M ManySignal
← All posts
AI & Agents Mar 9, 2026 · 9 min read

The Agentic Soc Is Not A Chatbot

MH

Marcus Hale

Head of Detection

The Agentic Soc Is Not A Chatbot is not an abstract topic for enterprise security teams — it sits at the intersection of the pressures that define modern security operations: alert volumes that outrun human capacity, budgets taxed by ingestion pricing, auditors demanding evidence, and a talent market that cannot fill the seats. This piece looks at the operational reality behind the headline, drawing on the patterns we see across enterprise SOCs and MDR practices every week.

The thread connecting all of it: the traditional SOC operating model scales with headcount, and headcount is the one input enterprises cannot scale. What follows is an honest tour of the pain points — and what changes when the work itself, rather than the humans, becomes the thing that scales.

01

The queue that never empties

Walk into any enterprise SOC at 9 a.m. and look at the queue. There will be somewhere between four hundred and four thousand alerts that arrived overnight, and a rota of tier-1 analysts expected to clear them before the next wave lands. The mathematics has not worked for years. A mid-size enterprise generates tens of millions of security events a day; even after correlation and suppression, the alert volume that survives is an order of magnitude beyond what a human team can investigate properly. So teams do what any rational actor does under impossible load: they sample. They work the highs, skim the mediums, and let the lows age out.

The uncomfortable truth is that attackers know this. Post-incident reviews keep finding the same pattern — the intrusion was detected, an alert did fire, and it sat unworked in the queue for eleven days because it was a medium riding behind three hundred other mediums. The detection stack did its job. The operating model around it failed. Detection coverage without triage capacity is not coverage at all; it is a compliance artefact that produces evidence of negligence after the breach.

Enterprises have tried to buy their way out with headcount, offshore tiers, and suppression rules. Each fix decays. Headcount churns, offshore tiers escalate anything ambiguous, and every suppression rule is a small bet that the suppressed pattern will never matter. The queue always wins — unless something other than a human works it.

02

Tool sprawl and the swivel-chair investigation

The average enterprise security stack now counts between forty-five and seventy-five tools. An analyst investigating a single suspicious login touches six of them: the SIEM for the alert, the identity provider for auth history, the EDR console for host state, the cloud console for API activity, the ticketing system for context, and a threat-intel portal for reputation. Each hop costs minutes, a login, and a mental context switch — and each tool speaks its own schema, so the analyst becomes a human ETL pipeline, joining datasets in their head at 2 a.m.

Vendors sell integration as the answer, but a webhook that copies an alert from one queue to another is not integration; it is duplication with extra latency. The join the analyst actually needs — this identity, across these five systems, over the last ninety days, compared against its own baseline — does not exist in any single console. It has to be rebuilt by hand for every investigation, which is why an investigation that should take ten minutes takes four hours.

The strategic cost is worse than the operational one. Because context lives in fragments, every conclusion is provisional. Analysts hedge, escalate, and re-investigate, and CISOs discover during incidents that their seventy tools produce seventy partial stories and no authoritative one.

03

Dwell time: the metric that indicts the model

Industry reports put median attacker dwell time somewhere between ten days and three weeks, depending on the year and the dataset. Consider what that number means: for two weeks, an active adversary moved through an environment that was instrumented, monitored, and staffed — and nothing connected the dots. Not because signals were absent, but because they arrived as disconnected alerts, each individually dismissible, spread across shifts and consoles and time zones.

Mean time to respond tells the same story from the other end. When an alert finally is worked, the clock has usually been running for hours. The alert waited in the queue, then waited for escalation, then waited for someone with cloud access, then waited for change approval to contain. Attackers operate in minutes; enterprise response is structured in handoffs, and every handoff is a queue.

The pattern that closes breaches fast is always the same: someone assembled the full chain — initial access, persistence, lateral movement — into one narrative early. Humans do this brilliantly but slowly, and only for the alerts they actually reach. The enterprises that cut dwell time from weeks to minutes are the ones that made chain assembly automatic instead of heroic.

04

Compliance evidence as a second full-time job

Every enterprise security team now serves two masters: the attackers and the auditors. SOC 2, ISO 27001, PCI DSS, DORA, HIPAA — each framework wants proof that monitoring exists, that alerts are investigated, that incidents follow procedure, that access reviews happen. Assembling that proof is a quarterly scramble of screenshots, CSV exports, and reconstructed timelines, performed by the same senior people who are supposed to be hunting threats.

The dirty secret is that most of this evidence is theatre. A screenshot of a dashboard proves the dashboard existed on the day of the screenshot. It says nothing about whether the alert at 3 a.m. on a Sunday in February was actually worked, by whom, and on what basis. Auditors accept it because nothing better is usually available, and everyone in the room quietly knows it.

Regulators are tightening. DORA and the SEC disclosure rules ask for operational reality, not intent — how fast incidents were detected, classified, reported. That standard cannot be met retroactively with screenshots. It requires an operating model where every detection, verdict, and response action generates its own tamper-evident record as a by-product of doing the work, not as a separate documentation exercise.

05

The MDR black box problem

Enterprises that give up on in-house coverage buy MDR, and most discover the same frustration within a year: the service is a black box. Alerts go in, closed tickets come out, and the reasoning in between is invisible. When the quarterly report says '14,000 alerts triaged, 12 escalated', there is no way to verify that the 13,988 closures were sound. You are asked to trust, without evidence, the same category of overloaded human analyst you were trying to escape — just employed by someone else.

The contract structure makes it worse. Response actions require a phone call and a change window. Data lives in the provider's tenant, so leaving means losing history. And when an incident does slip through, the post-mortem devolves into a liability negotiation between your counsel and theirs about what 'detected' means in schedule 3 of the SLA.

