CrowdStrike announced on September 2, 2026 that its Falcon cybersecurity platform is now available directly through the Anthropic Claude Marketplace — letting security teams purchase Falcon using existing Anthropic spend commitments and build custom security agents, via Charlotte AI AgentWorks, without writing code. Anthropic's Head of Enterprise Cybersecurity GTM, Ash Alhashim, framed the goal directly: "The teams that keep companies safe should be able to get the best security tools from Anthropic as easily as they get Claude."
TL;DR
| Question | Answer |
|---|---|
| What's new? | Falcon is purchasable and usable directly through the Claude Marketplace |
| The no-code piece | Charlotte AI AgentWorks — build custom SOC agents from Falcon telemetry, no coding |
| What agents can do | Triage, alert enrichment, threat hunting, response — conversationally, inside Claude |
| Billing | Existing Anthropic spend commitments can be used to purchase Falcon |
| Governance | Scoped permissions, human-in-the-loop approvals, full auditability on shared agents |
| Other launch partners for AgentWorks | AWS, NVIDIA, OpenAI, Salesforce (multi-vendor strategy) |
Why "buy security tooling through Claude Marketplace" is the actual news
The procurement detail here is arguably more significant than the technical integration itself. CrowdStrike is one of the largest, most established enterprise cybersecurity vendors — the fact that its flagship platform is now purchasable using a customer's existing Anthropic spend commitment, rather than requiring separate procurement, budget approval, and vendor onboarding specifically for CrowdStrike, signals something concrete about where Anthropic wants the Claude Marketplace to sit in enterprise buying decisions: not just a discovery catalog of AI-adjacent tools, but a genuine purchasing channel major enterprise vendors are willing to route real revenue through.
CrowdStrike's own framing supports that reading directly — Chief Business Officer Daniel Bernard's quote specifically calls out that "AI is changing how... technology is procured, deployed, and run," treating this as a procurement-model shift, not just a product integration.
What Charlotte AI AgentWorks actually does
Charlotte AI is CrowdStrike's existing agentic security analyst product, already built on Anthropic's Claude. AgentWorks is the newer, more specific capability being highlighted here: a way for security teams to build custom agents grounded in real Falcon telemetry — their actual endpoint, identity, and threat data — through a conversational, no-code interface, rather than needing security-engineering or AI-development expertise to stand up a working SOC automation.
The stated workflow categories — triage (initial alert assessment), enrichment (adding context to a raw alert), hunting (proactively searching for threats), and response (acting on a confirmed finding) — cover the standard SOC analyst workflow end to end, which is a meaningfully broader scope than a single-purpose chatbot. Built agents are explicitly designed to be shared and reused across a security team, with scoped permissions and human-in-the-loop approval gates built in rather than left to each team to design themselves, plus an audit trail for what each agent actually did.
Where this fits in CrowdStrike's broader AI strategy
It's worth distinguishing this from a separate, related CrowdStrike product: Falcon Guardian, which focuses on securing AI agents themselves at runtime, on the endpoint — a different problem (protecting against AI agents that misbehave or get compromised) than what's being announced here (using AI agents to do security work). CrowdStrike is clearly running both plays simultaneously: AI as a tool for security teams to use, and AI agents as a new category of thing security teams need to defend against — a distinction worth keeping in mind, since "CrowdStrike and AI" now covers genuinely different products depending on which side of that line a specific announcement is on.
Charlotte AI AgentWorks is also explicitly multi-vendor, not Anthropic-exclusive — launch partners include AWS, NVIDIA, OpenAI, and Salesforce alongside Anthropic. This specific announcement is CrowdStrike's Anthropic-facing piece of a broader strategy to make Falcon telemetry usable across whichever frontier AI platform a given enterprise customer has already standardized on, rather than betting the whole agentic-security strategy on one model provider.
Why marketplace-native security tooling is a different model than integrations
Most existing "AI meets cybersecurity vendor" stories through 2026 have been integration announcements: vendor X's product can now call model Y through an API, or vendor X built a chatbot on top of model Y. What CrowdStrike and Anthropic are describing here is a step further than that — Falcon isn't just accessible from Claude, it's purchasable through Claude's own marketplace infrastructure, with billing routed through an existing Anthropic relationship. That's a meaningfully different commercial arrangement: it treats Claude Marketplace as a genuine sales channel a major independent vendor is willing to route real revenue through, not merely a technical integration point.
