Context
Source connector
GitHub OAuth and repo selection keep source context tied to the investigation.
Case study / Agentic security operations
Security teams are looking at agentic SOC, AI alert triage, autonomous investigation, and SOC automation for a practical reason: analysts need better context before they act.
Northwall connects a GitHub source, builds repository context, shows an investigation graph, lets the analyst review the plan, streams the run, and turns approved findings into GitHub issues.
Project
Northwall
Category
Agentic SOC, AI alert triage, and security operations automation
Core loop
Connect source, build context, review plan, run agents, approve handoff
First connector
GitHub repository context and issue creation
Safety boundary
Owned systems, defensive analysis, analyst approval, no destructive actions
Repository
github.com/Inferensys/northwall
Product challenge
Northwall inventories repositories, routes, auth, config, CI, packages, and ownership context before the investigation starts.
The analyst sees the agent team, graph, task order, and approval notes before the run starts.
Each finding carries severity, confidence, evidence, owner notes, issue text, and labels before it becomes a GitHub issue.
Demo
The walkthrough shows source selection, context build, agent plan review, live investigation, findings review, and approved GitHub issue creation.
GitHub source selection and context build
Investigation graph with agent plan review
Finding handoff drafted as GitHub issues
Repository
The repo includes the Next.js frontend, Hono backend, shared schemas, agent runtime packages, screenshots, and demo video.
github.com/Inferensys/northwallSource repositoryProduct architecture
Northwall treats source context, evidence, authorization, and handoff as product surfaces, not hidden backend steps.
Context
GitHub OAuth and repo selection keep source context tied to the investigation.
Source map
The backend reads the files analysts need during response: routes, auth, config, CI, packages, and ownership hints.
Reasoning
Services, dependencies, owners, and work items become a graph the analyst can review.
Approval
Specialist agents and task order are shown before the investigation run starts.
Action
Findings become GitHub issues after the analyst selects and approves them.
Use cases
Northwall is shaped around security work that needs context, evidence, approval, and a clear owner handoff.
Triage
Turn noisy signals into a reviewed investigation plan with source context and analyst approval.
Investigation
Map services, dependencies, auth paths, routes, and owner hints into an investigation graph.
Vulnerabilities
Use repository context to draft actionable findings with evidence and suggested owner notes.
Response
Create a response record that shows what was checked, what agents found, and which actions need approval.
Remediation
Convert selected findings into GitHub issues with severity, confidence, evidence, labels, and owner notes.
Integration pattern
Northwall starts with repository context and issue handoff. The same product pattern can extend to SIEM, EDR, cloud, identity, ticketing, and evidence stores.
GitHub
Read repo, branch, packages, routes, auth files, config, CI, and ownership hints before running agents.
Detection
Alert data can feed the same triage workflow when teams connect Splunk, Sentinel, Datadog, or other detection sources.
Endpoint
Endpoint findings can be reviewed against source context before creating response work.
Cloud
Cloud configuration and identity events fit the same graph model when a team needs wider attack-path context.
Action
Approved findings can move into GitHub, Jira, ServiceNow, or SOAR workflows with evidence already attached.
Workflow showcase
The main product screens keep source context, agent planning, live work, and handoff decisions visible.
Source selection
The analyst chooses the source system up front. Tokens stay server-side, and the frontend sees connection metadata only.

Plan review
Northwall shows source context, the investigation graph, the agent team, task order, and approval notes in one place.

Live run
Socket.IO events keep the run log, findings, and evidence trail visible while the investigation is active.

Handoff
The analyst chooses which findings become GitHub issues and reviews the issue text before creation.

Operating loop

01
The analyst selects a GitHub repo and branch. Provider credentials stay on the backend.
02
Northwall inventories packages, routes, handlers, auth, config, CI, and ownership context.
03
The agent team, task order, graph, and approval notes are shown before the run starts.
04
The live stream shows agent activity, evidence, findings, confidence, and severity.
05
Selected findings are previewed as GitHub issues and sent only after analyst approval.
Core screens

01
The entry page explains the agentic SOC workflow in plain operational terms.

02
The analyst sees the investigation plan, graph, agent roles, and approval notes before the run starts.

03
Approved findings move into GitHub with evidence, severity, confidence, owner notes, and labels.
Search questions
These questions map to searches around AI SOC automation, alert triage automation, AI incident response, and security operations AI.
An agentic SOC platform uses AI agents to help with security operations work such as alert triage, threat investigation, evidence gathering, run logging, and response handoff. The analyst still needs clear review and approval points.
Northwall connects source context, builds an investigation graph, shows the agent plan, streams the run, and presents findings with severity, confidence, evidence, and owner notes.
Northwall is designed for human-in-the-loop security operations. It helps agents investigate and draft findings, but response work moves forward after analyst approval.
The first connector is GitHub for repository context and issue handoff. The same workflow can extend to SIEM, EDR, cloud, identity, ticketing, SOAR, and evidence storage systems.
Northwall fits AI alert triage, threat investigation, vulnerability review, incident response support, security work item creation, and source-aware remediation planning for owned systems.
Product coverage
The build includes the marketing entry point, source picker, plan review, live run, findings handoff, and mobile login flows.

Landing

Source selection

Agent plan

Live run

Findings

Mobile login
Contact
Share what you are building, where you need help, and what needs to ship next. We will reply with the right next step.
01
NDA available
We can start under NDA when the work requires it.
02
Direct team access
You speak directly with the team doing the technical work.
03
Clear next step
We reply with a practical recommendation on scope, implementation, or rollout.
30m
working session
Direct
team access