The Agentic SOC owned by IT

Jay Jimenez
Aug 31, 2026By Jay Jimenez

Keep the Trigger in IT

Security operations spent ten years optimizing the wrong constraint. We added analysts. We added tools. We outsourced the queue to an MDR or a managed SOC. Attackers did not wait for any of that to finish. Breakout times fell into minutes. Alert volume did not. What most IT leaders now live with is a familiar failure: detections that lack business meaning, investigations that die in a ticket, and containment decided by people who do not run the estate.

The industry is offering two fashionable exits from that failure, and both are incomplete. One is a larger remote SOC. The other is a “lights-out” platform that isolates production systems on its own. Neither produces fully context-aware detection and response. The model that does is narrower and more demanding. AI agents detect, enrich, correlate, and investigate at machine speed, inside your telemetry and your institutional knowledge. Internal IT remains the human-in-the-loop that authorizes and triggers the response.

That last sentence is the operating principle, not a slogan. Agents close the investigation gap. IT closes the accountability gap. If you separate those two jobs, you get speed without judgment or judgment without coverage. You do not get a modern SOC.

A conventional in-house SOC is a linear pipeline: alert, queue, Tier-1 triage, escalate, investigate, decide, act. It assumed a human could read every ticket. That assumption is dead. Analysts spend most of a shift proving noise is noise. Coverage is bounded by headcount and shift patterns. The context that would make an alert meaningful lives in people’s heads — the change window, the crown-jewel list, the “admin” account that is actually a service identity, the subnet that is a lab until Friday afternoon. When those people rotate off, the context leaves with them. You cannot staff your way out of a design that treats investigation as scarce human labor.

Outsourcing the queue solved staffing. It did not solve context. An external analyst can see a privilege escalation. They cannot reliably know that the same identity is executing a pre-approved cutover, that the host is a non-production replica, that isolating it will take down a clearing window, or that the outbound flow Finance just blessed is a new vendor integration. MDR is optimized for detections that transfer across many customers. Your environment does not transfer. The moment someone outside the organization that owns the systems pulls the containment lever, two things happen at once. Blast-radius decisions are made with incomplete business knowledge, and accountability fragments. The board still holds IT responsible. The operator who clicked Isolate does not sit in the same incident review.

Full autonomy without a named human trigger is the other dead end. It is a governance problem wearing a product label. After a bad containment, boards, regulators, auditors, and insurers ask a simple question: who authorized the action that took the payment rail offline? “The agent decided” does not survive a post-incident review, a supervisory inquiry, or a cyber-insurance claim. High-blast-radius actions — isolating hosts at scale, disabling privileged identities, changing firewall policy, shutting production — require a responsible human who understands the estate. Even vendors selling autonomous SOC language already draw this line in practice. Investigations can run without a person in the path. Irreversible response should not.

Context-aware detection and response is not a richer alert description. It is the ability to answer five questions in one loop. What happened, across identity, endpoint, network, cloud, email, and application telemetry rather than inside a single tool. To what, which asset, which identity, which data class, which business process. A domain controller is not a kiosk. A privileged finance user is not a contractor laptop. In what operational state change window, DR drill, merger integration, month-end close, a known-vulnerable system sitting on a documented exception. With what confidence, an evidence chain, alternative hypotheses tested, residual uncertainty stated plainly. With what proportionate action, contain the threat without becoming the outage.

Only an architecture that can hold technical telemetry and institutional knowledge in the same reasoning loop can answer all five. That is why the human in the loop cannot be a generic remote analyst. It has to be IT: the function that already owns the CMDB, the identity fabric, the change calendar, the application dependencies, and the political reality of taking a system down.

An Agentic SOC inverts the old queue. Instead of alerting and hoping a human investigates, every signal is investigated first. Agents pursue a goal, not a playbook written in 2022. They gather evidence, form a hypothesis, query the next source, revise, and return a verdict with an evidence chain. Humans do not disappear. They move to the decision that actually requires authority.

