The Agentic SOC Workforce: How Autonomous Triage Is Redesigning the Security Guard and Operator Role
Home / Intelligence / The Agentic SOC Workforce: How Autonomous...
Agentic AI

The Agentic SOC Workforce: How Autonomous Triage Is Redesigning the Security Guard and Operator Role

How autonomous triage is restructuring the security guard and SOC operator role, and why certification and governance haven't caught up to the technology.

Published July 2026
Read Time 15 min read
Stream Agentic AI
77%
Annual turnover rate in contract security guard services, 2024 (ASIS International)
0%
Projected net employment growth for security guards through 2034, against 162,300 annual job openings (BLS Occupational Outlook Handbook)
51%
Share of SOC teams who report feeling overwhelmed by alert volume (ACM Computing Surveys research)

The security guard is the most common protective job in America and the most quietly automated. In May 2025, the U.S. Bureau of Labor Statistics counted 1,283,470 people working as security guards and gambling surveillance officers, earning a median annual wage of $47,130 — a workforce larger than the entire U.S. Army active-duty force, distributed across nearly every office building, hospital, retail chain, and industrial site in the country. That workforce is not growing. The BLS Occupational Outlook Handbook projects essentially flat employment through 2034, with virtually all of the 162,300 annual job openings driven by replacement demand: guards who quit, retire, or move into supervisory roles, not net new hiring. Meanwhile, ASIS International's 2024 workforce data puts annual turnover in contract security services at 77%, and industry surveys documenting individual site-level churn as high as 300% are common enough to be treated as background noise rather than crisis.

This report is about what happens to that job when agentic AI stops just detecting and starts triaging, prioritizing, and in some cases acting. The conversation about agentic security AI has mostly been about capability and liability — can the system act safely, who is responsible when it does. This report asks the adjacent question that security directors, staffing agencies, and workforce planners are living with in 2026: what does the human role look like once an autonomous system is doing first-pass triage on every camera alert, and what does the industry's chronic staffing crisis actually mean once that redesign is underway. The short answer, grounded in labor statistics, SOC burnout research, and human-in-the-loop labor architecture literature, is that agentic AI does not eliminate the guard force. It restructures it around a much smaller number of higher-skill verification and response roles, and the industry is not yet certified, trained, or regulated to make that transition safely.

Three numbers that define the agentic workforce transition

77%Annual turnover rate in contract security guard services, 2024 (ASIS International / NYC security services sector data)
0%Projected net employment growth for security guards through 2034, against 162,300 annual job openings driven almost entirely by replacement demand (BLS Occupational Outlook Handbook)
51%Share of SOC teams who report feeling overwhelmed by alert volume, with analysts spending over 25% of their time on false positives (Trend Micro SOC survey, cited in ACM Computing Surveys research)

The security guard labor market was already breaking before agentic AI arrived

Every conversation about AI replacing security jobs has to start from the actual condition of the job it would be replacing, and that condition is closer to a staffing emergency than a stable occupation under threat.

The BLS Occupational Outlook Handbook projects security guard employment will grow by roughly 5,100 net positions over the 2024–2034 decade — effectively 0% growth against a base of 1.28 million workers. Yet the same projection shows 162,300 average annual job openings. The math only works one way: the overwhelming majority of hiring in this field exists to replace people who left, not to grow the workforce. The BLS is explicit that this reflects "workers who transfer to other occupations or exit the labor force, such as to retire."

Turnover data explains why that replacement demand is so large. ASIS International's 2024 figures put guard-service turnover at 77%, and multiple industry sources — including a 2025 UC Berkeley Labor Center analysis of New York City's security guard workforce — document contract security turnover running from 100% to 300% annually depending on business model and site type, compared to roughly 58% turnover across the broader private sector in the same period. More than 40% of security service providers identify turnover, not margin compression or wage compliance, as their single biggest operating challenge, according to ASIS reporting on the issue.

