Stopping the Burnout: Scaling Security Investigations with Agentic AI
Reducing MTTR by 83% with confident, guided, fast and explainable AI investigations
Take a look at the Live Product in action here
EXECUTIVE SUMMARY
Spearheaded the 0-to-1 design and strategy for an Agentic AI Security Operations Centre (SOC) Analyst, transforming a fragmented, manual investigation process into a unified, high-velocity workflow.
By solving the "AI Trust Gap" through explainable design patterns, I enabled Tier 1 analysts to achieve a world-class 83% reduction in MTTR (Mean Time to Respond).
THE IMPACT
83%
Reduction in MTTR
47%
Reduction in Manual Effort
2.5h
Time Saved Per Analyst Per Day
PROJECT METADATA
My Role
Lead Product Designer
Context
Cybersecurity / B2B Enterprise SaaS
Timeline
6 months (Concept to Launch)
Team Structure
1 Designer, 1 VP of Product, 2 Senior PMs, 1 AI Engineer, 8 Devs, 2 QA testers
THE CRISIS
400
Alerts
:
1
Tired Human
Security Operations Centers (SOCs) are broken.
Analysts are drowning in immense amount of security alerts daily, spending 90% of their time on "mechanical correlation" the tedious task of copy-pasting data across five different modules just to verify a threat.
Something needs to change.
THE USER FRICTION AND PAIN POINTS
High cognitive load from constant context switching between tasks.
Frequent false positives creating "alert fatigue" while distracting users from focusing on the real threat.
Deep distrust in AI because it traditionally acted as a "Black Box" without explanation.
THE INSIGHT : "If I don't understand it, I won't use it."
Through analyst shadowing and usability walkthroughs, I uncovered the Trust Gap. Analysts were skeptical of automation. If the AI recommended an escalation without showing its "work," analysts would ignore it and redo the investigation manually negating any speed gains.
THE STRATEGY : “Let’s empower analysts with a tool they can’t stop using”
We didn't just build an automation tool; we built an Explainable Partner. We pivoted from a "Chatbot" concept (which was too slow for live attacks) to a persistent "AI Insights Hub" integrated directly into the investigation workflow.
CONSTRAINTS
The Latency Gap:
Our LLM took 10–15 seconds to generate a full investigation. In a live cyber-attack, 15 seconds is an eternity.
The Hallucination Risk:
Early testing showed the AI occasionally suggested aggressive actions (ex. shutting down CEO’s laptop) based on weak signals.
Data Overload:
We had the data to show 50+ signals, but our research showed that "Information Density" was causing analysts to freeze.
THE SHIPPING DECISION : “Trust over Autonomy”
I led the decision to de-scope "Full Auto-Remediation"for the V1 launch.
While the business wanted "one-click fixes," my research proved the users weren't ready to trust the AI with the "Delete" key yet.
WHAT WE CUT? : “Automated Response Loop”
Moved to V2.
We decided to gather "Approval/Rejection" data from analysts first to train the model before giving it autonomy.
Key Decision 1 : Designing for Explainability
I designed the Explainable Reasoning Panel to mirror a senior analyst’s mental model.
Instead of a single Risk Score, the UI highlights the “Specific signals” -(IP spikes, MITRE techniques, and anomalous logins) that influenced the AI’s conclusion.
Key Decision 2 : Visualizing the “Uncertainty”
I introduced a Visual Confidence Scoring System to prevent analyst "Blind Trust."
By marking investigations as High, Medium, or Low Confidence, I allowed analysts to prioritize their attention.
I designed these to be pre-attentive. An analyst can scan 50 alerts and instantly know which ones are top priority as per the AI and that they require a deep human audit.
This transparency reduced the time spent "double-checking" high-confidence leads by 60%.
Key Decision 3 : From “What??" to “Now what?”
Identifying a threat is only half the battle.
To drive the 47% reduction in manual effort, I introduced Auto-Suggested Actions.
This transforms raw AI intelligence into a prioritized checklist of "Immediate Next Steps" that an analyst can approve or reject in a single click.
Key Decision 4 : Safety through “Human-In-The-Loop”
In high-stakes cybersecurity, an accidental escalations could be a catastrophe.
To give analysts the confidence to move fast and fix any unexpected wrong moves as the AI model learns, I implemented a Persistent Safety Net including "Undo" actions and manual escalation overrides.
FINAL EXPERIENCE : A Unified Intelligence Hub
The 0-to-1 experience replaces "module-hopping" with a single, guided investigation flow.
We turned a 2-hour manual grind into a 15-minute guided resolution.
CONFIDENTIALITY NOTE
Due to the sensitive nature of security data, all screens shown here are conceptual recreations designed to demonstrate UX decisions and workflow thinking without revealing proprietary or client information.
Wanna know more?
REFLECTIONS