Agentic is a design. Autonomous is a liability question.
The two words are used interchangeably and mean entirely different things. One describes how the work is organized. The other describes who answers for it when it goes wrong. Conflating them is how a security team ends up owning a decision it did not know it had delegated.
An agentic SOC delegates goals rather than tasks: AI agents decide what to investigate next, gather the context they need and propose a course of action, instead of executing a predefined playbook.
An autonomous SOC removes the human from the loop entirely, detection through response. That is a different claim, and it is an accountability claim more than a technical one.
A system can be thoroughly agentic and still stop at an approval gate before irreversible action. That is what responsible implementations look like today, and it is what Vijilan runs: Praxis AI™ correlates, triages and orchestrates at machine speed, and a Vijilan analyst owns the decision at every layer.
The useful test is not how confident the model is. It is whether the action can be undone.
Four questions that decide what may run unsupervised.
None of them is about model accuracy, which is the metric the category is currently marketed on and the least useful of the four.
Is the action reversible?
Enriching an alert, opening a case, gathering context and querying a log are all free to get wrong; you notice and move on. Isolating a production host during a trading window is not. The reversibility of the action, not the confidence of the model, is what should decide whether a human is in the loop.
What is the cost of being wrong, in both directions?
Over-containment has a cost that shows up immediately and lands on the provider. Under-containment has a cost that shows up later and lands on the customer. A system tuned only against the first will quietly drift toward the second, which is why the tuning target matters more than the accuracy figure.
Who is accountable when it is wrong?
This is the question that actually blocks autonomy, and it is not a technical one. A board asking who decided to disable the CFO account at 2am will not accept "the system" as an answer. Until that has a satisfying reply, an approval gate is not a limitation, it is the design.
Can you reconstruct why it acted?
An agent that pursued its own investigation path has to leave that path behind it: what it looked at, what it concluded, what it did next. Without that, the incident review is guesswork and the compliance evidence does not exist.
We do not run an autonomous SOC, and we would be cautious of anyone who says they do.
Not because the models are not good enough. Because the thing standing between today and full autonomy is not capability, it is accountability. When an automated decision isolates the wrong host during a month-end close, somebody has to answer for that, and “the system decided” is not an answer a board accepts.
So the boundary sits at irreversible action on a production estate. Everything up to it runs at machine speed: correlation, enrichment, ranking, context-gathering, the draft timeline. A Vijilan analyst owns detection, escalation and response, and from the Advanced tier executes containment under a runbook the customer approved in advance.
We expect that line to move, in narrow domains, for well-understood actions against clearly defined asset classes. We will say so when it does rather than in advance of it.
Agentic operations, answered without the hedge.
What is an agentic SOC?
A security operations center where AI agents are delegated goals rather than tasks. Instead of executing a predefined playbook, an agent decides what to investigate next, gathers the context it needs, and proposes a course of action. The distinction from ordinary automation is about who chooses the next step.
Is an agentic SOC the same as an autonomous SOC?
No, and conflating them is the central confusion in this category. Agentic describes how the work is organized: agents pursuing goals with their own judgment about the next step. Autonomous describes who is accountable: nobody, because no human is in the loop. A system can be thoroughly agentic and still stop at an approval gate, and that is what responsible implementations look like today.
Does Vijilan run an autonomous SOC?
No, and we would be cautious of anyone who says they do. Praxis AI™ correlates, triages and orchestrates response across every connected source at machine speed, and a Vijilan analyst owns the decision at every layer: detection, escalation and response. We describe that as a boundary rather than a gap we are closing, because the thing preventing full autonomy is accountability rather than capability.
What can safely run without a human?
Broadly, anything reversible. Correlation, enrichment, deduplication, ranking, gathering context, opening and closing cases, querying sources, drafting the timeline. That is a large share of the work and automating it is where the real throughput gain lives. What waits for a person is irreversible action on a production estate.
Is the human approval gate just slowing things down?
Sometimes, and it is worth being honest that the trade is real rather than pretending it is free. The argument for it is that the cases where speed matters most are also the cases where being wrong costs most, and those are correlated rather than independent. A gate on irreversible actions, with everything up to that point already done, is a much smaller delay than it sounds.
How do we evaluate a vendor claiming agentic or autonomous operations?
Four questions. Which specific actions execute without human approval. What the system does when it is uncertain rather than when it is confident. Whether anyone samples what it dismissed, not only what it escalated. And whether you can reconstruct, after the fact, why it did what it did. Vague answers to those four are the finding.
Will this change?
Probably, and in narrow domains first. Well-understood, low-blast-radius actions against clearly defined asset classes are where supervised autonomy becomes reasonable earliest. What will not change soon is anything where the cost of a wrong action is borne by the customer and the accountability sits with a vendor.
Bring the four questions
to every vendor on your shortlist.
Which actions run without approval, what happens when the system is uncertain, who samples what it dismissed, and whether you can reconstruct why it acted. Ask us first if you like.