OpenSecOps SOAR 4.0.0: Current Claude Models
SOAR 4.0.0 is released. It moves SOAR's AI analyses to the current generation of Claude models on Amazon Bedrock. It is a major release because the AI configuration changes: two parameters are removed and six take their place, so an existing installation needs a small configuration edit before it can deploy.
Why
SOAR uses Claude to explain each security ticket, autoremediation and incident to the team that owns the account, and to write the weekly security report. Until now it ran on Claude Sonnet 4.5, named by a hand-written inference-profile ID in the configuration. The current Opus and Sonnet models produce better security analysis, but they take a different request (adaptive thinking with a configurable effort level) and they can decline requests. Keeping up with new models should not mean editing profile IDs or code each time, so the configuration now names models and SOAR works out the rest.
Declines and the fallback
Claude Opus 5.5, Opus 5 and Sonnet 5.5 have safety classifiers that can decline a request, and Anthropic notes that benign cybersecurity work can trigger them. SOAR's analyses are exactly that: defensive explanations of findings from AWS's own security services, sent only to security staff and the account's team. The prompts now state this purpose plainly, which removed most declines in our tests, but not all.
So SOAR 4.0.0 requires a fallback model. When the primary model declines, SOAR asks the fallback once. The recommended fallback is Claude Opus 4.8, which has no such classifiers. Each time the fallback answers, SOAR publishes a message to a new SNS topic, OpenSecOpsSOARAIFallbacks, so you can see how often it happens. Subscribe to it if you want to know. Failures of any kind still go to OpenSecOpsSOARExternalCallFailures, and the ticket, incident notification or report is still sent, without the AI text.
Configuration
Six keys in apps/soar/parameters.toml, all required:
| Key | Recommended | Meaning |
|---|---|---|
| AIModel | anthropic.claude-opus-5-5 | The model for all analyses. Claude Opus 4.6 or Sonnet 4.6 or later. |
| AIFallbackModel | anthropic.claude-opus-4-8 | Used once when the primary declines. Choose a model without classifiers. none disables it. |
| AIRegion | us-east-1 | The Bedrock Region SOAR calls. |
| AILocality | regional | regional: processing stays within the Region's geography (US, EU, Japan, Australia and so on). global: any commercial Region worldwide, at slightly lower cost. |
| AIEffort | high | How much the model thinks before answering. Opus 5.5 accepts low, medium, high, xhigh and max. |
| AIMaxTokens | 128000 | Output cap, thinking included. At most the model's limit; 128000 for both recommended models. |
SOAR asks the model for adaptive thinking with an effort level. Claude Opus 4.6 and Claude Sonnet 4.6 are the earliest models that accept both; Claude Sonnet 4.5, the model SOAR used until now, does not. Effort levels vary by model: Opus 4.6 and Sonnet 4.6, for example, have no xhigh.
An EU organisation that wants inference to stay in the EU sets AIRegion to an EU Region and keeps regional. Claude Sonnet 5.5 at high is a faster alternative to Opus 5.5; keep Opus 4.8 as its fallback.
Every deploy checks the configuration: SOAR looks up each model's inference profile in your Region and calls each model once. A wrong model ID, a model without a profile in the Region, an effort level or token cap the model rejects, or a model the account cannot use stops the deploy with the reason, and the previous version keeps running.
SOAR 4.0.0 supports Claude models only. We intend to open it to more models in coming releases.
Also in this release
- AI error handling is consistent: every AI step retries transient Bedrock errors and reports a failure once. Before, some steps caught only timeouts and some caught nothing.
- Fresh installations of SOAR and of
Foundation-control-tower-log-aggregatorfailed on two custom resources (one since SOAR 3.0.0 and log-aggregator 1.6.0, one since SOAR 2.4.1). This is fixed, and a custom resource that does not respond now fails the deploy after 5 minutes instead of an hour. The log-aggregator fix is in its 1.6.7 release. - The 1 October component releases moved
urllib3to 2.8.0 wherever it is used, fixing CVE-2026-97687, CVE-2026-97688 and CVE-2026-97689../initinstalls them along with this release; nothing else is needed.
Upgrading
cd Installer && git pull, then./initon both Foundation and SOAR.- In
apps/soar/parameters.toml, delete theBedrockRegionandBedrockModellines and copy in the six AI lines fromapps.example/soar/parameters.toml. Adjust the values if you want. ./deploy-all, as usual.
Without step 2, the SOAR deploy stops before changing anything, with Parameters: [AIFallbackModel, AIEffort, AIModel, AIMaxTokens, AIRegion, AILocality] must have values.
One prerequisite, which most installations already meet: Anthropic's one-time use-case form must have been submitted for the organisation (organisations already using Claude on Bedrock have done so). Each model's Marketplace subscription is created automatically on first use.
More information
- SOAR
CHANGELOG.md, v4.0.0: the complete list of changes. - Anthropic: Refusals and fallback.
- AWS: cross-Region inference (regional versus global) and model access (the use-case form).