Blog

What 24/7 AI SOC Coverage Actually Looks Like for a 200-Employee Company

A 200-person company rarely has a dedicated SOC analyst — and the legacy '24×7 SOC' it can afford typically means a shared queue someone checks in the morning. Here is what genuine round-the-clock coverage looks like when the triage agent runs the queue and a named human is on the contract, not the rota.

Posted August 21, 2026

What '24×7 SOC' usually means at 200 employees

The phrase '24×7 SOC' appears in nearly every managed-security proposal, and it almost never describes what the buyer imagines. At the price point a 200-person company can justify — typically $30–$60 per endpoint per year on a traditional MSSP contract — it describes a shared analyst pool that is staffed during business hours, a paging rotation that may or may not reach a human before morning, and a weekly report that summarises what the queue held. The buyer signed for coverage; they received coverage _in name_.

The gap is structural, not a matter of analyst quality. A shared pool billing dozens of clients against the same analyst rota cannot give a 200-person company the same response depth it gives a 2,000-person company whose contract funds dedicated resources. The economics of headcount-based coverage punish the mid-market buyer every time — and the buyer rarely finds out until an incident lands at two in the morning and the acknowledgment arrives at nine.

What the agent actually runs at three in the morning

An autonomous triage agent does not sleep or share a rota. The four-station loop — Watch, Patch, Contain, Escalate — runs continuously on every signal the fleet produces, and every action the agent takes writes an audit row before any notification fires. The row is the proof; the notification is the downstream consequence. The order is not a policy — it is a hard property of the append-only Merkle-anchored log.

For a 200-person company, this means the agent is running the same loop at 03:00 that it runs at 11:00. When an EDR signal and an identity-graph anomaly arrive in the same two-minute window, the correlation engine treats them as peers and surfaces one incident, not two. The agent acts on the correlation — quarantining the process, revoking the token — and writes the evidence row before the named operator on the contract is paged. By the time a human reads the notification, the blast radius has already been bounded.

Watch — continuous signal ingest
Endpoint telemetry, identity-graph state, and SaaS audit events enter the same queue regardless of the hour. There is no reduced-coverage window; the correlation engine does not thin the queue at night.
Patch — reversible auto-containment
Process quarantine, token revocation, and egress restriction are applied before the analyst is paged. Each action carries the reversal step in the same row so nothing is a one-way door.
Contain — blast-radius bounding
Where the correlation engine names peer endpoints or identities inside the same lineage, containment extends to those peers in a single incident row — not as a separate ticket the analyst opens at nine.
Escalate — named human on a named trigger
The handoff is defined in the contract, not improvised per incident. Three named triggers route to the named human — confidence threshold, governance review, and cyber-insurance notification. The handoff row records which trigger fired.

The three tiers in plain English for a 200-person buyer

The tiers on the pricing page describe the same continuous coverage at three depths. The agent is the same agent; the audit log is the same log. What changes is how much the agent is authorised to act on its own, how many maintenance windows the customer declares, and what the export shape looks like for the underwriter.

Starter — $10 per endpoint per month
EDR and identity signals, one nightly patch window, append-only audit log available as CSV on demand. The named operator above the confidence threshold is the handoff; no published SLA on the acknowledgment. The right shape for a team whose underwriter wants a log, not a clock.
Standard — $17 per endpoint per month
EDR, identity, and SaaS signals correlated together. Two maintenance windows — nightly and weekend. Reports export by containment lineage; 15-minute acknowledgment SLA on the named-operator handoff. The most common fleet shape for a 200-person company entering a cyber-insurance renewal.
Complete — $25 per endpoint per month
Adds deep SaaS and cloud-control-plane signal, Okta/Entra ID token-graph correlation, three configurable maintenance windows with staged rollout, optional hold-and-review on risk-tiered patches, and a weekly attestation pack for underwriters. Named technician on call during declared windows. The tier for regulated workloads or underwriter-scrutiny renewals.

A normal week — what the 200-person company actually sees

Most weeks the agent closes what it sees without paging anyone. The queue fills with EDR noise — a process that looks suspicious until the correlation engine sees it runs every Tuesday at 22:00 on every laptop in the fleet — and the agent closes those rows without escalation. The audit log fills in regardless; the operator's portal shows a week of closed rows, each with the evidence and the outcome. No alert fatigue, no morning triage queue inherited from the overnight rota.

The export is always there. A Starter customer can pull the CSV at any point; a Standard customer can pull it grouped by containment lineage with the 15-minute SLA on any open row; a Complete customer gets it in the weekly attestation pack that ships to the underwriter's inbox. The same source of truth, three reader shapes.

An incident week — what changes

When an incident lands, the agent's loop does not change — the same four stations run in the same order. What changes is which trigger fires. A containment lineage change, a Complete-tier escalation, an audit anchor divergence, or an identity-graph mutation each fires the cyber-insurance notification trigger, which writes a tagged row and pages the named human on the contract.

The named human receives the page with the audit row already written — they are not arriving at a blank queue and starting triage from scratch. They are reviewing a bounded situation: the agent's actions, the evidence, the blast radius as currently contained, and the governance hold if any action crossed a declared maintenance window. The 15-minute SLA on Standard starts from the moment the row fires the page, not from whenever the overnight analyst checks the queue.

The incident does not change the invoice. There is no surge pricing. The flat per-endpoint subscription is the same at the end of an incident week as it is at the end of a quiet one — that is by design, and it is named on the pricing page.

What this means for the 200-person buyer

A 200-person company shopping for '24×7 coverage' in 2026 is actually shopping for two things at once: a triage agent that runs the queue without headcount, and a named human who is on the contract for the three triggers the agent will not close on its own. Both of those are separate from the analyst pool that staffs the legacy shared rota — and the buyer who conflates the two is the one who finds out the difference at three in the morning.

The reasonable next step is a discovery call to confirm fleet size, the maintenance windows that match the company's change-control policy, and the export shape the underwriter needs at renewal. The tier comparison is on the pricing page; the discovery-call path is on the contact page. The audit log starts filling in from the first enrolled endpoint — the evidence the underwriter reads next year is being written now.

Ready when you are

Posture, on a procurement spreadsheet. The full pricing band is on /pricing.

curtainwall@curtainwallsecurity.com