| Tier 1 SOC | Repetitive triage, enrichment, documentation, shifts and planned hires | Human oversight, escalations, incident command and high-consequence decisions |
| SOAR | Investigation playbooks, specialist maintenance, connector work and some licensing | Approved response actions in EDR, IAM, firewall, ITSM-or a smaller SOAR footprint |
| XDR / MDR | Premium analytics, managed hunting, managed triage and per-endpoint service uplift | Endpoint prevention, telemetry, isolation and other native controls |
| MSSP | First-line monitoring, routine analysis, duplicate escalation and overflow hours | Optional response support, governance, specialist expertise and contractual coverage |
| Security stack | Duplicate analyst consoles, niche workflow tools and manual reporting | SIEM/data, identity, email, cloud, network and security systems of record |