Skip to content

Solutions / Use case

Security operations automation, from first alert to shipped fix.

Every alert, phishing report and finding has to cross the SIEM, identity, devices, ticketing and chat before anyone acts on it. When those systems don't talk, analysts spend the shift copying context between tabs. Tray.ai connects every handoff, so the team starts each case at the decision.

Great — a couple more details

This helps us connect you with the right person. Optional, and you can skip it.

Jump to the stages
One suspicious sign-in moving through security operations: Datadog flags impossible travel on Dana's account, Okta adds who she is and what she can reach, Slack asks her whether it was her and she says no, Okta revokes her sessions, Jira opens case SEC-412, and an analyst picks it up already contained, with the evidence attached.

The short answer

What is security operations automation?

Security operations (SecOps) automation is the work a security team runs every day, done by workflows instead of by hand: collecting the logs detections need, triaging alerts, working phishing reports, responding to compromised accounts and endpoints, and routing vulnerabilities and bug reports to the teams that fix them. It runs across the SIEM, identity, device, email, ticketing and chat systems, and most of an analyst's time goes on the gaps between them: looking up the owner, the device and the history before the real decision can start.

  1. 1 Collect the logs
  2. 2 Triage alerts
  3. 3 Phishing reports
  4. 4 Contain accounts
  5. 5 Contain devices
  6. 6 Route the fixes
  7. 7 Triage outside reports
connectors, Okta and Datadog among them
700+
Type 2 audited every year, with the reports in our trust center
SOC 1 & 2
Gartner Hype Cycles in 2026
14
Willingness to Recommend, 2026 Gartner Voice of the Customer
97%

The security operations process, stage by stage

Seven stages, each with what breaks and a how-to guide for building it.

  1. 1

    Security log collection

    Sign-in, admin and audit events from every SaaS app land in the SIEM, in one shape, minutes after they happen.

    Where it breaks: An app's log feed stops quietly, and nobody notices until an investigation needs the week that is missing.

  2. 2

    Alert triage

    Every alert gets its owner, asset and history attached before a person opens it, and known noise is held back.

    Where it breaks: The one alert that mattered is closed as noise by somebody in their fourth hour on the queue.

  3. 3

    Phishing report triage

    Reported emails are checked, grouped into campaigns and answered, and every copy is found across the company.

    Where it breaks: Forty people report the same email, forty tickets open, and the copies still sit in everyone else's inbox.

  4. 4

    Compromised account response

    A risky sign-in gets checked with the user, and a confirmed takeover has its sessions revoked and its sign-in reset in minutes.

    Where it breaks: The password is reset, the attacker's open session keeps working, and so does the mail rule they set up.

  5. 5

    Endpoint alert containment

    A serious detection on a laptop or server gets the device isolated, the user told and a case opened, with a person approving where it matters.

    Where it breaks: The laptop is isolated at 2am, the on-call engineer's production access goes with it, and nobody told them why.

  6. 6

    Vulnerability routing

    Scanner findings are ranked on real exposure, grouped by the fix, and sent to the team that ships it.

    Where it breaks: Eleven thousand findings land in a security queue, and the ones fixed are whichever sit at the top.

  7. 7

    Bug bounty report triage

    Reports from researchers are checked for duplicates, sized and routed to the owning team, and the researcher hears back on time.

    Where it breaks: A valid report waits three weeks for an owner, and the researcher posts about it first.

Three ways to connect the security tools

  • The security tool’s own playbooks. Quick inside one product, and they stop at its edge: the HR record, the service desk, the engineering tracker and the chat thread each need their own link.
  • Custom scripts. Full control, and the team owns the fixes, credentials and monitoring for every script, including the one written during last year’s incident.
  • An integration platform. Every handoff in one place, with the same error handling, logging and access control, and a record of every action taken on an account or a device. This is Tray.ai: security operations owns the rules, IT governs the credentials.

The metrics security operations moves

What security teams measure, and which stage each number depends on.

