The SOC is where agent autonomy gets tested first. Exabeam's October release shows both sides
Exabeam added a persistent AI investigation assistant, a Claude Skill Pack and ingestion of AI activity logs. Agents now work inside the SOC and are watched by it.
Listen to this article · 6 min
AI-generated narration of the full article.

Security operations is the enterprise function where AI agents meet the least patience. Analysts are drowning in alerts, so they welcome help. They are also trained to distrust anything they cannot verify, because a wrong conclusion in an investigation has consequences. That combination makes the SOC an early test bed for what bounded autonomy looks like in practice.
Exabeam’s October 2026 release is a useful snapshot because it moves in two directions at once. Agents are moving into the SOC’s own work. And the SOC is starting to watch AI activity across the enterprise as a new kind of signal.
What Exabeam shipped
Exabeam’s October updates span its cloud-native New-Scale Fusion platform and its LogRhythm SIEM.
Agents helping analysts. On New-Scale Fusion, the Exabeam Nova assistant is now a platform-wide sidebar that follows the analyst across screens and keeps context. Exabeam says it automates background context collection, secondary searches and triage assistance during active investigations. A Claude Skill Pack adds prebuilt investigative guidelines for Claude Code so Exabeam Nova can triage the alert queue, prioritize cases and guide investigations through simple commands. A Related Cases feature correlates active and historical cases by shared artifacts and entities.
The SOC watching AI. A new ingestion option normalizes Claude Enterprise activity logs and chat API data into a single timeline, which Exabeam positions as closing AI visibility gaps and establishing behavioral baselines for non-human activity. On LogRhythm, new collectors cover ChatGPT, Google Gemini and GitHub Copilot, alongside community Model Context Protocol server support, an OpenSearch migration and a self-service reporting engine.
Exabeam’s release page does not distinguish general availability from preview for individual features, and it schedules webinars on October 6 and 8. Confirm the status of anything you plan around.
- Alert arrives
- Agent gathers context and runs searches
- Analyst decides
- Containment action
- AI activity logs feed the SIEM
- Agents inside the SOC: Agent gathers context and runs searches · Analyst decides · Containment action
- AI watched by the SOC: AI activity logs feed the SIEM
Agent or AI activityHuman authority
Why the SOC pattern generalizes
Look at what the agent does in Exabeam’s description: it gathers context, runs follow-up searches, assembles related cases and suggests priorities. It does not close incidents, isolate hosts or disable accounts on its own. The analyst stays the decision maker.
That division of labor is the right default for most enterprise agents, not only security ones:
- Autonomy on reading, authority on writing. Let agents collect, search, correlate and draft freely within their permissions. Put a human decision in front of actions that change state.
- Context persistence is a feature and a risk. A sidebar that remembers the investigation saves time. It also accumulates sensitive material, so its retention and access deserve the same review as the case file.
- Skills encode procedure. A skill pack is a written investigation playbook that an agent can follow. That makes the playbook reviewable and versionable, which is better than the procedure living in one senior analyst’s head.
We saw the same pattern in Google’s agents inside code review: agents that work inside an existing control, with deterministic checks and human sign-off, reach production faster than agents that invent a new process.
AI activity is now security telemetry
The second direction may matter more over time. Once employees and agents use assistants at scale, AI usage logs become a security data source like email or endpoint logs: who asked what, which data was involved, which agent took which action, and whether that pattern is normal for that identity.
Two consequences follow. First, the identity work comes first. Behavioral baselines only make sense if each agent has its own identity, which is the point we made in our piece on agent identity as its own IAM discipline. Second, these logs contain prompts and outputs, often with confidential material, so the SIEM inherits a custody responsibility it did not have before. We explored that tension in our analysis of agent observability.
Speed now has a regulatory clock
A listed company already works against a clock: the SEC’s cybersecurity disclosure rules require a Form 8-K within four business days of determining that an incident is material. That clock starts at the materiality determination, and the determination depends on how quickly the investigation produces facts. Agents that gather context faster can shorten that path. They also become part of the record of how the company reached its conclusion, so their steps need to be logged and reviewable.
What to do now
- Draw the line between reading and acting in your SOC, in writing, before turning on agent assistance.
- Review skill packs like runbooks: version them, approve changes, test them against past incidents.
- Bring AI activity into the SIEM for your sanctioned assistants, and decide retention and access for prompt data with legal.
- Give agents their own identities so the SOC can baseline them, and alert on agents acting outside their normal scope.
- Measure the assist, not just adoption: time to first useful context, analyst override rate, cases where the agent’s summary was wrong.
The bottom line
The SOC is showing what mature agent deployment looks like: agents do the reading and the legwork, people keep the authority, and every AI action becomes something the security team can see. Most enterprise agent programs will end up with the same shape. Security teams just got there first because they cannot afford to guess.