Autonomy is a question of who decides what
An autonomous security operations center (SOC) uses software agents to do the routine work of a SOC without waiting for a person to start each step. That work includes collecting and normalizing events, adding context, deciding how serious an alert is, grouping related alerts, and taking the first response.
Autonomous does not mean unattended. A useful definition says which decisions the system may make alone and which it must hand to a person. If a design can't answer that, it is automation without guardrails.
How the work flows in AgentSOC
Jutsu describes AgentSOC as a single AI-native platform that replaces a stack of disconnected tools: a SIEM, a separate SOAR, threat-intelligence feeds, and standalone reporting. Each event that enters the platform passes through the same pipeline.
- Ingest: events arrive from Wazuh, Google Workspace, syslog, or the Ingest API.
- Normalize and triage: each alert gets a category, severity, risk score, and verdict.
- Enrich: indicators are checked against threat intelligence such as VirusTotal, AbuseIPDB, AlienVault OTX, GreyNoise, MalwareBazaar, Kaspersky OpenTIP, MISP, CISA KEV, and IP-API geolocation.
- Correlate: related alerts become incidents, including multi-hop attack chains such as lateral movement.
- Respond: AgentSOAR runs response actions against connected cloud, email, and identity providers.
- Report: incident reports and SOC, compliance, and executive reports are generated for you.
Where humans stay in control
AgentSOC bounds its own autonomy in four ways. They are why your team can let agents work through the queue without losing control of what happens in production.
- Escalation: alerts the agents can't resolve with confidence go to an analyst for investigation.
- Approval-based response: from the Startup plan, an analyst approves an action before it runs.
- Policy-guided automation: from the Growth plan, actions your policies allow can run on their own.
- Audit and revert: every AgentSOAR execution is recorded with its status, and actions such as blocking an IP, isolating a host, or disabling a user can be reverted.
Roles for a tiered team
Role-based access follows the shape of a real SOC. Organizations can assign owner, admin, member, and analyst roles, including L1, L2, and L3 analysts. Cases carry evidence, comments, and escalation, so a handoff from the agents to an analyst, or from L2 to L3, keeps its context.
