Skip to main content

Socrates: Investigate Outside a Case

Ask Socrates Investigator anything - investigate, review, and take action at a workspace level.

Overview

Socrates is Torq's in-platform conversational AI surface for its AI agents. This article covers Investigator (Socrates working as an autonomous SOC analyst outside a case), which you select with the Investigator/Builder toggle at the top. (Builder, the other agent at launch, can perform workspace-level actions; see Socrates Builder: Getting Started.)

Investigator is always available across your workspace. For Socrates working on a specific case, see Socrates: Transform Case Investigations.

Scope

As a SOC analyst, Socrates works in three ways:

  • In-case chats: Inside a case, in the case's Socrates tab.

  • Autonomous case investigation: Socrates runs a predefined Actionplan on an assigned case.

  • Investigation outside a case: As Socrates' Investigator agent.

Outside a case, a chat operates across your entire workspace. Any signal (an alert, an observable, or any other finding or query) can serve as the starting point. Socrates draws on full workspace context, including existing cases and observables, to help you investigate, operate, and take action across your tech stack.

Prerequisites

  • Case Management is enabled for your workspace. Investigator is available only to Case Management customers.

How to use

Find and open Investigator

  • Open Socrates from the Socrates entry at the top of the left sidebar, then select Investigator using the Investigator/Builder toggle.

Start a chat

  1. Navigate to the Socrates tab.

  2. Enter a prompt in the message field describing what you want to investigate or do.

Use tools in a chat

To see which tools are available or ask Socrates to use a specific one, open the tool menu and select a tool. The selected tool is embedded in your message as a chip.

  • In Socrates: type / to open the tool menu.

Socrates only uses existing, enabled tools, and it cannot execute built-in tools in restricted cases. Explicitly selecting a tool does not guarantee that Socrates will use it. It may choose a different or additional tool based on your message. See Socrates Tools.

Reference

Collaboration and history

Chats are saved and can be shared for collaboration. You can filter the chat list to All chats, My chats, or Public chats. Multiple analysts can view, contribute, and take action, with full visibility into Socrates' responses and executions. You can rename or delete a chat from its three-dot menu.

Chat access

Each chat has one of three access levels, set from its three-dot menu under Manage access. New chats are Private by default.

  • Private: Only you can access the chat.

  • Restricted: Only you and the users or groups you select can access the chat.

  • Public: Anyone with the socrates.investigations.read scope can access the chat. Without that scope, a user can't open the chat even though it's Public.

You can add collaborators from the message composer before starting a new chat. For an existing chat, manage its collaborators and access level from its three-dot menu instead.

Anyone with access to a chat, whether added explicitly or because it's Public, can send messages in it. The one exception is admin mode, available to the Owner role: an Owner viewing a Private chat they weren't added to can see it, but can't send messages.

Only the chat's owner, the user who created it, can change its access level or manage its collaborators. Other participants can take part in the chat, but can't modify who else has access.

Changing a chat's access level or adding a collaborator to a Restricted chat gives that person immediate access to the chat's full history, not just to messages sent afterward. Review the contents of a chat before expanding its access, especially if it concerns a sensitive topic.

Monitoring

Activity logs: Each message in a Socrates chat is recorded in the Activity Log (event source: Socrates conversation message), whether or not Socrates performs an action.

Audit logs: When Socrates performs an action, the Audit Log attributes it to Socrates, acting on your behalf. See Socrates Auditing: Monitor Your AI Analyst.

Permissions

  • socrates.investigations.read: List and read the content of chats.

  • socrates.investigations.write: Start and participate in chats. Available to all roles except Viewer roles.

For more on scopes and permissions, see Torq Roles and Scopes.

Use cases

Investigate indicators: Enrich and investigate IOCs, IPs, domains, users, and endpoints across Torq observables and cases, as well as the threat intelligence feeds and platforms you are integrated with. For example, check whether an indicator is linked to known threats, or look up DNS data for a domain.

Query and act on cases: Search cases and observables, break them down by criteria, and take action. For example, find cases matching specific criteria, assign them to an analyst, and send a Slack notification with case details.

Take response actions: Run the tools set up in your workspace to respond directly from a chat, such as adding an IP or domain to a blocklist, contacting a compromised user, or quarantining a user or endpoint. Available actions depend on the Socrates Tools you have configured.

FAQ

What permissions do I need for workspace-level investigations with Socrates?

The socrates.investigations.write scope to start or participate; socrates.investigations.read to view only.

Does Socrates store or share workspace data?

No. All data remains private within your workspace. Socrates processes context within the workspace and does not expose data beyond it.

Explore related resources

Did this answer your question?