Automate the response. Keep the human in the loop.
Netgraph SOAR is native to the platform — code-first, workflow-orchestrated playbooks with a visual canvas, not a bolted-on acquisition. Playbooks trigger from any detection plane, autonomy is graduated by policy-as-code — single, dual or auto approval per action class — and every pending action sits in a durable HITL queue where approving re-invokes the exact tool. Around it: full case management, from alert→case hyperlinks to evidence vault to PICERL checklists that progress themselves.
What is SOAR (Security Orchestration, Automation & Response)?
SOAR turns the manual steps after a detection — enrich, decide, contain, notify, document — into orchestrated playbooks, so response takes minutes instead of hours. Netgraph's SOAR is code-first (playbooks live in Git with reviews and tests, not in a drag-and-drop canvas that breaks on upgrade) and policy-gated: each action class is configured for single approval, dual approval, or full autonomy, with a durable human-in-the-loop queue that survives restarts and re-invokes the exact approved action.
What ships in the module
Orchestration, approvals and cases — one connected loop.
Autonomy you can govern
Approve once. The exact tool runs — nothing else.
Most SOAR approval flows approve an intention; Netgraph approves an invocation. The pending action is persisted at the API boundary with its full parameters, and approval re-invokes precisely that tool call — no drift between what the analyst saw and what executed. The autonomy ladder is policy-as-code, so a containment action can require dual sign-off while an enrichment runs automatically.
- Per-action-class policy: single, dual or auto — graduated, not all-or-nothing.
- Queue survives restarts — approvals are durable state, not in-memory hope.
- Inline Approve/Reject in the Agent Console; dedicated HITL queue consoles for the backlog.
- Every push to EDR, firewall, proxy, AD or zero-trust returns a deploy receipt.
Functionality map
Module functions at a glance
| Function | What it does | Where it lives |
|---|---|---|
| Cases | Case records with alert→case links, Case-ID search, evidence vault, semantic timeline, audit-to-comments, PDF report export | SOC ▸ Detect & Respond ▸ Cases |
| Playbook Triggers | Wire playbooks to detections from any plane | SOC ▸ Detect & Respond ▸ Playbook Triggers |
| Orchestrate | Code-first playbooks with visual canvas; containment pushed via enabled integrations with deploy receipts | SOC ▸ Detect & Respond ▸ Orchestrate |
| HITL queues | Durable approval queue — HITL Approvals Runner + Escalation & HITL Queue; inline Approve/Reject in the Agent Console | Operations ▸ Agentic SOC ▸ HITL queues |
| Autonomy policy | Policy-as-code: single / dual / auto approval per action class | Playbook + policy definitions |
| PICERL checklists | SANS-methodology checklists that auto-progress on agent write-back, preserving human edits | Case detail ▸ PICERL |
| Take-Action menu | Enrich / TIP / runbook / add-to-case / suppress / mark-FP with a KB feedback loop | SOC ▸ Detect ▸ Alerts |
| On-call directory | Responder directory synced to the knowledge base and Agentic AI; on-call picker for case assignment | Case assignment + knowledge base |
Common questions
SOAR & Case Management — asked and answered
How is Netgraph SOAR different from a bolted-on SOAR product?+
Bolted-on SOAR spends most of its playbook steps fetching context from other tools' APIs. Netgraph playbooks read the knowledge graph directly — the host, identity, and blast-radius context is already there — so playbooks are shorter, faster, and far less brittle. MTTR for automated playbooks runs at 15 minutes or less.
Do automated actions run without human approval?+
Only where you configure them to. Every skill carries a side-effect class and a policy: read-only enrichment can be autonomous, while consequential actions (isolate host, disable account) wait in a durable approval queue. Approvals are audited and re-invoke the exact tool call that was reviewed.
Can playbooks survive an audit?+
Yes — playbooks are versioned in Git with PR history, and every execution logs its full decision trace to the hash-chained audit ledger. Our blog post 'SOAR without tears' walks through the approach.
Works with everything on the graph
Agentic AI SOC
The AI agents investigate and act through the same HITL gate — graduated autonomy governs human and agent alike.
Explore→Threat Intelligence
TIP lookup sits right in the Take-Action menu, and confirmed indicators flow back into orchestrated response.
Explore→EDR / EPP
Isolate, scan and live-response actions execute on the unified endpoint agent — one approval away.
Explore→