{"id":11593,"date":"2026-09-11T10:02:01","date_gmt":"2026-09-11T10:02:01","guid":{"rendered":"https:\/\/launchlemonade.app\/blog\/?p=11593"},"modified":"2026-09-11T10:02:01","modified_gmt":"2026-09-11T10:02:01","slug":"how-security-operations-platforms-with-agentic-ai-work","status":"publish","type":"post","link":"https:\/\/launchlemonade.app\/blog\/how-security-operations-platforms-with-agentic-ai-work\/","title":{"rendered":"How Security Operations Platforms With Agentic AI Work"},"content":{"rendered":"<h1 class=\"text-2xl font-bold mt-4 mb-2\">How Security Operations Platforms With Agentic AI Work<\/h1>\n<section id=\"quick-answer\">\n<h3>Quick Answer<\/h3>\n<p class=\"my-2\">Security operations platforms with agentic AI use AI agents to investigate alerts and coordinate approved security actions.<br \/>\nThey combine telemetry, threat intelligence, workflows, and reasoning to reduce repetitive analyst work.<br \/>\nThe strongest platforms preserve human approval for high-impact changes.<br \/>\nTeams should evaluate evidence quality, governance, integrations, and measurable SOC outcomes before deployment.<\/p>\n<\/section>\n<h3>Summary<\/h3>\n<p class=\"my-2\">Agentic AI adds adaptive reasoning to security operations. Instead of only following fixed playbooks, agents can gather evidence, assess context, select approved next steps, and produce a documented recommendation or action. The practical goal is not an unattended SOC. It is a faster, more consistent SOC where people retain authority over consequential decisions.<\/p>\n<section id=\"ai-summary\">\n<h3>What This Guide Covers<\/h3>\n<ul class=\"list-disc list-outside my-2 space-y-1 pl-6\">\n<li class=\"pl-2\">What agentic AI means in a security operations context<\/li>\n<li class=\"pl-2\">How agentic platforms differ from copilots, SIEMs, XDR, and SOAR<\/li>\n<li class=\"pl-2\">The workflows where AI agents can add real operational value<\/li>\n<li class=\"pl-2\">Six notable platforms and their different approaches<\/li>\n<li class=\"pl-2\">The governance controls that determine whether autonomy is safe<\/li>\n<li class=\"pl-2\">A practical evaluation process for SOC leaders<\/li>\n<\/ul>\n<\/section>\n<h2 class=\"text-xl font-bold mt-3 mb-2\">What Are Security Operations Platforms With Agentic AI?<\/h2>\n<p class=\"my-2\">Security operations platforms with agentic AI bring AI reasoning, tool use, and workflow orchestration into detection and response work. They aim to reduce analyst effort across alert triage, investigations, threat hunting, detection engineering, and response coordination.<\/p>\n<p class=\"my-2\">A conventional automation rule might isolate a device when a severity threshold is met. An agentic workflow can instead gather endpoint, identity, email, network, and threat-intelligence evidence first. It can then decide whether the predefined isolation condition has been met, explain its evidence, and request approval where required.<\/p>\n<p class=\"my-2\">That distinction matters. Traditional automation is deterministic. It follows prescribed conditions. Agentic AI can deal with incomplete and changing evidence, but it also introduces uncertainty. Therefore, its output requires clear guardrails.<\/p>\n<h3 class=\"text-lg font-semibold mt-3 mb-1\">Agentic AI Is Not Just a Security Copilot<\/h3>\n<p class=\"my-2\">A security copilot usually responds to an analyst prompt. It can summarise an incident, help write a query, or explain a suspicious command. These capabilities are useful, but they are primarily assistive.<\/p>\n<p class=\"my-2\">An AI agent can be invoked by an alert or workflow. It may retrieve context, use connected security tools, update a case, open a ticket, recommend containment, or trigger a controlled response. The difference is operational agency.<\/p>\n<p class=\"my-2\">That does not mean every platform uses the same autonomy level. Some emphasise investigation and recommendations. Others combine agents with SOAR capabilities and support controlled execution. Buyers should ask exactly what the platform can do, what permissions it needs, and when people remain in the loop.<\/p>\n<h3 class=\"text-lg font-semibold mt-3 mb-1\">Where Agentic Workflows Fit<\/h3>\n<p class=\"my-2\">The best initial use cases are usually repetitive, evidence-heavy, and bounded by clear policies. They often include:<\/p>\n<ul class=\"list-disc list-outside my-2 space-y-1 pl-6\">\n<li class=\"pl-2\">Tier 1 alert triage<\/li>\n<li class=\"pl-2\">Indicator and asset enrichment<\/li>\n<li class=\"pl-2\">Phishing investigations<\/li>\n<li class=\"pl-2\">Case timeline creation<\/li>\n<li class=\"pl-2\">Detection rule drafting and tuning<\/li>\n<li class=\"pl-2\">Natural-language threat hunting<\/li>\n<li class=\"pl-2\">Vulnerability or exposure prioritisation<\/li>\n<li class=\"pl-2\">Ticket and incident-summary creation<\/li>\n<\/ul>\n<p class=\"my-2\">These tasks can be time-consuming, but they are not identical. A platform that is excellent for endpoint investigations may be less suitable for broad multi-tool orchestration. That is why product fit matters more than an \u201cagentic\u201d label.<\/p>\n<h2 class=\"text-xl font-bold mt-3 mb-2\">How Do Security Operations Platforms With Agentic AI Make Decisions?<\/h2>\n<p class=\"my-2\">They make decisions by combining available telemetry, instructions, tool permissions, reasoning models, and workflow constraints. Their quality depends on data coverage and governance, not on AI capability alone.<\/p>\n<p class=\"my-2\">A typical workflow starts with a detection. The platform receives an alert and collects associated context, such as the affected user, device, cloud workload, process tree, IP address, email message, authentication history, or threat-intelligence matches.<\/p>\n<p class=\"my-2\">The agent then compares the evidence against a task objective. That objective might be: \u201cDetermine whether this alert needs escalation.\u201d It may produce a verdict, confidence level, evidence summary, recommended next step, and audit trail.<\/p>\n<h3 class=\"text-lg font-semibold mt-3 mb-1\">The Core Operating Model<\/h3>\n<div class=\"my-2 overflow-x-auto max-w-full\">\n<div style=\"background-color: #111827; border: 1px solid #374151; border-radius: 12px; overflow-x: auto; max-width: 100%; margin: 16px 0;\">\n<table style=\"width: 100%; border-collapse: collapse; font-size: 14px;\">\n<thead>\n<tr style=\"background-color: rgba(255, 255, 255, 0.08); border-bottom: 2px solid #4B5563;\">\n<th style=\"padding: 14px 16px; text-align: left; font-weight: bold; color: #ffffff; border-right: 1px solid #374151;\">Stage<\/th>\n<th style=\"padding: 14px 16px; text-align: left; font-weight: bold; color: #ffffff; border-right: 1px solid #374151;\">What the Agent Does<\/th>\n<th style=\"padding: 14px 16px; text-align: left; font-weight: bold; color: #ffffff;\">Required Control<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"border-bottom: 1px solid #1F2937; background-color: rgba(255, 255, 255, 0.02);\">\n<td style=\"padding: 12px 16px; color: #ffffff; font-weight: 500; border-right: 1px solid #1F2937;\">Trigger<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Receives an alert, case, analyst request, or scheduled task<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db;\">Clear scope and event filters<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #1F2937;\">\n<td style=\"padding: 12px 16px; color: #ffffff; font-weight: 500; border-right: 1px solid #1F2937;\">Context Gathering<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Queries approved tools and enriches evidence<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db;\">Least-privilege access<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #1F2937; background-color: rgba(255, 255, 255, 0.02);\">\n<td style=\"padding: 12px 16px; color: #ffffff; font-weight: 500; border-right: 1px solid #1F2937;\">Reasoning<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Builds an investigation plan and evaluates evidence<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db;\">Instructions, policy constraints, validation<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #1F2937;\">\n<td style=\"padding: 