Most SOC outsourcers ticket and escalate.
The pattern is familiar to anyone who has bought a security service that disappointed them. An alert fires. A Tier-1 analyst somewhere clicks through a checklist they don't fully understand. The ticket gets escalated, then escalated again, and eventually it lands in your queue with a note that says, in effect, "something is happening, please handle it." By the time a human on your side reads it, understands it, and decides what to do, the attacker has already moved laterally, and the window to contain cheaply has closed. You paid for monitoring and got a notification service.
Our MDR engineers contain incidents themselves. When a real threat is confirmed, we isolate the affected machine, kill the malicious session, and stop the spread, without waiting for your sign-off on the obvious. The escalation to you is a phone call after the fire is out, with a written timeline and clear recommendations, not a 3am alarm asking you to log in and figure it out. We don't hand you the problem. We hand you the postmortem.
"They called at 4am to tell me they had already isolated the laptop. I went back to sleep. The postmortem was in my inbox at 8."
This is only possible because the same firm that watches your environment also runs it, or works closely with whoever does. Containment requires the authority and the context to act, and an outside SOC that has never seen your network can do neither. Pairing MDR with managed technology means the people responding already know which server can be isolated safely and which one runs payroll.