Watch · narrated walkthroughs
The Autonomous SOC debate is fundamentally a debate about authority. When an AI agent quarantines a production server, revokes credentials, or blocks a network segment, those acts are consequential and sometimes irreversible. No published decision-theoretic framework exists for when an autonomous SOC should act versus escalate — and that absence is itself an exploitable gap. This series builds the governance architecture from the ground up: a taxonomy of autonomous actions by reversibility and blast radius, the principal hierarchy that governs which agent can do what, the chain-of-custody problem when the forensic investigator is an AI, the playbook-drift attack surface when SOAR updates itself, and a maturity model for assessing readiness to grant autonomous authority. Grounded in NIST SP 800-61, NIST AI RMF, NIST SP 800-207, ISO/IEC 27035, and the human-autonomy interaction literature.