{"kind":"atlas-fold-public-documentation-research","notice":"Provisional editorial anchored assessments in tenths (0.0–5.0), not hands-on effectiveness or purchasing recommendations. Fractional scores include shared rubric criteria and credited source evidence. Unknown scores remain null. Compare only within the same segment, cohort and rubric version.","methodology":"https://atlasofsecurity.com/landscape/explore/methodology/","segment":{"slug":"security-operations","name":"Response orchestration & managed operations","short":"SOAR / MDR"},"reviewedAt":"2026-09-21","rubricVersion":"1.1","cohorts":[{"id":"soar-platforms","name":"SOAR platforms","scope":"Customer-operated orchestration, playbooks and incident/case response software. Deployment forms are explicit; no staffing or reliability ranking."}],"dimensions":[{"id":"maturity","name":"Operational maturity","description":"Documented repeatability of orchestration, case work and response supervision; no uptime or efficacy inference.","question":"Which operating steps and supervision points can an operator follow?","anchors":["The vendor explicitly states that this edition provides no security orchestration workflow.","An operator can execute a documented individual action.","An operator can define and run a multi-step playbook.","Playbooks operate on incident or case information with documented analyst participation and execution context.","Stage 3 plus documented testing, failure handling and change/version management.","Stage 4 plus documented recovery and controlled promotion between environments."],"refinements":[{"base":3,"criteria":[{"id":"playbook-testing","label":"Documented playbook testing or simulation procedure","weight":3},{"id":"failure-handling","label":"Documented execution-failure handling and continuation controls","weight":4},{"id":"change-version-management","label":"Documented change or version management for playbooks","weight":3}]}]},{"id":"innovation","name":"Shipped innovation","description":"Progression of documented shipped workflows against a current SOAR baseline, not novelty inferred from ordinary automation.","question":"Is a workflow demonstrated beyond routine playbooks, cases, integrations and human gates?","anchors":["The vendor explicitly states that this edition has no automation workflow.","A documented isolated automated action.","A documented multi-step workflow with conditions.","Established SOAR baseline: integrated actions, case or alert context and human participation. This stage makes no novelty claim.","A shipped workflow materially beyond the stated baseline, with a concrete documented difference and edition limits.","Multiple independently documented beyond-baseline workflows with operating controls and limitations."]},{"id":"breadth","name":"Capability breadth","description":"Documented functions within the selected orchestration edition; no counted connectors or claimed coverage rates.","question":"Which orchestration functions are included in the selected offering?","anchors":["The vendor explicitly states that orchestration capabilities are unavailable in this edition.","Individual action execution.","Playbook construction and incident or alert intake.","Playbooks, case/incident investigation and analyst-directed response are documented.","Stage 3 plus separate threat-intelligence management and reporting workflows documented in the same edition.","Stage 4 plus documented multi-tenant and lifecycle-administration workflows in that edition."]},{"id":"ecosystem","name":"Ecosystem & integration","description":"Documented integration configuration and extension mechanisms, not compatibility assumed from a logo list.","question":"How can operators connect existing tools and extend supported actions?","anchors":["The vendor explicitly states that external integrations are unsupported.","One documented native integration.","Configuration of external connectors or integration instances.","Reusable integration/content packages and documented configuration of actions or connectors.","Stage 3 plus a documented custom-integration SDK/API and its authentication boundaries.","Stage 4 plus documented compatibility testing and controlled update/rollback of integrations."]},{"id":"governance","name":"Governance & control","description":"Documented authorization and audit controls around automation; no guarantee of enforcement in a customer deployment.","question":"How are operator privileges, action gates and administrative changes controlled?","anchors":["The vendor explicitly states that operator access controls are absent.","A documented administrative access boundary.","Documented roles or playbook access permissions.","Documented roles/access restrictions, human action gates, and activity or administrative audit records.","Stage 3 plus separately scoped credentials and documented tenant/environment isolation limits.","Stage 4 plus documented segregation of change approval, deployment and emergency overrides."]},{"id":"operations","name":"Operator enablement","description":"Public operator procedures for building, investigating and debugging workflows.","question":"What can an operator configure and troubleshoot using the public procedures?","anchors":["The vendor explicitly states that operator tooling is unavailable.","Instructions for running an individual action.","Instructions for building and running a playbook.","Playbook construction plus case/investigation procedures and human-input handling.","Stage 3 plus a documented debugger or simulator with explicit operational cautions.","Stage 4 plus deployment health, recovery and version promotion procedures."]