VOLOVLOAutomation risk & transition, task by task
AskOccupationsMajorsBusinessFoundersChangesNotesMethod
Search occupations, majors…
EN
  • English
  • 简体中文
  • 日本語
  • Español
  • Português
  • Français
VLO
VOLO

Understanding how automation changes work — task by task, with the evidence shown and the uncertainty admitted.

AskOccupationsMajorsBusinessFoundersChangesNotesMethodAboutRole diagnosisPrivacyTerms
© 2026 VOLO
Occupations
All occupations
AI / software
Translator / InterpreterBank tellerCopywriterCustomer service representativeAdministrative assistantSoftware tester / QA engineerGraphic designerParalegalVideo editorAccountant / BookkeeperMarketing specialistFrontend developerData analystInsurance claims handlerTechnical writer / documentation engineerJunior software developerHR / recruiterLoan officer / credit officerFinancial analystProcurement / supply chain specialistJournalistSales / account managerReal estate agentIT support specialist / helpdeskAuditorManagement consultantBackend developerAI researcherProduct / UX designerBusiness systems ownerE-commerce operations specialistRadiologistData engineerLawyerMedical assistant / clinic assistantMachine learning engineerExperienced software engineerDevOps / platform / SRE engineerProduct managerPharmacistPartnerships / channel managerSecurity analyst (SOC)Compliance officerArchitectFirst-line manager / team supervisorCounsellor / therapistRetail salesperson / shop assistantSecurity guardSchool teacherGeneral practitioner / primary care doctorWaiter / restaurant serverAuto mechanic / vehicle technicianPhysiotherapist / rehabilitation therapistConstruction workerRegistered nurseCare worker / nursing assistantAI implementation lead
RPA / self-service
Government service clerkOperations coordinatorReceptionist / front desk
Robotics
Retail cashier / shop assistantWarehouse workerAssembly line workerMedical laboratory technicianChef / cookCleaner / janitorElectrician
Autonomous driving
Ride-hail / taxi driverTruck driverDelivery rider / courier
Majors
All majorsEnglish / Foreign languagesComputer scienceAccountingPsychologyJournalism / CommunicationFinance / EconomicsLawVisual communication designMarketingNursingBusiness administrationEducation and teacher trainingArchitecturePublic administrationMedicine
Guides
Ask VOLOFor businessFor foundersRecent changesNotesRole diagnosisMethod & evidenceAboutFollow an occupationSearch
Enter as:I have a jobI am studyingI run a companyI am building something
Recent changes›Security analyst (SOC)›2025-06-01
DeploymentCognitive automation2025-06-01

The US Justice Department reported a user-behaviour monitoring system in production since June 2025 that it says finds behaviour too subtle for a person to detect

Security analyst (SOC)occupation page →
Event date / reported
2025-06-01 · reported 2026-01-28
Evidence stage
DeploymentAn employer has put it into production. Can move the baseline — weighted by scale and how similar the setting is.
Tasks this bears on
Looking for what nothing alerted on
Starting from a hypothesis rather than an alert — assuming something is already inside and going to look for it.
Still human-led✓ Evidence-backed
Where this applies
One bureau (EOUSA) inside one department, reported under a statutory duty rather than chosen for publication. Entry DOJ-0119 in the individually-reported CSV. The inventory gives the month, not the day, so the date here is the first of that month. The claim that matters is the department describing the problem it solves as "identification and prevention of anomalous user behavior too subtle for human detection and analysis" — an employer stating in a filing that a machine covers ground its people cannot. Two things are in the same rows and belong beside it. The department classified this system High-impact, and every safeguard the high-impact classification requires is recorded as in progress: testing, impact assessment, independent review, ongoing monitoring, training, failsafe, appeal process and public consultation, with authority to operate answered No. The system holds personal data. Separately, entry GSA "Elastic Machine Learning Threat Detection (Phase 2)" describes the other side of the same boundary in a different agency, saying its models allow "isolation and ranking of cyber threats, facilitating faster and more accurate escalation to threat hunting and incident response teams" — the machine ranks and the hunting team still receives. Neither entry reports a headcount, a caseload or a measured detection rate, and the department's own evaluation of whether the claim holds is one of the items marked in progress.
What this means
An employer put a system into production on the claim that it sees what its people cannot, and put that claim in a filing rather than a brochure. Read beside it the other entry in the same inventory, where the machine ranks and a hunting team still receives what it ranked: the two together describe a boundary being moved rather than a job being removed, and the department has not yet finished testing whether its own claim is true.
What it does not yet show
It does not say anyone hunts less. There is no headcount, no caseload, no measured detection rate and no comparison with what the team found before. It also does not establish that the claim is true: the department's own testing, independent review and ongoing monitoring are all recorded as in progress, on a system it classified as high-impact, holding personal data, with authority to operate answered no. A filing that a system exists is not a filing that it works.
What you can check
If your organisation runs behaviour analytics, ask for two numbers: how many of its findings in the last quarter turned out to be something, and how many of the things you did find started somewhere other than the tool. The second number is the one that tells you whether the hunting still has to happen, and almost nobody keeps it.
Does it change the assessment?
No. The impact index is never moved by a single event. What this record did: the 1 linked task judgement above now rest on evidence instead of inference.
Source
OMB — 2025 Federal Agency AI Use Case Inventory (entry DOJ-0119) · verified 2026-09-20 · Claude (agent) · interpreted 2026-09-20 · Claude (agent)
Primary source — published by the party that did this, or the authority of record. No co-signature needed.
All changes for Security analyst (SOC) →All recent changes →How events become evidence →