Agentic SOC Field Observations
How does the SOC actually change once an agentic SOC is in place? Not the way the loudest marketing says it does. The people do not disappear, the fundamentals of security do not change, and the completely autonomous SOC that parts of the market are selling is not what a well-run deployment looks like. This paper shares what we at D3 observe as our customers deploy an agentic SOC in production. What changes is the economics of investigation. Work that consumed hours of analyst time now completes in minutes, and floods of related alerts collapse into a single investigation with a readable timeline. The payoff arrives in two forms, and both are real. The first is cost: triage is the most expensive repetitive work in security, and when it stops consuming the majority of analyst hours, the savings show up in the budget, in avoided hiring, in overtime, and in service fees. For some organizations that saving is the business case, and it is a legitimate one. The second is capacity: every SOC carries a pressing backlog of projects it has never been able to staff, and the freed hours are how that list finally gets worked. The deployments that satisfy their boards count both. Getting there requires taking three things seriously that the market’s louder voices skip past: guardrails for the moments the system is wrong or blind, governance that can satisfy a regulator’s questionnaire, and unit economics that survive the end of subsidized model pricing. We built Morpheus around exactly those three things, and this paper states where each answer lives. Buyers should apply the same demands to every vendor on their shortlist, including D3.
Key Findings
- The core benefit of the agentic SOC is now well established in production settings: enrichment, cross-system investigation, and timeline construction that consumed hours of analyst time complete in minutes, with the case for escalation and the case for closure both stated explicitly, alongside the evidence that supports each.
- The unit of work is shifting from the alert to the investigation. A single intrusion can scatter dozens or hundreds of related alarms across email, endpoint, identity, and network sensors; operators increasingly expect those alarms to resolve into a handful of coherent incident narratives, not a queue to be cleared by hand.
- The financial return arrives on two lines, and deployments we observe capture both. The direct savings are real: triage labor is the largest cost in most SOCs, and reducing the cost per triaged alert shows up in budget, hiring plans, overtime, and service fees. The second return is capacity: freed analyst hours flow into detection engineering, threat hunting, and the improvement backlog that never gets funded. Pursuing savings is fine. The mistake is a board mandating a fixed percentage of workforce cuts before the deployment has shown where the hours are best spent.
- The completely autonomous SOC remains a pitch, not a practice. Autonomy is real and growing at the level of individual triage stages, but end-to-end closure without human governance fails the two tests that matter in production: the cost of the errors it will make at volume, and the scrutiny it will face from regulators and auditors.
- The category’s early AI claims were largely narrative dressing: alerts passed through a general-purpose model to produce better prose on top of the same queue. The vocabulary that survived (autonomous, human in the loop, AI-powered) now means different things from different vendors, and buyers report they can no longer distinguish systems by language alone.
- Transparency has become a procurement gate, not a preference. Legal, compliance, and AI-governance teams now ask vendors to show what was decided, when, why, and what data trained the models involved. A system whose answer is trust the model will increasingly fail the questionnaire before pricing is ever discussed.
- The economics of frontier-model dependence are a deferred bill. General-purpose frontier models are subsidized today and are generalists by design; they do not know a customer’s environment, and their per-token pricing will harden. Agentic SOC pricing must be evaluated at production volume and post-subsidy rates, not at pilot volume.
Recommendations
Security operations leaders planning for the SOC that follows agentic adoption should:
- Build the business case on both returns. Quantify the direct savings honestly (cost per triaged alert, avoided hires, overtime, service fees), then name the two or three roles the freed hours will fund (detection engineering, threat hunting, purple teaming). Savings satisfy the CFO; coverage satisfies the board’s risk committee; a deployment should be measured on both.
- Write the project list before you write the RFP. Inventory the security work your team has deferred for lack of hours: detection coverage gaps, log sources never onboarded, tuning debt, identity hygiene, tabletop exercises. Paired with the savings math, that list is the full business case for the agentic SOC.
- Require every vendor to show its work on your data. Ask for the complete record of one real triage decision: what was read, what queries ran, what evidence came back, what was concluded and why, what actions executed, and who approved them. Treat the absence of that record as a finding.
- Test the missing-evidence path explicitly. Disable a log source or revoke a credential during the evaluation and watch what the system concludes. A system that gets more confident as evidence disappears is a liability with a dashboard.
