We had an agent loop running in early 2026, and it still failed. Here is the scaffolding that made Sherlock, our investigation agent, useful in real incidents: 85% of the roughly 11,000 alerts a month suppressed as noise before a model ever runs, and investigations that once took 10+ minutes now finish in about 2 minutes on average, for less than a third of the cost.