Zscaler Agentic SOC is a new security-operations product that correlates alerts with identity, device, application and exposure context, then uses specialised AI agents to triage, investigate and recommend containment. Zscaler announced it on September 9 as part of a wider effort to connect its security telemetry directly to response controls.
- The product groups alerts into threat stories instead of treating every alert as an isolated event.
- Context comes from Zscaler telemetry and compatible third-party security tools.
- AI agents support triage, investigation, summaries and response recommendations.
- Customers can keep human approval or automate selected playbooks as confidence grows.
How Zscaler Agentic SOC works
The workflow begins by aggregating alerts from network, endpoint, identity, email and cloud tools. Zscaler says its Data Fabric for Security maps those signals to entities such as users, assets, vulnerabilities and applications, giving an incident more business context than a raw detection usually carries.
Specialised agents then handle bounded tasks: grouping related signals, validating indicators, summarising an attack path, mapping techniques and proposing a response. The company says each determination can show supporting and contradictory evidence so an analyst can review why an agent reached its conclusion.
Zscaler Agentic SOC is best understood as a decision pipeline, not an autonomous security officer: it assembles evidence, prioritises incidents and connects approved playbooks to inline controls, while the customer decides which actions require a person.
| Stage | Function |
|---|---|
| Unify | Aggregate Zscaler and third-party alerts |
| Enrich | Add identity, asset, posture and exposure context |
| Investigate | Build attack-path summaries and evidence-backed verdicts |
| Respond | Recommend or execute scoped containment playbooks |
What is verified and what remains a claim
Dutch IT Channel independently reported the September 9 launch and the combination of exposure management, AI-driven workflows and zero-trust telemetry. Blockonomi separately described the alert-correlation and automated-response design. Both corroborate the product event, while scale, detection quality and response-speed claims still come mainly from Zscaler.
Zscaler says the platform can analyse its inline traffic without forwarding all raw logs to a SIEM. That could change ingestion costs, but customers should validate how much data still needs long-term retention, which third-party sources are supported and whether regulatory evidence can be exported intact.
Controls security teams should test
A pilot should measure false grouping, missed relationships and the time required for an analyst to reconstruct the evidence. Teams should test whether contradictory signals remain visible and whether every automated containment action has an owner, scope, rollback step and immutable audit record.
Automation should begin with reversible steps such as isolating a test endpoint or blocking a known malicious indicator. The evidence discipline resembles how Google frames agentic AI threat response, while the need for measurable human review echoes the Observe.AI performance agents rollout.
FAQs
Does Zscaler Agentic SOC replace a SIEM?
Zscaler says it complements a SIEM. Customers may retain a SIEM for compliance, long-term storage and broad aggregation while forwarding higher-fidelity incidents from the new product.
Can it contain threats automatically?
It can connect response playbooks to inline controls. Organisations can require human approval or automate selected actions according to their own confidence and policy.
What should buyers verify first?
They should verify data-source coverage, evidence transparency, false-positive rates, rollback behaviour, audit exports and the boundary between recommendations and autonomous actions.
Where the operating model changes
Traditional alert operations often divide ownership between detection engineering, the SIEM team, identity specialists, endpoint responders and application owners. Correlation can shorten that handoff only if the product preserves which source produced each signal and which team owns the affected system.
The launch therefore creates a governance task as well as a tooling choice. Security leaders need a catalogue of agents and playbooks, named owners, approval thresholds and a review schedule. An agent that recommends blocking a domain carries a different business risk from one that isolates an executive’s device or revokes an identity token.
Teams should record the starting alert set, the context added, the agent’s reasoning summary, the final human decision and the observed outcome. That makes it possible to measure whether automation actually reduced investigation time without hiding misses or shifting work into exception handling.
Procurement should also ask which capabilities are available at launch, which depend on other Zscaler modules and which require third-party connectors. Clear licensing and data-retention boundaries are necessary before a pilot can produce a meaningful total-cost comparison with an existing SIEM and SOAR stack.
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.



