What you are evaluating
This is licensed software the buyer configures and staffs. AI-assisted authoring still requires human control of go-live. Torq is not a managed detection and response service.
A useful evaluation context
Evaluation is whether AI-assisted playbook authoring with human control of go-live fits how the team already works.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- HyperAgents and a Socrates orchestrator for automated case handling the buyer governs.
- Natural-language workflow building that still requires human control before production use.
- Case handling across connected security tools through workflows the customer maintains.
Where it fits in the work
- Draft a workflow in natural language for a synthetic alert, then review the generated steps before enabling it.
- Keep a human control on go-live so an AI-authored path cannot isolate hosts unattended.
- Record case handling outcomes for audit and confirm failed steps can be recovered.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
In an authorized test tenant, author a synthetic phishing workflow with natural language, require a human go-live approval, run it only against disposable test identities, and capture the case record.
Evidence to look for
The case record shows human go-live approval, actions limited to the test identities, and a recoverable failed-step path.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- Which workflow steps must stay human-gated regardless of HyperAgent suggestions?
- How are cases exported if the team later leaves Torq?
- Who is accountable when an AI-authored workflow takes an unauthorized infrastructure action, and how is that action rolled back?