blog

We're Not Replacing the Analyst. We're Changing What the Job Is.

Gal Dudi

Gal Dudi

|

|

Reading Time:

3

min

Table of Contents

Every time this category comes up, someone asks the same question, sometimes directly, usually underneath a different one: does this replace my analysts? It's a fair question. It's also the wrong frame.

Look at what most analysts actually spend their day doing today, and it's rarely judgment. It's legwork in service of judgment. Pulling logs from three different systems that don't talk to each other. Manually checking whether an IP is actually anomalous or just an engineer on a new VPN subnet. Escalating a case not because it's genuinely ambiguous, but because the analyst who picked it up doesn't have visibility into the one system that would resolve it in ten seconds, so it goes up the chain to someone who does. None of that is the skill we hired analysts for. It's the tax we pay for context being scattered.

That's the part of the job that changes. Not the analyst's judgment, the plumbing underneath it.

From executor to supervisor

The old model has the analyst doing the gathering and the deciding, back to back, case after case. The new model has the agentic layer doing the gathering, continuously, across every system the org runs, and surfacing a case to the analyst already assembled: here's what happened, here's the context from the four systems that matter, here's what we'd recommend and why. The analyst's job stops being "go find out" and becomes "review this, and decide."

That's a supervisor's job, not an executor's. It's a more senior use of a person's time, not a smaller one.

From queue-clearing to decision-making

When most of the day is spent gathering context, the actual decisions get made in whatever time is left, often rushed, often on cases that piled up while the analyst was heads-down on a different one. Consistency suffers not because the analyst lacks skill, but because judgment made at the end of a long context-gathering slog is worse than judgment made with the context already in hand.

Take the gathering off the table, and what's left is the actual decision, made with full context, every time. That's not a smaller job. It's the job the analyst was trained for, minus the parts that were never a good use of that training.

Why this changes what "tier 1" can mean

Escalation exists because knowledge isn't evenly distributed. A tier-3 responder isn't smarter than a tier-1 analyst, they've just spent years accumulating context: which systems to check, what normal looks like for this org, what the last five incidents like this one turned out to be. That's the actual gap between tiers. Not judgment. Accumulated access.

Close that gap and the tiers collapse. When every case arrives with the same depth of context a senior responder would have spent hours building, a tier-1 analyst isn't making a tier-1 decision anymore, they're making the same call the best person on the team would make, on their first case, on day one.

That's the real shift. Not "tier 1 escalates less." Tier 1 becomes as good as your best analyst, every time, because the thing that used to separate a junior responder from a senior one wasn't skill. It was what they had in front of them when they had to decide.

The role, not the headcount

This is the distinction we keep coming back to at Treat. The machine doesn't remove the person who used to run it by hand. It changes what running it means. The analyst who used to spend the day turning bolts now spends it configuring the machine, deciding what matters, catching what the machine gets wrong, owning the calls that genuinely need a human behind them.

AI does the work. Humans own the decision. That line isn't a tagline for us, it's a description of exactly where the boundary sits.