Can AI run a SOC?
AI can investigate a SOC's alerts, but people decide what the SOC does. We place every ARRTECH product available today on five levels of who decides and when. Each is designed to keep people, or the rules they write, in charge.
Levels
Observes only.
Raises findings. A person judges each one.
Investigates, read-only.
Writes a case through read-only queries. A person reviews it.
Works when approved.
Works only on approved tasks, and a person accepts the result. In early access.
Acts by rule.
Acts only as your team wrote in advance. SOAR playbooks wait at each Operator node for a person.
Acts alone.
Acts with no person's rule or approval. Our products are designed to keep a person or your rules in charge.
Limits
Scale
This scale is ours. It shows the most each product can do today, not what every deployment uses.
Rules
Acting by rule is only as safe as the rules. Review changes to playbooks and DLP policies as you would any change to production.
Standards
Naming a clause is not a claim of certification.
OECD
The OECD's framework for reporting AI incidents asks for a system's maximum autonomy level. This scale gives each of our products one.
OWASP
LLM06:2025, Excessive Agency, is more permission or autonomy than a task needs. The first two levels give our models read access only.
NIST
AI RMF MAP 2.2 asks how output is used and overseen by people. This page documents that for every product available today.