}],"assessments":[{"vendor":"palo-alto-cortex-orchestration","cohort":"soar-platforms","edition":"Cortex XSOAR 8 SaaS; customer-operated orchestration, excluding XSIAM and Unit 42 services","asOf":"2026-09-21","status":"research-preview","summary":"Playbooks, War Room investigation, permissions and management audit have public procedures. SaaS administration and content-pack dependencies remain deployment-specific.","dimensions":{"maturity":{"score":4,"confidence":"medium","rationale":"Debugger procedures, retry/stop/continue/error-path controls and saved playbook versions with restore establish all anchor-4 lifecycle conditions. Controlled development-to-production promotion requires an additional development-tenant license, which is not assumed in this scope; anchor 5 is not assigned.","sourceIds":["p1","p2","p6","baseline-errors","baseline-versions","baseline-licenses"]},"innovation":{"score":3,"confidence":"medium","rationale":"Playbooks and shared investigation context meet the established SOAR baseline. They do not establish a novel or uniquely effective workflow.","sourceIds":["p1","p2"]},"breadth":{"score":3,"confidence":"medium","rationale":"Playbooks and War Room investigation establish the scoped orchestration and response workflow. The license guide separates Starter SOAR from Enterprise threat-intelligence management and separately licensed multi-tenant capabilities. Those additional license tiers are not silently included to raise this score.","sourceIds":["p1","p2","baseline-licenses"]},"ecosystem":{"score":4,"confidence":"medium","rationale":"Marketplace integrations are supplemented by a Python build-your-own-integration procedure, integration-instance configuration and role-scoped API keys with expiration and authentication requirements. This establishes custom integration and auth boundaries at anchor 4. A complete compatibility-testing and integration rollback procedure is not established for anchor 5.","sourceIds":["p5","baseline-integrations","baseline-api"]},"governance":{"score":3,"confidence":"medium","rationale":"Role permissions, manual gates and management audit establish anchor 3. Named credentials, external-vault lookup and command-level integration permissions are also documented, but the full credential-plus-tenant/environment isolation requirement of anchor 4 is not established for this license scope. Default integration permissions require operator attention.","sourceIds":["p1","p3","p4","baseline-credentials","baseline-permissions","baseline-licenses"]},"operations":{"score":4,"confidence":"medium","rationale":"The debugger supplements playbook authoring and War Room investigation. It runs with the operator’s permissions and can execute real commands; manual tasks pause execution and parallel tasks may continue at breakpoints. This supports tooling with explicit cautions, not safe-by-default testing.","sourceIds":["p1","p2","p6"]}},"constraints":["Selected scope is XSOAR 8 SaaS; no XSIAM entitlement or staffed response is assumed.","Integrations depend on content packs, remote-system permissions and the configured instance.","Debugger use requires a controlled test incident and review of actions that can reach external systems.","XSOAR development tenants and multi-tenant capabilities require additional licenses; Enterprise adds threat-intelligence capabilities beyond Starter. No such entitlement is inferred from the generic XSOAR 8 SaaS scope."],"sources":[{"id":"p1","title":"Cortex XSOAR playbooks","url":"https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/what-is-a-playbook.md","accessedAt":"2026-09-21","kind":"documentation"},{"id":"p2","title":"War Room investigation","url":"https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/use-the-war-room-in-an-investigation.md","accessedAt":"2026-09-21","kind":"documentation"},{"id":"p3","title":"Role-based permissions","url":"https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/users-and-roles-management/roles-management/role-based-permissions-in-cortex-xsoar.md","accessedAt":"2026-09-21","kind":"documentation"},{"id":"p4","title":"Management audit logs","url":"https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/troubleshoot-and-reference/troubleshoot/management-audit-logs.md","accessedAt":"2026-09-21","kind":"documentation"},{"id":"p5","title":"Cortex Marketplace","url":"https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/marketplace/cortex-marketplace.md","accessedAt":"2026-09-21","kind":"documentation"},{"id":"p6","title":"Debug a playbook","url":"https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/debug-your-playbook.md","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-errors","title":"Configure script error handling in a playbook","url":"https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/configure-script-error-handling-in-a-playbook.md","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-versions","title":"Manage playbook content and saved versions","url":"https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/manage-playbook-content.md","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-integrations","title":"Configure integrations and build your own integration","url":"https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/integrations/configure-integrations.md","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-api","title":"Cortex XSOAR API authentication and roles","url":"https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/troubleshoot-and-reference/reference/cortex-xsoar-api.md","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-licenses","title":"Understand Cortex XSOAR licenses","url":"https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/learn-about-cortex-xsoar/understand-cortex-xsoar-licenses.md","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-credentials","title":"Manage integration credentials","url":"https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/integrations/manage-credentials.md","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-permissions","title":"Configure integration permissions","url":"https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/integrations/add-an-integration-instance/configure-integration-permissions.md","accessedAt":"2026-09-21","kind":"documentation"}],"name":"Cortex XSOAR and XSIAM","company":"Palo Alto Networks","profileUrl":"/landscape/vendors/palo-alto-cortex-orchestration/"},{"vendor":"splunk-soar","cohort":"soar-platforms","edition":"Splunk SOAR On-premises 6.4.1 documentation scope; customer-operated deployment","asOf":"2026-09-21","status":"research-preview","summary":"On-premises procedures document playbooks, prompt gates, asset approvals and optional audit categories. Operating the underlying deployment remains a customer responsibility.","dimensions":{"maturity":{"score":3.6,"confidence":"medium","rationale":"Existing event-context playbooks and approvals establish stage 3. Exact-version 6.4.1 procedures establish testing (+0.3) and revision history with restore (+0.3). Logging success or failure is not itself execution-failure handling, so that remaining component receives no credit.","sourceIds":["s1","s2","s6","baseline-settings","baseline-debug"],"refinement":{"base":3,"evidence":[{"criterion":"playbook-testing","rationale":"The 