TL;DR: Agentic SOC triage can reach under $2 per alert, with Morpheus cited at $0.97 and 98% accuracy when uncertainty is deferred to a human, according to D3. The economics matter because SOC automation now has to prove not just speed, but bounded trust, auditability, and analyst oversight.
At a glance
What this is: This is a D3 research-led analysis of the economics and control model behind agentic SOC triage, with the key finding that per-alert costs can fall sharply when AI handles routine work and defers uncertain cases to humans.
Why it matters: It matters because SOC teams adopting AI-assisted triage still need defensible oversight, evidence quality, and escalation boundaries, which are the same governance questions identity and access teams face when automation takes on decision-making.
By the numbers:
- Morpheus: $0.97 at 98% accuracy; when uncertain, it defers to a human.
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes and as quickly as 9 minutes in some cases.
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials.
👉 Read D3's research on the agentic SOC triage economics and operating model
Context
Agentic SOC describes security operations where AI systems help process alerts, triage events, and route work with limited human intervention. The governance problem is not whether automation can reduce analyst load, but whether the organisation can prove what the AI did, when it deferred, and where human approval still governs high-risk decisions.
In this context, cost-per-alert is only useful if it is paired with control boundaries. SOC teams, IAM leads, and GRC practitioners should treat agentic triage as an access and accountability issue as much as an operations issue, because the same trust gap appears whenever software is allowed to act before a human signs off.
D3 frames the current starting position as typical for teams under alert pressure, not an unusual edge case.
Key questions
Q: How should security teams govern agentic triage in the SOC?
A: Treat the agent as an operational system with scoped access, documented decision boundaries, and mandatory logging. It can assist with evidence gathering and correlation, but human reviewers should own containment decisions and exception handling. Governance should focus on what data the agent can see, what systems it can touch, and who can override its conclusions.
Q: Why do AI-driven SOC workflows need stronger governance than traditional automation?
A: Traditional automation follows predefined rules, but AI-assisted workflows can change how a case is interpreted, prioritised, or escalated. That makes governance more important, not less, because the decision path becomes less predictable. Teams need evidence, logging, and ownership controls that fit probabilistic recommendations, not just scripted workflows.
Q: What breaks when agentic triage has no clear deferral boundary?
A: The SOC can no longer explain why a case was auto-processed, why a signal was dismissed, or who accepted the risk. That creates an accountability gap, weakens post-incident review, and makes cost claims hard to trust.
Q: Who is accountable when an AI triage system misses an incident?
A: The organisation remains accountable, even if software performed the first-pass analysis. Risk owners, SOC leadership, and the control owner for the workflow need to define approval rights, review obligations, and evidence retention before the system is relied upon.
Technical breakdown
How agentic SOC triage changes the cost model
Agentic triage changes the economics by moving repetitive classification, enrichment, and first-pass routing from analysts to software. The key operational shift is that the unit of value becomes not just fewer alerts handled by humans, but fewer human minutes required per alert while maintaining acceptable accuracy. That only works when the system can separate routine signals from ambiguous ones and preserve a review trail for the latter. In practice, cost claims are meaningless without knowing what is automated, what is deferred, and what is still manually validated.
Practical implication: benchmark savings against analyst minutes saved per alert, not only vendor-stated accuracy.
Why human deferral is a control, not a fallback
Human deferral is a governance mechanism that prevents low-confidence automation from becoming a silent decision engine. In agentic SOC design, the system must know when uncertainty crosses a threshold and stop short of actioning a conclusion on its own. That makes deferral part of the architecture, not an exception path. For SOCs, the important questions are whether the confidence threshold is explainable, whether deferred cases are reviewed consistently, and whether the audit trail captures both the machine assessment and the human override.
Practical implication: define explicit deferral thresholds and audit them as part of SOC control testing.
Agentic SOC pricing depends on where liability sits
SOC pricing models are really liability models in disguise. If the AI performs more of the investigative work, the organisation still owns the consequences of false positives, missed escalation, and weak evidence handling. That is why per-alert pricing has to be judged alongside approval gates, logging fidelity, and case provenance. A low price can be attractive, but only if the operating model still supports incident response, compliance review, and post-incident reconstruction. Otherwise, the savings are offset by weaker defensibility.
Practical implication: require vendors and internal teams to map pricing assumptions to evidence retention and accountability controls.
NHI Mgmt Group analysis
Agentic SOC economics are a governance story, not just a cost story. A low per-alert figure only matters if the organisation can show where human judgment was removed, where it was retained, and how exceptions were handled. For SOC leaders, the decisive issue is whether automation reduces load without creating an evidence gap that undermines incident response, audit, or legal review. The practitioner conclusion is straightforward: treat savings claims as incomplete until they are paired with defensible control design.
