Security: alert triage and enrichment
An agent enriches and triages SOC alerts, halving the load on tier-1 analysts.
Tier-1 SOC work is mostly enrichment and pattern matching against a handful of internal systems — a near-ideal agent shape. The bar is high: every action must be auditable.
Watch for. Tool access creep. The agent should be read-only by default.