For the SOC lead and the CISO

Let your SOC agents act.
Every response runs through your policy.

The agent holds no credential on your EDR, SIEM or identity provider. It proposes; the rule decides.

For the SOC lead and the CISO

Let your SOC agents act. Every response runs through your policy.

The agent holds no credential on your EDR, SIEM or identity provider. It proposes; the rule decides.

Where the pilot stalls

Triage ships in weeks. Then someone asks whether the agent can isolate the host.

A SOC has three layers that decide things. Identity says where the agent may log in. Orchestration says which playbook it was in. Neither says whether this action was entitled to run.

LayerAnswersComponents
DetectionIs something happening?SIEM, EDR, NDR
OrchestrationWhat runs next?SOAR playbooks
IdentityWho may connect to what?IAM, PAM, SSO
AuthorityIs this action, on this target, entitled to run right now?Nobody. Until now, the analyst.

ZIFFER decides whether a proposed action runs. It does not detect anything, it does not make triage more accurate, and it does not replace your SIEM or SOAR.

Where the pilot stalls

Triage ships in weeks. Then someone asks whether the agent can isolate the host.

A SOC has three layers that decide things. Identity says where the agent may log in. Orchestration says which playbook it was in. Neither says whether this action was entitled to run.

  • DetectionIs something happening?SIEM, EDR, NDR
  • OrchestrationWhat runs next?SOAR playbooks
  • IdentityWho may connect to what?IAM, PAM, SSO
  • AuthorityIs this action, on this target, entitled to run right now?Nobody. Until now, the analyst.

ZIFFER decides whether a proposed action runs. It does not detect anything, it does not make triage more accurate, and it does not replace your SIEM or SOAR.

Three stages, one policy

The agent investigates freely. Only your rule lets it respond.

  • Investigate. Every tool call is a proposal. Actions with a fixed shape are catalog entries, and the agent cannot express one outside the catalog.
  • Respond. Reversible and in scope: granted in 41 ms. Irreversible or high impact: held for a quorum of two named humans, who sign the exact bytes that will run. No rule: refused.
  • Prove. Every outcome, refusals included, leaves a signed receipt: the alert, the policy version, who approved, what ran. That receipt is the decision record your auditor asks for.

Three stages, one policy

The agent investigates freely. Only your rule lets it respond.

  • Investigate. Every tool call is a proposal. Actions with a fixed shape are catalog entries, and the agent cannot express one outside the catalog.
  • Respond. Reversible and in scope: granted in 41 ms. Irreversible or high impact: held for a quorum of two named humans, who sign the exact bytes that will run. No rule: refused.
  • Prove. Every outcome, refusals included, leaves a signed receipt: the alert, the policy version, who approved, what ran. That receipt is the decision record your auditor asks for.

On a real shift

The rule decides, not the model.

An agent fooled by a poisoned ticket and an agent that is right every time meet the same table.

ProposalTargetGradeOutcome
isolate_hostTest workstationLOW✓ granted · 41 ms
isolate_hostProduction app serverHIGH■ held · 2-of-2 on-shift approvers
isolate_hostDomain controllerno rule✕ refused · a human does it from the console, as today
block_indicatorPerimeter firewall, IP not on an allowlistLOW✓ granted
block_indicatorPerimeter firewall, IP on the partner allowlistHIGH■ held · 2-of-2
disable_userStandard account, confirmed credential theftHIGH■ held · 2-of-2
revoke_sessionsStandard account, within your hourly boundLOW✓ granted
revoke_sessionsAdmin or executive accountHIGH■ held · 2-of-2
delete_logsAnyno rule✕ refused · on the record

LOW is a decision you own. Whatever you grade LOW, you have accepted that the agent may do it on a wrong reading of the alert. Grade LOW what you can undo, bound it per target class and per hour, and let the receipts tell you when to widen it.

What changes on the floor

Today, propose-onlyWith an authority layer
The agent triages in seconds and writes a recommendation. An analyst opens the EDR console and isolates the host, opens the firewall console and blocks the IP, opens the identity provider and revokes the sessions, then documents what they did.The same recommendation is a set of proposals. Those your policy grades LOW run as they are proposed. Those graded HIGH are held for the on-shift approvers to sign. Those with no rule are refused and recorded.
The time saved at triage is spent again at execution. The pilot shows a better analyst, not a faster SOC.The analyst reviews outcomes, not a queue.