Deferral is the named control boundary that makes agentic SOC viable. In this model, the AI is allowed to work quickly only until uncertainty or risk crosses a threshold, at which point it defers to a human. That makes deferral the equivalent of a privilege boundary in identity programmes, because it defines where software stops acting independently. The practitioner implication is to validate the threshold, the logging, and the handoff path before trusting any economics claim.
Agentic SOC adoption will push security teams toward measurable autonomy limits. The market is moving from abstract automation claims to questions about how much independent action a system can take before oversight is required. That shift mirrors broader governance pressure in NHI and agentic AI, where control is less about blocking AI and more about defining bounded authority. Practitioners should expect procurement, risk, and operations teams to ask for autonomy metrics rather than generic efficiency promises.
This category is converging on an identity-and-accountability model for AI operations. Once AI systems participate in triage, investigation, and routing, their permissions, approvals, and audit trails become operational controls, not implementation details. That is where SOC tooling intersects with identity governance: who or what is allowed to decide, and under what conditions. The practitioner conclusion is to align agentic SOC design with governance patterns already used for high-risk access, not with simple workflow automation.
What this signals
Autonomy limits will become a procurement requirement. SOC teams should expect agentic triage products to be judged less on generic accuracy and more on the ability to define, test, and log the point at which the AI must stop acting. That shifts purchasing decisions toward governance evidence, not just workflow speed. Practitioners should plan for control testing that resembles access-risk validation, not feature evaluation.
The next maturity step for agentic SOC is not more automation, but better proof of restraint. Teams that cannot show what was deferred, why it was deferred, and who reviewed it will struggle to defend the operating model in audit and incident review. That makes auditability a first-class design requirement, not a reporting add-on.
As agentic systems spread across security operations, the same governance patterns used for high-risk access will matter more, especially when tooling can enrich, route, and prioritise cases independently. For teams building broader AI governance, the relevant question is whether every autonomous action has a traceable owner, a bounded scope, and a review path.
For practitioners
- Define confidence thresholds for escalation Set clear thresholds for when the AI must defer to an analyst, and test those thresholds against real alert samples before expanding autonomous triage scope.
- Measure per-alert savings against analyst effort Track minutes saved, queue reduction, and analyst touchpoints per alert so CFO-facing pricing claims can be compared with actual operating impact.
- Audit the evidence trail for every deferred case Require the case record to capture machine output, confidence score, human override, and final disposition so incident reconstruction remains defensible.
Key takeaways
- Agentic SOC triage can reduce cost per alert, but the savings are only credible when autonomy is bounded and auditable.
- A low per-alert price does not remove accountability, because the organisation still owns missed escalations, false confidence, and evidence quality.
- SOC teams should treat deferral thresholds, audit trails, and case provenance as core controls, not optional implementation details.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST AI RMF, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Agentic triage changes who or what can act on security events. |
| NIST AI RMF | GOVERN | The article focuses on oversight, accountability, and control boundaries for AI in operations. |
| NIST SP 800-53 Rev 5 | AU-2 | AI-driven triage depends on reliable event logging and case provenance. |
| CIS Controls v8 | CIS-8 , Audit Log Management | Defensible SOC automation depends on traceable logs and consistent evidence retention. |
Use GOVERN to define ownership, escalation rights, and audit expectations for agentic SOC workflows.
Key terms
- Agentic Soc: An agentic SOC is a security operations model where AI systems assist with triage, investigation, and response using tool access and execution authority. The control challenge is not just accuracy, but governance of what the machine can see, decide, and do.
- Deferral threshold: The point at which an AI system stops acting on a case and hands it to a human reviewer. In security operations, this threshold is a control boundary that limits unsafe automation, preserves accountability, and keeps high-uncertainty events inside the human review process.
- Case provenance: The record of how a security case was created, enriched, classified, escalated, and closed. Provenance matters because it lets teams reconstruct the path from alert to outcome, showing which steps were machine-driven, which were human-reviewed, and where decisions changed.
What's in the full report
D3's full research covers the operational detail this post intentionally leaves for the source:
- Field observations from D3 deployments showing how agentic SOC triage changes analyst workload and queue handling.
- Pricing questions that expose whether the AI cost model survives CFO scrutiny under different alert volumes.
- The Morpheus pricing and accuracy framing in more detail, including when the system defers to a human.
- The governance assumptions behind agentic SOC autonomy and where review trails need to be preserved.
Deepen your knowledge
NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, secrets management, and agentic AI identity. It helps practitioners connect access control, accountability, and lifecycle governance across modern security programmes.
Published by the NHIMG editorial team on August 1, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org