6.4.1 debugger procedure specifies an inactive saved playbook, test event, execution identity and artifact scope.","sourceIds":["baseline-debug"]},{"criterion":"change-version-management","rationale":"Playbook settings document viewing previous revisions and restoring an earlier revision as the current version.","sourceIds":["baseline-settings"]}]}},"innovation":{"score":3,"confidence":"medium","rationale":"Integrated playbooks and human approvals are ordinary current SOAR functions. These procedures establish the baseline without a differentiation claim.","sourceIds":["s1","s2","s6"]},"breadth":{"score":3,"confidence":"medium","rationale":"Event-context playbooks, analyst input and asset actions document orchestration and response. This scope excludes Splunk Enterprise Security and Cloud-only entitlements.","sourceIds":["s1","s2","s5"]},"ecosystem":{"score":3,"confidence":"medium","rationale":"Apps provide actions through configured assets, giving operators reusable integrations and explicit connection configuration. A supported app still needs target-specific credentials.","sourceIds":["s5"]},"governance":{"score":3,"confidence":"medium","rationale":"Roles separate privileges, asset settings govern action approvals, and audit categories record selected activity. Audit configuration is required; the presence of these options is not an enabled-by-default guarantee.","sourceIds":["s3","s4","s6"]},"operations":{"score":4,"confidence":"medium","rationale":"Data Preview and the debugger provide testing and logged block output for saved, inactive playbooks. Safe Mode depends on connector action classifications, does not propagate to child playbooks and is not preserved on export. These explicit cautions meet anchor 4; complete health, recovery and promotion procedures remain unverified.","sourceIds":["s1","baseline-debug","baseline-settings"]}},"constraints":["The fetched legacy documentation identifies release 6.4.1; verify the deployed supported release and upgrade requirements.","Most configurable audit tracking is disabled by default; action and playbook executions are logged even when those categories are disabled.","Unauthenticated prompt links are inappropriate for sensitive response approvals; use the documented authenticated or asset-approval controls.","This on-premises scope carries different hosting duties from the other SaaS pilots; no reliability or effort ranking is implied.","In 6.4.1, Safe Mode must be set separately on child playbooks; Active, Logging, Safe Mode and automatic-run settings do not persist in exported playbooks. Enterprise Security finding-based debugging requires a separately paired ES instance."],"sources":[{"id":"s1","title":"Automate analyst workflows with playbooks","url":"https://docs.splunk.com/Documentation/SOARonprem/latest/Playbook/Overview","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"Prompt blocks","url":"https://docs.splunk.com/Documentation/SOARonprem/latest/Playbook/PromptBlock","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"Roles and permissions","url":"https://docs.splunk.com/Documentation/SOARonprem/latest/Admin/Roles","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"Audit trail logs","url":"https://docs.splunk.com/Documentation/SOARonprem/latest/Admin/Audit","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s5","title":"Apps and assets","url":"https://docs.splunk.com/Documentation/SOARonprem/latest/Admin/AppsAssets","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s6","title":"Approve actions before execution","url":"https://docs.splunk.com/Documentation/SOARonprem/latest/User/Actions","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-settings","title":"Manage playbook settings and revision history (6.4.1)","url":"https://help.splunk.com/en/splunk-soar/soar-on-premises/build-playbooks/6.4.1/manage-playbooks-and-playbook-settings/manage-settings-for-a-playbook-in-splunk-soar-on-premises","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-debug","title":"Data Preview and playbook debugger (6.4.1)","url":"https://help.splunk.com/en/splunk-soar/soar-on-premises/build-playbooks/6.4.1/use-the-playbook-editor-to-create-and-view-playbooks-to-automate-analyst-workflows/use-data-preview-to-build-test-and-edit-splunk-soar-on-premises-playbooks","accessedAt":"2026-09-21","kind":"documentation"}],"name":"Splunk SOAR","company":"Cisco","profileUrl":"/landscape/vendors/splunk-soar/"},{"vendor":"google-security-operations-soar","cohort":"soar-platforms","edition":"Google Security Operations SOAR documented legacy case/playbook workflows; exclude Pre-GA enhanced Cases","asOf":"2026-09-21","status":"research-preview","summary":"Case investigation, playbook approval links, permissions, audit and simulation have public procedures. Google Cloud migration and simulator side effects require explicit validation.","dimensions":{"maturity":{"score":4,"confidence":"medium","rationale":"The simulator and explicit stop/skip/fallback controls are supplemented by the documented GitSync power-up for committing, backing up and moving playbooks through Git. Together they establish testing, failure handling and change management at anchor 4. GitSync requires configured repository authentication and privileged SOAR credentials; complete anchor-5 recovery and controlled promotion are not inferred.","sourceIds":["g1","g2","g3","g8","g9","baseline-gitsync"]},"innovation":{"score":3,"confidence":"medium","rationale":"Case-context playbooks and human approval are the established SOAR baseline. The simulator is useful tooling, but no novelty or market-first claim is made.","sourceIds":["g1","g2","g3"]},"breadth":{"score":3,"confidence":"medium","rationale":"Documented case investigation, playbook automation and human-input actions cover the selected orchestration scope. SIEM detection quality and MDR staffing are excluded.","sourceIds":["g1","g2","g3"]},"ecosystem":{"score":3,"confidence":"medium","rationale":"Content Hub packages integrations and workflows; connector procedures describe how external alerts enter cases. Integration permissions and maintenance remain customer checks.","sourceIds":["g6","g7"]},"governance":{"score":3,"confidence":"medium","rationale":"Playbook permissions, approval-link actions and the Audit page document access boundaries, human gates and activity records. Migration-specific IAM behavior must be verified for the tenant.","sourceIds":["g3","g4","g5"]},"operations":{"score":4,"confidence":"medium","rationale":"Simulator