sequenced.ai
Articles/Agents & support/Blueprint//7 min read

CrowdStrike turns Falcon security context into governed AI investigation

CrowdStrike combines Charlotte AI, custom agents and security workflows, with separate entitlements for investigation and response.

By Sequenced deskAI-assisted, source-led · how we work
Visit CrowdStrike website ↗
Charlotte AIInvestigationSecurity reasoning inside Falcon
AgentWorksCustom agentsInstructions, tools and approval gates
Agentic SOAROrchestrationAgents and deterministic workflows
Monthly creditsAI licensingConsumption varies by task
CrowdStrike mark
CrowdStrikecrowdstrike.com · independent research

Represent this company? Verify your work email to access its workspace, or send the desk a factual correction.

CrowdStrike combines Charlotte AI, custom agents and security workflows, with separate entitlements for investigation and response.

In brief
  1. 01What it does Applies AI to security investigation and coordinates actions across Falcon and connected systems.
  2. 02Best fit Security teams that already have usable Falcon telemetry and want to reduce repetitive investigative work.
  3. 03Buying question Which agent features and connectors are included, and how many credits does the actual workflow consume?

01 / ProductCharlotte AI works within a larger security platform

CrowdStrike supplies the Falcon security platform across endpoints, identities, cloud environments and security operations. Its AI-specific offer centres on Charlotte AI, which brings conversational investigation, specialist agents and proposed response into that operational context. The reader decision is whether those capabilities can turn existing security evidence into a clearer, more controlled investigation—not whether a general chatbot can describe a suspicious event.

AgentWorks lets teams define a custom agent’s mission, knowledge, input and output structure, and authorised tools. Charlotte Agentic SOAR combines these agents with deterministic workflows and Falcon Foundry applications. These names describe related layers: reasoning about an incident, specifying a repeatable task, and coordinating the steps that connect the task to other systems.

A useful distinction is between identifying a likely incident and changing a production environment. CrowdStrike describes default prebuilt agents as informational; environmental actions require configuration and approval by an authorised security team member. That leaves the organisation responsible for selecting the permitted response. Sequenced has reviewed public sources, without testing detection accuracy, deployment reliability or incident outcomes.

02 / AudienceThe strongest fit starts with an existing investigation queue

Consider a security operations team that repeatedly gathers process context, identity activity and asset ownership before deciding whether to escalate an alert. Much of its delay may be evidence assembly rather than specialist judgement. An agent is worth evaluating when it can produce a useful case package while preserving the analyst’s ability to inspect the underlying events.

A small organisation buying basic endpoint protection faces a different decision. The availability of Falcon Go or another bundle does not establish access to every Charlotte capability. Start from the task and the current tenant entitlement. An attractive endpoint price cannot price a multi-system investigation whose connectors, retention and AI consumption belong to other products.

For a team building its own retrieval and analytical experience, Elastic provides a useful comparison around search and data control. For a team connecting security decisions to broader operational cases, ServiceNow is relevant to workflow ownership. These are architectural comparisons, not claims that either reproduces Falcon’s detection stack.

03 / WorkflowProposed workflow: prepare a suspicious-activity case for approval

Begin with a bounded class of alerts, such as an unusual administrative tool on a managed workstation. Define the evidence the analyst needs: event time, user, affected host, observed process, relevant identity activity and asset importance. Use existing authorised telemetry and an approved test environment. This proposed workflow is an evaluation design, not a report of a completed CrowdStrike deployment.

Create a case template that separates observations from interpretation. An observed process command belongs in the evidence section; an inference that it resembles an administrator’s routine work belongs in the assessment. Require an explicit missing-data field. If the identity connector is unavailable, an agent should not silently turn the absence of identity evidence into a clean verdict.

Use AgentWorks to encode the team’s procedure and define a narrow output. The initial agent should assemble context and recommend the next question, with tools restricted to the information required for that task. Version its instructions when the playbook changes. Retain examples of expected outputs so a model or connector change can be checked against the same incidents.

Place the agent in a SOAR workflow with a clear trigger, case identifier and destination. Deterministic logic can validate mandatory fields and choose an escalation queue. Agentic reasoning can interpret an ambiguous command or relate events. Keeping those responsibilities explicit makes failures easier to locate: a missing field, a failed connector and an unsupported interpretation need different fixes.

For the pilot, require analyst approval before containment or changes to identity access. Record the proposed target and action in the approval view, then read back the resulting state. A correct recommendation is only one part of success; applying it to the wrong machine or leaving a partial response undisclosed would still fail the workflow.

