AI security & operations for MSPs

Slack

Hal posts every escalation into one private Slack channel as it happens, with the full write-up in a thread beneath it, drops the morning digest there, and answers your team in threads. Slack is an addition: the portal’s Events page and email stay the channels of record.

The investigation, where your team already talks

Each escalation arrives as one post naming the client, the severity and the headline, with the full investigation in a thread under it. Reply in that thread and Hal answers with the whole investigation in mind; ask anything in the channel and he starts a thread with his answer. He works on one thread at a time per conversation, and if several people ask at once he says so rather than silently queueing.

What Hal posts
Every escalation as it happens, with its full write-up in a thread beneath it; the morning digest; health notices that need your action, such as an expiring credential or a source gone quiet; and PDF reports on request.
What your team can do
Ask anything in the channel, no @ needed, and he answers in a thread. Reply in an escalation’s thread and he answers with that whole investigation in mind.
What it is not
The channel of record. The portal’s Events page and email are: a Slack outage, or a Slack you never connect, changes nothing about what Hal delivers there.
How it connects
One Slack app of your own, connected outbound over Socket Mode, so nothing listens on your network; nine bot scopes; one private channel.
Who belongs in it
Membership gives the access a portal viewer has: everyone in the channel reads what Hal posts there, so invite only staff you would give portal access. Hal’s admin actions stay in the portal’s web chat.
Setup
The app, the scopes, the tokens and the channel: in the docs →
Hal's private Slack channel: the morning digest for one day, with log volumes, the day's six alerts by severity and volume by client, then a HIGH escalation for a client's cross-tenant OAuth consent grant, and the thread pane open on the right with the escalation and its write-up, four remediation steps
Hal’s channel in Slack. The morning digest, an escalation below it, and the escalation’s full write-up in its thread. The clients and people in it are fictional.

See what Hal surfaces on your own clients.

No deck. Ask us anything first. When you want to see Hal on your own tenants, we sign a short evaluation agreement and stand up your instance; you connect one tenant, Hal watches it for 14 days, and we walk you through what he found.

  1. 01You ask us your questions. No deck, no demo dataset.
  2. 02You sign a short evaluation agreement, and we stand up your own instance.
  3. 03You connect one tenant from your own admin console. Hal watches it for 14 days.
  4. 04We walk through what he found. Keep going month to month, or revoke the scopes yourself and stop.