← Back to Use Cases
Pilot Use Case 01

SOC Response: Credential Reset + Tool Access

A concrete workflow for security teams: gate the agent before IAM, SOAR, tickets, logs, or cameras are touched.

Triggeralert / event
Requesttool call
Gateauthority check
StateHOLD / route
Receiptevidence
Scenario + Requested Action

Impossible travel alert for an admin account.

A SOC agent receives an “impossible travel” alert for an admin account. It asks to disable the account, reset credentials, create an incident ticket, query logs/camera data, and notify the owner.

What Continuum Holds Before Execution

Continuum places the action in HOLD if no incident ID exists, the agent lacks response authority, the tool path touches credentials or cameras, or operator approval is missing.

Clearance / Routing Path

A security lead authenticates through the approved module and clears the action. Continuum routes only the cleared steps to IAM, SOAR, ticketing, or evidence collection — not the entire agent request.

Receipt + Buyer Proof

The receipt captures the evidence needed to prove what was requested, why it was held or cleared, and what was routed.

agent_idrequested_toolrisk_reasonHOLD / YES / NO / NULL stateapprovertimestamprouteresult_hash
Demo logic: unclear or unauthorized → HOLD before execution; approved → routed action + audit-grade receipt.