- Price the system at the SOC you are becoming. Require your cost per alert at your volume and alert mix, model the bill at ten times current volume and at unsubsidized model rates, and read every price as a multiple of the analyst labor it displaces.
- Treat completely-autonomous, no-analysts-required claims as a signal about the vendor, not a maturity level. Autonomy without an accountability record and a human escalation path is a vendor asking you to absorb their liability.
Market Context
An agentic SOC applies AI agents to autonomously triage, investigate, and respond to security alerts, with human analysts supervising. The category is moving from pilot to production consideration faster than any security tooling shift in recent memory, and the noise has kept pace. Vendor briefings blur together around the same three claims. Boards have converted the industry’s messaging into workforce mandates. A segment of the market has gone further still, pitching the completely autonomous SOC: no analysts, no queue, no problem. Practitioners are right to be skeptical of all of it, and right about what sits underneath: the fundamentals of security still hold, and the economics of investigation have changed. Depth of enrichment, cross-system correlation, and full timeline reconstruction that only the largest and best-funded security organizations could ever afford is becoming affordable to everyone.
What follows is drawn from what we observe as our customers deploy the agentic SOC in production: what genuinely improves, what the louder promises get wrong, and where the returns actually land. All observations are anonymized and aggregated. We will also say plainly where we stand. Our reading of this market is more conservative than its marketing: autonomy has to be earned in production, governance has to survive an auditor, and the economics have to survive the end of subsidized model pricing. The method throughout is to replace adjectives with evidence, and to let every vendor, including D3, be held to it.
Analysis
What does an agentic SOC actually do for alert triage?
It investigates, and that is the improvement our customers validate most consistently in production: enrichment, cross-system investigation, and timeline construction that consumed hours of analyst time now complete in minutes. An alert almost never contains enough information to make a determination on its own. The traditional workflow sends an analyst to other systems to fill the gaps: pull the running processes, query the identity provider, check the proxy logs, reconstruct what happened before and after. That is the work that consumes twenty to forty minutes on an honest investigation, and hours on a hard one. Agentic systems do this well. They reach into the surrounding systems, retrieve what is missing, and assemble the story: what happened first, what followed, which machines and identities were touched, and what the competing explanations are. The stronger implementations argue both sides, stating the case for escalation and the case for closure with the evidence behind each. And related alerts stop being individual tickets. An intrusion that starts with a phishing message, drops a loader on a workstation, and begins beaconing to attacker infrastructure can scatter dozens or hundreds of alarms across email security, endpoint, and network sensors; grouped triage resolves them into one investigation with one narrative and one disposition.
In Morpheus, this work is the spine of the product: an eight-stage triage lifecycle that is autonomous at every stage and governed at every stage. Investigation runs read-only against your systems and fails toward a human when it cannot get what it needs. Scoring is done through the Effective Alert Risk model, where the factors, the weights, and the evidence behind every score are visible, and the model surfaces contradicting evidence. The story stage assembles the investigation into a three-act narrative your analysts and your auditors can read: what the alert claimed, what the evidence actually shows, and what risk it carries. Customers rely on Morpheus triage in production every day at 98% triage accuracy. When Morpheus is uncertain, it defers to a human.
How close is the completely autonomous SOC?
Not as close as the pitch. Part of the market is selling autonomy as an endpoint: the SOC with no analysts, where the machine closes everything and the humans have been redeployed or released. Two tests separate that pitch from production reality. The first is error cost at volume. Wrongness in a SOC is a volume phenomenon: a system that is 99% accurate sounds finished, but at 10,000 alerts a day it is wrong 100 times a day, 36,500 times a year, and a fully autonomous system owns every one of those mistakes with no one positioned to catch them. The second is accountability. When the questionnaire arrives asking who decided, on what evidence, and under whose authority, an unsupervised loop has no good answer. The realistic trajectory, and the one we would defend in front of any board, is graduated autonomy: the system earns wider authority per class of work as its record justifies it, and the boundary is always explicit. That is how every other consequential automation, from flight control to trading, actually entered production.
Morpheus is built for that trajectory. The recommendation stage works as a copilot with four autonomy modes, so a team sets how much the system does on its own, per class of work, and widens it as trust accumulates. Actions carry command-risk tagging, so the risk of the command itself sets the approval gate. Autonomy in Morpheus is not a switch you flip on faith. It is a dial you turn on evidence.
Does an agentic SOC deliver cost savings, or freed capacity?
