Also known as: Agentic Security Operations Center, AI SOC
A security operations model in which AI agents use approved tools and context to perform bounded investigation, reporting, and response work under defined human governance.
An agentic SOC uses AI agents to select and coordinate approved security capabilities for goals such as triage, investigation, source-health review, reporting, or response preparation. The agents operate within defined data, role, tenant, and action boundaries.
An agentic SOC is not an unattended security team. People still define policy, approve sensitive actions, validate weak or contradictory evidence, handle exceptions, and own the outcome.
The difference between an assistant and an agent is not conversational language. An agent can pursue a bounded goal through approved capabilities, while an assistant may only answer a question or draft a query.