top of page

Zscaler Agentic SOC Brings Autonomous Containment Into the Security Operations Center

2 hours ago
11 min read

Zscaler launched Zscaler Agentic SOC on September 9, moving AI agents from advisory work toward direct threat containment across enterprise networks. The conflict is immediate. Faster attacks demand faster defenses, but an automated mistake can also block a legitimate user or disrupt an essential application.

The product combines specialized agents, Zscaler telemetry, third-party alerts, business context, and inline Zero Trust Exchange controls. Those agents can triage signals, reconstruct attack paths, assign verdicts, and initiate response workflows. Customers can retain human approval or enable greater automation as confidence grows.

That places Zscaler inside a larger contest over the future of security operations. Microsoft, Databricks, Dropzone AI, and other vendors are also developing agent-led investigation and response systems. Zscaler’s wager is that its position inside network traffic gives its agents better evidence and a shorter path from detection to enforcement.

This is not simply another security chatbot. The consequential feature is closed-loop remediation, where analysis can lead directly to blocking traffic, isolating identities, or restricting access. The value will depend on whether customers trust the evidence, controls, and recovery process behind those actions.

Zscaler Agentic SOC Connects Detection to Containment

The launch changes where automation stops: Zscaler wants AI agents to carry an incident from scattered signals through a containment decision.

Zscaler describes its new product as an AI-first security operations system rather than an assistant added to an existing dashboard. It became globally available when the company announced it from San Jose, California, on September 9, 2026.

A security operations center, or SOC, is the team and technology responsible for monitoring, investigating, and responding to digital threats. Most SOC workflows still divide those responsibilities among several products and multiple analysts.

Zscaler Agentic SOC tries to collapse that sequence. Specialized agents handle triage, root-cause investigation, verdict assignment, and response orchestration. Each agent performs a limited role, then passes its findings into a shared incident narrative.

The system draws from Zscaler’s network, identity, endpoint, cloud, data protection, and deception signals. It can also ingest alerts and context from outside products. Zscaler says its context graph connects those signals with details such as asset importance, user identity, device posture, and known exposure.

That context matters because an alert rarely explains its own business significance. A suspicious connection from an unused test device presents a different risk than the same connection from a finance executive’s managed laptop.

Zscaler says its agents can map activity to the MITRE ATT&CK framework, summarize an attack path, display supporting evidence, and surface contradictory evidence. The last feature addresses a basic trust problem. Analysts need to see why an automated verdict was reached before they approve a disruptive response.

The company’s launch details say the service uses models from Anthropic and OpenAI alongside proprietary threat intelligence. Zscaler has not publicly reduced the product to one foundation model, which gives it room to route tasks across different models.

The most consequential step comes after investigation. Zscaler says the platform can use native inline controls to isolate compromised users, block command-and-control traffic, and restrict lateral movement. Third-party integrations can extend those response options beyond Zscaler’s own platform.

Customers do not have to start with unattended containment. The response controls support manual execution, human-approved playbooks, and automated actions. This graduated model lets teams begin with recommendations before granting agents broader authority.

That distinction separates the launch from generative AI features that only summarize alerts. Zscaler Agentic SOC places automated reasoning beside the mechanisms that can change access in real time.

AI-Driven Attacks Are Compressing the Defender’s Clock

Zscaler is selling response speed because attackers increasingly automate the reconnaissance and execution steps that once gave analysts more time.

The company argues that conventional SOC processes cannot correlate, analyze, and remediate hostile activity quickly enough. Its ThreatLabz researchers have observed attackers using trusted websites, legitimate remote-management tools, and browser-based techniques to evade familiar controls.

Those methods are difficult because each individual action can resemble authorized behavior. A remote administration utility has legitimate business uses. A trusted domain does not automatically indicate safe content. Browser prompts can persuade users to execute commands without dropping recognizable malware.

AI can help attackers test more variations, rewrite lures, collect public information, and coordinate multistep activity. It does not make every intrusion novel. It increases the speed and volume at which familiar techniques can be adapted.

