Every alert ends in a decision: close it, escalate it, or act on a host or an account. Software can gather the evidence and carry out the action, but a person has to own the choice. Gartner expects 70% of large SOCs to pilot AI agents by 2028, and only 15% to show measurable improvement without structured evaluation.
Autonomy
Gartner calls the category AI SOC agents. Among its questions for buyers: where the boundaries of autonomy sit, and whether you can audit what the AI did. Products answer the first question in one of two ways. ARRTECH builds only the first.
In the loop
The software recommends and a person approves before anything changes. A September 2026 survey by Prophet Security, an AI SOC vendor, found that 57% of teams require human review before an alert is closed, and 44% let AI recommend while a person executes.
On the loop
The software acts on its own and a person monitors it, with an option to override. The person reviews what has already happened.
Investigation
How deeply an alert is investigated depends on who picks it up and how many others are waiting. The questions asked, and the evidence that would change the answer, are rarely written down.
Cyberdroid AI Investigation starts from Cyberdroid AI Detection findings and ARRTECH SIEM alerts. It states what it will investigate, why, and what evidence would disprove it. Software compiles its questions into read-only queries, validates each field and enforces row, time and cost budgets.
A separate critic step tests the verdict before the case is written. An investigation that runs out of budget is parked incomplete rather than concluded.
Response
Isolating a host or disabling an account is a business decision. Software that acts on its own acts on a false positive as readily as on a real attack.
An ARRTECH SIEM correlation alert, a monitored mailbox, a REST call or an analyst opens an ARRTECH SOAR incident. The playbook extracts IPs, hashes and other indicators and updates their reputation. At an Operator node, a person receives an email with up to five options, and the playbook waits. Pending decisions sit on one page.
SOAR then runs the choice through its integrations over REST APIs: it updates a list, creates an incident, runs a Python script, sends mail or runs up to five branches in parallel. You can simulate a playbook on sample data before it runs, and action nodes are validated without executing.
Record
Afterwards, someone will ask why an action was taken and who approved it.
Every request is decided from policy, not from its wording, and recorded as Task, Pending approval, Refused or Rate-limited, with an operation id and a reason. An agent’s work finishes in review, never resolved. A person verifies it, then resolves or reopens the task. Requesters receive a plain-language outcome, and technical artifacts stay with operators.
ARRTECH SOAR keeps the history of every run and an SLA dashboard. The measures are minutes per case and cost per accepted task, not alert volume.
Limits
What automation does not do here.
Authority
Cyberdroid AI Investigation never touches your systems, and it cannot approve its own work or choose who receives an answer. Action stays in ARRTECH SOAR and XDR, on a person’s approval.
Scope
Cyberdroid AI Investigation is in early access and requires Cyberdroid AI Detection. It reads ARRTECH SIEM and Detection data, a third-party SIEM connects through its export, and it puts depth before speed.
Evaluation
An evaluation runs on your own alerts, with success and stop criteria agreed in writing before the first case. You see which cases a person accepted, the minutes per case and the cost per accepted task.
Schedule a meetingSources
Products

Cross-source behavioral detection on your SIEM: identity, network, DNS, process and firewall telemetry, baselined against each entity’s own history.

Runs incident playbooks through API integrations, with a human decision built into the flow.
