Morpheus · Guardrails
Five Guardrails. One Audit Trail. Autonomy You Can Prove.
Agentic SOC guardrails are the controls that stop an autonomous investigation from acting on evidence it cannot verify. Morpheus applies five of them to every investigation Attack Path Discovery (APD) runs. APD is D3’s investigation engine, tracing attacks across identities, endpoints, cloud, and email infrastructure.
A large US-based MSSP put all five under adversarial testing. APD 2.0 passed 5 of 5 scenarios with zero false all-clear verdicts. When Morpheus is uncertain, it defers to a human.
The five guardrails
- Data-source health checks on every query
- Verdict withholding when evidence is incomplete
- Investigation guidelines enforced per query
- A query-level audit trail you can reconcile
- Handoff to an analyst with the reason attached
The failure mode nobody demos
Every agentic SOC demo runs on healthy data. Production does not. A SIEM connector expires. An endpoint agent drops offline. An identity API drifts and starts returning partial results. The investigation still completes. It completes on less evidence than it appears to have.
That is where autonomy breaks. The AI queries, finds nothing, and reports nothing found. A real incident closes as benign and the record looks clean. Guardrails exist so that outcome cannot happen quietly.
The five guardrails
Guardrails run on every investigation, in every autonomy mode. They are properties of the engine, so they apply whether Morpheus drafts for your approval or closes cases end to end.
01
Data-source health. Morpheus knows when it cannot see.
Before APD trusts a result, it checks whether the query actually succeeded. Authentication failures, platform outages, and API drift are classified by cause and severity, then attached to the investigation. A permanent authentication error and an empty result set are different findings, and Morpheus records them differently.
Evidence
With Microsoft Sentinel authentication deliberately broken mid-investigation, APD 2.0 identified a permanent authentication issue and kept the incident open.
02
Verdict withholding. No confirmation without evidence.
When the evidence is incomplete, APD states that the verdict cannot be confirmed and names the root cause. The incident stays open. “No threat found” and “unable to verify” are separate outcomes with separate handling, and the summary says which one applies.
Evidence
Across three induced data-source failures, APD 2.0 produced zero false all-clear verdicts. When Morpheus is uncertain, it defers to a human.
03
Investigation guidelines. Your policy, enforced per query.
Investigation guidelines are rules you write. Morpheus applies them at query construction, before the query runs, so scoping happens at the field level of the data rather than in the model’s judgment. A guideline requiring a customer name in every SIEM search binds every search.
Evidence
In a multi-tenant SOC, that guideline held in every query APD 2.0 ran across the customer’s isolation probes.
04
Query-level audit trail. The summary is the record.
Every query APD executes is logged, and the investigation summary is generated from that log. What you read is what ran. Your auditors and regulators can reconcile the two line by line, without taking the narrative on trust.
Evidence
A query-by-query audit by the customer’s security engineering team returned an exact match. When Morpheus is uncertain, it defers to a human.
05
Human handoff. Escalation with the reason attached.
When a guardrail fires, Morpheus routes the investigation to an analyst with the failure cause, the queries attempted, and the partial evidence already gathered. Your team picks up context instead of rebuilding it. Once the underlying issue is fixed, the investigation reruns against complete data.
Evidence
After Okta API drift was corrected, APD 2.0 reran its queries and reached the correct conclusion.
Where guardrails fit
Autonomy sets the ceiling. Guardrails set the floor.
Guardrails are the Keep Control layer of the accountable agentic SOC platform. Autonomy Modes decide how much Morpheus does on its own. Guardrails decide what Morpheus does when it cannot finish the job safely. The two are designed together, so raising your autonomy level never lowers the evidence standard.
Proven under failure
5 / 5
A large US-based MSSP designed five adversarial scenarios and ran them against live APD 2.0 investigations. Their environment, their pass criteria. Zero false all-clear verdicts. When Morpheus is uncertain, it defers to a human.
faqs
Frequently Asked Questions
What are agentic SOC guardrails?
Agentic SOC guardrails are controls that keep an autonomous investigation from making wrong decisions on incomplete information. In Morpheus APD 2.0, guardrails detect data-source failures, withhold unverifiable verdicts, enforce customer-written investigation policies, keep a query-level audit trail, and hand off to a human analyst when evidence is incomplete.
What happens when Morpheus has incomplete information?
Morpheus does not guess. APD 2.0 states that the verdict cannot be confirmed, reports the root cause of the data problem, and fails to a human analyst. In customer testing this produced zero false negatives under induced data-source failures. When Morpheus is uncertain, it defers to a human. “No threat found” and “unable to verify” are different answers, and Morpheus knows the difference.
How is the audit trail verifiable?
Every query APD 2.0 lists in its investigation summary corresponds to a query it actually executed. The MSSP confirmed this with a query-by-query audit: a 100% match. When Morpheus is uncertain, it defers to a human. The investigation record is verifiable evidence your auditors and regulators can check.
How does tenant isolation work in a multi-tenant SOC?
Investigation guidelines act as enforceable policy. One guideline requiring the customer name in every Sentinel search was honored in every query APD 2.0 ran, scoping results at the field level of the SIEM data itself. Results from other tenants are excluded by construction.
How were the guardrails tested?
A large US-based MSSP operating a multi-tenant Microsoft Sentinel environment designed its own acceptance tests and ran them against live APD 2.0 investigations. Their scenarios, their environment, their pass criteria. APD 2.0 passed all five. The full test-by-test breakdown is in the MSSP guardrails case study.
Break it on purpose.
Bring your own failure scenarios to a 30-minute demo and watch what the guardrails do.
Updated August 2026. Customer results from independent acceptance testing; customer identity withheld by request. Related: MSSP guardrails case study · Agentic SOC glossary · Guardrails FAQ