Map the AlertTriage and Notifier agents to a model

SOC disables a built-in agent that has no agentMapping entry, so the new
AlertTriage agent and the Notifier it delegates to need one to run.
This commit is contained in:
Mike Reeves committed 2026-10-06 20:43:04 -04:00
1 parent d1114a0dae
commit b11fc6257a
2 files changed
+8

No files matched your search

+2
View File
@@ -1542,6 +1542,8 @@ soc:
Orchestrator: sonnet@SOAI
Investigator: gemma@SOAI
DetectionEngineer: gemma@SOAI
AlertTriage: gemma@SOAI
Notifier: gemma@SOAI
useMemory: false
useMemoryScanner: false
dontScanBefore: ""
+6
View File
@@ -937,6 +937,12 @@ soc:
DetectionEngineer:
description: This agent manages detections and their overrides, including tuning noisy rules and authoring rule content.
global: True
AlertTriage:
description: This agent triages alerts autonomously for the Alert Triage automation, ending each run with a report and an assessment of the alert. It can notify through the Notifier but cannot acknowledge alerts or escalate to cases.
global: True
Notifier:
description: This agent sends a single notification on behalf of another agent, such as AlertTriage, and takes no other action.
global: True
useMemory:
description: Enables the Memory system for OnionAI
global: True