[{"data":1,"prerenderedAt":48},["ShallowReactive",2],{"blog-tag-agents":3},[4,24,37],{"id":5,"slug":6,"body":7,"html":8,"title":9,"description":10,"category":11,"tags":12,"author":17,"date":18,"year":19,"month":20,"quarter":21,"status":22,"featured":23},"2026\u002F08\u002Findustry-applications\u002Foperations-control-and-disruption-management","operations-control-and-disruption-management","\nIn aviation and logistics, disruption is normal: weather, technical faults, crew limits, port congestion, customs holds, missed connections. What separates a good day from a bad one is how quickly the operation understands the impact, agrees a recovery and executes it.\n\nIn many operations that coordination still happens over phone, radio, chat groups and whiteboards. Decisions are made well, but they aren't recorded well. Downstream teams learn about changes late.\n\n## What the application does\n\nThe **operations control** family in the Atlas provides a shared workflow for disruption:\n\n1. **Detect:** events arrive from operational systems (flight or shipment status, maintenance, crew, weather, partner messages).\n2. **Assess impact:** affected flights, shipments, crews, passengers or customers, and downstream connections.\n3. **Generate options:** recovery options such as swap, delay, cancel, reroute or re-book, with their consequences.\n4. **Decide:** the controller selects an option, with the rationale recorded.\n5. **Execute:** tasks go to the affected teams (ground handling, crew control, customer service, partners), each with an owner.\n6. **Communicate:** updates to customers and partners.\n7. **Log and learn:** an operational log of events, decisions and outcomes, available for post-event review and regulatory records.\n\n## Where AI helps\n\n- **Impact summarization:** “what does this delay break?” answered in seconds.\n- **Recovery option generation:** candidate plans scored against cost, delay minutes, crew legality and customer impact. The controller chooses.\n- **Forecasting:** disruption risk from weather and schedule patterns, so teams prepare early.\n- **Drafting communications:** customer and partner messages for review.\n- **Post-event analysis:** timelines and contributing factors compiled from the log.\n\n## Human authority stays explicit\n\nOperational decisions carry safety, regulatory and commercial consequences. The application frames AI outputs as options, never actions. It records who decided and keeps deterministic rules, such as crew duty limits or dangerous-goods constraints, as hard constraints rather than model suggestions.\n\n## Integrations\n\nOperations and scheduling systems, crew management, maintenance and technical records, passenger service or TMS\u002FWMS, partner messaging (such as airline industry message formats or EDI), weather and airport data, and customer communication platforms.\n\n## Who uses it\n\nOperations controllers and duty managers, crew and maintenance control, ground and hub operations, customer service leads and operations leadership.\n\n## First scope\n\nOne disruption type that recurs weekly, where the recovery decision and downstream tasks are currently coordinated by phone. Measure recovery time, communication lag and log completeness. Scope it in a [Solution Definition Sprint](\u002Fservices\u002Fsolution-definition-sprint).\n\nSee [logistics, transport and aviation](\u002Findustries\u002Flogistics-transport-aviation), explore the [Atlas](\u002Fatlas), or [bring us your disruption playbook](\u002Fcontact).\n","\u003Cp>In aviation and logistics, disruption is normal: weather, technical faults, crew limits, port congestion, customs holds, missed connections. What separates a good day from a bad one is how quickly the operation understands the impact, agrees a recovery and executes it.\u003C\u002Fp>\n\u003Cp>In many operations that coordination still happens over phone, radio, chat groups and whiteboards. Decisions are made well, but they aren&#39;t recorded well. Downstream teams learn about changes late.\u003C\u002Fp>\n\u003Ch2>What the application does\u003C\u002Fh2>\n\u003Cp>The \u003Cstrong>operations control\u003C\u002Fstrong> family in the Atlas provides a shared workflow for disruption:\u003C\u002Fp>\n\u003Col>\n\u003Cli>\u003Cstrong>Detect:\u003C\u002Fstrong> events arrive from operational systems (flight or shipment status, maintenance, crew, weather, partner messages).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Assess impact:\u003C\u002Fstrong> affected flights, shipments, crews, passengers or customers, and downstream connections.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Generate options:\u003C\u002Fstrong> recovery options such as swap, delay, cancel, reroute or re-book, with their consequences.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Decide:\u003C\u002Fstrong> the controller selects an option, with the rationale recorded.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Execute:\u003C\u002Fstrong> tasks go to the affected teams (ground handling, crew control, customer service, partners), each with an owner.