Cortex tells your agent what’s wrong. With Tamnoon MCP, it now also learns what matters, who owns it, and how to fix it safely. Security teams are moving past chat assistants and toward agents that act.

Cortex tells your agent what’s wrong. With Tamnoon MCP, it now also learns what matters, who owns it, and how to fix it safely.
Security teams are moving past chat assistants and toward agents that act. These agents work across tools, pull context, and carry a task from alert to resolution. To do that well, an agent needs asset context, ownership data, and remediation safety signals before it can turn findings into safe fixes.
Today, we’re announcing Tamnoon MCP for Cortex. When Cortex’s agent hits an issue, it can now ask Tamnoon for the context that turns a finding into an action. Cortex drives the workflow, while Tamnoon supplies the remediation intelligence that powers it.
Tamnoon MCP exposes the cloud security context teams need to move from findings to action, with a direct Cortex connection and four workflows teams can run right away.
Tamnoon MCP exposes Tamnoon’s insights so an agent can read them and reason over them. Instead of querying a database or stitching together screenshots, the agent asks Tamnoon directly and receives structured context in return.
Here’s what it can pull:
Each of these insights comes from Tamnoon’s agentic remediation model, where Tami runs the analysis and Remediation Experts, Tamnoon’s cloud security engineers, validate the work.
Cortex’s agent connects to Tamnoon MCP with an API key you generate in Tamnoon. Once connected, the agent can call Tamnoon at any point in a workflow, retrieve the required context, and act on it.
The workflow is simple:
Cortex is the first integration. Because Tamnoon MCP follows the Model Context Protocol, the same insights are available to any other agent you connect.
Once Cortex and Tamnoon MCP are connected, your agent can answer questions it couldn’t before.
Here are four example workflows to start with, each with the prompt and what runs behind the scenes.
Prompt: “Which open tasks are past SLA, who owns them, and what communication attempts have been made?”
Chasing down owners and past outreach usually means pinging people and scrolling through comment history. Here, the agent pulls both in a single pass, so a manager can see who’s accountable and what’s already been tried before the escalation goes out.
Prompt: “Draft the monthly security review: posture trend, MTTR, SLA compliance, top risks, and what we remediated.”
A review that used to take hours of manual work becomes a first draft that the team can edit. The remediation side of the picture draws on Tamnoon’s reporting and compliance data to enrich the output.
Prompt: “Generate an investigation plan for any critical issues that touch assets that are public and contain PII or sensitive data.”
The hard part of triage is knowing which exposed asset actually holds sensitive data and whether the fix is safe. Tamnoon’s agentic investigation runs the analysis, rates each fix, creates a remediation plan, and executes it once it’s confirmed safe.
Prompt: “Check for new critical issues on the most valuable assets in my production environment and open a ticket and Slack ping if any appear.”
The agent checks Cortex, confirms the assets that matter with Tamnoon, and acts only when a critical issue lands on something you care about.
Cortex is the first integration, and more will follow. We’re also working toward letting an agent trigger a Tamnoon remediation directly, so the same workflow that finds and plans a fix can carry it through to done.
For now, Tamnoon MCP gives your Cortex agent the context to investigate, prioritize, and plan with confidence.
Cortex finds the risks in your cloud. Tamnoon gives your agent what it needs to act on them safely, from ownership and classification to a vetted, production-safe fix. Together, they take an issue from detected to resolved with less manual work in between.
Teams that run Tamnoon see MTTR reduction up to 72% without adding headcount. Book a demo to try Tamnoon MCP with your own Cortex environment, or see the Cortex integration to learn how the two work together.