procedures explain inspecting steps and using test cases, including a warning that saved simulated data on active playbooks can affect incoming production cases. This is not a blanket safe-simulation guarantee.","sourceIds":["g1","g2","g3","g8"]}},"constraints":["Verify package entitlements, migrated versus standalone tenancy and the current permissions model.","Enhanced unified Cases features marked Pre-GA are outside this assessment.","Simulator changes saved on an active playbook can affect production cases; use controlled test cases and review external actions.","MDR services and SIEM detection efficacy are outside this software cohort.","GitSync is an explicitly configured power-up with repository credentials and privileged SOAR API access; its version-control workflow does not establish isolated test environments or a complete disaster-recovery procedure."],"sources":[{"id":"g1","title":"Playbook and automation overview","url":"https://docs.cloud.google.com/chronicle/docs/soar/respond/working-with-playbooks/whats-on-the-playbooks-screen","accessedAt":"2026-09-21","kind":"documentation"},{"id":"g2","title":"Investigation and case management overview","url":"https://docs.cloud.google.com/chronicle/docs/soar/investigate/working-with-cases/cases-overview","accessedAt":"2026-09-21","kind":"documentation"},{"id":"g3","title":"Assign approval links in actions","url":"https://docs.cloud.google.com/chronicle/docs/soar/respond/working-with-playbooks/assign-approval-links-in-actions","accessedAt":"2026-09-21","kind":"documentation"},{"id":"g4","title":"Manage playbook permissions","url":"https://docs.cloud.google.com/chronicle/docs/soar/respond/working-with-playbooks/playbook-permissions","accessedAt":"2026-09-21","kind":"documentation"},{"id":"g5","title":"Monitor user activities","url":"https://docs.cloud.google.com/chronicle/docs/soar/admin-tasks/advanced/monitoring-user-activities","accessedAt":"2026-09-21","kind":"documentation"},{"id":"g6","title":"SOAR Content Hub","url":"https://docs.cloud.google.com/chronicle/docs/soar/marketplace/using-the-marketplace","accessedAt":"2026-09-21","kind":"documentation"},{"id":"g7","title":"Ingest through SOAR connectors","url":"https://docs.cloud.google.com/chronicle/docs/soar/ingest/connectors/ingest-your-data-connectors","accessedAt":"2026-09-21","kind":"documentation"},{"id":"g8","title":"Test playbooks with the simulator","url":"https://docs.cloud.google.com/chronicle/docs/soar/respond/working-with-playbooks/working-with-playbook-simulator","accessedAt":"2026-09-21","kind":"documentation"},{"id":"g9","title":"Manage playbook flows","url":"https://docs.cloud.google.com/chronicle/docs/soar/respond/working-with-playbooks/using-flows-in-playbooks","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-gitsync","title":"GitSync: version control and migration for SOAR playbooks","url":"https://docs.cloud.google.com/chronicle/docs/soar/marketplace/power-ups/gitsync","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-ide","title":"Develop and debug custom SOAR components in the IDE","url":"https://docs.cloud.google.com/chronicle/docs/soar/respond/ide/using-the-ide","accessedAt":"2026-09-21","kind":"documentation"}],"name":"Google Security Operations SOAR","company":"Google","profileUrl":"/landscape/vendors/google-security-operations-soar/"}],"scenarios":[{"id":"human-approval","name":"Supervised response","description":"Review how analysts approve disruptive actions and investigate failures.","priorities":["governance","operations"],"questions":["Which actions require an authenticated approver?","Which logs show who approved, executed and changed a workflow?"]},{"id":"existing-toolchain","name":"Existing security tools","description":"Validate connectors and the operational duties of the selected hosting model.","priorities":["ecosystem","maturity"],"questions":["Which exact connector and remote API versions are supported?","Who maintains the deployment, credentials and content-pack updates?"]}],"researchNotes":["These are provisional public-documentation evidence stages, not observed effectiveness, reliability, effort savings, or product quality. Unknown evidence is null; zero requires affirmative documented absence. A supported stage is not a claim that undocumented higher stages are absent.","The current baseline is established commercial functionality. Innovation stage 3 means a documented baseline workflow, without a novelty or market-leadership claim. Higher stages require explicit shipped workflows and a defensible difference from that baseline; preview and AI branding do not qualify.","The assessments use primary public sources. No product deployment, customer-tenant testing or performance measurement was performed.","Staffed MDR services are not assessed by this SOAR software rubric. They require a separate cohort and service-specific rubric before scoring; the unassessed catalog includes those services.","The reviewed Splunk SOAR sources describe version 6.4.1. Some later automated link checks were blocked; that access limitation is not evidence of a missing product capability.","Rubric 1.1 adds evidence-backed tenths only for supported components of the next maturity anchor. The same criterion weights apply to every offering in this comparison group. Uncredited components are not established by this review, not proven absent. Innovation scores remain unchanged: ordinary baseline workflows do not earn decimal novelty credit.","All six dimensions were re-reviewed for the 2026-09-21 momentum baseline. Additional source-backed anchor and evidence-gap corrections are documented in docs/research/2026-09-21-momentum-baseline-b.md. These are baseline research corrections, not measured vendor progress; historical comparisons require later comparable review snapshots."],"history":{"segment":"security-operations","snapshots":[{"id":"2026-09-21","publishedAt":"2026-09-21","kind":"baseline","research":{"segment":"security-operations","reviewedAt":"2026-09-21","rubricVersion":"1.1","cohorts":[{"id":"soar-platforms","name":"SOAR platforms","scope":"Customer-operated orchestration, playbooks and incident/case response software. Deployment forms are explicit; no staffing or reliability ranking."