Both, and the deployments we observe succeed by counting both honestly. The savings are real and substantial. Triage labor is the largest cost in most security operations; proper investigation of a single alert is worth roughly $20 to $45 in analyst time, and a SOC that handles even a thousand alerts a day is spending millions a year on work an agentic system performs for a fraction of the cost. Customers see that reduction land in concrete places: budgets that stop growing with alert volume, requisitions that no longer need to be filed, overtime that stops being structural, service fees renegotiated. For some organizations, particularly those under hard budget pressure, the savings alone justify the deployment, and there is nothing wrong with that business case. What we caution against is a specific distortion of it: a board that absorbs the industry’s messaging, concludes that AI means a fixed percentage of workforce reduction, and hands the security leader a mandate before the deployment has shown where the hours are best spent. That mandate has nothing to do with risk, and it forfeits the second return. Because no security organization has ever had enough people or budget for the threats it faces, every SOC carries a list of pressing projects it has never been able to staff: detection coverage mapped against the techniques that matter, log sources that were never onboarded, tuning debt, identity hygiene, threat hunting that happens in name only, exercises that keep getting postponed. When triage stops consuming the majority of analyst hours, that backlog finally gets worked. The organizations getting the most from agentic systems capture the savings and level their people up into the work that was always waiting, and they decide the mix themselves, after the hours come back, not before.
Our position is the same one we build to: Morpheus is sold on cost per alert, time returned, and coverage gained, never on a promise to remove people. The savings are yours to bank or to reinvest. The product’s own safety model simply depends on experienced humans being present, because a system that defers to a human when uncertain needs a human worth deferring to.
Why does every agentic SOC vendor sound the same?
Because the language got ahead of the systems. In the category’s first wave, having an AI story was a market requirement, and for most vendors the story was the same: take the alarm, pass it through a general-purpose model, and return a better-written summary of what the alarm already said. That is narrative dressing on an unchanged queue. The vocabulary from that era survived and calcified. Autonomous now describes everything from closed-loop response to a draft email. Human in the loop means a genuine approval gate at one vendor and a rubber stamp at another. Practitioners say plainly that they can no longer tell what is real from what is repeated, and they are right to be frustrated: when every vendor claims the same three things, the claims carry no information.
We think the way out of the echo is evidence. In our opinion, the demonstration that matters is a system showing its work on your alerts, in your environment, with the record available afterward. That is the demonstration we ask buyers to demand from us, and from everyone else.
Can an agentic SOC show its work to auditors and regulators?
A new set of stakeholders has arrived in the evaluation, and they do not attend demos. Legal teams, AI-compliance functions, insurers, and financial regulators are sending questionnaires that ask a consistent set of questions. Show me what you did. Show me the thought process. Tell me what happened at this timestamp and why that decision was made. What data trained your models? Does our data train models used for other customers? Where does the data live, and who can access it? Speed and accuracy claims sail through these reviews while clarity and transparency fail them, because for most systems the honest answer is that the reasoning lives inside a model and cannot be reproduced. Regulators have never accepted trust me as documentation, and they are not starting with AI.
This is where we have spent our architecture budget. Morpheus keeps a traceable record of every step, a chain of custody that runs from alert intake to final action: what was read, what was queried, what came back, what was concluded, what was recommended, what was executed, and under whose authority. Risk scoring shows its factors and weights, and it surfaces the evidence that cuts against its own conclusion. When the questionnaire arrives, the answer is the record.
What happens when the agentic SOC is wrong?
Every system errs. What separates vendors is what an error costs, and the most expensive error in the category has a specific shape: the system that cannot retrieve evidence and concludes benign anyway. A query fails, a log source is dark, a credential has expired, and the alert closes because nothing bad was found in the evidence that happened to be reachable.
One rule should govern that moment, and we hold ourselves to it: missing evidence must increase uncertainty, not increase confidence in benignity.
In Morpheus, incomplete evidence never closes an alert, confidence is bound to evidence coverage, and an investigation that cannot get what it needs fails toward a human.