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Communicate:\u003C\u002Fstrong> updates to customers and partners.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Log and learn:\u003C\u002Fstrong> an operational log of events, decisions and outcomes, available for post-event review and regulatory records.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch2>Where AI helps\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Cstrong>Impact summarization:\u003C\u002Fstrong> “what does this delay break?” answered in seconds.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Recovery option generation:\u003C\u002Fstrong> candidate plans scored against cost, delay minutes, crew legality and customer impact. The controller chooses.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Forecasting:\u003C\u002Fstrong> disruption risk from weather and schedule patterns, so teams prepare early.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Drafting communications:\u003C\u002Fstrong> customer and partner messages for review.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Post-event analysis:\u003C\u002Fstrong> timelines and contributing factors compiled from the log.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>Human authority stays explicit\u003C\u002Fh2>\n\u003Cp>Operational decisions carry safety, regulatory and commercial consequences. The application frames AI outputs as options, never actions. It records who decided and keeps deterministic rules, such as crew duty limits or dangerous-goods constraints, as hard constraints rather than model suggestions.\u003C\u002Fp>\n\u003Ch2>Integrations\u003C\u002Fh2>\n\u003Cp>Operations and scheduling systems, crew management, maintenance and technical records, passenger service or TMS\u002FWMS, partner messaging (such as airline industry message formats or EDI), weather and airport data, and customer communication platforms.\u003C\u002Fp>\n\u003Ch2>Who uses it\u003C\u002Fh2>\n\u003Cp>Operations controllers and duty managers, crew and maintenance control, ground and hub operations, customer service leads and operations leadership.\u003C\u002Fp>\n\u003Ch2>First scope\u003C\u002Fh2>\n\u003Cp>One disruption type that recurs weekly, where the recovery decision and downstream tasks are currently coordinated by phone. Measure recovery time, communication lag and log completeness. Scope it in a \u003Ca href=\"\u002Fservices\u002Fsolution-definition-sprint\">Solution Definition Sprint\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>See \u003Ca href=\"\u002Findustries\u002Flogistics-transport-aviation\">logistics, transport and aviation\u003C\u002Fa>, explore the \u003Ca href=\"\u002Fatlas\">Atlas\u003C\u002Fa>, or \u003Ca href=\"\u002Fcontact\">bring us your disruption playbook\u003C\u002Fa>.\u003C\u002Fp>\n","Operations control in aviation and logistics: managing disruption as a workflow","Operations-control applications that turn disruption handling into a shared, auditable workflow with AI-assisted recovery options and human decisions.","industry-applications",[13,14,15,16],"logistics-aviation","operations","human-in-the-loop","agents","fazezero-editorial","2026-08-20T00:00:00.000Z",2026,8,3,"published",false,{"id":25,"slug":26,"body":27,"html":28,"title":29,"description":30,"category":11,"tags":31,"author":17,"date":35,"year":19,"month":36,"quarter":21,"status":22,"featured":23},"2026\u002F07\u002Findustry-applications\u002Fai-in-the-soc-triage-and-investigation","ai-in-the-soc-triage-and-investigation","\nSecurity operations centres don't lack alerts. They lack analyst time. Every tool in the stack produces detections, and many are duplicates, benign or low value. Real incidents compete for attention with noise, and analysts spend a large share of their day gathering context rather than making judgements.\n\n## What the application does\n\nThe **security operations** family in the Atlas focuses on the workflow between detection and response:\n\n1. **Ingest:** alerts from SIEM, EDR, email security, identity and cloud security tools, normalized into one model.\n2. **Enrich:** asset ownership, user context, threat intelligence and related alerts attached automatically.\n3. **Correlate:** group related alerts into a single investigation.\n4. **Triage:** prioritize by severity, asset criticality and confidence.\n5. **Investigate:** a case with a timeline, evidence, notes and tasks.\n6. **Respond:** response actions through the organization's tools, with approvals for high-impact steps.\n7. **Close and learn:** a disposition, lessons learned and tuning feedback to the detection owners.\n8. **Report:** metrics for SOC leadership and control evidence for audit.\n\n## Where AI helps\n\n- **Summarization:** a plain-language summary of what happened, affected assets and the evidence so far.\n- **Triage support:** a suggested priority and likely disposition, with the reasoning shown.\n- **Investigation assistance:** suggested next queries and pivots, and drafted incident timelines.\n- **Agentic enrichment:** bounded, read-only lookups across tools to assemble context before an analyst opens the case.