What changed, and why it matters to a mid-market buyer
A SOC used to be a human queue. Alerts in, an analyst rota out, a weekly postmortem. The bottleneck was the queue, so the buyer optimised for analyst headcount and time-to-close. That model is collapsing under two pressures at once: alert volumes have grown faster than the talent pool that clears them, and the underwriters writing modern cyber-insurance policies are starting to ask for evidence a human queue simply does not produce.
The agentic SOC is the response: an autonomous triage agent sits in front of the human analyst rota, with explicit guardrails around what it may close on its own and what must escalate. The agent never closes the loop alone — every action writes to the audit log before it writes to a notification, and a reversal is its own row. The mid-market buyer no longer picks between a queue and a tool: they pick a tool that runs the queue and proves it ran it.
The buyer should stop reading "24×7 SOC" and start reading posture
Every managed-security RFP still asks about coverage windows, analyst-to-client ratios, and Mean Time to Acknowledge. Those numbers answer the wrong question. Coverage windows describe when someone is awake; they say nothing about what was actually done. Analyst ratios describe staffing; they describe nothing about how a low-confidence alert was treated at three in the morning. MTTA is the easiest place to game — acknowledge in fifteen minutes, then let the alert rot in a queue for three hours.
Audit posture is the term that replaces those. Posture collapses four questions into one: did the agent act, what did it do, can you prove it, and is the proof readable by someone other than you? A posture that survives an underwriter scrutiny is the same posture that survives your own CISO tracing an incident six months later.
Six questions to put on the procurement spreadsheet
The list below mirrors exactly what already sits on the FAQ and pricing pages — no new claims, no aspirational numbers. Use it as the agenda for the first discovery call.
A walkthrough that grounds the questions in pricing
The same six questions land very differently at the three tiers on the pricing page. Starter answers the underwriter question with an append-only CSV export and a Merkle-anchored log; the named operator above the confidence threshold is the handoff, but without a published SLA. Standard adds the 15-minute acknowledgment SLA on the handoff, two maintenance windows, and exports grouped by containment lineage — the most common fleet shape, designed for teams whose underwriters want a response time they can depend on.
Complete is the tier where posture starts to look like an attestation. Three configurable maintenance windows with staged rollout and optional hold-and-review on risk-tiered patches. A named technician on call during the maintenance windows you declare. A weekly attestation pack that ships alongside the CSV export. The same audit log the customer reads is the audit log the underwriter reads; the export shape is the only thing that differs across the three tiers.
Where this leaves the buyer
A managed-security contract in 2026 should describe posture, not coverage. The buyer should walk away from the discovery call able to answer the same six questions from the same source of truth the vendor will read in three years. If the answers are different on the contract and on the pricing page, those differences are the audit failures waiting to happen.
The reasonable next step is the same regardless of tier: enroll, watch the audit log fill in, and verify the exports match the same claims that earned the signature. The pricing tiers are listed here; the enrollment path is the one that turns posture from a slide into a working system. Detail on the three tiers is on the pricing page.