AI can triage alerts. But do you
trust it to act on yours?

Six criteria for adopting autonomy you can put your name on — and defend to the board, the regulator, and the NIS2 72-hour clock. Mapped to NIS2, DORA, and the EU AI Act.

Experience and scale that matters LSEG S&P Global Cummins Scotiabank PwC

Triage is table stakes. Trust is the hard part — this guide is about the hard part.

Every AI SOC vendor can produce a verdict in seconds. None of that matters if you can’t see how it got there, contain it when it’s wrong, and defend it after the fact. This guide gives you the six criteria to judge any AI SOC platform — the ones that decide whether autonomy is something you can put your name on. Use them on us. Use them on anyone.

Every AI SOC gives a lightning-fast verdict.
You just need the right one.

The question that decides whether an AI SOC earns a place in yours is not whether it can produce a verdict. It’s whether you can trust it to investigate your environment, hand off when it isn’t sure, and prove what it did, why, and on what evidence.

A verdict you can’t interrogate isn’t an answer. Four questions decide whether an AI SOC is something you can actually run:

Can an analyst see the logic?

Can they see why it reached a verdict — or just the verdict?

Can you produce the audit trail on demand?

One record when a regulator asks — or a weekend of stitching logs together after the fact?

What happens when it’s uncertain?

AI strives to find the answer — which is why it hallucinates. What does the architecture do to contain that tendency?

Are sensitive actions deterministic?

Investigation can be probabilistic. The remediation that touches your environment and your users cannot be a coin flip.

A tool your team doesn’t trust
never leaves the pilot.

Your analysts will re-verify the AI’s work — for a year, maybe always. The stakes are too high not to. So the platform that earns trust isn’t the one that asks them to stop checking; it’s the one that lets them check everything — the full story of an alert, and why a verdict was reached — at a glance. AI isn’t perfect. Transparency is. What kills trust is not being able to see what the AI did, or why.

And when an analyst finds a crack, they correct it — and the AI never makes that mistake again. That’s how a pilot turns into production. Everything below is what earns that trust — and the criteria to demand of any AI SOC vendor, not just this one.

You’re pushed from both directions at once.

A board and a mandate want AI in the SOC now. An examiner, an insurer, and a general counsel will ask — the morning after a material breach — who decided, on what basis, and can you prove it. You’re expected to move early and defend the move.

You answer up — to the CFO, the regulator, the cyber-insurer

They want a defensible decision and a record they can actually read — not a black box.

You answer down — to your SOC leader & team

They want one thing: more time on real threats. When the AI isn’t certain, it hands off to them — so they know they’re not being replaced. There’s still ample need for their context, their judgment, and their call.

Accountability is how you do both — adopt autonomous AI without it becoming your personal liability, and without your team feeling written out of the loop. Here’s what to demand.

Criterion 01 · Autonomy

Autonomy should be a dial — not set-and-forget.

A phishing email and a domain-admin compromise don’t deserve the same leash. In Morpheus you set the autonomy level to match the alert — and widen the dial as trust grows. Same reasoning engine at every level; only the amount of human sign-off changes.

Morpheus · four autonomy levels Set per alert type · widen as trust grows
1
Deterministic
SOAR mode
Rule-based playbooks run end to end. No AI in the chain.
Regulated workflowsCompliance-critical pathsApproved remediation playbooks
2
AI-Assisted
Analyst co-pilot
Your analyst leads the investigation and queries Morpheus in plain language for answers and deeper analysis. Morpheus surfaces the evidence; the analyst carries it forward.
Identity alertsEDR detectionsCloud posture findings
3
AI-Led
Investigates + drafts response
Morpheus completes a deep investigation and drafts the response. Your analyst reviews and can approve or modify anything.
Phishing triageMalware containmentDLP investigations
4
Autonomous
End to end · gates configurable
Investigation and response run end to end against the approval gates you set in advance — no live sign-off needed. Every action is logged and reversible.
High-volume L1 categoriesWell-understood alert typesOne-click rollback
Autonomy levels — see them in a live demo →
Bring a question or your toughest alert — our team will walk you through it.

Criterion 02 · Hallucination containment

A wrong answer should never reach a consequential action.

Most tools are built to triage everything, come hell or high water — so on the alerts they can’t resolve, they invent the evidence behind a confident verdict. Morpheus is built the other way. It triages what it can do confidently — with strict rules to hand off what it can’t.

In one SOC that might mean it handles 70% of alerts cleanly rather than claiming 95%. The rest is escalated on purpose, not closed on a guess. Reasoning is bounded; nothing destructive happens without a gate. The rule: certain, or it asks.

Prevention

Grounded reasoning over your real telemetry, bounded so it can’t wander into invented facts — hard caps on iteration, cost, and tool scope.

Containment

Uncertain findings escalate to a human instead of auto-closing. A wrong answer can’t reach a destructive action.

The 99% trap

A vendor claims 99% accuracy? In a SOC running 4,400 alerts a day, that’s 44 wrong calls every day — and the ones that hurt are the missed threats closed as benign. Ask for the containment story, not the accuracy number.

Criterion 03 · Reversible response

Autonomous response, in production today — on the right alerts.

Some alerts can’t wait for a human. A phishing blast mid-spread, a credential popping on an exposed host, a token exfiltrating — on those, every minute of delay is blast radius. Morpheus has already investigated the alert in full and orchestrated the response: isolate the host, disable the account, block the sender. It acts first and buys you time.

Because every action is logged and reversible, the call is never final — so your analyst gets the time to review what was done and why, on a contained incident instead of a live one. Disagree? Roll it back in one click. Fast action stops being a gamble.

