CISO dinner in Vancouver, Sept 9RSVP
Alaris
Pricing
Alaris Build Suite

Build on the platform, your way

The developer layer of the Alaris Enterprise Platform. Connect any AI agent through the MCP server, compose custom agents with guardrails in Agent Builder, and integrate anything else through full APIs.

connect-mcp.ts
MCP
MCP native
Open protocol
works with any MCP-compatible agent or client
Custom agents
Agent Builder
compose prompts, tools, and triggers visually
Full API access
Every capability
programmatic access to alerts, graph, and actions
Your guardrails
You set the limits
permissions and approval gates on every action
How It Works

From first connection to production agent

Three steps take you from an empty editor to a custom agent running inside the same loop as every native agent on the platform.

MCP Server
ClientStatus
Claude DesktopConnected
SOC copilotConnected
Custom agentConnected
24 tools connected · scoped per client
01

Connect via MCP

  • Point any MCP-compatible agent, copilot, or LLM client at the Alaris MCP server
  • Platform tools become callable: graph queries, alert data, enrichment, and response actions
  • Scoped credentials control exactly what each client can see and do
Agent Builder
Prompt defined
hunt for exposed credentials
Tools selected
graph · intel · edr
Guardrails attached
read-only, approvals on actions
02

Compose your agent

  • Define the prompt, pick the tools, and set the triggers in Agent Builder
  • Attach guardrails: read-only by default, approval gates on response actions
  • Test runs show every step before anything touches production
Run Log
03

Ship it into the loop

  • Your agent runs alongside Alaris native agents on the same infrastructure
  • Same observability: every reasoning step, tool call, and decision is logged
  • Refine and redeploy anytime, versioned and auditable
Core Capabilities

Everything you need to extend the platform

MCP, Agent Builder, guardrails, and APIs work together as one developer surface, so what you build inherits the platform's context and controls.

Alaris MCP Server
24 tools
query_graphREAD
get_alertREAD
enrich_indicatorREAD
isolate_hostACTION
create_caseWRITE

MCP Server

Open protocol, native tools

Expose Alaris capabilities to any AI agent or LLM client over the Model Context Protocol. Graph queries, alert data, enrichment, and response actions become tools your agents can call directly, backed by live platform data.

Agent BuilderDeploy
Prompt
Hunt for credentials exposed outside approved vaults...
Tools
query_graphsearch_intelget_alert
Guardrails
Read-only by default
Response actions require approval

Agent Builder

Compose, test, deploy

Build custom security agents from prompts, tools, and triggers without standing up your own infrastructure. Test runs show every step the agent takes before you deploy it into production.

Permissions
Graph queries
ReadWriteApprove
Alert data
ReadWriteApprove
Enrichment
ReadWriteApprove
Response actions
ReadWriteApprove
Pending approval: isolate_host2m ago

Guardrails and permissions

You set the limits

Every custom agent and connected client is scoped to explicit permissions. Read-only by default, with approval gates on write and response actions, so nothing you build can exceed what you authorize.

REST APIv1
GET/v1/alerts
GET/v1/graph/query
POST/v1/actions/isolate
POST/v1/webhooks
200 OK · 41ms · application/json

APIs and custom integrations

Programmatic access to everything

Full APIs for alerts, the Security Graph, enrichment, and actions. Wire the platform into your own tooling, pipelines, and workflows, with webhooks for anything that needs to react in real time.

What you can do with it

Put Build Suite to work

See how teams use the developer layer to cover the detection and response work no off-the-shelf agent handles.

Use case

Build Your Own Agents

Bring your own agents to the platform