D3 Security · Security Operations Glossary
What Are Autonomy Modes?
A standalone glossary definition, part of the D3 Security Operations Glossary.
Definition
Autonomy modes are the graduated levels of independence a governed agentic SOC applies to response, set per alert class: Deterministic, AI-Assisted, AI-Led, and Autonomous. Each mode decides how, and whether, the platform executes a response, with per-action approval gates underneath.
Autonomy modes answer a question every SOC leader asks about AI: how much do I let it do, and where do I stay in control. A single human-in-the-loop switch answers that with one setting for everything. Autonomy modes answer it per alert class, so a low-risk, high-volume alert can run further toward autonomous while a consequential alert class stays gated.
The four autonomy modes
| Mode | What the platform does | Where the human stays |
|---|---|---|
| Deterministic | Runs rule-based automation only, with no AI judgment in execution | In full control of every rule and action |
| AI-Assisted | Investigates and recommends a response plan | Approves each response action before it executes |
| AI-Led | Executes within gates set by command-risk tagging | Approves the consequential and high command-risk actions |
| Autonomous | Investigates and responds end to end within pre-set command-risk gates; the self-learning pipeline tunes confidence from past decisions | Sets the gates, retains override, and reviews the audit trail |
Also see:
Command-Risk Tagging
Governed Agentic SOC
How autonomy modes work with command-risk tagging
Autonomy modes decide how, and whether, the platform executes. Command-risk tagging sets the per-action approval gate underneath the chosen mode. This is why a governed agentic SOC is not one on-off switch: the mode sets the ceiling, and command-risk tagging scopes the gates per action. Whatever the mode, every step lands in one traceable record per incident, so the level of autonomy never changes the quality of the audit trail.
How are autonomy modes built in Morpheus?
In Morpheus, the four autonomy modes govern execution from fully deterministic to fully autonomous, per alert class, with command-risk tagging setting approval gates at stage 5 of the alert lifecycle. Investigation and scoring run at machine speed in every mode; only the response stage is gated. The self-learning pipeline in Autonomous mode tunes confidence from past decisions, and it never acts on its own learning without approval. See the full breakdown on the Morpheus Autonomy Modes page.
Frequently asked questions
What are the four autonomy modes?
Deterministic, AI-Assisted, AI-Led, and Autonomous. Each mode decides how, and whether, a governed agentic SOC executes a response, set per alert class, with per-action approval gates underneath.
What is the difference between AI-Assisted and AI-Led?
In AI-Assisted, the platform investigates and recommends, and a human approves each response action. In AI-Led, the platform executes within gates, and a human approves the consequential and high command-risk actions rather than every action.
Can different alert classes run in different modes?
Yes. Autonomy modes are set per alert class. A low-risk, high-volume alert can run further toward autonomous while a consequential alert class stays more gated, so you concentrate human judgment where it matters.
How do autonomy modes relate to command-risk tagging?
The autonomy mode decides how, and whether, the platform executes a response. Command-risk tagging sets the per-action approval gate underneath the chosen mode. The mode sets the ceiling; command-risk tagging scopes the gates per action.
Is Autonomous mode the same as no human oversight?
No. Autonomous mode runs investigation and response end to end within pre-set command-risk gates, with human override available at any stage and one audit trail per incident. It is credible autonomy, not reckless autonomy.
Do autonomy modes change the audit trail?
No. Every mode produces one traceable record of every step per incident. The chain of custody does not change with the mode; only how far the platform runs before a human gate does.
How is this different from human-in-the-loop?
Human-in-the-loop usually means one switch: a person approves everything or nothing. Autonomy modes are graduated, set per alert class, with per-action gates underneath. The human is in command of the loop, and chooses where to be in it.
Related terms
Governed Agentic SOC — The operating model that applies autonomy modes to response.
Command-Risk Tagging — The per-action approval gates that sit underneath each mode.
Autonomous SOC — A SOC where investigation and response run without constant human intervention.
Bounded Agentic Reasoning — Autonomous reasoning held inside explicit iteration, cost, tool-scope, and approval-gate limits.
Further reading
Morpheus Autonomy Modes
Why fail-open matters
Book a demo
Last updated: July 2026