Solace investigates. The analyst decides whether to believe it.
Arclight/Solace · Agentic SOC · System Design
Arclight is an AI-powered security operations platform exploring human and AI collaboration in security operations. Solace runs the first-pass investigation, coordinating specialist agents to gather and connect evidence into a case the analyst can evaluate. The system takes on the investigation work, while final judgment stays with the person responsible for the outcome.
Duration
4-week sprint
Role
I designed the product and interaction architecture for Solace, defining the four-signal interaction model, specialist agent responsibilities, orchestration logic, analyst workflows, notification system and human approval experience. I also built the interactive prototype in Claude Code.
Methods
Figma · Claude Code · FigJam
Conceptual project built from a structured design sprint brief, exploring how human oversight could work within an agentic SOC. Not affiliated with, built for or deployed by any real financial institution.
The Problem
An alert that gets dismissed is the one that might matter.
Security teams already have more alerts than they can reasonably investigate. The hard part isn't finding them. It's deciding which ones deserve a person's attention.
Most AI systems are built to help analysts process alerts faster. For a SOC analyst, the harder question is whether the recommendation can be trusted.
Solace explores a different question.
Can the system decide when a human is needed in the first place?
Not every alert needs Maya. Solace can act on its own whenever the response is reversible, regardless of how serious the case looks. But some decisions cannot wait for perfect evidence.
An encoded PowerShell execution reaches Solace at 61% confidence. The evidence points toward action, but there's no time to wait for more. Blocking it is reversible, Maya can undo it before 09:30 if the call turns out wrong, and that's what lets Solace act now instead of holding the alert for her sign-off.
Reversibility decides where that boundary sits.
For a Tier 2 analyst, the cost runs in both directions. Block too aggressively and legitimate trading activity can be disrupted. Wait too long and a real threat can escalate. Automate too much without explanation and Maya loses confidence in the system's judgment.
Making uncertainty actionable matters more than making Solace look certain. The handoff to Maya should feel deliberate, not like a failure of automation.
Design the decision path first. Then decide what the system can automate.
The simpler system wasn’t necessarily the better experience.
A single agent could investigate this case. It would be simpler to build and easier to explain. But asking one model to reason across identity, network and endpoint signals often smooths over disagreement instead of exposing it. When the evidence conflicts, Maya needs to see that conflict, not a single averaged answer.
The architecture underneath the experience
Solace is the orchestration layer. The specialist agents work behind the scenes; Maya primarily interacts with the investigation state, evidence, recommendation and decision points.
Meet Solace, your shift partner.
She's always available when Maya needs to ask something, but the badge stays simple: What do you want to know?
I built the Bloom state so Solace becomes a real partner. Opening it starts a genuine dialogue, walking Maya through the evidence and the decision ahead.
Most cases start quiet.
Ambient
Solace is heads-down, correlating, executing approved low-risk actions in the background. Nothing needs her yet, so it stays out of her way. Click anytime, no urgency required.
Insight
If something starts taking shape, the pill shifts to signal a pattern is forming. Visibility, nothing more. Just Solace paying attention out loud.
Notice
If it keeps building, the pill names that shift before she ever opens the card, so she knows her judgment is actually needed now.
Bloom Card
This is not a status update. It's Solace explaining what she's confident about, where she isn't and where she needs Maya specifically.
Critical
Some threats don't get to wait for any of that: straight to a blocking modal, because it needs her judgment immediately.
Not every shift needs the same thing from her.
Triage · TRDR-114
A credential theft attempt, or routine maintenance that looks exactly like one.
Solace grouped three signals into one case. Something read the login credentials out of memory on a trading engineer's machine, a classic first step in stealing access, then used that access to reach two other machines on the network. That same pattern also matches a known credential-refresh routine, so intent isn't clear from the telemetry alone.
What is confirmed: the two machines it reached have no trading-related purpose. That's Maya's basis for acting, not the part that's still ambiguous.
The instinct with an ambiguous case is to offer more options, so nothing feels too final. But more choices under pressure just means more time spent deciding, not a better decision.
Governance · host-14
Solace was sure. The sign-off still wasn’t optional.
A host on the network is talking to a known-bad server, confirmed, 84% confidence. Solace isn't uncertain here, it's already staged the fix: cut the connection.
At 84% auto-executing was tempting. The confidence was real and every second spent waiting is a second the connection stays live. But cutting off a live production system still needs a person's sign-off, no matter how sure Solace is. Making an exception for “when the model's sure enough" would quietly undo the reason that rule exists in the first place.