Evaluate the completed cases against analyst-reviewed examples. Measure evidence completeness, mistaken escalations, missed escalation reasons and time needed to review the case. Keep ordinary administration and ambiguous activity in the set as well as confirmed incidents. Count credits per completed investigation, including retries and follow-up questions, so the assessment produces both an operational result and a realistic consumption estimate.

04 / PricingCredits and feature entitlements are separate purchasing questions

The SOAR pricing page distinguishes Essentials from the paid offer. Its FAQ explicitly excludes Detection Triage and Response agents from Essentials, despite broader access language higher on the page. Essentials also limits case management to Falcon incidents and limits workflow connectors. Confirm those boundaries against the exact order instead of reading ‘access’ as unlimited functionality.

The licensing terms describe calendar-month credit caps, no rollover and task-dependent consumption. They distinguish an endpoint-linked Charlotte AI Module allowance from paid Agentic SOAR credit tiers that are not endpoint-based. The pages consulted do not publish a universal currency price for an AI credit. The applicable SKU therefore matters as much as the total endpoint count.

OfferCommercial basisImportant boundary
EssentialsEligible Falcon customers opt in; limited credit entitlementNo Detection Triage or Response agent; limited connectors and case management
Paid Agentic SOARQuoted monthly credit tierBroader orchestration; confirm modules and third-party connectors
Charlotte AI ModuleEndpoint-linked monthly credit allowanceDifferent entitlement route from paid SOAR tiers
Falcon endpoint bundlesSeparate device-based subscriptionA bundle price is not a quote for the AI workflow

Commercial structure from Charlotte Agentic SOAR pricing and CrowdStrike licensing, consulted 17 September 2026.

CrowdStrike’s bundle page separately offers monthly and annual billing for eligible endpoint packages. Treat any endpoint trial as its stated feature set, rather than a trial of the complete agentic platform. Request a written bill of materials for telemetry, retention, automation and credits, with the consequences of reaching the cap stated in operational terms.

05 / DistinctionsShared security context can make an agent more useful

The meaningful attraction is proximity to the investigation. A model asked about a pasted alert sees the pasted text; a properly configured Falcon workflow can bring together approved platform context and record what happens next. That may reduce copying between consoles, but the advantage exists only if the needed telemetry and permissions are actually present.

The combination of rules and reasoning is also useful. Not every task needs an agent deciding what to do. A fixed escalation policy, required case fields and an approval gate can stay deterministic while a model handles interpretation. This provides a practical way to introduce AI without making every operational step depend on generated judgement.

06 / QuestionsResolve coverage, audit and consumption before increasing autonomy

Ask which evidence each agent can access in the proposed tenant and region. A product page’s cross-domain description is not proof that a particular connector is licensed, configured or current. Demonstrate the same investigation with one data source deliberately unavailable and check whether the case shows that limitation clearly.

Review the trace and approval record as an analyst would during a disputed incident. It should be possible to understand the evidence, instruction version, proposed action and executing identity. Then check whether relevant records remain available for the organisation’s incident-review period. An impressive live summary has limited value if its evidence cannot be reconstructed later.

Finally, test consumption during a burst of alerts. Credits spent on repeated investigation of the same underlying incident can make an apparently inexpensive pilot misleading. Establish how duplicate triggers are handled and who can change caps. Wider autonomy should follow reliable case handling and a clear understanding of operating costs, rather than a headline vendor accuracy claim.

07 / DecisionChoose the investigation boundary before the automation level

CrowdStrike belongs on the shortlist when Falcon is already a substantial source of security evidence and the team can define the work it wants agents to perform. The first useful result is a traceable, reviewable case. Response automation becomes valuable when the team has also demonstrated that the right action reaches the right system under the right authority.

Existing Falcon SOC

Evidence gathering consumes analyst time

Pilot a read-only case-preparation agent using representative alerts and measure review quality.

Evaluate within the current stack
Cross-system response

Investigations must act beyond Falcon

Confirm paid connector and response entitlements, then test approvals and action read-back.

Scope the complete workflow
Basic protection

You mainly need endpoint prevention

Compare endpoint bundles on their own requirements before adding AI orchestration.

Keep the purchase focused
What should we explore next?

A business worth understanding.

Suggest your business or one you find interesting. Tell us what you want to understand about its product, positioning, design or workflows.

Suggestions are free. Selection and publication stay with the desk.

Sources
Filed under Agents & supportCompany CrowdStrikeNot affiliated with CrowdStrikeRequest a correctionRequest a refresh by email

Continue reading

All in this category