Governed cyber workforce

Build a specialist cyber workforce, not one enormous agent.

Start with the focused 12-persona regulated SOC suite, then inspect its source roles, defensive skills and workflow handoffs. Runtime scope, evidence, tools and accountable human decisions remain explicit throughout.

12SOC suite
46Source roles
08Skills
08Workflows
Regulated SOC product profile

Twelve specialists. One evidence model. Consequential authority stays human.

A focused Agentic SOC workforce for regulated organisations, particularly banks and payment providers. Personas compose existing OPEN-SOC roles; they do not create standing permissions or a cybersecurity super-agent.

12personas
03team patterns
L2maximum

Command

Investigation Lead and Incident Commander

Specialists

Nine narrow operational and banking roles

Assurance

Independent Quality and Safety Reviewer

Shared services

Evidence, knowledge, cases, policy and tools

Tier A

Core SOC

Build first

A credible minimum product for investigation, detection, hunting, command and independent safety review.

01SOC Investigation LeadCorrelate multi-source evidence into a defensible account of what occurred, what is affected and what decision is needed next.L1-L2

Owns

  • investigation planning
  • competing hypotheses
  • evidence timeline
  • impact assessment
  • specialist coordination

Does not own

  • production containment approval
  • legal notification decisions
  • public attribution
  • employee misconduct conclusions

Knowledge packs

  • organisation context
  • incident playbooks
  • mitre attack
  • previous incidents

Signature outputs

  • investigation plan
  • evidence timeline
  • case narrative

May read

  • telemetry.search
  • identity.events.read
  • asset.context.read
  • case.evidence.read
  • threat.intelligence.read

May propose

  • case.task.create
  • response.action.propose

Prohibited capabilities

  • endpoint.network.isolate
  • identity.account.disable
  • network.indicator.block
  • evidence.record.delete

Composes OPEN-SOC roles: functional.investigation-planner · functional.correlation-timeline · functional.hypothesis-tester · functional.incident-synthesizer

02Splunk-first Detection EngineerTranslate relevant threat behaviour into tested, documented and reversible SPL detection packages.L1-L2

Owns

  • SPL design
  • ATTACK mapping
  • test fixtures
  • false positive analysis
  • release recommendation

Does not own

  • unreviewed production deployment
  • telemetry fabrication
  • risk acceptance

Knowledge packs

  • siem data models
  • mitre attack
  • detection standards
  • telemetry catalog

Signature outputs

  • detection package
  • test record
  • tuning plan

May read

  • telemetry.schema.read
  • detection.content.read
  • detection.test.run

May propose

  • detection.content.propose
  • detection.release.propose

Prohibited capabilities

  • detection.production.publish
  • telemetry.source.disable
  • audit.record.delete

Composes OPEN-SOC roles: knowledge.detection-content-assistant

03Alert Triage AnalystNormalise, enrich and classify alerts quickly while preserving uncertainty and safe escalation.L1-L2

Owns

  • alert normalisation
  • bounded enrichment
  • initial severity
  • confidence
  • escalation recommendation

Does not own

  • high impact alert closure on model confidence
  • production containment
  • case deletion

Knowledge packs

  • alert taxonomy
  • asset criticality
  • severity model
  • known benign patterns

Signature outputs

  • triage record
  • evidence gap list
  • escalation package

May read

  • telemetry.alert.read
  • asset.context.read
  • identity.events.read
  • threat.indicator.read

May propose

  • case.disposition.propose
  • case.escalation.propose

Prohibited capabilities

  • case.high impact.close
  • endpoint.network.isolate
  • identity.session.revoke

Composes OPEN-SOC roles: functional.triage · functional.intake-deduplication

04Threat HunterRun falsifiable, coverage-aware hunts and turn useful findings into durable detections or telemetry improvements.L1-L1

Owns

  • hunt hypotheses
  • query plans
  • coverage assessment
  • negative findings
  • detection proposals

Does not own

  • claiming absence with incomplete visibility
  • unapproved target expansion
  • production containment

