Report an Incident Become a Partner Careers Contact
Book a Demo
The roster

Fourteen agents.
Fourteen jobs that used to be yours.

This is a SOC org chart, not a feature list. Each agent owns one function the way a real SOC is staffed, with a defined scope, its own tools, and an escalation path it cannot route around.

Roster · on duty14 agents
L1L1 TriageFront line
WATCHWatchFront line
L2L2 InvestigationInvestigate
FUSIONFusionInvestigate
INTELIntel AnalystInvestigate
HUNTThreat HunterProactive
DETDetection Eng.Proactive
VULNVulnerabilityProactive
INSIDERInsider RiskProactive
RESPResponseon approval
COMMSCommsService ops
RPTReportingService ops
MAINTMaintenanceService ops
MGRSOC ManagerService ops
How the roster works

One job each,
and a route they cannot go around.

Every agent runs the same underlying discipline: scoped tools, logged actions, evidence retained, and a decision that can be shown.

The scoping is the part worth understanding. An agent is not a general-purpose model given a login to your estate. It is given the tools its function requires and no others, and what it does with them is recorded against the investigation whether a person approved it or not.

That is what makes the roster auditable rather than merely impressive. Asking "which agent did this, using what, and who let it" has an answer for every action on every incident.

Front line

Everything arriving
in the queue.

The alerts, plus standing cover on the accounts and systems you can least afford to lose.

L1

SOC L1 Triage Agent

The front door. Every alert passes through here first.

Every incident gets the same investigation, at the same standard, at any hour, with the evidence attached.

Takes the incident out of Sentinel, resolves which triage procedure applies, establishes who and what is actually involved, runs the investigation steps, audits its own work for gaps, assesses the evidence, and produces a verdict with a report attached.

What it takes off your desk

Alerts queueing behind an analyst’s shift pattern. The four hundredth alert of the night getting less attention than the fourth.

What it costs you today

Dwell time measured in hours because nobody got to the ticket, and analysts spending their expertise on volume rather than on the incidents that needed them.

WATCH

Watch Agent

The early warning, ahead of any alert firing.

When the evidence is not conclusive, we do not close and hope. We watch, on a clock, and every check is recorded.

Puts a user under active observation after an incident where the evidence was not conclusive enough to close and not serious enough to escalate. It builds targeted queries over sign-in activity, directory changes and alerts for that user, checks them on a cycle, and records the result of every check including the clean ones.

What it takes off your desk

The incident closed as inconclusive and never looked at again, right up until the second one.

What it costs you today

The attacker who was in the first alert and confirmed in the third.

Worth knowingThe judgement is deliberately fail safe. If the assessment of a tripwire hit cannot be completed for any reason, the hit is treated as an anomaly and escalated. An outage never silently swallows a detection.

Investigation

Turning escalations
into evidenced verdicts.

Where an escalation becomes an answer, with the real-world context attached and the question of whether it stands alone already asked.

L2

SOC L2 Investigation Agent

The hub. Works escalations to a verdict and directs every other agent.

L2 does not restart the investigation. It starts from everything L1 found and goes after what L1 could not answer.

Everything L1 escalates. It takes the handover, enriches it with your own history and business context, activates the investigation hypotheses that fit the evidence, runs them against the estate, resolves the gaps L1 left, and produces a verdict, a blast radius assessment and a recommendation.

What it takes off your desk

The escalation that lands in a senior analyst’s queue as a paragraph of context and half an investigation.

What it costs you today

Your most expensive analysts re-doing discovery that was already done once.

Worth knowingWhere L2 has no configured rules for a given procedure, it always escalates to a human and flags it for review. It never guesses in the absence of policy.

FUSION

Fusion Agent

Joins the dots, then asks whether this is one incident or a campaign.

An incident is never investigated in isolation. Before a verdict is reached we ask what else touched these users, these devices and these addresses, how it ended, and whether this is a pattern, a campaign or a one off.

Stops incidents being treated as unrelated events. When an incident reaches investigation, Fusion pulls every incident from the last 30 days sharing an entity with it, every standalone alert from the last 14 days touching the same entities, and how each of those was resolved. It then classifies what it is looking at: a recurring pattern, an active campaign, or a one off.

What it takes off your desk

Three incidents, three analysts, three separate verdicts of "low severity, closed", and one campaign nobody saw because no single ticket was alarming on its own.

What it costs you today

The breach that was visible in aggregate and invisible one alert at a time.

Worth knowingIt also checks whether an alert type is firing abnormally for you specifically, by comparing the last 24 hours against your own seven-day baseline rather than against a generic threshold.

