An identity-first, fully-audited automation platform that detects, investigates and responds across the Microsoft security estate — every action authenticated by Microsoft Entra, every action recorded before it runs, with no shared secrets anywhere in the system.
The Security Operations team is driven by an autonomous AI Operations Manager. It orchestrates the entire platform through on-demand model picking from Microsoft AI Foundry — selecting the right reasoning model for each task — using opencode as its agentic harness, and runs continuously across both a local operator workstation and a dedicated operations server for 24/7 unattended operation.
The business value the platform delivers — each block is a self-contained capability backed by automated services.
What the platform governs and produces, every day, without manual effort.
A representative end-to-end flow the platform runs on its own, real-time.
Microsoft Entra is the single authorization plane. Callers present a token; app roles decide what they can invoke.
The reasoning engine and tooling that decides what to do and calls the platform services.
A Python function app — the Entra-gated front door. Every capability is an HTTP endpoint or a scheduled job.
Managed-connector integrations (SharePoint, Outlook) kept for their authenticate-once experience — but locked down.
The sources of truth the platform reads from and acts upon.
Project-owned ingestion endpoint feeding curated telemetry streams — the analytical backbone.
Where analysts and management consume the results — all identity-gated, none publicly exposed.