AI Employee Roster · Security teams

The AI SOC Analyst

Every alert worked — and your analysts on the decisions that need a person.

Security tools generate more alerts than a small team can read, and most of them turn out to be nothing. The AI SOC Analyst triages every alert and reported email, gathers the evidence, and drafts a verdict, so your analysts start each case with the groundwork done.

Configured to your security tools, playbooks, and escalation rules. Working alongside your analysts on a least-privilege identity, with the access and authority you choose to give it.

Or see a typical day
A security analyst reviewing a prepared case on a wide monitor in a dimly lit Miami operations room
AI SOC Analyst
Least-privilege security identity
In your alert queue Working after hours
Identity
Its own scoped security identity
Works with
Your analysts and IT leads
Available
Whenever alerts fire
Starts in
Supervised mode
Trained on
Your playbooks and past cases
Part of the team

A first-line analyst, with limits you can see

Your AI SOC Analyst works inside the alert queue and case tools your team already uses. It has its own security identity, so every lookup, verdict, and action is recorded under its name — and its access can be scoped, reviewed, and revoked like any account.

Your analysts see what it closed and why, what it escalated, and what it is waiting on. Security work has a built-in paradox: the agent reads emails, tickets, and logs where an attacker may have planted instructions. So it treats that input as possibly hostile, works with least privilege, and leaves consequential decisions to people.

  • What it closed
  • What it escalated
  • What needs a decision
Case: Unusual sign-in
Identity alert from your sign-in logs
Sign-in from a new country for a finance user, shortly after a sign-in from the office.
AI SOC Analyst case notes
The two locations can't both be real for one person. No travel on record, and a new mailbox forwarding rule was created after the second sign-in. Likely compromised.
Recommended: revoke sessions and reset the password. Needs analyst approval.
Approve response Review evidence
Illustrative example of a supervised case
What the research shows

Analysts with an AI agent got faster and more accurate

6.5×

as many true positives per analyst-minute, at best, for analysts using Microsoft's phishing-triage agent in a randomized controlled trial (2025).

Source: Microsoft study (arXiv)
77%

improvement in verdict accuracy compared with a control group in the same trial — faster and more accurate, not just busier.

Source: Microsoft study (arXiv)
Verify

is still the rule. Microsoft's own guidance says agent outputs can be inaccurate, generated scripts need testing, and people must verify critical outputs.

Source: Microsoft

What your AI SOC Analyst can do

Five kinds of first-line security work — each one inside the limits your team sets.

01

Triage every alert, not just the loud ones

Endpoint, email, identity, firewall: each tool raises its own alerts, and most of them are benign. When a small team can't read them all, the one that matters can sit unread.

Your AI SOC Analyst reviews every alert as it arrives, checks it against related activity, and sorts it: closed as benign with the reason written down, or opened as a case for an analyst with a verdict and its confidence.

Alert queue
Triaged on arrival
  • Admin tool run on a server
    Closed · benign Matches scheduled maintenance
  • Unusual sign-in for a finance user
    Case · likely malicious High confidence
  • New software on a laptop
    Case · needs analyst Low confidence
  • Blocked connection to a known-bad site
    Closed · already blocked Reason recorded
02

Work through reported phishing

Training staff to report suspicious email works — and then someone has to look at every report. Most are harmless; a few are the start of an attack.

Your AI SOC Analyst checks the sender, links, and attachments, looks for the same message in other mailboxes, and drafts a verdict with the evidence behind it for an analyst to confirm.

It doesn't follow instructions in the email. Anything it reads in a suspicious message is treated as evidence, never as a command.

Reported email
Likely phishing
Subject
"Urgent: updated wire instructions for this week's payment"
  • Sender domain registered recently, look-alike of a vendor
  • Link leads to a credential page, not the vendor
  • Same message found in other inboxes
  • Verdict drafted · removal awaits analyst approval

Illustrative

03

Gather the evidence before an analyst opens the case

The slow part of an investigation is collecting context: who the user is, what the device did, what changed, and what else happened around the same time — across several consoles.

Your AI SOC Analyst pulls that context together into one timeline, with a link back to the source for each entry, so your analyst can check the work and spend their time on what it means.

Case timeline
Illustrative
  1. Sign-in from the office
    Identity provider
  2. Sign-in from another country
    Identity provider
  3. Mailbox forwarding rule created
    Email audit log
  4. Invoices searched in the mailbox
    Email audit log
04

Draft the verdict and response for an analyst to approve

Once the evidence is in, someone has to decide what happened and what to do. Your AI SOC Analyst writes that up: the verdict, the reasoning, and the recommended response from your playbook.

Where a query or script would help, it drafts one for your analyst to review and test before anything runs.

The analyst decides. The draft is the starting point, not the decision.

Drafted for analyst review
Compromised account
Verdict
With the reasoning behind it
Evidence
Each item linked to its source
Recommended response
From your playbook
Drafted hunting query
To be tested before it runs
05

Run only the containment steps you pre-approve

At 2 a.m., the first minutes matter. Some steps are low-risk and reversible — quarantining a malicious email, blocking a known-bad address — and waiting until morning for them helps nobody.

