Alert triage
Investigation Layer
SOC automation
Agentic AI
When analysts can't keep up with low-priority alerts: what AI triage actually fixes
Denis StefanMay 28, 20266 min read
Denis StefanMay 28, 20266 min read

AI Engineer at Arcanna
He builds the interface that lets users design agentic workflows inside Arcanna — the place where a complex investigation gets decomposed into a chain of agents, each with the right tools and guardrails. He spends his time where AI engineering meets the operational reality of production SOCs.
How agentic workflows are built — agent structure, tools, and getting it right in production.
Why static playbooks can't keep up with the branching reality of real investigations.
How to put AI decisions under governance the team — and an auditor — can trust.