Who Should Make the First Triage Decision in a Modern SOC?
The average SOC receives nearly 4,000 alerts per day. Two-thirds are never investigated. When speed determines whether a breach is contained or catastrophic, who — or what — should decide what gets looked at first?
- #soc
- #triage
- #ai
- #operations
The average SOC receives nearly 4,000 alerts per day. Two-thirds are never investigated. When speed determines whether a breach is contained or catastrophic, the question of who makes the first triage decision is no longer academic.
The L1 bottleneck
Tier-1 analysts are expensive to hire, hard to retain, and burn out fast. The classic “every alert gets eyes on glass” model never scaled — and the volume keeps climbing.
Three approaches we see in the field
- Pure automation — playbooks dispose of low-confidence alerts. Fast, but blind to subtle signals.
- AI-augmented L1 — an AI co-pilot triages, an analyst confirms. The current sweet spot for most teams.
- AI-led, human-supervised — the AI makes the call, humans audit a sample. Higher leverage, requires confidence in the model.
The question behind the question
Choosing between those three is really a decision about where you are willing to accept risk. Pure automation accepts the risk of a quiet miss. Eyes-on-glass accepts the risk of a queue: the alert that mattered sat at position 400 while an analyst worked position 12.
The second risk is the one that actually produces breaches. Attackers do not need your detection to fail, only your response to be slow. Two-thirds of alerts never investigated is not a staffing problem you can hire your way out of; at 4,000 alerts a day the arithmetic never closes.
What a good first decision looks like
Whoever, or whatever, makes the first call has to deliver three things:
- A verdict, not a score. “78% suspicious” moves the decision, it does not make it.
- The evidence that produced it. An analyst has to be able to audit the reasoning, not take it on faith at 3 a.m.
- Reversibility. Any containment action taken automatically must be undoable in one click, or nobody will ever be allowed to switch it on.
Miss any one of those and you are back to a queue with extra steps.
Where Blacklight sits
Blacklight’s AI-led triage produces a verdict, a confidence score and a full reasoning trail, so analysts can trust it, override it, or correct it. Level-1 triage, investigation and containment run at machine speed; the breaking-change decision, the judgement about what a response will do to the business, stays with a person.
The measurable result is not “alerts handled.” It is the exposure window: how long an attacker operates before containment. That is the number that maps to breach cost, and the one worth holding a SOC to.
Related: what agentic AI actually changes in the SOC and why the autonomous SOC was the wrong target.
Related reading
Book a live walkthrough.
Sixty minutes on a pre-loaded, anonymised environment: one real incident handled end to end, mapped to your sector. No connectors or data required from you.