12px 16px; color: #ffffff; font-weight: 500; border-right: 1px solid #1F2937;\">Recommendation<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Suggests closure, escalation, containment, or further investigation<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db;\">Analyst-readable explanation<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #1F2937; background-color: rgba(255, 255, 255, 0.02);\">\n<td style=\"padding: 12px 16px; color: #ffffff; font-weight: 500; border-right: 1px solid #1F2937;\">Action<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Executes an approved workflow step<\/td>\n<td style=\"padding: 12px 16px; color: #34d399; font-weight: 500;\">Approval gates for high-impact actions<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #1F2937;\">\n<td style=\"padding: 12px 16px; color: #ffffff; font-weight: 500; border-right: 1px solid #1F2937;\">Learning Review<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Captures analyst feedback and workflow outcomes<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db;\">Change control and audit logs<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p class=\"my-2\">A strong implementation keeps the system observable. Analysts should be able to inspect the evidence used, actions attempted, systems accessed, and approvals requested. If the platform cannot provide that visibility, it is difficult to trust in a high-stakes environment.<\/p>\n<h3 class=\"text-lg font-semibold mt-3 mb-1\">Why Data Quality Still Determines Outcomes<\/h3>\n<p class=\"my-2\">AI agents cannot compensate for missing telemetry, inconsistent asset inventory, or weak identity context. If an agent sees only endpoint data, it may miss evidence held in email, cloud, IAM, or network systems.<\/p>\n<p class=\"my-2\">The issue is not merely detection quality. It affects response safety. An agent asked to disable an account needs enough context to distinguish a compromised privileged user from an essential service identity. That is why data access should be intentional, governed, and tested.<\/p>\n<p class=\"my-2\">Google\u2019s\u00a0<a class=\"text-blue-600 dark:text-blue-400 underline hover:no-underline font-medium\" href=\"https:\/\/docs.cloud.google.cn\/chronicle\/docs\/secops\/triage-investigation-agent\" target=\"_blank\" rel=\"noopener noreferrer\">Triage and Investigation Agent documentation<\/a>\u00a0illustrates the kind of data-driven work an agent can perform. It describes dynamic searches, indicator enrichment, command-line analysis, and process-tree reconstruction.<\/p>\n<h2 class=\"text-xl font-bold mt-3 mb-2\">Which Agentic AI Workflows Deliver the Most Value First?<\/h2>\n<p class=\"my-2\">Alert triage and investigation often deliver the best early value because they are repetitive, measurable, and easier to constrain. Teams can compare time-to-verdict, investigation completeness, and escalation quality before enabling more autonomous workflows.<\/p>\n<p class=\"my-2\">The most sensible first deployment is rarely \u201cgive the agent access to everything.\u201d Start with a narrow case type that creates analyst drag. For example, phishing, impossible-travel alerts, suspicious PowerShell activity, or known-malware detections.<\/p>\n<h3 class=\"text-lg font-semibold mt-3 mb-1\">Start With Bounded, High-Volume Work<\/h3>\n<p class=\"my-2\">A useful first workflow has five characteristics:<\/p>\n<ol class=\"list-decimal list-outside my-2 space-y-1 pl-6\">\n<li class=\"pl-2\"><strong class=\"font-bold\">It occurs frequently.<\/strong>\u00a0There must be enough volume to show a meaningful result.<\/li>\n<li class=\"pl-2\"><strong class=\"font-bold\">It has a documented process.<\/strong>\u00a0Analysts should already know the evidence they need.<\/li>\n<li class=\"pl-2\"><strong class=\"font-bold\">It has an acceptable failure mode.<\/strong>\u00a0A poor summary is less harmful than an incorrect destructive action.<\/li>\n<li class=\"pl-2\"><strong class=\"font-bold\">It can be measured.<\/strong>\u00a0Track investigation time, escalation accuracy, and analyst edits.<\/li>\n<li class=\"pl-2\"><strong class=\"font-bold\">It has reliable data sources.<\/strong>\u00a0The agent needs the right telemetry to form a defensible conclusion.<\/li>\n<\/ol>\n<p class=\"my-2\">Google Security Operations positions its\u00a0<a class=\"text-blue-600 dark:text-blue-400 underline hover:no-underline font-medium\" href=\"https:\/\/cloud.google.com\/solutions\/security\/agentic-soc\" target=\"_blank\" rel=\"noopener noreferrer\">Agentic SOC<\/a>\u00a0around alert triage, threat hunting, and detection engineering. Its public materials highlight autonomous workflow support, while the product documentation clarifies practical constraints and data sources.<\/p>\n<h3 class=\"text-lg font-semibold mt-3 mb-1\">Keep High-Impact Response Under Tight Control<\/h3>\n<p class=\"my-2\">Agents can also support containment. They may suggest endpoint isolation, account disablement, email removal, firewall blocking, or ticket escalation. These actions can reduce attacker dwell time, but they can also disrupt operations.<\/p>\n<p class=\"my-2\">Use a tiered policy:<\/p>\n<div class=\"my-2 overflow-x-auto max-w-full\">\n<div style=\"background-color: #111827; border: 1px solid #374151; border-radius: 12px; overflow-x: auto; max-width: 100%; margin: 16px 0;\">\n<table style=\"width: 100%; border-collapse: collapse; font-size: 14px;\">\n<thead>\n<tr style=\"background-color: rgba(255, 255, 255, 0.08); border-bottom: 2px solid #4B5563;\">\n<th style=\"padding: 14px 16px; text-align: left; font-weight: bold; color: #ffffff; border-right: 1px solid #374151;\">Action Type<\/th>\n<th style=\"padding: 14px 16px; text-align: left; font-weight: bold; color: #ffffff; border-right: 1px solid #374151;\">Example<\/th>\n<th style=\"padding: 14px 16px; text-align: left; font-weight: bold; color: #ffffff;\">Recommended Operating Mode<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"border-bottom: 1px solid #1F2937; background-color: rgba(255, 255, 255, 0.02);\">\n<td style=\"padding: 12px 16px; color: #ffffff; font-weight: 500; border-right: 1px solid #1F2937;\">Low impact<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Enrich an IOC or create a case summary<\/td>\n<td style=\"padding: 12px 16px; color: #34d399; font-weight: 500;\">Automatic<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #1F2937;\">\n<td style=\"padding: 12px 16px; color: #ffffff; font-weight: 500; border-right: 1px solid #1F2937;\">Moderate impact<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Assign an incident, open a ticket, notify an owner<\/td>\n<td style=\"padding: 12px 16px; color: #34d399; font-weight: 500;\">Automatic with audit logging<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #1F2937; background-color: rgba(255, 255, 255, 0.02);\">\n<td style=\"padding: 12px 16px; color: #ffffff; font-weight: 500; border-right: 1px solid #1F2937;\">High impact<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Isolate an endpoint or disable a user<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db;\">Require analyst approval initially<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #1F2937;\">\n<td style=\"padding: 12px 16px; color: #ffffff; font-weight: 500; border-right: 1px solid #1F2937;\">Critical impact<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Change production access or block a business-critical service<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db;\">Require dual approval and documented process<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p class=\"my-2\">As confidence grows, teams can expand the automation boundary. However, approvals should be a design decision, not a temporary inconvenience.<\/p>\n<h2 class=\"text-xl font-bold mt-3 mb-2\">Which Platforms Illustrate Different Agentic SOC Approaches?<\/h2>\n<p class=\"my-2\">The market includes native security platforms, cloud security ecosystems, and operations layers that sit across existing tools. Each has a different data advantage and operating model.<\/p>\n<p class=\"my-2\">The following examples are not a universal ranking. They show how leading vendors approach agentic investigations, workflow execution, and analyst control.