What is agentic SOAR?
A plain-English definition from a team building it, including the parts vendors usually skip: what it does not do, and how to tell real autonomy from a rules engine in a trench coat.
Agentic SOAR is security orchestration, automation, and response where reasoning AI agents, not pre-built playbooks, do the investigation and drive the response. Agents read an alert, pull context from your stack, reason to a conclusion with the evidence attached, and act through your existing tools, within autonomy limits a human sets and with every decision recorded on an audit trail.
Three eras of SOC automation.
Automated clicking
Flowcharts wired to APIs. Powerful when the world matches the diagram, brittle the moment it does not. The hidden cost: a permanent engineering backlog of broken playbooks, and automation most teams switch half off.
Automated triage
LLM-era tools that investigate and summarize alerts well, then stop. The verdict still lands in a human queue, so the SOC gets faster reading, not fewer actions. Better, but the labor moved rather than shrank.
Automated decisions, sealed actions
You ask for an outcome; the agent plans first, then carries the case from alert to response: investigate, decide with evidence, then act through your tools, autonomously where you allow it, behind the Seal where you do not. The playbook is gone; the receipts are not.
One conversation. The Seal on every consequential move.
The abstract category gets concrete here: you ask the Familiar for an outcome in plain English, it plans first, and it detects, responds, and records behind one conversation, with the Seal on every consequential action.
Reads and correlates
Signals land from your tools and get correlated by entity into one timeline, mapped to MITRE ATT&CK, with the evidence kept attached.
Plans and casts the Spell
Contain, evict, and restore across the tools you run, mapped to MITRE D3FEND. Reversible by design, with consequential steps held at the Seal.
Writes down every decision
The case documents itself: evidence, confidence, and approver on one replayable receipt, kept in sync with your ticketing.
Five things to demand from anything labelled "agentic."
The label is free. These are not. We publish this list because we are happy to be measured by it, and you should measure everyone by it.
Reasoning you can read
Every conclusion should carry its evidence and its logic. If the system cannot show its work, you are buying trust on credit.
Actions, not just summaries
Ask what the system actually did last week: messages quarantined, hosts isolated, accounts disabled. "Autonomous alerting" is triage with better fonts.
A seal you control
Autonomy should be a per-use-case dial with a seal on destructive actions, not a global switch. You decide where the line sits, and move it when trust is earned.
A complete trail
Alert to action on one replayable record: tool calls, costs, confidence, and the human who approved what. If they cannot show this page, walk.
Reversibility by default
Automated responses should prefer actions that can be undone, and label the ones that cannot. One-way doors are where autonomy goes to die.
Judge us by it
The interactive tour shows all five on a real case, ungated, in three minutes. That is the whole pitch.
Watch an InvestigationAnd an agentic SOC analyst?
The phrase is everywhere and the definitions are conveniently vague. If agentic SOAR is the platform, the agentic SOC analyst is the agent doing the work inside it, with the boundary conditions that separate a working one from a marketing slide.
An agentic SOC analyst is an AI agent that performs tier-1 security operations work the way a human analyst would: it reads the alert, pulls context from your stack, enriches the indicators, reasons to a conclusion with the evidence attached, and either closes the case or escalates a finding. In agentic SOAR it also casts the response as Spells, with consequential actions held at the Seal a human controls.
A real agentic analyst does
- ✓Investigate every alert at full depth, including the boring ones, in seconds to minutes.
- ✓Cite a tool result for every claim: intel lookups, log searches, domain age, click-through checks.
- ✓State confidence and show the reasoning behind every verdict, readable by a human.
- ✓Close false positives on its own where you allow it, with the full record kept.
- ✓Carry confirmed incidents through to response: cast Spells to quarantine, block, disable, escalate.
It must never quietly
- !Take a high-blast-radius action without an explicit, recorded human Seal.
- !Collapse disagreement between tools into one tidy score with no story.
- !Mark a step successful when the underlying tool call failed.
- !Prefer an irreversible action when a reversible one exists.
- !Ask for trust it has not earned. Autonomy widens with evidence, never by default.
Asked honestly, answered the same way.
How is agentic SOAR different from traditional SOAR?
How is it different from an "AI SOC analyst"?
Does it replace SOC analysts?
How do you trust it?
Do SOPs and runbooks still matter?
The definition, demonstrated.
Walk one real case from alert to receipt. Three minutes, no signup.