CrowdStrike’s latest announcement deserves attention—not simply because another major security company has introduced AI agents, but because of how those agents are being organized.
CrowdStrike is bringing data, detection, specialist agents, shared context, orchestration, governance, and response together inside the Falcon platform. Its agents can investigate different security domains concurrently, build on one another’s findings, and converge on an outcome that analysts can inspect and act upon.
This is more than another set of AI capabilities. It is the beginning of a new operating model for the SOC.
CrowdStrike’s announcement validates something the security industry is rapidly discovering: deploying individual agents is not enough. The more difficult problem is creating the environment in which agents can work together reliably.
Every Agentic SOC needs a harness.
That creates two decisions. Technology companies must decide how their agents and capabilities will participate in broader operations. Enterprise leaders must decide whether the operating layer coordinating those capabilities should be centered on one platform or designed to operate across them.
From AI Features to an Operating Model
Security vendors have spent the past several years adding AI to individual parts of the analyst experience. AI can summarize an alert, explain a command line, enrich an indicator, generate a query, or recommend a response.
These capabilities make individual tasks faster, but they do not necessarily change how the SOC operates. The analyst often remains responsible for moving information between tools, reconciling separate conclusions, determining the next step, and maintaining the overall investigation.
The AI performs tasks. The human coordinates the system.
CrowdStrike is describing something more complete:
Data → Detection → Investigation → Coordination → Decision → Action → Learning
Its newly announced architecture combines three important layers: a data foundation that makes native and third-party evidence available for investigation, coordinated teams of specialist agents working from shared context, and a common environment for building and governing deterministic and agentic automation.
CrowdStrike calls this the next evolution of the Agentic SOC. The capabilities will mature over time, but the architectural direction is already clear. The company is moving beyond isolated assistants toward a system in which humans and agents operate as a security workforce.
That distinction matters.
Agents Need More Than Intelligence
The industry spends considerable energy comparing models: which one reasons best, produces the fewest errors, or performs most effectively on a benchmark.
Models matter, but the model is only one component of an operational system.
A capable agent also needs a defined role, an objective, access to the right tools and evidence, relevant organizational context, and a way to collaborate with other specialists. Its actions must remain within policy. Humans must be involved when judgment or additional authority is required. The evidence, decisions, and actions produced during the work must be preserved.
Without these elements, even a highly capable model remains an isolated intelligence. It may answer a question or complete a task, but it cannot reliably participate in sustained security operations.
The surrounding operational system is the harness.
A harness turns model intelligence into controlled work. It assembles agents around an objective, supplies the appropriate context, coordinates their contributions, evaluates proposed actions, and makes the operation visible to the humans accountable for the outcome.
CrowdStrike is building such a harness around Falcon.
The larger opportunity is to make this operating model available across the rest of the security ecosystem.
The Agentic SOC Will Not Live in One Product
Enterprise security operations rarely run on a single vendor’s platform.
An investigation might begin with an endpoint detection, incorporate identity and cloud evidence, retrieve threat intelligence, examine network activity, consult a vulnerability platform, update a case-management system, and initiate response actions through several different controls.
Each system holds a valuable part of the operation: telemetry, detection logic, specialized expertise, response capabilities, institutional knowledge, or business context.
The Agentic SOC should make these capabilities more useful. It should not require organizations to abandon them.
CrowdStrike clearly recognizes the need for interoperability. Charlotte Agentic SOAR is designed to connect third-party agents into Falcon and CrowdStrike agents to external tools through bidirectional MCP, while supporting multiple model choices.
This is strategically important, but connectivity is only the first step.
MCP can expose a capability. It does not determine which agent should use it, whether its use supports the current objective, what context may be shared, which policies apply, or how the result should affect the larger investigation. It does not determine when an action requires human approval or who remains accountable for the outcome.
MCP connects agents and tools. A harness turns those connections into operational work.
CrowdStrike is building that operating environment around Falcon. The broader enterprise challenge emerges when no single product is the natural center—when agents, data, policies, and actions belong to several vendors, organizational domains, and business functions.
This is where a neutral harness becomes important.
The distinction is not between an open platform and a closed one. It is between extending an agentic ecosystem from one platform and coordinating an agentic workforce across many platforms.
The Harness Is an Enterprise Architecture Decision
The choice of harness is not only a product decision. It is an enterprise architecture decision.
A harness determines how agents are selected, how context moves between systems, where policies are enforced, how humans participate, and whether decisions and actions can be reconstructed afterward. It also influences which models, tools, and vendors can participate in future operations.
When the harness is anchored to a single platform, the organization may gain deep integration with that platform. It may also make the broader agentic operating model dependent on one vendor’s data architecture, agents, governance model, and product roadmap.
