From alerts to answers — an agentic SOC analyst built by Proofpoint’s own Applied Services team, now in private preview and enhanced with OpenAI Daybreak models
Security teams don’t have a data problem. They have a prioritization problem. Alerts arrive faster than any team can review them, spread across a growing set of products, each with its own console and its own version of the truth. According to Proofpoint’s 2026 AI and Human Risk Landscape Report, nearly nine in ten global organizations have moved AI assistants beyond pilot — adding new surfaces for security teams to monitor at exactly the moment analyst capacity hasn’t kept pace.
We ran into this ourselves. Proofpoint’s own Applied Services team — the analysts who investigate and respond to incidents for our customers every day — needed a faster way to move from a raw alert to a clear, defensible next step across every product in our platform, without switching tools or writing a new query for each one.
Today, we’re introducing the Proofpoint SOC Analyst Agent — an agentic AI SOC analyst that our Applied Services team built to solve that problem for themselves. It's entering private preview with a growing number of beta customers, with general availability targeted for the end of Q3 2026. Through the Daybreak Defense Network, we’re bringing OpenAI Daybreak models into the agent’s investigation workflow, pairing Proofpoint’s security operations expertise and data with OpenAI’s cyber reasoning capabilities for authorized defensive work.
How it works
A security team asks a question or describes a task in natural language — no query language, no console-hopping. The agent plans the investigation, pulls context from connected security data across Proofpoint’s product surface (alerts, logs, DLP events, user risk signals), and returns a structured finding with a recommended next step. Any team member can create custom workflows that run on a schedule — for data security, abuse mailbox messages, and more — with routing and notification to the analysts who need them.
Why a cyber model, not just a frontier model
The hard part of an investigation is rarely reading the data. It’s answering what someone was trying to accomplish, and what they’d do next. That question takes reasoning from the actor’s side: how a lure is built to work on the person receiving it, how data gets staged and moved out of an environment without tripping policy, how a series of unremarkable actions adds up to intent.
General-purpose models are tuned to step back from exactly that reasoning. Security investigations often require analysts to examine attacker or insider techniques in detail so they can understand intent, connect activity and determine what deserves attention next.
OpenAI Daybreak models are designed to support authorized defensive security work like this. In the SOC Analyst Agent, that reasoning helps move an investigation from “these alerts fired” to “this is what the activity adds up to, and this is what to look at next.”
That same capability is exactly why the boundaries below matter as much as they do: we give the model room to reason about how an attack works. We give it no room to act.
Recommendations, not replacements
The agent is built to make a human analyst faster — not to act in their place. Every finding comes with a recommended next step, but the agent does not take that step on its own. Account changes, containment, and any other action beyond producing a finding or a report stay with a human reviewer, consistent with how our Applied Services team uses the tool today. That’s a deliberate design choice: the value of an agentic SOC analyst is in manual work between an alert and a decision — analysts spend less time pulling data across dashboards and more time on judgement calls. The human always stays in the loop.
What this looks like day to day
1. For analysts, the console doesn’t change — the workflow does. An analyst asks a question in natural language instead of writing a query, and gets back a finding with context already attached, across every connected Proofpoint product, in one place.
2. For CISOs and team leads, insight arrives on a schedule, not just on request. Recurring investigations — such as nightly threat hunts, daily escalation summaries — can run automatically and route results to the right analysts, so leadership visibility doesn’t depend on someone remembering to pull a report.
3. For every investigation, the reasoning is traceable. Every finding is auditable back to the underlying source data, so a recommendation can always be checked, not just trusted.
What this means for your organization
For most security teams, the hard part isn’t a lack of data — it’s turning that data into a prioritized, defensible next step fast enough to matter. That’s what the SOC Analyst Agent is designed to help with: natural-language access to cross-product security data, scheduled investigation and reporting workflows, and recommendations a human stays in control of.
The SOC Analyst Agent is available today in private preview to select beta customers, with general availability targeted for the end of Q3 2026 (timing subject to standard product rollout considerations). If you’d like to see it in action, reach out to your Proofpoint Applied Services team.
Frequently asked questions
What is the SOC Analyst Agent?
It’s an agentic AI SOC analyst, built by Proofpoint’s Applied Services team, that lets a security team investigate alerts and incidents in natural language across Proofpoint’s product surface, returning structured findings and recommended next steps.
Is this a Proofpoint product or an OpenAI product?
It’s a Proofpoint product. OpenAI Daybreak models power part of the agent’s investigation and reasoning capabilities through the Daybreak Defense Network. The product, data connections, workflows and policies are Proofpoint’s.
Why use a cyber-specific model instead of a general-purpose one?
Investigations require reasoning about how an attacker or an insider operates, including techniques and intent that defenders need to understand in order to investigate incidents effectively. OpenAI Daybreak models are designed to support authorized defensive security work, giving the SOC Analyst Agent additional cyber reasoning capability within Proofpoint-defined workflows and controls. The agent’s permitted actions remain constrained by Proofpoint policy regardless of which model is doing the reasoning.
Does the agent take action on its own — like disabling an account or blocking a user?
No. The agent produces findings, structured summaries, and recommended next steps. Any action beyond that — account changes, containment, or other remediation — requires human review and initiation.
How is this different from what Proofpoint Applied Services already does?
It’s the same team’s workflow, accelerated. The SOC Analyst Agent was built by our Applied Services analysts to reduce manual investigation work in their own workflows, and is now available to customers directly, in addition to continuing to support our Applied Services engagements.
What does “scheduled” or “recurring” investigation mean in practice?
You can configure an investigation — like a nightly threat hunt or a daily CISO-level escalation report — to run automatically on a schedule, with results delivered without anyone needing to request them.
Which Proofpoint products does this cover?
The private preview and beta focus on data security, including email DLP, insider threat management, and cloud DLP, with other product support in the following quarter.
Is this available now?
The SOC Analyst Agent is in private preview with select beta customers today, with general availability targeted for the end of Q3 2026. Reach out to your Proofpoint Applied Services team to learn more.