agents · CAT-30030930 · rev 1.0|
Charlotte AI. @charlotte-ai
5.0Reviews ▾
Rated 5.0 / 5 by clients on GoodFirms.
Read verified reviews on GoodFirms →Vetted by Scrums.com Platform
Provider CrowdStrike
Last review 2026-08-14
What you get
the numbers that matterPriced on scope
billed monthly
≈ 2 weeks
signed to first PR
96%
engagements renewed
96%
to your stack & domain
Agentic security AI from CrowdStrike for investigation, threat hunting and security operations across CrowdStrike Falcon workflows.
How this operator works
every way of working, already decidedOwns the system, not the ticket
Takes end-to-end ownership of a service or surface. Design, delivery, on-call. And is measured on outcomes, not hours.
Embedded, async-first, instrumented
Works inside your repos, your CI and your rituals. Daily written standups, decisions logged. No status-meeting tax.
Runbooks, canaries, reversible deploys
Every change gated and reversible. Incidents get a timeline and a postmortem; nothing ships without a rollback.
Plugged into your Slack & rituals
Joins standups and retros, reports weekly against the goal. You get an operator, not a queue.
Brings a pre-wired stack or adopts yours
Infrastructure and observability as code by default. No bespoke setup tax to absorb.
Scoped, gated, reversible
Week-1 shadow, week-2 ownership, swap on request inside the trial window. No long-tail handover risk.
Overview
Charlotte AI is CrowdStrike's agentic security AI. It works across CrowdStrike Falcon workflows to investigate detections, support threat hunting and speed up security operations. Analysts ask questions in natural language and get answers grounded in Falcon telemetry.
Through Scrums.com, Charlotte AI is listed on the catalog and deployed by Scrums.com delivery teams. They integrate it into your stack, apply your governance rules, and track its operation on the SEOP, alongside your existing security operations.
What it does
Detection triage
Charlotte AI helps assess and prioritise detections so analysts spend time on the incidents that matter.
Natural-language threat hunting
Analysts express hunts in plain language instead of hand-writing queries against platform telemetry.
Investigation summaries
It condenses investigation context into summaries an analyst or responder can act on.
Guided response
It supports security operations work across CrowdStrike workflows, helping teams move from finding to action faster.
Deploying it with Scrums.com
- Scope. Scrums.com runs a fit assessment against your workflows and governance requirements, including your SOC processes and escalation paths.
- Integrate. Scrums.com engineers wire it into your repos, pipelines and tools with guardrails, connecting it to your CrowdStrike Falcon environment and alert routing.
- Operate. The deployment runs under governance, with usage and outcome reporting via the SEOP.
Commercial availability
Charlotte AI is sold by CrowdStrike as an enterprise SaaS capability of the CrowdStrike platform. Procurement runs through CrowdStrike; Scrums.com supports the commercial process as part of a deployment.
FAQs
How is this different from a SOAR playbook?
SOAR playbooks execute pre-defined automation steps. Charlotte AI is an agentic assistant: analysts direct it in natural language and it reasons over CrowdStrike telemetry. Many teams run both together.
What does deployment need?
A CrowdStrike Falcon subscription with Charlotte AI licensed, admin access to configure it, and agreement on which teams and workflows use it.
How is access governed?
Charlotte AI operates inside your CrowdStrike tenant and its role-based access. Scrums.com configures scopes and review points to match your security policy, and the SEOP records how it is used.
What's included
in every engagement · no add-onsTrack record
deployments on real systems · anonymizedWorks inside your stack
surfaces this operator binds toBoundaries
what to deploy insteadScoped to this discipline. For an adjacent capability, compose a second operator into the squad. compose →
Not a fractional advisory engagement. For advisory-only, contact platform@scrums.com.
Deployments
the only social proof we publish402deploys
across 38 organizations
+24 last 30 days · median age 11.4 mo · retention 96%
Live telemetry
this operator's system surfacePricing
one number · one footnotePriced on scope
All-in: the operator, delivery manager and replacement guarantee. No recruiter fee, no markup surprises.
Final pricing computed at deploy from your committed envelope, region and account tier.
FAQ
common questionsHow is Charlotte AI priced?+
Priced on scope. Request a quote and pricing is computed from the work envelope.
Is Charlotte AI available now?+
Yes. It is published and deployable directly from the Scrums.com catalog.
Can a Charlotte AI deployment be reversed?+
Yes. Deployments are reversible with a one-click swap inside the trial window.
Who provides Charlotte AI?+
CrowdStrike, vetted by the Scrums.com platform.
How it compares
vs other agents| Option | From | Stack | Status |
|---|---|---|---|
| Charlotte AI · this one | Priced on scope | agent · ai-agents · security-operations | ● available |
| Qdrant MCP Server | Priced on scope | mcp · qdrant · vector database | ● available |
| Pinecone MCP Server | Priced on scope | mcp · pinecone · vector database | ● available |
| Databricks SQL MCP Server | Priced on scope | mcp · databricks · sql | ● available |
Commonly deployed with
more agentsQdrant MCP Server
Qdrant MCP Server gives approved AI clients access to qdrant vector-memory workflows for storing and retrieving semantically relevant context. It is most valuable where teams want to provide engineering agents with an explicit semantic memory or retrieval layer for code and technical knowledge.
Pinecone MCP Server
Use Pinecone MCP Server to connect engineering agents with pinecone documentation, index management, upserts and vector queries. The key operational benefit is to let AI engineers build and operate retrieval systems directly from their coding agents.
Databricks SQL MCP Server
Databricks SQL MCP Server is a first-party MCP surface for aI-generated SQL against Unity Catalog tables with read/write governed by Databricks permissions. The engineering-leadership use case is straightforward: connect engineering and data agents to governed SQL execution over enterprise data.
Priced on scope