TL;DR: As detection coverage expands, human capacity becomes the limiting control: 5 analysts with 28 effective hours per day can spend about 17 hours on triage, yet 100 alerts at roughly 7 minutes each still consume around 12 hours, leaving little slack for hunting or tuning, according to Prophet. The practical issue is not alert volume alone but how human capacity becomes the limiting control as detection coverage expands.
NHIMG editorial — based on content published by Prophet: SOC Capacity Modeling, How Many Alerts Can Your Team Really Handle?
Questions worth separating out
Q: How should security teams model SOC capacity before adding more detections?
A: Start with effective analyst hours, not headcount, then compare that time with daily alert arrival rate and average handling time.
Q: Why does alert volume create governance risk for security operations?
A: High volume creates governance risk when teams can no longer apply consistent decision criteria.
Q: What do teams get wrong about AI-assisted triage?
A: They often measure it by whether it replaces analysts, rather than whether it improves investigation quality under real workload pressure.
Practitioner guidance
- Calculate effective triage capacity first Convert rostered analyst hours into usable alert-handling hours after meetings, breaks, and handoffs.
- Measure close-time distributions, not just averages Pull open and close timestamps for alerts and review the median, 75th percentile, and outliers.
- Reserve analyst time for higher-value work Explicitly ring-fence time for threat hunting, tuning, and detection engineering instead of allowing triage to consume the full day.
What's in the full article
Prophet's full article covers the operational detail this post intentionally leaves for the source:
- Step-by-step capacity math for converting analyst shifts into usable triage hours
- Worked examples showing how utilisation changes at 100 alerts per day versus 200 alerts per day
- Discussion of how to split remaining time between hunting, tuning, and detection engineering
- The article's Human plus AI capacity table showing how front-end escalation changes workload allocation
👉 Read Prophet's analysis of SOC capacity modelling and AI-assisted triage →
SOC capacity modeling: are your alert queues already saturating?
Explore further
Capacity strain is becoming an operational control issue, not just a staffing issue. Once a SOC spends most of its available time on queue management, detection coverage becomes conditional on human slack rather than security need. That means the organisation is no longer choosing detections purely on risk, but on whether analysts can absorb the work. The practical conclusion is that alert capacity has become part of the control environment, not a separate operational concern.
A question worth separating out:
Q: How can teams tell whether AI triage is actually improving SOC operations?
A: Look for lower manual processing time, fewer duplicate reviews, shorter disposition cycles, and faster removal of related malicious messages. If the model only shifts work rather than reducing it, the SOC has not gained capacity. The control should measurably free analysts for higher-value investigations.
👉 Read our full editorial: SOC capacity modeling shows where alert triage breaks down