Calibrated to Act: The Practitioner's Guide to Building an Agentic SOC That Knows When Not to Act
Description
Agentic SOC platforms promise machine-speed incident response. But a January 2026 adversarial evaluation — OpenSec, by researcher Jarrod Barnes — found that three of four frontier AI models, acting as autonomous incident response agents, executed containment with false positive rates between 82% and 97%. Only one model demonstrated partial calibration. The conclusion: the gap is not in detection. It is in restraint.
This paper argues that calibration — knowing when not to act — is the defining engineering and governance challenge of the agentic SOC era. It covers the complete deployment lifecycle: a three-phase migration roadmap with hard exit criteria, a calibrated reference architecture, ownership-risk-entity access governance beyond product RBAC, MITRE ATT&CK and ATLAS integration, SOAR transition strategy with specific vendor guidance, cloud-native and OT/ICS environment considerations, inter-agent trust and the ASI07 failure mode, cost modelling and capacity planning, a KPI and SLA framework, and human factors including automation bias, skill atrophy, and the analyst career path.
Thirteen prioritised recommendations for security engineers, CISOs, and AI leaders. 27 citations. Research and drafting assistance provided by Claude (Anthropic); all analysis and conclusions are the author's own.
Files
CalibratedToAct_Agentic_SOC.pdf
Files
(762.5 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:6a74aa9f59ec8311fe00030d843dbcd2
|
762.5 kB | Preview Download |
Additional details
Related works
- Cites
- Preprint: arXiv:2601.21083 (arXiv)
Dates
- Issued
-
2026-06-01Publication date