Product1 publisher3 min readPublished
Swimlane's new router treats cost per alert, not analyst hours, as the SOC's binding constraint
Its CEO puts AI investigations at $5 to $10 each, which makes the new triage layer's real job deciding which alerts never touch a model at all.
The Product Desk · Product desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- Swimlane Inc., an agentic AI cybersecurity automation company, announced the expansion of its AI security operations centre to support automatic routing for security investigations.
- The new capability routes incoming alerts to different paths: deterministic automation, AI-assisted investigation or agentic automation.
- Swimlane said the front-end triage capability allows the system to quickly assess the complexity of the work and the level of AI involvement needed for the alert, without defaulting every task to expensive AI models.
- Cornell said that at the scale of hundreds of thousands of investigations, $5 to $10 for each investigation piles up quickly.
- Cornell said: "As AI consumption continues to rise, the next generation of the SOC will not be able to run every task through AI by default. It will know which work actually needs AI."
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
Swimlane has expanded its AI security operations centre to automatically route incoming alerts down one of three paths: deterministic automation, AI-assisted investigation, or agentic automation [1][2]. The interesting part is not the routing. It is that the company is willing to say out loud why routing is needed: co-founder and chief executive Cody Cornell put the cost of an AI investigation at $5 to $10, and noted that at the scale of hundreds of thousands of investigations that piles up quickly [4].
That is a concession most agentic security vendors avoid. The pitch for the category has been capability; Swimlane's pitch here is restraint. A front-end triage layer assesses how complex the work is and how much AI involvement it needs, rather than defaulting every task to expensive models [3]. Cornell's framing: the next generation of the SOC "will not be able to run every task through AI by default. It will know which work actually needs AI" [5].
The company's diagnosis of the current state is specific enough to be checkable. AI-driven platforms, it says, send work to generative models that deterministic scripts could handle, so an expensive model ends up crunching something as simple as a text search, or doing what a six-line Python script would do [6]. Swimlane describes that as a potential cost tradeoff of several thousand percent, for an outcome where the model could return a wildly different answer [7].
The unit economics do the arguing. Swimlane cites one healthcare customer investigating more than 180 threats a day that reported 90% cost savings from intelligent routing, reserving agentic evaluation for only the most complex 10% of threats [8][9]. Run the arithmetic on Cornell's own price band and that volume implies $900 to $1,800 a day, or roughly $329,000 to $657,000 a year, if every one of those threats went through an AI investigation [1]. Note also that the claimed 90% saving is the exact complement of the 90% of threats diverted away from agentic evaluation, which means the comparison is treating the non-AI paths as effectively free [2]. That is a modelling choice, not a measurement.
Two design details matter more than the headline number. If the router sends what looked like a simple alert to deterministic automation and it turns out to be the tip of the iceberg, the team can still push it to a higher-reasoning model [10]. And when the agent does act, Swimlane says the system learns which alerts the team wants evaluated and turns those into repeatable playbooks [11]. That is the mechanism by which a cost-control layer either improves or quietly ossifies into a set of rules nobody revisits.
Cornell's summary of the goal is the sentence operators should hold the product to: customers should be able to expand what their SOC handles "without replacing an analyst-capacity problem with an AI-spend problem" [12].
What to watch: the announcement carries no figure for router accuracy, no cost for the routing layer itself, and no per-path pricing, so the $5 to $10 band and the 90% saving both rest on the vendor's own account [3]. Watch whether buyers start demanding cost per closed alert as a contractual metric, and whether competitors follow Swimlane in publishing a price per investigation at all.