Walk into any security operations center and count the dashboards. Every one of them is a way of showing you more alerts, sorted differently. We have spent a decade getting very good at a problem the SOC does not actually have. Analysts are drowning in alerts and starved of the one thing an alert never contains: an explanation.
An Alert Is a Symptom. The Story Is the Job.
An alert is a symptom. It tells you something twitched: a process spawned, a login came from somewhere new, a file left the building. What happened, whether it matters, what to do: on all three, the alert is silent. Producing those answers is the actual job, and it is laborious in a specific way. An analyst takes the symptom and goes hunting: pivoting into the EDR for process lineage, into identity for whether the account is privileged, into email for the phish that might have started it, into cloud and network for where it went. They assemble the fragments into a narrative, a story of what happened, and only then can they judge whether it’s a real incident or noise.
That assembly is the work that fills the day. It is also the work that does not scale, because there are always more symptoms than there are hours to explain them. So the queue grows, the hard cases wait behind the easy ones, and the corners that get cut are exactly the ones an adversary is counting on.
Shuffling Symptoms Faster Was the Wrong Fix
For years the industry’s answer was automation that made the symptoms move faster. Route them, enrich them, deduplicate them, auto-close the obvious ones. Useful, but it treated the wrong bottleneck. Shuffling symptoms more efficiently does not produce a single explanation. The analyst still has to build every story by hand.
The premise of an agentic SOC is that the machine can do the assembly. It investigates each symptom. It pulls the same threads a good analyst pulls, across the same tools, and hands back the story: here is what happened, here is the evidence, here is whether you are at risk, here is what to do. That is the bar. Anything less is a faster dashboard.
What an Analyst Actually Needs, in Order
Getting there means being honest about four things an analyst needs, in order. First, what happened: the attack path reconstructed across the whole stack, read-only, so a human can read the entire thing without worrying the tool changed something while it looked. Second, whether you are actually at risk. This is where most tools go quiet, handing back a number with no way to see inside it. A risk score you cannot open is just a black box wearing a lab coat. The score has to come with its reasoning: the factors, the weights, the evidence, and, above all, the contradicting evidence surfaced where you can see it. Third, what to do, with a human in command of anything consequential. And fourth, a way to keep asking questions, so you can explore the story yourself.

That fourth act is where the story stops being a document and becomes something you can interrogate. The most useful thing an analyst can do with an investigation is pull a thread the tool didn’t think to pull: “show me everything this identity touched in the last hour,” “what else came from that host.” When the whole investigation is a graph you can question in plain English, the analyst spends judgment where it’s worth the most, on the cases that actually need it. (That graph is shipping this summer; we’ll say more when it’s in customers’ hands.)

Underneath the four acts is a longer chain of work: intake, investigation, scoring, synthesis, recommendation, response, audit, and learning. The discipline that matters is that every stage is both autonomous and governed. Autonomous, because the point is to do the assembly for you. Governed, because none of it is worth anything if you can’t retrace it: the investigation itself becomes the audit trail, one chain of custody per incident, and consequential actions wait behind an approval gate that the risk of the action sets for itself.
This gives the analyst back the part of the job that was always theirs. It takes the mechanical part, the pivoting, the fragment-gathering, the reconstruction, and hands back judgment. The analyst stops being a research assistant to the alert queue and starts being the person who decides what the story means and what to do about it.
So the reframe worth carrying into your next evaluation is this. Don’t ask a vendor how many alerts it can close. Ask it to tell you the story of one, and to show you every piece of evidence behind every claim it makes.
Want to see it on a real alert? See the attack path Morpheus reconstructs from a single alert, evidence included.