\n- **Reporting:** draft incident reports and management summaries.\n\n## Guardrails that matter here\n\nSecurity is where uncontrolled automation does the most damage. The application enforces:\n\n- **Read-only by default.** Enrichment agents can look, not act.\n- **Human approval for containment.** Isolating hosts, disabling accounts and blocking traffic require an analyst, and a second approver for high-impact actions.\n- **Prompt-injection awareness.** Alert content is treated as untrusted data, never as instructions.\n- **A full audit trail** of every AI suggestion, every action and who approved it.\n\nWe cover the general pattern in [agentic automation with human checkpoints](\u002Fblog\u002Fagentic-automation-with-human-checkpoints).\n\n## Who uses it\n\nSOC analysts (tier 1 to 3), incident responders, SOC managers, CISOs, and control owners who need evidence for audits.\n\n## Integrations\n\nSIEM and log platforms, EDR\u002FXDR, identity providers, email security, cloud security posture tools, ticketing and ITSM, threat intelligence feeds, and asset inventories or CMDBs.\n\n## Measuring it honestly\n\nTrack time to triage, time to contain, the share of alerts closed as benign and analyst hours per incident. Agree the baseline first. Improvements should show up in your own metrics, not in vendor claims.\n\n## Where it applies\n\nEnterprise SOCs, managed security providers, financial institutions with regulatory incident-reporting obligations, and government security operations.\n\nExplore the [Atlas](\u002Fatlas), or [bring us your triage queue](\u002Fcontact).\n","\u003Cp>Security operations centres don&#39;t lack alerts. They lack analyst time. Every tool in the stack produces detections, and many are duplicates, benign or low value. Real incidents compete for attention with noise, and analysts spend a large share of their day gathering context rather than making judgements.\u003C\u002Fp>\n\u003Ch2>What the application does\u003C\u002Fh2>\n\u003Cp>The \u003Cstrong>security operations\u003C\u002Fstrong> family in the Atlas focuses on the workflow between detection and response:\u003C\u002Fp>\n\u003Col>\n\u003Cli>\u003Cstrong>Ingest:\u003C\u002Fstrong> alerts from SIEM, EDR, email security, identity and cloud security tools, normalized into one model.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Enrich:\u003C\u002Fstrong> asset ownership, user context, threat intelligence and related alerts attached automatically.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Correlate:\u003C\u002Fstrong> group related alerts into a single investigation.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Triage:\u003C\u002Fstrong> prioritize by severity, asset criticality and confidence.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Investigate:\u003C\u002Fstrong> a case with a timeline, evidence, notes and tasks.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Respond:\u003C\u002Fstrong> response actions through the organization&#39;s tools, with approvals for high-impact steps.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Close and learn:\u003C\u002Fstrong> a disposition, lessons learned and tuning feedback to the detection owners.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Report:\u003C\u002Fstrong> metrics for SOC leadership and control evidence for audit.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch2>Where AI helps\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Cstrong>Summarization:\u003C\u002Fstrong> a plain-language summary of what happened, affected assets and the evidence so far.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Triage support:\u003C\u002Fstrong> a suggested priority and likely disposition, with the reasoning shown.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Investigation assistance:\u003C\u002Fstrong> suggested next queries and pivots, and drafted incident timelines.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Agentic enrichment:\u003C\u002Fstrong> bounded, read-only lookups across tools to assemble context before an analyst opens the case.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Reporting:\u003C\u002Fstrong> draft incident reports and management summaries.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>Guardrails that matter here\u003C\u002Fh2>\n\u003Cp>Security is where uncontrolled automation does the most damage. The application enforces:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Read-only by default.\u003C\u002Fstrong> Enrichment agents can look, not act.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Human approval for containment.\u003C\u002Fstrong> Isolating hosts, disabling accounts and blocking traffic require an analyst, and a second approver for high-impact actions.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Prompt-injection awareness.\u003C\u002Fstrong> Alert content is treated as untrusted data, never as instructions.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>A full audit trail\u003C\u002Fstrong> of every AI suggestion, every action and who approved it.