And the action itself is deterministic — the same way, every time. Most tools bolt on and babysit a separate SOAR for that. Morpheus has a full deterministic SOAR built in — one engine, one bill, one audit trail.

Criterion 04 · Investigation depth

It investigates like a top analyst — on every alert, across your stack.

800+ integrations, so it works with the stack you already run — SIEM, EDR, identity, email, cloud. Attack Path Discovery correlates across all of them to find root cause before an analyst opens the alert.

As a Microsoft Intelligent Security Association (MISA) member, the Microsoft integration runs deep — native Defender, Sentinel, Entra, and Azure. Morpheus reads your Microsoft signal and adds the reasoning and response layer on top. It doesn’t replace what you own — it makes it more valuable.

Controlled benchmark: three multi-stage phishing scenarios mapped to MITRE ATT&CK, the same evidence available to both tools — a test of investigation depth, not a knock on Microsoft’s signal.

On three multi-stage phishing attacksD3 Morpheus 3 / 3MS Copilot 0 / 3
Root causeTraced in all threeFound in none
Kill chainReconstructed 6–8+ stagesSummarized, not connected
CorrelationEmail, endpoint, network, cloudStayed within Defender’s data
OutputReady to contain & remediateBack to the starting line

The two are designed to work together: Microsoft for detection, Morpheus for the verdict. Full methodology on request.

Microsoft Intelligent Security Association
Member · deep Defender, Sentinel & Azure integration

Criterion 05 · Memory you own

The experience can’t walk out the door.

Morpheus absorbs your team’s local knowledge and special tactics — the VIPs, the contractor logins that look suspicious but aren’t, the scripts ten other tools keep flagging. When a senior analyst resigns, what they taught the system stays.

What it learns stays inside your environment: never pooled, never used to train anyone else, exportable if you leave. And it keeps its own integrations healthy — so your engineers spend their hours on hardening and hunting, not plumbing.

Yours alone

Scoped to your environment — never pooled, never used to train anyone else’s model, exportable if you ever leave.

Self-healing integrations

It keeps its own connectors alive — engineers stop firefighting them mid-incident.

Which is the point for a CISO

Every hour AI spends on maintenance is an hour your people spend maturing SecOps.

Criterion 06 · One audit trail

One record — the artifact your regulator,
board, and insurer actually read.

When the SEC, your auditor, or your cyber-insurer asks how a decision was made, the answer can’t be a weekend of stitching logs together. Many AI SOC tools spread the work across separate agents that each keep their own log — so the record gets reassembled by hand at audit time, exactly when you can least afford it. Morpheus runs one engine, on purpose, and produces one continuous record per incident, first alert to closeout, in open YAML.

That’s what holds up under NIS2 incident reporting and the DORA ICT-incident regime, gives you the traceability the EU AI Act expects of a high-risk AI system, satisfies the cyber-insurer at renewal, and — for those of you with US operations — meets SEC 8-K Item 1.05 and NYDFS Part 500 too. One provable, attributable record on demand is what shortens the disclosure clock and keeps you out of a finding.

For the European CISO

The six criteria, mapped to the regulation
you actually answer to.

Accountability isn’t abstract in Europe — it’s written into three overlapping regimes, and each one asks a question the six criteria above are built to answer. Here’s where they line up.

NIS2
Directive (EU) 2022/2555

Extends incident reporting and risk-management duties across essential and important entities — with management-body accountability and an early-warning obligation within 24–72 hours.

Answered by
06 One audit trail — the provable record behind the report
03 Reversible response — act inside the clock, defensibly
01 Autonomy dial — deterministic paths where sign-off must be evidenced
DORA
Regulation (EU) 2022/2554

For financial entities and their ICT providers: ICT-incident classification and reporting, resilience testing, and a demonstrable chain of who did what during an incident.

Answered by
06 One audit trail — one continuous record per incident
04 Root-cause investigation — the basis behind each classification
02 Hallucination containment — no invented evidence in a filing
EU AI Act
Regulation (EU) 2024/1689

Where AI supports consequential security decisions, expects traceability, human oversight, and logging proportionate to the system’s risk — you must be able to show how the AI reached its call.

Answered by
01 Autonomy dial — human oversight, set per alert type
05 Memory you own — the reasoning context, retained and portable
06 One audit trail — traceability in open, readable YAML

This mapping is guidance for evaluation, not legal advice. Obligations vary by member-state transposition, sector, and entity classification — confirm the specifics with your own counsel and DPO.

Then you should meet Morpheus.

An autonomous SOC with the guardrails and scale enterprise operations demand — plus everything in this guide. It investigates every alert, holds the autonomy dial you set, keeps one audit trail, runs your existing playbooks unchanged, and reads the SIEM, EDR, and cloud tools you already own.

Morpheus AI analyst workspace showing an encoded PowerShell phishing incident with AI Summary, attack graph, and timeline panels
At one of the world’s largest financial services organizations — $10B+ revenue, 190+ countries — D3 cut alert triage time 90% (10 minutes to 1) and gave each analyst 10× the daily alert-handling capacity.
Anonymized D3 enterprise customer.

Answer up to the board. Answer down to your team.
Accountable on every decision.

  • See Morpheus run a live investigation, start to finish
  • Get every question from this guide answered
  • Bring your toughest alert and pressure-test it with our team
Gartner Peer Insights 4.7 SOC 2 Type II Certified
LSEG S&P Global Cummins Scotiabank PwC
© 2026 D3 Security · Morpheus, the accountable agentic AI SOC platform d3security.com