Filip Stojkovski's SecOps Shift Map at SecOps Unpacked is one of the more useful lenses for where security operations work happens. It splits the lifecycle into four lanes. Far left is the data foundation. Left is detection and readiness, which includes the context databases and graphs that feed detection. The middle is investigation: triage, DFIR, hunting. Right is remediation and improvement. Feedback runs across all of it.
His newest post applies that lens to roles, and you should read it. It left me with a question SOC managers have been asking me for most of this year. If AI keeps absorbing work in the middle, where do the analysts who lived there go?
They move. Some go left into detection engineering and context building. Others go right into response, or end up building and supervising the agents that now handle first pass triage.
Nobody budgets for the ramp.
The ramp is where the time goes
When I moved from tier 3 operations into engineering work, the new tooling took a few weeks to learn. The months went somewhere else. My investigative judgment lived in my head and across a dozen consoles, and none of it was in a form the new job could use. I knew what a bad session looked like. I could not hand that knowledge to a pipeline.
That gap shows up in every lane change on the map.
An analyst moving into detection engineering knows what a malicious sign-in looks like on the console. To write a detection, she needs to know which sources hold the evidence, which fields matter, what normal looks like in this environment, and how a responder confirms a hit. Most of that is tribal. The confirmation steps live in a runbook last updated two reorganizations ago.
An analyst who becomes the person building agents has a different problem. The agent needs to do investigation steps the way a senior analyst would, and someone has to be able to audit what it did. In practice that means writing integrations against every console API, handling authentication for each one, and hoping the agent's reasoning can be reconstructed afterward.
An analyst moving right into response needs scope before anything gets remediated. Scope comes out of an investigation.
Look at those three moves together. Every one of them carries middle-of-the-map work with it. The middle now gets called from more places, by people who no longer sit in it.
Investigation as a callable service
Command Zero sits in the middle of the Shift Map. I'm not going to pretend otherwise. What our REST API and MCP server change is who can reach the middle, and from where.
The working unit in Command Zero is a Question: an investigation step written by an experienced analyst, mapped to specific data sources, and run against the data where it already lives. Nothing gets centralized first. Through the MCP server, someone working in Claude Code or any other MCP client can search the question catalog, open an investigation, run Questions against identity and endpoint sources, and pull the results back into their editor. The investigation record stays in Command Zero. The REST API exposes those same investigation capabilities to scripts and pipelines.
That matters for the ramp because the analyst changing lanes keeps the investigation knowledge and calls it from the new seat.
Moving left: run the hunt before you write the rule
Most new detection engineers write the rule first and find out what it catches afterward. Flip that.
The cmdzero-hunt skill in our zerocmd/recipes repository runs lead-less Questions, ones that don't need a starting user or host, and you can filter them to specific sources like Microsoft Graph sign-in data or CrowdStrike telemetry. Point it at the behavior you plan to detect and you see what it returns in your environment before anything goes into the SIEM. If the hunt comes back noisy, you learn that in an afternoon, before the tuning complaints start.
When the rule ships, the Questions that confirmed the hits become the triage steps attached to it. The analyst who now owns detections already knows those Questions. She ran them for two years on the floor. Her experience goes with her into the new role.
Building agents: hand them a glass box
The alternative to writing a connector per console is letting the agent call Questions through MCP. Every invocation leaves a record, and the rows behind any result can be pulled back up later. When an agent concludes an account is compromised, a human can open the investigation and see which Question returned which evidence.
Here is a real example from our demo tenant. An investigation into a contractor account found the account disabled in AWS through SCIM, yet still producing active sign-ins from geographically scattered IPs. Those IPs matched CrowdStrike egress data for the contractor's host. Questions against identity, provisioning, and EDR data each returned a piece of that verdict, and every piece is sitting in the investigation record where a reviewer can check it.
That's what makes agent supervision a job a former analyst can do well. They read the evidence trail the same way they'd review a junior analyst's case notes. The cmdzero-triage skill fits the narrower version: one alert, one fast pass, a disposition, with escalation into a full investigation only when the triage pass finds a reason.
Moving right: scope before remediation
Response work starts with blast radius. Which other accounts touched those IPs? Which hosts did the session reach? Those are investigation questions, and the responder can keep working the same investigation from the response seat. The remediation plan then points to evidence already in the record.
This is also where the Shift Map's feedback lane earns its place. A confirmed verdict, with the Questions that produced it, is exactly what the detection engineer on the left needs to tune the rule that fired.
What this changes
Writing good detections and building trustworthy agents are skills that take time, and a tier 1 analyst still has to put in that time to become a detection engineer.
What changes is that institutional knowledge survives the move. When a senior analyst's investigative patterns are encoded as Questions, those patterns stay callable after they change lanes, and after they leave the company. A team reorganizing around the Shift Map points its new roles at the investigation knowledge it already has.
If you're running a SOC where people are starting to move across the map, begin with an inventory. Find the investigation steps that exist only in people's heads and in stale runbooks, the ones you'd lose if your best analyst moved to detection engineering next quarter. Encode those first. Then make them reachable from wherever your people are going.



