Capability tracks

Defined work, without invented guarantees.

SOCRoot is in pre-production validation. The tracks below describe work that can be scoped and evaluated; they are not a public managed-SOC SLA, an unattended remediation promise, or a claim of regulatory certification.

Status notice

Pricing, response times, uptime commitments, and production coverage are agreed only in a written, scoped engagement after technical and operational validation. This page intentionally publishes no default SLA or checkout flow.

Scoped engagement design

Authorized exposure assessment

A bounded review of approved external assets with explicit ownership, exclusions, evidence handling, and acceptance criteria.

Typical outputs

  • Scope and authorization record
  • Prioritized findings
  • Reproduction evidence
  • Remediation guidance
Pre-production validation

SOC workflow prototype

A lab or pilot workflow connecting alerts, enrichment, human approval, response proposals, and an evidence trail.

Typical outputs

  • Synthetic or approved telemetry
  • Triage decision record
  • Dry-run response
  • Operator and rollback notes
Advisory / readiness support

Architecture and control mapping

A structured comparison between current technical evidence and selected security-control objectives. It is not certification or legal assurance.

Typical outputs

  • Current-state assumptions
  • Evidence-to-control mapping
  • Gap register
  • Prioritized next steps
Educational content

Security awareness material

Practical training content and exercises that can support an organization’s program but do not constitute an accredited certification.

Typical outputs

  • Learning modules
  • Scenario exercises
  • Knowledge checks
  • Completion record

Engagement gates

Safety is part of the deliverable.

Work should stop when authorization, evidence handling, or rollback conditions are unclear. These gates are not optional process overhead; they define whether the work is professionally defensible.

01Written authorization and target ownership
02Defined scope, exclusions, and data-handling rules
03Synthetic data unless real data is explicitly approved
04SOAR_DRY_RUN=true for demonstrations and pilots
05Human approval for sensitive actions
06Documented verification and rollback steps

Next step

Start with a written scope, not a checkout.

Describe the asset owner, the decision you need to support, the environment, and the evidence you expect. SOCRoot will not accept work that lacks authorization or requires unsupported production guarantees.