CrowdStrike named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Download report
Charlotte AI AgentWorks

Build your AI security workforce

Go beyond prebuilt automation. Design custom AI agents on a trusted foundation - grounded in your data, your policies and your mission.

Agentic SOC Summit: The New Standard for Autonomous Defense

Transform your SOC into an agentic command center.

No two security teams operate the same way


Every organization has distinct data, policies, and institutional knowledge. Out-of-the-box agents aren’t grounded in the unique context of each team.

Build the agents you need, tailored to the way you work

Scale your security team’s expertise, 24/7


Design agents tailored to your team’s specific policies, data, and playbooks. Drive outcomes at machine speed, and extend your team’s reach.

AgentWorks screenshot
×
AgentWorks image
×

Design mission-ready agents in minutes — no code required


Define your agent’s mission, select your preferred LLM, define input and output structure and specify authorized actions, all in a seamless, no-code interface.

Govern your agents with enterprise-grade controls


AgentWorks agents have built-in guardrails so teams stay fully in command - from audit logs to role-based policies, to credit caps and version controls. Define what data agents can access, when they act, and trace agent decisions and source data.

AgentWorks screenshot
×
AgentWorks screenshot
×

Automate full response workflows with Agentic SOAR


Turn incremental time savings into hours of offloaded work by orchestrating multi-agent workflows, with configurable checkpoints for analyst approvals.

Drive outcomes across your security stack


AgentWorks connects unified CrowdStrike data, leading AI models, and built-in connectors to third party tools, backed by a growing ecosystem of global partners such as Accenture, Kroll, and Telefónica Tech.

abstract falcon image
×

Access the ecosystem powering agentic security


See how global partners are using AgentWorks to operationalize agentic security on the Falcon platform.

Organizations face increasingly sophisticated threats that demand machine-speed security, yet many struggle to deploy trusted AI at scale. AgentWorks addresses this challenge by bringing greater customization to the agentic SOC.”
Rex Thexton, CTO
Accenture logo
Security teams are under pressure to respond faster… AgentWorks helps us operationalize AI within MDR — building tailored agents that accelerate investigations and response.”
David Burg, Global Head of Cyber Risk
kroll logo
With AgentWorks, we are accelerating our transition to an AI-Native SOC, industrializing our security expertise into scalable agents that enhance detection, response, and cyber resilience.”
Alejandro Ramos Fraile, Global Cybersecurity Director
telefonica tech logo

Charlotte AI AgentWorks Resources

Press release
Expanding the Charlotte AI AgentWorks Ecosystem
Guide
The Agentic SOC Guide
Guide
Getting Started with Charlotte AI

FAQs

Charlotte AI AgentWorks is a no-code workspace within the Falcon platform for building, deploying, and managing custom AI security agents.

SOC teams, security operations leaders, vulnerability analysts, detection engineers, MDR providers, threat hunters, and organizations looking to customize security automation without code or hiring AI engineers.

No two security teams operate the same way. Pre-built agents can offload common, well-defined tasks but can't account for every team's unique environment, workflows, and policies. Charlotte AI AgentWorks lets every team build exactly the agents they need, grounded in their own data and policies, without writing code or requiring AI expertise.

Yes. AgentWorks has a no-code interface. Using natural language, security teams can define an agent's mission, select a preferred AI model, specify authorized actions using first-party tools and third-party connectors. Go from initial prompt to deployed agent in minutes.

Security teams define exactly what each agent can access, what actions it can take, and when it can act. Role-based access controls ensure each agent operates only within its authorized scope. Every execution is recorded in a full audit log, giving teams complete visibility into how agents behave.

AgentWorks runs on industry-leading AI infrastructure like AWS Bedrock and supports multiple AI models, including OpenAI GPT, Anthropic Claude, NVIDIA Nemotron and more. Teams choose the model that fits their needs without being locked into a single provider.

Unlike general-purpose agent builders, Charlotte AI AgentWorks is purpose-built for security operations. Agents run on the Falcon platform’s unified data foundation, comprising trillions of cross-domain security events, threat intelligence from more than 265 adversaries tracked globally, and insights from CrowdStrike incident responders, threat hunters and expert SOC analysts.


That security context helps agents to act with context and precision, while built-in guardrails, role-based access and audit trails keep analysts in control at every step.

AgentWorks agents automate security workflows across the full operations lifecycle - from detection triage and phishing analysis to threat hunting, query generation, compliance reporting, and automated response. Teams can also build agents for operational tasks like data engineering, detection tuning, and user activity monitoring, tailored to their specific environment.

CrowdStrike customers can contact their account representative to request access to Charlotte AI AgentWorks or can opt in to try Charlotte AI free directly from the Falcon console.


Not yet a customer? Contact us to get started.