By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: ExaforcePublished March 17, 2026

TL;DR: GigaOm compared 19 SecOps automation vendors and highlighted an agentic SOC approach for automating detection, triage, investigation, and response across identities, resources, and time, according to Exaforce. The broader shift is that SecOps is moving from static playbooks to AI-driven correlation, where identity context becomes operational, not optional.


At a glance

What this is: This is a vendor-authored reaction to GigaOm’s 2025 SecOps Automation Radar, with the key finding that agentic AI and cross-domain correlation are becoming central to modern security operations.

Why it matters: It matters to IAM and security teams because SOC automation now depends on identity context, especially where alerting, investigation, and response intersect with service accounts, SaaS access, and other NHIs.

By the numbers:

👉 Read Exaforce’s analysis of the 2025 GigaOm Radar for SecOps Automation


Context

Security operations are under pressure from alert volume, cloud complexity, and identity sprawl. In that environment, automation is no longer just about reducing analyst workload. It is about deciding which signals can be trusted, which identities are involved, and how far response can safely progress without creating more risk.

The identity angle is real here because the article describes correlations across identities, resources, and time. That is a governance problem as much as an operations problem, since SOC tooling now needs to reason about service accounts, tokens, and human accounts in one investigation path. For readers who are mapping this to broader NHI practice, the question is not whether AI helps, but whether the identity data beneath it is governable enough to support response decisions.


Key questions

Q: What breaks when SOC teams automate without identity visibility?

A: When SOC teams automate without identity visibility, they lose context about which identities moved, what privileges changed, and whether an access path was legitimate. AI may still prioritise alerts, but it cannot reliably distinguish benign activity from attacker movement. The result is faster triage built on incomplete evidence.

Q: Why does identity sprawl make SecOps automation harder to trust?

A: Because the platform must reason over many identity types at once, including human users, service accounts, and machine credentials. If ownership, privilege scope, or lifecycle state is unclear, the automation cannot reliably distinguish normal delegation from malicious activity. Trust depends on clean identity metadata, not just better alerting.

Q: How can analysts tell whether AI-driven SOC automation is actually working?

A: Look beyond alert volume and measure whether the platform produces accurate incidents, preserves tenant context, and shortens time to closure without creating rework. If analysts still need to reconstruct the story manually, the automation is reducing noise but not truly improving operational control.

Q: Which frameworks matter when SOC automation depends on identity data?

A: NIST-CSF and NIST SP 800-53 are the most useful anchors because they connect logging, access control, monitoring, and auditability. For identity-heavy environments, NHI governance also matters because service accounts and credentials often feed the same automated workflows. The question is whether the control stack can support defensible machine-assisted decisions.


Technical breakdown

How agentic SOC automation changes detection and response

Agentic SOC platforms combine detection, triage, investigation, and response into a single workflow layer. Instead of handing every alert to an analyst, they attempt to correlate telemetry, prioritise likely incidents, and trigger next actions with some degree of system-level reasoning. The technical difference is not just faster scripting. It is a shift from deterministic playbooks to model-driven orchestration, where the platform decides which evidence matters and how to sequence steps. That creates efficiency, but also concentrates trust in the quality of the underlying data and model outputs.

Practical implication: verify which response steps remain human-approved and which are executed automatically before enabling agentic automation.

Why identity sprawl changes correlation quality

Identity sprawl makes SecOps correlation harder because the same user journey can span human accounts, service accounts, SaaS permissions, cloud roles, and machine credentials. If the platform cannot normalise those identities into a coherent graph, correlation becomes shallow and noisy. The article’s reference to stitching events across identities, resources, and time points to the need for context-rich telemetry rather than raw alert counts. In practice, identity-aware correlation depends on stable inventory, clear ownership, and enough metadata to distinguish routine privilege from suspicious delegation.

Practical implication: improve identity context in log pipelines before expecting higher-fidelity automated triage.

What a pre-LLM data layer actually does for SecOps

A pre-LLM data layer is the normalization and enrichment stage before model inference. It removes duplication, standardises fields, and adds context from logs, configs, identities, and code so the model can reason over cleaner inputs. Without that layer, generative or agentic systems inherit the same ambiguity that burdens analysts. In security operations, data quality is not cosmetic. It determines whether the platform can distinguish correlated events from unrelated noise, and whether it can safely automate next steps based on evidence that is actually consistent.

Practical implication: treat identity and log normalization as a control prerequisite, not a back-end optimisation.


NHI Mgmt Group analysis

Agentic SOC is becoming an identity governance problem, not just an operations problem. Once a platform is correlating identities, resources, and time, it is implicitly making decisions about trust, ownership, and privilege scope. That pushes SOC automation into the same governance conversation as IAM and NHI management. The practical conclusion is that automation maturity now depends on identity data quality as much as on detection logic.

Identity sprawl is the named risk that modern SecOps platforms must absorb. The article points to a world where analysts no longer review isolated alerts, but linked activity across human and non-human identities. That is the core governance challenge: if the identity inventory is incomplete, automated correlation will miss relationships or overstate risk. Readers should treat identity sprawl as an operational control gap, not a reporting inconvenience.

