Atlas Fold / SOAR / MDR

SOAR / MDR, unfolded.

Response orchestration & managed operations

Atlas Fold / SOAR / MDR / First edition

Response orchestration & managed operations

Provisional editorial research based on public documentation, not tested effectiveness.

First edition · Reviewed · Rubric 1.1

Six dimensions, each scored 0.0–5.0 in tenths. Gaps stay visible.

Customer-operated orchestration, playbooks and incident/case response software. Deployment forms are explicit; no staffing or reliability ranking.

Download JSON

Six dimensions, with gaps listed

Each row is one 0.0–5.0 dimension. Every assessed offering has a consistent color, shape, and number. Numbers identify offerings, not rank. Unknown scores are omitted.

Separated marks connect to their exact positions. Separation does not change scores.

Momentum: building history. Numbers identify offerings, not rank; lines between dimensions are profiles, not time.

A position is only half the story

Momentum

Building history

Baseline recorded 2026-09-21. A second comparable review is needed to show movement.

Download dated history

Own movement is the score change. Relative movement subtracts the median change of matched peers, excluding this offering. Dimensions stay separate.

History appears as a hollow earlier mark connected to the current solid mark in Unfold and Overview. Profile lines between dimensions do not show time. Numbers identify offerings, not rank.

Review history & what changed

The 2026-09-21 baseline incorporates the six-dimension review. Decimal calibration and research corrections are not product momentum. Unknowns stay unknown.

  • 2026-09-21 · baseline · rubric 1.1 · Starting point; no movement inferred.
How momentum is calculated →

Documented scores

Cortex XSOAR and XSIAM (medium confidence) and Google Security Operations SOAR (medium confidence) are tied at documented score 4.0 for Operational maturity among assessed offerings in this comparison group.

Cortex XSOAR and XSIAM (medium confidence) and Splunk SOAR (medium confidence) and Google Security Operations SOAR (medium confidence) are tied at documented score 3.0 for Shipped innovation among assessed offerings in this comparison group. No distinction is evidenced among the scored offerings.

Unknowns and gaps

Unknown is not low quality. Marks are omitted where a required score is unknown.

  • Cortex XSOAR and XSIAM: no unknown dimensions.
  • Splunk SOAR: no unknown dimensions.
  • Google Security Operations SOAR: no unknown dimensions.

Scenario lens

A scenario highlights priorities and validation questions only. It does not rewrite scores or claim eligibility.

Selected evidence

Cortex XSOAR and XSIAM · Palo Alto Networks

Cortex XSOAR 8 SaaS; customer-operated orchestration, excluding XSIAM and Unit 42 services · Assessed 2026-09-21 · Research preview

Operational maturity

Which operating steps and supervision points can an operator follow?

Documented repeatability of orchestration, case work and response supervision; no uptime or efficacy inference.

Playbooks, War Room investigation, permissions and management audit have public procedures. SaaS administration and content-pack dependencies remain deployment-specific.

Score4.0 / 5.0medium confidence

Rationale and sources

Debugger procedures, retry/stop/continue/error-path controls and saved playbook versions with restore establish all anchor-4 lifecycle conditions. Controlled development-to-production promotion requires an additional development-tenant license, which is not assumed in this scope; anchor 5 is not assigned.

Constraints

  • Selected scope is XSOAR 8 SaaS; no XSIAM entitlement or staffed response is assumed.
  • Integrations depend on content packs, remote-system permissions and the configured instance.
  • Debugger use requires a controlled test incident and review of actions that can reach external systems.
  • XSOAR development tenants and multi-tenant capabilities require additional licenses; Enterprise adds threat-intelligence capabilities beyond Starter. No such entitlement is inferred from the generic XSOAR 8 SaaS scope.