INTEL

Intel Analyst Agent

The context. Global intelligence, made specific to you.

Intelligence is only useful once someone has asked whether you would see it. That question gets asked automatically, for every report, against your estate.

Ingests threat intelligence continuously from vendor feeds, research publications and Microsoft Defender Threat Intelligence, extracts the actors, techniques and indicators, and works out which of it is actually relevant to your estate. It then does the step most intelligence programmes skip: it checks whether a reported technique is something your detections would actually see, and raises the gap to Detection Engineering.

What it takes off your desk

Threat intelligence as a reading list. A feed nobody maps to their own environment.

What it costs you today

Paying for intelligence that changes nothing about your defences.

Proactive

Finding what
never alerted.

And closing the gaps that let it through in the first place, so the next one does alert.

HUNT

Threat Hunter Agent

Looks for what no detection caught.

Hunts written for your estate, run on a schedule, and reported whether or not they find anything. A hunt that finds nothing is a result, and you get it.

Hunts on a schedule, on demand, and in response to new intelligence. It reads your environment and your coverage gaps, then writes its own hunts and its own queries, constrained to the data you actually ingest, so it never proposes a hunt against a table you do not have.

What it takes off your desk

Hunting as an occasional project that happens when someone has a quiet week.

What it costs you today

Everything sitting below the detection threshold, indefinitely.

Worth knowingIt also ingests penetration test and red team reports, extracts the engagement window and the activities performed, and hunts each activity against that exact window. That answers the question a pen test rarely does: would we have caught it. Hunting ships requiring approval before it runs.

DET

Detection Engineering Agent

Every incident makes the next one easier to catch.

Your detections get reviewed on a cycle, tested against your own history before anything changes, and tuned against what your alerts actually turned out to be.

Owns the detection rules as a living estate rather than a deployment. It reviews rules on a cycle, rewrites logic that is underperforming, backtests the proposed change against real historical data before anything is deployed, and grounds its tuning in how incidents from that rule were actually dispositioned by analysts.

What it takes off your desk

Detection drift. Rules tuned once, then quietly degrading while the estate changed around them.

What it costs you today

Alert fatigue from rules nobody has time to retune, and blind spots where a rule stopped firing and nobody noticed.

Worth knowingA new or rewritten rule is a draft; deploying it to Sentinel is a separate, gated step. It also detects rule changes made outside CYBERSHIELD AI, directly in the Sentinel portal, and records what changed and when.

VULN

Vulnerability Management Agent

Exposure ranked by what attackers can actually reach.

The score is arithmetic and the same every time. The AI writes the plan, not the priority.

Pulls vulnerability findings, asset context, installed and end-of-life software, misconfigurations, browser extensions, certificates and hardware inventory from Defender, prioritises against exploitation data and against which of your assets actually matter, and produces the remediation plan.

What it takes off your desk

A vulnerability report that is a list sorted by severity, handed to an IT team with no way to decide what to do on Monday morning.

What it costs you today

Effort spent patching what is scary rather than what is exploited.

Worth knowingPrioritisation is deterministic, using CISA KEV, EPSS exploitation probability and CVSS, and the AI layer writes the narrative on top of it. That separation is deliberate, and it is the answer to "how do I know the AI is not just making this up".

INSIDER

Insider Risk Agent

Watches the threat that already has a login.

The score is arithmetic, not a model’s opinion, so "why is this person at the top of the list" has an answer that survives an HR conversation.

Builds a per-user risk picture from the signals your estate already emits, scores it, and surfaces the people whose behaviour has actually changed against their own established baseline rather than against a generic rule. It discounts activity with known third parties, decays older activity, and shows the arithmetic behind every score.

What it takes off your desk

Insider risk as a product nobody trusts, because the score is a black box and the conversation it triggers is an HR conversation.

What it costs you today

Either no insider programme at all, or one that generates accusations nobody can substantiate.

Worth knowingThe scoring is deliberately not done by a language model, and every score decomposes into the signals that produced it. It is the strongest explainability story in the platform.

Response

Containment,
inside the limits you set.

Planned and executed against a plan you approved, with the tools for each step scoped to that step.

RESP

Response Agent

From verdict to contained, without waiting for a ticket.

Response runs on a plan you approved, with tools scoped per step, and every action recorded with the reason it was allowed to run.

Executes the containment and response plan once an investigation calls for one. Plans are built from steps, each step declares the exact tools it may use, and the agent is given only those tools. It proposes each action, holds it for approval where approval is required, executes on approval, and records the outcome with the reason.

What it takes off your desk

The gap between knowing what happened and doing something about it, measured in whoever is awake.