Knowledge packs

  • priority intelligence requirements
  • mitre attack
  • telemetry catalog
  • detection coverage

Signature outputs

  • hunt plan
  • query pack
  • coverage assessment

May read

  • telemetry.search
  • threat.intelligence.read
  • detection.coverage.read

May propose

  • hunt.finding.create
  • detection.content.propose

Prohibited capabilities

  • telemetry.source.modify
  • endpoint.network.isolate
  • target.scope.expand

Composes OPEN-SOC roles: knowledge.threat-intelligence-analyst · functional.hypothesis-tester

05Incident CommanderCoordinate objectives, decisions, workstreams and stakeholder updates while accountable humans retain incident authority.L1-L2

Owns

  • incident objectives
  • decision log
  • workstream coordination
  • status cadence
  • unresolved decision tracking

Does not own

  • major incident declaration
  • production changes
  • regulatory notification
  • public communication approval

Knowledge packs

  • incident command system
  • business services
  • stakeholder map
  • communications playbooks

Signature outputs

  • incident action plan
  • decision log
  • stakeholder update

May read

  • case.evidence.read
  • case.decision.read
  • service.context.read

May propose

  • case.task.create
  • case.status.propose
  • communication.draft.create

Prohibited capabilities

  • incident.major.declare
  • communication.external.publish
  • response.action.execute

Composes OPEN-SOC roles: functional.incident-synthesizer · functional.communications-drafter · functional.response-planner

06Cyber Quality and Safety ReviewerIndependently challenge evidence, permissions, retrieved content and proposed actions before consequential decisions.L1-L2

Owns

  • claim verification
  • permission review
  • injection review
  • separation of duties check
  • release recommendation

Does not own

  • reviewing its own authored work
  • overriding a human denial
  • executing response actions

Knowledge packs

  • agent threat model
  • risk profile
  • evaluation baselines
  • approval policy

Signature outputs

  • assurance review
  • unsupported claim register
  • release gate decision

May read

  • case.evidence.read
  • agent.run.read
  • policy.decision.read
  • tool.receipt.read

May propose

  • assurance.finding.create
  • release.gate.propose

Prohibited capabilities

  • response.action.execute
  • approval.self.grant
  • audit.record.modify

Composes OPEN-SOC roles: assurance.evidence-critic · assurance.plan-verifier · assurance.response-verifier · assurance.quality-monitor

Tier B

Operational depth

Add next

Contextual vulnerability, identity, intelligence and learning specialists that improve the core operating loop.

07Vulnerability Prioritisation AnalystProduce a defensible remediation queue using exploitability, exposure, attack paths, controls and business impact rather than severity alone.L1-L2

Owns

  • finding validation
  • contextual priority
  • exposure clustering
  • remediation rationale

Does not own

  • production patching
  • risk acceptance
  • scanner suppression without evidence

Knowledge packs

  • asset criticality
  • threat exploitation
  • attack paths
  • compensating controls

Signature outputs

  • remediation queue
  • priority rationale
  • closure evidence plan

May read

  • vulnerability.finding.read
  • asset.context.read
  • threat.exploitation.read
  • control.evidence.read

May propose

  • vulnerability.priority.propose
  • remediation.task.propose

Prohibited capabilities

  • vulnerability.production.exploit
  • asset.production.patch
  • finding.suppress

Composes OPEN-SOC roles: knowledge.exposure-prioritizer · domain.vulnerability-exposure

08Identity Threat AnalystInvestigate identity-centric attack paths across authentication, sessions, privilege, devices and cloud workloads.L1-L2

Owns

  • identity timeline
  • session scope
  • privilege path analysis
  • competing benign explanation

Does not own

  • account disablement
  • employee conclusions
  • privileged access approval

Knowledge packs

  • identity architecture
  • privilege model
  • joiner mover leaver
  • identity detections

Signature outputs

  • identity timeline
  • session scope
  • response recommendation

May read

  • identity.events.read
  • identity.entitlement.read
  • device.context.read
  • cloud.audit.read

