Internal Agents Map

Security operations agents

Company
Harvey
Approach type
Agent family
Work
Security
Human involvement
Drafts reviewed
Invocation
Scheduled, Interactive
Deployment stage
Deployed
Evidence strength
Detailed primary
Entry reviewed

Purpose

Harvey’s SOC combines independently scheduled reporting, alert-triage and threat-watch agents for its security team.

Check the reviewed sources and claim details.

How it works

Representative workflow: detection engineering and tuning → human-reviewed production-change PRs. Research details

Review telemetry

Daily reporting and hourly triage agents inspect telemetry and escalate critical clusters.

Investigate threats

Threat-watch compares external intelligence with coverage and proposes detections.

Where people stay involved

Each scope pairs its normal attention boundary with supporting evidence. See the supervision definitions for the level mapping and limits.

  • detection engineering and tuning human-reviewed production-change PRs

    Work-product review · Level 3

Catalog interpretation: Level 3 for detection engineering and tuning human-reviewed production-change PRs; human attention boundary: work-product-review.

Observed in 14 May 2026

Implementation details

Model
Not reportedNot documented for this subject in the reviewed source.
Harness
Separate security infrastructure from Spectre.
Sandbox
Not reportedNot documented for this subject in the reviewed source.
Tool access
RunReveal MCP exposes security corpus tools.
Knowledge
ClickHouse security telemetry and threat-model instructions.
Context management
Postgres memory with retention, deduplication and profile-specific injection budgets.
Credentials
Not reportedNot documented for this subject in the reviewed source.
Interfaces
Not reportedNot documented for this subject in the reviewed source.

Validation and failure handling

Review production changes

Data-tested detections and tuning rules become GitHub pull requests for human review.

Reported observations

The catalog records what the sources report, with the scope and the denominator of every figure. A qualification below limits the figure it sits under.

Unreported: The reviewed source does not document this for the named subject.

Lessons

Unreported: The reviewed source does not document this for the named subject.

Sources and research details

Citations link to the original publisher. Each source also keeps a preserved copy in the repository, so a changed or removed page stays checkable.

  1. Building an agentic security operations centerhttps://www.harvey.ai/blog/building-an-agentic-security-operations-centerEngineering blog · First party · Last source verification: 2026-08-31
Question coverage and scope
purpose
Reported
workflow
Reported: Documented use example; no universal platform run is implied.
human involvement
Reported
implementation
Reported
validation
Reported
observations
Unreported: The reviewed source does not document this for the named subject.
lessons
Unreported: The reviewed source does not document this for the named subject.
Research details for every claim on this page
  1. Summary
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  2. Harness
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  3. Knowledge
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  4. Context management
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  5. Tool access
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  6. Review telemetry
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  7. Investigate threats
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  8. Review production changes
    Statement type
    Fact
    Provenance
    Reported
    Confidence
    High
    Confidence reason
    A linked first-party source states the claim.
  9. Operating model assessment
    Statement type
    Inference
    Provenance
    Catalog judgment
    Confidence
    Medium
    Confidence reason
    Harvey explicitly gates every production change through human review, while reports and triage have separate scheduled scopes.
    Observation date
    2026-05-14
Back to agents
Know an internal agent?

Share a resource or public mention, suggest an addition, or correct an existing entry.