Claude · Codex · any MCP client

You ask. Your agent does the work.

The Companion is where you look. Your AI agent is how you work.

Connect Claude or Codex to The Unbounded SIEM. Ask in plain language to investigate a case, build the monthly SOC report, check whether your data is flowing, or assess compliance evidence. The agent uses Fluency’s governed tools, with exactly your access, and posts the finished work to the Companion for your team.


Start my free 30-day trial
See how to connect Claude or Codex ↓

30 days free, no credit card. Microsoft 365 is enough to start.

A Fluency case page after clicking Investigate in Claude, and the Tier 2 prompt it copies into Claude
One click on a case copies a Tier 2 investigation prompt into Claude.Expo demonstration tenant · synthetic identities

Why an agent needs Fluency

AI is smart. It doesn’t know how to run your SIEM.

On its own, an agent doesn’t know your organization, your data sources, your rules or what is safe to change. Handing it raw API access doesn’t fix that. Fluency teaches it the job.

What the agent has to know

  • Whose data is this question about, and what can I reach?
  • Which data answers it, and which tool fetches that data?
  • What is the right process, step by step?
  • What must never happen: no guessing, no unapproved changes, no mixing one customer’s data with another’s.

Route

Cheat sheets

Match the request to the right mode and load only what is relevant, so the agent’s working memory holds current rules instead of guesses.

Process

Skills

Recipes for whole jobs, like the monthly SOC report or a case investigation. Read them, download them, change them to match how your team works.

Do

Tools

Governed functions with the data, state and safety built in. The agent calls them rather than reinventing them against raw APIs.

Fluency’s behavioral analytics, clustering and risk scoring organize the evidence first, so the agent spends its tokens on the cases that matter instead of reading every event. Read the engineering brief: governed MCP vs MCP over API (PDF) ↓

Investigate

From a Critical case to a verdict you can defend.

A user clicked a link in a Teams message. Defender allowed the click, then flagged the link as phishing. It was the first time that alert had fired anywhere in the organization. Fluency scored the case 8,800, Critical, and its AI triage recommended escalating to Tier 2. Here is what happened when an analyst handed it to Claude.

  1. 01

    Hand it over

    Investigate in Claude copies a Tier 2 prompt with the case, entity, score and triage summary.

  2. 02

    Collect the evidence

    Claude expands the case and captures the raw events: the click, and the message removal.

  3. 03

    Correct the record

    Triage said no mitigation. The evidence shows removal, but 14 seconds after the click.

  4. 04

    Decide

    About 80% real, 15% benign, 5% indeterminate. Next check: the user’s sign-ins after the click.

Timeline of the phishing click, removed 14 seconds later, mapped to MITRE ATT&CK
Claude found what the first triage missed: Microsoft removed the message 14 seconds after the click.Expo demonstration tenant · synthetic identities
A quantified verdict: about 80% real issue, 15% benign, 5% indeterminate, with reasons on both sides
A quantified verdict with the case for both sides, and the one check that would settle it.Expo demonstration tenant · synthetic identities
Read the full investigation report →

Report

“Build the monthly SOC report for August.”

That’s the whole request. The report skill confirms the customer and the month, asks the data 8 to 16 questions about cases, response times, repeat actors and data-source health, and writes an eight-chapter report. Where data is missing, it says so.

“Compare it with July and add recommendations for the board.”

More analysis, for a new audience.

“Format this as a PDF.”

A 16-page, print-ready PDF, checked page by page.

“Post it to Companion.”

Filed in Monthlies for August. Last month’s moves to the archive.

Monthly SOC report: headline numbers compared with July and cases per day for August
From the August report: headline numbers against July, and every chart built from this month’s data.Expo demonstration tenant · synthetic identities

Without an agent

A vendor has to build every variant. The board, the CISO and the SOC each wait for their own version, in a fixed layout, until the next release.

With Fluency and your agent

The same evidence-backed content, shaped for any audience in plain language: your analysis, your branding, HTML or PDF, when you need it.

Automate

Put the work on a schedule.

A scheduled task in Claude or Codex is a prompt that runs on a timetable. Write the whole instruction once, including who hears about the result, and it runs the same way every time.

WhenThe scheduled prompt
Monthly, 1st, 7:00“Build the monthly SOC report for Acme Inc. for last month. Post it to Companion, then send the link with a three-line summary to Acme’s security team in Teams.”
Weekly, Mon, 6:00“Run the health status report for all my tenants. If any data source is broken or stale, message me the list on Telegram. Otherwise, do nothing.”
Daily, 8:00“List the open cases from the last 24 hours with a risk score of 8,000 or more, and send me a short summary in Slack.”

Automate the gathering and the heads-up. Keep a person on anything that goes to a customer or changes a case.

Connect

One address, one sign-in, once per client.

Every Companion site has its own MCP address. Add it to your agent, sign in with the same Microsoft or Google identity you use for the Companion, and approve. The agent gets exactly your role and scope, nothing more.

Claude Code

claude mcp add --transport http fluency https://<your-site>/mcp

Then run /mcp, choose fluency and Authenticate.

Codex

codex mcp add fluency --url https://<your-site>/mcp

Then codex mcp login fluency to sign in.

Claude Desktop and Claude.ai

Settings → Connectors → Add custom connector, paste the /mcp address, then sign in and approve.

Any MCP client

Add a remote (streamable HTTP) MCP server with the /mcp address and complete the browser sign-in.

The Fluency approval screen showing the signed-in identity and the read and write permissions
You approve read access, and optionally governed case actions.Expo demonstration tenant · synthetic identities
fluency:read
Reports, cases, health, billing and posture, within what you are allowed to see.
fluency:write
Only governed case actions, such as acknowledging and closing a case.

Safe by default

Reading is safe. Changing anything needs your say-so.

Read-only by default

Reports, searches and case reviews change nothing in Fluency.

Changes are confirmed

Acknowledging or closing a case is previewed first, needs your explicit confirmation, and is recorded.

Your scope, every call

Role and scope are checked on every request. One customer or the whole fleet, never mixed in one answer.

Secrets stay out of chat

Credentials go through a secure intake page. The agent never sees your connector secrets.

Try it on your own data

Connect Microsoft 365. Ask a real question.

Free for 30 days, no credit card. After the trial, SMB pricing starts at $7 per user a month with a $75 monthly minimum and one year of retention.