A day in the loop for an enrolled endpoint — and what the audit trail proves.
A long-form look at how the AI-native MDR model runs in practice, written for a buyer who's never heard of Curtainwall and wants to read the mechanism before booking a discovery call. Every claim below is consistent with /faq and /pricing — no numbers invented here, no new tiers.
Four stations, run in sequence, every minute of every day.
The agent never closes the loop alone. Every action — patch, quarantine, token revocation — produces a row in the audit log before it produces a notification, and a reversal is its own row.
- Station 01WatchEDR, identity, and SaaS signal stream into a triage agent that ranks, correlates, and either acts below threshold or files in seconds. The L1 queue never pages your team.
- Station 02PatchRoutine OS and third-party patches apply autonomously, on the cadence you configured at enrollment. Out-of-window changes are held, summarised, and applied only after explicit sign-off.
- Station 03ContainSuspicious processes are quarantined, identity tokens revoked, and network egress restricted the moment confidence drops below threshold. Every action produces an audit row first.
- Station 04EscalateA named technician is paged only when an incident crosses the agent confidence threshold, a governance review demands sign-off, or an insurance notification trigger fires — never on noise.
The agent never closes the loop alone.
Every action — patch, quarantine, token revocation — produces a row in the audit log before it produces a notification. If the action is reversed, the reversal is also a row. The customer reads the same log the auditor does.
When a named human actually steps in.
The rule is narrow. A real person is paged only when (a) an incident crosses the confidence threshold, (b) a governance review demands sign-off, or (c) a cyber-insurance notification trigger fires. Routine triage, correlation, and patching never page an analyst. The shape of the human handoff is calibrated by tier — the rule is the same.
What the auditor actually reads.
Each action produces a row in the audit log BEFORE it produces a notification. Row contents are fixed: agent ID, evidence, and outcome. The log is Merkle-anchored, append-only, and readable by both the customer and the auditor from the same source of truth. The Merkle head is anchored off-platform so it cannot be quietly rewritten — a reversal is a new row, never an edit.
- 14:02:11Ztriageprocess quarantined · wininit.exe clone · mb=57%agent/sigma-3 · 0x9c4a…b217
- 13:58:47Zpatchapplied · CVE-2026-3191 · 412 endpointsagent/rho-12 · 0x9c4a…b204
- 13:55:02Zidentitytoken revoked · session 9b31…a204agent/theta-7 · 0x9c4a…b1f1
- 13:50:36Ztriageclosed · lowercase-noise · false-positiveagent/iota-1 · 0x9c4a…b1d8
- 13:42:19Zescalatehandoff · analyst: l.chen · ct-confidence 0.94agent/lambda-4 · 0x9c4a…b1c2
The maintenance window, untangled.
Patching is not "as fast as possible." It runs on the cadence you defined at enrollment, inside the windows you configured. The plan-adjust / no-adjust split is deliberate: most patches need no decision, a few do, and the agent knows which is which.
Why trust a vendor you just heard of.
Five transparency pillars — the things a vendor either does or does not do when nobody is watching. None of these are marketing slides; they are commitments that show up in the log, the contract, and the contact surface.
One log, two readers
The auditor reads the same log the customer reads. There is no separate "vendor view" — what your underwriter sees is what your CISO sees, with the same row IDs and the same Merkle head.
A named human per handoff
Every agent→human escalation names the technician on the receiving end. No anonymous ticketing, no rotating queues — a human is on the hook per handoff, by name, in the row.
Narrow escalation gates
Escalations fire on three triggers, nothing else. The rule is published in /faq in plain English, so a stranger can audit the threshold without signing a contract first.
Flat subscription cannot grow
Pricing is a flat monthly subscription per endpoint, inside the established $10–$25 band (see /pricing). An incident does not change your invoice — by design — so there is no penalty for declaring one.
A real address, not a chat widget
No chat widget, no captcha farm, no third-party marketing tracker. The contact surface is one address: a real person reads what lands there.
Cross-references: /faq — the objection ledger. /pricing — the flat-subscription detail. The home page — the short version of the same loops above.
The four follow-ups we hear most.
Short questions, short answers — written for a stranger who has read this far and wants the last few details before they book the call.
Read the loop, then enroll the fleet. We’ll confirm scope on the discovery call.
curtainwall@curtainwallsecurity.com