State of the space ·  AUG 2026

Response Automation Agents

AMS Map of five roster products across agent independence, job width, and output to cost, with each chip carrying its public pricing metric or pricing not public.
The quadrant, Aug 2026 ·open full page →· this file does not change after publish

All eight still price by coverage

Response Automation Agents build, execute, verify, and maintain governed containment and remediation playbooks after a security case reaches a response conclusion. The agentic range runs from workflow-bound execution to agents that compose multi-step actions across approved tools, with human approval held at defined control points. Agentic AI pricing is clearest where vendors publish a usage unit. Swimlane tiers Turbine by daily automated actions.

1Actions and creditsPositions: Monetizely analysisPublic data only
5 / 2
Roster products / tracked products.
2 of 5
Roster products with a public agent-linked usage unit.
2023
Year Torq says Socrates debuted.

Who is on this map

No items found.

Public evidence supports Emerging placement for all five roster products. Torq disclosed total funding of $332 million in January 2026; Tines disclosed $272 million raised; BlinkOps disclosed $90 million raised and dozens of Fortune 500 customers; Swimlane disclosed a $45 million growth round and more than 50 Global 1,000 customers; and Mindflow founders publicly disclosed a €5 million round. No product receives Established placement in this edition because current public evidence does not consistently substantiate the revenue, customer-count, or public-company-product threshold.

Torq HyperSOC, Tines Stories, BlinkOps Security Micro-Agent Builder, Swimlane Turbine, and Mindflow AI··Agents each publish post-conclusion response capabilities alongside workflow execution. No additional vendor sits in the tracked list beyond D3 Security and SIRP. A tracked product graduates when public evidence establishes a shipped response product plus at least $5 million raised, three named customers, or equivalent commercial traction.

D3 Security Morpheus and SIRP OmniSense are tracked. Their public materials describe governed playbook execution, response, or remediation agents, while the reviewed public record does not independently establish the roster commercial threshold for this edition.

What this category does

Security orchestration, automation, and response, or SOAR, systems coordinate actions across endpoint, identity, cloud, email, ticketing, and intelligence tools. Response Automation Agents extend that work after a case conclusion by composing permitted steps, executing containment or remediation, checking outcomes, documenting actions, and maintaining reusable playbooks as tools and policies change.

SOC automation engineers retain ownership of response policy, access scopes, approval thresholds, test cases, exception handling, and audit review. They also decide which containment actions can run automatically, investigate failed or ambiguous executions, and revise the operational rules that govern agent behavior.

The task list agents can take over
  1. Compose - translate approved response intent into reusable containment and remediation playbooks.
  2. Execute - invoke authorized security-tool actions across the affected environment.
  3. Verify - confirm that containment, remediation, and related case updates completed as intended.
  4. Maintain - test, revise, and repair response workflows as policies, integrations, and threats change.

The agentic shift

From fixed playbooks to governed Response Automation Agents

The category history starts with agent-assisted response inside established automation systems. Torq says Socrates debuted in 2023, and Torq HyperSOC-2o shipped in April 2025 with Runbook and Remediation Agents for orchestrated containment under autonomous or human-approved configurations. The work shifted from executing predefined steps toward selecting and assembling approved response actions for the circumstances of a case.

In 2025, Swimlane released Hero in Turbine, Tines released the AI Agent action, BlinkOps released Security Micro-Agent Builder, and Mindflow released AI··Agents. Each product frames response work around scoped tools, reusable workflows, and varying approval controls instead of a single ungoverned execution path.

Public price disclosure is uneven. Swimlane publishes a tiered Turbine model based on the daily average number of automated actions, with agentic and generative capabilities included across tiers. Tines publishes editions with event capacity and sells AI run-time credits as an add-on; its AI Agent action also counts as a licensed flow. BlinkOps states that subscriptions carry usage limits, while Torq and Mindflow list pricing as pricing not public in the vendor material reviewed.

The published materials attach measurable consumption to operating throughput instead of seats: Swimlane counts automated actions, and Tines separately identifies events, flows, and AI run-time credits. Across the roster, the observable meter is automation usage.

Sources: Swimlane pricing; Tines packaging; Tines AI Agent action FAQ; BlinkOps terms; Torq HyperAgents; Mindflow SecOps.

Sources:category analysis,NDR comparison,Vendr

Observed monetization patterns
  1. Daily automated actions - Swimlane prices Turbine in tiers based on the daily average number of automated actions, with unlimited playbooks and agentic capabilities included in its published package description. Source.
  2. AI run-time credits - Tines lists AI run-time credits as an add-on to paid editions, alongside event, flow, team, and application limits. Source.
  3. Contracted usage limits - BlinkOps states that subscriptions are subject to agreed usage limits, while numerical public pricing is not supplied in the reviewed terms. Source.

This quarter

May - Aug 2026 ·gold = a monetization move· grey = product, market, or capital

The long arc

2023 to 2026 - published response-agent history

Vendor by vendor

Journalist first, analyst second

Method:we work journalist first and analyst second. We document the agentic products each vendor actually ships, with sources a reader can check, and the AMS placement follows from that documented capability. Vendors with no shipped agentic product stay on the quadrant and out of this section. We report how each vendor charges today, and we do not use this page to advise vendors on what to charge.
No items found.

Not covered

Corelight builds the evidence pipeline that most of the other tools on this page depend on, on top of  Zeek, one of the most widely used network analysis frameworks in security. When we went looking for a shipped  product that triages, investigates, or responds on its own, we did not find one, so Corelight stays on the quadrant and out of the breakdown section. The same finding applies to Netography, which provides flow observability at scale. If either company ships an agentic product, it enters this section in the edition that documents it.

About this data

Everything on this page is a synthesis of public information: published reporting, analyst coverage, vendor documentation, and procurement data that anyone can access. We link to those sources throughout. Nothing on this page draws on private or confidential information, and the positions are Monetizely's analysis of that public record, refreshed monthly.