Vvanakor
Back to writing
Architecture3 min read

ARGOS: building a SOC agent you would let near production

ARGOSAgentic AIArchitectureDetection

The constraint nobody designs for

Building a SOC agent that can act is easy. Building one you would let near production is not. Most autonomous SOC work treats safety as a later addition — an approval queue, a human in the loop, bolted onto something that was designed to move fast.

ARGOS starts from the opposite assumption. Detection speed and operational safety are co-equal constraints. Neither wins by default. Everything below follows from that one decision.

Identity first, not network first

The entity graph sits in Neo4j and scores risk across six dimensions, including lateral movement paths. Alongside it is a registry for non-human identities — service accounts, workload identities, API principals — scored across five dimensions, with anomaly detection and rotation recommendations.

This ordering is deliberate. In most estates the non-human identities outnumber the humans and nobody owns them. If you model the network first, you spend your time explaining traffic. If you model identity first, you spend it explaining intent.

An agent that can say it does not know

The triage agent has confidence calibration and six abstention pathways, plus a formal auto-close policy. Abstention matters more than accuracy here. An agent that always produces an answer is worse than no agent, because it manufactures confidence that an analyst will then act on.

Guardrails are mechanical, not advisory

Ten forbidden actions. Blast radius controls. Six circuit breakers. A prompt injection scanner in front of it all.

None of that is a prompt asking the model to behave. A constraint you can talk a model out of is not a constraint. These are enforced outside the reasoning loop, which is the only place they mean anything.

Memory that forgets on purpose

Working memory lives in Redis with TTLs. Episodic memory lives in Qdrant, with an explicit decay formula and a ranking function.

An agent that remembers everything forever is an agent whose beliefs you cannot audit. That is the same failure I wrote about in MISC 147 — if a false premise reaches long-term memory and never ages out, every decision after it is downstream of something you can no longer see.

Measuring whether any of it works

Twenty KPIs, expected calibration error, and P50, P95 and P99 latency.

Calibration is the one people skip. An agent that is confident 90 percent of the time and right 60 percent of the time is not a detection system, it is a random number generator with good manners.

Running it

Three deployment tiers. Minimum Viable needs only the Anthropic API, and several examples need no API key at all. Intermediate adds Redis and Qdrant. Full adds Neo4j.

The forty-plus tests run with no API key and no infrastructure. That was a design goal, not a convenience — if the tests need a running stack, nobody runs them.

What I would still call unproven

The governance model holds in the examples. It has not been through a real incident at volume, with a tired analyst at three in the morning deciding whether to trust an abstention. That is the test that matters, and it has not happened yet.

The code is open. If you break it, tell me how.

Back to writing