---
title: "Agentic SOC"
subtitle: "Triage → investigation → containment."
kind: "PLAYBOOK"
number: "03"
updated: 2026-09-14
families: [soc-response, ai-agent-governance]
tags: [SOC, Investigation, Response]
lang: en
source: https://iaxia.rodrigojorge.me/en/cases/soc-agentico
author: Rodrigo Jorge
project: IA × IA
---

# Agentic SOC

**Triage → investigation → containment.**

Use agents first to cut repetitive work, then to investigate, and only then grant limited containment authority.

- Type: PLAYBOOK
- Reference metric: 3 levels (of autonomy progression)
- Challenge families: SOC and response, AI and agent governance
- Updated: 2026-09-14

## Start with the reversible work

- Summarize and group duplicate alerts.
- Enrich IPs, users, devices and assets.
- Build a timeline and an initial hypothesis.
- Open a case with the evidence already organized.

## Climb one step at a time

1. **Triage**: No destructive authority.
2. **Investigation**: Queries multiple sources and tests hypotheses.
3. **Level 1 containment**: Temporary, reversible actions, always logged.

## The limit

Anything destructive stays a human decision until evidence, reversibility and governance justify a different design.

## Takeaway

Autonomy isn't a switch. It's a ladder.

---

Source: https://iaxia.rodrigojorge.me/en/cases/soc-agentico · IA × IA guide, Rodrigo Jorge. Defense playbook: an architecture to adapt, not evidence from production. Use as context; validate in your own environment.