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>We cover the general pattern in \u003Ca href=\"\u002Fblog\u002Fagentic-automation-with-human-checkpoints\">agentic automation with human checkpoints\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch2>Who uses it\u003C\u002Fh2>\n\u003Cp>SOC analysts (tier 1 to 3), incident responders, SOC managers, CISOs, and control owners who need evidence for audits.\u003C\u002Fp>\n\u003Ch2>Integrations\u003C\u002Fh2>\n\u003Cp>SIEM and log platforms, EDR\u002FXDR, identity providers, email security, cloud security posture tools, ticketing and ITSM, threat intelligence feeds, and asset inventories or CMDBs.\u003C\u002Fp>\n\u003Ch2>Measuring it honestly\u003C\u002Fh2>\n\u003Cp>Track time to triage, time to contain, the share of alerts closed as benign and analyst hours per incident. Agree the baseline first. Improvements should show up in your own metrics, not in vendor claims.\u003C\u002Fp>\n\u003Ch2>Where it applies\u003C\u002Fh2>\n\u003Cp>Enterprise SOCs, managed security providers, financial institutions with regulatory incident-reporting obligations, and government security operations.\u003C\u002Fp>\n\u003Cp>Explore the \u003Ca href=\"\u002Fatlas\">Atlas\u003C\u002Fa>, or \u003Ca href=\"\u002Fcontact\">bring us your triage queue\u003C\u002Fa>.\u003C\u002Fp>\n","AI in the SOC: alert triage and investigation with evidence","Security operations applications that use AI to enrich, summarize and prioritize alerts while analysts keep the decisions and the evidence trail.",[32,33,34,15,16],"cybersecurity","case-management","evidence","2026-07-28T00:00:00.000Z",7,{"id":38,"slug":39,"body":40,"html":41,"title":42,"description":43,"category":44,"tags":45,"author":17,"date":47,"year":19,"month":36,"quarter":21,"status":22,"featured":23},"2026\u002F07\u002Fai-in-production\u002Fagentic-automation-with-human-checkpoints","agentic-automation-with-human-checkpoints","\nAgents, meaning AI systems that plan and take multi-step actions with tools, are the most exciting and the most dangerous AI capability in the enterprise. An agent that gathers context from five systems before an analyst opens a case saves real time. An agent that closes accounts, moves money or emails customers on its own is a governance incident waiting to happen.\n\nThe answer isn't to avoid agents. It's to put them inside a workflow with **checkpoints**.\n\n## Design principles\n\n**1. Bounded tools.** An agent can only call tools that the application explicitly exposes to it, each with a narrow purpose and validated inputs. No general shell, no arbitrary API access.\n\n**2. Read before write.** Most value comes from read-only work: gathering context, correlating records, drafting. Make read-only the default and treat every write as a separate, higher-risk capability.\n\n**3. Explicit approval for consequential actions.** Anything that changes a record of consequence, contacts a customer, moves value or changes access requires a person to approve. Some actions require two people.\n\n**4. Identity and least privilege.** The agent acts with its own service identity or on behalf of a user, never with broader permissions than the user who invoked it.\n\n**5. Deterministic workflow state.** The workflow engine, not the model, decides what state a case is in and what happens next. The agent proposes, and the workflow disposes.\n\n**6. Untrusted input.** Content the agent reads (emails, documents, alerts, web pages) is data. Instructions embedded in it are ignored, and attempts are logged.\n\n**7. Full traceability.** Every plan, tool call, input, output, approval and rejection is recorded, so reviewers can reconstruct why something happened.\n\n## Where agents earn their keep\n\n- **Case preparation:** assemble customer, transaction and history context before a human opens the case. See [AI-assisted case management](\u002Fblog\u002Fai-assisted-case-management).\n- **Security enrichment:** read-only lookups across security tools. See [AI in the SOC](\u002Fblog\u002Fai-in-the-soc-triage-and-investigation).\n- **Document workflows:** extract, validate and route documents, and escalate what fails validation.\n- **Operations recovery:** generate and score recovery options for a controller to choose from. See [operations control](\u002Fblog\u002Foperations-control-and-disruption-management).\n- **Reconciliation:** propose matches and classify breaks for an analyst to confirm.\n\nIn each case, the agent compresses the time *before* a human decision. It doesn't replace the decision.\n\n## What to measure\n\nTime saved before the decision point, how often agent proposals are accepted unchanged, the rejection reasons, how often approval gates fire, and incidents caused by agent actions. That last number should be zero, and the design should make it hard to be anything else.\n\n## How it fits the architecture\n\nIn our application foundations, agent tools are ordinary application services with contracts, authorization and tests. That's the same discipline as any other API. This is the practical meaning of [AI accelerates the implementation, architecture governs it](\u002Fblog\u002Fai-accelerates-architecture-governs).