becomes a durable buying criterion. Enterprises are unlikely to delegate consequential security changes because a product can technically perform them; they will need evidence that decisions are reliable, auditable, recoverable, and compatible with existing risk controls.
The product architecture is therefore being shaped around responsibility at the same time as automation expands. As security agents gain permission to act, the boundary between software, internal teams, and managed providers becomes part of the security design rather than merely a staffing choice.