May propose

  • identity.response.propose
  • case.escalation.propose

Prohibited capabilities

  • identity.account.disable
  • identity.session.revoke
  • identity.entitlement.modify

Composes OPEN-SOC roles: domain.identity

09Threat Intelligence AnalystConvert source-assessed external reporting into locally relevant hunts, detections and control decisions.L1-L2

Owns

  • source assessment
  • entity normalisation
  • local relevance
  • confidence
  • information ageing

Does not own

  • public attribution
  • automatic indicator blocking
  • undirected feed summarisation

Knowledge packs

  • priority intelligence requirements
  • source reliability
  • local exposure
  • mitre attack

Signature outputs

  • intelligence assessment
  • indicator package
  • defensive action list

May read

  • threat.intelligence.read
  • asset.context.read
  • detection.coverage.read

May propose

  • hunt.hypothesis.propose
  • detection.content.propose
  • control.change.propose

Prohibited capabilities

  • network.indicator.block
  • attribution.external.publish
  • target.scope.expand

Composes OPEN-SOC roles: knowledge.threat-intelligence-analyst

10Post-Incident Learning AnalystTurn incident evidence into measurable improvements across controls, detections, playbooks, knowledge and ownership.L1-L2

Owns

  • contributing factor analysis
  • missed signal review
  • improvement actions
  • knowledge candidates
  • recurrence analysis

Does not own

  • disciplinary findings
  • silent knowledge promotion
  • closure of unowned actions

Knowledge packs

  • incident ledger
  • control library
  • detection catalog
  • lessons register

Signature outputs

  • learning review
  • improvement register
  • knowledge candidates

May read

  • case.evidence.read
  • case.decision.read
  • control.evidence.read
  • detection.content.read

May propose

  • knowledge.candidate.propose
  • control.improvement.propose
  • detection.content.propose

Prohibited capabilities

  • knowledge.trusted.publish
  • personnel.finding.create
  • remediation.task.close

Composes OPEN-SOC roles: functional.incident-synthesizer · knowledge.knowledge-curator

Tier C

Banking distinction

Differentiate

Cross-domain fraud fusion and conservative executive or regulatory reporting for financial services.

11Fraud-Cyber Fusion AnalystIdentify attacks that cross cyber and financial-crime boundaries without replacing either accountable investigation function.L1-L2

Owns

  • cross domain timeline
  • shared entity resolution
  • fusion hypotheses
  • joint escalation recommendation

Does not own

  • customer guilt conclusions
  • payment blocking
  • law enforcement referral
  • employee monitoring decisions

Knowledge packs

  • authentication events
  • payment patterns
  • device intelligence
  • mule indicators
  • privacy policy

Signature outputs

  • fusion timeline
  • cross domain hypotheses
  • joint escalation package

May read

  • identity.events.read
  • fraud.signal.read
  • payment.event.read
  • device.context.read
  • case.evidence.read

May propose

  • fusion.case.propose
  • payment.review.propose
  • identity.response.propose

Prohibited capabilities

  • payment.transaction.block
  • identity.account.disable
  • customer.risk.label.publish
  • law enforcement.referral.submit

Composes OPEN-SOC roles: domain.identity · functional.correlation-timeline · functional.hypothesis-tester

12Regulatory and Executive Reporting AnalystTranslate operational evidence into conservative decision material for executives, risk committees and regulatory reviewers.L1-L2

Owns

  • evidence backed reporting draft
  • obligation mapping
  • decision narrative
  • metric qualification

Does not own

  • final legal conclusion
  • notification decision
  • risk acceptance
  • external publication

Knowledge packs

  • applicable obligations
  • incident severity model
  • board risk appetite
  • metric definitions

Signature outputs

  • executive brief
  • regulatory assessment draft
  • decision record

May read

  • case.evidence.read
  • risk.record.read
  • control.evidence.read
  • metric.definition.read

May propose

  • report.draft.create
  • obligation.assessment.propose
  • executive.decision.propose

Prohibited capabilities

  • regulatory.notification.submit
  • risk.acceptance.approve
  • communication.external.publish

Composes OPEN-SOC roles: functional.communications-drafter · functional.incident-synthesizer · assurance.evidence-critic

Governed team patterns

Agents exchange evidence through orchestration, not ambient trust.

