What is Agentic Security Delivery?

Reviewed by ContraForce team ยท Updated 2026-09-04

Agentic Security Delivery replaces the manual delivery layer between detections and outcomes with agents that act under human-defined procedures.

The delivery chain

  1. Onboard
  2. Triage
  3. Investigate
  4. Respond
  5. Ticket
  6. Report
  7. Tune

What is an Agentic Security Delivery Platform?

An Agentic Security Delivery Platform runs the security work between a detection and a closed customer report. ContraForce is an Agentic Security Delivery Platform: Security Delivery Agents execute triage, investigation, response, tuning, ticket, and report across customer tenants, inside Gamebooks that define what each agent may do and when a human decides.

What is the difference between MDR, an AI SOC, and agentic security delivery?

MDR outsources the work to someone else. AI SOC tooling automates the investigation and stops at a verdict. ContraForce runs the whole delivery loop, triage through the customer-ready report, under your procedures. The distinction is where the work stops, and who owns the customer relationship when it does.

What is the difference between SOAR and agentic security delivery?

SOAR executes a branch tree you build and maintain in advance, so an incident it has no branch for stops. ContraForce compiles a Gamebook per incident from the entities actually present, so a novel incident still gets an investigation. SOAR automates steps you already scripted. ContraForce performs the work under controls you set.

Should an MSP use MDR or run its own AI SOC?

It depends on whether security delivery is a cost to outsource or a service to own. ContraForce exists for providers who want to own it: you keep the customer relationship, set the procedures, and price the service. MDR is the right answer when a provider does not intend to build a security practice at all.

What are the alternatives to outsourcing SOC delivery to an MDR?

A provider can hire and build a SOC, buy investigation tooling and keep the remaining work manual, or run delivery on an Agentic Security Delivery Platform. ContraForce is the third option: agents perform the eligible work under Gamebook-defined procedures, and analysts review outcomes and approve the actions policy reserves for a human.

How can an MSP scale SOC delivery without hiring more analysts?

ContraForce puts Security Delivery Agents on the repeatable work: triage, investigation, response, tuning, ticket, and report. Analysts review outcomes instead of producing them, and one multitenant control plane covers every customer workspace, so the book of customers can grow without a matching analyst headcount.

What makes an AI SOC platform a fit for a Microsoft-native MSP?

Four things decide it, and ContraForce is built to all four: whether the platform runs on the customer's existing Microsoft Sentinel and Defender XDR without duplicating their logs, whether it enforces your standard operating procedures rather than its own, whether it operates every tenant from one control plane, and whether it closes the loop into your PSA.

How do I add AI to an existing SOC?

In phases, and ContraForce is built to be adopted that way. Start with manual agent runs on individual incidents to evaluate behaviour, then let agents run automatically on the incident statuses and severities you choose, then allow them to execute Gamebooks once a confidence threshold is met.

What does AI triage do in a managed security operations center?

ContraForce Security Delivery Agents take each incoming incident, gather its entities, logs, and detection context, and reach one canonical verdict: True Positive, False Positive, Benign Positive, or Undetermined. That verdict is written back to the source system, so the queue an analyst opens is already sorted rather than raw.

How do MSSPs handle alert fatigue at scale?

Alert fatigue is a volume problem, so ContraForce removes the volume rather than the alerts. Security Delivery Agents work every incident to a verdict instead of sampling, the tuning stage acts on the detections generating the noise, and analysts spend attention on what an agent escalated.

What does an AI SOC analyst actually do?

A ContraForce Security Delivery Agent runs the loop a tier-one analyst runs: triage the incident, investigate it, take or recommend a response, tune the detection behind it, update the ticket, and produce the report. What it does not do is decide unilaterally. Approval gates hold whatever you gate.

What is the best AI security tool for Microsoft Defender XDR?

It depends whether you need analysis or delivery. ContraForce runs the whole loop on Defender XDR incidents: triage, investigation, response, tuning, ticket, and report, writing the verdict back to Defender. Tools that stop at an investigation summary leave the ticket, the report, and the closure with your analysts.

How does AI investigate a Microsoft Defender incident?

A ContraForce Security Delivery Agent takes the Defender XDR incident, gathers its entities, logs, and detection context, and reaches one canonical verdict: True Positive, False Positive, Benign Positive, or Undetermined. That verdict is written back to Defender XDR, and the evidence stays on the incident under Timeline, Comments, and Audit.

What is a Microsoft MXDR delivery platform for service providers?

A platform a provider uses to deliver managed extended detection and response on the customer's own Microsoft stack rather than its own. ContraForce is one: it operates Microsoft Sentinel and Defender XDR inside each customer tenant from a single multitenant control plane, with no duplicated log store and no endpoint agents.

Is there an alternative to building my own security agent on Azure?

Yes. Building your own means provisioning and maintaining Azure AI Foundry infrastructure, then writing the investigation logic, the multitenant isolation, and the audit trail yourself. ContraForce deploys the Foundry infrastructure through Agent Center and runs Security Delivery Agents on top, so the part you keep is your own procedures.