This is the labor market that agentic security AI is entering: not a healthy occupation with stable headcount that automation threatens to disrupt, but a chronically understaffed, high-churn field where median pay is $47,130 a year for work that increasingly requires sustained attention across dozens of camera feeds. The guard shortage itself is well documented; what has received far less structured analysis is what the job becomes once AI absorbs the part of the work that was driving people out.

Alert fatigue is the mechanism, not the metaphor

Alert fatigue in security monitoring is not a vague complaint about a hard job. It is a documented, measurable phenomenon with a body of peer-reviewed research behind it, most of it originating in cybersecurity operations centers but directly transferable to physical security monitoring, because the underlying task — sustained visual or signal attention with a low true-positive rate — is identical.

A 2025 survey-based study published in ACM Computing Surveys, "Alert Fatigue in Security Operations Centres: Research Challenges and Opportunities," synthesizes the state of the field: SOC teams report that 51% feel overwhelmed by alert volume, analysts spend more than a quarter of their working time chasing false positives, and 60–70% of alerts in a typical SOC are ultimately categorized as benign. A separate field study cited in the same research found that while human analysts correctly separated true alarms from false ones 83% of the time, only 39% of their stated justifications actually reflected the true root cause — meaning experienced analysts were frequently right for the wrong reasons, a pattern consistent with fatigue-driven pattern-matching rather than deliberate judgment. Industry-side data points in the same direction: a Tines practitioner survey found 63% of security operations staff report some level of burnout, and more than 80% say their workload increased in the past year.

The physical security equivalent of this is well known to anyone who has run a guard-staffed monitoring room. The Mackworth clock experiments — the original vigilance-decrement research from radar operator studies in the 1950s, replicated many times since in video-monitoring contexts — established that human detection accuracy on sustained, low-event-rate visual monitoring tasks degrades measurably within 20–30 minutes and continues to decline across a shift. A guard watching sixteen quadrant feeds for an eight-hour shift is not performing at the same detection accuracy in hour seven that they were in minute ten, and no amount of training discipline fully overcomes that physiological reality.

Why This Isn't Just a Cybersecurity Problem

Physical security monitoring rooms have the same failure signature as SOCs

Cybersecurity SOCs and physical security monitoring rooms are structurally the same task: a human watches a continuous, mostly-benign stream for the rare true event, and burns out doing it. The vigilance-decrement research on physical monitoring predates the cybersecurity SOC literature by decades, but the newer academic base — peer-reviewed, well-cited, and specifically about alert triage — gives physical security programs a much stronger evidentiary foundation for what agentic AI should actually change: not whether an alert reaches a human, but how much irrelevant noise a human has to wade through before they see the one that matters.

What agentic AI actually changes in the operator's task

It is worth being precise about what "agentic" means in this context, because vendor language has stretched the term to cover everything from a simple rules-based alert filter to genuinely autonomous multi-step response. The Security Industry Association's AI Advisory Board describes the emerging capability set plainly: AI systems that can "autonomously trigger deterrence measures, adjust camera views, lock access points, and notify responders" without waiting for a human to initiate each step. That is a meaningfully different task allocation than first-generation computer vision, which simply raised a flag and left every subsequent decision to a person.

In a detection-only architecture, the human operator's job is: watch feeds, notice something, decide if it matters, decide what to do, do it. In an agentic architecture, the system performs the first three steps — watch, notice, and a first-pass judgment on materiality — and surfaces only the alerts that clear a confidence and context threshold, often already annotated with the relevant camera angle, historical pattern, and a suggested response path. The human's job compresses to: verify, decide on escalation, and execute or delegate the response. This is not the removal of judgment from the loop. It is the relocation of judgment from continuous low-grade pattern-scanning to intermittent high-stakes verification — a fundamentally different cognitive task, with a different skill profile, different fatigue curve, and different training requirement.

