← All Netgraph solutions
SOAR & Case ManagementDetect & Respond

Automate the response. Keep the human in the loop.

Netgraph SOAR is native to the platform — code-first, workflow-orchestrated playbooks with a visual canvas, not a bolted-on acquisition. Playbooks trigger from any detection plane, autonomy is graduated by policy-as-code — single, dual or auto approval per action class — and every pending action sits in a durable HITL queue where approving re-invokes the exact tool. Around it: full case management, from alert→case hyperlinks to evidence vault to PICERL checklists that progress themselves.

Native, code-first playbooksSingle / dual / auto approvalDurable HITL queuePICERL auto-progressContainment with deploy receipts

What is SOAR (Security Orchestration, Automation & Response)?

SOAR turns the manual steps after a detection — enrich, decide, contain, notify, document — into orchestrated playbooks, so response takes minutes instead of hours. Netgraph's SOAR is code-first (playbooks live in Git with reviews and tests, not in a drag-and-drop canvas that breaks on upgrade) and policy-gated: each action class is configured for single approval, dual approval, or full autonomy, with a durable human-in-the-loop queue that survives restarts and re-invokes the exact approved action.

What ships in the module

Orchestration, approvals and cases — one connected loop.

01

Code-first playbooks

Workflow-orchestrated playbooks defined as code with a visual canvas on top — native to the platform, triggered from any detection plane: SIEM, EDR, NDR, cloud, UEBA.

02

Graduated autonomy

Policy-as-code decides how much trust each action class earns: single approval, dual approval, or fully automatic. Tighten or loosen the ladder without rewriting a playbook.

03

Durable HITL approvals

Pending actions are persisted at the API boundary — they survive restarts — and approving re-invokes the exact tool. Inline Approve/Reject in the Agent Console, plus dedicated HITL Approvals Runner and Escalation & HITL Queue consoles.

04

Full case management

Alert→case hyperlinks, Case-ID search, default L2 assignee with an on-call picker, evidence-vault attachments with tags, a semantic timeline and audit-to-comments — the whole investigation in one record, exportable as a PDF case report.

05

PICERL checklists

SANS PICERL incident checklists auto-progress as the agent investigation writes back — while preserving every human edit. The methodology tracks itself; the analyst stays in charge.

06

On-call responder directory

A responder directory synced to the knowledge base and Agentic AI — assignment and escalation know who is actually on call.

07

Alert Take-Action menu

Enrich, TIP lookup, runbook, add-to-case, suppress and mark-FP straight from the alert — with a knowledge-base feedback loop so every disposition makes the next one smarter.

08

Deterministic approvals

SOAR playbook approvals update paused runs deterministically in place — the run you approved is the run that continues, not a re-fire.

09

Containment orchestration

Push containment to EDR, firewalls, proxies, AD and zero-trust via enabled integrations — with deploy receipts confirming what actually landed where.

Autonomy you can govern

Approve once. The exact tool runs — nothing else.

Most SOAR approval flows approve an intention; Netgraph approves an invocation. The pending action is persisted at the API boundary with its full parameters, and approval re-invokes precisely that tool call — no drift between what the analyst saw and what executed. The autonomy ladder is policy-as-code, so a containment action can require dual sign-off while an enrichment runs automatically.

  • Per-action-class policy: single, dual or auto — graduated, not all-or-nothing.
  • Queue survives restarts — approvals are durable state, not in-memory hope.
  • Inline Approve/Reject in the Agent Console; dedicated HITL queue consoles for the backlog.
  • Every push to EDR, firewall, proxy, AD or zero-trust returns a deploy receipt.

Functionality map

Module functions at a glance

FunctionWhat it doesWhere it lives
CasesCase records with alert→case links, Case-ID search, evidence vault, semantic timeline, audit-to-comments, PDF report exportSOC ▸ Detect & Respond ▸ Cases
Playbook TriggersWire playbooks to detections from any planeSOC ▸ Detect & Respond ▸ Playbook Triggers
OrchestrateCode-first playbooks with visual canvas; containment pushed via enabled integrations with deploy receiptsSOC ▸ Detect & Respond ▸ Orchestrate
HITL queuesDurable approval queue — HITL Approvals Runner + Escalation & HITL Queue; inline Approve/Reject in the Agent ConsoleOperations ▸ Agentic SOC ▸ HITL queues
Autonomy policyPolicy-as-code: single / dual / auto approval per action classPlaybook + policy definitions
PICERL checklistsSANS-methodology checklists that auto-progress on agent write-back, preserving human editsCase detail ▸ PICERL
Take-Action menuEnrich / TIP / runbook / add-to-case / suppress / mark-FP with a KB feedback loopSOC ▸ Detect ▸ Alerts
On-call directoryResponder directory synced to the knowledge base and Agentic AI; on-call picker for case assignmentCase assignment + knowledge base

Common questions

SOAR & Case Management — asked and answered

How is Netgraph SOAR different from a bolted-on SOAR product?+

Bolted-on SOAR spends most of its playbook steps fetching context from other tools' APIs. Netgraph playbooks read the knowledge graph directly — the host, identity, and blast-radius context is already there — so playbooks are shorter, faster, and far less brittle. MTTR for automated playbooks runs at 15 minutes or less.

Do automated actions run without human approval?+

Only where you configure them to. Every skill carries a side-effect class and a policy: read-only enrichment can be autonomous, while consequential actions (isolate host, disable account) wait in a durable approval queue. Approvals are audited and re-invoke the exact tool call that was reviewed.

Can playbooks survive an audit?+

Yes — playbooks are versioned in Git with PR history, and every execution logs its full decision trace to the hash-chained audit ledger. Our blog post 'SOAR without tears' walks through the approach.

See it live

Trigger a playbook. Approve the exact action.