What CrowdStrike Charlotte AI does
CrowdStrike Charlotte AI is the agentic security layer for Falcon, combining natural-language investigation, mission-ready agents, custom AgentWorks agents, and Agentic SOAR.
Charlotte AI is CrowdStrike's AI operating layer for the Falcon platform. It provides natural-language access to security investigation and threat context, while mission-ready agents can perform defined work such as triage or malware analysis. AgentWorks allows teams to create, test, and deploy custom agents without conventional code by defining mission, data, and behavior. Agentic SOAR combines those reasoning capabilities with repeatable orchestration, creating a route from detection through investigation and response without moving evidence into an unrelated chatbot.
CrowdStrike does not publish one universal Charlotte AI price. Total cost depends on Falcon platform and module licensing, endpoints and workloads, retained or ingested data, Charlotte AI products, AgentWorks, Agentic SOAR, services, support, and contract. Falcon offers a fifteen-day trial for selected protection capabilities, but that should not be interpreted as a full Charlotte entitlement or production evaluation. Buyers need a line-item quote, current usage units and limits, model or data-region details, and an operational pilot on representative alert volume.
Falcon context can reduce investigation time, but an agent can still follow a misleading detection, overstate malware confidence, miss off-platform evidence, or call an action with excessive scope. Custom agents add prompt injection, tool permission, looping, secret exposure, and unreviewed workflow risk. Apply least-privilege Falcon roles and service accounts, constrain every action and data source, test agents against false positives and adversarial inputs, and use deterministic approval gates before isolation, deletion, blocking, or identity changes. Preserve raw telemetry and analyst ownership of verdicts.
How CrowdStrike Charlotte AI works
Charlotte AI uses Falcon telemetry, threat intelligence, detections, and licensed module context to answer analyst questions and execute defined missions. Mission-ready agents investigate or analyze specialized work; AgentWorks lets teams specify custom agents in natural language; Agentic SOAR coordinates agents and deterministic actions. Analysts inspect evidence, constrain tools, and approve disruptive responses.
Ground work in Falcon telemetry
Charlotte AI works from licensed Falcon detections, telemetry, intelligence, and module context. Coverage, retention, sensor health, and role permissions determine what an agent can see.
Investigate with specialized agents
Mission-ready agents perform bounded work such as triage or malware analysis. Analysts can ask natural-language questions and inspect supporting evidence rather than relying only on a generated narrative.
Coordinate agents and automation
AgentWorks defines custom missions and Agentic SOAR chains reasoning with deterministic tools. Scope data, actions, duration, loops, secrets, and failure handling before production deployment.
Approve reversible security action
A human validates the verdict and business impact before isolation, blocking, deletion, or identity change. Preserve evidence, rollback, full traces, overrides, and cost data.
How to set up CrowdStrike Charlotte AI
Map Falcon coverage and gaps
Inventory endpoints, identities, cloud, intelligence, SIEM, data retention, third-party sources, current modules, incident processes, and response authorities.
Obtain exact Charlotte packaging
Request prices and limits for Falcon modules, Charlotte AI, mission-ready agents, AgentWorks, Agentic SOAR, data, services, support, region, and renewal.
Configure least-privilege missions
Assign scoped analyst and service roles, restrict data and tools, separate development from production, protect secrets, and define time, cost, and action limits.
Test agents against known cases
Replay true and false positives, benign administration, malware families, missing telemetry, poisoned artifacts, prompt injection, tool failures, and duplicate events.
Approve and audit response
Require human review for disruptive actions, preserve evidence and rollback, monitor agent traces, false positives, cost and overrides, and retire unsafe missions.
CrowdStrike Charlotte AI FAQs
How much does Charlotte AI cost?
CrowdStrike requires a custom quote based on Falcon modules, workloads, data, Charlotte capabilities, services, and contract. A Falcon trial does not imply every AI feature.
What is AgentWorks?
It is CrowdStrike's environment for defining, testing, and deploying custom security agents through natural-language mission, data, and behavior configuration.
What is Charlotte Agentic SOAR?
It orchestrates purpose-built agents with security workflows and deterministic automation, coordinating investigation and response across configured Falcon context and tools.
Can Charlotte AI replace SOC analysts?
No. It can reduce repetitive investigation and orchestration work, while analysts remain responsible for evidence, uncertainty, business context, and response authorization.
How should custom agents be secured?
Use scoped roles and tools, isolated testing, adversarial cases, protected secrets, cost and loop limits, complete traces, human approvals, and reversible actions.
Listing reviewed 2026-07-15. Product details and pricing can change; verify important terms on the provider's website.
Related Productivity AI tools
Related AI guides
Reviews
Tell the community what you made, what worked, and what you wish you knew before starting.