For enterprise buyers, the practical effect is fewer separate vendor relationships to manage for a security stack that increasingly touches AI at every layer — one procurement conversation with Anthropic can now extend into purchasing CrowdStrike capability, rather than requiring parallel, independent negotiations with each vendor whose product happens to plug into Claude.
What "human-in-the-loop" actually buys a security team here
It's worth being specific about why the governance details in this announcement — scoped permissions, human-in-the-loop approvals, full auditability on agents built through Charlotte AI AgentWorks — matter more here than they might for a lower-stakes agent use case. Security operations work is exactly the domain where an overconfident, unsupervised agent can cause real damage: an agent with response-workflow permissions that misclassifies a benign process as malicious and takes automated action against it, or one that misses a genuine threat because it was tuned for a different pattern, has direct operational consequences in a way that, say, a shopping agent recommending the wrong product doesn't.
Building approval gates and audit trails into the no-code agent-creation flow from the start — rather than leaving that responsibility to each individual security team building their own agents — is the detail that determines whether this integration actually reduces SOC workload safely, or just moves the risk of automation error from a custom-built internal tool to a vendor-provided one without meaningfully changing the underlying risk calculus.
What to watch for as the marketplace model matures
The open question worth tracking as more vendors follow CrowdStrike into AI-native marketplaces: whether unified spend-commitment purchasing actually simplifies vendor management for enterprise buyers in practice, or whether it just adds another layer of complexity (now needing to understand both the underlying vendor's pricing and how it maps through the AI platform's commitment structure). Early adopters of this model will be the real test case for whether "buy your security stack through your AI vendor's marketplace" becomes a durable procurement pattern or stays a niche option alongside traditional direct vendor relationships.
Honest limitations
- Specific pricing for Falcon through the Claude Marketplace, and exact terms for how much of an existing Anthropic commitment can be applied to CrowdStrike purchases, weren't detailed in the sources reviewed for this piece.
- This is a vendor-to-vendor commercial and product announcement — independent evaluation of how well Charlotte AI AgentWorks-built agents actually perform in production SOC environments isn't available yet.
- The relationship between this integration and Falcon Guardian (the separate agent-security-at-runtime product) is described here based on CrowdStrike's own public positioning, not independently verified technical detail.
How this connects to CrowdStrike's dual AI strategy
It's worth restating the bigger picture one more time, because it clarifies why CrowdStrike is investing in both directions simultaneously rather than picking one. On one side, Falcon-through-Claude-Marketplace and Charlotte AI AgentWorks are about making CrowdStrike's own security data and tooling more accessible via AI, letting customers build agents faster than a traditional professional-services engagement would allow. On the other side, the separately positioned Falcon Guardian product is about defending against the new risk category AI agents themselves introduce — a company running dozens of custom-built agents against sensitive systems has created new attack surface that didn't exist before those agents were built. A vendor addressing both sides of that equation at once — making agents easier to build safely, and securing the agents once they exist — is a coherent, if ambitious, bet on where enterprise security spend is heading as agentic AI adoption accelerates across the industry.
Closing
This is a genuine signal about where enterprise AI purchasing is heading: a major, independent cybersecurity vendor routing a real product line through a foundation-model provider's marketplace, with existing spend commitments applicable across both. For security teams already standardized on Claude, the practical value is real — no-code agent building against actual Falcon telemetry, with governance controls built in rather than bolted on. For anyone tracking the broader agent skills and MCP ecosystem, it's another data point that enterprise vendors are increasingly treating "build a custom agent against our product" as a first-class, self-serve capability rather than something requiring a professional-services engagement.
Related on explainx.ai
- Claude Commerce Agents: Open-Source Blueprint
- What Are Agent Skills? Complete Guide
- What Is MCP (Model Context Protocol)? Complete Guide
- Gemini 3.8 Flash Is Official: Benchmarks, Flash Cyber, and Pricing
- OpenAI Astra Confirmed Critical for Cybersecurity
- Claude for Work
Sources
- CrowdStrike — CrowdStrike Brings the Falcon Platform to the Anthropic Claude Marketplace (September 2, 2026)
- StockTitan — CrowdStrike Falcon Platform Coming to Claude Marketplace
- CrowdStrike — Charlotte AI AgentWorks
This post reflects CrowdStrike and Anthropic's official announcement as of September 3, 2026.
