Ask a SOC leader what changed after they turned on agentic triage, and you’ll usually get a quick answer: fewer alerts, faster decisions, maybe a new platform name. Ask what changed on the shift schedule, and the answer usually gets a lot less clear.
Dave Kennedy laid out the what: deterministic work moves to agents, judgment work stays with the analyst, and three new responsibilities show up on the SOC floor. I want to talk about the part that gets less attention: when that work actually happens.
That gap is already showing up. Among security leaders at organizations with more than 1,000 employees, 82% want proactive investigation prioritized over reactive alert response. Only 33% say they actually discover incidents that way (Devo/Wakefield, April 2025).
That is not a technology gap. Plenty of teams have already bought the latest AI software. It is a priority gap.
Everyone selling agentic SOC tooling has a point of view on what the analyst’s job becomes. Far fewer people are talking about how to rebuild the week around that new job.
The alert queue was never just a pile of work. It ran the SOC. It told analysts what mattered next because the top of the queue was always next. It set the pace because a full queue meant move faster, and a cleared backlog meant maybe you could catch up on something else. It showed managers where capacity was. It also made shift change simple because the next team picked up wherever the queue left off.
When an agent takes over the deterministic work, you do not just remove one task. You remove the thing that was organizing the day. Most SOCs have not replaced it yet.
The queue has not fully disappeared, which is part of the problem. 47% of organizations still discover incidents primarily through alerts (Devo/Wakefield, 2025), so the old scheduling logic is still running underneath even where AI triage sits in front of it.
Microsoft describes its own agentic SOC model in a similar way, saying analysts move “from triaging alerts to supervising outcomes.” I like that phrasing because it gets at the real shift. Analysts are not doing less. They are doing more of the work that requires judgment (Lefferts and Weston, Microsoft Security Blog, April 2026). But “supervising outcomes” is a job description. It is not a schedule. It does not tell you what the day looks like.
Buying the technology does not redesign the operating model on its own. The SANS 2025 Threat Hunting Survey found that only 51% of organizations formally measure hunting effectiveness, down from 64% the year before, even while 48% are prioritizing AI and machine learning in hunting tools (SANS, Josh Lemon, March 2025). Investment is going up. Structure is not keeping pace.
In practice, four things need to replace what the queue used to do: protected hunt blocks, AI-output review loops with clear depth, escalation paths for ambiguity, and handoffs that carry reasoning instead of ticket counts.
No two SOCs look exactly alike. Team size, coverage model, customer mix, and tooling all matter. So think of this as a practical starting point, not a schedule to copy and paste.
Rhythm element | Cadence (illustrative) | What it produces | What it replaces |
Hunt block | Two protected hours, twice a week, per analyst, scheduled like an on-call shift | A written hypothesis and a recorded result | Hunting when the queue happens to be quiet |
AI-output review loop | Every shift, depth set by consequence, not a fixed sampling percentage | Agent verdicts confirmed or overturned, with the reason attached | Rubber-stamping, or re-doing the agent's work |
Escalation window | A standing slot per shift plus a named path for ambiguity | A second opinion on the unclear, not just the severe | Escalation routed by ticket severity |
Shift handoff | 15 minutes, structured on reasoning | The next analyst starts where you stopped | Open ticket counts and tool status |
Hunting that gets scheduled happens. Hunting that waits for “when there’s time” usually does not. Unprotected time is exactly what a staffing shortage, customer escalation, or noisy day will eat first.
Put the block on the calendar and protect it the way you would protect an on-call shift. In other operational environments, protected time is not treated as optional. It is part of how the system stays safe and effective. Hunt time needs the same treatment. It also needs an artifact at the end: a written hypothesis and a recorded result, even when the answer is “we ruled this out.”
That output needs somewhere to land, or the block turns into open-ended browsing. Case management is the top unmet capability gap Devo/Wakefield respondents named, at 77% (Devo/Wakefield, 2025). Before you schedule the first hunt block, decide where the hypothesis, evidence, and outcome will live.
