That gap is where most MXDR quietly fails, because correlating six domains produces more to investigate rather than less. A human SOC handles that by rationing: low-value alerts closed fast to keep the queue moving, and the depth of any investigation depending on who is on shift. Widening the scope without changing how the work gets done just moves the bottleneck.
An AI SOC removes the rationing. Fourteen specialised agent roles carry triage, investigation, hunting, response and service operations, with 250+ named analyst skills behind them, working a nine-stage pipeline against triage procedures our own analysts wrote. Every correlated incident gets the same treatment at four in the morning as at four in the afternoon.
The stage worth knowing about is the completeness gate. It audits a finished investigation for evidence gaps, generates the steps that would close them, runs those and reassesses. It is a loop rather than a checkpoint, and it is why an investigation does not stop at the first plausible answer.
Average time to an L1 verdict is 3m 30s, measured across our own SOC. The clock starts when the signal reaches us, not when an analyst opens the ticket.