Platform
An agentic SOC, with the brakes built in
AI generates more security signal than any team can read, so the answer cannot be another queue. SAF3AI runs the loop with agents: the fabric senses, the triage agent opens the case, the investigation agent reasons over the evidence, and the response agent acts — inside an autonomy policy that decides what it may do without asking.
Capabilities
Key Features
A detection fabric, not a rule list
Stream, behavioural and graph tiers over one substrate, with 187 rules mapped to the OWASP LLM Top 10 and MITRE ATLAS — so coverage is a claim you can audit rather than a number on a slide.
A triage agent that opens the case
Signals that never correlate into an incident are still clustered by entity and scored, so the meaningful ones become candidate incidents instead of ageing out of a queue nobody reads.
An investigation agent that reads first
It gathers evidence, timeline and toxic combinations, then writes a verdict — true positive, likely benign, or needs more evidence — with a confidence score and the findings it based that on.
A response agent that composes
For a known threat it runs a predefined workflow. For a novel one it assembles a chain from the live skill catalogue, constrained to skills that actually exist — it cannot invent an action.
An autonomy policy you control
A dial, not a switch. Move an action class from recommend to automatic as it earns trust, with hard gates the platform will not cross and a kill switch that routes everything back to a human.
A SOC analyst you can ask
Question the estate in plain language and get an answer grounded in your own incidents, entities and evidence — not a general-purpose chatbot with your logs pasted into the prompt.
The roster
Named agents, stated boundaries
"AI-powered" tells you nothing. Here is each agent, what it does, and — more usefully — what it is not permitted to do. The boundary is the product.
Detection Fabric
Senses
Scores every signal from every surface through one asynchronous substrate — stream, behavioural and graph tiers — and correlates the results into incidents.
Boundary Deterministic and statistical. Reads telemetry, writes incidents. Takes no action.
MoreTriage agent
Prioritises
Clusters uncorrelated signals by entity into candidate incidents and scores them by severity and volume, so the middle of the funnel stops being a dead end.
Boundary Proposes cases. An analyst promotes, or the autonomy policy does.
Investigation agent
Reasons
Assembles evidence, timeline and toxic combinations before a human opens the case, then writes an assessment with a confidence score and cites what it used.
Boundary Strictly read-only. It cannot act, and its prompt forbids asserting what the evidence does not support.
Response agent
Acts
Runs a predefined workflow for a known threat, or composes a new chain of skills for a novel one — validated against the live catalogue so every step is a real capability.
Boundary Reversible actions run and record their undo path. Irreversible ones always require a human.
MoreAutonomy engine
Decides
Sits between verdict and action. For each proposed step it returns act, ask a human, or hold — and the reason for that decision, in writing.
Boundary Conservative by construction. Every gate below must pass before anything runs unattended.
SOC analyst agent
Answers
Answers questions about your estate in plain language, grounded in your own incidents, entities and evidence rather than in general knowledge.
Boundary Read-only, and scoped to your tenant.
Autonomy
A dial, not a switch
Nobody sensible turns an agent loose on production security on day one. Autonomy here is something you raise one action class at a time, as each earns trust — and every gate below has to pass before anything runs unattended.
Level 1
Observe
Agents gather, reason and explain. Nothing acts. Most teams start here and stay a while.
Level 2
Recommend
The investigation verdict and a proposed response arrive together. A human approves each step.
Level 3
Act, within gates
Confirmed, confident, reversible and non-critical steps execute on their own. Everything else still asks.
Confirmed only
The investigation agent must have returned a true positive. A likely-benign or needs-more-evidence verdict never acts on its own.
Above the confidence bar
The verdict must clear a confidence threshold you set. The default is deliberately high.
Reversible actions only
Rotate, revoke, delete, purge, wipe and terminate are never auto-executed, however confident the verdict. They route to a human every time.
Severity exclusions
Critical incidents are held for a person by default. You choose which severities the platform may handle alone.
Off means off
Disabling autonomy routes every step to approval. There is no mode where the platform acts against that setting.
Everything is logged
Each decision records what ran, why it was allowed, and how to undo it. Autonomy that cannot be audited is not autonomy you can deploy.
The platform is conservative on purpose. An agent that acts confidently and wrongly costs far more trust than one that asks — so every default here errs toward asking, and you move the dial rather than us.
Get started with Agentic AI-SOC
See how Saf3AI can help secure your AI agents.