Early Access|Command

Operate Risk Intelligence From Signal to Delivery

Command lets organizations and service providers build customer-specific intelligence pipelines, staff them with tiered digital analyst roles, control models and budgets, track standing threats, and deliver evidence-backed alerts and reports through a complete review chain.

Early access is offered through focused evaluations. Command pricing is not yet published.

Scout or External Event
Tier-1 Review
Manager Decision
Approval Gate
Alert or Report

When to Choose Command

Use Command when intelligence has to run as an operation

Command is for teams that need repeatable adjudication, customer separation, review tiers, budget control, persistent monitoring, evidence-backed reporting, and an audit trail—not merely another stream of alerts.

You operate intelligence for multiple customers or business units

Use one organization account while keeping each customer’s data, workflows, programs, reporting, portal access, model policy, and spend fully separated.

High-volume review needs a consistent operating model

Put every event through a defined adjudication chain instead of relying on ad hoc analyst judgment, inbox rules, or disconnected spreadsheets.

Critical decisions require review and proof

Require manager or CSO-level approval, preserve the reasoning and confidence behind every decision, and trace each alert or report back to its evidence.

Recurring monitoring must produce more than alerts

Cluster related activity into standing signals, re-verify them over time, and compile scheduled intelligence reports from adjudicated evidence.

Model cost and customer budgets must be controlled

Meter every processing action, see per-decision cost, set customer budgets and thresholds, and automatically pause a runaway pipeline.

Customers need branded delivery without direct platform access

Provide controlled, read-only portals, branded reports, scheduled delivery, and redaction rules for exactly what each customer can see.

Organizations and Customers

One operation, many separated customers

Run Command as an internal intelligence operation or a service provider. Configure each customer independently without creating a separate deployment for every program.

Multi-customer operations

One organization can manage many customers with separated data, workflows, programs, reporting, portal visibility, model access, budgets, and spend.

Customer-specific configuration

Tailor pipelines, brand terms, taxonomy, review policy, report branding, schedules, thresholds, model catalog, and delivery for each customer without a separate deployment.

Teams and roles

Invite and manage internal users with role-based access while providing customers a controlled read-only portal for their intelligence.

The Digital Workforce

Staff every customer with defined analyst roles

Command uses named AI analyst agents—virtual analysts—with assigned roles, skills, models, review authority, and budget controls. The point is not anonymous automation; it is a visible workforce where every decision can be traced to who made it and why.

Named analyst agents

Create named personas with a defined role, assigned skills, and an approved AI model.

Tiered review chains

Mirror a real intelligence or security operation: Tier 1 adjudicates, a manager reviews potential threats, and a CSO-level role handles critical escalation.

Signed decisions

Every decision records who made it, the reasoning, confidence, category, policy version, processing units, and cost.

Budget controls

Set monthly customer budgets, alert thresholds, and automatic pause conditions so pipelines stop safely when limits are reached.

What the workforce can do

Threat analysis and classification of monitored content
Risk scoring and sentiment analysis
Entity extraction for people, organizations, domains, locations, and other identifiers
Summarization and situation-report writing
Decision review, second-opinion arbitration, and consensus voting
Quote-drift checking so reports do not say more than the evidence supports
Critical-approval gating for high-stakes actions
Signal labeling and monitoring-program context
Custom skill blocks for organization-specific analyst logic

Data Sources

Bring in Scout intelligence or external events

Scout feeds

Continuous monitored content from the open, social, and deep web using the customer’s Scout terms and taxonomy.

Inbound webhooks

Push events from external systems into a customer workflow.

Scheduled pulls and HTTP requests

Fetch from APIs on a cadence and return the result to the pipeline.

Manual and event triggers

Run a workflow on demand or when a defined event occurs.

Visual Workflows

Build the operating policy as a diagram

Compose no-code pipelines on a drag-and-drop canvas, version them, run customer-specific instances, and test against live feeds before enabling.

Triggers

Feed polling, webhooks, schedules, events, program ingestion, and monitoring windows.

Routing logic

Conditions, multi-way switches on any field or decision, branch merging, thresholds, and customer-specific escalation policy.

Analyst steps

Run any approved workforce skill at any review tier, with conditions controlling when deeper review is required.

Approval gates

Hold alerts, reports, verdicts, and other consequential actions until the configured sign-off is complete.

Actions

Create alerts, send email, post webhooks, call HTTP APIs, capture screenshots, generate and deliver reports, and write verdicts back to Scout.

Fan-out and reuse

Fork an event into another workflow or monitoring program so one ingestion can support multiple customers, reports, or use cases without duplicate collection cost.

Standing Coverage

Monitoring programs that remember what is still unfolding

Command turns recurring feeds into customer programs with continuous adjudication, persistent signals, duplicate control, precedent recall, scheduled re-verification, and report windows.

Standing monitoring programs

Define brand terms and variants, routing categories, schedules, thresholds, customer context, and reporting windows.

Continuous adjudication

Triage new events on a cadence and sweep in late-arriving content so program coverage remains current.

Persistent threat signals

Cluster related events into signals that persist, age, carry over between windows, and are re-verified on schedule.

Duplicate and precedent control

Collapse exact matches and near-duplicates by meaning, then recall how similar past events were decided for greater consistency.

Scheduled intelligence reporting

Compile reports from adjudicated events and signals using customer time zones, templates, review chains, and delivery schedules.

Reports and Delivery

Every report remains tied to its evidence

Command produces scheduled, customer-branded intelligence through a controlled review chain. Claims are checked against the source evidence before delivery, and the complete lineage remains available afterward.

Customer-branded reports

Use templates and branding configured for the customer or service provider.

Approval before delivery

Require the configured manager and CSO-level review chain before a report or critical alert is released.

Evidence built in

Include source links, captured screenshots, contributing events, and the decisions supporting each reported finding.

Claim verification

Check report language against the underlying evidence and flag unsupported drift before delivery.

Portal and redaction controls

Deliver scheduled reports through a customer portal while controlling what end users can see.

Full lineage

Trace any report back to every contributing signal, decision, source event, policy version, and review step.

Model Strategy

Choose the models that fit the customer and task

Provider choice

Use Anthropic Claude, OpenAI, Moonshot Kimi, xAI Grok, or approved self-hosted models.

Organization model catalog

Set organizational defaults and restrict which models individual customers, workflows, or roles may use.

Provider flexibility

Switch or mix providers without rebuilding the workflow logic.

Encrypted credentials

Store provider API keys encrypted and keep them hidden from customer users and workflow viewers.

Visibility, Cost, and Trust

See how the operation is performing

Program operations dashboard

Review events received, kept rate, review depth, verification failures, active signals, report-chain status, and window cost for each customer.

Drill-through metrics

Open the queue behind each metric instead of relying on a disconnected summary number.

Weekly trends

Compare event volume, decisions, review activity, signals, and spend over time.

Attention thresholds

Surface stale reviews, failed verification, blocked report chains, budget pressure, and other operating conditions before customers notice.

Complete audit trail

Preserve decisions, approvals, policy versions, costs, workflow versions, source events, screenshots, report lineage, and delivery actions.

Customer-level security

Maintain customer data separation, modern session and login protection, strong password policy, encrypted credentials, role-based access, and portal redaction.

Configured consequence controls

Alerts and reports do not leave the system until the review and approval chain configured for that customer has completed.

Evaluate Command Against Your Operating Model

Early access is structured around a focused evaluation of your customer program, review policy, reporting requirement, workflow, or monitored feed. Command pricing is not yet published.