
Nobody sells your middle
If your SOC runs a SIEM, a SOAR, a vulnerability scanner and an EDR from four different vendors, the gap between them is not a plumbing problem — it is a decision and authorisation problem, and no vendor has an incentive to solve it for you. The design, up front: a language model to read the unnormalised residue between those tools, a deterministic floor it may raise but never lower, an allowlist that authorises rather than describes, an action budget capping how much of the estate can be affected at once, and the containment credential held where the model cannot reach it. Ends on the 03:00 question — do you let it act alone — and on the fact that most organisations already answered by accident.