<\/p>\n<h3 class=\"text-lg font-semibold mt-3 mb-1\">Tools at a Glance<\/h3>\n<div class=\"my-2 overflow-x-auto max-w-full\">\n<div style=\"background-color: #111827; border: 1px solid #374151; border-radius: 12px; overflow-x: auto; max-width: 100%; margin: 16px 0;\">\n<table style=\"width: 100%; border-collapse: collapse; font-size: 14px;\">\n<thead>\n<tr style=\"background-color: rgba(255, 255, 255, 0.08); border-bottom: 2px solid #4B5563;\">\n<th style=\"padding: 14px 16px; text-align: left; font-weight: bold; color: #ffffff; border-right: 1px solid #374151;\">Tool<\/th>\n<th style=\"padding: 14px 16px; text-align: left; font-weight: bold; color: #ffffff; border-right: 1px solid #374151;\">Best For<\/th>\n<th style=\"padding: 14px 16px; text-align: left; font-weight: bold; color: #ffffff; border-right: 1px solid #374151;\">Key Strength<\/th>\n<th style=\"padding: 14px 16px; text-align: left; font-weight: bold; color: #ffffff; border-right: 1px solid #374151;\">Key Limitation<\/th>\n<th style=\"padding: 14px 16px; text-align: left; font-weight: bold; color: #ffffff; border-right: 1px solid #374151;\">Starting Price<\/th>\n<th style=\"padding: 14px 16px; text-align: left; font-weight: bold; color: #ffffff;\">Best Fit<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"border-bottom: 1px solid #1F2937; background-color: rgba(255, 255, 255, 0.02);\">\n<td style=\"padding: 12px 16px; color: #ffffff; font-weight: 500; border-right: 1px solid #1F2937;\">Google Security Operations<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Teams using Google Cloud security capabilities<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Agentic triage, investigation, hunting, and detection engineering<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Best value often depends on alignment with Google\u2019s ecosystem<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Check current pricing<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db;\">Cloud-forward enterprise SOCs<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #1F2937;\">\n<td style=\"padding: 12px 16px; color: #ffffff; font-weight: 500; border-right: 1px solid #1F2937;\">CrowdStrike Charlotte AI<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Falcon customers seeking agentic SOAR and endpoint-led operations<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Agents and automation within the Falcon platform<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Strongest fit for teams already invested in CrowdStrike data and workflows<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Check current pricing<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db;\">Endpoint-centric SOCs<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #1F2937; background-color: rgba(255, 255, 255, 0.02);\">\n<td style=\"padding: 12px 16px; color: #ffffff; font-weight: 500; border-right: 1px solid #1F2937;\">Microsoft Security Copilot<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Microsoft security customers<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Broad integration across Microsoft Security products<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Value depends on Microsoft estate maturity and capacity planning<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Check current pricing<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db;\">Microsoft-first enterprises<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #1F2937;\">\n<td style=\"padding: 12px 16px; color: #ffffff; font-weight: 500; border-right: 1px solid #1F2937;\">Palo Alto Networks Cortex AgentiX<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">SOCs needing deep automation and custom agent workflows<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Multi-step agent plans plus a mature automation foundation<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">May require more design work to achieve full value<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Check current pricing<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db;\">Complex enterprise SOCs<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #1F2937; background-color: rgba(255, 255, 255, 0.02);\">\n<td style=\"padding: 12px 16px; color: #ffffff; font-weight: 500; border-right: 1px solid #1F2937;\">SentinelOne Purple AI<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Teams prioritising natural-language investigation across Singularity<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Investigation support, summaries, and guided next actions<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Best fit depends on Singularity platform adoption<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Check current pricing<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db;\">Lean endpoint and AI SIEM teams<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #1F2937;\">\n<td style=\"padding: 12px 16px; color: #ffffff; font-weight: 500; border-right: 1px solid #1F2937;\">ReliaQuest GreyMatter<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Organisations coordinating many existing security tools<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Operations layer across multi-vendor environments<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Requires careful integration and operating-model alignment<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Check current pricing<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db;\">Large, heterogeneous security stacks<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<h3 class=\"text-lg font-semibold mt-3 mb-1\">Google Security Operations<\/h3>\n<p class=\"my-2\">Google Security Operations focuses on Gemini-native agentic defense. Its stated workflows include triage, investigation, threat hunting, and detection engineering. It also combines security operations capabilities with Google Threat Intelligence and Mandiant expertise.<\/p>\n<p class=\"my-2\"><strong class=\"font-bold\">Pros<\/strong><\/p>\n<ul class=\"list-disc list-outside my-2 space-y-1 pl-6\">\n<li class=\"pl-2\">Supports agentic workflows across common SOC activities.<\/li>\n<li class=\"pl-2\">Can be compelling for teams already using Google Cloud security tooling.<\/li>\n<li class=\"pl-2\">Documentation provides practical details about agent investigation functions.<\/li>\n<\/ul>\n<p class=\"my-2\"><strong class=\"font-bold\">Cons<\/strong><\/p>\n<ul class=\"list-disc list-outside my-2 space-y-1 pl-6\">\n<li class=\"pl-2\">Architecture and tenant constraints need validation during evaluation.<\/li>\n<li class=\"pl-2\">Consumption and packaging should be assessed carefully against expected workflow volume.<\/li>\n<\/ul>\n<p class=\"my-2\">Read Google\u2019s\u00a0<a class=\"text-blue-600 dark:text-blue-400 underline hover:no-underline font-medium\" href=\"https:\/\/docs.cloud.google.com\/architecture\/agentic-ai-orchestrate-security-ops-workflows\" target=\"_blank\" rel=\"noopener noreferrer\">agentic AI security operations architecture guidance<\/a>\u00a0for an example of multi-agent workflows with third-party security systems and human approval steps.<\/p>\n<h3 class=\"text-lg font-semibold mt-3 mb-1\">CrowdStrike Charlotte AI<\/h3>\n<p class=\"my-2\">CrowdStrike\u2019s Charlotte Agentic SOAR combines agents and security automation in the Falcon ecosystem. The platform emphasises natural-language agent creation, case management, workflow orchestration, and analyst-defined guardrails.<\/p>\n<p class=\"my-2\"><strong class=\"font-bold\">Pros<\/strong><\/p>\n<ul class=\"list-disc list-outside my-2 space-y-1 pl-6\">\n<li class=\"pl-2\">Combines deterministic automation with agentic reasoning.<\/li>\n<li class=\"pl-2\">Supports custom agents and structured controls within its platform.<\/li>\n<li class=\"pl-2\">Can reduce context switching for Falcon-centric SOC teams.<\/li>\n<\/ul>\n<p class=\"my-2\"><strong class=\"font-bold\">Cons<\/strong><\/p>\n<ul class=\"list-disc list-outside my-2 space-y-1 pl-6\">\n<li class=\"pl-2\">The data and workflow advantage is strongest when Falcon is already central to operations.