# How Much Autonomy Should You Give AI Agents in Your SOC? Page: https://stenobird.com/podcast/defense-in-depth-427616/how-much-autonomy-should-you-give-ai-agents-in-your-soc Text version: https://stenobird.com/podcast/defense-in-depth-427616/how-much-autonomy-should-you-give-ai-agents-in-your-soc.md Podcast: [Defense in Depth](https://stenobird.com/podcast/defense-in-depth-427616) Published: 2026-02-19T11:00:00+00:00 Episode link: https://defenseindepth.libsyn.com/how-much-autonomy-should-you-give-ai-agents-in-your-soc Audio file: https://traffic.libsyn.com/secure/defenseindepth/Defense_in_Depth_02-19-26.mp3?dest-id=1020683 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/defense-in-depth-427616/episodes/how-much-autonomy-should-you-give-ai-agents-in-your-soc Duration seconds: 1879 ## Resource All links and images can be found on CISO Series . This week's episode is co-hosted by me, David Spark , the producer of CISO Series , and Steve Zalewski . Joining us is our sponsored guest, Cliff Crosland , co-founder and CEO, Scanner.dev . In this episode: Earning autonomy gradually The blast radius question The reality check Today's value, tomorrow's evolution Huge thanks to our sponsor, Scanner All your security logs end up in cloud storage like AWS S3. Scanner makes them searchable in seconds and runs real-time detections directly on that data. No pipelines, no re-ingestion. 100x faster than traditional data lakes, 10x cheaper than SIEMs. Loved by analysts. Built for AI agents. Learn more at scanner.dev . ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/defense-in-depth-427616/episodes/how-much-autonomy-should-you-give-ai-agents-in-your-soc/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/defense-in-depth-427616/how-much-autonomy-should-you-give-ai-agents-in-your-soc.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.