One console. Three Watcher orders. A seal on every consequential move.
You ask the Familiar in plain English. Three orders of Watchers detect, respond, and record like a senior team, and every destructive action waits for a human seal. Autonomous where you trust it, sealed where it matters.
Watchers read the omens
The Attack order correlates the signals and names what is happening, then opens and builds the inquiry. No flowchart to pre-build.
Watchers cast Spells
The Defend order casts response Spells to contain, evict, and restore, under gated authority. Every conclusion carries its evidence on one trail.
Watchers keep the Scrolls
The Scholar order documents the inquiry, collects the seals, and keeps your ticketing in sync. Autonomous where you trust it, sealed where you do not.
Watchers that reason, not flowcharts that break
Legacy SOAR makes you draw the investigation by hand and rebuild it every time a tool changes. The Attack order does the legwork instead: its Watchers read the omens, correlate the signals mapped to MITRE ATT&CK, and follow the thread the way a senior analyst would, opening and building the inquiry as they go.
- Context across endpoints, identity, email, cloud, and tickets, in one inquiry.
- Omens enriched automatically, with the evidence kept attached.
- No prebuilt flowchart to maintain when your tools change.
Decisions you can replay and defend
Investigation is creative. The record should not be. The Scholar order documents the inquiry as it unfolds: explicit, repeatable decision logic renders the call, with the evidence and a confidence value attached, all on one Scroll. The seals it collects and your ticketing stay in sync.
- The same inputs reach the same call, every time.
- Every conclusion carries its evidence, never a bare verdict.
- One trail end to end, ready to review, replay, or defend.

Actual product. Demo data.
Spells, dialed to the trust you have
Response is where most teams hold back, and rightly so. The Defend order casts response Spells mapped to MITRE D3FEND, and you set the autonomy per use case: full speed where the risk is low and the call is clean, a Seal where the blast radius is real. Spells are reversible, so a confident automated cast never becomes a one-way door.
- Block, isolate, reset, or escalate across the tools you already run.
- A per-use-case autonomy dial, with a Seal on every destructive cast.
- Reversible Spells, never a one-way door.
Three Watcher orders, one inquiry.
Not a vague society of agents. A concrete division of labor: Attack detects, Defend responds, Scholar records. The Familiar commands all three.
Read the omens, correlate the signals, and name what is happening. They open and build the inquiry.
ATT&CK
Cast response spells to contain, evict, and restore, under gated authority. Destructive casts pause at a seal.
D3FEND
Document the inquiry, collect the seals, and keep your ticketing in sync: Jira, ServiceNow, Resilient.
& sync
Omens in. Sealed response out.
Read the omens, correlate the signals, and name what is happening. They open and build the inquiry.
ATT&CK
Cast response spells to contain, evict, and restore, under gated authority. Destructive casts pause at a seal.
D3FEND
Document the inquiry, collect the seals, and keep your ticketing in sync: Jira, ServiceNow, Resilient.
& sync
One verdict hides the truth. A spread shows it.
Most tools collapse a threat into a single score and move on. Soarcery surfaces a native, in-workflow multi-engine verdict spread inside the investigation, not a separate lookup. You see where engines agree, where they disagree, and how confident the call really is, right where the agent is working.
Disagreement is signal. Instead of averaging the engines into one number and losing the nuance, Soarcery keeps the spread intact and turns it into a control: a confidence spread value drives the escalation threshold, and the threshold is yours to set per use case.
Engines agree, high confidence
A tight spread means the engines line up. Low spread, safe to auto-act within the threshold you set.
Engines split, contested
A wide spread means the engines disagree. The call is contested, so Soarcery escalates instead of guessing.
Spread tracked over time
Spread is recorded across investigations, so shifting agreement on the same indicator surfaces as drift you can act on early.
Works with the tools you already run.
If it has an API, Soarcery works with it. Bring the stack you have, no rip-and-replace.
Start asking the Familiar.
A 30-minute walkthrough on your real triage flow. See the three Watcher orders detect, respond, and record, with a Seal on every consequential move, on your own alerts.