← All Netgraph solutions
SOAR & Case ManagementDetect & Respond

Automate the response. Keep the human in the loop.

Netgraph SOAR is native to the platform, code-first, workflow-orchestrated playbooks with a visual canvas, not a bolted-on acquisition. Playbooks trigger from any detection plane, autonomy is graduated by policy-as-code, single, dual or auto approval per action class, and every pending action sits in a durable HITL queue where approving re-invokes the exact tool. Around it: full case management, from alert→case hyperlinks to evidence vault to PICERL checklists that progress themselves.

Native, code-first playbooksSingle / dual / auto approvalDurable HITL queuePICERL auto-progressContainment with deploy receipts

What is SOAR (Security Orchestration, Automation & Response)?

SOAR turns the manual steps after a detection, enrich, decide, contain, notify, document, into orchestrated playbooks, so response takes minutes instead of hours. Netgraph's SOAR is code-first (playbooks live in Git with reviews and tests, not in a drag-and-drop canvas that breaks on upgrade) and policy-gated: each action class is configured for single approval, dual approval, or full autonomy, with a durable human-in-the-loop queue that survives restarts and re-invokes the exact approved action.

What ships in the module

Orchestration, approvals and cases, one connected loop.

01

Code-first playbooks

Workflow-orchestrated playbooks defined as code with a visual canvas on top, native to the platform, triggered from any detection plane: SIEM, EDR, NDR, cloud, UEBA.

02

Graduated autonomy

Policy-as-code decides how much trust each action class earns: single approval, dual approval, or fully automatic. Tighten or loosen the ladder without rewriting a playbook.

03

Durable HITL approvals

Pending actions are persisted at the API boundary, they survive restarts, and approving re-invokes the exact tool. Inline Approve/Reject in the Agent Console, plus dedicated HITL Approvals Runner and Escalation & HITL Queue consoles.

04

Full case management

Alert→case hyperlinks, Case-ID search, default L2 assignee with an on-call picker, evidence-vault attachments with tags, a semantic timeline and audit-to-comments, the whole investigation in one record, exportable as a PDF case report.

05

PICERL checklists

SANS PICERL incident checklists auto-progress as the agent investigation writes back, while preserving every human edit. The methodology tracks itself; the analyst stays in charge.

06

On-call responder directory

A responder directory synced to the knowledge base and Agentic AI, assignment and escalation know who is actually on call.

07

Alert Take-Action menu

Enrich, TIP lookup, runbook, add-to-case, suppress and mark-FP straight from the alert, with a knowledge-base feedback loop so every disposition makes the next one smarter.

08

Deterministic approvals

SOAR playbook approvals update paused runs deterministically in place, the run you approved is the run that continues, not a re-fire.

09

Containment orchestration

Push containment to EDR, firewalls, proxies, AD and zero-trust via enabled integrations, with deploy receipts confirming what actually landed where.

Autonomy you can govern

Approve once. The exact tool runs: nothing else.

Most SOAR approval flows approve an intention; Netgraph approves an invocation. The pending action is persisted at the API boundary with its full parameters, and approval re-invokes precisely that tool call, no drift between what the analyst saw and what executed. The autonomy ladder is policy-as-code, so a containment action can require dual sign-off while an enrichment runs automatically.

  • Per-action-class policy: single, dual or auto, graduated, not all-or-nothing.
  • Queue survives restarts, approvals are durable state, not in-memory hope.
  • Inline Approve/Reject in the Agent Console; dedicated HITL queue consoles for the backlog.
  • Every push to EDR, firewall, proxy, AD or zero-trust returns a deploy receipt.

Functionality map

Module functions at a glance

FunctionWhat it doesWhere it lives
CasesCase records with alert→case links, Case-ID search, evidence vault, semantic timeline, audit-to-comments, PDF report exportSOC ▸ Detect & Respond ▸ Cases
Playbook TriggersWire playbooks to detections from any planeSOC ▸ Detect & Respond ▸ Playbook Triggers
OrchestrateCode-first playbooks with visual canvas; containment pushed via enabled integrations with deploy receiptsSOC ▸ Detect & Respond ▸ Orchestrate
HITL queuesDurable approval queue, HITL Approvals Runner + Escalation & HITL Queue; inline Approve/Reject in the Agent ConsoleOperations ▸ Agentic SOC ▸ HITL queues
Autonomy policyPolicy-as-code: single / dual / auto approval per action classPlaybook + policy definitions
PICERL checklistsSANS-methodology checklists that auto-progress on agent write-back, preserving human editsCase detail ▸ PICERL
Take-Action menuEnrich / TIP / runbook / add-to-case / suppress / mark-FP with a KB feedback loopSOC ▸ Detect ▸ Alerts
On-call directoryResponder directory synced to the knowledge base and Agentic AI; on-call picker for case assignmentCase assignment + knowledge base

Common questions

SOAR & Case Management, asked and answered

How is Netgraph SOAR different from a bolted-on SOAR product?+

Bolted-on SOAR spends most of its playbook steps fetching context from other tools' APIs. Netgraph playbooks read the knowledge graph directly, the host, identity, and blast-radius context is already there, so playbooks are shorter, faster, and far less brittle. MTTR for automated playbooks runs at 15 minutes or less.

Do automated actions run without human approval?+

Only where you configure them to. Every skill carries a side-effect class and a policy: read-only enrichment can be autonomous, while consequential actions (isolate host, disable account) wait in a durable approval queue. Approvals are audited and re-invoke the exact tool call that was reviewed.

Can playbooks survive an audit?+

Yes, playbooks are versioned in Git with PR history, and every execution logs its full decision trace to the hash-chained audit ledger. Our blog post 'SOAR without tears' walks through the approach.

See it live

Trigger a playbook. Approve the exact action.