TL;DR: A large US-based MSSP ran five adversarial tests against Morpheus APD 2.0, breaking Sentinel and CrowdStrike inputs, auditing every query, probing tenant isolation, and degrading Okta telemetry, and the system passed all five with zero false all-clear verdicts and full query matching, according to D3. Confidence without verification is a governance failure in agentic SOC operations.
NHIMG editorial — based on content published by D3: LLMjacking style guardrails testing for APD 2.0
Questions worth separating out
A: Start with structured case management, not with broad automation.
Q: Why do identity and telemetry failures create outsized risk in agentic SOC workflows?
A: Because the agent can turn partial evidence into a decisive answer faster than a human reviewer can spot the gap.
Q: What do identity teams get wrong about tenant isolation?
A: Identity teams often treat tenant isolation as a product label rather than a control outcome.
Practitioner guidance
- Define explicit unable to verify states Make incomplete evidence a first-class investigation outcome, with mandatory human handoff when SIEM, endpoint, or identity telemetry cannot be confirmed.
- Reconcile agent queries against the audit trail Capture every search, filter, and tenant scope the AI agent uses, then compare the reconstructed query set with the investigation summary before production use.
- Test tenant isolation as an access control Run cross-tenant probes in a controlled environment and verify that every agent query remains bound to the intended customer or business unit scope.
What's in the full article
D3's full analysis covers the operational detail this post intentionally leaves for the source:
- Step-by-step description of the five adversarial scenarios the customer designed and why each one matters to AI SOC governance
- Customer-reported verdict language for each failure mode, including how the system handled incomplete Sentinel, CrowdStrike, and Okta inputs
- Query-by-query audit methodology that compared the investigation summary with the actual searches the AI agent executed
- Multi-tenant probing approach showing how field-level scoping was enforced in the customer's environment
👉 Read D3's analysis of APD 2.0 guardrails under adversarial SOC testing →
Agentic SOC guardrails - are your investigations failing safe?
Explore further
Fail-safe behaviour is now the minimum viable control for agentic SOC adoption. A SOC agent that cannot verify a conclusion should stop short of a verdict, not manufacture confidence from partial telemetry. That changes the governance bar from detection quality to decision integrity. In practice, this is the same problem identity teams face when authentication or authorization context is missing, only now the failure can be automated at speed.
A question worth separating out:
Q: Who is accountable when an AI investigation cannot confirm a verdict?
A: The operating team remains accountable for the workflow design, the controls around uncertainty, and the decision to allow autonomy at all. If a tool cannot verify its evidence, the safe outcome is escalation and re-verification, not closure. Governance must assign ownership before the incident happens.
👉 Read our full editorial: Agentic SOC guardrails need fail-safe verdicts, not confident guesses