University of South Florida researchers embedded in a working SOC for over a year built and deployed an LLM-based agentic companion to handle high-volume, low-priority tickets, with analysts using it in the final four months. They report that companion outputs were reused in analysts' closing reports in more than 90% of cases, and that analysts who shaped the companion's behaviour came to trust it more.
Why it matters
It is field evidence from a real SOC, not a benchmark, on how analysts adopt and trust an AI triage agent.
Key facts
As stated in the sources, with where to find them.
- Fieldwork ran over one year; analysts were invited to use the companion during the last four months.Abstract
- In more than 90% of cases the companion's outputs were reused in the ticket's closing report; of 108 coded tickets, 35 used the draft verbatim, 63 partially and 10 were written from scratch.Abstract; Results, Table 2
- The coded corpus is 108 tickets from six analysts (29 April to 31 July 2026); the companion was offered only to more experienced analysts. Median draft reuse was 96.7% and the mean 85.5%.Corpus and coding; Results