Skip to content

SOC manager

Run the shift, not the spreadsheet.

Your job is throughput and quality. Both are invisible when the queue is unmeasurable and the handover is a chat message.

What changes

What your week looks like

Left is the week you have. Right is the same week on the platform. Nothing else on this page matters more than whether the left column is recognisable.

  1. Shift handover is a message someone types at the end of a long day.

    Active, pending and resolved work compiled at the shift boundary, with nothing typed by hand.

  2. You can't tell whether the queue is genuinely worse or just noisier.

    Volume, classification split and queue depth per agent and per source, so a worse week is distinguishable from a noisier one.

  3. SLA breaches are discovered after the fact.

    Every review queue carries its own SLA countdown on the card, and the identity gate is four hours.

  4. Analyst disagreement with tooling is anecdotal, so nothing gets tuned.

    Model-analyst agreement, the disagreement count, and whether enough has accrued to trigger a retrain, with the divergences listed.

Access

What you own, and what you can reach.

The platform has three roles, not six. This is the one you would hold, enforced at the route on the client and again on the server rather than hidden in the interface.

Platform role

Admin or Analyst

What it opens
Analyst covers every subscribed agent workspace and the review queues you actually run the shift from.
What it does not
Model training and the Management Portal need Admin. If you own tuning as well as throughput, take the wider role.

The measure

The numbers you would be judged on.

Published targets and platform behaviour, not projections. Where one of these is a target rather than an achievement, it says so.

  • 67%

    Noise reduction

    What classification removes before an analyst reads anything.

  • 4 hrs

    Identity review gate

    And a timeout doesn't contain. Nothing resolves because nobody answered.

  • P / R / F1

    Model health

    Precision, recall and F1 with trend, and a convergence badge per version.

  • 3

    Routing lanes

    Auto-execute, review, monitor. Every agent resolves into one of them.

Your workspaces

What you would actually open.

You can turn one on and add the others later. A connector configured for one is available to the rest.

Questions

The things people ask first.

  • How do I know the queue is genuinely improving?

    Noise reduction is the headline, and it opens to show its arithmetic: how many alerts were ingested, how many were deduplicated, how many a tuning rule suppressed, and what working set is left. A figure you can defend rather than one you have to trust.

  • What happens when an analyst disagrees with the model?

    The override is captured as reinforcement signal. The console tracks decisions processed, model-analyst agreement, the disagreement count, and whether enough disagreements have accrued to trigger a retrain, with a filterable table of exactly where the two diverged.

  • Does anything auto-resolve when nobody is on shift?

    Only what routes to auto-execute, which is the high-confidence, cheap-to-undo end. The identity review gate is SLA'd at four hours and expiring doesn't release the containment: if nobody answers, nothing happens.

  • Is the handover editable before it goes out?

    It compiles from the incident state at the shift boundary rather than from anyone's notes, and it's a document you review rather than one that publishes itself. Scheduled reports work the same way: generated automatically, held for review.