Agentic SOC market claims, and the evidence that separates them
| The claim you will hear | What is often being sold | The evidence to demand |
|---|---|---|
| Completely autonomous; you will not need analysts | Queue suppression without accountability, and a liability transfer to the buyer | The record of a wrong decision: how it was caught, what it cost, and what changed afterward |
| AI-powered triage | A general-purpose model rewriting the alert into better prose | A live investigation on your data: the queries run, evidence retrieved, and both cases argued |
| Human in the loop | Anything from a real approval gate to a rubber stamp after the fact | The exact boundary: what the system cannot do without approval, and how that boundary is set |
| Adopt AI and cut a fixed percentage of headcount | A workforce mandate detached from risk, made before the deployment shows where hours are best spent | Both returns quantified: the real savings arithmetic, and which unfunded projects the freed hours will staff |
| Simple, flat per-alert pricing | Subsidized model economics that harden after the pilot | The bill at ten times your volume, at unsubsidized rates, with retries and failed loops priced in |
Market claims are characterized from recurring practitioner accounts, paraphrased and unattributed; apply the evidence column to every vendor, including D3.
What will agentic SOC triage cost when the subsidies end?
Two facts about the category’s cost base are underpriced in most evaluations. First, general-purpose frontier models are subsidized: the prices buyers see today reflect providers spending capital to win share, and anyone planning a multi-year deployment should expect those rates to harden. Second, frontier models are generalists. They are remarkable at ingesting and extrapolating data, and they are not security operations experts: handed a raw alarm, a generalist model does not know your environment, your log shapes, or your query languages, and it underperforms exactly where triage gets hard. Vendors that simply resell frontier tokens inherit both problems and pass them to the buyer, and the buyers who signed at pilot pricing will discover this at renewal. The evaluation consequence is simple: price every agentic SOC at production volume and post-subsidy economics, and read every price as a multiple of the analyst labor it displaces. The arithmetic we use with customers gives the thresholds: against triage labor worth roughly $20 to $45 per alert, the business case starts working below about $4.50 per alert, survives a skeptical finance review at $2 or less, and stops being a debate at about $1. Our own number is $0.97 per alert, achieved through architecture and design.
What does the agentic SOC do to the analyst’s job?
The queue was never the job. For twenty years the industry has measured analysts on tickets cleared per shift, burned them out on exactly that metric, and then wondered why the talent pipeline is broken at both ends: juniors cannot get hired because entry-level triage is the first thing automated, and experienced analysts sit in tier structures with no defined path upward. The tiered model has always had an odd inversion at its heart, placing the least experienced people in front of the rawest signal and promoting them away from it as they improve. The agentic SOC gives the industry its first honest chance to retire that model. When triage is grouped, investigated, and documented by the system, the analyst’s unit of work becomes the investigation: reviewing the narrative, challenging the evidence, taking the escalations that genuinely need human judgment, and spending recovered hours on detection engineering and hunting. Teams then organize around investigations, and the work itself defines skill progression.
Morpheus is built for that shape of work. Analysts supervise an autonomous pipeline, and escalations arrive with the evidence and the narrative attached. The career that emerges looks like running a program: detection engineering, hunting, and the supervision of machine investigation. That is a job worth recruiting into, which the current one, by the industry’s own admission, has not been for years.
How to Evaluate Agentic SOC Vendors: Ten Questions to Ask
- Show me the complete record of one real triage decision: what was read, what queries ran, what evidence returned, what was concluded and why, what executed, and who approved it.
- When a query fails or a log source is unreachable, what does the system conclude, and where does that limitation appear in the output?
- What exactly can the system do without human approval, and is that boundary set by the risk of the action or by per-customer configuration someone must maintain?
- Is your triage a general-purpose model summarizing my alerts, or an investigation? Show me the queries it runs in my environment.
- How are related alerts grouped into one investigation, and can my team and my auditors read the resulting narrative?
- What triage accuracy do you sustain in production, how do you measure it, and what happens on the misses?
- Whose models does my data touch, what is retained and where, and is any of it used to train models that serve other customers?
- What is my cost per alert at my volume and at ten times my volume, at unsubsidized model rates, and who pays for retries and failed investigation loops?
- Which projects and roles have your current customers reallocated freed analyst hours into, and what coverage did they gain?
- Where does this fit with my existing SIEM and SOAR investments: what does it replace, what does it work alongside, and what can I retire?
Evidence and Assumptions
- The observations in this paper come from D3 customer deployments of the agentic SOC and from discussions during 2026 with security operations leaders, security service providers, and advisors. All accounts are anonymized, aggregated, and paraphrased, and none are attributed, by design.
- Illustrative accuracy arithmetic: 99% accuracy at 10,000 alerts per day yields 100 wrong dispositions per day, 36,500 per year. The point is structural, not vendor-specific: error handling matters because error volume scales with alert volume.