}],"dimensions":[{"id":"maturity","name":"Operational maturity","description":"Documented repeatability of orchestration, case work and response supervision; no uptime or efficacy inference.","question":"Which operating steps and supervision points can an operator follow?","anchors":["The vendor explicitly states that this edition provides no security orchestration workflow.","An operator can execute a documented individual action.","An operator can define and run a multi-step playbook.","Playbooks operate on incident or case information with documented analyst participation and execution context.","Stage 3 plus documented testing, failure handling and change/version management.","Stage 4 plus documented recovery and controlled promotion between environments."],"refinements":[{"base":3,"criteria":[{"id":"playbook-testing","label":"Documented playbook testing or simulation procedure","weight":3},{"id":"failure-handling","label":"Documented execution-failure handling and continuation controls","weight":4},{"id":"change-version-management","label":"Documented change or version management for playbooks","weight":3}]}]},{"id":"innovation","name":"Shipped innovation","description":"Progression of documented shipped workflows against a current SOAR baseline, not novelty inferred from ordinary automation.","question":"Is a workflow demonstrated beyond routine playbooks, cases, integrations and human gates?","anchors":["The vendor explicitly states that this edition has no automation workflow.","A documented isolated automated action.","A documented multi-step workflow with conditions.","Established SOAR baseline: integrated actions, case or alert context and human participation. This stage makes no novelty claim.","A shipped workflow materially beyond the stated baseline, with a concrete documented difference and edition limits.","Multiple independently documented beyond-baseline workflows with operating controls and limitations."]},{"id":"breadth","name":"Capability breadth","description":"Documented functions within the selected orchestration edition; no counted connectors or claimed coverage rates.","question":"Which orchestration functions are included in the selected offering?","anchors":["The vendor explicitly states that orchestration capabilities are unavailable in this edition.","Individual action execution.","Playbook construction and incident or alert intake.","Playbooks, case/incident investigation and analyst-directed response are documented.","Stage 3 plus separate threat-intelligence management and reporting workflows documented in the same edition.","Stage 4 plus documented multi-tenant and lifecycle-administration workflows in that edition."]},{"id":"ecosystem","name":"Ecosystem & integration","description":"Documented integration configuration and extension mechanisms, not compatibility assumed from a logo list.","question":"How can operators connect existing tools and extend supported actions?","anchors":["The vendor explicitly states that external integrations are unsupported.","One documented native integration.","Configuration of external connectors or integration instances.","Reusable integration/content packages and documented configuration of actions or connectors.","Stage 3 plus a documented custom-integration SDK/API and its authentication boundaries.","Stage 4 plus documented compatibility testing and controlled update/rollback of integrations."]},{"id":"governance","name":"Governance & control","description":"Documented authorization and audit controls around automation; no guarantee of enforcement in a customer deployment.","question":"How are operator privileges, action gates and administrative changes controlled?","anchors":["The vendor explicitly states that operator access controls are absent.","A documented administrative access boundary.","Documented roles or playbook access permissions.","Documented roles/access restrictions, human action gates, and activity or administrative audit records.","Stage 3 plus separately scoped credentials and documented tenant/environment isolation limits.","Stage 4 plus documented segregation of change approval, deployment and emergency overrides."]},{"id":"operations","name":"Operator enablement","description":"Public operator procedures for building, investigating and debugging workflows.","question":"What can an operator configure and troubleshoot using the public procedures?","anchors":["The vendor explicitly states that operator tooling is unavailable.","Instructions for running an individual action.","Instructions for building and running a playbook.","Playbook construction plus case/investigation procedures and human-input handling.","Stage 3 plus a documented debugger or simulator with explicit operational cautions.","Stage 4 plus deployment health, recovery and version promotion procedures."]}],"assessments":[{"vendor":"palo-alto-cortex-orchestration","cohort":"soar-platforms","edition":"Cortex XSOAR 8 SaaS; customer-operated orchestration, excluding XSIAM and Unit 42 services","asOf":"2026-09-21","status":"research-preview","summary":"Playbooks, War Room investigation, permissions and management audit have public procedures. SaaS administration and content-pack dependencies remain deployment-specific.","dimensions":{"maturity":{"score":4,"confidence":"medium","rationale":"Debugger procedures, retry/stop/continue/error-path controls and saved playbook versions with restore establish all anchor-4 lifecycle conditions. Controlled development-to-production promotion requires an additional development-tenant license, which is not assumed in this scope; anchor 5 is not assigned.","sourceIds":["p1","p2","p6","baseline-errors","baseline-versions","baseline-licenses"]},"innovation":{"score":3,"confidence":"medium","rationale":"Playbooks and shared investigation context meet the established SOAR baseline. They do not establish a novel or uniquely effective workflow.","sourceIds":["p1","p2"]},"breadth":{"score":3,"confidence":"medium","rationale":"Playbooks and War Room investigation establish the scoped orchestration and response workflow. The license guide separates Starter SOAR from Enterprise threat-intelligence management and separately licensed multi-tenant capabilities. Those additional license tiers are not silently included to raise this score.","sourceIds":["p1","p2","baseline-licenses"]},"ecosystem":{"score":4,"confidence":"medium","rationale":"Marketplace integrations are supplemented by a Python build-your-own-integration procedure, integration-instance configuration and role-scoped API keys with expiration and authentication requirements. This establishes custom integration and auth boundaries at anchor 