Skip to main content
Falcon Cortex Intelligence documentation

Build understanding. Operate with confidence.

Architecture, implementation guidance, operating procedures, and developer references for teams deploying governed workforce and process intelligence.

This public overview describes the current engineering build. API, desktop, and tenant runbooks are private or UAT materials shared during an approved engagement; there is no public API endpoint, self-service signup, or trial.

Guides

Choose your path

6 topics
Get started

Enterprise onboarding

Customer-specific steps for approving domains, establishing tenant ownership, configuring identity, and preparing a governed pilot.

  1. 1Approve and verify company domains
  2. 2Configure SAML/OIDC, SCIM, and MFA
  3. 3Invite the pilot cohort
  4. 4Validate roles and tenant isolation
Desktop

Employee desktop client

Private-release guidance for an approved tenant: authenticate, consent, select work context, capture safely, and receive governed updates.

  1. 1Install from the private release channel
  2. 2Complete login and legal consent
  3. 3Choose office or home context
  4. 4Review capture transparency and exclusions
Intelligence

Process intelligence

Current-build guidance for evaluating event quality, variants, conformance, bottlenecks, drift, and automation opportunities.

  1. 1Validate event quality
  2. 2Discover process variants
  3. 3Compare expected and observed flow
  4. 4Govern improvement recommendations
AI

AI and BYOK governance

UAT guidance for configuring providers, allowed models, fallback, regional policy, budgets, evidence, and kill switches.

  1. 1Choose platform AI or tenant BYOK
  2. 2Allowlist models and regions
  3. 3Set quotas and budget controls
  4. 4Review grounded evidence and human approvals
Developers

Private API, SDK, CLI, and MCP

Private/UAT developer materials for one governed authorization boundary across REST, typed SDKs, the JSON-first CLI, and MCP tools. No public API endpoint is available.

  1. 1Request an approved developer engagement
  2. 2Use the versioned contract in private/UAT
  3. 3Automate with TypeScript, Python, or CLI
  4. 4Use proposal-first MCP mutations
Trust

Security, privacy, and assurance

Review the current-build security and privacy model, capture policy, evidence boundaries, retention choices, incident response, and customer responsibilities.

  1. 1Review the shared-responsibility model
  2. 2Complete DPIA and capture policy
  3. 3Test isolation and recovery
  4. 4Collect control evidence

Reference architecture

One governed signal path

The current architecture candidate limits desktop capture to policy-authorised signals. Tenant isolation, role-appropriate insight, AI, and developer interfaces are evaluated against one governed authorization boundary during private/UAT work.

Employee client

Consent, task context, application policy, encrypted local durability.

Cortex data plane

Canonical ingestion, tenant controls, retention choices, lineage, evidence, and analytics.

Enterprise experiences

Approved-tenant dashboards, FCI insight, private developer tools, and auditable controls.

Developer platform

API-first, governed everywhere

The versioned contract and developer tools are private/UAT materials. During an approved engagement, they are evaluated with explicit tenant context, scoped credentials, bounded responses, idempotency, and proposal-first changes. No public API endpoint is offered.

  • OpenAPI v1 contract (private/UAT)
  • TypeScript and Python SDKs (private/UAT)
  • JSON-first Cortex CLI (private/UAT)
  • Streamable HTTP MCP gateway (private/UAT)
Private/UAT contract sketchillustrative · not a public endpoint
curl --request GET \
  --url https://<private-uat-api-origin>/v1/processes \
  --header "Authorization: Bearer $CORTEX_TOKEN" \
  --header "X-Cortex-Tenant: <tenant-id>"

Need deployment-specific documentation?

Customer runbooks, integration mappings, security evidence, and rollout plans are prepared for an approved tenant engagement and are not public self-service documentation.

Contact sales