Watch the Familiar triage a phish.
One reported phishing email, end to end. You ask in plain English, the Familiar plans before it acts, you approve the one step that needs a human at the Seal, and the receipt shows everything. This is the product on demo data, not a video.
A user reports a phishing email.
It reads like an unpaid-invoice notice with an attachment, from a sender the user did not recognize. Three people got it; one clicked away from handing over credentials. In most inboxes this now waits for an analyst to have a free minute.
Here it becomes a case the moment it lands. Every report gets the same full triage, including the ones that turn out to be nothing.
- Pull the reported message and its attachment from mail.
- Detonate the attachment in a sandbox.
- Check the reply-to domain for typosquatting and enrich every indicator across intel.
- If it is a real threat, propose containment and stop at the Seal.
Assumptions: the report is good faith, containment is reversible, and nothing consequential runs without your approval.
You ask in plain English. It plans before it acts.
No playbook to author, no rules to wire. You tell the Familiar the outcome you want, the way you would tell a teammate: triage this reported phish and contain it if it is real.
It answers with a plan, not an action: the steps it will take, the Tools it will use, and the assumptions it is making. You approve it, edit any step, or reject it. This plan is the Spell it will cast across your stack.
It works the plan and cites every step.
This is the part legacy automation never did: the actual thinking. The Familiar detonates the attachment in a sandbox, checks the reply-to domain for typosquatting, and enriches every indicator across intel. Evidence accumulates, and each claim is pinned to the Tool result behind it.
Open the show reasoning toggle on the domain check: nothing here asks for your trust, it shows you the work instead.
Confirmed phish, three mailboxes affected
confidence: high- ✓Reply-to domain is a look-alike of a known brand, registered 4 days ago.
- ✓The attachment opens a credential-harvest page when detonated in the sandbox.
- ✓All four extracted indicators match a public blocklist.
- ✓No recipient entered credentials. No sessions from unfamiliar networks.
A verdict you can read, with the evidence attached.
The output is a verdict in plain language: what it found, the evidence for it, how confident it is, and what it proposes to do. Confirmed phish, high confidence, containment recommended.
Notice what it does not do. Quarantining mailboxes and blocking a domain touch real users, so those actions wait. The verdict recommends; the Seal decides. And had the evidence come back benign, there would be nothing to approve at all.
Confirmed phish, high confidence. Quarantine removes the message from all three inboxes before anyone clicks, and the reply-to domain is blocked at the mail gateway. Both are reversible: one action restores them if the verdict changes.
One step needed a human. It is yours.
Two minutes of work happened without you. This is the moment that should not: an action that touches three mailboxes and blocks a domain stops at the Seal, with the evidence and the blast radius in front of you.
You set where the Seal sits, per outcome. Teams start with everything sealed, watch the Familiar be right, and grant more autonomy at their own pace. Go ahead, approve it.
Every step. Every source. Every decision. One receipt.
The whole case, from the report landing to the mailboxes cleaned, is one replayable record: what the Familiar planned, what it ran, what each Tool returned, and which human approved the action that mattered.
Hand it to an auditor. Replay it after a review. Or read it with your coffee, because the case closed in ninety-eight seconds and no one on your team touched a console.
Yours arrive by the thousand.
Bring one and watch the Familiar work it.
A 30-minute walkthrough on your real triage flow, with the same receipts at the end. Technical, not a pitch.