<\/li>\n<li class=\"pl-2\">Buyers should distinguish product announcements, preview capabilities, and generally available functionality.<\/li>\n<\/ul>\n<p class=\"my-2\">CrowdStrike describes\u00a0<a class=\"text-blue-600 dark:text-blue-400 underline hover:no-underline font-medium\" href=\"https:\/\/www.crowdstrike.com\/en-us\/platform\/charlotte-ai\/agentic-soar\/\" target=\"_blank\" rel=\"noopener noreferrer\">Charlotte Agentic SOAR<\/a>\u00a0as a way to unite intelligent agents with automation. Its\u00a0<a class=\"text-blue-600 dark:text-blue-400 underline hover:no-underline font-medium\" href=\"https:\/\/www.crowdstrike.com\/en-us\/platform\/charlotte-ai\/charlotte-ai-agentworks\/\" target=\"_blank\" rel=\"noopener noreferrer\">AgentWorks overview<\/a>\u00a0also highlights custom agent design, policies, audit logs, and approval checkpoints.<\/p>\n<h3 class=\"text-lg font-semibold mt-3 mb-1\">Microsoft Security Copilot<\/h3>\n<p class=\"my-2\">Microsoft Security Copilot is an AI-powered security solution that supports incident response, hunting, intelligence gathering, and posture work. Its agents are designed to automate repetitive work across Microsoft\u2019s security portfolio and supported partner integrations.<\/p>\n<p class=\"my-2\"><strong class=\"font-bold\">Pros<\/strong><\/p>\n<ul class=\"list-disc list-outside my-2 space-y-1 pl-6\">\n<li class=\"pl-2\">Strong fit for organisations with Microsoft Defender, Sentinel, Entra, and Intune data.<\/li>\n<li class=\"pl-2\">Integrates assistive and agent-based experiences across security operations.<\/li>\n<li class=\"pl-2\">Can help standardise workflows for teams already working in the Microsoft ecosystem.<\/li>\n<\/ul>\n<p class=\"my-2\"><strong class=\"font-bold\">Cons<\/strong><\/p>\n<ul class=\"list-disc list-outside my-2 space-y-1 pl-6\">\n<li class=\"pl-2\">Outcomes depend heavily on existing Microsoft security product deployment.<\/li>\n<li class=\"pl-2\">Teams should model consumption, access controls, and agent permissions before scaling use.<\/li>\n<\/ul>\n<p class=\"my-2\">Microsoft\u2019s\u00a0<a class=\"text-blue-600 dark:text-blue-400 underline hover:no-underline font-medium\" href=\"https:\/\/learn.microsoft.com\/en-us\/copilot\/security\/agents-overview\" target=\"_blank\" rel=\"noopener noreferrer\">Security Copilot agents overview<\/a>\u00a0explains that agents can respond to requests and system events while incorporating feedback and control mechanisms.<\/p>\n<h3 class=\"text-lg font-semibold mt-3 mb-1\">Palo Alto Networks Cortex AgentiX<\/h3>\n<p class=\"my-2\">Cortex AgentiX extends Palo Alto Networks\u2019 automation heritage with system and custom agents that can plan and execute multi-step workflows. It is aimed at SOC teams handling variable investigations where static playbooks become difficult to maintain.<\/p>\n<p class=\"my-2\"><strong class=\"font-bold\">Pros<\/strong><\/p>\n<ul class=\"list-disc list-outside my-2 space-y-1 pl-6\">\n<li class=\"pl-2\">Strong automation orientation for complex, multi-stage processes.<\/li>\n<li class=\"pl-2\">Supports system-provided and custom agents.<\/li>\n<li class=\"pl-2\">Can connect agents to broad security operations actions and integrations.<\/li>\n<\/ul>\n<p class=\"my-2\"><strong class=\"font-bold\">Cons<\/strong><\/p>\n<ul class=\"list-disc list-outside my-2 space-y-1 pl-6\">\n<li class=\"pl-2\">Advanced automation programmes require ownership, process design, and ongoing tuning.<\/li>\n<li class=\"pl-2\">Some capabilities may have different availability stages, so confirm status during procurement.<\/li>\n<\/ul>\n<p class=\"my-2\">Palo Alto Networks explains in its\u00a0<a class=\"text-blue-600 dark:text-blue-400 underline hover:no-underline font-medium\" href=\"https:\/\/cortex-docs.paloaltonetworks.com\/cortex-agentix\/learn-about-cortex-agentix\/agentic-ai-in-cortex-agentix\" target=\"_blank\" rel=\"noopener noreferrer\">Agentic AI in Cortex AgentiX documentation<\/a>\u00a0that agents can investigate cases, hunt for threats, and support tailored automation. Its\u00a0<a class=\"text-blue-600 dark:text-blue-400 underline hover:no-underline font-medium\" href=\"https:\/\/docs-cortex.paloaltonetworks.com\/r\/Cortex-AgentiX\/Cortex-AgentiX-Documentation\/Agentic-Response-Preview\" target=\"_blank\" rel=\"noopener noreferrer\">Agentic Response documentation<\/a>\u00a0also makes an important distinction: predictable workflows can remain better suited to conventional playbooks.<\/p>\n<h3 class=\"text-lg font-semibold mt-3 mb-1\">SentinelOne Purple AI<\/h3>\n<p class=\"my-2\">SentinelOne positions Purple AI as an agentic security analyst within the Singularity platform. It focuses on natural-language investigation, automated analysis, evidence presentation, and next-step recommendations.<\/p>\n<p class=\"my-2\"><strong class=\"font-bold\">Pros<\/strong><\/p>\n<ul class=\"list-disc list-outside my-2 space-y-1 pl-6\">\n<li class=\"pl-2\">Supports natural-language investigation without requiring analysts to write every query manually.<\/li>\n<li class=\"pl-2\">Can help reduce analyst context switching through summaries and guided investigation.<\/li>\n<li class=\"pl-2\">Fits teams investing in SentinelOne\u2019s endpoint and AI SIEM capabilities.<\/li>\n<\/ul>\n<p class=\"my-2\"><strong class=\"font-bold\">Cons<\/strong><\/p>\n<ul class=\"list-disc list-outside my-2 space-y-1 pl-6\">\n<li class=\"pl-2\">Platform fit depends on the breadth of a team\u2019s SentinelOne deployment.<\/li>\n<li class=\"pl-2\">Teams should verify which response actions are automated, recommended, or approval-based.<\/li>\n<\/ul>\n<p class=\"my-2\">SentinelOne\u2019s\u00a0<a class=\"text-blue-600 dark:text-blue-400 underline hover:no-underline font-medium\" href=\"https:\/\/www.sentinelone.com\/platform\/purple\/\" target=\"_blank\" rel=\"noopener noreferrer\">Purple AI overview<\/a>\u00a0describes agentic investigation and auto-triage features, while its\u00a0<a class=\"text-blue-600 dark:text-blue-400 underline hover:no-underline font-medium\" href=\"https:\/\/www.sentinelone.com\/solutions\/detect-investigate-and-respond-with-ai\/\" target=\"_blank\" rel=\"noopener noreferrer\">AI-driven security operations page<\/a>\u00a0explains the wider Singularity context.<\/p>\n<h3 class=\"text-lg font-semibold mt-3 mb-1\">ReliaQuest GreyMatter<\/h3>\n<p class=\"my-2\">ReliaQuest GreyMatter is positioned as an operations layer across a customer\u2019s existing security stack. Its agentic approach is aimed at multi-vendor environments that need investigation, detection, hunting, and response coordination without replacing every underlying product.<\/p>\n<p class=\"my-2\"><strong class=\"font-bold\">Pros<\/strong><\/p>\n<ul class=\"list-disc list-outside my-2 space-y-1 pl-6\">\n<li class=\"pl-2\">Suits enterprises with fragmented, multi-tool telemetry.<\/li>\n<li class=\"pl-2\">Focuses on connecting existing security technologies and workflows.<\/li>\n<li class=\"pl-2\">Offers an operational approach beyond a single EDR or SIEM estate.<\/li>\n<\/ul>\n<p class=\"my-2\"><strong class=\"font-bold\">Cons<\/strong><\/p>\n<ul class=\"list-disc list-outside my-2 space-y-1 pl-6\">\n<li class=\"pl-2\">The platform\u2019s impact depends on integration depth and process adoption.<\/li>\n<li class=\"pl-2\">Buyers should validate vendor claims with their own data, use cases, and governance requirements.<\/li>\n<\/ul>\n<p class=\"my-2\">ReliaQuest\u2019s\u00a0<a class=\"text-blue-600 dark:text-blue-400 underline hover:no-underline font-medium\" href=\"https:\/\/reliaquest.com\/security-operations-platform\/\" target=\"_blank\" rel=\"noopener noreferrer\">GreyMatter security operations platform overview<\/a>\u00a0outlines its cross-tool approach. Its\u00a0<a class=\"text-blue-600 dark:text-blue-400 underline hover:no-underline font-medium\" href=\"https:\/\/reliaquest.com\/security-operations-platform\/agentic-ai-soc\/\" target=\"_blank\" rel=\"noopener noreferrer\">agentic AI SOC page<\/a>\u00a0describes agentic personas for investigation, hunting, and detection engineering.<\/p>\n<h2 class=\"text-xl font-bold mt-3 mb-2\">How Should Teams Evaluate Security Operations Platforms With Agentic AI?