Skip to content

SOC analyst

Open ten alerts that matter, not a thousand that do not.

You don't need another dashboard. You need the enrichment done, the duplicates merged, and the reasoning visible so you can agree or disagree quickly.

What changes

What your week looks like

Left is the week you have. Right is the same week on the platform. Nothing else on this page matters more than whether the left column is recognisable.

  1. You copy indicators into three tools before you can judge an alert.

    Every address, domain, hash and account enriched from threat intel and your own context before the alert opens.

  2. The same event is in your queue twelve times.

    Alerts that describe one event arrive as one case, so you work the case rather than twelve copies of a signal.

  3. Containment means asking someone with the right admin role.

    The action set is proposed and executes on your approval through Microsoft Graph, not through finding whoever holds the role.

  4. You override the tool constantly and nothing changes.

    Every confirmation and override is reinforcement signal, and the console tracks when enough has accrued to retrain.

Access

What you own, and what you can reach.

The platform has three roles, not six. This is the one you would hold, enforced at the route on the client and again on the server rather than hidden in the interface.

Platform role

Analyst

What it opens
Every subscribed agent and its workspace, the review queues, and read access to settings. This is the day-to-day operator role.
What it does not
The Management Portal, the CISO Cockpit and user management redirect you back to the hub. You are not meant to be in them.

The measure

The numbers you would be judged on.

Published targets and platform behaviour, not projections. Where one of these is a target rather than an achievement, it says so.

  • 70 / 50

    Confidence bands

    At or above 70 reads green, 50 to 69 amber, below 50 red.

  • One click

    To agree or override

    The classification, its confidence, and the features behind it.

  • Reason

    Required at the gate

    A classification change cannot reach a ticket without one.

  • Recorded

    Before it runs

    The rollback for an action is written down before the action executes.

Questions

The things people ask first.

  • Will it close things I would not have closed?

    It closes what it is confident about and writes the determination onto a Jira ticket, so a closure is a record you can find rather than an alert that vanished. Every classification is reversible and every change goes through the gate.

  • Can I see why it decided something?

    Every alert exposes the features that drove its classification, the confidence behind it, and the MITRE tactic it mapped to. Phishing and identity incidents additionally carry a plain-language rationale and a ranked set of recommended actions.

  • What can I actually execute myself?

    The proposed set, in one approval: purge and sender blocks on a phishing incident, session revocation and forced MFA re-enrolment on an identity alert. It runs through Graph under the agent's own permissions, so it does not depend on you holding an admin role.

  • What if I approve something and it was wrong?

    Roll it back. Soft-deleted mail restores from Deleted Items, sender and URL blocks revert, accounts re-enable and MFA methods restore. The incident moves to a rolled-back state and the recovery is logged with your reason.