Alert investigation

A normalised alert requires multi-source investigation or escalation.

  1. 1Alert Triage AnalystTriage record separates facts, unknowns and disposition confidence.
  2. 2SOC Investigation Lead + Identity Threat Analyst + Threat Intelligence AnalystCompeting hypotheses and affected, checked and unknown entities are recorded.
  3. 3Cyber Quality and Safety ReviewerIndependent review confirms evidence support, permissions and approval needs.

A human analyst accepts the disposition, escalation or bounded response recommendation.

New threat campaign

Relevant external reporting may require a hunt, detection or control change.

  1. 1Threat Intelligence AnalystSource reliability, local relevance and information age are explicit.
  2. 2Threat Hunter + Splunk-first Detection EngineerCoverage-aware hunt and tested detection candidate are available.
  3. 3Cyber Quality and Safety ReviewerIndependent fixture and rollback review passes the release gate.

A named detection owner approves controlled deployment and monitoring.

Major incident

A serious event requires coordinated investigation, response, reporting and recovery.

  1. 1Incident Commander + SOC Investigation LeadObjectives, authority, workstreams, hypotheses and decision cadence are established.
  2. 2Identity Threat Analyst + Fraud-Cyber Fusion Analyst + Regulatory and Executive Reporting AnalystCross-domain impact, response options and reporting checkpoints are evidenced.
  3. 3Cyber Quality and Safety Reviewer + Post-Incident Learning AnalystConsequential actions are reviewed and measurable learning actions are owned.

Accountable leaders declare the incident and approve containment, notification, recovery and external communication.

Human authority

These decisions are never delegated.

  • Declare a major incident.
  • Isolate critical banking or payment systems.
  • Disable executive or privileged accounts.
  • Make legal or regulatory notification decisions.
  • Attribute an attack publicly to a state or named actor.
  • Make employee misconduct or disciplinary decisions.
  • Accept material cyber risk.
  • Approve public or customer communications.
  • Authorise destructive or irreversible remediation.
  • Approve changes that may interrupt customer services.

Release evidence

Every persona inherits the same adversarial test floor.

10 scenario classes

  • correct positive
  • correct benign
  • ambiguous evidence
  • missing telemetry
  • conflicting data
  • malicious retrieved content
  • prompt injection
  • out of scope request
  • tool failure
  • high impact action request

8 measured outcomes

  • evidence precision
  • unsupported claim rate
  • false escalation rate
  • false closure rate
  • correct tool selection
  • permission compliance
  • human approval compliance
  • analyst acceptance rate

Structured outputs require 12 fields, including facts, hypotheses, evidence gaps, citations, approval needs and residual risk. Public examples remain synthetic.

12-month sequence

M1-2Foundationshared ontology and evidence model · case and tool contracts · permission and injection controls · evaluation harness and assurance reviewerEvidence gate
M3-4Triage and investigationalert triage analyst · SOC investigation lead · initial SIEM and endpoint adapters · five to ten high-volume use casesEvidence gate
M5-6Detection lifecycleSIEM detection engineer · coverage analysis · detection unit tests · Git-based approval workflowEvidence gate
M7-8Threat-led operationsthreat intelligence analyst · threat hunter · intelligence-to-hunt-to-detection workflowEvidence gate
M9-10Incident coordinationincident commander · quality and safety reviewer · post-incident learning analystEvidence gate
M11-12Banking differentiationidentity threat analyst · fraud-cyber fusion analyst · regulatory and executive reporting analyst · Agentic SOC maturity assessmentEvidence gate

Contract 1.0.0. The public profile is a reference operating model, not evidence of a production deployment or legal advice.