<\/h2>\n<p class=\"my-2\">Teams should evaluate the platform\u2019s operational fit, evidence quality, safety controls, data access, and measurable outcomes. A polished chatbot interface is not enough.<\/p>\n<p class=\"my-2\">Start with your current operating model. Identify which systems analysts use every day, where manual work accumulates, and which case types cause delays. Then test whether the platform can reduce that work without introducing blind automation.<\/p>\n<h3 class=\"text-lg font-semibold mt-3 mb-1\">Use an Evidence-First Evaluation Framework<\/h3>\n<p class=\"my-2\">Ask vendors to demonstrate a realistic investigation using your own representative data. The agent should show what it queried, what evidence it found, what conclusion it reached, and why.<\/p>\n<p class=\"my-2\">A good proof of value should include:<\/p>\n<ul class=\"list-disc list-outside my-2 space-y-1 pl-6\">\n<li class=\"pl-2\">A known alert type with sufficient historical volume<\/li>\n<li class=\"pl-2\">Required telemetry from relevant security tools<\/li>\n<li class=\"pl-2\">Defined success measures and quality thresholds<\/li>\n<li class=\"pl-2\">A documented list of allowed and prohibited actions<\/li>\n<li class=\"pl-2\">Analyst review sessions for agent findings<\/li>\n<li class=\"pl-2\">A rollback plan for any automated action<\/li>\n<\/ul>\n<h3 class=\"text-lg font-semibold mt-3 mb-1\">Evaluate Governance Before Autonomy<\/h3>\n<p class=\"my-2\">The most important question is not, \u201cCan the agent respond automatically?\u201d It is, \u201cCan we safely define when it should?\u201d<\/p>\n<p class=\"my-2\">Evaluate:<\/p>\n<ul class=\"list-disc list-outside my-2 space-y-1 pl-6\">\n<li class=\"pl-2\">Role-based access and least-privilege permissions<\/li>\n<li class=\"pl-2\">Case-level evidence and decision traceability<\/li>\n<li class=\"pl-2\">Agent configuration controls<\/li>\n<li class=\"pl-2\">Workflow versioning and change management<\/li>\n<li class=\"pl-2\">Approval gates for disruptive actions<\/li>\n<li class=\"pl-2\">Monitoring for failed tasks, unusual tool use, and poor outcomes<\/li>\n<li class=\"pl-2\">Data residency, retention, and model-processing requirements<\/li>\n<\/ul>\n<p class=\"my-2\">A well-governed agent can improve consistency. An opaque agent can create a faster path to mistakes.<\/p>\n<h2 class=\"text-xl font-bold mt-3 mb-2\">What Implementation Mistakes Should SOC Leaders Avoid?<\/h2>\n<p class=\"my-2\">The common mistakes are over-automating too early, treating AI output as evidence, and failing to redesign workflows around clear ownership. Technology alone does not create an effective agentic SOC.<\/p>\n<h3 class=\"text-lg font-semibold mt-3 mb-1\">Mistake One: Starting With Autonomous Containment<\/h3>\n<p class=\"my-2\">Containment is attractive because it appears measurable and urgent. Yet it can also disrupt business-critical systems. Begin with investigation, enrichment, and recommendation workflows instead.<\/p>\n<p class=\"my-2\">Once your team trusts the evidence quality, expand to moderate-risk actions. Keep critical actions under approval until performance is proven over time.<\/p>\n<h3 class=\"text-lg font-semibold mt-3 mb-1\">Mistake Two: Measuring Only Time Saved<\/h3>\n<p class=\"my-2\">Speed matters, but it is not the full outcome. A platform can close alerts quickly and still create poor outcomes if it misses true positives or produces weak evidence.<\/p>\n<p class=\"my-2\">Measure:<\/p>\n<ul class=\"list-disc list-outside my-2 space-y-1 pl-6\">\n<li class=\"pl-2\">Mean time to triage<\/li>\n<li class=\"pl-2\">Investigation completeness<\/li>\n<li class=\"pl-2\">Escalation precision<\/li>\n<li class=\"pl-2\">Analyst override rate<\/li>\n<li class=\"pl-2\">False-positive handling<\/li>\n<li class=\"pl-2\">Containment accuracy<\/li>\n<li class=\"pl-2\">Detection coverage improvements<\/li>\n<li class=\"pl-2\">Cost per investigated case<\/li>\n<\/ul>\n<h3 class=\"text-lg font-semibold mt-3 mb-1\">Mistake Three: Ignoring Analyst Adoption<\/h3>\n<p class=\"my-2\">Analysts need to understand when to trust the system and when to challenge it. If the platform creates unexplained conclusions, it may be ignored. If it requires excessive review, it may add work rather than remove it.<\/p>\n<p class=\"my-2\">Include analysts in workflow design. Their feedback is often the fastest route to practical improvements.<\/p>\n<h3 class=\"text-lg font-semibold mt-3 mb-1\">Mistake Four: Assuming One Platform Replaces Every Tool<\/h3>\n<p class=\"my-2\">Agentic AI can provide a valuable operational layer, but it does not automatically replace SIEM, EDR, identity security, email security, threat intelligence, case management, or SOAR. In some environments, it will unify workflows across these tools. In others, it will be strongest within a single vendor ecosystem.<\/p>\n<p class=\"my-2\">Procure for the role you need the platform to play.<\/p>\n<h2 class=\"text-xl font-bold mt-3 mb-2\">How Can You Build an Agentic SOC Roadmap?<\/h2>\n<p class=\"my-2\">Build the roadmap in phases, beginning with low-risk, high-volume workflows and expanding only after evidence supports the change. The aim is trusted operational maturity, not maximum autonomy on day one.<\/p>\n<h3 class=\"text-lg font-semibold mt-3 mb-1\">A Practical 90-Day Approach<\/h3>\n<div class=\"my-2 overflow-x-auto max-w-full\">\n<div style=\"background-color: #111827; border: 1px solid #374151; border-radius: 12px; overflow-x: auto; max-width: 100%; margin: 16px 0;\">\n<table style=\"width: 100%; border-collapse: collapse; font-size: 14px;\">\n<thead>\n<tr style=\"background-color: rgba(255, 255, 255, 0.08); border-bottom: 2px solid #4B5563;\">\n<th style=\"padding: 14px 16px; text-align: left; font-weight: bold; color: #ffffff; border-right: 1px solid #374151;\">Period<\/th>\n<th style=\"padding: 14px 16px; text-align: left; font-weight: bold; color: #ffffff; border-right: 1px solid #374151;\">Priority<\/th>\n<th style=\"padding: 14px 16px; text-align: left; font-weight: bold; color: #ffffff;\">Deliverable<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"border-bottom: 1px solid #1F2937; background-color: rgba(255, 255, 255, 0.02);\">\n<td style=\"padding: 12px 16px; color: #ffffff; font-weight: 500; border-right: 1px solid #1F2937;\">Days 1 to 30<\/td>\n<td style=\"padding: 12px 16px; color: #f87171; border-right: 1px solid #1F2937;\">Baseline manual SOC work and select one workflow<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db;\">Use-case charter, data map, success metrics, risk controls<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #1F2937;\">\n<td style=\"padding: 12px 16px; color: #ffffff; font-weight: 500; border-right: 1px solid #1F2937;\">Days 31 to 60<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Run a controlled pilot with analyst review<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db;\">Evidence-quality findings, time-saved analysis, workflow refinements<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #1F2937; background-color: rgba(255, 255, 255, 0.02);\">\n<td style=\"padding: 12px 16px; color: #ffffff; font-weight: 500; border-right: 1px solid #1F2937;\">Days 61 to 90<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Expand successful workflows carefully<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db;\">Approved operating model, governance process, scale decision<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<p class=\"my-2\">The platform should earn more autonomy through results. Use the pilot to identify data gaps, analyst concerns, integration limits, and actions that should stay manual.<\/p>\n<h3 class=\"text-lg font-semibold mt-3 mb-1\">Which Tool Should You Choose?