\n\n[Bring us a workflow](\u002Fcontact) where an agent could prepare the decision, and we'll scope the checkpoints with you.\n","\u003Cp>Agents, meaning AI systems that plan and take multi-step actions with tools, are the most exciting and the most dangerous AI capability in the enterprise. An agent that gathers context from five systems before an analyst opens a case saves real time. An agent that closes accounts, moves money or emails customers on its own is a governance incident waiting to happen.\u003C\u002Fp>\n\u003Cp>The answer isn&#39;t to avoid agents. It&#39;s to put them inside a workflow with \u003Cstrong>checkpoints\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Ch2>Design principles\u003C\u002Fh2>\n\u003Cp>\u003Cstrong>1. Bounded tools.\u003C\u002Fstrong> An agent can only call tools that the application explicitly exposes to it, each with a narrow purpose and validated inputs. No general shell, no arbitrary API access.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>2. Read before write.\u003C\u002Fstrong> Most value comes from read-only work: gathering context, correlating records, drafting. Make read-only the default and treat every write as a separate, higher-risk capability.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>3. Explicit approval for consequential actions.\u003C\u002Fstrong> Anything that changes a record of consequence, contacts a customer, moves value or changes access requires a person to approve. Some actions require two people.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>4. Identity and least privilege.\u003C\u002Fstrong> The agent acts with its own service identity or on behalf of a user, never with broader permissions than the user who invoked it.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>5. Deterministic workflow state.\u003C\u002Fstrong> The workflow engine, not the model, decides what state a case is in and what happens next. The agent proposes, and the workflow disposes.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>6. Untrusted input.\u003C\u002Fstrong> Content the agent reads (emails, documents, alerts, web pages) is data. Instructions embedded in it are ignored, and attempts are logged.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>7. Full traceability.\u003C\u002Fstrong> Every plan, tool call, input, output, approval and rejection is recorded, so reviewers can reconstruct why something happened.\u003C\u002Fp>\n\u003Ch2>Where agents earn their keep\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Cstrong>Case preparation:\u003C\u002Fstrong> assemble customer, transaction and history context before a human opens the case. See \u003Ca href=\"\u002Fblog\u002Fai-assisted-case-management\">AI-assisted case management\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Security enrichment:\u003C\u002Fstrong> read-only lookups across security tools. See \u003Ca href=\"\u002Fblog\u002Fai-in-the-soc-triage-and-investigation\">AI in the SOC\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Document workflows:\u003C\u002Fstrong> extract, validate and route documents, and escalate what fails validation.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Operations recovery:\u003C\u002Fstrong> generate and score recovery options for a controller to choose from. See \u003Ca href=\"\u002Fblog\u002Foperations-control-and-disruption-management\">operations control\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Reconciliation:\u003C\u002Fstrong> propose matches and classify breaks for an analyst to confirm.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>In each case, the agent compresses the time \u003Cem>before\u003C\u002Fem> a human decision. It doesn&#39;t replace the decision.\u003C\u002Fp>\n\u003Ch2>What to measure\u003C\u002Fh2>\n\u003Cp>Time saved before the decision point, how often agent proposals are accepted unchanged, the rejection reasons, how often approval gates fire, and incidents caused by agent actions. That last number should be zero, and the design should make it hard to be anything else.\u003C\u002Fp>\n\u003Ch2>How it fits the architecture\u003C\u002Fh2>\n\u003Cp>In our application foundations, agent tools are ordinary application services with contracts, authorization and tests. That&#39;s the same discipline as any other API. This is the practical meaning of \u003Ca href=\"\u002Fblog\u002Fai-accelerates-architecture-governs\">AI accelerates the implementation, architecture governs it\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"\u002Fcontact\">Bring us a workflow\u003C\u002Fa> where an agent could prepare the decision, and we&#39;ll scope the checkpoints with you.\u003C\u002Fp>\n","Agentic automation with human checkpoints","How to use AI agents in enterprise workflows safely: bounded tools, read-before-write, explicit approvals and an audit trail of every step.","ai-in-production",[16,15,46,34],"production","2026-07-14T00:00:00.000Z",1790080513503]