A month ago we made the largest change to Soarcery since we started building it. We took a product that had grown into several places you had to learn, several consoles you had to operate, and several agent orders you had to keep straight, and we folded all of it behind one conversation. You now ask the Familiar for an outcome in plain English. It shows you a plan before it touches anything. You approve, edit, or reject that plan. Then it builds and casts the Spell across your stack, and anything consequential stops at the Seal, where a named human approves and every decision leaves a receipt.
We did not cut features to make the demo shorter. We cut surfaces because the surfaces were the tax, and the substance was hiding underneath them.
This post is the honest version of why. It is the successor to the 2.2 release note, which introduced the Familiar as the cornerstone and then, in the same breath, gave you an org chart of agents to command. That post stays up as the record of what we believed at the time. This one explains what we learned by watching people use it.
What we actually heard
When you put a genuinely capable system in front of security practitioners, the feedback is rarely about capability. It is about operation. The people who tried Soarcery did not tell us the agents were not smart enough. They told us there was too much to hold in their heads. There was a place to author detections, a place to author responses, a place where the case wrote itself, and a rail that tried to make sense of all of it. Each part was defensible on its own. Together they asked the analyst to become an operator of Soarcery before they could get any leverage out of it.
The sharpest version of the note came through a friend of the company, relaying a first-time visitor who could not answer the plainest question after a full walkthrough: what does this thing do. Not because the answer was bad, but because the answer was spread across four surfaces and three orders of agents, and the mystique arrived before the meaning did. When a smart, motivated person cannot summarize your product after you have shown it to them, the product is not too advanced. It is too wide.
What people were reaching for, underneath the specific complaints, was consistent. They wanted a magical way to build and run response. They wanted to describe the outcome they needed and have the system do the assembling. They did not want a new set of screens to master in exchange. The magic they were promised was never the org chart. It was the sentence you type and the work that follows from it.
Complexity was the tax, not the value
It is easy, when you have built something intricate, to mistake the intricacy for the worth. We had modeled the SOC as a society of agents with real roles, and the model was correct in a way that felt like insight. Detection, response, and record-keeping really are different jobs with different doctrines. So we exposed that structure. We gave each part a name, a color, a place you could go and operate it directly.
The mistake was not the model. The mistake was making you live inside the model. An analyst does not want to dispatch a detection order and then walk over to a response order and then check on the record. That is org design, and it is our job, not theirs. The value was always the outcome: the phishing wave contained, the account locked, the case documented and reconciled with your ticketing system. The structure that produced the outcome was overhead we had asked the user to carry.
The concepts did not die. They stopped being places you visit and became work the Familiar orchestrates.
So we stopped charging that tax. The concepts our earlier releases carried as separate orders are all still there, doing the same jobs. They are simply no longer surfaces you operate. They are the machinery behind one conversation.
Where the old orders went
The three orders our 2.2 release introduced, which that release called "the Watchers", did not get deleted. They got absorbed. Detection, response, and record-keeping are still first-class work inside Soarcery. When you ask the Familiar to investigate an alert, the detection logic runs. When it proposes containment, that is the response work. When the case is written up and kept in sync with your ITSM tool, that is the record being kept. None of it went away. What went away is the requirement that you know which order is acting, navigate to it, and drive it yourself.
This is the part we want to be precise about, because it would be easy to read the pivot as a retreat. It is the opposite. Orchestrating three kinds of work behind a single plain-English request is harder than exposing three consoles and letting the user route between them. We took on more of the coordination so that you take on less. The Familiar is not a chat box bolted onto the old surfaces. It is the thing that decides which capabilities a request needs, sequences them, and shows you the result as one plan instead of three dashboards.
The reusable building blocks moved with the same logic. Your saved response actions live in the Spellbook, and you can adopt prebuilt ones from the Bazaar rather than authoring from a blank page. Borrow, adapt, and run, instead of learning a library to assemble one by hand. The connectors to the tools you already operate are just Tools the Familiar can reach for. The vocabulary got smaller on purpose, because a smaller vocabulary is a smaller thing to learn.
Plan first, always
Cutting surfaces could easily have meant cutting transparency, and that was the one trade we refused. A system that acts on your infrastructure from a single sentence, with no visible reasoning, is not simpler. It is more frightening. The whole reason a plain-English front door is safe is that it never acts on the sentence alone.
Every request produces a plan before anything happens. The plan is legible: the steps the Familiar intends to take, the Tools it will use to take them, and the assumptions it is making about your environment. You read it the way you would read a change request from a colleague you trust but still check. You approve it, you edit it, or you reject it. Only then does it build and cast the Spell. The conversation is the easy part to show in a demo. The plan is the part that makes the conversation trustworthy, and it is not optional.
This is the same discipline we wrote about in deterministic verdicts on top of non-deterministic agents. Let the agent be creative about finding the truth. Never let it be creative about what happens next without showing you first. Plan-first is how creativity and control coexist in the same system.
The Seal is the line we do not move
Underneath the plan sits the gate, and the gate is the product. Anything consequential, anything that touches a user, a host, an account, or a live control, stops at the Seal. A named human approves it before it runs. The approval is recorded. The action, the evidence behind it, and the person who authorized it all become a receipt you can export and hand to an auditor without assembling anything after the fact.
Governed autonomy is the product. Raw autonomy is a liability with better marketing.
We are deliberate about this because the market is full of the other pitch. Fully autonomous response sounds like the future until you picture it isolating the wrong host at the wrong hour with no one accountable. The Seal is a deterministic gate, not a suggestion the model can talk its way past. Where you set it is a dial you control: as trust accrues in a given use case, you can let more run unattended, and until then the consequential moves wait with their case file in front of you. The Familiar can be as autonomous as you want everywhere the cost of a mistake is low, and it always waits where the cost is real. Simplifying the surfaces changed nothing about this. If anything it made the gate clearer, because now there is one place the consequential decisions surface, not several.
An evolution, not a retraction
We are not embarrassed by the model we shipped in 2.2. It was an honest attempt to make the inner workings of an agentic SOC legible by giving them structure and names. What we got wrong was the assumption that legibility meant exposure, that showing you the structure required making you operate it. The structure was right. The surfacing of it was the tax.
So the through-line from 2.2 to now is not a reversal. It is a distillation. The Familiar was always meant to be the cornerstone. We simply took the word seriously. A cornerstone is the single stone the rest of the structure aligns to, not one feature among several. Everything the earlier orders did still happens. It happens behind one conversation, with a visible plan you approve and a Seal you cannot route around, and that is the agentic SOAR we actually want to run. Less to operate, nothing important given up, and a straight line from a sentence to a governed outcome. That was the promise all along. Now it is the whole product.