<\/h3>\n<div class=\"my-2 overflow-x-auto max-w-full\">\n<div style=\"background-color: #111827; border: 1px solid #374151; border-radius: 12px; overflow-x: auto; max-width: 100%; margin: 16px 0;\">\n<table style=\"width: 100%; border-collapse: collapse; font-size: 14px;\">\n<thead>\n<tr style=\"background-color: rgba(255, 255, 255, 0.08); border-bottom: 2px solid #4B5563;\">\n<th style=\"padding: 14px 16px; text-align: left; font-weight: bold; color: #ffffff; border-right: 1px solid #374151;\">If You Need&#8230;<\/th>\n<th style=\"padding: 14px 16px; text-align: left; font-weight: bold; color: #ffffff; border-right: 1px solid #374151;\">Consider<\/th>\n<th style=\"padding: 14px 16px; text-align: left; font-weight: bold; color: #ffffff;\">Why<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"border-bottom: 1px solid #1F2937; background-color: rgba(255, 255, 255, 0.02);\">\n<td style=\"padding: 12px 16px; color: #ffffff; font-weight: 500; border-right: 1px solid #1F2937;\">Agentic SOC workflows within Google Cloud security operations<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Google Security Operations<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db;\">It supports agentic triage, investigations, hunting, and detection engineering.<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #1F2937;\">\n<td style=\"padding: 12px 16px; color: #ffffff; font-weight: 500; border-right: 1px solid #1F2937;\">Endpoint-led agentic automation in a Falcon environment<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">CrowdStrike Charlotte AI<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db;\">It combines agents, automation, custom workflows, and Falcon case context.<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #1F2937; background-color: rgba(255, 255, 255, 0.02);\">\n<td style=\"padding: 12px 16px; color: #ffffff; font-weight: 500; border-right: 1px solid #1F2937;\">Agent support across a Microsoft security estate<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Microsoft Security Copilot<\/td>\n<td style=\"padding: 12px 16px; color: #34d399; font-weight: 500;\">It is designed to work across Microsoft Security products and supported partner services.<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #1F2937;\">\n<td style=\"padding: 12px 16px; color: #ffffff; font-weight: 500; border-right: 1px solid #1F2937;\">Deep security orchestration with custom agent workflows<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">Palo Alto Networks Cortex AgentiX<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db;\">It combines agent planning with security automation and customisation.<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #1F2937; background-color: rgba(255, 255, 255, 0.02);\">\n<td style=\"padding: 12px 16px; color: #ffffff; font-weight: 500; border-right: 1px solid #1F2937;\">Natural-language investigations in the Singularity platform<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">SentinelOne Purple AI<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db;\">It focuses on investigation, summaries, and guided analyst actions.<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #1F2937;\">\n<td style=\"padding: 12px 16px; color: #ffffff; font-weight: 500; border-right: 1px solid #1F2937;\">An agentic operations layer across a multi-vendor stack<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db; border-right: 1px solid #1F2937;\">ReliaQuest GreyMatter<\/td>\n<td style=\"padding: 12px 16px; color: #d1d5db;\">It is positioned to connect and coordinate existing security tools.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/div>\n<section id=\"key-takeaways\">\n<h2 class=\"text-xl font-bold mt-3 mb-2\">Key Takeaways<\/h2>\n<ul class=\"list-disc list-outside my-2 space-y-1 pl-6\">\n<li class=\"pl-2\"><strong class=\"font-bold\">Agentic AI extends traditional SOC automation.<\/strong>\u00a0It can gather evidence, reason across steps, and take approved actions.<\/li>\n<li class=\"pl-2\"><strong class=\"font-bold\">Human control remains essential.<\/strong>\u00a0Keep disruptive and business-critical actions behind defined approval controls.<\/li>\n<li class=\"pl-2\"><strong class=\"font-bold\">Data coverage determines usefulness.<\/strong>\u00a0Agents need accurate telemetry, asset context, and permissions to investigate safely.<\/li>\n<li class=\"pl-2\"><strong class=\"font-bold\">Begin with bounded workflows.<\/strong>\u00a0Alert triage, enrichment, phishing investigations, and case summaries are practical starting points.<\/li>\n<li class=\"pl-2\"><strong class=\"font-bold\">Evaluate evidence, not demos.<\/strong>\u00a0Test real cases, inspect reasoning, and measure investigation quality alongside speed.<\/li>\n<li class=\"pl-2\"><strong class=\"font-bold\">Choose for ecosystem fit.<\/strong>\u00a0The best platform depends on your existing security stack, workflow maturity, and governance requirements.<\/li>\n<\/ul>\n<\/section>\n<h2 class=\"text-xl font-bold mt-3 mb-2\">Conclusion: Agentic AI Should Make the SOC More Accountable, Not Less<\/h2>\n<p class=\"my-2\">Agentic AI can change how security teams handle large volumes of repetitive work. It can help analysts investigate faster, build a clearer evidence trail, and coordinate common actions across a complex security stack.<\/p>\n<p class=\"my-2\">However, agentic capability should not be confused with unattended autonomy. The best implementation gives agents clear goals, limited permissions, accessible evidence, and strong human oversight.<\/p>\n<p class=\"my-2\">When evaluating security operations platforms with agentic AI, start with the work your team already performs repeatedly. Measure whether the platform improves quality as well as speed. Then expand only when your governance model and operational results justify it.<\/p>\n<h2 class=\"text-xl font-bold mt-3 mb-2\">Frequently Asked Questions<\/h2>\n<div class=\"faq-accordion\">\n<details open>\n<summary><h3>What Is an Agentic AI Security Operations Platform?<\/h3><\/summary>\n<div class=\"faq-answer\">\n<p class=\"my-2\">It is a security platform that uses AI agents to plan, investigate, enrich, recommend, and sometimes execute defined security tasks. Unlike a basic chatbot, an agent can use approved tools and follow multi-step workflows.<\/p>\n<\/div>\n<\/details>\n<details>\n<summary><h3>Are Agentic SOC Platforms Fully Autonomous?<\/h3><\/summary>\n<div class=\"faq-answer\">\n<p class=\"my-2\">They should not be assumed to be fully autonomous. Mature programmes define which actions agents can take automatically and which require analyst approval.<\/p>\n<\/div>\n<\/details>\n<details>\n<summary><h3>Can Agentic AI Replace SOC Analysts?<\/h3><\/summary>\n<div class=\"faq-answer\">\n<p class=\"my-2\">No. Agentic AI can reduce repetitive work and improve investigation speed, but analysts remain accountable for security decisions. People are also essential for exceptions, business context, and high-impact response actions.<\/p>\n<\/div>\n<\/details>\n<details>\n<summary><h3>How Is Agentic AI Different From Traditional SOAR?<\/h3><\/summary>\n<div class=\"faq-answer\">\n<p class=\"my-2\">Traditional SOAR commonly follows predefined playbooks and rules. Agentic AI can interpret context and select between approved workflow steps. Both approaches can work together in a modern SOC.<\/p>\n<\/div>\n<\/details>\n<details>\n<summary><h3>What SOC Tasks Are Best for Agentic AI?<\/h3><\/summary>\n<div class=\"faq-answer\">\n<p class=\"my-2\">Alert triage, evidence enrichment, phishing analysis, case summarisation, threat hunting, and detection engineering support are common starting points. These workflows are often repetitive and easier to constrain.<\/p>\n<\/div>\n<\/details>\n<details>\n<summary><h3>What Should Teams Test During an Agentic AI Pilot?<\/h3><\/summary>\n<div class=\"faq-answer\">\n<p class=\"my-2\">Test realistic investigations, data access, evidence quality, approval controls, integration reliability, and operational cost. Measure the agent against a baseline for analyst time, decision quality, and escalation outcomes.<\/p>\n<\/div>\n<\/details>\n<details>\n<summary><h3>Does Agentic AI Require a SIEM Replacement?<\/h3><\/summary>\n<div class=\"faq-answer\">\n<p class=\"my-2\">Not necessarily. Some platforms are built around a native SIEM or security ecosystem. Others sit across existing tools and coordinate data and workflows without requiring an immediate replacement.<\/p>\n<\/div>\n<\/details>\n<details>\n<summary><h3>What Is the Biggest Risk of Agentic AI in Security Operations?<\/h3><\/summary>\n<div class=\"faq-answer\">\n<p class=\"my-2\">The biggest risk is granting broad authority without appropriate controls. Limit permissions, require approvals for impactful actions, maintain auditability, and verify outcomes through a controlled pilot.