That creates pressure on analysts working across fragmented tools. One console may contain identity events, while another stores endpoint alerts. Network traffic, cloud activity, vulnerability findings, and business ownership records may sit elsewhere.

Every handoff consumes time. Analysts must search for related events, decide whether they describe one incident, identify the affected assets, and select a proportionate response. Automation becomes valuable when it removes those mechanical delays without hiding the evidence.

Zscaler says its Zero Trust Exchange processes more than 750 billion transactions each day. The company presents that scale as a data advantage because its service already sits in the path of many customer connections.

That claim needs careful interpretation. A large telemetry volume does not automatically produce accurate incident verdicts. Data quality, customer coverage, correlation logic, model behavior, and environment-specific context remain decisive.

However, inline visibility can shorten the path between observation and action. An overlay tool may identify suspicious activity but still depend on another platform to block it. Zscaler can connect a finding with controls already enforcing access policies.

This pressure is not limited to Zscaler customers. Microsoft describes an agentic SOC model where autonomous defenses lock accounts, isolate devices, and assemble evidence before an analyst opens the queue.

Databricks has taken a different route with Lakewatch, applying agentic analysis to security data stored in a lakehouse. Its approach emphasizes open formats, broad data retention, and analysis near the underlying business data.

Dropzone AI focuses on investigating alerts across an existing security stack before escalating confirmed threats. That overlay model can appeal to buyers who want automation without replacing their established tools.

These products differ, but their commercial argument is similar. Human attention has become the constrained resource. Vendors therefore want software to close routine cases, prioritize serious incidents, and prepare complex investigations for expert review.

The forced response for security leaders is operational, not rhetorical. They must decide which decisions an agent can make, what evidence it must present, and which actions still require explicit approval.

The Real Contest Is Native Telemetry Versus Neutral Integration

Zscaler’s primary advantage is also its central tradeoff: native data can improve response context, while platform dependence can narrow what the system sees.

Zscaler frames many competing agentic SOC products as overlays placed above fragmented alerts. In its view, those tools inherit the same weak context and delayed signals that already burden human analysts.

Its alternative begins with telemetry generated inside the Zero Trust Exchange. The platform can combine a connection with the user’s identity, device state, application, data policy, and access conditions. Agents then evaluate an incident using that joined context.

The product can investigate Zscaler traffic without forwarding all raw logs into a separate security information and event management system. A SIEM is a platform that collects security records for analysis, investigation, compliance, and retention.

Zscaler does not say every customer should remove its SIEM. It positions Agentic SOC as an operational layer that can send distilled incidents to the SIEM while leaving long-term storage and broad aggregation there.

This architecture can reduce duplicate movement of high-volume network logs. It can also let response agents act through the same platform that observed the traffic. Both outcomes depend on how much of the customer’s relevant environment Zscaler actually covers.

A native platform sees its own signals with unusual depth. It may still need outside data to reconstruct activity across email, source code, software-as-a-service applications, operational technology, and security products from other vendors.

That is why third-party integration is not a secondary feature. It determines whether the context graph represents a complete attack path or a detailed fragment of one.

Databricks presents the opposing route. Its Lakewatch design emphasizes open formats and analysis across security and business data already stored in a lakehouse. That can provide broad historical context without starting from an inline enforcement platform.

Microsoft has another structural advantage. Defender, Entra, Sentinel, Microsoft 365, and Azure can contribute endpoint, identity, email, cloud, and collaboration signals. Its agentic strategy builds across a large installed enterprise estate.

Specialists such as Dropzone AI offer neutrality. Their systems can sit across existing SIEM, endpoint detection, case management, and orchestration products. That flexibility can reduce dependence on one platform, although the agents must normalize data from many sources.

Zscaler’s answer is an open integration model combined with native enforcement. It wants outside evidence to enter its investigation while keeping containment close to its own inline controls.

The outcome will not be determined by the number of integrations on a product page. Buyers need to test whether those connections carry sufficient context, operate in both directions, and preserve evidence after an automated action.

A shallow integration may import an alert title without the surrounding events. A stronger one can retrieve raw evidence, update a case, initiate a controlled response, and record the result.

