Research

Research seriesL3paper

The Governance of Autonomous SOC Authority

The Autonomous SOC debate is fundamentally a debate about authority. When an AI agent quarantines a production server, revokes credentials, or blocks a network segment, those acts are consequential and sometimes irreversible. No published decision-theoretic framework exists for when an autonomous SOC should act versus escalate — and that absence is itself an exploitable gap. This series builds the governance architecture from the ground up: a taxonomy of autonomous actions by reversibility and blast radius, the principal hierarchy that governs which agent can do what, the chain-of-custody problem when the forensic investigator is an AI, the playbook-drift attack surface when SOAR updates itself, and a maturity model for assessing readiness to grant autonomous authority. Grounded in NIST SP 800-61, NIST AI RMF, NIST SP 800-207, ISO/IEC 27035, and the human-autonomy interaction literature.

Murali Chillakuru·5 articles
  1. 1
    The Irreversibility Spectrum: A Taxonomy of Autonomous SOC Actions

    Before granting autonomous authority to a SOC response engine, an organization must classify every action by how difficult that action is to undo — and govern accordingly.

  2. 2
    Principal Hierarchies in AI-Automated Response: Who Governs the Responder?

    When a multi-agent SOC stack executes containment without human confirmation, the question of which agent can countermand which is not merely organizational — it is a security boundary.

  3. 3
    Chain-of-Custody in AI-Mediated Forensics

    When the forensic analyst is an AI, the chain-of-custody obligation does not disappear — it shifts to the infrastructure that fed the AI its evidence.

  4. 4
    Playbook Drift as an Attack Surface: When SOAR Updates Itself

    A SOAR platform that modifies its own response playbooks based on learned outcomes is an AI system with a feedback loop — and feedback loops can be poisoned.

  5. 5
    Measuring Autonomous SOC Readiness: An Assessment Framework

    Before an organization grants autonomous authority to a SOC response engine, it should be able to answer five questions — and produce evidence for each answer.