Published July 3, 2026 | Version v2

Calibrated to Act: The Practitioner's Guide to Building an Agentic SOC That Knows When Not to Act

Authors/Creators

  • 1. Independent Security Researcher

Description

Agentic SOC platforms promise machine-speed incident response. But a January 2026 adversarial evaluation — OpenSec, by researcher Jarrod Barnes — found that three of four frontier AI models, acting as autonomous incident response agents, executed containment with false positive rates between 82% and 97%. Only one model demonstrated partial calibration. The conclusion: the gap is not in detection. It is in restraint.

This paper argues that calibration — knowing when not to act — is the defining engineering and governance challenge of the agentic SOC era. It covers the complete deployment lifecycle: a three-phase migration roadmap with hard exit criteria, a calibrated reference architecture, ownership-risk-entity access governance beyond product RBAC, MITRE ATT&CK and ATLAS integration, SOAR transition strategy with specific vendor guidance, cloud-native and OT/ICS environment considerations, inter-agent trust and the ASI07 failure mode, cost modelling and capacity planning, a KPI and SLA framework, and human factors including automation bias, skill atrophy, and the analyst career path.

Thirteen prioritised recommendations for security engineers, CISOs, and AI leaders. 27 citations. Research and drafting assistance provided by Claude (Anthropic); all analysis and conclusions are the author's own.

Files

CalibratedToAct_Agentic_SOC.pdf

Files (762.5 kB)

Name Size Download all
md5:6a74aa9f59ec8311fe00030d843dbcd2
762.5 kB Preview Download

Additional details

Related works

Cites
Preprint: arXiv:2601.21083 (arXiv)

Dates

Issued
2026-06-01
Publication date