Every alert arrives with its homework done.
A detection fires. Before an analyst opens it, the context is already gathered, the runbook is already loaded, and the tools are already connected. Read-only, and only the ones you allowed.
The shape
Trigger, context, workspace.
Everything between the event and the first turn is gathered by an automation, so the agent never starts from nothing.
Trigger
Splunk · detection 4471
Impossible travel · svc-payments
Two successful logins, 4,100km apart, 18 minutes.
Gathered first
- Asset owner and on-call rota from the CMDB
- 24 hours of authentication events for the principal
- Related detections on the same asset this week
- The runbook for this detection ID
- The last six tickets that closed as false positive
Composed of
soc-triage
- mcp
- splunk, crowdstrike (read-only)
- tools
- github
- ttl
- 2h
An analyst opens a workspace that has already done the legwork, and spends their time on the decision instead of the gathering.
What it displaces
Before and after.
Forty minutes proving an alert is not real
Four minutes deciding whether it is
A runbook nobody opens because finding it takes longer than guessing
The runbook already in the workspace, for this detection ID
An AI SOC product with someone else's detection logic
Your runbooks, your model, your data boundary
