Source: https://internal-agents.com/agents/harvey-security-operations

# Harvey — Security operations agents

Harvey’s SOC combines independently scheduled reporting, alert-triage and threat-watch agents for its security team.

- Company: [Harvey](https://internal-agents.com/organizations/harvey)
- Collection: Agents
- Approach type: Agent family
- Deployment stage: Deployed
- Autonomy: Drafts reviewed
- Evidence strength: Detailed primary
- Status: Internal
- First reported year: 2026
- Work: Security
- Invocation: Scheduled, Interactive
- Entry reviewed: 2026-09-17

## Purpose

### Summary

Harvey’s SOC combines independently scheduled reporting, alert-triage and threat-watch agents for its security team.

Fact · Reported · High confidence · `harvey-security-operations--summary`

Confidence reason: A linked first-party source states the claim.

Evidence:

- Supports · [1] [Building an agentic security operations center](https://www.harvey.ai/blog/building-an-agentic-security-operations-center) · Eyes Always On; From Threat to Detection; Persistent Memory; Two Systems

Representative workflow: detection engineering and tuning → human-reviewed production-change PRs.

## How it works

### Review telemetry

Daily reporting and hourly triage agents inspect telemetry and escalate critical clusters.

Fact · Reported · High confidence · `harvey-security-operations--primitives-0`

Confidence reason: A linked first-party source states the claim.

Evidence:

- Supports · [1] [Building an agentic security operations center](https://www.harvey.ai/blog/building-an-agentic-security-operations-center) · Eyes Always On; From Threat to Detection; Persistent Memory; Two Systems

### Investigate threats

Threat-watch compares external intelligence with coverage and proposes detections.

Fact · Reported · High confidence · `harvey-security-operations--primitives-1`

Confidence reason: A linked first-party source states the claim.

Evidence:

- Supports · [1] [Building an agentic security operations center](https://www.harvey.ai/blog/building-an-agentic-security-operations-center) · Eyes Always On; From Threat to Detection; Persistent Memory; Two Systems

## Where people stay involved

- **detection engineering and tuning → human-reviewed production-change PRs** — Work-product review · Level 3

### Supervision evidence

#### Operating model assessment

Level 3 for detection engineering and tuning → human-reviewed production-change PRs; human attention boundary: work-product-review.

Inference · Catalog judgment · Medium confidence · `harvey-security-operations--operating-models-0`

Confidence reason: Harvey explicitly gates every production change through human review, while reports and triage have separate scheduled scopes.

Qualifications:

- Observation date: 2026-05-14

Evidence:

- Supports · [1] [Building an agentic security operations center](https://www.harvey.ai/blog/building-an-agentic-security-operations-center) · From Threat to Detection to Tuned Alert: both detection proposals and tuning rules are GitHub PRs for human review

## Implementation details

### Harness

Separate security infrastructure from Spectre.

Fact · Reported · High confidence · `harvey-security-operations--architecture-harness`

Confidence reason: A linked first-party source states the claim.

Evidence:

- Supports · [1] [Building an agentic security operations center](https://www.harvey.ai/blog/building-an-agentic-security-operations-center) · Eyes Always On; From Threat to Detection; Persistent Memory; Two Systems

### Knowledge

ClickHouse security telemetry and threat-model instructions.

Fact · Reported · High confidence · `harvey-security-operations--architecture-knowledge`

Confidence reason: A linked first-party source states the claim.

Evidence:

- Supports · [1] [Building an agentic security operations center](https://www.harvey.ai/blog/building-an-agentic-security-operations-center) · Eyes Always On; From Threat to Detection; Persistent Memory; Two Systems

### Context management

Postgres memory with retention, deduplication and profile-specific injection budgets.

Fact · Reported · High confidence · `harvey-security-operations--architecture-context-mgmt`

Confidence reason: A linked first-party source states the claim.

Evidence:

- Supports · [1] [Building an agentic security operations center](https://www.harvey.ai/blog/building-an-agentic-security-operations-center) · Eyes Always On; From Threat to Detection; Persistent Memory; Two Systems

### Tool access

RunReveal MCP exposes security corpus tools.

Fact · Reported · High confidence · `harvey-security-operations--architecture-tool-access`

Confidence reason: A linked first-party source states the claim.

Evidence:

- Supports · [1] [Building an agentic security operations center](https://www.harvey.ai/blog/building-an-agentic-security-operations-center) · Eyes Always On; From Threat to Detection; Persistent Memory; Two Systems

### Implementation coverage

- **Model:** unreported — Not documented for this subject in the reviewed source.
- **Harness:** reported
- **Sandbox:** unreported — Not documented for this subject in the reviewed source.
- **Tool access:** reported
- **Knowledge:** reported
- **Context management:** reported
- **Credentials:** unreported — Not documented for this subject in the reviewed source.
- **Interfaces:** unreported — Not documented for this subject in the reviewed source.

## Validation and failure handling

### Review production changes

Data-tested detections and tuning rules become GitHub pull requests for human review.

Fact · Reported · High confidence · `harvey-security-operations--primitives-2`

Confidence reason: A linked first-party source states the claim.

Evidence:

- Supports · [1] [Building an agentic security operations center](https://www.harvey.ai/blog/building-an-agentic-security-operations-center) · Eyes Always On; From Threat to Detection; Persistent Memory; Two Systems

## Reported observations

**Unreported:** The reviewed source does not document this for the named subject.

## Lessons

**Unreported:** The reviewed source does not document this for the named subject.

## Question coverage and scope

- **purpose:** Reported
- **workflow:** Reported — Documented use example; no universal platform run is implied.
- **human involvement:** Reported
- **implementation:** Reported
- **validation:** Reported
- **observations:** Unreported — The reviewed source does not document this for the named subject.
- **lessons:** Unreported — The reviewed source does not document this for the named subject.

## Related reading

- Related implementation: [Harvey — Spectre](https://internal-agents.com/agents/harvey-spectre)

## Sources

1. [Building an agentic security operations center](https://www.harvey.ai/blog/building-an-agentic-security-operations-center)
   - Engineering blog · First party · Evidence
   - Original URL: <https://www.harvey.ai/blog/building-an-agentic-security-operations-center>
   - Accessed: 2026-08-12 · Last verified: 2026-08-31
