Use Case
On-call SOC workflows that fit on a phone.
An on-call SOC is a security operations team that maintains 24×7 coverage by rotating who carries the pager. PocketSOC supports on-call SOC workflows through portal-managed credentials, group-based push notification routing, on-call schedule integration, biometric-protected actions, and per-device audit visibility. Teams configure vendor connections once in the PocketSOC Portal and assign them to groups; only the on-call rotation receives push notifications outside business hours.
The problem
A SOC team of six analysts rotates the on-call duty across nights and weekends. The team needs every analyst to be able to triage incoming alerts and take containment actions, but only the person on rotation should be woken up. Sharing API credentials by email is a non-starter. Letting every analyst configure their own credentials means inconsistent scope and no central revocation. There has to be a way to manage this from one place.
The PocketSOC workflow
- A SOC admin configures vendor connections (CrowdStrike, Defender, GuardDuty) once in the PocketSOC Portal
- Admin creates groups (e.g., "Tier 2 On-Call") and assigns the vendor configs to each group
- Analysts are invited to the appropriate groups via the portal
- On-call schedule is configured so only the active rotation gets push notifications
- Each analyst signs into PocketSOC; the app pulls the vendor configs assigned to their groups
- Devices are visible in the portal — admins can deactivate any device immediately if it's lost or an analyst departs
- All actions are logged with the analyst's identity in the vendor audit trail and in PocketSOC
Outcomes
- Centralized credential management — rotate, revoke, or update vendor secrets in one place
- Group-based scoping — junior analysts see what they need to, senior analysts see more
- Push notification routing follows the on-call schedule, not the whole team
- Per-device audit visibility — every action is attributable to a user and a device
- New hires onboard in minutes; departing analysts are removed centrally
Supported vendors for this workflow
- CrowdStrike Falcon
- Microsoft Defender for Endpoint
- Microsoft Defender for Cloud
- AWS GuardDuty