Couldn’t make Fal.Con? Get in on Fal.Con Digital. Learn more
CrowdStrike® Charlotte AI™ AgentWorks

Build your AI security workforce

Turn your team's playbooks, policies, and institutional knowledge into secure-by-design AI agents without writing code.

No two security teams run the same way


Out of the box agents suit common tasks. The rest have to encode your knowledge, run your procedures, and operate with controls only you define.

Unique context

Agents should codify the context no one else has: your data, your policies, and your institutional knowledge.
Unique workflows

Agents should work as an extension of your team: your escalation paths, your procedures, and across your tools.
Unique guardrails

Agents should run inside the controls you set: your permissions, your access rules, your approval gates.

Build the agents you need, tailored to the way you work

Scale your security team’s expertise, 24/7


Design agents tailored to your team’s specific policies, data, and playbooks. Drive outcomes at machine speed, and extend your team’s reach.

Platform screenshot of model settings
×
New

Build agents with the models of your choice


Define your agent's mission, select your preferred LLM or bring your own, define input and output structure, and specify authorized actions, all in a seamless, no-code interface.

Govern your agents with enterprise-grade controls


AgentWorks agents have built-in guardrails, so teams stay fully in command, from audit logs to role-based policies, to credit caps and version controls. Define what data agents can access, when they act, and trace agent decisions to source data.

Screenshot of Charlotte AI platform
×
Screenshot of Charlotte AI Agentic SOAR
×

Automate full response workflows with Agentic SOAR


Recover hours of analyst time by orchestrating multi-agent workflows in Charlotte Agentic SOAR, with configurable checkpoints for approvals at every step you choose.

New

Connect to every tool across your stack


AgentWorks connects unified CrowdStrike data, leading AI models, and built-in connectors to third party tools, backed by the model context protocol (MCP) and a growing ecosystem of global partners.

Screenshot of AgentWorks agent tools
×

Access the ecosystem deploying agentic security


See how global partners are using AgentWorks to operationalize agentic security on the Falcon platform.

Organizations face increasingly sophisticated threats that demand machine-speed security, yet many struggle to deploy trusted AI at scale. AgentWorks addresses this challenge by bringing greater customization to the agentic SOC.”
Rex Thexton, CTO
Accenture logo
The fact that my team can build an agent as easily as writing a prompt completely changed how we think about automation. The hardest part wasn't building the agent, it was deciding which problem to solve first.”
Mauricio de la Cruz, Threat Hunting Engineer
PALIG logo
The cybersecurity skills shortage isn't going away. What changes is how effectively we multiply the expertise we do have. AgentWorks lets our senior analysts encode their knowledge into agents that work alongside the entire team, so our best thinking operates at scale, around the clock, without burning out the people behind it.”
Michael Macy, Cybersecurity Engineer
AmSty logo

 

Latest innovations from

Fal.Con 2026 logo
CrowdStrike unveils the next evolution of the agentic SOC
Coordinated, cross-domain investigations, out of the box
Proactively uncover external risk with agentic recon

Charlotte AI AgentWorks FAQs

Charlotte AI AgentWorks is a no-code workspace within the Falcon platform for building, deploying, and managing custom AI security agents.

SOC teams, security operations leaders, vulnerability analysts, detection engineers, MDR providers, threat hunters, and organizations looking to customize security automation without code or hiring AI engineers.

No two security teams operate the same way. Pre-built agents can offload common, well-defined tasks but can't account for every team's unique environment, workflows, and policies. Charlotte AI AgentWorks lets every team build exactly the agents they need, grounded in their own data and policies, without writing code or requiring AI expertise.

Yes. AgentWorks has a no-code interface. Using natural language, security teams can define an agent's mission, select a preferred AI model, specify authorized actions using first-party tools and third-party connectors. Go from initial prompt to deployed agent in minutes.

Security teams define exactly what each agent can access, what actions it can take, and when it can act. Role-based access controls ensure each agent operates only within its authorized scope. Every execution is recorded in a full audit log, giving teams complete visibility into how agents behave.

AgentWorks runs on industry-leading AI infrastructure like AWS Bedrock and supports multiple AI models, including OpenAI GPT, Anthropic Claude, NVIDIA Nemotron and more. Teams choose the model that fits their needs without being locked into a single provider.

Unlike general-purpose agent builders, Charlotte AI AgentWorks is purpose-built for security operations. Agents run on the Falcon platform's unified data foundation, comprising trillions of cross-domain security events, threat intelligence from more than 265 adversaries tracked globally, and insights from CrowdStrike incident responders, threat hunters and expert SOC analysts.

AgentWorks agents automate security workflows across the full operations lifecycle from detection triage and phishing analysis to threat hunting, query generation, compliance reporting, and automated response.

CrowdStrike customers can contact their account representative to request access to Charlotte AI AgentWorks or can opt in to try Charlotte AI free directly from the Falcon console.


Not yet a customer? Contact us to get started.