Two scopes
Workspace-wide. The chat resolves every connected integration and every skill in the workspace. This is the mode for open-ended work: hunting across sources, answering a question nobody wrote a skill for, or reaching a tool no agent owns. Agent persona. Scope the chat to one agent and it inherits exactly that agent’s skills, tools, and instructions. Use it to interrogate what an agent would do — and to test a skill change before an alert exercises it at 3am.Threat hunting
Because the chat holds every connected integration at once, a hunt does not mean opening six consoles.- Query the detection stack directly — Microsoft Sentinel KQL and advanced hunting, Splunk searches, Datadog, CrowdStrike Falcon and cloud, SentinelOne, Microsoft Defender XDR, Falco, Wiz, Huntress.
- Pivot across identity — Okta, Microsoft Entra, Google Workspace, JumpCloud, 1Password, and the device fleet behind them.
- Pivot across infrastructure — AWS, GCP, Cloudflare, Vercel, Replit, Tailscale, DNS lookups, and on-chain address data.
- Search Clarion’s own memory — signals and signal rules, the issue history, and every asset’s merged timeline. “Have we seen this before?” is one question, not an archaeology project.
- Start from the Brain — ask who owns a host, what a service supports, or which devices belong to a person, before touching a single provider API.
Automating security work
Anything a skill can instruct an agent to do, the chat can do on request — with the same guardrails.- Remediate through the connected providers: DNS records, cloud IAM, endpoint containment, identity actions.
- Notify and escalate to a configured destination, or DM a specific person.
- Draft and file tickets, evidence, and questionnaire answers grounded in workspace knowledge.
- Read the docs — Clarion’s own documentation is a tool, so “how do I configure this” is answerable in place.
Building agents by asking
Authoring — creating agents, writing skills, and setting up schedules from a prompt — runs over Clarion’s MCP server rather than in the in-app chat. Connect Claude Code, Cursor, or any MCP client to your workspace and you get tools to:- Create an agent from scratch or from one of the agent templates, and update it afterwards.
- Create a skill from scratch or from a skill template, and edit it in place.
- Browse the template library — list and read agent and skill templates before instantiating one.
- Operate the scheduler — create, update, enable, disable, and run schedules once.
- Drive chats programmatically — start a chat, send messages, and read transcripts from a script.
- Inspect runs — read agent jobs and their full transcripts, retrigger an issue, complete a remediation item.
- Read and write the Brain — search knowledge, propose and update elements, link assets, and manage workspace instructions.
Authoring agents, skills, and schedules is an Admin permission wherever it is done, including over MCP — see Roles & permissions for why.
Where chats live
Chats are workspace objects, not browser tabs. They persist, they’re listed, and a chat’s transcript can be read back later — by a teammate, or by a script over MCP. Assistant chats have their own permission (Use the assistant), held by every role. Slack and Microsoft Teams can also front the assistant, so a question asked in a channel reaches the same runtime as one asked in the app.The Brain
The memory chat reasons with.
MCP access
Connect Claude Code or Cursor to your workspace.
Our agents
Templates to build from.
Tools
What agents and chat can call.