Case study · Security Operations
The safety net and the bottleneck.
One function’s climb from manual to autonomous, and why the gate is the only honest way up.
Picture two security operations centres. The first trusts nothing to machines: every alert is read by a human. It is the safest SOC you can imagine, and it is drowning. Ten thousand alerts a day, a handful of analysts, a queue that never empties. The one real intrusion is in that pile, and by the time a tired human reaches it the attacker has been inside for days. Here the human is the bottleneck.
The second SOC solved speed. It automated triage, enrichment, and closure. It is fast and quiet. Then one night the AI looked at a real intrusion, decided it was routine, and closed it. Nobody was watching, because the whole point had been to stop watching. Speed was bought, and the safety net was spent to buy it.
Refuse to climb
Keep the net whole. The human bottleneck strangles your speed and your people burn out.
Rush to the top
Gain speed and scale. Each step moves a decision away from a human, so the safety net thins.
“How far up do I dare go, and how do I know I have not gone too far?”
Northwind Retail is caught precisely on this knife-edge. This case follows them, and it ends with the mechanism that resolves the dilemma. The answer is not a rung on the ladder. The answer is a gate.
The problem
A security operations team wants AI to take the load, but its safety net cannot hold what it hands over.
What this demo proves
One function climbs one autonomy rung the governed way: repair the net first, then hand over the work, with the gate deciding when.
The ladder
Every rung is a place the human stands.
Each rung is defined by one thing: where the human sits relative to the work. As the human moves from inside every step, to watching the stream, to reviewing after the fact, speed rises and the net changes shape. The task throughout is alert triage, because everyone recognises it.
The AI
Nothing.
You
Read, investigate, decide, and act on every alert.
The net
Total. A person judges everything.
The bottleneck
Severe. Throughput is capped at human hours.
The AI
Enriches the alert and drafts a verdict.
You
Review and approve every single draft.
The net
Full. Nothing acts without a human yes.
The bottleneck
Eased. Reading a draft beats building one.
The AI
Auto-handles routine alerts, escalates the ambiguous ones.
You
Watch the stream, work exceptions, override in real time.
The net
A sampling-and-override net. You catch the odd ones.
The bottleneck
Mostly gone for routine volume.
The AI
Runs triage end to end inside a bounded policy, takes permitted actions.
You
Notified after, check the result, set policy, intervene by exception.
The net
A policy-bounds-plus-after-review net.
The bottleneck
Eliminated for in-policy work.
Down low, the human guarantees the net and pays for it with the bottleneck. Up high, the human trades the guarantee for speed. Nobody escapes that trade by wishing. They escape it by earning the right to move, which is the gate.
The stack
Each rung is a real stack, not a mood.
Every rung is a concrete stack of tooling and capability. The four named skills below are the ones actually loaded on Northwind’s saved run. Notice what happens down the list: the same skills a human runs by hand at the bottom become an agent’s procedure at the top.
A SIEM raises alerts into a console. The analyst pivots by hand, runs intel lookups one at a time, reads email headers, writes the ticket. Every capability exists; a human performs each one. This is where the queue outgrows the team.
An enrichment-and-drafting layer on top of the SIEM. Context is pulled automatically, a copilot drafts a disposition, and the analyst reviews and approves each one. Faster per alert, but a human still signs every decision.
A SOAR layer runs playbooks gated by a confidence threshold. High-confidence, low-risk alerts are auto-dispositioned; ambiguous ones escalate to a human watching the stream. The routine volume stops touching a person.
An always-on agent runs the full triage-and-respond loop inside a bounded policy: enrich, check the playbook, take permitted actions, report the verdict. It is reachable from a messaging channel. This is where the companion agent sits.
The capability does not appear at the top. It is built at the bottom and progressively handed over. That handover is the whole story, and it is only safe if the net keeps pace.
The resolution
The gate is the answer to the dilemma.
The gate is not a brake on ambition and not a rubber stamp for it. It reads two axes. One is governance: your people, process, and technology maturity, the machinery that catches an AI when it is wrong. The other is autonomy: how much you have handed to the machine.
The rule is simple. You may only operate at the autonomy your governance can safely supervise. If autonomy runs ahead of governance, the gate shuts, because at that point the net has holes the AI can fall through. Speed is allowed exactly to the extent that safety is earned.
Governance on one axis, autonomy on the other. Stay above the line, or the gate shuts.
