Skip to content
Explore solutionsSOC Management & Governance
Solutions / SOC Management & Governance

Run the SOC.
Show the work behind it.

Imperum brings workload, response approvals, reporting and supervised case review into one operational platform. Give your SOC leaders a clear view of the work, control over consequential decisions, and evidence they can take into the next review.

Understand workloadGovern responseExplain performance
From operational data to the leadership reviewIllustrative workflow
Platform KPIBacklog

Example tenant · current snapshot

Open cases24
SLA at risk3
SLA breached8
Age of open casesCases
Under 1 day
16
1–7 days
6
Over 7 days
2
Open a metricInspect the underlying cases ↗
Custom reportWeekly SOC review
01
Example tenantLast 7 days
01
Workload & backlogCurrent open cases and aging
02
ResolutionCase outcomes for the period
03
Management commentaryYour priorities for the next review
weekly-soc-review.pdfCompleted · available in History
Choose the report’s widgets and time range, then generate it from operational data. All figures shown are synthetic. Report generation reads current data; it does not freeze this dashboard.

Generate the configured report and retrieve the resulting file in History. Review its content before sharing it with leadership.

01 - Workload

Know where your team needs help.

A queue total tells you how much work exists. Platform KPI helps you understand its age, priority, ownership and outcomes, so the next staffing or process discussion starts with the cases behind the numbers.

Find pressure in the queue.

Review open cases, aging and service-level risk. Open supported metric tiles to inspect the underlying cases before deciding what needs attention.

Compare work across a period.

Explore resolution, routing, analyst activity and shift views. Select a reporting window and export KPI data as CSV or Excel for further analysis.

Views use authorized tenant scope. Current backlog and historical activity answer different questions; large datasets can be subject to query limits.

Explore the case workflow
02 - Control

Put a human decision where it matters.

Use configured approval steps in Automatio to pause a response workflow for review. The approver can inspect the requested action, affected assets and context before choosing the next branch.

A configured response approvalSynthetic example · SecOps Platform
Automatio / approval step

Review host isolation

A case investigation requests containment of LAB-WS-07. Check the evidence and business impact before permitting the configured response branch.

Risk
Critical
Required reviewer
Configured approver
Awaiting reviewA request is not an executed action.

Approval follows the configured approval branch. Rejection follows the configured rejection branch. The response result is checked separately.

Illustration only. Approver permissions, escalation and timeout behavior depend on the configured workflow. These controls demonstrate a decision; they do not operate a host.

Keep the decision traceable.

The approval record stores the decision, authenticated actor, timestamp and any reason. Review that record separately from the eventual action result.

Set autonomy for the capability.

Approval rules differ across playbooks and agents. Review each capability’s permissions and policy before enabling automated changes.

Explore Automatio
03 - Reporting & evidence

Bring the report. Keep the supporting record.

Build an executive summary, daily SOC brief or client report from reusable widgets. Choose the scope, period and format, then generate a file or set up a subscription for recurring delivery.

A report for its audience.

Start with a built-in template or create your own. Combine metrics with text, tables and charts. Use framework-specific templates to organize evidence for a compliance review. History lists completed and failed runs and provides downloads for available files.

PDFExcelCSVHTML

Evidence for a specific question.

Filter the Audit Log by actor, action, resource, result or date, then export matching records as CSV or JSON. Inspect case evidence in Casebook when the question concerns an incident.

Audit LogSynthetic records · filtered to one case
TimeActorActionResourceResult
09:41Example analystUpdatedCASE-DEMO-24Success
10:06Example reviewerUpdatedCASE-DEMO-24Success
Audit export and report generation are separate actions. Export is capped; narrow the date range for large requests. Change details are available when captured by the source action.

Reuse the reporting setup. Spend the review explaining exceptions and next steps, with a consistent format and the relevant records close at hand.

04 - Quality

Make review part of the work.

Magister connects junior analysts with mentors. When an analyst in an active mentorship proposes closing a case they own or are assigned to, the case goes to their mentor for review.

  1. 01Propose a disposition

    The analyst submits their case conclusion.

  2. 02Review the reasoning

    The assigned mentor checks the work and gives feedback.

  3. 03Close or improve

    Approval closes the case. A request for changes keeps it open for rework.

Coach at the point of decision. Review and rework become part of case handling, giving the team a concrete way to improve investigation quality.

Magister requires the relevant licensed capability and permissions. This closure gate applies to active mentorships and eligible owned or assigned cases.

Getting started

Start with your next operational review.

Choose the tenant and reporting period. Identify the workload question, the response that needs oversight, and the evidence your audience expects. Then configure the report and review workflows around those responsibilities.

Available modules and actions depend on your Imperum license, assigned permissions and configuration. Scheduled email delivery also requires the deployment’s email service.

Questions from SOC leaders.

1Are the figures on this page customer results?

No. The illustration uses synthetic data to explain the workflow. Your operational metrics depend on the cases, activity, scope and period in your deployment. No customer savings or performance result is claimed here.

2Does every response action require a person?

Approval behavior depends on the capability, permissions and configured policy. An Automatio approval step routes the workflow through its configured approval or rejection branch. Approval does not establish that the response action succeeded.

3Can we report for individual tenants?

Yes. Reports and KPI views use authorized tenant scope. Cross-tenant reporting requires additional authorization; it is not enabled simply by choosing a report template.

4What should we check before sharing a report?

Check the tenant, time range, included widgets and generated content. Reports read data at generation time. PDF output requires an available PDF renderer; otherwise generation can produce HTML. Download the available file from History and check that it fits the review’s purpose.

5Does an export establish compliance?

A report or audit export supplies records for your review. Your governance team still needs to assess whether the evidence answers the control or requirement being examined. Audit exports and generated reports are separate outputs.

Have any other questions?
Talk to our team

Bring your next
leadership question.

See how workload, approvals and reporting can support your SOC’s next operational review.