This is the core competitive question behind Zscaler Agentic SOC. Native telemetry offers speed and coherence. Neutral platforms offer broader choice. Enterprise buyers must decide which weakness presents the greater risk in their environment.

Autonomous Response Creates a New Failure Surface

An agent that can stop an attacker can also interrupt legitimate work, making containment accuracy more important than fluent incident summaries.

A mistaken summary wastes analyst time. A mistaken automated response can disable an account, block a trusted service, interrupt production, or isolate a critical device during an urgent business process.

This risk does not make autonomous containment unusable. It changes the standard of proof. Security teams must evaluate an agent as an operational control, not simply as a productivity feature.

The first requirement is traceable evidence. Zscaler says its agents show both supporting and contradictory signals for each determination. Customers should verify that those explanations reference underlying events rather than providing a persuasive narrative without reproducible evidence.

The second requirement is bounded authority. An agent allowed to block a malicious file presents a different operational risk from one allowed to isolate executives, revoke credentials, or modify broad network policy.

Permissions should match incident severity, confidence, asset criticality, and recovery cost. Lower-risk actions can run automatically. Higher-impact actions should require approval until the organization has established dependable performance.

The third requirement is reversibility. Every automated playbook needs a tested rollback path. Analysts must know how to restore access, reverse a block, and recover the original state when the verdict changes.

The fourth requirement is auditability. Security and compliance teams need records showing what the agent observed, which models or policies influenced the decision, what action occurred, and who approved it.

The fifth requirement is resistance to manipulation. An attacker may try to poison data, create misleading correlations, or exploit instructions consumed by an agent. Greater tool access gives a compromised agent more ways to cause damage.

NIST’s agent security analysis found broad agreement that established cybersecurity principles remain relevant but require adaptation for AI agents. Identity, authorization, monitoring, and governance become more difficult when software can plan and act with limited supervision.

Human approval alone does not solve every problem. Analysts may approve recommendations too quickly when alert volume is high or explanations appear authoritative. Oversight must therefore include clear escalation rules, sampling, performance review, and independent validation.

The quality of the underlying telemetry presents another uncertainty. An industry critique of the visibility gap argues that agents can misfire when endpoint, identity, cloud, and network evidence remains fragmented.

Zscaler’s context graph directly addresses that criticism, but the company has not publicly supplied universal accuracy benchmarks for every customer environment. Its performance and benefits remain vendor claims until deployments produce independently comparable evidence.

False positives are only one side of the problem. An agent can also produce false negatives, close a suspicious case, or miss a novel chain of individually benign actions.

Customers should evaluate complete incidents rather than isolated alert classifications. Useful tests include compromised identities, remote-management abuse, browser-based attacks, lateral movement, and activity spanning Zscaler plus third-party systems.

Teams should also compare assisted and automated modes. A recommendation that analysts routinely reject should not become an unattended action merely because a confidence score crosses an arbitrary threshold.

Agentic containment needs staged adoption. Begin with observation and summaries, progress to recommendations, automate narrow reversible actions, and expand authority only after measured evidence supports the change.

Zscaler’s AI Partnerships Matter Less Than Its Control Plane

The models can improve reasoning, but Zscaler’s durable differentiation comes from the data, permissions, and enforcement systems surrounding them.

Zscaler has named Anthropic and OpenAI as model partners for Agentic SOC. That gives the platform access to frontier models without tying every task to a single provider.

A multi-model strategy can route different jobs to the model best suited for them. One model might summarize a complex incident, while another evaluates evidence or generates a response plan.

However, foundation models are increasingly available to many cybersecurity vendors. Access to them does not create a lasting advantage by itself. Competitors can license similar capabilities or replace models as performance changes.

The harder work sits around the model. Security agents need normalized evidence, constrained tools, organization-specific policies, identity controls, durable logs, and response mechanisms. They also need evaluation systems that test behavior against real incident patterns.

Zscaler says its agents draw on more than ten years of SOC, managed detection, response, and threat-hunting experience. The company also says intelligence from thousands of customer environments informs the system.

Those statements describe the training and tuning inputs, not independently verified accuracy. Buyers still need results from environments resembling their own.

