Production data from a governed loop.
Automation speeds up work. It doesn't remove the decision burden. A system where the Governor, not a ticket queue, decides when a case closes does.
These aren't isolated improvements
The same three numbers from the homepage. This page goes deeper on where they come from.
The deeper numbers
What sits underneath the headline three.
The four outcomes of switching to Sirp
- Detection~5 min
- Ticket~15 min
- Assignment~20 min
- Investigation~95 min
- Approval~40 min
- Action~10 min
- Detection~5 sec
Covers ticket, assignment, investigation, approval
- Evaluation~55 sec
- Action~15 sec
Response speed becomes structural
The Autonomy Gate fires per action, before execution, not after a human picks up a ticket. Decision and execution happen in the same step. Containment windows for ransomware and lateral movement are measured in minutes. When your gate-to-execution time is seconds, you're inside that window.
Volume stops scaling with headcount
The Executor runs whatever the Gate allows, without waiting on analyst availability. Alert volume can grow without a matching hiring plan, because nothing in the loop is rate-limited by a person's calendar.
Analyst work changes completely
The Decision Governor issues one of three verdicts per case: close it, escalate it, or send it back to the Planner with a delta. Only the escalate verdict reaches a person, and Sara is what surfaces it with the reasoning attached, not a bare alert.
The cost curve flattens
Planner reasoning runs on compute, not on shift coverage. Cost tracks alert volume the way infrastructure cost tracks usage, not the way payroll tracks headcount.
Real deployments
11 analysts, approval gates, 4–6 hour case age
2 analysts on oversight, under 30 second case age, under 5% human review
7x cost reduction, zero audit findings, more thorough compliance documentation
"Audit trail improved. Automated logging turned out more complete than manual documentation ever was."
Tiered L1 to L2 to L3 escalation model
System-first resolution, single oversight team
92% autonomous actions, zero routine escalations, team stayed intact
"Running in parallel for 30 days, the autonomous system caught three incidents the human team missed to queue backlog. That ended the internal debate."
Why these metrics move together
This isn't five separate improvements. It's one architectural change, measured five ways.
Reasons about what an alert needs and proposes every action. It approves none of them, so speed here doesn't trade off against control.
Checks each proposed action against policy before it runs, per action type, not per platform. This is where response-speed and false-positive numbers both originate: the same check that keeps latency low is the check that keeps error rate low.
Runs only what the Gate allowed. This is where the headcount-decoupling comes from. Nothing here waits on an analyst's queue position.
Fires once, after the run, and issues one of three verdicts. The 90% autonomous-actions figure and the 5–10% escalation rate are the same number, seen from opposite sides: cases the Governor closed vs. cases it sent to a human.
The key difference: decision placement.
Workflow automation makes humans faster at the same job. This loop removes humans from the execution path and gives them the judgment calls instead. That's why MTTD, MTTR, cost, and analyst hours all move together — they're all downstream of where the decision gets made, not five separate product features.
What the system doesn't handle
This is the Governor's second verdict: escalate.
It fires when:
- Confidence falls below policy threshold
- The attack pattern is novel or outside training data
- Context requires business knowledge the system doesn't have
- Multiple conflicting signals produce ambiguous risk
Escalation rate: 5–10% of investigations
False positive rate: <2%
Humans handle ambiguity and strategy. The system handles volume and routine execution.
2025-06-26 09:32 AM
Rewterz — IPS Traffic Accepted from Malicious source.

How we measured this:
Excluded: Test incidents, training data, simulations, deployment phase, cases requiring human judgment
Read the full methodology in the Trust Center
What this means for your SOC
If your SOC depends on human availability, tickets, and shift coverage, your performance is capped by how fast analysts work and how many you can hire.
When decisions are policy-bound and system-executed, response speed becomes predictable, cost becomes flat, quality becomes consistent, and scale becomes an infrastructure question.
The operating model changes. The outcomes follow.