This distinction matters because it reframes the staffing conversation. The industry's chronic turnover problem is concentrated heavily in the "watch and notice" layer — the monotonous, low-autonomy, poorly compensated work that the BLS wage data and turnover statistics describe. If agentic systems absorb that layer, the remaining human role is smaller in headcount but requires a different, arguably higher, skill set: rapid situational verification, de-escalation judgment, and multi-channel response coordination. That is a labor market restructuring, not a straightforward headcount reduction, and treating it as either "AI takes the jobs" or "nothing changes" both miss what the data shows is actually happening.

A framework for the human-in-the-loop redesign

Recent labor-economics and human-computer-interaction research gives security operators language for this transition that goes beyond "human oversight" as a vague governance checkbox. A 2026 SSRN working paper, "Human-in-the-Loop Labor Architectures: Reinstating and Reconfiguring Work through Skills, Certification, and Human-Centered AI," proposes a four-layer framework for how automation should reconfigure — rather than simply eliminate — jobs: capabilities (what the system can do autonomously), roles (what task allocation remains for humans), skills and certification (what training the redesigned role requires), and governance (how the system and the human are jointly accountable). Complementary research published in a 2025 Technovation framework paper on the automation of work makes the empirically supported point that job automation happens far more often through partial automation and task redesign than through wholesale replacement of an entire occupation — which matches what the guard-turnover and SOC-fatigue data above would predict for physical security specifically.

Applied to the physical security guard force, that four-layer framework looks like this:

Human-in-the-Loop Labor Architecture

Four layers for redesigning the guard and operator role around agentic AI

Adapted from the SSRN human-in-the-loop labor architecture framework for physical security operations.

LAYER 1
Capabilities

Define exactly what the agentic system does without a human step: continuous scan, first-pass confidence scoring, alert suppression on low-materiality events, and routing of high-confidence alerts to the right responder channel.

LAYER 2
Roles

Redefine the operator's task as verification and response coordination rather than continuous scanning. Fewer operators per shift, each handling a materially different cognitive task than the role they replaced.

LAYER 3
Skills & Certification

Build training and state licensing requirements around rapid verification judgment, de-escalation, and multi-channel dispatch — a different curriculum than the current state-mandated guard training hours, which range from 4 to 48 hours depending on jurisdiction.

LAYER 4
Governance

Establish joint accountability: logged reasoning for every suppressed alert, defined escalation thresholds, and an audit trail showing which decisions were autonomous versus human-verified, aligned to NIST AI RMF human-oversight expectations.

The certification and training patchwork wasn't built for this role

The redesigned operator role this framework describes requires a different skill set than the role it replaces — but state licensing and training regimes for security officers have not caught up, and in most states were never rigorous to begin with. There is no federal training standard for unarmed security officers. Training hour requirements are set state by state and vary by an order of magnitude: Florida requires 42 hours of pre-assignment training for unarmed guards, one of the higher state requirements in the country, while South Carolina requires as little as 4 hours, and Louisiana, Montana, and Pennsylvania impose no specific initial or refresher training hour requirement at all, according to a National Association of Security Companies (NASCO) white paper on state training-hour requirements. Forty-one states plus Washington, D.C. license security officers in some form; nine states have no licensing framework whatsoever.

That patchwork was built for a job defined by post-incident reporting, access control, and basic use-of-force awareness. It was not built for a job defined by verifying AI-flagged events under time pressure, understanding confidence scores and false-positive rates well enough to know when to escalate a marginal call, and coordinating a multi-channel response across access control, mass notification, and dispatch systems simultaneously — the operator task this report describes in the section above. No state currently requires training specific to AI-assisted verification, and no national certification body has published a competency standard for it. This is the workforce-readiness gap sitting underneath the technology deployment curve: agentic capability is arriving in the field years ahead of the licensing and training infrastructure that would certify a workforce to operate it responsibly.