<\/p>\n<\/div>\n<\/details>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>How Security Operations Platforms With Agentic AI Work Quick Answer Security operations platforms with agentic AI use AI agents to investigate alerts and coordinate approved security actions. They combine telemetry, threat intelligence, workflows, and reasoning to reduce repetitive analyst work. The strongest platforms preserve human approval for high-impact changes. Teams should evaluate evidence quality, governance, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":11595,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[52],"tags":[],"class_list":["post-11593","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-business"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.4 (Yoast SEO v28.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>How Security Operations Platforms With Agentic AI Work<\/title>\n<meta name=\"description\" content=\"Compare security operations platforms with agentic AI, core capabilities, risks, and fit for modern SOC teams.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/launchlemonade.app\/blog\/how-security-operations-platforms-with-agentic-ai-work\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How Security Operations Platforms With Agentic AI Work\" \/>\n<meta property=\"og:description\" content=\"Compare security operations platforms with agentic AI, core capabilities, risks, and fit for modern SOC teams.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/launchlemonade.app\/blog\/how-security-operations-platforms-with-agentic-ai-work\/\" \/>\n<meta property=\"og:site_name\" content=\"LaunchLemonade\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-11T10:02:01+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/launchlemonade.app\/blog\/wp-content\/uploads\/2026\/09\/security-operations-platforms-with-agentic-ai-featured-image.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1408\" \/>\n\t<meta property=\"og:image:height\" content=\"768\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Lem, AI blog Writer\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@launchlemonade\" \/>\n<meta name=\"twitter:site\" content=\"@launchlemonade\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lem, AI blog Writer\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"15 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/launchlemonade.app/blog\\\/how-security-operations-platforms-with-agentic-ai-work\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/launchlemonade.app/blog\\\/how-security-operations-platforms-with-agentic-ai-work\\\/\"},\"author\":{\"name\":\"Lem, AI blog Writer\",\"@id\":\"https:\\\/\\\/launchlemonade.app/blog\\\/#\\\/schema\\\/person\\\/73bc50f4965eb4a2b336aa468e4465c5\"},\"headline\":\"How Security Operations Platforms With Agentic AI Work\",\"datePublished\":\"2026-09-11T10:02:01+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/launchlemonade.app/blog\\\/how-security-operations-platforms-with-agentic-ai-work\\\/\"},\"wordCount\":3342,\"publisher\":{\"@id\":\"https:\\\/\\\/launchlemonade.app/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/launchlemonade.app/blog\\\/how-security-operations-platforms-with-agentic-ai-work\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/launchlemonade.app/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/security-operations-platforms-with-agentic-ai-featured-image.webp\",\"articleSection\":[\"Business\"],\"inLanguage\":\"en-US\",\"copyrightYear\":\"2026\",\"copyrightHolder\":{\"@id\":\"https:\\\/\\\/launchlemonade.app/blog\\\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/launchlemonade.app/blog\\\/how-security-operations-platforms-with-agentic-ai-work\\\/\",\"url\":\"https:\\\/\\\/launchlemonade.app/blog\\\/how-security-operations-platforms-with-agentic-ai-work\\\/\",\"name\":\"How Security Operations Platforms With Agentic AI Work\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/launchlemonade.app/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/launchlemonade.app/blog\\\/how-security-operations-platforms-with-agentic-ai-work\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/launchlemonade.app/blog\\\/how-security-operations-platforms-with-agentic-ai-work\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/launchlemonade.app/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/security-operations-platforms-with-agentic-ai-featured-image.webp\",\"datePublished\":\"2026-09-11T10:02:01+00:00\",\"description\":\"Compare security operations platforms with agentic AI, core capabilities, risks, and fit for modern SOC teams.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/launchlemonade.app/blog\\\/how-security-operations-platforms-with-agentic-ai-work\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/launchlemonade.app/blog\\\/how-security-operations-platforms-with-agentic-ai-work\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/launchlemonade.app/blog\\\/how-security-operations-platforms-with-agentic-ai-work\\\/#primaryimage\",\"url\":\"https:\\\/\\\/launchlemonade.app/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/security-operations-platforms-with-agentic-ai-featured-image.webp\",\"contentUrl\":\"https:\\\/\\\/launchlemonade.app/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/security-operations-platforms-with-agentic-ai-featured-image.webp\",\"width\":1408,\"height\":768,\"caption\":\"Security operations platforms with agentic AI featured image with Agentic SOC Platforms on a soft yellow gradient\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/launchlemonade.app/blog\\\/how-security-operations-platforms-with-agentic-ai-work\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/launchlemonade.app/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How Security Operations Platforms With Agentic AI Work\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/launchlemonade.app/blog\\\/#website\",\"url\":\"https:\\\/\\\/launchlemonade.app/blog\\\/\",\"name\":\"LaunchLemonade\",\"description\":\"Launch your AI Agents\",\"publisher\":{\"@id\":\"https:\\\/\\\/launchlemonade.app/blog\\\/#organization\"},\"alternateName\":\"LaunchLemonade\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/launchlemonade.app/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Organization\",\"Place\"],\"@id\":\"https:\\\/\\\/launchlemonade.app/blog\\\/#organization\",\"name\":\"LaunchLemonade\",\"url\":\"https:\\\/\\\/launchlemonade.app/blog\\\/\",\"logo\":{\"@id\":\"https:\\\/\\\/launchlemonade.app/blog\\\/how-security-operations-platforms-with-agentic-ai-work\\\/#local-main-organization-logo\"},\"image\":{\"@id\":\"https:\\\/\\\/launchlemonade.app/blog\\\/how-security-operations-platforms-with-agentic-ai-work\\\/#local-main-organization-logo\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/launchlemonade\"],\"telephone\":[],\"openingHoursSpecification\":[{\"@type\":\"OpeningHoursSpecification\",\"dayOfWeek\":[\"Monday\",\"Tuesday\",\"Wednesday\",\"Thursday\",\"Friday\",\"Saturday\",\"Sunday\"],\"opens\":\"09:00\",\"closes\":\"17:00\"}]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/launchlemonade.app/blog\\\/#\\\/schema\\\/person\\\/73bc50f4965eb4a2b336aa468e4465c5\",\"name\":\"Lem, AI blog Writer\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/launchlemonade.app\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/lem_ai_profile.webp\",\"url\":\"https:\\\/\\\/launchlemonade.app\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/lem_ai_profile.webp\",\"contentUrl\":\"https:\\\/\\\/launchlemonade.app\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/lem_ai_profile.webp\",\"caption\":\"Lem, AI blog Writer\"},\"description\":\"Lem is LaunchLemonade's AI blog writer, covering the tools, workflows, and no-code automations that help modern teams work smarter. Every guide is researched and tested firsthand before it goes live.