Not based on a specific customer deployment. The company, figures, decisions, and outcomes below are a constructed example that shows how Intended’s mechanism applies to this kind of problem. They are not measured results from a named customer. Where we publish a real, attributed customer outcome, we will say so explicitly.
Automating Incident Response with Governed AI Agents
Consider a cybersecurity firm running a 24/7 SOC whose AI agents handle threat detection, alert triage, containment actions, evidence collection, and initial remediation across many enterprise clients.
01 · the challenge
The kind of problem this addresses.
02 · how it works
See the difference.
Threat detected
Lateral movement from compromised endpoint
Alert fires in SIEM
Priority: P1, but enters analyst queue
Analyst reviews (18 min wait)
Queue backlog during off-hours
Manual containment
Analyst isolates host, 38 min total
Evidence collection
Manual, incomplete, no chain of custody
03 · the solution
What they deployed.
- — Installed SecOps domain pack with incident response, threat containment, and forensics intents
- — Pre-authorized P1 containment actions: host isolation, network segmentation, credential rotation
- — P2/P3 containment requires analyst approval with 15-minute SLA escalation
- — Connected CrowdStrike, Splunk, and PagerDuty via Intended connectors
- — Every containment action produces a tamper-evident evidence chain built for chain-of-custody review
04 · implementation
From zero to governed.
Week 1
Map
Catalogued all SOC AI agent actions. Classified 28 incident response intents across detection, containment, and remediation.
Week 2
Configure
Installed SecOps pack. Defined pre-authorization rules for P1 containment, approval workflows for P2/P3, and evidence chain format.
Week 3
Integrate
Connect SIEM, EDR, and ticketing systems. Validate the evidence-chain format with the legal team for chain-of-custody review.
Week 4
Enforce
Enable enforcement. Pre-authorized P1 containment then executes in seconds with a full evidence chain attached.
05 · illustrative outcomes
What this is designed to deliver.
Modeled figures for this scenario — what the workflow above is built to achieve, not measured results from a named customer.
<0s
P1 containment time
Design target for pre-authorized actions
0%
Evidence chain coverage
Tamper-evident, built for chain-of-custody
0%
P1 actions pre-authorized
No manual approval bottleneck
0
Severity tiers
P1 auto, P2/P3 analyst-approved
06 · decision replay
Example decisions, full trace.
Sample decision records that show the shape of the evidence Intended produces. Illustrative, not drawn from a live customer’s logs.
sec.incident.containmentRISK: 74/100ALLOW18msIsolate endpoint WS-ACME-4821: lateral movement detected from compromised credentials
Resolved by: Policy: P1 containment pre-authorized (host isolation)
sec.incident.credential-rotationRISK: 68/100ALLOW22msForce credential rotation for user jsmith@acme.com: compromised session detected
Resolved by: Policy: P1 credential rotation pre-authorized
sec.incident.containmentRISK: 82/100ESCALATE15msBlock outbound traffic from subnet 10.4.0.0/24: data exfiltration attempt
Resolved by: SOC Lead (approved subnet isolation in 2m 44s)
sec.forensics.evidence-collectionRISK: 45/100ALLOW31msCollect memory dump from server DB-PROD-03 for forensic analysis
Resolved by: Policy: forensic collection auto-approved for active incident
sec.remediation.firewall-changeRISK: 88/100ESCALATE19msUpdate firewall rules to block known C2 IPs across all client environments
Resolved by: Security Director (approved global rule change in 8m 33s)
the takeaway
Automated containment only works if it is accountable. Pre-authorizing P1 actions collapses response time from minutes to seconds, while every action still carries cryptographic proof that it was policy-authorized — the kind of evidence chain a client's legal team can rely on.
Why this pattern matters — not a customer quote.
Start governing AI incident response
Free to start. See every AI decision from day one.