Where the regulatory frameworks don't yet reach autonomy

The NIST AI Risk Management Framework is the closest thing physical security has to a governance baseline for AI human-oversight expectations, and it is instructive precisely because of where it stops. The framework's GOVERN function requires organizations to establish risk-tolerance policies and assign accountability for AI-related risk, and its broader guidance distinguishes oversight expectations by risk tier — high-impact systems generally warrant human-in-the-loop final approval, while lower-risk systems can operate with periodic review rather than case-by-case sign-off. What the framework does not do, as several 2026 governance analyses of the RMF have noted, is differentiate systematically based on a system's degree of operational autonomy. A framework built primarily around AI that classifies, predicts, or recommends translates awkwardly onto AI that also acts — locking doors, triggering mass notification, or adjusting camera coverage without a human initiating each step.

This is a governance gap, not a hypothetical one, and it is analogous to a failure pattern well documented in an entirely different high-velocity automated domain. The 2010 "Flash Crash" — in which the Dow Jones Industrial Average fell nearly 1,000 points in minutes before substantially recovering — is one of the most thoroughly studied cases of automated systems interacting faster than human oversight could contain. Academic post-mortems on the event describe how algorithmic trading systems, high-frequency market-maker withdrawal, and cascading stop-loss orders combined to produce a market dislocation that human traders and risk managers watching their screens had no realistic ability to intervene in before automated circuit breakers — themselves an engineered pause mechanism, not human judgment — halted trading long enough for the market to reassess. The lesson transfers directly: at sufficient speed and scale, autonomous systems can act faster than a human-in-the-loop governance model assumes, and the safeguard that actually worked was a pre-engineered pause point, not real-time human oversight. Physical security agentic systems that lock doors or reroute notification chains autonomously need the equivalent of a circuit breaker — a defined, tested pause-and-verify threshold — not just a human somewhere in the workflow who is theoretically able to intervene.

The Operator Role Before and After Agentic Triage

DimensionDetection-Only Model (Today's Baseline)Agentic-Augmented Model
Primary taskContinuous multi-feed visual scanning across a shiftIntermittent verification of pre-triaged, confidence-scored alerts
Alert volume reaching the humanEvery motion event and camera alert, including 60–70% benign noiseOnly alerts clearing a confidence and context threshold
Dominant failure modeVigilance decrement and fatigue-driven miss rate over a shiftOver-trust in system triage; verification complacency
Skill profile requiredSustained attention, basic reporting, access control procedureRapid situational judgment, de-escalation, multi-channel dispatch coordination
Training standard todayState-mandated hours ranging from 0 to 48, no national floorNo state or national standard yet exists
Governance modelHuman reviews all footage/alerts; accountability is straightforwardJoint human-AI accountability; requires logged reasoning and defined escalation thresholds
Headcount implicationStaffing scales roughly with camera/feed countStaffing scales with verification and response load, not raw feed count
Real IntelliSee AI detection output flagging two people on an after-hours security camera feed with bounding boxes and confidence scoring
LIVE CAM-02 · AFTER-HOURS LOT
Actual IntelliSee detection output. Two people flagged on an after-hours camera feed — this is the moment the agentic layer performs the "watch and notice" work that used to consume the bulk of an operator's shift. The system surfaces the event with bounding-box and confidence detail already computed; the human task that remains is verification and response, not continuous scanning. No facial recognition. No stored video. No PHI. Alert routing reaches designated responders within seconds.

What this means for security directors and staffing models

For a security director building next year's staffing model, the practical implication of this research is not "reduce headcount and redeploy the savings." It is a three-part planning problem. First, headcount for the continuous-scanning layer of the job should shrink as agentic triage matures, and that reduction should be modeled against the 77% turnover baseline — meaning the near-term savings show up primarily in reduced hiring and retraining cost, not necessarily in a smaller total roster, since much of today's headcount is already backfilling constant departures rather than net capacity. Second, the remaining and redesigned verification/response role needs a different hiring profile, a different training investment, and in most states, an advocacy conversation with the licensing body, since no jurisdiction currently certifies for this specific competency. Third, governance documentation — logged reasoning for suppressed alerts, defined escalation thresholds, an audit trail distinguishing autonomous from human-verified decisions — needs to exist before an insurer, a plaintiff's attorney, or a regulator asks for it after an incident, not after.

