AI security & operations for MSPs

Using Hal in Chat

Two ways to work with Hal

Hal runs in two modes at once.

Always watching. On his own, Hal monitors every client and escalates only what matters, the SIEM and AI SOC roles. You don’t have to ask; the alerts come to you.

Always there to ask. You can also just talk to him. Ask a question in plain English and Hal answers from across every connected source, tenant, ticket, and runbook, the Senior Engineer and Knowledge Worker roles.

Asking good questions

  • Name the client, and Hal scopes the answer to them.
  • After an incident, ask him to watch the account, and he opens a watch that re-checks it on a schedule and alerts like any other alert.
  • Put a higher-risk person, an executive or an administrator, under sentry, and he reads every event that names them each cycle, indefinitely.
  • Ask for what you actually want, a recommendation, a checklist, a signed report, and he produces it.
  • Follow up. Hal keeps the thread’s context, so you can drill in without repeating yourself.

Hal reaches your team through the web portal and, if you connect it, your own Slack workspace.

Where the values in an answer come from

Hal’s answers follow the same rule as his reports: each count, time or address is filled in by code from what he read, or typed by him and checked against it, and tables are built by code, row for row. In the web chat a value with a source has a faint dotted underline; hover over it, focus it or tap it for a box saying where it came from, with Details for the exact query. Something that still fails the check after up to two rewrites is delivered followed by (unverified), in amber in the web chat and as the text alone in Slack. When a read the answer relies on was partial or failed, the answer ends with a line saying so. How the check works →

When the model declines

Anthropic, the AI provider, declines some requests on its policy grounds. When the model Hal uses in chat declines one, he says so instead of answering: “I couldn’t answer that: the AI model I use declined the request. Rephrasing sometimes helps. If this is about an alert, a person should review it.” When a backup model declined too, it reads “…declined the request, and so did its backup”, or “its backups” when there was more than one. The same answer comes in the portal and in Slack. When a backup model answered instead, the model pill in the chat’s footer names it, since the pill always shows the model that answered the latest reply.

Chat commands

The portal chat takes a few slash commands. Type / and the list appears; type /help (or /?) and Hal prints it. They act on your own browser session, not on Hal’s memory of the conversation, and none of them exist in Slack, where you just talk.

CommandWhat it does
/model familySwitches the model for this conversation. Typed alone it lists the families you can choose from; the default is whatever your admin set under Settings.
/newStarts a fresh conversation. Anything Hal was still working on is cancelled and the session cost counter returns to zero.
/clearClears the messages from the screen only. Hal still has the conversation’s context; keep asking follow-ups.
/resetForgets everything the browser stored, the conversation, your model choice, the input history, and reloads the page. The clean-slate command.
/theme nameChanges the chat colour theme for you. Typed alone it lists the themes and marks the current one.
/helpPrints the command list.

Three keys are worth knowing too. Esc interrupts a request Hal is still working on. The up and down arrows recall what you typed earlier in the session. Enter sends, and Shift+Enter starts a new line inside a message.

See what Hal surfaces on your own clients.

No deck. Ask us anything first. When you want to see Hal on your own tenants, we sign a short evaluation agreement and stand up your instance; you connect one tenant, Hal watches it for 14 days, and we walk you through what he found.

  1. 01You ask us your questions. No deck, no demo dataset.
  2. 02You sign a short evaluation agreement, and we stand up your own instance.
  3. 03You connect one tenant from your own admin console. Hal watches it for 14 days.
  4. 04We walk through what he found. Keep going month to month, or revoke the scopes yourself and stop.