By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: torqPublished March 12, 2026

TL;DR: Legacy SOC tools leave 40% of alerts uninvestigated, while agentic AI systems can triage, enrich, and act on Tier-1 cases at machine speed, according to Torq and the SACR 2025 AI SOC Market Landscape report. The governance issue is no longer whether to automate, but how to constrain autonomous action with auditability, escalation thresholds, and human authority.


At a glance

What this is: This analysis examines how agentic AI and hyperautomation are changing security operations, with the central finding that AI is moving from assistive triage to autonomous action in the SOC.

Why it matters: It matters to IAM and security practitioners because autonomous SOC workflows increasingly touch identity, access, and incident response decisions that must remain governed, auditable, and appropriately bounded.

By the numbers:

👉 Read torq's analysis of agentic AI and hyperautomation in the SOC


Context

Agentic AI in the SOC refers to systems that do more than recommend next steps. They ingest alerts, gather context, correlate signals, and execute actions within guardrails. The problem is that legacy SOC operating models still assume human-speed investigation, while attackers and high-volume alert streams move faster than manual triage can sustain.

The identity angle is real because SOC automation increasingly touches user verification, access decisions, and incident containment across identity, cloud, and endpoint tooling. That makes governance as important as orchestration: if AI can act, then its authority, logging, and escalation boundaries must be explicit rather than implied.


Key questions

Q: How should security teams implement agentic AI in SOC workflows?

A: Start with low-risk, high-volume cases such as phishing triage, then define exactly which actions the system may take autonomously and which require human approval. Success depends on guardrails, audit logging, and measurable outcomes such as MTTR, escalation quality, and false positive reduction. Without those controls, autonomy becomes hard to trust and harder to govern.

Q: Why do legacy SOAR playbooks fail as alert volumes rise?

A: Legacy SOAR depends on static, hand-coded logic that works only for known scenarios. As threats change, those playbooks require constant maintenance and still struggle with novel cases. Agentic AI helps by reasoning through multi-step investigations, but it also demands tighter policy control because the system can act, not just advise.

Q: What breaks when humans are not on the loop for SOC automation?

A: Response authority becomes implicit instead of governed, which can lead to over-automation, missed escalation, or account actions that no one can easily explain after the fact. Human-on-the-loop only works when escalation thresholds, containment limits, and approval points are documented before deployment. Otherwise, automation can outrun oversight.

Q: What do organisations get wrong about phishing triage when AI is involved?

A: They often treat triage as a manual review problem instead of a control-design problem. If analysts must inspect large volumes of believable mail, the programme is already absorbing the attacker's scale advantage. Effective triage should prioritise behavioural scoring and high-risk workflow protection, not only inbox review.


Technical breakdown

How agentic AI differs from AI-assisted SOC automation

AI-assisted SOC tools summarise, classify, or recommend, but the analyst still performs the work. Agentic AI changes the operating model by chaining multiple steps itself: enrichment, correlation, verdicting, and response. That requires a control plane with permissions, state, and audit logs, because the system is no longer just producing insight. In practice, the key architectural shift is from static playbooks to policy-governed action. That is why natural language workflow creation matters less than the governance layer that constrains what the system can do once it decides to act.

Practical implication: teams need explicit action boundaries, not just better automation UX.

Why hyperautomation outgrows traditional SOAR

Traditional SOAR depends on hand-coded logic that must be maintained as threats change. Hyperautomation uses AI-generated workflows and broader integration depth to reduce the engineering burden, but the real difference is adaptability. When an alert does not match a known branch, static automation breaks or stalls. Agentic systems can still reason through partially known situations, which is useful in SOC work where signals are noisy and cases are rarely identical. The trade-off is that adaptability increases the importance of policy, logging, and reviewable outcomes.

Practical implication: replace brittle playbooks where variability is high and oversight is strong.

