What it automates
A playbook is a predefined sequence of steps for a type of alert. For a suspected phishing email, a SOAR can extract the links and attachments, check them against threat intelligence sources, search for the same message in other mailboxes, delete it and open a ticket, all in seconds. For a compromised account, it can disable the user, revoke active sessions and notify the analyst.
SOAR and SIEM
A SIEM collects data and raises alerts. A SOAR acts on those alerts. Many modern platforms combine both, and XDR products often include automated response for their own tools.
Limits
Automation is only as good as the playbooks behind it. Poorly designed rules can disable the wrong account or flood teams with tickets. Most organisations automate enrichment and low risk actions first, and keep a person deciding on actions with business impact.
Why it matters
Automation shortens the time to respond, which limits the damage of an attack, and frees analysts for real investigation. It is one of the reasons a SOC or MDR provider can cover many companies efficiently. Automated, documented actions also support the incident response evidence auditors ask for.