The architecture gives Zscaler several practical levers. It can enrich a suspicious connection with policy and posture context. It can recommend a response based on business impact. It can then execute through inline controls without waiting for another vendor’s system.

This closed loop is valuable only when governance remains attached to every step. A model should not receive unrestricted access simply because the surrounding platform has broad visibility.

Security teams need role-based access, scoped credentials, action limits, approval policies, and isolation between customers. They should also know whether incident data is retained, where inference occurs, and how model providers handle submitted content.

Model updates create another operational issue. A newer model can behave differently even when the surrounding workflow stays constant. Vendors need regression testing before changing a model that influences containment decisions.

Customers should ask whether Zscaler records the model version, agent configuration, policy state, and evidence used for each action. Without those details, investigating an incorrect response becomes much harder.

Explainability also requires more than prose. An effective incident view should let analysts inspect timestamps, identities, network sessions, affected assets, contradictory signals, and the sequence of agent decisions.

This is where the Zscaler Agentic SOC proposition becomes concrete. The headline mentions AI agents, but the product will succeed through dependable control engineering.

Frontier models can help agents interpret ambiguity. They cannot compensate for missing evidence, excessive permissions, weak integrations, or an untested recovery plan.

Three Signals Will Show Whether Zscaler Agentic SOC Works

The next test is not another feature announcement; it is whether customers can automate meaningful containment without increasing business disruption.

The first signal is measurable production performance. Buyers should look for documented changes in investigation time, containment time, analyst workload, false-positive actions, and reversed decisions.

A customer quote about faster analysis provides useful context, but it does not establish general reliability. Strong evidence would compare automated and human-led workflows across defined incident categories.

The most valuable reports will separate triage from containment. Many tools can summarize or prioritize alerts. Far fewer can safely execute a response against a live identity, device, destination, or application.

If deployments show faster containment with few unnecessary actions, Zscaler’s native telemetry argument gains support. Frequent reversals or approval bottlenecks would weaken the case for closed-loop automation.

The second signal is the depth of third-party integration. Zscaler must prove that Agentic SOC can assemble coherent incidents when the evidence extends beyond its own platform.

Buyers should watch which SIEM, endpoint, identity, cloud, ticketing, and orchestration integrations support two-way workflows. They should also examine what context each connector transfers.

Broad integration would strengthen Zscaler’s claim that native telemetry and open tooling can coexist. Limited context would leave customers with another partial view, even if that view is detailed.

The third signal is how competitors connect reasoning with enforcement. Microsoft can build autonomous workflows across Defender, Entra, Sentinel, Azure, and Microsoft 365. Databricks can emphasize open data and long-term context. Specialist vendors can argue for independence from the enforcement platform.

A competitive response that delivers comparable containment with broader evidence would reduce Zscaler’s differentiation. Conversely, weak or delayed integrations across competing stacks would make Zscaler’s inline position more attractive.

Security leaders should not wait for a universal winner. They can define a narrow incident class, establish a human-reviewed baseline, and test the same workflow across candidate systems.

The evaluation should measure evidence quality, decision consistency, containment speed, integration depth, analyst intervention, and rollback success. It should also include adversarial tests designed to mislead the agent.

Teams need a reliable record of those trials. A searchable technical knowledge base can preserve playbooks, rejected verdicts, integration limits, and post-incident findings across security and engineering groups.

The Zscaler Agentic SOC launch makes autonomous defense a current procurement decision rather than a distant concept. Its strongest proposition is the union of context and inline action.

Its hardest question is equally direct. Can organizations grant agents enough authority to outrun attackers without allowing one uncertain verdict to become an automated outage?

Start with one reversible workflow, define the evidence threshold, and measure every intervention. The future of agentic security operations will be decided by those records, not by how confidently an AI narrates the incident.

Give every agent the context to do better work

Connect your agents to the knowledge, decisions, and history already organized in remio.

remio currently supports Windows 10+ (x64) and Macs with Apple silicon.

Your AI Partner at Work
Get more done with remio

Plan. Create. Deliver.
All in one place.

bottom of page