Log source coverage
Share of the apps that matter whose security events reach the SIEM, and arrived in the last hour.
What moves it Collecting every app's events on a schedule, with an alert when a feed goes quiet. How to build SaaS security log collection 
Mean time to triage
Average time from an alert firing to somebody deciding whether it matters.
What moves it Attaching the owner, the asset and the history before the alert reaches the queue. How to build security alert triage 
Phishing time to verdict
Time from an employee reporting an email to the team deciding it is safe or malicious.
What moves it Checking each report automatically and grouping copies of the same email into one case. How to build phishing report triage 
Time to revoke access
Minutes from a confirmed account takeover to every session and token for that account being cut off.
What moves it Revoking sessions in every app the account reaches as one step, not one app at a time. How to build compromised account response 
Mean time to contain
Average time from a serious endpoint detection to the device being cut off from the network.
What moves it Isolating devices on a clear rule, with a person approving only the cases the rule can't decide. How to build endpoint alert containment 
Time to remediate by risk band
Days from a finding being raised to the fix shipping, split by how exposed the asset is.
What moves it Ranking on real exposure and sending one ticket per fix to the team that owns the service. How to build vulnerability to ticket routing 
Time to first response
Hours from a researcher submitting a report to a person replying with a decision.
What moves it Checking for duplicates and finding the owning team as soon as the report arrives. How to build bug bounty report triage 

Connectors for security teams

The systems security operations runs on, grouped by the seat each one fills. Each links to its connector page.

SIEM, logs and monitoring

Where security events land, detections fire and investigations search.

Identity

Where accounts, sessions and sign-in methods live, and where access gets cut off.

Devices, email and workspace

Where laptops are managed, mail arrives and admin events are recorded.

Code and vulnerability reports

Where the fixes ship and outside researchers report what they found.

Cases, tickets and on-call

Where security cases are worked, fixes are tracked and the right person gets paged.

Chat

Where users confirm activity, owners get asked and analysts work a case together.

Data and reporting

Where outcomes are kept, so triage time, coverage and misses can be measured.

Anything not listed connects through the full connector library, or directly through its API.

Processes next to security operations

These share systems and data with security operations without being stages of it.

Frequently asked questions

How is this different from a SOAR product?

+

A SOAR product runs playbooks inside the security stack. Most security work also reaches outside it: the HR record that says somebody is leaving, the service desk ticket, the engineering tracker that ships the fix, the chat thread where the user confirms a sign-in. Tray.ai connects all of those in the same workflow, and works alongside a SOAR product if you already run one.

Which systems does Tray.ai connect in security operations?

+

SIEM and monitoring (Splunk, Datadog, New Relic, AWS CloudWatch), identity (Okta, Azure Active Directory, OneLogin, JumpCloud), devices and workspace (Microsoft Intune, Office 365, Google Workspace), code and reports (GitHub, GitLab, HackerOne), cases and on-call (Jira, ServiceNow, FreshService, OpsGenie), plus Slack, Microsoft Teams and the warehouse. A tool without a connector, such as your EDR, connects through its API.

Should automation contain threats without a person?

+

For the clear cases, yes, because each of them can be undone. Revoking the sessions of an account whose owner says the sign-in was not them costs a false alarm one fresh sign-in. An isolated laptop keeps its link to the endpoint tool, so an analyst releases it after a check. Isolating a production server, cutting off an administrator or pulling mail from every inbox goes to a person for approval first, with the evidence already attached.

Where do AI agents fit in security operations?

+

In the reading and the summing up. Agents read a reported email and explain what is wrong with it, summarize a case for the analyst who picks it up, check a bug report against past ones for duplicates, and draft the reply to the reporter. An agent never cuts off access or isolates a device on its own. Those steps run on the security team's written rules, or wait for a person to approve them.

Can the security team run this without engineering?

+

Yes. The suppression rules, scoring weights and containment rules open in Tray Build, the visual canvas, so security operations changes them as threats change. Credentials stay in the workspace, scoped to what each workflow needs.

Do we have to replace our SIEM or EDR?

+

No. Tray.ai connects the tools you already run and carries the context between them. The stages above describe what moves between systems, not which ones you use.

Last reviewed 2 October 2026.

See security operations running on your stack.

Walk through your systems and stages with a Tray.ai expert.

Great — a couple more details

This helps us connect you with the right person. Optional, and you can skip it.

Browse the how-to guides