Sources

0–5 rubric anchors

  • 0 — The vendor explicitly states that this edition provides no security orchestration workflow.
  • 1 — An operator can execute a documented individual action.
  • 2 — An operator can define and run a multi-step playbook.
  • 3 — Playbooks operate on incident or case information with documented analyst participation and execution context.
  • 4 — Stage 3 plus documented testing, failure handling and change/version management.
  • 5 — Stage 4 plus documented recovery and controlled promotion between environments.
Assessed offerings inSOAR platforms. Unknown means not scored, not low quality.
OfferingOperational maturityShipped innovationCapability breadthEcosystem & integrationGovernance & controlOperator enablement
Cortex XSOAR and XSIAM4.0 (medium)3.0 (medium)3.0 (medium)4.0 (medium)3.0 (medium)4.0 (medium)
Splunk SOAR3.6 (medium)3.0 (medium)3.0 (medium)3.0 (medium)3.0 (medium)4.0 (medium)
Google Security Operations SOAR4.0 (medium)3.0 (medium)3.0 (medium)3.0 (medium)3.0 (medium)4.0 (medium)

Not yet assessed

Unknown is explicitly not low quality. These catalog offerings have no Atlas Fold scores.

Research notes

These are provisional public-documentation evidence stages, not observed effectiveness, reliability, effort savings, or product quality. Unknown evidence is null; zero requires affirmative documented absence. A supported stage is not a claim that undocumented higher stages are absent.

The current baseline is established commercial functionality. Innovation stage 3 means a documented baseline workflow, without a novelty or market-leadership claim. Higher stages require explicit shipped workflows and a defensible difference from that baseline; preview and AI branding do not qualify.

The assessments use primary public sources. No product deployment, customer-tenant testing or performance measurement was performed.

Staffed MDR services are not assessed by this SOAR software rubric. They require a separate cohort and service-specific rubric before scoring; the unassessed catalog includes those services.

The reviewed Splunk SOAR sources describe version 6.4.1. Some later automated link checks were blocked; that access limitation is not evidence of a missing product capability.

Rubric 1.1 adds evidence-backed tenths only for supported components of the next maturity anchor. The same criterion weights apply to every offering in this comparison group. Uncredited components are not established by this review, not proven absent. Innovation scores remain unchanged: ordinary baseline workflows do not earn decimal novelty credit.

All six dimensions were re-reviewed for the 2026-09-21 momentum baseline. Additional source-backed anchor and evidence-gap corrections are documented in docs/research/2026-09-21-momentum-baseline-b.md. These are baseline research corrections, not measured vendor progress; historical comparisons require later comparable review snapshots.

How to read these scores

Scores use tenths from 0.0 to 5.0 against published anchors. Fractional scores credit documented requirements toward the next anchor; the inspector exposes the calculation. Equal evidence can still produce a tie. Null means unknown and is never treated as zero. Views never average or blend dimensions into an overall winner. Cohort membership is the only comparison boundary.

What this edition covers.

First edition · reviewed · rubric 1.1. Historical movement will require later dated assessments; no trajectory is inferred from this snapshot.

  • These are provisional public-documentation evidence stages, not observed effectiveness, reliability, effort savings, or product quality. Unknown evidence is null; zero requires affirmative documented absence. A supported stage is not a claim that undocumented higher stages are absent.
  • The current baseline is established commercial functionality. Innovation stage 3 means a documented baseline workflow, without a novelty or market-leadership claim. Higher stages require explicit shipped workflows and a defensible difference from that baseline; preview and AI branding do not qualify.
  • The assessments use primary public sources. No product deployment, customer-tenant testing or performance measurement was performed.
  • Staffed MDR services are not assessed by this SOAR software rubric. They require a separate cohort and service-specific rubric before scoring; the unassessed catalog includes those services.
  • The reviewed Splunk SOAR sources describe version 6.4.1. Some later automated link checks were blocked; that access limitation is not evidence of a missing product capability.
  • Rubric 1.1 adds evidence-backed tenths only for supported components of the next maturity anchor. The same criterion weights apply to every offering in this comparison group. Uncredited components are not established by this review, not proven absent. Innovation scores remain unchanged: ordinary baseline workflows do not earn decimal novelty credit.
  • All six dimensions were re-reviewed for the 2026-09-21 momentum baseline. Additional source-backed anchor and evidence-gap corrections are documented in docs/research/2026-09-21-momentum-baseline-b.md. These are baseline research corrections, not measured vendor progress; historical comparisons require later comparable review snapshots.

SOAR platforms

Customer-operated orchestration, playbooks and incident/case response software. Deployment forms are explicit; no staffing or reliability ranking.

Find your next idea.

Tip: press / to open search. Escape closes this window.