4. A complete compatibility-testing and integration rollback procedure is not established for anchor 5.","sourceIds":["p5","baseline-integrations","baseline-api"]},"governance":{"score":3,"confidence":"medium","rationale":"Role permissions, manual gates and management audit establish anchor 3. Named credentials, external-vault lookup and command-level integration permissions are also documented, but the full credential-plus-tenant/environment isolation requirement of anchor 4 is not established for this license scope. Default integration permissions require operator attention.","sourceIds":["p1","p3","p4","baseline-credentials","baseline-permissions","baseline-licenses"]},"operations":{"score":4,"confidence":"medium","rationale":"The debugger supplements playbook authoring and War Room investigation. It runs with the operator’s permissions and can execute real commands; manual tasks pause execution and parallel tasks may continue at breakpoints. This supports tooling with explicit cautions, not safe-by-default testing.","sourceIds":["p1","p2","p6"]}},"constraints":["Selected scope is XSOAR 8 SaaS; no XSIAM entitlement or staffed response is assumed.","Integrations depend on content packs, remote-system permissions and the configured instance.","Debugger use requires a controlled test incident and review of actions that can reach external systems.","XSOAR development tenants and multi-tenant capabilities require additional licenses; Enterprise adds threat-intelligence capabilities beyond Starter. No such entitlement is inferred from the generic XSOAR 8 SaaS scope."],"sources":[{"id":"p1","title":"Cortex XSOAR playbooks","url":"https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/what-is-a-playbook.md","accessedAt":"2026-09-21","kind":"documentation"},{"id":"p2","title":"War Room investigation","url":"https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/investigate-and-respond-to-threats/incidents-and-indicators-investigation/investigate-an-incident/use-the-war-room-in-an-investigation.md","accessedAt":"2026-09-21","kind":"documentation"},{"id":"p3","title":"Role-based permissions","url":"https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/users-and-roles-management/roles-management/role-based-permissions-in-cortex-xsoar.md","accessedAt":"2026-09-21","kind":"documentation"},{"id":"p4","title":"Management audit logs","url":"https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/troubleshoot-and-reference/troubleshoot/management-audit-logs.md","accessedAt":"2026-09-21","kind":"documentation"},{"id":"p5","title":"Cortex Marketplace","url":"https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/marketplace/cortex-marketplace.md","accessedAt":"2026-09-21","kind":"documentation"},{"id":"p6","title":"Debug a playbook","url":"https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/debug-your-playbook.md","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-errors","title":"Configure script error handling in a playbook","url":"https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/develop-your-playbook/task-3.-add-tasks/configure-script-error-handling-in-a-playbook.md","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-versions","title":"Manage playbook content and saved versions","url":"https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/playbooks/manage-playbook-content.md","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-integrations","title":"Configure integrations and build your own integration","url":"https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/integrations/configure-integrations.md","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-api","title":"Cortex XSOAR API authentication and roles","url":"https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/troubleshoot-and-reference/reference/cortex-xsoar-api.md","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-licenses","title":"Understand Cortex XSOAR licenses","url":"https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/learn-about-cortex-xsoar/understand-cortex-xsoar-licenses.md","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-credentials","title":"Manage integration credentials","url":"https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/integrations/manage-credentials.md","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-permissions","title":"Configure integration permissions","url":"https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-saas/configure-cortex-xsoar/integrations/add-an-integration-instance/configure-integration-permissions.md","accessedAt":"2026-09-21","kind":"documentation"}]},{"vendor":"splunk-soar","cohort":"soar-platforms","edition":"Splunk SOAR On-premises 6.4.1 documentation scope; customer-operated deployment","asOf":"2026-09-21","status":"research-preview","summary":"On-premises procedures document playbooks, prompt gates, asset approvals and optional audit categories. Operating the underlying deployment remains a customer responsibility.","dimensions":{"maturity":{"score":3.6,"confidence":"medium","rationale":"Existing event-context playbooks and approvals establish stage 3. Exact-version 6.4.1 procedures establish testing (+0.3) and revision history with restore (+0.3). Logging success or failure is not itself execution-failure handling, so that remaining component receives no credit.","sourceIds":["s1","s2","s6","baseline-settings","baseline-debug"],"refinement":{"base":3,"evidence":[{"criterion":"playbook-testing","rationale":"The 6.4.1 debugger procedure specifies an inactive saved playbook, test event, execution identity and artifact scope.","sourceIds":["baseline-debug"]},{"criterion":"change-version-management","rationale":"Playbook settings document viewing previous revisions and restoring an earlier revision as the current version.","sourceIds":["baseline-settings"]}]}},"innovation":{"score":3,"confidence":"medium","rationale":"Integrated playbooks and human approvals are ordinary current SOAR functions. These procedures establish the baseline without a differentiation claim.","sourceIds":["s1","s2","s6"]},"breadth":{"score":3,"confidence":"medium","rationale":"Event-context playbooks, analyst input and asset actions document orchestration and response. This scope excludes Splunk Enterprise Security and Cloud-only entitlements.","sourceIds":["s1","s2","s5"]},"ecosystem":{"score":3,"confidence":"medium","rationale":"Apps provide actions through configured assets, giving operators