None of this argues against deploying agentic capability. The turnover and burnout data make an unusually strong case that the current model — asking humans to sustain sharp attention across dozens of low-signal feeds for eight-hour shifts — was already failing before AI entered the picture. The case this report makes is narrower and more specific: the technology deployment curve for agentic triage is running well ahead of the training, certification, and governance infrastructure that would let the security industry make this transition on stable ground rather than by accident.

Frequently asked questions about agentic AI and the security workforce

Does agentic AI eliminate the need for human security guards or operators?

No. The labor and research base described in this report supports task redesign, not elimination. Agentic systems absorb the continuous-scanning, first-pass triage layer of the work — the layer most associated with fatigue, burnout, and the industry's 77% turnover rate — while verification, escalation judgment, de-escalation, and physical response remain human functions. Total headcount per site is likely to decrease over time as triage automates, but the remaining roles require higher, not lower, skill levels.

What is "alert fatigue" and why does it matter for physical security specifically?

Alert fatigue is the documented decline in an operator's ability to accurately identify true events after sustained exposure to a high volume of mostly-benign alerts. Peer-reviewed research on SOC environments found 51% of teams feel overwhelmed by alert volume and that 60–70% of alerts are ultimately benign; the vigilance-decrement research underlying physical security monitoring shows the same accuracy decline within 20–30 minutes of sustained visual monitoring. This is the mechanism agentic triage is designed to address.

Are there training or certification standards for operators working with agentic AI systems?

Not yet, in any state. Existing state security officer training requirements range from 0 to 48 hours and were designed around the traditional guard role — patrol, access control, incident reporting — not around verifying AI-flagged events or coordinating multi-channel autonomous response systems. This is an active gap that licensing bodies and industry associations have not yet closed.

How does the NIST AI Risk Management Framework address human oversight of autonomous security systems?

The NIST AI RMF establishes a general expectation that higher-risk AI systems warrant human-in-the-loop approval while lower-risk systems can operate with periodic review, and its GOVERN function requires documented accountability structures. However, the framework does not systematically differentiate oversight requirements by a system's degree of operational autonomy, which creates ambiguity for agentic systems that act (locking doors, triggering notifications) rather than only classify or recommend.

What can security directors do now, before certification standards catch up?

Build internal governance documentation now: log the reasoning behind every suppressed or auto-resolved alert, define explicit confidence thresholds that trigger mandatory human escalation, and document which decisions were autonomous versus human-verified. This creates an audit trail that satisfies insurer and regulatory scrutiny even in the absence of a formal state or national certification standard, and it mirrors the four-layer human-in-the-loop labor architecture (capabilities, roles, skills/certification, governance) that labor-economics research recommends for automation-affected occupations.

Is this the same issue as the broader physical security staffing shortage?

They are related but distinct. The staffing shortage is a supply-and-turnover problem: too few people willing to do the job at current wages and working conditions. This report addresses a second-order question — once agentic AI changes what the job actually is, what training, certification, and governance infrastructure does the industry need to make that transition safely, rather than simply cutting headcount without redesigning the remaining role.

Does reducing the number of human monitors increase liability risk?

It can, if the reduction happens without the governance layer described above. Courts and insurers evaluating a negligent security or premises liability claim will look for a documented, defensible process behind any AI-assisted decision. A logged, auditable escalation framework reduces this risk; an undocumented headcount reduction with no equivalent governance structure increases it.

Continue the research

This report focuses on the workforce and governance dimension of agentic security AI. For the adjacent frameworks:

Request a Risk Assessment

Talk to an IntelliSee security specialist. No sales pitch — a structured conversation about your environment, your threat profile, and whether computer vision is the right fit.

Request a Risk Assessment