A neutral, cross-platform harness gives the enterprise another option.
The organization can preserve its existing investments while deciding which tools, agents, models, and sources of expertise should contribute to each objective. Platforms remain authoritative for their data and actions, while coordination occurs above them rather than inside any one domain platform.
This preserves architectural choice without requiring the enterprise to build the coordination layer itself.
It also creates a faster path to the Agentic SOC. Organizations do not have to wait for one vendor to provide every capability or replace systems that already work. They can begin with the tools and procedures they have today, introduce agents where they create immediate value, and expand across the environment over time.
Because tools, models, and vendors will change, the operating model should be designed to outlast any individual participant.
The question for enterprise leaders is therefore not simply which vendor has the best agents.
It is which architecture will allow the enterprise to adopt the best agents—now and as the market changes—without rebuilding how work gets done.
A Neutral Harness Should Not Become the New Center of Gravity
A reasonable question follows naturally: if a neutral harness coordinates enterprise work, doesn’t it simply become another platform on which the organization depends?
It can. Neutrality does not mean dependency disappears. It means that dependency is deliberately limited, visible, and replaceable.
A neutral harness should not become the system of record for endpoint telemetry, cloud inventory, identities, vulnerabilities, tickets, detections, or response controls. Those remain with the platforms built for those purposes, preserving each platform as the authoritative source for its data, expertise, and actions.
The harness coordinates something else: the execution of work.
It assembles context, applies policies, orchestrates specialists, preserves evidence and provenance, manages human participation, and records how decisions were reached. The procedures, policies, evidence, and operating knowledge produced through that coordination should remain enterprise assets—portable across existing technology investments rather than inseparable from the harness itself.
Neutrality therefore cannot mean connectivity alone. It should be measured by whether interfaces are documented, operational evidence can be retained outside the harness, procedures and policies can be transferred, and individual integrations can be replaced without reconstructing the operating model. A neutral harness should make adoption easier without making exit prohibitively expensive.
That distinction matters because enterprise technology changes continuously. Organizations replace SIEMs, endpoint platforms, cloud security tools, ticketing systems, and identity providers over time. Rebuilding the operational model each time those technologies change is where lock-in becomes expensive.
A neutral harness allows individual systems to be replaced without requiring the enterprise to reconstruct its procedures, governance model, institutional knowledge, or AI workforce. New products become new specialists participating in the workforce—not a reason to redesign how the workforce itself operates.
Bricklayer Is the Harness
Bricklayer was built for this layer of the architecture.
It does not ask security teams to replace the products on which they already depend. It organizes those products, their data, and their specialized capabilities into a coordinated AI workforce.
Every Bricklayer operation begins with a goal. The platform assembles the appropriate agents, tools, data, and context within an approved procedure. Agents can work concurrently, build on one another’s findings, and adapt as new evidence changes the investigation.
Three capabilities make this possible: context, coordination, and control.
- Context is more than access to data. Agents need to understand what information means, where it came from, how it relates to the current objective, and whether it can be shared. Findings must accumulate across the operation rather than disappear at each handoff.
- Coordination is more than assigning tasks. Endpoint, identity, cloud, vulnerability, network, intelligence, and incident-response specialists may all contribute to the same objective. Their work must be divided, performed, recombined, and sometimes reorganized as the situation develops.
- Control is more than establishing permissions before execution. Autonomous systems determine many of their next steps while running. An agent may retrieve additional information, select a tool, involve another specialist, change the plan, or propose an action that affects the environment. Each consequential action must be evaluated in the context of what the system is trying to accomplish and what has already occurred.
Bricklayer provides the environment in which these things happen. Humans can inspect the plan, evidence, agent contributions, decisions, and actions rather than receiving only an AI-generated answer at the end.
A harness does more than orchestrate work. It governs how objectives are translated into coordinated actions, how policies remain active throughout execution, how context is preserved across specialists, and how every decision can be reconstructed afterward.
That is what makes Bricklayer a harness rather than another collection of agents.
An Accelerant for Security Platforms
CrowdStrike has the scale and breadth to build an agentic operating environment deeply integrated with Falcon. Other security companies will make similar investments around their own platforms.
That is a logical response, but it does not resolve the larger architectural problem. Enterprise work crosses product boundaries.
The opportunity extends across the security ecosystem because every category brings a different form of expertise to the operation.
Broad technology platforms such as Microsoft, Cisco, Google, and Palo Alto Networks span security, identity, cloud, infrastructure, data, and observability.
Security operations platforms and product ecosystems—including CrowdStrike, SentinelOne, Splunk, Sumo Logic, Elastic, and Rapid7—hold valuable telemetry, detections, investigation logic, and response capabilities.
