Skip to content
Calcrivo

Analyst Capacity Calculator

Work out how many alerts one analyst and one shift can genuinely handle from shift hours, utilisation and handling time.

Inputs

hours
%
minutes
%

Pre-attached asset, identity and intel context removes most manual lookup time.

analysts
alerts

Alerts per Analyst per Shift

68.6alerts

Effective Handling Time

4.90minutes/alert

Shift Capacity

205.7alerts/shift

Daily Capacity Across All Shifts

617alerts/day

Capacity Headroom

-16.7%

Negative means the queue outruns the team.

Extra Analysts Needed

0.50analysts

Step by step

  1. Values used

    Shift length = 8 hours; Utilisation available for triage = 70 %; Handling time per alert = 7 minutes; Handling time saved by automated enrichment = 30 %; Analysts per shift = 3 analysts; Alerts arriving per shift = 240 alerts

  2. Analyst Capacity

    Alerts per analyst per shift = shift hours × 60 × utilisation ÷ effective handling minutes, where effective handling time = raw handling time × (1 − enrichment saving).

  3. Staffing gap

    Extra analysts = (arriving alerts − shift capacity) ÷ alerts per analyst, floored at zero.

  4. Alerts per Analyst per Shift

    = 68.6 alerts

  5. Effective Handling Time

    = 4.90 minutes/alert

  6. Shift Capacity

    = 205.7 alerts/shift

  7. Daily Capacity Across All Shifts

    = 617 alerts/day

  8. Capacity Headroom

    = -16.7

  9. Extra Analysts Needed

    = 0.50 analysts

How it works

The three levers are visible in the formula and cost very different amounts: hours are fixed, utilisation moves only a few points with better process, and handling time is where automated enrichment produces the large gains — cutting seven minutes to five raises throughput by 40%. Capacity is the number that decides whether a detection actually gets looked at, and it is the honest counterweight when someone proposes enabling another two hundred rules.

Formulas

Analyst Capacity

Alerts per analyst per shift = shift hours × 60 × utilisation ÷ effective handling minutes, where effective handling time = raw handling time × (1 − enrichment saving).

utilisation
Share of the shift genuinely spent triaging, 65–75% in practice
handling time
Mean minutes from opening an alert to closing or escalating it
enrichment saving
Reduction from pre-attached context

Staffing gap

Extra analysts = (arriving alerts − shift capacity) ÷ alerts per analyst, floored at zero.

shift capacity
Alerts the whole shift can handle
arriving alerts
Alerts presented to that shift

Frequently Asked Questions

How is Analyst Capacity calculated?

Alerts per analyst per shift = shift hours × 60 × utilisation ÷ effective handling minutes, where effective handling time = raw handling time × (1 − enrichment saving). The three levers are visible in the formula and cost very different amounts: hours are fixed, utilisation moves only a few points with better process, and handling time is where automated enrichment produces the large gains — cutting seven minutes to five raises throughput by 40%.

Why does Analyst Capacity matter?

Capacity is the number that decides whether a detection actually gets looked at, and it is the honest counterweight when someone proposes enabling another two hundred rules.

What values do I need to enter?

This calculator takes 6 inputs: Shift length, Utilisation available for triage, Handling time per alert, Handling time saved by automated enrichment, Analysts per shift, Alerts arriving per shift. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Why does enrichment beat hiring?

Because it multiplies rather than adds. Removing two minutes of manual lookup from every alert raises the whole team's throughput at once, whereas a new analyst adds one shift's worth of capacity and costs six figures a year.

Is a fixed handling time realistic?

It is an average over a skewed distribution — most alerts close in two minutes and a few consume an hour. Use it for planning, and if the tail matters to you, run the calculation separately per alert class.

You might also need