M ManySignal

Guide · ManySignal

Building a Lean SOC

A lean SOC is not a small SOC that does less — it is a right-sized SOC that achieves more with fewer analysts by eliminating manual work that software can do better. This guide covers the staffing model, tooling stack, and operating procedures for a three-to-six-person team running enterprise-grade detection and response with ManySignal.

HR Hannah Roth — VP Product, ManySignal
DI David Iwu — Staff Engineer, ManySignal
15 min read Published Jul 3, 2026 Download PDF
01

What lean means in practice

Lean does not mean accepting worse outcomes. It means designing the SOC so that the work that scales poorly with headcount — alert triage, evidence collection, enrichment, ticket creation — is handled by software, and the work that doesn't scale well with software — threat modelling, detection engineering, stakeholder relationships, novel incident judgement — is where analysts spend their time.

A three-person lean SOC running ManySignal should be able to achieve: 90%+ autonomous triage, sub-4-minute MTTV, 100% alert verdict rate, and monthly ATT&CK coverage expansion. These are not aspirational — they are the baseline the platform is designed to deliver.

02

Staffing model for a lean SOC

The lean SOC staffing model has three roles: SecOps lead (strategy, stakeholder management, escalation authority), detection engineer (detection-as-code, coverage gap analysis, tuning), and SOC analyst (case escalations, playbook improvement, tabletop facilitation). Each role is full-time in a team of three; in larger lean SOCs, these functions scale in parallel rather than adding headcount to the triage queue.

On-call coverage is the hardest lean SOC problem. The agentic model reduces but doesn't eliminate after-hours human need. For most organisations, a single on-call analyst with approve-gated authority for high-severity actions, backed by a full autonomous response capability, covers nights and weekends adequately.

Hire for detection engineering skills first. An analyst who can write, test, and tune detections compounds the SOC's capabilities every week. A pure-triage analyst does not.

  • SecOps lead with P1 escalation authority named
  • At least one detection engineer with git and YAML skills
  • On-call rotation defined with approve-gated authority scope
  • Escalation path to legal and executive for P0 incidents documented
03

Tooling stack for a lean SOC

ManySignal handles detection, triage, investigation, response, and reporting — collapsing five tool categories into one platform. The additional tooling a lean SOC needs: an EDR (CrowdStrike, SentinelOne, or Microsoft Defender for Endpoint) for host isolation and process telemetry, an IdP (Okta or Entra ID) for identity response, and a ticketing system (Jira or ServiceNow) for case escalations that require change management.

Avoid adding tools that duplicate ManySignal capabilities. A separate SOAR is redundant — ManySignal's respond agent is the SOAR. A separate threat intel platform that feeds raw feeds is redundant — ManySignal's enrichment resolvers consume threat intel inline.

04

Operating procedures

A lean SOC needs three written procedures: the weekly metrics review (30 minutes, five metrics, tuning tickets created), the monthly detection review (coverage gap analysis, backtest review, deprecated rules archived), and the quarterly tabletop (one scenario per quarter, PIR-derived, response playbook updated afterward).

Everything else should be automated. Alert triage is the agent's job. Weekly report is the report agent's output. Compliance evidence is the case timeline export. The more the SOC relies on written procedures for things software can do, the less lean it is.

05

Scaling the lean SOC

When to add headcount: when the detection engineering backlog exceeds three months of work, when the tabletop programme is running less than quarterly, or when compliance requirements demand dedicated personnel. Not when alert volume increases — that is an autonomy tuning problem, not a staffing problem.

The lean SOC scales its outcomes by expanding the autonomy ladder, not by hiring. Every new action class promoted to supervised-autonomous is equivalent to a part-time analyst in that domain. Measure the staffing equivalent of your autonomy expansions and report it to the CFO.

Key takeaways

  • Lean SOC: software handles triage, enrichment, and reporting; humans handle detection engineering and judgement.
  • Three-person model: SecOps lead, detection engineer, SOC analyst.
  • Hire for detection engineering skills — they compound. Triage skills do not.
  • Tooling stack: ManySignal + EDR + IdP + ticketing. Avoid duplicating ManySignal capabilities.
  • Three written procedures: weekly metrics, monthly detection review, quarterly tabletop.
  • Scale by expanding the autonomy ladder, not by hiring for triage capacity.

Further reading

Frequently asked questions

What is Building a Lean SOC in an agentic SOC?

Building a Lean SOC is part of ManySignal's agentic SOC and MDR platform, where AI agents detect, triage, investigate, and respond to threats with human-governed autonomy.

How does ManySignal handle building a lean soc?

ManySignal grounds building a lean soc in a temporal entity graph and behavioural baselines, so every verdict is backed by auditable evidence rather than opaque scores.

Can ManySignal replace my SOAR or MDR for building a lean soc?

Yes. ManySignal combines detection, triage, investigation, response, and reporting in one platform, and can operate as your MDR or augment an existing SOC team.

How is autonomy governed?

Through an autonomy ladder: recommend-only, approve-gated, and autonomous modes per action class, with dry-run previews, blast-radius limits, and a one-click tenant kill switch.

How fast is time to value?

Declarative connectors and shipped detections typically produce AI agent verdicts on live alerts within days, not quarters — no parsing projects or playbook-building phase.

Is ManySignal available as a managed service?

Yes. Consume ManySignal as MDR with 24/7 coverage and monthly reporting, run it as your in-house agentic SOC, or use it as the platform behind your own MDR practice.

How does ManySignal license the platform?

Pricing scales with protected assets and autonomy tier, not per-GB ingestion or per-alert volume. Starter, Growth, and Enterprise plans are available; MDR providers receive volume discounts for multi-tenant deployments.

Where does our data reside?

By default in AWS us-east-1. Enterprise tenants can pin data to specific AWS regions, deploy self-hosted on their own Kubernetes cluster, or use customer-managed encryption keys (CMK) to retain cryptographic control.

What does the evidence trail contain?

Each verdict stores the full question set, per-question agent answers, confidence weights, source event references, entity graph snapshots, and operator attestation — preserved immutably for the retention period chosen at contract time.

How does ManySignal handle a false-positive alert?

The triage agent auto-closes findings it assesses as false positives with a documented rationale — which rule fired, why the evidence fails to support escalation, and the entity baseline that informed the decision. Auto-closure rates typically reach 85–95% within 90 days as baselines mature.

Continue reading

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.