We replaced our SOAR in a month. Here’s the honest story of why we did it, and what happened next.
I want to be upfront with you: what I’m about to describe did not start as a success story.
It started with a win. Victrix’sSEvOC, the managed SOC I run in Quebec, won a major RFP. Forty-five new customers in the parapublic sector, all at once. Hundreds of thousands of new endpoints to protect. It was exactly the kind of growth we had worked toward.
Then came the question nobody had fully answered: how do we actually serve all of them?
We could not hire twenty new analysts. That was never the plan. The plan was to automate our way to scale with a SOAR. So that is what we did. Restricted choices: we need Canadian Data residency. We invested in one. We onboarded it. We set a target of automating at least 20% of our incoming tickets within the first year.
At the end of that year, I had to tell my leadership something uncomfortable: we had failed to hit that goal. Not because the team did not work hard. Because the platform did not work for us.
“Each time we went live with something new, it brought new problems. Our analysts stopped using it entirely. They went back to doing everything manually.”
I do not say this to embarrass anyone. Every vendor has growing pains. But when your analysts are actively routing around your SOAR because it is too buggy to trust, that is not a product problem you can wait out. That is a signal.
So we started looking again.
The 3 Requirements we could not compromise on
By the time we decided to switch, we knew exactly what we needed.
#1: Production-ready AI
built into the platform. Not promised on a roadmap. Not a bolt-on tool sitting next to the SOAR. AI embedded in the playbooks, doing the investigation and correlation that was eating our analysts alive. Our previous vendor had promised this. We never saw it in production.
#2: Canadian data residency
This is not optional for us. Our customers’ data stays in Canada. That requirement eliminated a lot of options and, honestly, it was the reason we did not go with Swimlane the first time. Swimlane was actually our first choice a year earlier. But they did not have a Canadian tenant then, so we went elsewhere.
#3: A partner that understands and supports MSSPs
A managed security provider is not the same as an enterprise running a single internal SOC. We have dozens of customer environments, dozens of different tool stacks, and we need a platform built for that complexity. The previous support team never quite got that.
The call that changed everything
About six months after we started looking, Swimlane reached out. They had built a Canadian tenant. Were we still interested?
I did not hesitate. I knew what I had to do. I had to convince my leadership that we should rip out a SOAR we had just spent a year building on, migrate everything, and do it fast. That was not an easy conversation. But I believed in it, and I made the case.
Then came the part I really was not prepared for.
“We did in three weeks exactly the same thing we had done in one year with the previous platform. Even my boss didn’t believe me when I said that.”
Why this time was different
The Swimlane team worked in parallel with us the entire time. While they were rebuilding our integrations and workflows on their side, my team was training. We built some playbooks together. Swimlane would review them and say, you got it, keep going. It was a genuinely different way of working. Not a vendor handing us documentation and wishing us luck. An actual partnership.
“If we have to work days, nights, and weekends to make this switch,” my team told me, “we will do it.” And they meant it. There was energy around this migration that I had never seen with the previous platform. People wanted to move.
What We Noticed Immediately
The first thing I noticed was adoption. Every analyst who had been bypassing our SOAR and working manually was now using Turbine. All of them. From day one. That alone told me something important: when a tool is actually good, you do not have to force people to use it.
The second thing was the integrations. With our previous SOAR, every tool in every customer environment required its own separate integration work. With Turbine, we build one playbook and one connector for an EDR category. That single playbook runs against Microsoft Defender, CrowdStrike, or SentinelOne. Same logic, different connector behind it. We also built an Azure enterprise application that centralizes all the permission management across our customer base. The combination is clean in a way I had not experienced before.
The third thing was the AI. And this is the part I want to spend a moment on, because it matters.
The AI That Actually Does What It Says
We started embedding Swimlane’s AI into our playbooks. The AI runs the investigation. It correlates signals, analyzes the alert, and explains its conclusion to the analyst in plain language. The analyst reads it, makes the call, closes the case. What used to eat an hour of careful manual work now takes minutes.
I track every case where the AI makes a recommendation. I want to know how often the analyst agrees with it.
So far: one hundred percent of the time.
Every single recommendation Turbine has made in production, the analyst has reached the same conclusion independently.
I am not ready to say AI takes the wheel entirely. We are still in the phase where humans confirm every decision. That is the right call for now. But once a case type has a long enough track record, we will let the AI close it without analyst sign-off. That transition is coming. The data supports it.
“The AI does the job of an analyst, totally. It explains the tickets and alerts, and the analyst just has to decide if it’s okay or not. So far, no fails.”
Where We Are Going
Within six months, I plan to move 50% of our analysts off Level 1 work entirely. Not lay them off, but advance them to more strategic and interesting work. Give them Level 2 and Level 3 responsibilities. Security projects. Threat hunting. Work that actually needs a human brain, not just a human pair of eyes to confirm what software already figured out.
We are also planning to expand how we use Turbine. Vulnerability management is on the roadmap. Reporting is changing. The ticketing system may eventually move fully into Swimlane. We are building a broader cyber platform at Victrix, and Turbine sits in the middle of it.
One Piece of Advice If You Are Where We Were
If you are an MSSP running a SOAR that your analysts are working around instead of with, take that seriously. That is not a training problem. That is a platform problem.
And if you are evaluating replacements, here is what I would tell you: pick one use case. Something that costs your analysts real time every day. Email phishing analysis. Alert enrichment. Something concrete. Ask for a proof of concept on just that one thing. See what Turbine does with it in a couple of weeks.
The math will make the decision for you.
Ready to replace your SOAR?
If your analysts are working around your current SOAR, it’s time to upgrade to Swimlane AI SOC.