Pre-LLM data quality is the differentiator between usable automation and expensive noise. Normalizing logs, configs, identity data, and code before model analysis is what allows the SOC to move from pattern matching to evidence-driven action. But this also raises the bar for data stewardship, because bad inputs create confident errors at machine speed. Practitioners should align SOC automation with NIST-CSF and NIST SP 800-53 control expectations around logging, access control, and auditability.

AI in SecOps will increasingly expose the boundaries of current IAM and NHI programmes. If automated investigation can reason across service accounts, tokens, and human sessions, then entitlement hygiene and credential governance become upstream dependencies for response quality. That means the SOC can no longer be separated from identity lifecycle governance. The conclusion for security leaders is straightforward: if the identity layer is messy, the automation layer will inherit that mess.

GigaOm’s market framing suggests the category is moving toward outcome-based automation, not tool accumulation. Vendor differentiation is shifting from detection features alone to how well a platform can reduce noise, preserve context, and drive response at scale. For practitioners, that means re-evaluating whether existing stacks are instrumented for cross-domain correlation or merely generating more alerts with better packaging.

What this signals

Identity-aware automation will become a programme dependency, not a SOC feature. As platforms increasingly correlate identities, resources, and time, security teams will need cleaner identity inventories and better ownership data to make automation defensible. The immediate signal for practitioners is that SOC improvement roadmaps now overlap with IAM and NHI governance roadmaps.

Pre-LLM normalization is emerging as the control point that determines whether AI helps or harms operations. If log, identity, and config data are inconsistent, model-driven response will scale uncertainty instead of insight. Teams should therefore assess data quality, lineage, and auditability before expanding autonomous or semi-autonomous workflows.

Service-account visibility will shape the quality of machine-assisted investigations. Our research shows only 5.7% of organisations have full visibility into their service accounts, which means many SOC tools will still be operating with partial identity truth. That gap will show up as slower triage, weaker correlation, and lower confidence in response decisions.


For practitioners

  • Audit identity context in SOC telemetry Map which logs, alerts, and case records carry user, service account, token, and workload identity fields. If those fields are inconsistent or missing, automated triage will struggle to connect events across identities, resources, and time. Prioritise normalisation before expanding response automation.
  • Define human approval points for automated response Separate enrichment, correlation, containment, and remediation into distinct approval levels. Keep high-impact actions such as account disablement, token revocation, or network isolation under explicit control until the platform’s decision quality is measured against real incidents.
  • Validate data-layer quality before model adoption Test whether logs, configs, and identity records are deduplicated, enriched, and time-aligned well enough to support case generation. Weak pre-processing creates false confidence in AI-driven conclusions and makes response decisions harder to defend.
  • Tie SOC automation to identity governance ownership Assign accountable owners for the identity sources that feed automated detection, especially service account inventories, SaaS permissions, and cloud roles. Without ownership, the automation layer will continue to operate on stale or partial identity data.

Key takeaways

  • Agentic SOC automation changes the control problem because identity context becomes part of the decision engine, not just the evidence trail.
  • When security teams cannot normalise identities across users, service accounts, tokens, and workloads, automated correlation becomes noisy and harder to trust.
  • The next maturity step is not adding more AI features, but tightening identity governance, data quality, and approval boundaries around automated response.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0DE.CM-7Continuous monitoring and event analysis fit the article's SecOps automation focus.
NIST SP 800-53 Rev 5AU-6The article hinges on analysing, correlating, and acting on security telemetry.
CIS Controls v8CIS-8 , Audit Log ManagementThe platform's value depends on high-quality logs and normalized telemetry.
NIST AI RMFMANAGEAI-driven SOC operations require risk controls, oversight, and operational accountability.

Use DE.CM-7 to assess whether automated correlation improves detection fidelity without creating blind spots.


Key terms

  • Agentic Soc: An agentic SOC is a security operations model where AI systems assist with triage, investigation, and response using tool access and execution authority. The control challenge is not just accuracy, but governance of what the machine can see, decide, and do.
  • Identity Sprawl: Identity sprawl is the uncontrolled growth of identities, entitlements, and credentials across an environment. For NHIs, it usually appears when automation creates accounts faster than governance teams can inventory, review, and remove them. The result is hidden access, weak accountability, and a wider attack surface.
  • Pre-LLM data layer: The normalization and enrichment stage that prepares logs, identity records, configs, and code for model analysis. Its purpose is to reduce duplication, align context, and improve signal quality before AI systems infer meaning or recommend actions.

What's in the full article

Exaforce's full blog post covers the operational detail this post intentionally leaves for the source:

  • How the Agentic SOC platform maps detection, triage, investigation, and response into one workflow
  • Which log, identity, and code signals the vendor says are normalised before analysis
  • Where Exabots are positioned in the response chain and what that means for SOC operating models
  • Why the company says its architecture performs well against zero-day and cross-domain threat correlation

👉 The full Exaforce post covers the platform framing, feature emphasis, and market positioning behind the GigaOm recognition.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, workload identity, and secrets management for practitioners who need to connect identity control to broader security operations. It is designed for teams that want to strengthen governance across identity, privilege, and automation programmes.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org