Skip to content

Repository files navigation

Content

Calibrated to Act

Full title: Calibrated to Act: The Practitioner's Guide to Building an Agentic SOC That Knows When Not to Act

DOI: 10.5281/zenodo.21157411

Permanent URL: https://zenodo.org/records/21157411

What it's about

Agentic SOC platforms promise machine-speed incident response. The central finding that anchors this paper: a January 2026 adversarial evaluation (OpenSec, Jarrod Barnes, arXiv:2601.21083) found that three of four frontier AI models, acting as autonomous incident response agents, had false positive rates between 82% and 97% on autonomous containment. The gap is not in detection. It is in restraint.

This paper argues that calibration — knowing when not to act — is the defining engineering and governance challenge of the agentic SOC era.

What it covers

Three-phase migration roadmap (Establish → Calibrate → Mature) with hard exit criteria per phase Calibrated reference architecture — eight layers including coverage tiering, calibration gate, and entity-primitive IAM The calibration problem — OpenSec findings, evidence-gated thresholds, adversarial red-teaming Feedback loop as architecture — and as attack surface Governance beyond product RBAC — ownership, risk, and entity primitives Platform evaluation framework — what to ask vendors before you buy Cloud-native and hybrid environments — ephemeral compute, IAM-centric telemetry, coverage tiers OT/ICS environments — where false positives have physical consequences Inter-agent trust and the ASI07 failure mode Cost model and capacity planning MITRE ATT&CK and ATLAS integration SOAR transition strategy — including XSOAR end-of-sale guidance KPI and SLA framework with phase-specific targets Human factors — automation bias, automation disuse, analyst career path 13 prioritised recommendations 27 citations

Files in this repository

FileDescriptionCalibratedToAct_AgenticSOC.pdfFull paper — 546 paragraphs, 13 recommendations, 27 citationsCalibratedToAct_QuickReference.pdfTwo-page standalone quick reference — calibration table, 13 actions, migration roadmap, governance checklist, McKinsey five questionsCalibratedToAct_Architecture.svgEight-layer reference architecture diagram — Visio-exportable SVG

Citation

Priyadarshini, B. (2026). Calibrated to Act: The Practitioner's Guide to Building an Agentic SOC That Knows When Not to Act. Zenodo. https://doi.org/10.5281/zenodo.21157411

About

Peer-citable papers on agentic SOC design — when autonomous incident response should act, and when it should not. DOI-archived via Zenodo.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors