Why the operating model matters more than the tooling
This is a composite of how a Sphere™-powered SOC is designed to operate. It is not a customer scenario, and no figures below should be read as a specific customer's results. It is the reference operating model the platform is built to enable, assembled from how the underlying capabilities are meant to work together across a shift.
Most vendor demonstrations show a single detection or a single automated response. They rarely show what a full shift looks like when reasoning, evidence, and governance are combined across thousands of events. That gap is why buyers keep asking the same question: what does a day actually look like. The answer matters because it changes how a security leader plans headcount, defines escalation policy, and reports risk upward, not just how the product behaves during a demo.
The rest of this piece walks through the architecture that makes the model possible, the state of the SOC before the shift starts, six moments across a twelve-hour window, the metrics that leadership actually tracks, and the governance controls that keep automation inside defined limits.
The baseline architecture
The operating model rests on three layers working together, not on a single automation script bolted onto an existing SIEM.
- Data lake: telemetry from endpoint, identity, network, cloud, and application sources is normalised into a single evidentiary record, so an incident narrative can reference one consistent timeline rather than five disconnected consoles.
- Agent fabric: AuraXP™ agents perform correlation, enrichment, hypothesis testing, and response drafting continuously, operating on the data lake rather than on isolated alert streams.
- Governance envelope: AirWatch™ defines what agents may do autonomously, what requires pre-authorisation, and what must always route to a human, and it logs the reasoning behind every decision the agents make.
Before the shift starts
In a conventional SOC, a shift begins with a queue: hundreds or thousands of undifferentiated alerts, a handover note of variable quality, and an on-call rotation that exists because nobody trusts the queue to sort itself overnight.
In the reference model, the shift begins differently. Two on-shift analysts, one shift lead, and an on-call responder are on rotation, the same staffing shape as many mid-sized SOCs. What differs is what greets them. Overnight, the platform processed roughly 2,300 candidate incidents across the estate. Twenty-one required human review. None were escalated beyond the shift lead. That distribution, not the raw alert count, is the point of the model: coverage does not collapse into either an unmanageable queue or blind automation.
07:00, Overnight review
The shift lead opens the overnight summary. It is not an alert queue. It is a set of reasoned narratives: what happened, what the agent fabric did, why it did it, and what remains open. Each narrative links directly to the underlying evidence trail in the data lake, so nothing requires reconstruction.
Two narratives are flagged for review, not because the reasoning was wrong, but because the proposed containment step exceeded the automatic-authorisation threshold defined in policy. The lead approves one action and adjusts the other before both close. The review takes minutes, not hours, because the reasoning is already written down.
09:40, Credential misuse, two-stage escalation
A finance user's session shows unusual data access from a corporate device. A conventional UEBA rule would fire immediately. The AI UEBA capability inside Sphere absorbs the deviation, correlates it against a calendar entry indicating a quarterly close, and downgrades the signal. No ticket is created, but the reasoning is logged for later audit.
Ninety seconds later, the same device attempts to open a signed but unusual binary. The picture changes. AuraXP™ opens an investigation, pulls process lineage from the endpoint, checks the binary hash against threat intelligence, and finds a match against enrichment ingested in the previous 24 hours. The device is contained within the pre-authorised policy envelope, and the user is notified automatically. An approved narrative lands in the shift lead's queue in under two minutes from first anomaly to closed containment.
12:15, A supply-chain alert with ambiguous blast radius
A vendor notifies customers of a compromised software update mid-morning. Rather than a manual sweep across asset inventories, an analyst asks the platform to identify every host that received the affected package version in the last 30 days. The agent fabric queries the data lake, cross-references patch and deployment records, and returns a scoped list within minutes, along with a proposed isolation plan for hosts showing anomalous outbound connections.
Because full network isolation sits above the automatic-authorisation threshold for production hosts, the plan routes to the shift lead rather than executing outright. She approves isolation for the three hosts showing genuine anomalies and declines it for the rest, avoiding unnecessary disruption to unaffected systems. The decision and its rationale are recorded in the same evidence trail.
14:00, Threat hunt, not query-writing
A Tier 2 analyst wants to hunt for a technique surfaced in a fresh vendor advisory. In a conventional SOC this becomes a query-writing exercise across multiple tools. In the reference model it is a natural-language request: show evidence of DLL sideloading via signed Adobe binaries across the estate in the last 14 days. The autonomous threat hunting capability translates the request, executes it across the data lake, and returns ranked findings with severity scoring attached, ready for triage rather than raw data dumps.
16:45, An OT-adjacent anomaly, deliberately slow
Where operational technology sits within scope, the model treats it with more caution, not less. A protocol-level anomaly appears on a segment bridging IT and OT networks. The agent fabric flags it immediately but does not attempt any containment action on its own. OT environments carry safety and availability constraints that sit outside the platform's automatic-authorisation envelope by design.
Instead, the platform assembles the evidence, proposes two possible explanations, and routes the decision to the on-call responder with OT familiarity. This is a deliberate governance choice: certain classes of asset are configured to always require a human decision, regardless of confidence score.
19:00, Handover
The shift ends with a single-page brief generated automatically from the day's decisions. It reads like an incident report because it functions as one: what the platform decided, why, what it acted on, and what remains open, including the OT anomaly still awaiting a decision. The next shift starts with context, not archaeology.
What analysts stop doing, and what they start doing
The shift described above is not the removal of analyst judgment. It is a redistribution of where that judgment gets applied.
- Stop: writing and maintaining correlation rules by hand, pivoting across five consoles to reconstruct a timeline, and triaging hundreds of low-fidelity alerts to find the handful that matter.
- Start: reviewing agent decisions that sit at or above the authorisation threshold, tuning policy as the environment and threat landscape change, and handling the genuinely ambiguous cases that require context the platform does not have.
- Start: closing the loop on reversed or corrected decisions, so the agent fabric's future reasoning reflects what was actually right, not just what was statistically likely.
The metrics leadership actually watches
Alert volume and mean-time-to-detect remain useful, but they do not describe whether the operating model is behaving as intended. Security leaders running this model track a different set of indicators.
- Approved-narratives ratio: the proportion of agent-generated narratives approved without modification versus those adjusted or rejected, tracked over time as a proxy for reasoning quality.
- Agent-decision reversal rate: how often a human overturns an automated or semi-automated decision after the fact, watched closely for any upward drift.
- Analyst time distribution: the split between review and policy work versus manual investigation, used to confirm that effort is actually moving upward rather than simply shrinking.
- Mean-time-to-narrative: how long it takes from first signal to a reviewable, evidence-backed narrative, which is a more honest measure of SOC speed than time-to-detect alone.
How the governance envelope prevents runaway automation
None of the above works without limits that are enforced rather than assumed. AirWatch™ defines three tiers of action: fully autonomous within policy, pre-authorised with human notification, and always requiring explicit human sign-off. Every agent decision, at any tier, carries a logged reason and an evidence chain, so nothing is a black box after the fact.
Thresholds are not static. They are set by security leadership, reviewed on a cadence, and tightened or loosened based on observed reversal rates and incident outcomes, not on vendor defaults.
What this means for staffing and coverage
The team above ships the same coverage with fewer people, or the same people with materially wider coverage. That tradeoff is a policy choice made by security leadership, not a headcount outcome forced by the platform. Effort scales with policy complexity and the volume of genuinely ambiguous cases, not with raw alert volume, which is the structural difference this operating model is built to produce.
Frequently asked questions
How many analysts does an AI SOC need?
It depends on the coverage envelope, but the model scales differently. Analyst effort moves from linear-with-alert-volume to linear-with-policy-complexity and ambiguous-case-volume. Most Sphere-powered SOCs redeploy analyst time rather than reduce headcount outright.
Does the platform ever act without human approval?
Only within the policy envelope defined by security leadership. Low-risk, well-understood actions can execute autonomously; higher-impact actions require pre-authorisation or explicit sign-off. The AirWatch™ governance layer enforces the rules and records the reasoning behind every action.
What happens when the platform is wrong?
Every agent decision carries an evidence chain and a stated reason. Analysts can reverse containment actions, mark a decision as incorrect, and that feedback is incorporated into the agent fabric's subsequent reasoning, which is what the reversal-rate metric is designed to track over time.
How does this model handle operational technology or safety-critical assets?
Asset classes with safety or availability sensitivity can be configured to always require human decision, regardless of the platform's confidence score. The governance envelope treats OT and similar segments with deliberately narrower autonomy than standard IT assets.
Is this a real customer's SOC?
No. This is a composite operating model built from how Sphere's underlying capabilities, the data lake, the AuraXP™ agent fabric, and AirWatch™ governance, are designed to function together across a shift. It is intended to describe the model, not report specific customer outcomes.