What it costs you today

Containment that starts in the morning for an incident that started at two.

Worth knowingEvery step defaults to requiring approval. Auto-run requires both the step and the owning agent to allow it, and then a stated condition to hold. An unrecognised condition falls back to manual approval. It never fails open.

Service Ops · included on every package

The agents that run
the SOC itself.

On all three packages, because the service does not work without them.

COMMS

Communications Agent

Keeps people informed while an incident is still moving.

The notification is part of the investigation, not an afterthought attached to it.

Owns what you are told and when. It drafts the notification from the investigation, routes it to the right recipients for you and for that incident type, sends it from the SOC mailbox, records every send against the investigation, and tracks replies.

What it takes off your desk

A correct investigation nobody communicated, or communicated to the wrong person.

Worth knowingRecipients are resolved once, when the run starts, so an edit made mid-run cannot change the audience of an email already waiting for approval. "Why did this go to them" is always answerable.

RPT

Reporting Agent

Turns a month of security operations into something you can act on.

  • Produces scheduled service and executive reporting
  • Tracks incident trends, SLA performance and detection coverage over time
  • Builds board-ready summaries from the underlying case data
MAINT

Maintenance Agent

Makes sure the SOC can still see.

The platform checks its own plumbing continuously, because in security an absence of alerts is not the same as an absence of activity.

Keeps the platform’s own machinery honest: the health of every connection into your estate, the state of the tool catalogue, stalled or stuck work, and the reconciliation checks that confirm the platform’s own records match reality.

What it takes off your desk

A silently broken integration. The connector that stopped returning data three weeks ago and nobody noticed, because absence looks like quiet.

MGR

SOC Manager Agent

The coordinator. Runs the shift and holds the standard.

Somebody is always watching the queue, not just the incident.

Runs the service rather than the incident. It watches queue health, service level standing against target, workload distribution and throughput, and surfaces the incidents at risk of breaching before they breach rather than after.

Worth knowingWork is not dispatched first in, first out. Every incident carries a service level deadline set at ingestion and never moved, and as it approaches that deadline it moves through priority zones. In the two most urgent zones severity is deliberately set aside, so a near-breach low-severity ticket outranks a comfortable high-severity one.

How escalation works

L1 to L2 to L3,
and no shortcuts between them.

Agents cannot promote their own work past the next tier. The path is fixed, and where it ends depends on which way you bought the platform.

  1. L1

    Triage

    Every alert arrives here. L1 escalates to L2, and that is the only route out of triage. Nothing skips ahead because it looks urgent.

  2. L2

    Investigation

    Takes the handover in full, coordinates the specialist agents, and works the escalation to a verdict with a blast radius assessment attached.

  3. L3

    People

    Your team on the platform sale, ours on the managed service. On the managed service a senior analyst signs the verdict by default rather than by exception.

Where L2 has no configured rules for a procedure, it escalates to a human and flags it for review. It does not guess in the absence of policy.

The managed AI SOC they run Detection & Response

Questions

The roster, answered.

What is an agent, in this context?

A role with one job, its own scoped set of tools, and a defined escalation path. Not a general-purpose model with a login to your estate. What each one does is recorded against the investigation, so any action can be traced back to the agent that took it and the approval that allowed it.

Can an agent act without a person approving it?

Only where you have allowed it. Every autonomy switch ships off or ships requiring approval, and response steps default to needing a human. Auto-run requires the step and the owning agent to allow it, and a stated condition to hold. An unrecognised condition falls back to manual approval.

Can an alert skip triage if it looks serious?

No. Every alert arrives at L1, and L1 escalating to L2 is the only route out of triage. Nothing promotes itself past the next tier. Where L2 has no configured rules for a procedure it escalates to a human rather than guessing.

Who is L3?

Your team if you license the platform, our team if you buy the managed service. On the managed service a senior analyst signs the verdict by default rather than by exception, which is a deliberate choice about who is accountable for what reaches you.

Do all the agents come with every package?

No. Core is the front line only: the L1 Triage Agent, and the L2 Investigation Agent when an incident needs a deeper look. Complete and Command carry the whole roster, including the service operations agents. Agents are not sold individually — the package decides which of them are on duty for you.

Does the roster grow?

Yes. Agents are added as we automate more of what our analysts do, and the roster on this page is the current one rather than a fixed set. Each new role arrives the same way: a defined scope, its own tools, and an escalation path.

See them working

Watch the roster run
on your own alert types.

An hour with a SOC analyst: a live investigation, every agent that touches it named as it hands off, the escalation path, and the autonomy dial set where you would set it.