Yes for triage, investigation legwork, evidence gathering and first-pass verdicts, under supervision and with every action logged. No for accountability, which stays human: a person owns the verdict, the response and the answer the auditor receives. Secure60 runs AI workers in production on those terms, alongside human analysts.
Agentic AI in security performs a specific set of jobs, and the boundary between what it can carry and what it cannot is well defined.
| Security operations work | Can an agent do it? | What that looks like |
|---|---|---|
| Alert triage and first-pass verdicts | Yes, supervised | Reads the alert, checks history and context, proposes a verdict with reasoning attached |
| Investigation legwork | Yes | Pulls related logs across sources, builds the timeline, maps which hosts, users and accounts are involved |
| Evidence gathering | Yes | Assembles the log excerpts and artefacts a human needs to decide in minutes rather than an hour |
| Response and containment actions | Only behind approval gates | Proposes the action; a human approves before anything changes |
| Accountability for the outcome | No | A person owns the verdict, the response, and the answer the auditor receives |
Agents are strong where the work is retrieval, correlation and write-up across large volumes of data, which accounts for most of the hours in a SOC shift. Humans hold the decisions that carry consequences.
Supervision. An agent’s verdict is a proposal until the process says otherwise. Initially a human reviews everything, and the set of categories the agent closes on its own widens deliberately, against performance on your own alert mix, with override always available. Action does not widen automatically: anything that changes a system waits for approval.
A full audit trail. Every input the agent received, every tool call it made, every output it produced, and who authorised each step, recorded, retained and searchable. Without that trail the agent’s work cannot be reviewed, a customer’s question about autonomous action cannot be answered, and an incident it participated in cannot be reconstructed. How do you prove what an AI system did? sets out what to record.
With both conditions met, an agent is a supervised and evidenced part of the operation. Without either, it is an unaccountable actor holding production access.
Secure60 ships AI workers that investigate and triage alongside human analysts — digital workers — running in our platform today. A new threat arrives; a worker picks it up, pulls the related logs, builds the timeline, gathers the evidence and attaches a first-pass verdict with its reasoning. A human analyst reviews, agrees or overrides. Every session is logged end to end, so any verdict can be traced back through what the worker saw and did.
Two findings from running this in production. The throughput gain is not in the verdict itself: it is that every alert reaches the human with the investigation already complete, which reduces the human decision to minutes. And the audit trail delivers value well before any audit, because it allows the worker’s cases to be reviewed the way a junior analyst’s would be, so its remit widens on evidence.
Accuracy quoted on a vendor’s own benchmark carries little information about your alert mix, and it is not the property that causes failures. Invisibility is.
A wrong first-pass verdict that is logged and reviewable costs an analyst minutes to identify and correct. An unlogged agent fails a customer’s security review, leaves incident reconstruction without a source, and produces an audit finding, including on the occasions its verdicts were correct. The first request to make of any vendor is the complete log of what their agent did on a specific day. Where that log is thin, accuracy figures are not the deciding factor.
Secure60 runs security operations as a service, and that increasingly includes AI workers. They run triage and investigation under supervision inside our platform, with human analysts accountable for every outcome, and every action logged, attributable and reviewable as part of our AI Security capability. The throughput of agents and the record of how they behaved sit in the same place, so a customer or auditor asking how AI operates in your security stack is answered from that record.
Will AI agents replace SOC analysts?
No. They take the legwork — pulling logs, building timelines, assembling evidence, proposing first-pass verdicts — so analysts spend their time on judgement rather than retrieval. The accountable decision stays with a person.
What is an AI SOC analyst?
The market’s term for an AI agent that performs first-pass alert work: it reads an alert, gathers the related evidence across your logs, and proposes a verdict with its reasoning attached. The ones worth using run under supervision and log every step.
Is it safe to let an AI agent take response actions?
Only behind approval gates. Investigation and evidence gathering are read operations and low-risk to automate. Containment and response change systems, so a human approves before the agent acts, and the request, approval and action are all logged.
How do we evidence AI agent activity to an auditor or a customer?
Log the agent’s inputs, every tool call, its outputs, and who or what authorised each action, then retain and search those records like any other log stream. How do you prove what an AI system did? covers the full structure.
Do we need our own AI team to use agents in security operations?
No. Platforms ship the agents. What you supply is the governance: defined supervision, approval gates for anything that changes a system, and an audit trail you control. Those three are the first thing to evaluate in a vendor, ahead of accuracy claims.