ML_NEW_USER
First time for this user
This rule has never fired for this person before.
The Unbounded SIEM
If your SIEM isn’t producing cases, you don’t have a SIEM. You have an alert machine.
Fluency compares every signal with the history of the person or device behind it, groups related alerts into one case per entity per day, and scores that case by how much independent evidence agrees. Analysts start with a short queue of explained cases, not a wall of alerts.

From data to a case
Everything that arrives is raw data. By the time it reaches an analyst it has been enriched, matched against behavior rules, and grouped into a case that has already been scored. That is where the noise goes.

Events
Records are collected, enriched (a latitude and longitude becomes a country) and stored.
Notable
An event matches a behavior rule’s condition.
Alerts
The rule’s full conditions are met, including whether this is new for the entity.
Cases
Related alerts for one entity on one day are clustered and scored for review.
Behavioral analytics
The signature says what happened: a sign-in, a group change, a data-loss match. The history says whether it is new for this person. You shouldn’t be hacked all the time, so something that has never happened before is a far stronger signal than something that happens every day.

ML_NEW_USER
This rule has never fired for this person before.
ML_NEW_ALERT
Nobody in the organization has ever triggered this alert.
ML_NEW_GEO_ISP
This person has never signed in from this location and network.
Risk scoring
Fluency groups related alerts by entity, one day at a time. A case’s score is not the sum of its rules. It rises when separate, unique evidence points the same way, and it stays put when the same alert fires again.
The case in the screenshot
Different behavior rules that agree. First time for this user, for the organization, or from this location and network.
Volume. Twenty bad logins and a thousand bad logins are the same evidence: multiple bad logins.

A high score means Fluency is more certain a case needs a look, not that it is the most harmful. Because each new, independent piece of evidence adds to it, the score has no ceiling. The bands mark how certain we are.
| Band | Risk score | What to do |
|---|---|---|
| Critical | 8,000 and above | Review now |
| Serious | 2,000 – 7,999 | Review this shift |
| Moderate | 800 – 1,999 | Some supporting evidence |
| Low | Below 800 | Little supporting evidence |
First time in the organization
A user clicks a link in a Teams message. Defender allows the click, then flags the link as phishing. It is the first time that alert has fired for this user and the first time anywhere in the organization. A single rule scores 8,800, Critical, and Fluency’s AI triage recommends escalating to Tier 2.
An analyst then takes it further in Claude. The evidence shows Microsoft removed the message 14 seconds after the click, which the first triage had missed. The verdict: about 80% likely to be a real issue, and one check left to settle it.

Under the hood
Fluency runs on the Ingext streaming framework. Each record is collected, enriched once before it is stored, then routed to several places at once: the data lake for search and reporting, the security modules for detection, and notification. Detection is a destination on the pipe, not a separate system.

Activity
Sign-ins, changes and alerts from identity, email, endpoint, cloud and network sources, streamed continuously and turned into cases.
Resources
Configuration snapshots, at least daily: Office 365 users, devices, groups and apps; endpoint agents and OS versions; firewall configuration; the latest CVEs. They give every case context and drive posture reviews and compliance evidence.
Compliance evidence
Fluency maps live evidence onto NIST SP 800-53 Rev. 5, with related views for CSF 2.0, 800-171, CMMC and ISO 27001. Each control is marked supported, partial or not observed, and a source that failed to report is shown as a collection gap, never as a failed control.
Fluency supports readiness. Certification decisions stay with your assessor, and it works alongside platforms such as Vanta and Drata.

Pricing and scale
Fluency is priced per user, with storage included. You are not penalized for turning on another log source.
$7
per user a month (SMB)
3GB
storage included per user
$2.99
per GB only above the allowance
1 year
retention included
For MSSPs and MSPs
Access is checked two ways on every request: role decides what someone can do (Admin, Operator, CISO, Analyst), and scope decides which tenants they can reach. An MSSP sees every customer under its connectors, an MSP sees a hand-picked set, and a customer sees only itself. Analysts and AI clients inherit exactly that access.
The company behind the product
Fluency combines its SIEM with hands-on deployment and ongoing support. We help customers overcome integration obstacles, establish useful workflows, and build operational capability.
Agree on the first sources, access requirements, and questions to answer. Verify data flow and usable results as onboarding progresses.
For MSSPs, multi-tenant workflows support customer onboarding, health reviews, investigations, and reporting within the appropriate customer scope.
Work with a team that understands the product and the operational obstacles. Fluency was recognized for Best Support in G2’s Fall 2026 reports.
Bring your own data
Start with Microsoft 365. We’ll show you the cases, the scores and the evidence behind them.