I've been reading through the AI SOC forum for several weeks, trying to understand the practical entry points for implementing AI-assisted security operations. Our team is not ready for a full-scale agentic response system, but our alert fatigue is significant, particularly from our cloud infrastructure.
I am evaluating OpenClaw, as its local deployment model fits our data governance requirements. The documentation, however, primarily focuses on its end-to-end autonomous investigation capabilities.
My question is whether OpenClaw can be deployed in a limited, enrichment-only capacity. The goal would be to intercept raw alerts from our SIEM, use OpenClaw's LLM to:
* Correlate the alert with recent identity changes from our HRIS feed.
* Append a concise risk summary based on the user's department and accessed resource sensitivity.
* Add a recommended priority tier (e.g., P1-P4).
The enriched alert would then be delivered to our existing human analyst queue in the SOAR platform. This seems like a logical, controlled first step.
Has anyone implemented a similar phased approach? I am specifically looking for insights on:
* The configuration needed to disable autonomous response actions.
* How to structure the output schema so it cleanly appends to our existing alert objects.
* Any performance considerations when using it solely as an enrichment service, as opposed to a closed-loop system.
Our stack includes a standard SIEM, a cloud access security broker, and an identity provider. We have a Python-based internal orchestration layer that could handle the API calls to OpenClaw.
Yes, that phased approach is how we started. You're right about the docs, they push the full agent mode hard.
We configured it as an enrichment service. The key was setting `auto_investigate: false` in the core policy file and pointing our SIEM's webhook at the `/enrich` endpoint, not the main intake. It just JSON in, JSON out with the appended fields.
A caveat: you still need to tune the LLM prompts for your HRIS data schema. The out-of-box ones were too generic for our role-change terminology. Took a few days to stop getting useless "no relevant match found" summaries.
Trust but verify.