TL;DR: AI automation platform selection often overweights playbook-building for the 15% of work engineers do while ignoring the 85% of time analysts spend on case handling, data review, collaboration, and resolution, according to Swimlane. The governance lesson is that SOC tooling should be judged on analyst workflow quality, not automation elegance alone.
NHIMG editorial — based on content published by Swimlane: Your AI Automation Platform Decision is Missing Someone
By the numbers:
- The remaining 85% is analysts working cases, reviewing data, collaborating with teammates, and driving incidents to resolution.
Questions worth separating out
Q: How should security teams evaluate AI SOC platforms without confusing automation with autonomy?
A: Teams should test whether the platform investigates alerts at run time, or whether it only executes predefined steps after a human has framed the problem.
Q: Why does analyst experience affect SOC performance so much?
A: Because analysts spend most of their time inside the platform handling live cases, not building automations.
Q: What are the signs that SOC automation is too fragmented?
A: Look for repeated data entry, frequent tool switching, inconsistent case records, and analysts relying on side channels to reconstruct context.
Practitioner guidance
- Put analysts on the evaluation panel Require SOC analysts to score every finalist on case handling, evidence presentation, and investigation flow, not just on automation depth.
- Test the full investigation workflow Run a live case through alert intake, enrichment, collaboration, documentation, and closure to see where context breaks or gets re-entered.
- Measure context switching explicitly Track how many times an analyst must leave the platform or retype data during a case, then treat repeated handoffs as a design defect.
What's in the full article
Swimlane's full article covers the operational detail this post intentionally leaves for the source:
- The exact evaluation matrix the vendor proposes for comparing engineer priorities with analyst priorities.
- The specific examples of analyst workflow friction the vendor says appear when case management sits outside the automation platform.
- The vendor's recommended decision criteria for AI support, reporting, and case handling in SOC operations.
- The research framing behind the 15% and 85% split between playbook building and analyst work.
👉 Read Swimlane's analysis of SOC analyst experience in AI automation platform selection →
AI automation platforms: are analyst workflows the real evaluation gap?
Explore further
Analyst experience is now a control quality issue, not a UX preference. When 85% of platform time is spent on investigations, collaboration, and case resolution, the interface becomes part of the control stack. A platform that frustrates analysts slows triage, weakens documentation, and reduces response consistency. That is especially relevant to SOCs that rely on human identity workflows, escalation paths, and privileged review. Practitioners should treat analyst experience as a measurable operational control.
A question worth separating out:
Q: Should organisations use a separate case management tool with SOC automation?
A: Only if the operational handoff is genuinely seamless, which is rare. Separate tools usually force analysts to bridge context manually, creating delay and inconsistency. A unified platform is easier to govern because the same system can preserve evidence, workflow state, and reporting without relying on fragile integrations.
👉 Read our full editorial: SOC analyst experience is the missing test in AI automation selection