- Economic thresholds are derived arithmetic, not third-party findings. Proper Tier 1 triage takes 20 to 40 minutes of analyst time, worth roughly $20 to $45 per alert at fully loaded rates; a tenfold return on that displaced labor caps a defensible price at $2 to $4.50 per alert, and a bill that stays inside the cost of the two to three analysts it frees works out to about $1 per alert for a 1,000-alert-per-day SOC. The thresholds move with your inputs; the method does not.
- Descriptions of Morpheus behavior (the eight-stage lifecycle, read-only investigation, Effective Alert Risk scoring, command-risk tagging, the chain-of-custody record, autonomy modes) are D3’s own statements of how the system works, offered for inspection in a live demonstration on your data.
Frequently Asked Questions
What is an agentic SOC?
An agentic SOC uses AI agents to autonomously triage, investigate, and respond to security alerts, with human analysts supervising. The evaluation bar is three-legged: excellent triage, real guardrails that fail toward a human, and a unit cost that survives production volume and finance review. D3’s Morpheus is an agentic SOC layered on a platform built from scratch over two years by a team of 60.
How is an agentic SOC different from SOAR?
SOAR automates the steps you predefine: a playbook runs the same way every time, and someone has to build and maintain it for every alert type and every integration change. An agentic SOC investigates: it decides what to look up based on the evidence in front of it, reaches into surrounding systems, weighs the case for escalation against the case for closure, and documents the reasoning. The two are complementary in practice; the agentic layer does the investigative thinking, while orchestrated automation remains the right tool for well-defined response actions. Morpheus is built on a platform that carries both, which is why customers often consolidate tooling when they deploy it.
How should I evaluate agentic SOC vendors?
Ignore the adjectives and test three behaviors on your own data: the record (can the system show the complete trail of a real decision), the missing-evidence path (does it get less certain, and escalate, when a source is unreachable), and the economics (your cost per alert, at your volume and ten times it, at unsubsidized model rates). The ten questions in this paper cover all three, and they apply to every vendor, including D3.
Is a completely autonomous SOC realistic today?
No. Autonomy is real and growing at the level of individual triage stages, but an unsupervised end-to-end loop fails on error cost at volume and on accountability: at production alert volumes even a 99% accurate system is wrong tens of thousands of times a year, and regulators expect a decision record no unsupervised loop can produce. The realistic model is graduated autonomy with explicit boundaries, which is how Morpheus is built.
Will an agentic SOC replace SOC analysts?
What we observe says no. The realistic outcome is a mix the organization chooses for itself: real cost savings on triage labor, plus freed hours that fund the detection engineering, threat hunting, and tuning work that was never staffed. Programs built solely on eliminating a fixed number of positions forfeit the second return and undermine the human escalation path the system itself depends on.
How do you tell a real agentic SOC from agent-washing?
Ask the system to show its work on your data. A summarizer produces better prose about the alert it was handed. An investigation produces the queries it ran, the evidence it retrieved, the case for escalation and the case for closure, and a record connecting evidence to conclusion to action. If the record does not exist, the autonomy is a claim, not a capability.
What should an agentic SOC do when evidence is missing?
Become less certain, not more. A failed query or an unreachable log source must raise uncertainty and route the alert toward a human, never silently narrow the investigation to whatever was reachable. In Morpheus, incomplete evidence never closes an alert, and confidence is bound to evidence coverage.
What transparency will regulators expect from an agentic SOC?
A per-decision record: what was analyzed, what was concluded, when, why, what actions were taken and under whose authority, plus clear answers on where data lives, who accesses it, and whether customer data trains models used for others. Morpheus answers with its chain-of-custody record and risk scoring that shows its factors and weights.
How much should agentic SOC triage cost?
Measured against the analyst labor it displaces (proper triage is worth roughly $20 to $45 per alert), the business case starts working below about $4.50 per alert, survives finance scrutiny at $2 or less, and stops being a debate at about $1. Morpheus delivers full-depth triage at $0.97 per alert, achieved through architecture and design, at 98% triage accuracy in production. When Morpheus is uncertain, it defers to a human.
Next step.
Bring a week of your own alerts, and the project list your team has never had time to start, to a 30-minute demo. We will show you the investigation, the evidence, the score, and the record, and you can do the arithmetic on the hours.