You choose which playbook steps your AI SOC Analyst may run on its own, which need an analyst's approval, and which it never touches. Everything it does is recorded under its own identity.

Containment playbook
Set by your team
  • Quarantine a confirmed phishing email
    On its own
  • Block a known-bad address
    On its own
  • Revoke a user's sessions
    Needs approval
  • Isolate a production server
    Always a person

Picture this working on your alerts

Tell us which tools raise your alerts and who handles them today. We'll show you what an AI SOC Analyst configured for your environment would take on first.

A typical day

See it in a typical day

From the overnight alerts to the one that fires at 2 a.m.

An IT lead reviewing a short list of prepared security cases with coffee at the start of the day
7:00 a.m.
The overnight alerts are already worked
An empty operations room at night with security dashboards glowing purple on the wall
After hours
Still triaging when the office is empty
  1. 7:00 a.m.

    The overnight alerts are already worked.

    Benign noise is closed with a reason. Anything suspicious is waiting for an analyst as a case with the evidence attached.

  2. 10:30 a.m.

    Staff report a suspicious email.

    It checks the sender, links, and attachments, finds the same message in other inboxes, and drafts a verdict for an analyst to confirm.

  3. 2:15 p.m.

    A sign-in looks wrong.

    It builds the timeline — locations, devices, recent changes — and hands the case to your analyst with a recommended next step.

  4. After hours

    An alert fires at 2 a.m.

    It triages immediately, runs only the containment steps you pre-approved, and pages the on-call person when the playbook says to.

Each step can be configured around how your team actually works.

Your team sets the boundaries

The AI SOC Analyst starts with supervised work. Autonomy is something your team grants, one proven routine at a time — never something it takes.

How responsibility can grow
Illustrative · pace set by your team
Supervised-first autonomy for the AI SOC Analyst A stepped chart. Independent steps start at a supervised baseline where verdicts and actions are reviewed. The team can expand scope to proven routines, then to more routines with oversight and an activity record. A band at the top marks consequential remediation — isolating production systems, disabling executive accounts, wiping devices, and incident command — which is always authorized by your analysts. Isolating production, disabling executives, wiping devices Always authorized by your analysts · incident command stays human Supervised verdicts and actions reviewed Proven routines team opts in, step by step Expanded routines with oversight + activity record AS WORKFLOWS PROVE RELIABLE → STEPS IT MAY TAKE ALONE

Your team decides

Four controls, set by you and changeable at any time.

  • What it may access
    Which security tools, logs, and mailboxes it can read — on its own least-privilege identity.
  • What it may conclude
    Which alert types it may close as benign and which always need an analyst's verdict.
  • Which actions it may take
    Which containment steps, if any, it can run from a pre-approved playbook.
  • When it escalates
    The severities, systems, and people that always page your team immediately.

Want to talk through access and approvals?

We'll walk your IT and security leads through what the agent would see, what it could close, and what always comes to an analyst — before anything is switched on.

Configured, not generic

Built for your environment, not a generic security chatbot

Knowing what an attack looks like in general is not enough. A useful SOC analyst knows what normal looks like in your environment: your admins' habits, your scheduled jobs, your vendors, and which systems you can't afford to touch.

BASG configures the role from your playbooks, past cases, and the way your analysts decide, then refines it with their feedback. When an analyst corrects a verdict, that guidance can be incorporated going forward.

Configure, work, review, refine: the AI SOC Analyst improves with your analysts' feedback Your team's way of defending Configure Work Review Refine
Generic security chatbot
AI SOC Analyst
  • Explains security concepts
    Works your alerts with your tools and playbooks
  • Takes the input at face value
    Treats emails, tickets, and logs as possibly hostile
  • Suggests a script and moves on
    Drafts queries and scripts for an analyst to test first
  • Has no limits on what it can touch
    Runs on a least-privilege identity you control
  • Forgets corrections by the next chat
    Incorporates your analysts' feedback going forward
The result: an AI employee designed to work your alerts the way your best analyst would.

What could your team hand off?

The right starting point depends on where alerts pile up. For one team it's reported phishing; for another it's overnight coverage. Most start with one.

Start here? · 01

Alert triage

Every alert reviewed, benign noise closed with a reason, and real cases queued with evidence.

Start here? · 02

Reported phishing

Staff-reported emails analyzed, matched across inboxes, and given a drafted verdict.

Start here? · 03

Investigation groundwork

Timelines, related activity, and context gathered before an analyst opens the case.

Start here? · 04

After-hours first response

Alerts triaged at any hour, pre-approved containment run, and the right person paged.

Let's find the alerts your team can't get to — and design an AI SOC Analyst around them.

AI SOC Analyst — Common Questions

What IT and security leaders ask before bringing an AI employee onto the team.

Question we didn't answer?

Call and ask. You'll speak with someone who can explain how the AI SOC Analyst would work in your environment.

The AI Employee roster

Other roles on the team

See the full roster

Need the security program around it, too? See how BASG protects mid-market businesses with cybersecurity services.

Talk to BASG about an AI SOC Analyst

Tell us where your alerts pile up. We'll show you what an AI SOC Analyst configured for your environment could take on first.

Prefer to talk? We answer during business hours and return calls the same day.