L3 analysts handle the highest-severity incidents, conduct proactive threat hunting, and serve as subject matter experts for specific threat domains. They may also contribute to detection engineering, incident response planning, and mentoring junior analysts. L3 capacity is limited and expensive, making it critical that their time is not consumed by work that could be handled at lower tiers. Freeing L3 analysts from repetitive escalations is a key objective of SOC automation.