AI SOC · Example role composition

Security Operations Team

AI employees watch security around the clock, 365 days a year. They gather the logs from the security equipment you already have, and handle intake, analysis, response and review as separate roles.

Request a consultation
Demo video preview
Demo video · YouTube
One case, from event intake to closure
Video in preparation · click to request a demo

Watching over the equipment —
AI employees do it, through the night too.

A security operations centre (SOC) is not a piece of equipment such as a firewall. It is the operational work of watching, in real time, the logs and anomaly signals that equipment produces, and investigating and responding when something is a threat.

Sketch of picking out anomaly signals from the logs a device produces and sending them to monitoring
Sketch of alerts piling up beside an empty monitoring desk at night

Until a single event
is closed.

When an event comes in, a case is opened and analysed, action is taken within the approved scope, and the result is read back, reviewed and closed.

Sketch of the flow from an event through case creation, analysis, action and read-back to closure, with reopening when needed
01
Case opened
02
Analysis and recommendation
03
Action within the approved scope
04
Read-back review
05
Close · reopen

Building, analysis, execution and review
are held by different roles.

Each role starts with one agent by default, and the operating roles scale out to several instances as the alerts to handle grow.

Sketch of role separation: an alert moves along a partitioned bench through intake, analysis, action and review
Platform Builder

Builds the monitoring stack and deploys collection, rules and routing

Ticket Creator

Receives events, filters out duplicates and opens cases

Analyst

Analyses the evidence, scores IP reputation and recommends action

Action Executor

Checks the approved scope and acts only within set bounds

Leader / Reviewer

Reads the result back, approves or rejects it, and closes the case

Detection Engineer

Builds and tunes detection rules. Has no execution rights

So that nothing is blocked too broadly,
the system forbids it.

The worry of wrongly blocking a production line is reduced by design. The agents do not do the following.

Sketch of a prohibition line that stops actions such as broad blocking or changing rules, keeping the production line running
Blocking by IP range, ASN or country
Broad firewall or network changes
Changing detection rules on their own
Handling raw payloads or credentials
Fast-tracking a case that has no source IP

People move from handling tickets
to designing policy.

People no longer handle tickets themselves; they design the policy, the approval criteria and the oversight. It does not replace the security team — it frees them from repetitive work.

Sketch of a person moving from pushing a cart of manual tickets to designing policy and handling approval and oversight

Start with one server and a small PoC.

Ready-made organisations are delivered through a partner with onboarding included, and are billed in KRW. USD figures are indicative, converted at KRW 1,400 to US$1, and are not updated when exchange rates move. Amounts vary with how the organisation is composed.

Sketch of the split: you prepare the server and network, and WONDERMOVE provides the monitoring stack, detection rules, cases and audit settings
01
Prepare

You provide the server and the network. We provide the monitoring stack, detection, cases and audit records.

Sketch of stepping stones: after preparation and set-up, a small PoC, then policy tuning, move to operation and expansion
02
Test small

A PoC of about 2 to 4 weeks sets up the monitoring system first and tests it.

Sketch of weighing IP reputation, score and filters to sort cases into watch, conditional and bounded block
03
Decide on evidence

Responses are split into watching, conditional action and bounded blocking, according to reputation and evidence.

AI SOC · Organisation design example
Security Operations Team

AI employees watch security around the clock, 365 days a year. Working from Security Information and Event Management (SIEM), detection, analysis, response and review are separated into roles, and the monitored scope keeps widening.

SIEM and security monitoring tool integration included
KRW 4,200,000~/ agent · month · approx. US$3,000
Ask about pricing
Getting started
Start with one server and a small PoC.

You provide the server and the network. We provide the monitoring stack, detection, cases and audit records. A PoC of about 2 to 4 weeks sets up the monitoring system first and tests it. Responses are split into watching, conditional action and bounded blocking, according to reputation and evidence.

PoC by consultation
Request a consultation

What the price is based on

What you do yourself

Round-the-clock monitoring and analysis by people needs dedicated staff, and hiring them is hard to begin with. A ready-made organisation arrives with the role design, permission boundaries, integration and verification already done.

In real deployments the build investment has come down by hundreds of millions of won.

What the price covers

Organisation, role and permission design, monitoring stack set-up and log integration, rollout training and hands-on early operation. The partner takes on the whole onboarding.

How the number of agents is set

The number of agents needed grows with the volume of security logs collected, from a minimum of 5 up to 20. This applies to the on-premises install.

What work would
you like to hand over?

The AI team your company needs —
we start by defining the work together.

Talk to us about adoption
wondermove@clawpod.cloud
The work to hand over

Tell us the goal, the scope, and the result you expect.

The environment to work in

Tell us your work systems and the tools you need.

The boundary for human decisions

We set what requires approval and what must stop.