IA × IA / PLAYBOOK
PLAYBOOK · No. 03

Agentic SOC

Triage → investigation → containment.
Use agents first to cut repetitive work, then to investigate, and only then grant limited containment authority.
3 levelsof autonomy progression
SOCInvestigationResponse
Updated Sep 14, 2026

Start with the reversible work

  • Summarize and group duplicate alerts.
  • Enrich IPs, users, devices and assets.
  • Build a timeline and an initial hypothesis.
  • Open a case with the evidence already organized.

Climb one step at a time

TriageNo destructive authority.
InvestigationQueries multiple sources and tests hypotheses.
Level 1 containmentTemporary, reversible actions, always logged.

The limit

Anything destructive stays a human decision until evidence, reversibility and governance justify a different design.

Takeaway: Autonomy isn't a switch. It's a ladder.
Take this playbook with you

In Markdown to paste into your AI, or as the starting point for your own playbook.

Open this playbook in your AIChatGPTClaudePerplexityCopilotGrok