
Co-founder and CCO

We shipped bots in the LimaCharlie AI Terminal. You can create one in a few minutes: give it a role, pick a profile if you want one, and open a chat. I said this during our September Build Log demo and I'll repeat it here, because everything else in this post follows from it. The bot is the easy part.
The better the models get, the more a bot's foundation decides what it can do. In security that effect is sharper than anywhere else, because a bot working in a SOC can act. Whatever sits underneath a bot gets amplified. On a closed stack, a smarter model produces smarter suggestions for a human to carry out. On an open foundation, the same model gets more work done inside the limits you set. Every model release widens that gap.
One bot, one job A bot starts as a role described in plain language, such as an OSINT researcher, a detection engineer, or a triage analyst. You can chat with it directly and shape as much of its definition as you like.
Routines
Ask a bot to do something on a schedule and it proposes a routine you can save. For example, have a morning report at 8am covering the past day's exploited high-profile CVEs and any breaches with good technical detail. The bot runs it daily and posts its findings in chat, so the research is waiting when your analysts log in.
Groups
Put several bots in a group chat and give one of them orchestration duties. A"chief of staff" bot can take a request to check recent major CVEs against my tenant and suggest detections. It can send the research to the OSINT bot, give a scoping bot instructions to check exposure, and move the findings to a D&R rule builder once the data comes back. You’ll end up with detection rules to review, edit, and download.
Group chat as an interface pattern is familiar to anyone who has used an AI tool this year. The results depend on what each bot can reach.
Every function in LimaCharlie has been available through the API since we started building it in 2018, covering telemetry queries, detection and response rules, sensor tasking, case management, and tenant administration. We designed it that way for engineers who wanted to automate their own stack, and agents turned out to need exactly the same thing. When the scoping bot checks exposure, it queries real telemetry in your tenant. When the rule builder writes a detection, it produces the same D&R syntax your team already reads and deploys.
The terminal runs as you
Bots in the AI Terminal operate as your own user, so they carry your permissions and nothing more. A bot has no path into a tenant or capability you haven't been granted.
Memory is readable
You can view and edit the memory of every bot and every group. When a bot's behavior drifts, you can see what it's carrying and correct it directly.
The output is yours
Rules the bots produce are standard LimaCharlie D&R rules. You can read, edit, version, and deploy them like anything else your team writes.
The AI Terminal works with LimaCharlie's managed AI, your own cloud subscription or API keys, or models you run on your own infrastructure. Everything the bots use is exposed through our CLI and documentation, so switching models leaves the foundation untouched. When a better model ships, your bots benefit as soon as you point them at it.
Create one bot for a job your team does every morning, give it a routine, and read what it produces for a week. Then add a second bot and put them in a group. If you don't have a tenant yet, create a free account and open the AI Terminal.
The bots will get better every time the models do. We spent eight years making sure they'd have something worth standing on.