AI security & operations for MSPs

Microsoft Teams

Hal posts each alert into a Microsoft Teams channel as a card of its own: every escalation with its full write-up, the morning digest, Platform Health changes, watch results and notices. Teams receives alerts only, and the portal’s Events page and email stay the channels of record.

Every alert, in the channel your team already watches

Each escalation arrives as one card naming the client, the severity and the time, with the summary, the full write-up and a link to the report in the portal. There is no thread to open: a report too long for one card stops at a whole line and links to the rest in Hal. Teams and Slack are independent, so a team that works in Teams gets its alerts there, and one that uses both can connect either or both.

What Hal posts
Every escalation as it happens, with its full write-up and a link to the report in the portal; the morning digest, its ACTION items first; Platform Health changes; watch results; and notices, such as maintenance on your instance.
What it is not
A chat: your team talks to Hal in the portal and in Slack. Nor the channel of record: the portal’s Events page and email are, and a Teams outage changes nothing about what Hal delivers there.
How it connects
A workflow you create in Teams from Microsoft’s template, Send webhook alerts to a channel. Its link is all Hal holds: no app registration, no Microsoft sign-in, nothing installed, and no premium license.
Who belongs in it
Everyone in the channel’s team reads what Hal posts there, client names included, so choose a team of staff you would give portal access. Microsoft does not support these workflows in private channels.
If a post fails
Hal tells you outside Teams, on the portal’s Health page, in a Platform Health email and in the morning digest, until a card goes through.
Setup
The workflow, the link and the test: in the docs →
An escalation card in Hal's Microsoft Teams channel, posted by Workflows: HIGH, an illicit consent grant at a client, with its summary, what happened, the evidence, four remediation steps and a link to the report in Hal
An escalation in Hal’s Teams channel. The header, the summary, the full write-up and a link to the report in Hal, in one card. The clients and people in it are fictional.
The next card in the same channel: the watch Hal opened on the account, posting its first hit, a new inbox rule made from the attacker's address, with the report it follows named and a link to the new report
What came next. The watch Hal opened on the account catches an inbox rule made from the attacker’s address. It arrives as a card of its own, so it names the report it follows.

See what Hal surfaces on your own clients.

No deck. Ask us anything first. When you want to see Hal on your own tenants, we sign a short evaluation agreement and stand up your instance; you connect one tenant, Hal watches it for 14 days, and we walk you through what he found.

  1. 01You ask us your questions. No deck, no demo dataset.
  2. 02You sign a short evaluation agreement, and we stand up your own instance.
  3. 03You connect one tenant from your own admin console. Hal watches it for 14 days.
  4. 04We walk through what he found. Keep going month to month, or revoke the scopes yourself and stop.