From b11fc6257a383f70c4ab3c1ef67184cd18e8df78 Mon Sep 17 00:00:00 2001 From: Mike Reeves Date: Tue, 6 Oct 2026 20:43:04 -0400 Subject: [PATCH] Map the AlertTriage and Notifier agents to a model SOC disables a built-in agent that has no agentMapping entry, so the new AlertTriage agent and the Notifier it delegates to need one to run. --- salt/soc/defaults.yaml | 2 ++ salt/soc/soc_soc.yaml | 6 ++++++ 2 files changed, 8 insertions(+) diff --git a/salt/soc/defaults.yaml b/salt/soc/defaults.yaml index 4eeae5579..cd6b183c4 100644 --- a/salt/soc/defaults.yaml +++ b/salt/soc/defaults.yaml @@ -1542,6 +1542,8 @@ soc: Orchestrator: sonnet@SOAI Investigator: gemma@SOAI DetectionEngineer: gemma@SOAI + AlertTriage: gemma@SOAI + Notifier: gemma@SOAI useMemory: false useMemoryScanner: false dontScanBefore: "" diff --git a/salt/soc/soc_soc.yaml b/salt/soc/soc_soc.yaml index df9c142f9..d3e0ef5f1 100644 --- a/salt/soc/soc_soc.yaml +++ b/salt/soc/soc_soc.yaml @@ -937,6 +937,12 @@ soc: DetectionEngineer: description: This agent manages detections and their overrides, including tuning noisy rules and authoring rule content. global: True + AlertTriage: + description: This agent triages alerts autonomously for the Alert Triage automation, ending each run with a report and an assessment of the alert. It can notify through the Notifier but cannot acknowledge alerts or escalate to cases. + global: True + Notifier: + description: This agent sends a single notification on behalf of another agent, such as AlertTriage, and takes no other action. + global: True useMemory: description: Enables the Memory system for OnionAI global: True