Where Northwind stands today.
Northwind tried to escape the bottleneck by adopting AI fast. Their alert triage already runs at Augmented. But they spent the safety net to do it. The people meant to catch the AI when it is wrong are at L1, so the whole function is capped there no matter how good the tooling is.
Northwind Retail is a constructed case, not a client engagement. Every reading on this page is computed live by the diagnostic from a real assessment run, so the mechanism you are watching is the product working. The organisation is invented, and no outcome here was observed at a customer.
High adoption plus a thin net is not transformation. It is the appearance of speed bought with borrowed safety, and the gate is the only instrument in the room willing to say so in red. They are the second SOC from the opening, mid-fall, and the diagnostic caught them before the incident did.
The move
Repair the net, then hand over the work.
You do not reassess from scratch. You open the saved Northwind run, hit reassess, and two things happen together, because you are not just raising autonomy: you are repairing the net so it can hold that autonomy.
a · repair the net
Put the incident-response team through AI-incident exercises: tabletop and live drills where they review and validate the AI’s triage before it is trusted in production. Record it in reassess. People moves off L1. Now there are trained humans who can catch the AI when it errs.
b · hand over the capability
Apply the four skills already attached to the run. Together they let triage run end to end inside a policy rather than needing a human on every item. This is the autonomous stack, switched on.
What actually moved
before measured · after projected until the live reassess runsBEFORE · GATE SHUT
AFTER · GATE OPEN
The point moves straight up, not right. Autonomy holds at 2.2; the governance that earns it is what rises.
The counterintuitive beat, and the one worth saying out loud: the autonomy number barely moves. What moves is the function’s right to it. You did not make the AI do more. You rebuilt the net so the speed it was already running at became safe. That is the difference between adoption and engineering, on a single screen.
The five hours
Your team didn’t get smaller. Its job got bigger.
AI cut this team’s handling time by more than half. The hours it freed never went back to the business as savings. They went into work the queue had always made impossible.
5 hours the slide never draws · Modeled
What the room hears: Nothing on this slide says where the five hours went, so the board answers that question itself. It is the only honest reading of a bar that stops early, and it is how a productivity win turns into a headcount conversation.
This is the slide that decides whether a productivity win turns into a headcount conversation. A bar that stops early answers a question the board never asked. A bar that stays the same length answers the one they did: what are we getting for it? Same team, same shift, more ground covered.
It is also how the gate opens. People sat at the bottom rung because nobody had an hour to spend there. This function never needed headcount to climb. It needed the hours the AI had already handed back, spent on the capability that earns the autonomy it was running at anyway.
The companion
Autonomous, running, net on.
The diagnostic has now certified the function autonomous. That is the measurement. A companion agent reachable from a messaging channel is that certification, alive: text it an alert and it triages end to end using these very skills, enriches the indicators, checks the phishing playbook, and returns a verdict, with no human touching the individual steps. That is human over the loop, running in your hand.
Because the diagnostic now reads green, the agent is permitted to act. The counterfactual is the point: if the gate were still shut, this same agent would be pinned to assisted, allowed only to suggest a verdict for a human to approve. The gate is the live boundary on what the autonomous agent may do on its own, which is the safety net expressed as policy.
Demo note: the live companion (a self-hosted agent on a messaging channel) is shown in the walkthrough, not on this page.
The point it proves
The dilemma is real, and the gate resolves it. Staying low means the human bottleneck. Rushing high means a thin net. The gate lets you climb toward speed only as fast as you earn the safety, so you stop guessing where to stand.
Engineering, not adoption. Northwind did not climb by using more AI. They climbed by rebuilding the net so the AI they already used became safe. Movement is allocation discipline, not adoption velocity.
Measured, not claimed. The before read is real. The after read is recomputed live. The autonomy dial barely moves; the earned right to it does, and that is visible on screen.
Frameworks in play · CSA AI Controls Matrix (AICM) v1.0.3 · CSA AI Security Maturity Model (AISMM) · CSA AI Consensus Assessments Initiative Questionnaire (AI-CAIQ) v1.0.2 · AI Cyber Maturity Model (AI-CMM) (our model · calibrated to SAE J3016). Northwind Retail is a constructed case, not a client engagement; the organisation is invented and no outcome here was observed at a customer. The before read is measured from that saved run; the after read is produced live by the reassess and shown here as projected until then.