One portfolio, three boundaries

Google TIN can start automatically or manually and produces a structured alert assessment. Threat Hunt Agent is analyst initiated and read-only during a hunt. Detection Engineering Agent runs through compatible MCP clients, evaluates coverage, and drafts YARA-L rules that must be reviewed and created manually.

What actually differs?

AgentTriggerOutputWrite authority
TINEvent driven or manualVerdict, findings, reasoningRead-only in the reviewed documentation
Threat Hunt AgentHuman initiatedHunt case and evidenceRead-only
Detection Engineering AgentHuman initiated through MCPDraft YARA-L rulesNo automatic upload

Availability conflict

The public corpus contains conflicting preview descriptions for the Detection Engineering Agent. That conflict remains open for human review, so the projection reports availability as UNKNOWN rather than selecting the more favorable source.

Procurement consequence

Buyers should not treat the Agentic SOC umbrella as one deployment model. TIN is embedded and quota constrained, Threat Hunt depends on Enterprise Plus preview access, and the Detection Engineering Agent requires an external compatible MCP client. These differences affect integration effort, control testing, and licensing.