Charlotte AI: what to automate in your SOC
AI can help investigate security alerts. The useful test is whether it improves decisions and response in your own operation.
The cover image is an AI-generated editorial illustration. Screens and documents are illustrative concepts.
The first question to ask about AI in a security operations centre is what work it takes off the analyst’s desk. Collecting context for an alert is a sensible candidate. Deciding whether to interrupt a critical business service needs much more care.
CrowdStrike describes Charlotte AI as a way to assemble security context, coordinate investigations and support governed response workflows. Those are useful capabilities to evaluate. They do not, by themselves, establish how much time your team will save or which incidents it can handle without intervention.
Start with the investigation
Take a recurring alert your analysts know well. Check whether the AI can identify the affected user and machine, assemble the relevant activity and explain the evidence behind its conclusion. Include an ambiguous case, not just an obvious attack.
An investigation is easier to review when the analyst can follow the evidence. A confident summary without that trail creates another verification task.
Set boundaries around response
Decide which actions can run automatically and which need approval. The answer may differ between an employee laptop and a production server. Record exceptions and make it possible to investigate a mistaken action.
For a small business buying a managed service, ask who takes responsibility when the automation is uncertain. Around-the-clock software and around-the-clock response are different commitments. The service agreement should identify who investigates, who may contain an incident and who contacts your business.
We would judge an agentic SOC by those decisions and outcomes. Faster triage is valuable when it leads to a sound response, with fewer missed incidents and less unnecessary disruption.