Security operations agents
- Company
- Harvey
- Approach type
- Agent family
- Work
- Security
- Human involvement
- Drafts reviewed
- Invocation
- Scheduled, Interactive
- Deployment stage
- Deployed
- Evidence strength
- Detailed primary
- Entry reviewed
Purpose
Harvey’s SOC combines independently scheduled reporting, alert-triage and threat-watch agents for its security team.
How it works
Representative workflow: detection engineering and tuning → human-reviewed production-change PRs. Research details
Daily reporting and hourly triage agents inspect telemetry and escalate critical clusters.
Threat-watch compares external intelligence with coverage and proposes detections.
Where people stay involved
Each scope pairs its normal attention boundary with supporting evidence. See the supervision definitions for the level mapping and limits.
detection engineering and tuning → human-reviewed production-change PRs
Work-product review · Level 3
Catalog interpretation: Level 3 for detection engineering and tuning → human-reviewed production-change PRs; human attention boundary: work-product-review.
Observed in 14 May 2026
Implementation details
- Model
- Not reportedNot documented for this subject in the reviewed source.
- Harness
- Separate security infrastructure from Spectre.
- Sandbox
- Not reportedNot documented for this subject in the reviewed source.
- Tool access
- RunReveal MCP exposes security corpus tools.
- Knowledge
- ClickHouse security telemetry and threat-model instructions.
- Context management
- Postgres memory with retention, deduplication and profile-specific injection budgets.
- Credentials
- Not reportedNot documented for this subject in the reviewed source.
- Interfaces
- Not reportedNot documented for this subject in the reviewed source.
Validation and failure handling
Data-tested detections and tuning rules become GitHub pull requests for human review.
Reported observations
The catalog records what the sources report, with the scope and the denominator of every figure. A qualification below limits the figure it sits under.
Unreported: The reviewed source does not document this for the named subject.
Lessons
Unreported: The reviewed source does not document this for the named subject.
Sources and research details
Citations link to the original publisher. Each source also keeps a preserved copy in the repository, so a changed or removed page stays checkable.
- Building an agentic security operations centerhttps://www.harvey.ai/blog/building-an-agentic-security-operations-center
Question coverage and scope
- purpose
- Reported
- workflow
- Reported: Documented use example; no universal platform run is implied.
- human involvement
- Reported
- implementation
- Reported
- validation
- Reported
- observations
- Unreported: The reviewed source does not document this for the named subject.
- lessons
- Unreported: The reviewed source does not document this for the named subject.
Research details for every claim on this page
- Summary
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- SupportsBuilding an agentic security operations centerEyes Always On; From Threat to Detection; Persistent Memory; Two Systems
- Harness
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- SupportsBuilding an agentic security operations centerEyes Always On; From Threat to Detection; Persistent Memory; Two Systems
- Knowledge
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- SupportsBuilding an agentic security operations centerEyes Always On; From Threat to Detection; Persistent Memory; Two Systems
- Context management
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- SupportsBuilding an agentic security operations centerEyes Always On; From Threat to Detection; Persistent Memory; Two Systems
- Tool access
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- SupportsBuilding an agentic security operations centerEyes Always On; From Threat to Detection; Persistent Memory; Two Systems
- Review telemetry
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- SupportsBuilding an agentic security operations centerEyes Always On; From Threat to Detection; Persistent Memory; Two Systems
- Investigate threats
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- SupportsBuilding an agentic security operations centerEyes Always On; From Threat to Detection; Persistent Memory; Two Systems
- Review production changes
- Statement type
- Fact
- Provenance
- Reported
- Confidence
- High
- Confidence reason
- A linked first-party source states the claim.
- SupportsBuilding an agentic security operations centerEyes Always On; From Threat to Detection; Persistent Memory; Two Systems
- Operating model assessment
- Statement type
- Inference
- Provenance
- Catalog judgment
- Confidence
- Medium
- Confidence reason
- Harvey explicitly gates every production change through human review, while reports and triage have separate scheduled scopes.
- Observation date
- 2026-05-14
- SupportsBuilding an agentic security operations centerFrom Threat to Detection to Tuned Alert: both detection proposals and tuning rules are GitHub PRs for human review