Connect an AI system you control to Milgram through MCP. Put it to work on evidence, false positives, and detection engineering within the permissions you grant.
YOUR AI. YOUR PERMISSIONS.
From reviewing alerts to improving detection.
MCP connects a customer-controlled AI system to Milgram’s investigation and detection-engineering capabilities.
A connected AI can inspect detections, matched rules, prompts, responses, tool activity, and surrounding session context. It can record assessments, add investigation context, and correct inaccurate detections within its granted permissions.
The same interface enables rule authoring and adaptation. An AI can help create a new deterministic rule, refine an existing one, and identify benign cases that should be part of validation. The value extends beyond producing an alert summary.
Security teams can use the connection interactively or design an automated review workflow. They retain control of the model, instructions, access scope, and permitted actions.
THE FEEDBACK LOOP
Turn reviewed evidence into better signals.
1. DetectRules, session correlation, and the classifier surface candidate findings.
2. InvestigateA person or authorized AI examines the evidence and corrects false positives.
3. Improve rulesAuthor or adapt deterministic detections and validate them against malicious and benign examples.
4. Tune the classifierUse reviewed signals and corrections to adapt the smaller detector to the organization’s traffic.
WHY THIS ARCHITECTURE
More detection-engineering capacity. Explainable execution.
Rules require maintenance as attacks evolve. Traditionally, that work has been limited by the time available to human detection engineers. Customer-controlled AI can accelerate drafting, adaptation, and review while deterministic execution preserves concrete, inspectable matches.
That is an architectural advantage, not a guarantee that every evasion will be solved. New rules still need false-positive testing, representative examples, controlled rollout, and a way to reverse a poor change.
Large-model review operates outside the live request path. It does not require an extra judge-model call for every proxied interaction. The separate review model may still have inference costs, latency, data-handling requirements, and its own exposure to adversarial content.
CONNECTION AND GOVERNANCE
Grant access deliberately.
Start with investigation.
Connect through the deployment’s MCP endpoint and complete the supported authorization flow. Select the scopes the client requires. Milgram’s exposed tools are limited by the intersection of the token’s scopes and the user’s capabilities.
For an initial evaluation, keep the workflow focused on reading evidence and assessing findings before enabling write operations.
Expand with validation.
Grant rule or correction permissions only when the operating process is ready. Review the connected agent’s activity and revoke the connection when access is no longer required.
Ensure the reviewing AI is allowed to receive the session content it will inspect. A separate model’s data-processing terms still apply.
Is AI review automatically allowed to change every rule?
No. Available tools depend on authorized scopes and the user’s capabilities. Your operating process should define who approves changes, how rule tests are reviewed, and when updated rules can affect enforcement.
Does the classifier continuously teach itself from every alert?
The intended learning loop uses organization-specific signals and corrections to support fine-tuning. Raw detections should not be treated as unquestioned ground truth. Review quality, training configuration, and validation determine whether an update is useful.
INVITE-ONLY BETA
Bring your workflow. Define your evaluation.
Tell us what you use, what you need to protect, and where Milgram would run.