AI review does not make analyst attention disappear. It moves it. In a randomized controlled trial of a phishing triage agent, augmented analysts spent 53% more time on the emails the agent flagged as malicious and did not simply rubber-stamp its verdicts. The result was up to 6.5x more true positives per analyst-minute and 77% better verdict accuracy than the control group (Bono, arXiv, November 2025).
That is one task, measured closely. We should be careful about overextending it. But it gives SOC leaders a better starting point than a flat spot-check percentage.
Review depth should follow consequence, not a fixed sample rate. A mixed-methods study of explainable AI in SOCs found that analysts sometimes accepted lower-accuracy outputs when the explanation looked evidence-based, and that they preferred contextual depth over dashboard summaries (Rastogi et al., arXiv, July 2025). That matters because a polished explanation can earn more trust than the underlying accuracy deserves. A uniform 10% spot-check misses that. It treats very different decisions as if they carry the same risk.
Set review depth by consequence. Fully re-derive the cases where being wrong would be expensive, disruptive, or hard to unwind. For lower-risk cases, check the verdict and the evidence trail. Two lanes, stated plainly, used every shift.
Queue-era escalation ran on severity because severity was the main signal a ticket carried. In a judgment-shaped SOC, the case worth escalating is often the one the analyst cannot resolve with confidence, even if the severity looks low. If severity is the only trigger, ambiguity has nowhere to go. And when ambiguity has nowhere to go, it quietly becomes benign.
The faster triage runs, the less time anyone has to question a call before it hardens into a disposition. That makes an explicit ambiguity trigger more necessary, not less.
This is the cheapest fix on the list, and the cost of not fixing it is easy to see. Analysts at 84% of organizations unknowingly re-investigate the same incident multiple times a month, and 60% of those teams do it weekly or more (Devo/Wakefield, 2025). That is not a diligence problem. It is a handoff problem. The handoff passes state: open, closed, assigned. It does not pass reasoning: what I believe, why I believe it, and what would change my mind.
Agentic triage can make that worse if we are not careful, because now two layers of reasoning are at risk during shift change: the agent’s reasoning and the analyst’s judgment about the agent. 85% of analysts already spend substantial time manually gathering and connecting evidence into a case (Devo/Wakefield, 2025). That is the work that gets repeated when the next analyst has to reconstruct the story.
Make the handoff three questions instead of a ticket list: What do I believe? What did I base that on? What would change my mind?
Change the handoff template this week. It is the smallest change on this list and the one with the most immediate payoff.
Time does not stay free. It gets absorbed.
Nothing schedules itself into a vacuum. Without hunt blocks, defined review depth, and a real escalation path, the hours an agent frees up do not automatically become better investigations or more careful review. I have run delivery organizations at scale, and I have seen what happens instead: the open time gets swallowed by whatever is loudest that day.
Meetings. Ad hoc asks. An unstructured backlog nobody scheduled but everybody keeps feeding. The queue at least made that reallocation visible. Nothing replaces it by default.
The evidence suggests many SOCs are still queue-shaped even with AI in place. Fewer than one-third of organizations use AI for automated alert triage, and 36% use it for enrichment (Devo/Wakefield, 2025). The tooling is arriving faster than the operating model is changing.
The tell is simple: analysts start describing their week in terms of what they got through, not what they set out to find. That is the queue still running the schedule after you thought you turned it off.
Redesigning the week is step one, but it will not survive a budget cycle unless the scorecard changes too. Most of the work above creates outcomes the current metrics do not see.
A hunt that finds nothing scores as zero hours of productive work. An overturned AI verdict scores as rework. A handoff that saved the next shift four hours scores as nothing at all.
A rhythm nobody measures is a rhythm that will not survive budget season. Fixing the calendar comes first, but it is not the whole job. The next question is how you grade a job that no longer produces a clean ticket count. That is the harder half of this problem, and it is where SOC leaders need to spend real time next.