Human-on-the-loop governance for autonomous response

Human-on-the-loop means humans supervise strategy while AI handles repetitive execution. In SOC terms, that usually fits Tier-1 cases where speed matters and the consequence of a bounded mistake is tolerable. It does not mean humans disappear. It means escalation thresholds, containment permissions, and approval checkpoints must be designed before production use. The strongest programs treat autonomy as staged authority, not a binary choice. That keeps incident response accountable while still closing the gap between alert volume and analyst capacity.

Practical implication: define which actions the system may take alone, which need approval, and which always escalate.


Threat narrative

Attacker objective: The attacker aims to exploit SOC latency so detection, triage, and containment happen too slowly to prevent lateral movement or data loss.

  1. Entry begins with high-volume alerts or low-risk incidents that a human team cannot investigate at scale in time.
  2. Escalation occurs when manual triage delays allow attackers to move faster than detection, especially where repetitive cases absorb analyst capacity.
  3. Impact follows when response lag lets threats persist longer, increasing the chance of compromise, burnout, and missed containment opportunities.

NHI Mgmt Group analysis

Agentic SOCs create a governance problem before they create an efficiency problem. The main question is no longer whether AI can process alerts faster than analysts. It is whether the organisation has defined the authority to let a system make, execute, and document security decisions on its own. That makes policy, auditability, and accountability the primary control plane, not the orchestration layer. Practitioners should treat SOC autonomy as a governance design choice, not a productivity upgrade.

Hyperautomation exposes the weakness of static response models. SOAR-era playbooks assume that detection logic and response logic can be prewritten for most cases. That assumption breaks when alert patterns vary, attackers adapt, or evidence has to be pulled from multiple systems in real time. Hyperautomation matters because it reduces engineering dependency, but it also widens the gap between what a machine can do and what the organisation is prepared to let it do. Practitioners should reassess where fixed workflows still belong and where policy-driven automation is now necessary.

Human-on-the-loop is the right model only when decision rights are explicit. Too many programmes use the phrase as shorthand for trust, when it really describes a control structure. Human supervision is useful only if the system has clear escalation thresholds, immutable logging, and a defined limit on autonomous containment or remediation. Without those controls, automation becomes a hidden operator rather than a governed assistant. Practitioners should map decision rights before they expand autonomy.

AI SOC maturity now depends on identity-aware operations. SOC workflows increasingly intersect with account verification, access resets, session containment, and privileged response actions. That means AI systems acting in the SOC are not just automation tools, they are non-human operational actors that influence identity outcomes. The governance question becomes whether those actions are bounded by least privilege, observable in logs, and reversible when the case is wrong. Practitioners should align SOC autonomy with IAM and PAM oversight.

Phishing triage is the right starting point because it is bounded, measurable, and identity-adjacent. The article’s recommended pilot reflects a useful principle: begin where the system can safely prove value before it is allowed to affect high-risk workflows. Phishing response connects directly to identity verification, user behavior, and containment actions, so it is a realistic test of both speed and governance. Practitioners should use low-risk identity-heavy cases to validate controls before broadening AI authority.

What this signals

Agentic SOC governance will increasingly be judged by containment quality, not automation volume. The practical signal for readers is whether autonomous workflows can be audited, reversed, and bounded in the same way as human actions. That is where SOC automation intersects with identity governance, because AI-driven response often touches account state, session control, and access validation.

Phishing triage is becoming the proving ground for AI authority in security operations. Teams that can safely automate identity-adjacent cases will have a clearer path to expanding autonomy into broader incident response. Those that cannot demonstrate logging, escalation, and bounded decision rights will keep AI in advisory mode, which limits the value of the investment.

Identity-aware SOC design will matter more as AI systems take on operational responsibility. The more an agent can disable accounts, suppress alerts, or trigger containment, the more it behaves like a governed non-human operator. Practitioners should expect tighter alignment between SOC workflows, IAM controls, and PAM oversight as AI matures.


