Skip to content
Illustrative scenario

Not based on a specific customer deployment. The company, figures, decisions, and outcomes below are a constructed example that shows how Intended’s mechanism applies to this kind of problem. They are not measured results from a named customer. Where we publish a real, attributed customer outcome, we will say so explicitly.

← All case studies
Technology

Automating Incident Response with Governed AI Agents

Consider a cybersecurity firm running a 24/7 SOC whose AI agents handle threat detection, alert triage, containment actions, evidence collection, and initial remediation across many enterprise clients.

01 · the challenge

The kind of problem this addresses.

Slow
minutes from alert to containment with manual SOC processes
Bottleneck
P1 incidents delayed by manual approval queues
No chain
containment actions without cryptographic evidence chains for post-incident review

02 · how it works

See the difference.

Threat detected

Lateral movement from compromised endpoint

Alert fires in SIEM

Priority: P1, but enters analyst queue

Analyst reviews (18 min wait)

Queue backlog during off-hours

Manual containment

Analyst isolates host, 38 min total

Evidence collection

Manual, incomplete, no chain of custody

03 · the solution

What they deployed.

  • Installed SecOps domain pack with incident response, threat containment, and forensics intents
  • Pre-authorized P1 containment actions: host isolation, network segmentation, credential rotation
  • P2/P3 containment requires analyst approval with 15-minute SLA escalation
  • Connected CrowdStrike, Splunk, and PagerDuty via Intended connectors
  • Every containment action produces a tamper-evident evidence chain built for chain-of-custody review

04 · implementation

From zero to governed.

Week 1

Map

Catalogued all SOC AI agent actions. Classified 28 incident response intents across detection, containment, and remediation.

Week 2

Configure

Installed SecOps pack. Defined pre-authorization rules for P1 containment, approval workflows for P2/P3, and evidence chain format.

Week 3

Integrate

Connect SIEM, EDR, and ticketing systems. Validate the evidence-chain format with the legal team for chain-of-custody review.

Week 4

Enforce

Enable enforcement. Pre-authorized P1 containment then executes in seconds with a full evidence chain attached.

05 · illustrative outcomes

What this is designed to deliver.

Modeled figures for this scenario — what the workflow above is built to achieve, not measured results from a named customer.

<0s

P1 containment time

Design target for pre-authorized actions

0%

Evidence chain coverage

Tamper-evident, built for chain-of-custody

0%

P1 actions pre-authorized

No manual approval bottleneck

0

Severity tiers

P1 auto, P2/P3 analyst-approved

06 · decision replay

Example decisions, full trace.

Sample decision records that show the shape of the evidence Intended produces. Illustrative, not drawn from a live customer’s logs.

2026-03-15 02:14:33sec.incident.containmentRISK: 74/100ALLOW18ms

Isolate endpoint WS-ACME-4821: lateral movement detected from compromised credentials

Resolved by: Policy: P1 containment pre-authorized (host isolation)

2026-03-15 02:14:34sec.incident.credential-rotationRISK: 68/100ALLOW22ms

Force credential rotation for user jsmith@acme.com: compromised session detected

Resolved by: Policy: P1 credential rotation pre-authorized

2026-03-15 06:33:17sec.incident.containmentRISK: 82/100ESCALATE15ms

Block outbound traffic from subnet 10.4.0.0/24: data exfiltration attempt

Resolved by: SOC Lead (approved subnet isolation in 2m 44s)

2026-03-15 09:18:42sec.forensics.evidence-collectionRISK: 45/100ALLOW31ms

Collect memory dump from server DB-PROD-03 for forensic analysis

Resolved by: Policy: forensic collection auto-approved for active incident

2026-03-15 14:22:08sec.remediation.firewall-changeRISK: 88/100ESCALATE19ms

Update firewall rules to block known C2 IPs across all client environments

Resolved by: Security Director (approved global rule change in 8m 33s)

the takeaway

Automated containment only works if it is accountable. Pre-authorizing P1 actions collapses response time from minutes to seconds, while every action still carries cryptographic proof that it was policy-authorized — the kind of evidence chain a client's legal team can rely on.

Why this pattern matters — not a customer quote.

Start governing AI incident response

Free to start. See every AI decision from day one.

Intended — Intent Verification Infrastructure for Autonomous Agents