Two numbers move, and both are measured in your SOC: the share of response actions that no longer pass through a human keyboard, and the time from detection to the first containment action. A third stays flat by design, at zero: irreversible actions taken without a named human signing.

On a real shift

The rule decides, not the model.

An agent fooled by a poisoned ticket and an agent that is right every time meet the same table.

  • isolate_hostTest workstationLOW ✓ granted · 41 ms
  • isolate_hostProduction app serverHIGH ■ held · 2-of-2 on-shift approvers
  • isolate_hostDomain controllerno rule ✕ refused · a human does it from the console, as today
  • block_indicatorPerimeter firewall, IP not on an allowlistLOW ✓ granted
  • block_indicatorPerimeter firewall, IP on the partner allowlistHIGH ■ held · 2-of-2
  • disable_userStandard account, confirmed credential theftHIGH ■ held · 2-of-2
  • revoke_sessionsStandard account, within your hourly boundLOW ✓ granted
  • revoke_sessionsAdmin or executive accountHIGH ■ held · 2-of-2
  • delete_logsAnyno rule ✕ refused · on the record

LOW is a decision you own. Whatever you grade LOW, you have accepted that the agent may do it on a wrong reading of the alert. Grade LOW what you can undo, bound it per target class and per hour, and let the receipts tell you when to widen it.

What changes on the floor

  • Today, propose-onlyThe agent triages in seconds and writes a recommendation. An analyst opens the EDR console and isolates the host, opens the firewall console and blocks the IP, opens the identity provider and revokes the sessions, then documents what they did.With an authority layerThe same recommendation is a set of proposals. Those your policy grades LOW run as they are proposed. Those graded HIGH are held for the on-shift approvers to sign. Those with no rule are refused and recorded.
  • Today, propose-onlyThe time saved at triage is spent again at execution. The pilot shows a better analyst, not a faster SOC.With an authority layerThe analyst reviews outcomes, not a queue.

Two numbers move, and both are measured in your SOC: the share of response actions that no longer pass through a human keyboard, and the time from detection to the first containment action. A third stays flat by design, at zero: irreversible actions taken without a named human signing.

Fits the stack you already run.

Your agents, your orchestrators and your systems stay where they are. What changes is who holds the credential.

Through MCP, ZIFFER publishes your action catalog as the agent's tools. One SDK call works too, and so does plain HTTPS.

any modelMistral, OpenAI, Anthropic, or an open-weight model on your own hardware. The agent, the model and the framework do not change.
any orchestratorXSOAR, Splunk SOAR, Tines and Torq keep their playbooks. ZIFFER governs what is allowed to run across every agent that reaches your systems through ZIFFER.
any systemEDR, SIEM, firewall, identity provider, ticketing: each gets one scoped credential that only ZIFFER can use. Your systems accept automated response actions only from ZIFFER's identity.

The condition: ZIFFER covers an agent only where that agent holds no credential of its own. An agent built with an EDR API key in a config file is outside the wall until that key is revoked. Your analysts keep their consoles and their own accounts.

Fits the stack you already run.

Your agents, your orchestrators and your systems stay where they are. What changes is who holds the credential.

Through MCP, ZIFFER publishes your action catalog as the agent's tools. One SDK call works too, and so does plain HTTPS.

any modelMistral, OpenAI, Anthropic, or an open-weight model on your own hardware. The agent, the model and the framework do not change.
any orchestratorXSOAR, Splunk SOAR, Tines and Torq keep their playbooks. ZIFFER governs what is allowed to run across every agent that reaches your systems through ZIFFER.
any systemEDR, SIEM, firewall, identity provider, ticketing: each gets one scoped credential that only ZIFFER can use. Your systems accept automated response actions only from ZIFFER's identity.

The condition: ZIFFER covers an agent only where that agent holds no credential of its own. An agent built with an EDR API key in a config file is outside the wall until that key is revoked. Your analysts keep their consoles and their own accounts.

What you hand someone

What the SOC lead reports. What the auditor asks for. One record answers both.

Per shift, upward

  • Actions proposed, granted, held and refused
  • Actions executed outside policy: zero, by construction
  • Actions executed inside policy that were wrong: counted, with the receipt that shows which rule let them through
  • Time from grant to execution on granted actions
  • Approver latency on held actions, and holds that expired unsigned

After the incident, to the auditor

  • What response actions were taken, when, by which identity, and who approved
  • Every refusal on the record: an injected instruction that tried to delete backups is evidence, not noise
  • The policy version each action was graded against
  • Dual authorization, the auditor's word for our quorum of two named humans
  • Non-repudiation: a signed receipt behind every number, not a log line an admin can edit

Today that answer is assembled from SOAR history, EDR audit logs and chat threads. A ZIFFER receipt carries all of it for every agent action, in a ledger your own admin cannot rewrite once a record is anchored. Same published clauses as the home page checklist: AC-3(2) for dual authorization, AU-10 for non-repudiation.