None of this means managed outcomes are the wrong goal — 24/7 coverage without building a night shift is exactly what most enterprises need. The failure is opacity. A managed detection function is only trustworthy if every verdict it renders arrives with its evidence attached: the questions asked, the answers found, the weights applied. Transparency is not a nice-to-have in MDR; it is the entire difference between a service and a liability shield.

06

Identity is the new perimeter, and it is on fire

The modern enterprise attack surface is not a network edge; it is a directory. Tens of thousands of human identities, and — increasingly — multiples more non-human ones: service accounts, API keys, CI runners, and now AI agents with standing credentials. Attackers noticed years ago that stealing a valid credential beats exploiting a vulnerability: no malware, no exploit signature, just a login that looks almost right. The majority of serious cloud incidents now begin with a compromised identity, not a compromised host.

Almost right is the operative phrase. A stolen credential logs in from a slightly wrong place, at a slightly wrong hour, and touches resources slightly outside its habit. Each signal alone is dismissible — which is exactly why rule-based detection drowns: the rules fire on travellers and contractors all day, and the SOC tunes them down until the real one sails through.

Catching identity abuse requires knowing each identity's normal — its hours, geographies, volumes, and peer group — and evaluating every anomaly against that baseline in context. That is a per-entity statistical problem multiplied by a hundred thousand entities, refreshed continuously. No human team maintains that. It has to be computed.

"The agentic SOC only works if every verdict can show its evidence. That is the bar this platform is built to."

The ManySignal take

What an agentic SOC changes

The agentic model attacks these pain points at their common root: the assumption that investigation capacity must be human. In ManySignal's architecture, telemetry from cloud, identity, endpoint, and code normalises into a temporal entity graph with behavioural baselines computed per identity and per asset. When a detection fires, an AI triage agent answers a structured question set against that graph — is this normal for this entity, is it correlated with other findings, how close is it to critical assets — and renders a verdict with a confidence score and the full evidence trail attached. Every alert gets this treatment, not the fraction a human rota can reach.

Response is governed rather than merely automated. The autonomy ladder grants capability per action class — recommend-only, approve-gated, autonomous — with dry-run previews, blast-radius limits, rollback state, and a tenant-level kill switch enforced by the engine itself. Compliance evidence generates itself as a by-product: every question, answer, weight, verdict, and action lands on an immutable timeline that auditors can replay. The result is a SOC whose capacity scales with compute, whose knowledge compounds instead of resigning, and whose every decision can show its work — run in-house, or consumed as transparent MDR.

None of these pain points is new, and none of them is solved by another dashboard. They are symptoms of an operating model that asks humans to do machine-shaped work — repetitive, contextual, around-the-clock — and then wonders why the queue grows and the people leave. The enterprises pulling ahead are not the ones with the most tools; they are the ones that moved investigation into software, kept judgment with humans, and made every automated decision auditable.

That is the bet behind ManySignal's agentic SOC and MDR platform: every alert worked to an evidence-weighted verdict, every action governed by an autonomy ladder you control, every decision on an immutable record. If the agentic soc is not a chatbot is on your roadmap this year, start by asking one question of your current operation: what percentage of your alerts reach a documented conclusion? If the honest answer makes you uncomfortable, the model — not the team — is the problem.

MH

Marcus Hale

Head of Detection

Writes about detection engineering, agentic security operations, and what it actually takes to move an enterprise SOC beyond the alert queue.

Frequently asked questions

What is The Agentic Soc Is Not A Chatbot in an agentic SOC?

The Agentic Soc Is Not A Chatbot is part of ManySignal's agentic SOC and MDR platform, where AI agents detect, triage, investigate, and respond to threats with human-governed autonomy.

How does ManySignal handle the agentic soc is not a chatbot?

ManySignal grounds the agentic soc is not a chatbot in a temporal entity graph and behavioural baselines, so every verdict is backed by auditable evidence rather than opaque scores.

Can ManySignal replace my SOAR or MDR for the agentic soc is not a chatbot?

Yes. ManySignal combines detection, triage, investigation, response, and reporting in one platform, and can operate as your MDR or augment an existing SOC team.

How is autonomy governed?

Through an autonomy ladder: recommend-only, approve-gated, and autonomous modes per action class, with dry-run previews, blast-radius limits, and a one-click tenant kill switch.

How fast is time to value?

Declarative connectors and shipped detections typically produce AI agent verdicts on live alerts within days, not quarters — no parsing projects or playbook-building phase.

Is ManySignal available as a managed service?

Yes. Consume ManySignal as MDR with 24/7 coverage and monthly reporting, run it as your in-house agentic SOC, or use it as the platform behind your own MDR practice.

How does ManySignal license the platform?

Pricing scales with protected assets and autonomy tier, not per-GB ingestion or per-alert volume. Starter, Growth, and Enterprise plans are available; MDR providers receive volume discounts for multi-tenant deployments.

Where does our data reside?

By default in AWS us-east-1. Enterprise tenants can pin data to specific AWS regions, deploy self-hosted on their own Kubernetes cluster, or use customer-managed encryption keys (CMK) to retain cryptographic control.

What does the evidence trail contain?

Each verdict stores the full question set, per-question agent answers, confidence weights, source event references, entity graph snapshots, and operator attestation — preserved immutably for the retention period chosen at contract time.

How does ManySignal handle a false-positive alert?

The triage agent auto-closes findings it assesses as false positives with a documented rationale — which rule fired, why the evidence fails to support escalation, and the entity baseline that informed the decision. Auto-closure rates typically reach 85–95% within 90 days as baselines mature.

Continue reading

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.