Teams

Shift scheduling for SOCs, NOCs and 24/7 operations teams

SOC Rotate is shift-scheduling software for Security Operations Centres, MSSP and in-house, and for the Network Operations Centres and 24/7 operations or support teams that run the same rotation.

Security operations is where every feature came from. The shift model underneath it, with tiers, a night watch, a handover and coverage someone has to prove, is the one the others run too. See what the product does →

SOCs

SOC shift scheduling, built here first.

MSSP or in-house, one office or a follow-the-sun chain: this is the rotation the product was designed around, and every screen assumes a SOC floor.

  • Tiered coverage per shift, such as two T2 and one T1 on nights, enforced by the schedule rather than written in a runbook.
  • For an MSSP, clients are first-class: each carries its SLA target, the offices serving it, and a report link the client opens without a login.
  • Handover notes carry open incidents, live hunts and escalations between shifts, and between offices.
  • Working-time policy by jurisdiction (UK, EU, US, Australia, or your own limits) is the floor under every roster.
NOCs

NOC shift scheduling on the same 24/7 rotation.

A NOC runs the shift model a SOC does: tiers, a night watch, a handover, and an SLA someone has to prove was met. The engine does not care what the alerts are about.

  • Coverage counted per tier per shift, so the escalation path is staffed on nights and weekends rather than on paper.
  • Rule mode or a repeating pattern to build the roster; leave and swaps arrive with the rest check already done.
  • A fairness ledger for nights, weekends and holidays that every engineer can take apart.
  • Handover that names the open incident and who owns it before anyone logs off.

The product says "analyst" and "T1 / T2 / T3" throughout, and neither can be renamed. If your floor says "engineer" and "L1 / L2 / L3", that is the one translation you will make.

24/7 operations & support

24/7 operations and support rotas, where an empty shift is an outage.

Managed service desks, incident-response retainers, trading-floor support, platform on-call: anywhere coverage is contracted and the rotation has to hold when someone is off.

  • Minimum staffing per shift is a hard rule, and the schedule flags the moment a shift drops below it.
  • On-call runs as its own layer over the main rotation, planned alongside it rather than in a separate tool.
  • A team that works to different hours gets its own schedule without disturbing everyone else’s.
  • Every change to the team, schedule, leave and swaps is recorded, searchable and exportable.

The product says "analyst" and "T1 / T2 / T3" throughout, and neither can be renamed. If your floor says "engineer" and "L1 / L2 / L3", that is the one translation you will make.

FAQ

Common questions.

Have something specific to your floor? Speak to sales.

Is SOC Rotate only for security operations teams?
No. It was built for SOCs and every screen assumes one, but the shift model underneath it (tiers, a night watch, a handover, coverage someone has to prove) is the one NOCs and 24/7 operations or support teams run. Nothing in the product is switched off for them; the vocabulary is the one difference.
Can a NOC use it without the security-specific parts?
There are none to switch off. Tier coverage, rest rules, the fairness ledger, leave, swaps and handover are the whole product, and none of them care what the alerts are about. Handover has built-in fields for incidents, hunts and escalations; if "hunts" means nothing on your floor, build the handover form yourself.
Our floor says L1/L2/L3 and "engineer". Does the product adapt?
No. Seniority is T1, T2 and T3 and everyone on a rotation is an analyst; neither is configurable. It is a one-to-one translation, and the only one you will make.
What size of team is it for?
Ten seats minimum. A 24/7 team of four is rostered on a whiteboard; the product earns its place once there are enough people that the rotation, the fairness and the cover for leave stop fitting in one head. See pricing for the per-seat rate.
We run one team across several offices. Does that work?
Yes. Each office keeps its own time zone, holidays and people, and a client served by several offices is a chain whose combined coverage is measured as one picture. Hand-off gaps show before you save and are swept nightly.
Do you integrate with PagerDuty, Opsgenie or ServiceNow?
Not yet. Notifications reach people in the app, by email, or by Slack webhook, and there is no public API today. Tell us which one matters to you; it informs what gets built next.
Is there a free trial or self-serve sign-up?
No. Access follows a demo: send your shift pattern or staffing rules and the rotation is built on your own structure before you decide.
Running a rotation already?

See it on your own rotation, not a demo tenant.

Tell us how your floor is structured: shifts, tiers, offices, who never rotates. We'll build the rotation, walk through where coverage and fairness land, and answer the questions a generalist scheduling tool can't.

  • RotationA month of 24/7 coverage in one action.
  • CoverageEvery gap flagged before it reaches a client.
  • ComplianceEvery change logged, every override on record.