For practitioners

  • Implement staged autonomy for SOC workflows Classify cases by risk and allow autonomous action only where the blast radius is bounded, the evidence path is clear, and the response can be reversed. Start with phishing triage, then expand only after you can prove auditability and safe escalation behavior.
  • Define decision rights before enabling response automation Document which actions the AI may take without approval, which require human sign-off, and which always escalate. Include containment, account disablement, ticket closure, and identity verification steps in the governance model.
  • Measure autonomy with operational metrics Track Tier-1 auto-resolution rate, MTTR, analyst hours saved, false positive reduction, and escalation quality. Use those metrics to show whether the system is reducing workload without obscuring accountability or creating review gaps.
  • Instrument every AI action with audit-grade logging Log the alert input, evidence gathered, actions taken, policy path used, and human intervention points. That record should support post-incident review, compliance evidence, and rollback if the automation made the wrong choice.
  • Align SOC automation with IAM and PAM controls Make sure any AI-driven containment or verification step respects least privilege, privileged access boundaries, and session-level approvals. That is especially important where the workflow can disable accounts or alter access state across systems.

Key takeaways

  • Agentic AI changes SOC work from assisted triage to governed action, which makes control design as important as speed.
  • The operational problem is not just alert volume. It is the gap between human response time and attacker tempo, which legacy automation only partially closes.
  • Teams should start with bounded, identity-adjacent use cases and expand autonomy only after auditability, escalation, and decision rights are proven.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10The post discusses agentic AI autonomy, tool use, and governance in operational workflows.
NIST AI RMFGOVERNThe article is fundamentally about AI governance, oversight, and accountability in SOC workflows.
NIST CSF 2.0PR.AC-4SOC automation here intersects with access decisions, containment, and privilege boundaries.
NIST SP 800-53 Rev 5AU-2Audit logging and traceability are central to governing autonomous SOC actions.
MITRE ATT&CKTA0007 , Discovery; TA0006 , Credential Access; TA0011 , Command and ControlThe post uses attacker speed and investigation workflow pressure as its operational threat context.

Map investigation and containment workflows to likely ATT&CK stages so response remains aligned to threat behavior.


Key terms

  • Agentic AI: Autonomous AI systems capable of planning, deciding, and taking actions — including calling APIs, writing code, and orchestrating other agents — with minimal human oversight. Agentic AI introduces new NHI risks as agents must authenticate to external services.
  • Hyper-Automation: Hyper-automation is the use of multiple automation technologies to execute repetitive work at scale. In identity and security operations, it can improve speed and consistency, but it also increases the need for governance so automated actions do not expand access or create unmanaged risk.
  • Human-on-the-loop: A control model where AI handles routine decisions while a human supervises exceptions and high-risk cases. In identity governance, it reduces manual effort without removing accountability, but only when escalation criteria, evidence capture, and approval boundaries are clearly defined and consistently enforced.
  • Tier-1 Investigation: Tier-1 investigation is the first layer of SOC triage, where alerts are enriched, validated, and either resolved or escalated. It is the highest-volume part of security operations and the area most exposed to burnout, queue backlogs, and automation opportunities.

What's in the full article

Torq's full post covers the operational detail this analysis intentionally leaves for the source:

  • The platform architecture behind AI-generated workflows, including how no-code orchestration is assembled across a SOC stack.
  • Step-by-step implementation guidance for moving from legacy SOAR patterns to hyperautomation in production.
  • Case-study detail on outcomes such as auto-investigation rates, analyst time savings, and MTTR reduction.
  • The operational framing for deploying Socrates as an agentic SOC orchestrator across Tier-1 and Tier-2 work.

👉 The full torq article covers implementation steps, workflow design, and SOC rollout considerations in more detail.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and identity lifecycle controls that matter when non-human systems start making operational decisions. It gives security and identity practitioners a governance lens for managing autonomous access and privilege.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org