reusable integrations and explicit connection configuration. A supported app still needs target-specific credentials.","sourceIds":["s5"]},"governance":{"score":3,"confidence":"medium","rationale":"Roles separate privileges, asset settings govern action approvals, and audit categories record selected activity. Audit configuration is required; the presence of these options is not an enabled-by-default guarantee.","sourceIds":["s3","s4","s6"]},"operations":{"score":4,"confidence":"medium","rationale":"Data Preview and the debugger provide testing and logged block output for saved, inactive playbooks. Safe Mode depends on connector action classifications, does not propagate to child playbooks and is not preserved on export. These explicit cautions meet anchor 4; complete health, recovery and promotion procedures remain unverified.","sourceIds":["s1","baseline-debug","baseline-settings"]}},"constraints":["The fetched legacy documentation identifies release 6.4.1; verify the deployed supported release and upgrade requirements.","Most configurable audit tracking is disabled by default; action and playbook executions are logged even when those categories are disabled.","Unauthenticated prompt links are inappropriate for sensitive response approvals; use the documented authenticated or asset-approval controls.","This on-premises scope carries different hosting duties from the other SaaS pilots; no reliability or effort ranking is implied.","In 6.4.1, Safe Mode must be set separately on child playbooks; Active, Logging, Safe Mode and automatic-run settings do not persist in exported playbooks. Enterprise Security finding-based debugging requires a separately paired ES instance."],"sources":[{"id":"s1","title":"Automate analyst workflows with playbooks","url":"https://docs.splunk.com/Documentation/SOARonprem/latest/Playbook/Overview","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s2","title":"Prompt blocks","url":"https://docs.splunk.com/Documentation/SOARonprem/latest/Playbook/PromptBlock","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s3","title":"Roles and permissions","url":"https://docs.splunk.com/Documentation/SOARonprem/latest/Admin/Roles","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s4","title":"Audit trail logs","url":"https://docs.splunk.com/Documentation/SOARonprem/latest/Admin/Audit","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s5","title":"Apps and assets","url":"https://docs.splunk.com/Documentation/SOARonprem/latest/Admin/AppsAssets","accessedAt":"2026-09-21","kind":"documentation"},{"id":"s6","title":"Approve actions before execution","url":"https://docs.splunk.com/Documentation/SOARonprem/latest/User/Actions","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-settings","title":"Manage playbook settings and revision history (6.4.1)","url":"https://help.splunk.com/en/splunk-soar/soar-on-premises/build-playbooks/6.4.1/manage-playbooks-and-playbook-settings/manage-settings-for-a-playbook-in-splunk-soar-on-premises","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-debug","title":"Data Preview and playbook debugger (6.4.1)","url":"https://help.splunk.com/en/splunk-soar/soar-on-premises/build-playbooks/6.4.1/use-the-playbook-editor-to-create-and-view-playbooks-to-automate-analyst-workflows/use-data-preview-to-build-test-and-edit-splunk-soar-on-premises-playbooks","accessedAt":"2026-09-21","kind":"documentation"}]},{"vendor":"google-security-operations-soar","cohort":"soar-platforms","edition":"Google Security Operations SOAR documented legacy case/playbook workflows; exclude Pre-GA enhanced Cases","asOf":"2026-09-21","status":"research-preview","summary":"Case investigation, playbook approval links, permissions, audit and simulation have public procedures. Google Cloud migration and simulator side effects require explicit validation.","dimensions":{"maturity":{"score":4,"confidence":"medium","rationale":"The simulator and explicit stop/skip/fallback controls are supplemented by the documented GitSync power-up for committing, backing up and moving playbooks through Git. Together they establish testing, failure handling and change management at anchor 4. GitSync requires configured repository authentication and privileged SOAR credentials; complete anchor-5 recovery and controlled promotion are not inferred.","sourceIds":["g1","g2","g3","g8","g9","baseline-gitsync"]},"innovation":{"score":3,"confidence":"medium","rationale":"Case-context playbooks and human approval are the established SOAR baseline. The simulator is useful tooling, but no novelty or market-first claim is made.","sourceIds":["g1","g2","g3"]},"breadth":{"score":3,"confidence":"medium","rationale":"Documented case investigation, playbook automation and human-input actions cover the selected orchestration scope. SIEM detection quality and MDR staffing are excluded.","sourceIds":["g1","g2","g3"]},"ecosystem":{"score":3,"confidence":"medium","rationale":"Content Hub packages integrations and workflows; connector procedures describe how external alerts enter cases. Integration permissions and maintenance remain customer checks.","sourceIds":["g6","g7"]},"governance":{"score":3,"confidence":"medium","rationale":"Playbook permissions, approval-link actions and the Audit page document access boundaries, human gates and activity records. Migration-specific IAM behavior must be verified for the tenant.","sourceIds":["g3","g4","g5"]},"operations":{"score":4,"confidence":"medium","rationale":"Simulator procedures explain inspecting steps and using test cases, including a warning that saved simulated data on active playbooks can affect incoming production cases. This is not a blanket safe-simulation guarantee.","sourceIds":["g1","g2","g3","g8"]}},"constraints":["Verify package entitlements, migrated versus standalone tenancy and the current permissions model.","Enhanced unified Cases features marked Pre-GA are outside this assessment.","Simulator changes saved on an active playbook can affect production cases; use controlled test cases and review external actions.","MDR services and SIEM detection efficacy are outside this software cohort.","GitSync is an explicitly configured power-up with repository credentials and privileged SOAR API access; its version-control workflow does not establish isolated test environments or a complete disaster-recovery procedure."],"sources":[{"id":"g1","title":"Playbook and automation