TL;DR: GigaOm compared 19 SecOps automation vendors and highlighted an agentic SOC approach for automating detection, triage, investigation, and response across identities, resources, and time, according to Exaforce. The broader shift is that SecOps is moving from static playbooks to AI-driven correlation, where identity context becomes operational, not optional.
NHIMG editorial — based on content published by Exaforce: Exaforce Named a Leader and Outperformer in the 2025 GigaOm Radar for SecOps Automation
By the numbers:
- GigaOm compared 19 vendors across key features, emerging features, and business criteria dimensions.
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security.
Questions worth separating out
Q: What breaks when SOC teams automate without identity visibility?
A: When SOC teams automate without identity visibility, they lose context about which identities moved, what privileges changed, and whether an access path was legitimate.
Q: Why does identity sprawl make SecOps automation harder to trust?
A: Because the platform must reason over many identity types at once, including human users, service accounts, and machine credentials.
Q: How can analysts tell whether AI-driven SOC automation is actually working?
A: Look beyond alert volume and measure whether the platform produces accurate incidents, preserves tenant context, and shortens time to closure without creating rework.
Practitioner guidance
- Audit identity context in SOC telemetry Map which logs, alerts, and case records carry user, service account, token, and workload identity fields.
- Define human approval points for automated response Separate enrichment, correlation, containment, and remediation into distinct approval levels.
- Validate data-layer quality before model adoption Test whether logs, configs, and identity records are deduplicated, enriched, and time-aligned well enough to support case generation.
What's in the full article
Exaforce's full blog post covers the operational detail this post intentionally leaves for the source:
- How the Agentic SOC platform maps detection, triage, investigation, and response into one workflow
- Which log, identity, and code signals the vendor says are normalised before analysis
- Where Exabots are positioned in the response chain and what that means for SOC operating models
- Why the company says its architecture performs well against zero-day and cross-domain threat correlation
👉 Read Exaforce’s analysis of the 2025 GigaOm Radar for SecOps Automation →
Agentic SOC automation and identity sprawl: what should teams change?
Explore further
Agentic SOC is becoming an identity governance problem, not just an operations problem. Once a platform is correlating identities, resources, and time, it is implicitly making decisions about trust, ownership, and privilege scope. That pushes SOC automation into the same governance conversation as IAM and NHI management. The practical conclusion is that automation maturity now depends on identity data quality as much as on detection logic.
A question worth separating out:
Q: Which frameworks matter when SOC automation depends on identity data?
A: NIST-CSF and NIST SP 800-53 are the most useful anchors because they connect logging, access control, monitoring, and auditability. For identity-heavy environments, NHI governance also matters because service accounts and credentials often feed the same automated workflows. The question is whether the control stack can support defensible machine-assisted decisions.
👉 Read our full editorial: Exaforce’s GigaOm recognition points to the rise of agentic SOC