A custom tool
Something the agents can call that does not exist yet — a check, a lookup, an action against a system nobody has written a tool for. It joins the tool layer and is available to every agent that needs it.
The agents work through a tool layer, and that layer is not fixed. Where an investigation needs something your estate does not have — a tool, an integration into a system of your own, a program written for the way you operate — we build it. New tools, integrations and upgrades ship weekly.
Most estates need something. The question is which of these it is, because the shape of the work and how it is priced follow from that.
Something the agents can call that does not exist yet — a check, a lookup, an action against a system nobody has written a tool for. It joins the tool layer and is available to every agent that needs it.
The line-of-business system, the internal platform, the thing your team built years ago. If an investigation needs to read from it or act on it, we write the integration rather than working around it.
Software that exists because of how your organisation works and would not make sense anywhere else. Scoped, built and maintained as part of your deployment.
Both halves are stated here together because either one on its own is misleading.
Custom data connectors, parsers, analytical rules, playbooks and notebooks for your estate are built during onboarding and are part of the service. Microsoft Sentinel is the only hard requirement; where a connector does not exist for something you run, writing it is our job and not a change request.
A custom tool, an integration into a system of your own, or a program specific to your organisation is a build rather than a connection. It is scoped and quoted as development before anything starts, so you are deciding on it rather than discovering it on an invoice.
The split is the same on a platform deployment, where tool development is purchased rather than bundled.
New tools, integrations, features and upgrades ship weekly. Engineering the platform is not a project that finished before you arrived.
Added to the layer as investigations turn up things no tool covered. Once one exists it is available to the agents that need it.
More of the estate reachable, month on month, without anyone raising a change request to get there.
Existing tools get better at what they do. The agents inherit that without you doing anything.
Platform maintenance and updates are ours, wherever it is hosted — on the managed service and on a platform deployment alike.
Yes. That is the normal case rather than the exception. If an investigation needs to read from or act on a system your team runs, we write the tool and the integration for it, and it joins the tool layer the agents work through. Whether it is included or quoted as development depends on what it is: getting your existing security signals into Microsoft Sentinel is part of onboarding, and building software specific to your organisation is development.
Custom data connectors, parsers, analytical rules, playbooks and notebooks for your estate are built during onboarding and included in the managed service. A custom tool, an integration into an internal system of your own, or a program written specifically for your organisation is development work and may carry an additional development cost. It is scoped and quoted before anything is built.
Weekly. New tools, new integrations, new features and upgrades to existing ones ship continuously, and they reach every customer on the platform rather than only the one who asked. Platform maintenance and updates are ours whether the platform is hosted by us or self-hosted in your own Azure subscription.
Ownership, licensing and what happens to a bespoke build at the end of a contract are set out in the agreement rather than decided here. Raise it during scoping and it gets answered in writing before development starts.
An hour with a SOC analyst and an engineer: what your estate runs, what an investigation would need to reach, and which side of the line each piece of it falls on.