Works the alert queue the way the AI Technician works the ticket queue. It takes an identity alert, gathers the evidence, writes what it found, and proposes the containment. Read-only investigation is autonomous. Containment is gated by default.
Theo picks up identity and endpoint alerts from the systems you already run, and opens a ticket in the PSA so the work lives where the rest of your work lives.
Risky sign-in and risky user detections, impossible travel, unfamiliar sign-in properties, repeated MFA denials, legacy authentication attempts, and mailbox rule or forwarding changes.
Device alerts from Datto RMM and NinjaOne, with the device's compliance and patch state pulled in as part of the investigation rather than looked up afterwards.
Every alert Theo works becomes a ticket in ConnectWise, Autotask, Halo PSA or SuperOps, classified, routed and prioritised by the AI Triager like any other inbound work.
Investigation is read-only, so it runs without waiting for anyone. By the time a human reads the alert, the questions they were going to ask are already answered.
Recent successful and failed sign-ins for the account: timestamps, IP addresses, geography, client app, device and conditional-access outcome. Theo separates the sign-ins that look like the user from the ones that don't.
Current Entra risk level for the user and for the sign-in, which detections fired, and whether the risk was already remediated or dismissed — and by whom.
Every rule on the mailbox, with the ones that hide or redirect mail called out. A rule that moves anything containing "invoice" to a subfolder named with a single space is the tell, and it is the one a tired technician scrolls past.
Mailbox-level and transport-level forwarding, when it was set and by which account. External forwarding is reported explicitly rather than left in a list of settings.
Active sessions and refresh tokens for the account, registered MFA methods and when each was added. A method registered during the suspicious window is treated as part of the incident, not as background.
What the account can reach: group memberships, admin roles, shared mailbox and delegate access, and whether the same indicators appear on other users in the tenant.
Containment actions change a client's tenant, and several of them lock a real person out of their work. Theo does not take that judgement on its own. It presents the containment it recommends, the evidence behind it, and what the action will do — and waits.
Approve, change the scope, or decline. Approval is recorded against the named approver and attached to the ticket.
| Containment action | Reversible | Default |
|---|---|---|
| Revoke active sessions and tokens | Yes | Approval |
| Remove a malicious inbox rule | Yes | Approval |
| Remove external mail forwarding | Yes | Approval |
| Force a password reset | Yes | Approval |
| Block sign-in for the account | Yes | Approval |
| Revoke registered MFA methods | No | Approval, always |
Reversible here means the account can be restored to its previous state by a technician. It does not mean the containment was free — a session revocation still signs someone out of their day.
A contained account with no written record is a problem you will have again in three months, and an answer you will not have when the client asks. Theo writes the incident up in the PSA: what fired, what the evidence showed, what was contained, who approved it, and what is still open.
Every action carries a timestamp and a named approver, and the whole log is exportable for your own compliance evidence.
Entra flagged a risky sign-in for j.marsh@northwind.example at 02:14 from an IP in a country with no prior sign-in history. The same account authenticated successfully from its usual location at 08:41 the previous day.
Two findings: an inbox rule created at 02:19 moving mail matching "invoice" or "payment" to RSS Subscriptions, and an SMS MFA method registered at 02:22 against a number not in the client's records.
Recommended and approved: revoke sessions, remove the rule, force a password reset, revoke the new MFA method. Open item — the account holds Send-As on the shared finance mailbox; sent items from the last 12 hours need a human review.
It is not a replacement for your security stack. It works the alerts your stack produces, and it is worth being blunt about the line.
Book 30 minutes. We'll look at the identity alerts your tenants actually generate and which of them are worth Theo working end to end.