ESENTIRE + ANTHROPIC

Atlas, now in Claude.

eSentire customers can connect Atlas directly to Claude — investigating findings, querying their environment, and acting on tickets in natural language.

It's the next step in the eSentire–Anthropic partnership: the same Claude that already powers 120,000+ autonomous investigations behind Atlas, now available to your team as an interface to your own MDR data.

The Partnership

eSentire + Anthropic Atlas MCP eSentire + Anthropic Atlas MCP

Two sides of the same partnership.

Claude runs inside Atlas. The Atlas MCP turns the relationship around — bringing your Atlas data into Claude. Same partnership, two complementary surfaces.

— The engine

Claude inside Atlas

Behind the scenes, Atlas already uses Claude to run autonomous threat investigations across thousands of environments — averaging 44 tool calls per case, with above-90% alignment with senior SOC experts and 99.96% ransomware containment before encryption.

That work happens automatically, without anyone in your team having to ask.

120K+ Autonomous investigations / 12 mo
99.96% Ransomware containment

Read the full case study

— The interface

Atlas inside Claude

The Atlas MCP connector turns the relationship around. When your team connects Atlas to Claude Desktop or Claude Code, Claude can query your MDR environment directly: pull findings, look up assets, surface vulnerabilities, manage tickets.

It's your data, your permissions, surfaced through the chat your team already uses.

16 Purpose-built tools
OAuth 2.0 via Okta · RBAC-aware

Capabilities

What you can do with Atlas in Claude.

Three high-value flows your team will reach for first. Each example exercises real tools the MCP exposes today.

01 / Investigate

Investigate findings, fast.

Pull open critical findings, drill into signal-level detail, and identify affected assets — all in one conversation.

"Show me the open critical findings from the last 7 days. For the highest-severity one, pull the full signal data and tell me which assets are affected."

02 / Manage

Vulnerabilities and patches.

Surface unpatched critical vulnerabilities across your environment, group them by host, and see which fixes are available now.

"List my unpatched critical vulnerabilities from the last MVS scan, grouped by host, and show me which ones have missing patches available."

03 / Act

Triage and act on tickets.

Review case status, read the latest analyst comments, and create or update tickets without switching tools.

"Open ticket CS-12345 — summarize current status, show me the latest comments, and add a follow-up ticket for the remediation work."

Built for security teams

Faster triage. Trusted access. No new platform.

Faster triage,
deeper context

Cut the time between "alert lands" and "I understand what's happening." Atlas MCP gives Claude live access to findings, signal data, and asset context — so analysts spend less time pivoting and more time deciding.

Your data,
your controls

OAuth 2.0 via Okta. Customer-scoped access. The MCP only sees what your authenticated user is permitted to see — the same RBAC model as the Atlas platform.

No new platform
to learn

It's your Atlas data, surfaced through Claude. Pair the prompts and workflows your team already uses with Claude's reasoning, document handling, and analysis.

Architecture

How it works.

The connection

The Atlas MCP server runs at api.esentire.com/mcp/rpc and uses the Model Context Protocol (MCP) over Streamable HTTP. When you connect Claude to Atlas, Claude can call any of 16 purpose-built tools that read from — and in some cases write to — your eSentire environment. Authentication is OAuth 2.0 via Okta; data flows directly between Claude and eSentire's APIs over your authenticated session, with all infrastructure hosted in eSentire's us-west-2 (Oregon) AWS region.

Reference

Available tools.

Sixteen purpose-built tools split across four functional areas. Read tools surface data; write tools always prompt for confirmation.

Findings & signals

3 read-only
  • list_findings Search and filter open or closed findings
  • get_finding Full detail for a specific finding
  • get_signal_data Signal-level data behind a finding

Assets & vulnerabilities

5 read-only
  • list_assets Asset inventory, filterable by attributes
  • get_asset Single-asset deep-dive
  • list_vulnerabilities Vulns from MVS scans
  • get_vulnerability CVSS, hosts, exploitability
  • list_missing_patches Patches available but not applied

Support tickets

5 read 2 write
  • list_tickets Search support tickets
  • get_ticket Full ticket detail
  • get_ticket_comments Latest analyst comments
  • get_ticket_attachments Attached files
  • get_ticket_options Available case fields
  • create_ticket Open a new case (confirms first)
  • update_ticket Update status, comments (confirms first)

Findings actions

1 write
  • update_finding Close, change status, add notes (confirms first)

Security & privacy

Your data, your controls.

Authentication

OAuth 2.0 via Okta. Tokens are scoped to the authenticated user and follow the same RBAC permissions as the Atlas platform.

Data flow

All requests go directly from your Claude client to eSentire's API. No customer data is stored by the MCP server beyond the lifetime of the request.

What's accessed

Only the data your authenticated user is permitted to see — findings, assets, vulnerabilities, tickets, and signals tied to your tenant.

What's not accessed

The MCP does not query Claude's memory, conversation history, or files you've uploaded to Claude.

Common questions.

Who can use the Atlas MCP?

Existing eSentire customers with active API access. If you're not yet a customer, talk to sales.

Which Claude products work with it?

Claude Desktop and Claude Code today. Once accepted into Anthropic's Connectors Directory, it will also be available for users on connector-supported Claude.ai plans.

Will Atlas MCP work with other AI clients besides Claude?

MCP is an open standard, so technically any MCP-compatible client can connect. Our supported launch surface is Claude — that's where the work has been validated end-to-end and where customers will get the best experience day one. We'll evaluate additional clients based on customer demand and our ability to support them at the same quality bar.

How is this different from the Claude that powers Atlas?

They're complementary. Claude inside Atlas runs autonomous investigations on every signal — that's been live across our customer base for months. The Atlas MCP is the other direction: it gives your team a way to query Atlas data and act on it from inside their own Claude environment. Same partnership, two different surfaces.

What happens if my Okta access changes?

The MCP respects your eSentire RBAC permissions. If your access changes in Okta, the MCP reflects it on the next request.

Can Claude make changes I didn't approve?

No. Write tools (creating or updating findings and tickets) always prompt you for confirmation before executing.

Where is the data hosted?

The Atlas MCP runs in eSentire's eu-west-1 (Ireland) AWS region behind API Gateway.

Ready to connect Atlas to Claude?

Bring the same Claude that already powers Atlas's autonomous investigations into your team's daily workflow.