Calibrated to Act
Full title: Calibrated to Act: The Practitioner's Guide to Building an Agentic SOC That Knows When Not to Act
DOI: 10.5281/zenodo.21157411
Permanent URL: https://zenodo.org/records/21157411
What it's about
Agentic SOC platforms promise machine-speed incident response. The central finding that anchors this paper: a January 2026 adversarial evaluation (OpenSec, Jarrod Barnes, arXiv:2601.21083) found that three of four frontier AI models, acting as autonomous incident response agents, had false positive rates between 82% and 97% on autonomous containment. The gap is not in detection. It is in restraint.
This paper argues that calibration — knowing when not to act — is the defining engineering and governance challenge of the agentic SOC era.
What it covers
Three-phase migration roadmap (Establish → Calibrate → Mature) with hard exit criteria per phase Calibrated reference architecture — eight layers including coverage tiering, calibration gate, and entity-primitive IAM The calibration problem — OpenSec findings, evidence-gated thresholds, adversarial red-teaming Feedback loop as architecture — and as attack surface Governance beyond product RBAC — ownership, risk, and entity primitives Platform evaluation framework — what to ask vendors before you buy Cloud-native and hybrid environments — ephemeral compute, IAM-centric telemetry, coverage tiers OT/ICS environments — where false positives have physical consequences Inter-agent trust and the ASI07 failure mode Cost model and capacity planning MITRE ATT&CK and ATLAS integration SOAR transition strategy — including XSOAR end-of-sale guidance KPI and SLA framework with phase-specific targets Human factors — automation bias, automation disuse, analyst career path 13 prioritised recommendations 27 citations
Files in this repository
FileDescriptionCalibratedToAct_AgenticSOC.pdfFull paper — 546 paragraphs, 13 recommendations, 27 citationsCalibratedToAct_QuickReference.pdfTwo-page standalone quick reference — calibration table, 13 actions, migration roadmap, governance checklist, McKinsey five questionsCalibratedToAct_Architecture.svgEight-layer reference architecture diagram — Visio-exportable SVG
Citation
Priyadarshini, B. (2026). Calibrated to Act: The Practitioner's Guide to Building an Agentic SOC That Knows When Not to Act. Zenodo. https://doi.org/10.5281/zenodo.21157411