← Back to blog

We are not the SOC: the pivot from service to engine

The original positioning was an AI-augmented SOC: we investigate, we deliver the verdict, the customer pays us. Three months in I threw it out. The architecture had already become something else, and the positioning was the last part of the business still describing the old thing.

What was wrong with being the SOC

Two things, and the second is the one that actually mattered.

First, it drops you into the most crowded category in security services. "AI-powered managed detection" is a sentence hundreds of companies are already saying, most of them with sales teams, reference customers and budgets. Competing there as one person is not a strategy.

Second — and this is the part I was slow to see — it contradicted the architecture I had already built. The system deploys inside the customer's own tenant. The compute runs on their cloud bill. Nothing routes through my infrastructure. That is not the cost structure of a service business, where each new customer adds delivery cost. It is the cost structure of a product, where each new customer adds almost nothing. I had built a product and was selling it as a service, which is the worst combination of the two: a product's margins priced like a service, with a service's delivery expectations attached.

The reposition

The engine, not the SOC. A managed service provider deploys it into their client's tenant, it investigates, and the provider delivers the resulting security service under their own brand. Their client may never know the engine exists.

The buyer of record is the provider, not the small business. That single change fixes several problems at once. The provider already owns the client relationship. They already bill monthly. They already think in resale margin, so a wholesale price is a familiar conversation rather than a negotiation. And the small business — who genuinely does not self-diagnose a need for security investigation, and will not buy it directly — never has to be convinced of anything.

As the SOCAs the engine
Who signsThe small businessThe service provider
Who deliversMeThe provider, under their brand
Pricing shapePer seat, negotiatedFlat per tenant, published wholesale
Tier-1 supportMineThe provider's
Who does responseAmbiguousThe provider, on access they already hold

Deployment is free, deliberately

The tooling that prepares a tenant — the scripts, the connector setup, the permission grants — is free and will stay free. This confuses people, so it is worth being explicit.

Tenant preparation is the provider's own billable work. They already charge their client for security configuration; that is a normal line on a normal invoice. Charging them for the privilege of doing work they are getting paid for is backwards, and it puts a toll gate directly in front of adoption. Free deployment tooling is what makes the thing trivially resellable, and the recurring subscription is where the money is.

The first months are free too, for a reason that is specific rather than promotional: the value of this system is partly accumulated. It learns the tenant — which alerts are routine, which service accounts are supposed to behave strangely, what the customer has already confirmed as expected. In month one, that accumulation does not exist yet. Charging full price for the noisiest month of the relationship is charging most for the least.

What the moat is, honestly

Not the investigation loop. The platform vendor is shipping agentic triage natively, and the correct planning assumption is that autonomous alert investigation becomes a cheap commodity feature. Building the story on the loop would be building it on sand.

Two things compound instead. The first is accumulated tenant context — not the facts themselves, but the mechanism that captures them: a non-expert answers a question in plain language in a chat channel, and that answer becomes a durable, operational fact that changes how future alerts are handled. Cancel and you do not return to neutral; you return to month one. That switching cost is built by the customer, out of their own answers.

The second is distribution to a segment the platform vendors will not chase: the long tail of small generalist providers running Business Premium tenants.

The uncomfortable part. In this model I am structurally incomplete. The engine investigates and advises; it does not act. Response lives with the provider, on admin access they already hold. That is a deliberate safety decision, and it also means the product is only a product when a partner is attached to it.

What this did not fix

Positioning is a hypothesis about who buys and why. Mine was coherent, internally consistent, and aligned with the architecture — and it produced zero conversions over the following quarter, for reasons that had nothing to do with whether the positioning was correct.

Getting the model right is necessary and it is not sufficient, and I spent considerably longer on the necessary half than on the other one.

Who is writing this

I am Ivan Melekhin. Twenty-five years in cybersecurity, most of the last decade running security operations — building and operating distributed SOC and MSSP teams across Asia-Pacific, with a long detour through OT and maritime environments. This log is the build record for an autonomous SOC investigation agent I started in January 2026, written as the decisions happened rather than tidied up afterwards. I am on LinkedIn if you want to argue with any of it.