TL;DR: Agentic AI is being used to automate SOC triage, enrichment, and resolution across the threat lifecycle, with Torq citing 100% Tier 1 auto-triage at Carvana and faster phishing response at Lennar Corp, while a 2026 academic study independently reported triage reductions from hours to under ten minutes. The operational test is no longer whether automation can save analyst time, but whether it can produce auditable decisions, complete evidence, and controlled escalation.
NHIMG editorial — based on content published by torq: AI SOC automation framework powered by agentic AI
By the numbers:
- 80% of security leaders say their SOC is still fragmented across too many platforms.
- Carvana auto-triages 100% of Tier 1 and Tier 2 cases.
- A peer-reviewed 2026 framework reduced average incident triage time from hours to under ten minutes.
Questions worth separating out
Q: How should security teams use AI in the SOC without losing human control?
A: Use AI to remove repetitive work, enrich alerts, and accelerate triage, but keep humans accountable for escalation, containment, and exception handling.
Q: Why does fragmented SOC tooling weaken automation outcomes?
A: Fragmentation forces analysts and AI systems to reconstruct context across separate consoles, which slows triage and increases the chance of incomplete decisions.
Q: What do security teams get wrong about agentic AI security tools?
A: The most common mistake is treating agentic AI security as an extension of an existing category such as NHI, endpoint, or DSPM.
Practitioner guidance
- Implement identity-aware case routing Route alerts using identity context from IAM, PAM, cloud, and NHI sources so triage reflects who or what actually initiated the activity.
- Require evidence-backed automated decisions Block autonomous closure unless the case includes linked telemetry, enrichment results, and the specific reason the system classified the alert the way it did.
- Separate machine-executable response from analyst-approved response Classify response actions into containment, notification, and remediation, then decide which categories a system may execute directly and which require human approval.
What's in the full article
Torq's full blog covers the operational detail this post intentionally leaves for the source:
- The five-step AI SOC automation framework as presented by the vendor, including the exact sequence from ingest to closure.
- Customer examples tied to specific workflow changes, including how Carvana and Lennar Corp operationalised automation.
- The named Torq components and how the vendor maps them to triage, enrichment, orchestration, and case management.
- The evaluation checklist in its original form, including the implementation prompts the vendor wants SOC teams to use.
👉 Read Torq's analysis of AI SOC automation and agentic case resolution →
AI SOC automation frameworks: are your controls keeping up?
Explore further
AI SOC automation is becoming an identity governance problem as much as an operations problem. SOC workflows now depend on identity context to decide whether activity is benign, suspicious, or compromised. That means human identities, NHI, delegated access, and service accounts are all part of the decision surface. When those identities are poorly governed, automation inherits the same blind spots as the analysts it is trying to assist. Practitioner conclusion: SOC automation programs should be evaluated alongside identity and privilege governance, not separately from them.
A question worth separating out:
Q: How do organisations know if SOC automation is actually improving security?
A: Measure the time from alert creation to validated conclusion, the percentage of investigations that remain auditable, and how often findings produce durable detections or hunting hypotheses. If automation only lowers queue volume without improving evidence quality or detection coverage, it is reducing visibility rather than risk.
👉 Read our full editorial: AI SOC automation is shifting from triage to full case resolution