What you are evaluating
Optional managed SIEM is a distinct offer. Advertised mean time to respond is vendor-reported, not an independent result. The customer keeps existing tools and still must authorize auto-remediation.
A useful evaluation context
Evaluation is whether the organization wants to keep existing EDR, identity, and cloud tools and still receive staffed response.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Staffed around-the-clock SOC on customer-owned EDR, identity, and cloud tools.
- Workbench transparency so the customer can see investigations in progress.
- AI-assisted investigation (Ruxie) with auto-remediation only after analyst validation and pre-authorization.
Where it fits in the work
- Onboard the existing EDR, identity, and cloud tools Expel will monitor, plus the pre-authorization matrix.
- Investigate workbench cases and distinguish analyst-validated auto-remediation from notify-only findings.
- Hand remaining IT changes the customer did not pre-authorize, and treat managed SIEM as a separate decision.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
In an authorized test tenant using a disposable identity, pre-authorize one low-impact test action, raise a supported harmless detection, and confirm that auto-remediation waits for analyst validation before running.
Evidence to look for
The workbench shows analyst validation, the pre-authorized action only, and that production identities were not changed.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- Which auto-remediation acts are pre-authorized, and which remain customer-executed?
- Is managed SIEM in the same order form or a distinct offer?
- How are investigation narratives, IOCs, and action logs exported at termination, and do they remain in the customer's own tools?