overview","url":"https://docs.cloud.google.com/chronicle/docs/soar/respond/working-with-playbooks/whats-on-the-playbooks-screen","accessedAt":"2026-09-21","kind":"documentation"},{"id":"g2","title":"Investigation and case management overview","url":"https://docs.cloud.google.com/chronicle/docs/soar/investigate/working-with-cases/cases-overview","accessedAt":"2026-09-21","kind":"documentation"},{"id":"g3","title":"Assign approval links in actions","url":"https://docs.cloud.google.com/chronicle/docs/soar/respond/working-with-playbooks/assign-approval-links-in-actions","accessedAt":"2026-09-21","kind":"documentation"},{"id":"g4","title":"Manage playbook permissions","url":"https://docs.cloud.google.com/chronicle/docs/soar/respond/working-with-playbooks/playbook-permissions","accessedAt":"2026-09-21","kind":"documentation"},{"id":"g5","title":"Monitor user activities","url":"https://docs.cloud.google.com/chronicle/docs/soar/admin-tasks/advanced/monitoring-user-activities","accessedAt":"2026-09-21","kind":"documentation"},{"id":"g6","title":"SOAR Content Hub","url":"https://docs.cloud.google.com/chronicle/docs/soar/marketplace/using-the-marketplace","accessedAt":"2026-09-21","kind":"documentation"},{"id":"g7","title":"Ingest through SOAR connectors","url":"https://docs.cloud.google.com/chronicle/docs/soar/ingest/connectors/ingest-your-data-connectors","accessedAt":"2026-09-21","kind":"documentation"},{"id":"g8","title":"Test playbooks with the simulator","url":"https://docs.cloud.google.com/chronicle/docs/soar/respond/working-with-playbooks/working-with-playbook-simulator","accessedAt":"2026-09-21","kind":"documentation"},{"id":"g9","title":"Manage playbook flows","url":"https://docs.cloud.google.com/chronicle/docs/soar/respond/working-with-playbooks/using-flows-in-playbooks","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-gitsync","title":"GitSync: version control and migration for SOAR playbooks","url":"https://docs.cloud.google.com/chronicle/docs/soar/marketplace/power-ups/gitsync","accessedAt":"2026-09-21","kind":"documentation"},{"id":"baseline-ide","title":"Develop and debug custom SOAR components in the IDE","url":"https://docs.cloud.google.com/chronicle/docs/soar/respond/ide/using-the-ide","accessedAt":"2026-09-21","kind":"documentation"}]}],"scenarios":[{"id":"human-approval","name":"Supervised response","description":"Review how analysts approve disruptive actions and investigate failures.","priorities":["governance","operations"],"questions":["Which actions require an authenticated approver?","Which logs show who approved, executed and changed a workflow?"]},{"id":"existing-toolchain","name":"Existing security tools","description":"Validate connectors and the operational duties of the selected hosting model.","priorities":["ecosystem","maturity"],"questions":["Which exact connector and remote API versions are supported?","Who maintains the deployment, credentials and content-pack updates?"]}],"researchNotes":["These are provisional public-documentation evidence stages, not observed effectiveness, reliability, effort savings, or product quality. Unknown evidence is null; zero requires affirmative documented absence. A supported stage is not a claim that undocumented higher stages are absent.","The current baseline is established commercial functionality. Innovation stage 3 means a documented baseline workflow, without a novelty or market-leadership claim. Higher stages require explicit shipped workflows and a defensible difference from that baseline; preview and AI branding do not qualify.","The assessments use primary public sources. No product deployment, customer-tenant testing or performance measurement was performed.","Staffed MDR services are not assessed by this SOAR software rubric. They require a separate cohort and service-specific rubric before scoring; the unassessed catalog includes those services.","The reviewed Splunk SOAR sources describe version 6.4.1. Some later automated link checks were blocked; that access limitation is not evidence of a missing product capability.","Rubric 1.1 adds evidence-backed tenths only for supported components of the next maturity anchor. The same criterion weights apply to every offering in this comparison group. Uncredited components are not established by this review, not proven absent. Innovation scores remain unchanged: ordinary baseline workflows do not earn decimal novelty credit.","All six dimensions were re-reviewed for the 2026-09-21 momentum baseline. Additional source-backed anchor and evidence-gap corrections are documented in docs/research/2026-09-21-momentum-baseline-b.md. These are baseline research corrections, not measured vendor progress; historical comparisons require later comparable review snapshots."]},"changes":[]}]},"unassessed":[{"slug":"tines","name":"Tines","company":"Tines","profileUrl":"/landscape/vendors/tines/"},{"slug":"torq","name":"Torq","company":"Torq","profileUrl":"/landscape/vendors/torq/"},{"slug":"swimlane-turbine","name":"Turbine","company":"Swimlane","profileUrl":"/landscape/vendors/swimlane-turbine/"},{"slug":"fortinet-fortisoar","name":"FortiSOAR","company":"Fortinet","profileUrl":"/landscape/vendors/fortinet-fortisoar/"},{"slug":"rapid7-insightconnect","name":"Rapid7 Automation","company":"Rapid7","profileUrl":"/landscape/vendors/rapid7-insightconnect/"},{"slug":"crowdstrike-falcon-complete","name":"Falcon Complete","company":"CrowdStrike","profileUrl":"/landscape/vendors/crowdstrike-falcon-complete/"},{"slug":"microsoft-defender-experts","name":"Defender Experts MDR","company":"Microsoft","profileUrl":"/landscape/vendors/microsoft-defender-experts/"},{"slug":"sophos-mdr","name":"Sophos MDR","company":"Sophos","profileUrl":"/landscape/vendors/sophos-mdr/"},{"slug":"arctic-wolf-mdr","name":"Aurora MDR","company":"Arctic Wolf","profileUrl":"/landscape/vendors/arctic-wolf-mdr/"},{"slug":"expel","name":"Expel MDR","company":"Expel","profileUrl":"/landscape/vendors/expel/"},{"slug":"zscaler-mdr","name":"Zscaler MDR","company":"Zscaler","profileUrl":"/landscape/vendors/zscaler-mdr/"},{"slug":"esentire","name":"eSentire MDR","company":"eSentire","profileUrl":"/landscape/vendors/esentire/"},{"slug":"huntress","name":"Huntress","company":"Huntress","profileUrl":"/landscape/vendors/huntress/"},{"slug":"rapid7-mdr","name":"Rapid7 MDR","company":"Rapid7","profileUrl":"/landscape/vendors/rapid7-mdr/"},{"slug":"sentinelone-wayfinder","name":"Wayfinder MDR","company":"SentinelOne","profileUrl":"/landscape/vendors/sentinelone-wayfinder/"}]}