\",\"sameAs\":[\"https:\\\/\\\/launchlemonade.app\"]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/launchlemonade.app/blog\\\/how-security-operations-platforms-with-agentic-ai-work\\\/#local-main-organization-logo\",\"url\":\"https:\\\/\\\/launchlemonade.app/blog\\\/wp-content\\\/uploads\\\/2024\\\/04\\\/LaunchLemonade-Logo-1.png\",\"contentUrl\":\"https:\\\/\\\/launchlemonade.app/blog\\\/wp-content\\\/uploads\\\/2024\\\/04\\\/LaunchLemonade-Logo-1.png\",\"width\":512,\"height\":512,\"caption\":\"LaunchLemonade\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"How Security Operations Platforms With Agentic AI Work","description":"Compare security operations platforms with agentic AI, core capabilities, risks, and fit for modern SOC teams.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/launchlemonade.app\/blog\/how-security-operations-platforms-with-agentic-ai-work\/","og_locale":"en_US","og_type":"article","og_title":"How Security Operations Platforms With Agentic AI Work","og_description":"Compare security operations platforms with agentic AI, core capabilities, risks, and fit for modern SOC teams.","og_url":"https:\/\/launchlemonade.app\/blog\/how-security-operations-platforms-with-agentic-ai-work\/","og_site_name":"LaunchLemonade","article_published_time":"2026-09-11T10:02:01+00:00","og_image":[{"width":1408,"height":768,"url":"https:\/\/launchlemonade.app\/blog\/wp-content\/uploads\/2026\/09\/security-operations-platforms-with-agentic-ai-featured-image.webp","type":"image\/webp"}],"author":"Lem, AI blog Writer","twitter_card":"summary_large_image","twitter_creator":"@launchlemonade","twitter_site":"@launchlemonade","twitter_misc":{"Written by":"Lem, AI blog Writer","Est. reading time":"15 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/launchlemonade.app\/blog\/how-security-operations-platforms-with-agentic-ai-work\/#article","isPartOf":{"@id":"https:\/\/launchlemonade.app\/blog\/how-security-operations-platforms-with-agentic-ai-work\/"},"author":{"name":"Lem, AI blog Writer","@id":"https:\/\/launchlemonade.app\/blog\/#\/schema\/person\/73bc50f4965eb4a2b336aa468e4465c5"},"headline":"How Security Operations Platforms With Agentic AI Work","datePublished":"2026-09-11T10:02:01+00:00","mainEntityOfPage":{"@id":"https:\/\/launchlemonade.app\/blog\/how-security-operations-platforms-with-agentic-ai-work\/"},"wordCount":3342,"publisher":{"@id":"https:\/\/launchlemonade.app\/blog\/#organization"},"image":{"@id":"https:\/\/launchlemonade.app\/blog\/how-security-operations-platforms-with-agentic-ai-work\/#primaryimage"},"thumbnailUrl":"https:\/\/launchlemonade.app\/blog\/wp-content\/uploads\/2026\/09\/security-operations-platforms-with-agentic-ai-featured-image.webp","articleSection":["Business"],"inLanguage":"en-US","copyrightYear":"2026","copyrightHolder":{"@id":"https:\/\/launchlemonade.app\/blog\/#organization"}},{"@type":"WebPage","@id":"https:\/\/launchlemonade.app\/blog\/how-security-operations-platforms-with-agentic-ai-work\/","url":"https:\/\/launchlemonade.app\/blog\/how-security-operations-platforms-with-agentic-ai-work\/","name":"How Security Operations Platforms With Agentic AI Work","isPartOf":{"@id":"https:\/\/launchlemonade.app\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/launchlemonade.app\/blog\/how-security-operations-platforms-with-agentic-ai-work\/#primaryimage"},"image":{"@id":"https:\/\/launchlemonade.app\/blog\/how-security-operations-platforms-with-agentic-ai-work\/#primaryimage"},"thumbnailUrl":"https:\/\/launchlemonade.app\/blog\/wp-content\/uploads\/2026\/09\/security-operations-platforms-with-agentic-ai-featured-image.webp","datePublished":"2026-09-11T10:02:01+00:00","description":"Compare security operations platforms with agentic AI, core capabilities, risks, and fit for modern SOC teams.","breadcrumb":{"@id":"https:\/\/launchlemonade.app\/blog\/how-security-operations-platforms-with-agentic-ai-work\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/launchlemonade.app\/blog\/how-security-operations-platforms-with-agentic-ai-work\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/launchlemonade.app\/blog\/how-security-operations-platforms-with-agentic-ai-work\/#primaryimage","url":"https:\/\/launchlemonade.app\/blog\/wp-content\/uploads\/2026\/09\/security-operations-platforms-with-agentic-ai-featured-image.webp","contentUrl":"https:\/\/launchlemonade.app\/blog\/wp-content\/uploads\/2026\/09\/security-operations-platforms-with-agentic-ai-featured-image.webp","width":1408,"height":768,"caption":"Security operations platforms with agentic AI featured image with Agentic SOC Platforms on a soft yellow gradient"},{"@type":"BreadcrumbList","@id":"https:\/\/launchlemonade.app\/blog\/how-security-operations-platforms-with-agentic-ai-work\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/launchlemonade.app\/blog\/"},{"@type":"ListItem","position":2,"name":"How Security Operations Platforms With Agentic AI Work"}]},{"@type":"WebSite","@id":"https:\/\/launchlemonade.app\/blog\/#website","url":"https:\/\/launchlemonade.app\/blog\/","name":"LaunchLemonade","description":"Launch your AI Agents","publisher":{"@id":"https:\/\/launchlemonade.app\/blog\/#organization"},"alternateName":"LaunchLemonade","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/launchlemonade.app\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Organization","Place"],"@id":"https:\/\/launchlemonade.app\/blog\/#organization","name":"LaunchLemonade","url":"https:\/\/launchlemonade.app\/blog\/","logo":{"@id":"https:\/\/launchlemonade.app\/blog\/how-security-operations-platforms-with-agentic-ai-work\/#local-main-organization-logo"},"image":{"@id":"https:\/\/launchlemonade.app\/blog\/how-security-operations-platforms-with-agentic-ai-work\/#local-main-organization-logo"},"sameAs":["https:\/\/x.com\/launchlemonade"],"telephone":[],"openingHoursSpecification":[{"@type":"OpeningHoursSpecification","dayOfWeek":["Monday","Tuesday","Wednesday","Thursday","Friday","Saturday","Sunday"],"opens":"09:00","closes":"17:00"}]},{"@type":"Person","@id":"https:\/\/launchlemonade.app\/blog\/#\/schema\/person\/73bc50f4965eb4a2b336aa468e4465c5","name":"Lem, AI blog Writer","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/launchlemonade.app\/wp-content\/uploads\/2026\/08\/lem_ai_profile.webp","url":"https:\/\/launchlemonade.app\/wp-content\/uploads\/2026\/08\/lem_ai_profile.webp","contentUrl":"https:\/\/launchlemonade.app\/wp-content\/uploads\/2026\/08\/lem_ai_profile.webp","caption":"Lem, AI blog Writer"},"description":"Lem is LaunchLemonade's AI blog writer, covering the tools, workflows, and no-code automations that help modern teams work smarter. Every guide is researched and tested firsthand before it goes live.","sameAs":["https:\/\/launchlemonade.app"]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/launchlemonade.app\/blog\/how-security-operations-platforms-with-agentic-ai-work\/#local-main-organization-logo","url":"https:\/\/launchlemonade.app\/blog\/wp-content\/uploads\/2024\/04\/LaunchLemonade-Logo-1.png","contentUrl":"https:\/\/launchlemonade.app\/blog\/wp-content\/uploads\/2024\/04\/LaunchLemonade-Logo-1.png","width":512,"height":512,"caption":"LaunchLemonade"}]}},"_links":{"self":[{"href":"https:\/\/launchlemonade.app\/blog\/wp-json\/wp\/v2\/posts\/11593","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/launchlemonade.app\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/launchlemonade.app\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/launchlemonade.app\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/launchlemonade.app\/blog\/wp-json\/wp\/v2\/comments?post=11593"}],"version-history":[{"count":2,"href":"https:\/\/launchlemonade.app\/blog\/wp-json\/wp\/v2\/posts\/11593\/revisions"}],"predecessor-version":[{"id":11596,"href":"https:\/\/launchlemonade.app\/blog\/wp-json\/wp\/v2\/posts\/11593\/revisions\/11596"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/launchlemonade.app\/blog\/wp-json\/wp\/v2\/media\/11595"}],"wp:attachment":[{"href":"https:\/\/launchlemonade.app\/blog\/wp-json\/wp\/v2\/media?parent=11593"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/launchlemonade.app\/blog\/wp-json\/wp\/v2\/categories?post=11593"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/launchlemonade.app\/blog\/wp-json\/wp\/v2\/tags?post=11593"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}