What you hand someone

What the SOC lead reports. What the auditor asks for. One record answers both.

Per shift, upward

  • Actions proposed, granted, held and refused
  • Actions executed outside policy: zero, by construction
  • Actions executed inside policy that were wrong: counted, with the receipt that shows which rule let them through
  • Time from grant to execution on granted actions
  • Approver latency on held actions, and holds that expired unsigned

After the incident, to the auditor

  • What response actions were taken, when, by which identity, and who approved
  • Every refusal on the record: an injected instruction that tried to delete backups is evidence, not noise
  • The policy version each action was graded against
  • Dual authorization, the auditor's word for our quorum of two named humans
  • Non-repudiation: a signed receipt behind every number, not a log line an admin can edit

Today that answer is assembled from SOAR history, EDR audit logs and chat threads. A ZIFFER receipt carries all of it for every agent action, in a ledger your own admin cannot rewrite once a record is anchored. Same published clauses as the home page checklist: AC-3(2) for dual authorization, AU-10 for non-repudiation.

SOC objections

What the SOC lead asks before the first automated response.

Our EDR already auto-isolates on high-confidence detections.

Keep it. That path is triggered by your detection rules on your telemetry. ZIFFER sits on the path where an LLM agent, having read text you do not control, proposes the same action. Same outcome, different trigger, different authorization problem.

Our SOAR already has approval steps.

It governs its own playbooks. It does not see the agent that calls the EDR API directly, the copilot in your ticketing tool, or the next agent someone ships. Policy has to sit where every agent's actions pass, or it is a policy for one tool.

Holding actions for two humans kills response time at 3 a.m.

Enrichment, revoking a standard user's sessions and blocking an unknown IP are the actions you grade LOW, and those run in milliseconds. Only actions nobody can take back are held. The quorum is a role: any two of your named on-shift approvers. A hold that nobody signs expires and is recorded as such. It never silently becomes a grant.

We will keep the agent in propose-only mode for now.

That is the state every pilot is in today, and it is where the return stops. The review tells you which response actions could safely be LOW tomorrow, which ones your policy would hold, and which ones no rule should ever cover.

We will wait for our SOAR vendor to ship this.

They will ship it for their playbooks. Ask them whether it covers agents they do not orchestrate, and whether the receipt can be verified without access to their console.

SOC objections

What the SOC lead asks before the first automated response.

Our EDR already auto-isolates on high-confidence detections.

Keep it. That path is triggered by your detection rules on your telemetry. ZIFFER sits on the path where an LLM agent, having read text you do not control, proposes the same action. Same outcome, different trigger, different authorization problem.

Our SOAR already has approval steps.

It governs its own playbooks. It does not see the agent that calls the EDR API directly, the copilot in your ticketing tool, or the next agent someone ships. Policy has to sit where every agent's actions pass, or it is a policy for one tool.

Holding actions for two humans kills response time at 3 a.m.

Enrichment, revoking a standard user's sessions and blocking an unknown IP are the actions you grade LOW, and those run in milliseconds. Only actions nobody can take back are held. The quorum is a role: any two of your named on-shift approvers. A hold that nobody signs expires and is recorded as such. It never silently becomes a grant.

We will keep the agent in propose-only mode for now.

That is the state every pilot is in today, and it is where the return stops. The review tells you which response actions could safely be LOW tomorrow, which ones your policy would hold, and which ones no rule should ever cover.

We will wait for our SOAR vendor to ship this.

They will ship it for their playbooks. Ask them whether it covers agents they do not orchestrate, and whether the receipt can be verified without access to their console.

Keep the analyst. Remove the credential.

Thirty minutes with your SOC lead. You leave with your response actions graded LOW, HIGH or refused, and the sample receipt your auditor would receive. If propose-only is enough today, the memo says so.

Onboarding within 48 hours · open spec · verify before you pay

Keep the analyst. Remove the credential.

Thirty minutes with your SOC lead. You leave with your response actions graded LOW, HIGH or refused, and the sample receipt your auditor would receive. If propose-only is enough today, the memo says so.

Onboarding within 48 hours · open spec · verify before you pay