Back to workflows
Security & ITEnrich and routeTeam

SOC alert triage

Enrich alerts, rank confidence, and prepare a cited disposition for analyst approval.

What this workflow does

Enrich alerts, rank confidence, and prepare a cited disposition for analyst approval. It resolves identity, enriches the case with approved evidence, and shows why the proposed route is appropriate before anything is assigned.

What you gain

Analyst-approved alert disposition

What the AI agent changes

How this worked before

Rule-based routing handled only clean, predefined fields and broke when the request was incomplete or written in natural language.

What the AI agent changes

The agent can interpret unstructured context, gather missing evidence, explain its recommendation, and pause when confidence is low.

Agent trigger

A supported security alert enters the SOC queue.

Inputs

  • Process context: alert, asset, identity, threat intelligence, and prior cases
  • Approved policies, ownership, and exception rules

Agent flow

  1. 1

    Resolve the case identity and validate source freshness.

  2. 2

    Enrich the case with approved context and show every scoring signal.

  3. 3

    Prepare a cited severity, disposition, and response route with confidence and exceptions.

  4. 4

    Create the approved assignment and notify its owner.

Human decisions

After step 3

The accountable process owner approves a cited severity, disposition, and response route.

Outcome

  • Analyst-approved alert disposition
  • Evidence, exceptions, and audit trail

Guardrails

  • Do not route low-confidence identity matches automatically.
  • Use an allowlist of destinations and writable fields.

Risks and mitigations

A wrong identity match can send a case to the wrong owner.

Require deterministic identifiers and expose the routing rationale.

Sources and evidence

Sources establish feasibility or impact. Not every metric comes from an identical implementation.