AI Tier 3 Analyst
A verdict on every alert, with the evidence attached
The triage agent works every actionable finding the moment it's raised — answering a structured question set and synthesising a verdict with a confidence score.
How it works
Question sets, not prompts
Each detection type maps to a question set: is there intel on this actor? How often has this rule fired for this entity? Are there correlated open findings? Is the entity close to critical assets in the graph? Does behaviour deviate from baseline? Does business context explain it?
Weighted synthesis
Each answer contributes a weighted signal. The normalised score drives the verdict — escalate, false positive, or benign true positive — and the confidence reflects how much the signals agree.
Escalation with SLAs
Escalations become cases with priority and SLA clocks set by severity. Everything else is closed with a recorded, auditable rationale.
Key capabilities
Full reasoning trace
Every question, answer, and weight is stored on the agent run for audit and tuning.
Rule health feedback
Verdicts feed back into per-rule health metrics, surfacing noisy detections automatically.
Kill-switch aware
Tenant kill switch halts triage actions instantly without losing queued findings.
What security leaders say
“Every verdict comes with the question set, the answers, and the weights. Our auditors had never seen anything like it.”
Jonas Meyer
Director of Security & Compliance, Cobalt Health
“The kill switch mattered more than any demo. When leadership asked 'what if it goes wrong', we had a one-click answer.”
Rachel Steinberg
Deputy CISO, Northwind Bank
“Attack-chain reconstruction turned a 4-hour investigation into a 10-minute review. The case arrives already assembled.”
Victor Nkemelu
Incident Response Lead, Vantagrid
Triage Agent agent: frequently asked questions
What does the Triage Agent agent do?
The triage agent works every actionable finding the moment it's raised — answering a structured question set and synthesising a verdict with a confidence score. It operates as the AI Tier 3 Analyst inside ManySignal's agentic SOC and MDR platform.
How is the Triage Agent agent governed?
Like every ManySignal agent, it runs under the autonomy ladder: recommend-only, approve-gated, or autonomous per action class, with dry-run previews and a tenant kill switch.
Can I audit the Triage Agent agent's decisions?
Yes. Every question it answers, every verdict, and every action is recorded on an immutable case timeline with evidence weights.
Does it work with my existing stack?
Yes. Declarative connectors normalise telemetry from cloud, identity, endpoint, and code sources into the entity graph the agent reasons over.
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.