The division of labor is explicit. Agents correlate weak signals, score them against asset criticality and identity risk, and run the L1-to-L3 investigation on every alert, timeline, blast radius, related identities, discarded explanations. They recommend a proportionate response with confidence, expected impact, and a rollback path, and they prepare the action pack. IT defines what “critical” means, feeds institutional context into the platform, reviews novel or high-severity verdicts, and corrects the agent when lived knowledge contradicts telemetry. Then IT accepts, modifies, or rejects the recommendation and triggers the response. Afterward, outcomes write back into detections and policy: which action classes may later move from approve-to-run to pre-authorized.

This is not SOAR with a chatbot on top. A playbook executes a path a human already imagined. An agent chooses the next investigative step at runtime from live evidence, which is why it can handle novel tradecraft instead of only the last incident you documented. It is also not the vendor’s SOC with a nicer dashboard. Investigation must run against your tenancy, your detections, your asset model, and your response authorities. A managed layer, if you use one, exists to operate the platform and keep the agents current. It does not exist to become the owner of your containment decisions.

IT as the trigger is the design choice that makes the rest honest. Accountability stays where the board already put it. When a payment switch, a core-banking interface, or a plant historian is isolated, the person who authorized it must explain why to operations, to legal, and to a regulator. That person sits in IT, or in a security function that reports through IT. Outsourcing the click does not outsource the liability.

Business context is not a feed you can buy. Crown-jewel lists rot. Application owners change. A development subnet becomes production during a cutover. The only durable source of that knowledge is the team that changes the environment every week. Agents become context-aware only when that team is in the loop, correcting verdicts and enriching the model. An offshore analyst working dozens of other tenants cannot do that job.

Proportionate response is operational judgment, not a severity color. Isolating a jump host during ransomware may be right. Isolating the same host during a month-end batch may create a larger incident than the alert. IT is the only function that can hold both facts at once. Trust in agents is earned the same way trust in junior engineers is earned. Start human-in-the-loop: IT approves every response. Graduate specific, low-blast-radius actions to human-on-the-loop only after measured precision in your environment, block a known-bad domain, revoke a single session, never as a procurement checkbox. Autonomy is a privilege the estate grants. It is not a feature you switch on because the demo was fast.

The economics follow the design. Investigation coverage moves from what the shift could reach to every alert, every time, including the quiet precursor activity that never used to get a verdict. Time-to-context collapses from hours to minutes, so the scarce human hour is spent on the decision rather than gathering logs from six consoles. Mean time to respond becomes a function of IT’s decision speed, not a vendor queue. That dependency is correct. You can staff a trigger roster. You cannot buy missing context. False-positive labor drops because agents close obvious noise with an evidence trail IT can sample, instead of a black-box “auto-closed.” Analysts and engineers stop being copy-paste machines and become governors of detections, owners of response policy, and hunters of novel paths.

If a program cannot answer a short list of questions in writing, it is automation with better copy. Where does the investigation run, in your tenancy, or as a verdict from a multi-tenant queue? How is institutional context injected, CMDB, identity, change calendars, business-process tags, exceptions? Is every verdict an evidence chain? Who can trigger which class of action, by named role, with reversibility designed in? What happens when the agent is wrong, and does the correction train the next investigation? Can autonomy be staged against measured precision in your estate, not the vendor’s demo tenant?

Attackers already operate at machine speed. Defense that waits for a human to assemble context from six consoles will lose on time. Defense that lets a remote operator or an unconstrained agent pull the containment lever will lose on judgment. The modern SOC is therefore a hybrid with a hard rule. Agents do the work that does not require institutional authority: watch everything, investigate everything, explain everything. IT does the work that does: decide what the business can absorb, and trigger the response.

That is fully context-aware detection and response. Not because the language is fashionable. Because context lives in the estate, authority lives with the people who run it, and speed only matters if the action you take is the right one. The decision in front of IT leaders is not SOC versus MDR versus AI. It is who investigates, who decides, and who is allowed to change the running state of the business. Put investigation on agents. Keep the trigger in IT. Build the platform so those two facts share the same evidence, the same asset model, and the same audit trail. Everything else is implementation.