Unlike Triage, where the evidence was ambiguous enough to need two different paths forward, there's no ambiguity about what should happen here. Only about who authorizes it and when. So there's just one decision: approve the containment. Confidence bought speed, not permission.
Learning Pattern
What gets to graduate and what never does.
Solace surfaces what it handled overnight, then proposes moving a specific pattern toward full autonomy. A backup script can graduate toward silence; a judgment call like the TRDR-114 override never does, no matter how many times Maya makes the same call. Some patterns don't resolve into either state yet, RDP overrides from unusual geolocations are still being calibrated, and Solace keeps asking rather than guessing.
Override outcomes update the rule immediately, but nothing surfaces that back to Maya when it matters; she'd have to go looking for it.
Three tradeoffs where the harder call was to hold something back, not to add more capability.
Full transparency would have looked more trustworthy.
Most of what Solace does happens behind the scenes. The real question was how much of that needs to surface for Maya to actually trust it.
My first answer was to show her everything: every specialist agent's role, every step of the reasoning. It felt transparent, but it turned into evidence noise, more to read, not more reason to trust it.
That doesn't make it unimportant. It just doesn't need to be part of the call she's making in the moment. The audit log exists for a different job: per-case compliance and verification, not the decision itself.
A repeated pattern would have looked like permission to act alone.
Patterns are how Solace learns from Maya to make better recommendations, not how it earns the right to decide for her.
I explored whether repeated approvals could eventually let Solace act without confirmation. But recognizing a pattern is different from replacing judgment. A script running the same action every time is predictable, an analyst making the same call repeatedly is still a decision.
In low-risk, high-confidence cases, Solace can already act, that comes from reversibility, not from a pattern repeating enough times. Learning just makes it sharper at knowing what to look at and connect. Even then, every action stays undoable.
Every serious decision would have looked the same in red.
Urgency has to inform the decision without discouraging it.
Early designs colored every high-stakes approval button red, sign-off required or not. But host-14 already has its pause built in, the mandated sign-off itself, so the button didn't need to also shout. Color would have added urgency to a decision that's supposed to be deliberate, not fast.
The real second gate isn't the color, it's what happens after. Approving opens the Bloom Card: Solace explains what it just did and gives her a window to undo it. A color can only warn her before she acts. A conversation gives her something to engage with after.
The interface was never the hard part.
Buttons, badges, colors, those are easy to get right once you know what they need to say. The hard part was deciding what Solace is never allowed to do without her and building that boundary into the product itself instead of trusting good intentions to hold under pressure.
Four behaviors carry that boundary. Each one is a specific way Solace could have quietly taken over a decision that should have stayed hers but didn't.
Controllability
Break-glass suspends all autonomous action outright, no partial version. Focus Mode is separate and lighter: it just quiets notifications so a busy shift never gets treated like a compromised one.
Human Oversight
Actions are named, “Approve: isolate 2 hosts," not “Approve." Color adds a second layer, red reserved for genuine urgency, not every serious case. A generic button gets rubber-stamped under pressure; this one makes her read what she's actually authorizing.
Calibrated Confidence
Every score ships with the specific gap driving it. “92% confident, the missing piece is whether j.martin had legitimate reason to access LSASS," not “92%" alone, because a bare number tells her to trust it, not what to go check first.
Failure Visibility
When Solace lacks sufficient data, it admits it: “no precedent found," “agents disagree," “previously overridden," instead of forcing a confident-sounding answer. If an outcome is wrong anyway, the audit log's agent trail traces why.
Next steps.
This project hasn't been tested with SOC analysts, so these are design decisions based on research and my own reasoning. Two gaps matter most.
The notification system
Ambient, Insight and Notice felt clearly differentiated while I was designing them, working through this alone and unrushed. I have no evidence they'd stay legible during an actual high-volume shift.
The correction loop
It closes on Solace's side, not Maya's. An override updates the rule, but nothing tells her at the next relevant decision, she'd have to go find it. I'd want to test whether a proactive callout builds trust or just adds noise mid-shift.
Solace can investigate, correlate evidence and recommend an action. The analyst still decides whether that action should happen.
Every security vendor is adding some version of an AI agent. The harder problem is designing one that knows where its responsibility ends and the analyst's begins.
That became Solace’s foundation. It investigates first, gathering evidence, finding patterns, building a recommendation. But it never executes anything irreversible on its own. When the evidence is weak, conflicting or carries real consequences, it stops and asks.
The real problem I kept coming back to was calibration. Showing Maya more didn't automatically mean she trusted Solace more, sometimes it just meant more to read. What mattered was whether she trusted it enough to act without switching off her own judgment.