What '24×7 SOC' usually means at 200 employees
The phrase '24×7 SOC' appears in nearly every managed-security proposal, and it almost never describes what the buyer imagines. At the price point a 200-person company can justify — typically $30–$60 per endpoint per year on a traditional MSSP contract — it describes a shared analyst pool that is staffed during business hours, a paging rotation that may or may not reach a human before morning, and a weekly report that summarises what the queue held. The buyer signed for coverage; they received coverage _in name_.
The gap is structural, not a matter of analyst quality. A shared pool billing dozens of clients against the same analyst rota cannot give a 200-person company the same response depth it gives a 2,000-person company whose contract funds dedicated resources. The economics of headcount-based coverage punish the mid-market buyer every time — and the buyer rarely finds out until an incident lands at two in the morning and the acknowledgment arrives at nine.
What the agent actually runs at three in the morning
An autonomous triage agent does not sleep or share a rota. The four-station loop — Watch, Patch, Contain, Escalate — runs continuously on every signal the fleet produces, and every action the agent takes writes an audit row before any notification fires. The row is the proof; the notification is the downstream consequence. The order is not a policy — it is a hard property of the append-only Merkle-anchored log.
For a 200-person company, this means the agent is running the same loop at 03:00 that it runs at 11:00. When an EDR signal and an identity-graph anomaly arrive in the same two-minute window, the correlation engine treats them as peers and surfaces one incident, not two. The agent acts on the correlation — quarantining the process, revoking the token — and writes the evidence row before the named operator on the contract is paged. By the time a human reads the notification, the blast radius has already been bounded.
The three tiers in plain English for a 200-person buyer
The tiers on the pricing page describe the same continuous coverage at three depths. The agent is the same agent; the audit log is the same log. What changes is how much the agent is authorised to act on its own, how many maintenance windows the customer declares, and what the export shape looks like for the underwriter.
A normal week — what the 200-person company actually sees
Most weeks the agent closes what it sees without paging anyone. The queue fills with EDR noise — a process that looks suspicious until the correlation engine sees it runs every Tuesday at 22:00 on every laptop in the fleet — and the agent closes those rows without escalation. The audit log fills in regardless; the operator's portal shows a week of closed rows, each with the evidence and the outcome. No alert fatigue, no morning triage queue inherited from the overnight rota.
The export is always there. A Starter customer can pull the CSV at any point; a Standard customer can pull it grouped by containment lineage with the 15-minute SLA on any open row; a Complete customer gets it in the weekly attestation pack that ships to the underwriter's inbox. The same source of truth, three reader shapes.
An incident week — what changes
When an incident lands, the agent's loop does not change — the same four stations run in the same order. What changes is which trigger fires. A containment lineage change, a Complete-tier escalation, an audit anchor divergence, or an identity-graph mutation each fires the cyber-insurance notification trigger, which writes a tagged row and pages the named human on the contract.
The named human receives the page with the audit row already written — they are not arriving at a blank queue and starting triage from scratch. They are reviewing a bounded situation: the agent's actions, the evidence, the blast radius as currently contained, and the governance hold if any action crossed a declared maintenance window. The 15-minute SLA on Standard starts from the moment the row fires the page, not from whenever the overnight analyst checks the queue.
The incident does not change the invoice. There is no surge pricing. The flat per-endpoint subscription is the same at the end of an incident week as it is at the end of a quiet one — that is by design, and it is named on the pricing page.
What this means for the 200-person buyer
A 200-person company shopping for '24×7 coverage' in 2026 is actually shopping for two things at once: a triage agent that runs the queue without headcount, and a named human who is on the contract for the three triggers the agent will not close on its own. Both of those are separate from the analyst pool that staffs the legacy shared rota — and the buyer who conflates the two is the one who finds out the difference at three in the morning.
The reasonable next step is a discovery call to confirm fleet size, the maintenance windows that match the company's change-control policy, and the export shape the underwriter needs at renewal. The tier comparison is on the pricing page; the discovery-call path is on the contact page. The audit log starts filling in from the first enrolled endpoint — the evidence the underwriter reads next year is being written now.