Specialists such as Okta, Wiz, Zscaler, Tenable, Netskope, Recorded Future, and others provide deeper expertise across identity, cloud security, network access, exposure management, and threat intelligence.
Service providers, systems integrators, and managed security providers bring another essential asset: the procedures, operational knowledge, and customer-specific expertise required to turn product capabilities into repeatable outcomes.
Each participant can build agents that understand its products and domain. The more difficult question is how those agents contribute to work that extends beyond them.
An identity agent may establish who or what is involved. An endpoint agent may determine what occurred on a device. A network specialist may reconstruct movement across the environment. A cloud agent may evaluate exposure and configuration. A threat-intelligence agent may connect the activity to a broader campaign. Internal agents may contribute business context that no external provider possesses.
No single participant needs to own the entire operation. Each can remain authoritative for its data, expertise, policies, and actions while contributing to a shared objective.
The challenge is not simply connecting these agents. It is enabling them to organize around an objective, exchange relevant context, operate within policy, and produce an outcome for which a human remains accountable.
This is where Bricklayer fits.
Bricklayer does not need to own the data, detection, model, response control, or customer interface. Each participant continues to own what makes its platform valuable. Bricklayer provides the coordination and governance harness in which those capabilities can operate together.
This gives vendors a faster path to the Agentic SOC without requiring each of them to independently build the entire operating layer. Their agents and expertise can participate in broader customer operations while their data, intellectual property, and policy controls remain within the boundaries established by their platforms and customer agreements.
The relationship is not zero-sum. Bricklayer succeeds by making connected platforms more useful together, not by replacing them.
The same model applies to CrowdStrike. Falcon agents and capabilities could participate as specialists in operations that extend beyond Falcon’s natural boundaries. CrowdStrike would remain authoritative for the expertise, data, and actions contributed by Falcon, while Bricklayer coordinated the broader objective.
The Coordination Layer Is Becoming Strategic
Security vendors have historically differentiated themselves through sensors, telemetry, detection content, data platforms, investigation interfaces, and response controls.
Those assets remain essential. Agentic systems do not diminish their value.
But another layer is emerging around them. This layer determines how work is defined, how specialists are selected, how context is assembled, how agents collaborate, how policies remain active during execution, and how humans participate in consequential decisions.
As agents become more capable, strategic value will increasingly come from how work is coordinated across the systems that hold the data—not only from where the data is stored.
This does not mean one company must control every part of the stack. It creates an opportunity for products to become participating members of a broader, governed workforce.
For vendors, the strategic question is no longer only, “What can our agent do?”
It is also, “How can our expertise contribute to the larger operation?”
The Harness Extends Beyond the SOC
The SOC is an ideal proving ground for a multi-agent workforce. The work is complex, multidisciplinary, time-sensitive, and governed by strict operational boundaries. Agents must combine specialized expertise, collaborate across systems, preserve evidence, and keep humans accountable for consequential decisions.
But these requirements are not unique to security operations.
The same architecture can coordinate work across IT operations, fraud, risk, compliance, privacy, and other enterprise functions. Each domain requires different agents, tools, policies, and knowledge, but the underlying problem is the same: how to turn distributed intelligence into trusted operational outcomes.
That makes Bricklayer more than an Agentic SOC product.
Bricklayer is a harness for governed AI work. Cybersecurity is where the architecture has been developed and deployed, but the architecture applies wherever specialized agents and humans must work together across complex enterprise systems.
For security vendors, this creates an opportunity beyond adding agents to an existing product. Their expertise can become part of a wider enterprise workforce while remaining governed by the policies and boundaries of their domain.
Security is the starting point. It does not have to be the boundary.
Architecture Comes Next
CrowdStrike deserves credit for moving the conversation forward. Its announcement makes the Agentic SOC more concrete and signals where the market is heading.
The industry is beginning to converge around several principles. Security work will increasingly be performed by teams of specialized agents. Those agents will need shared, trustworthy context. Humans and agents will operate in common environments. Existing security products will increasingly participate through APIs, MCP, and other interoperable interfaces. Autonomous actions must remain visible and governed. Operational knowledge must be able to improve the system without making it opaque.
The destination is coming into focus.
The next question is how quickly the rest of the security ecosystem can get there.
Bricklayer provides the harness: a governed, coordinated environment in which agents, analysts, tools, and organizational knowledge can operate as one workforce.
For technology companies, the opportunity is to make their agents, expertise, and capabilities available wherever customers need them.
For enterprise leaders, the opportunity is to establish a cross-platform operating layer that coordinates the best capabilities across their environment while preserving authority over their procedures, policies, evidence, and future technology choices.
CrowdStrike is showing what an Agentic SOC can become inside Falcon.
Bricklayer provides a faster path to building it across the enterprise.


