The State of Cloud Remediation 2026 report is live Read Here

July 29, 2026

Introducing Tamnoon MCP for Cortex Cloud

Maya Levine

Manager of Product Management, Tamnoon

Share:

Cortex Cloud tells your agent what’s wrong. With Tamnoon MCP, it now also learns what matters, who owns it, and how to fix it safely.

Security teams are moving past chat assistants and toward agents that act. These agents work across tools, pull context, and carry a task from alert to resolution. To do that well, an agent needs asset context, ownership data, and remediation safety signals before it can turn findings into safe fixes.

Today, we’re announcing Tamnoon MCP for Cortex. When Cortex’s agent hits an issue, it can now ask Tamnoon for the context that turns a finding into an action. Cortex Cloud drives the workflow, while Tamnoon supplies the remediation intelligence that powers it.

Tamnoon MCP exposes the cloud security context teams need to move from findings to action, with a direct Cortex Cloud connection and four workflows teams can run right away.

What the Tamnoon MCP Does

Tamnoon MCP exposes Tamnoon’s insights so an agent can read them and reason over them. Instead of querying a database or stitching together screenshots, the agent asks Tamnoon directly and receives structured context in return.

Here’s what it can pull:

  • Crown-jewel status: Whether an asset is business-critical.
  • Ownership: Who owns the asset and which team is responsible. Unclear ownership is the biggest reason remediation stalls, so Tamnoon goes beyond tags, using signals like recent deployers and team mapping to point to the person who can actually apply the fix.
  • Asset classification: Labels for PII, sensitive, and public exposure.
  • Environment mapping: What an asset connects to, so the agent can judge the blast radius.
  • Remediation Confidence Indicator (RCI): Tamnoon’s SAFE, RISKY, or AWAITING DATA rating for a given fix. It answers the question that stops most teams from acting: whether the change breaks something in production. A SAFE rating means Tamnoon has checked the blast radius and dependencies and confirmed the fix can be applied without disruption, so the agent can move on it after verification. 
  • Investigation plan: How Tamnoon determines whether an alert is a real risk or a false positive. Automations analyze the full context around a finding, so an asset flagged as publicly exposed can be cleared when a security group rule is actually blocking the traffic. Those same automations check whether applying a fix would affect production, so the plan reflects both real exposure and real impact.
  • Remediation plan: The vetted, step-by-step fix for an alert, when one exists. Tamnoon provides a detailed remediation playbook covering the exact changes to make and how to apply them safely within your environments.
  • Remediation history and MTTR: What’s been fixed, how fast, and what’s still open.

Each of these insights comes from Tamnoon’s agentic remediation model, where Tami runs the analysis and Remediation Experts, Tamnoon’s cloud security engineers, validate the work.

How Tamnoon’s MCP Works With Cortex Cloud

Cortex Cloud’s agent connects to Tamnoon MCP with an API key you generate in Tamnoon. Once connected, the agent can call Tamnoon at any point in a workflow, retrieve the required context, and act on it.

The workflow is simple:

  1. You send a prompt to Cortex Cloud’s AI agent for a specific request.
  2. The agent queries Tamnoon MCP for the necessary context.
  3. Tamnoon returns structured insight, such as ownership, classification, or an RCI rating.
  4. The agent uses that context to determine the next step.

Cortex Cloud is the first integration. Because Tamnoon MCP follows the Model Context Protocol, the same insights are available to any other agent you connect.

Examples of What You Can Do With the Tamnoon MCP

Once Cortex Cloud and Tamnoon MCP are connected, your agent can answer questions it couldn’t before. 

Here are four example workflows to start with, each with the prompt and what runs behind the scenes.

1. Find What’s Past SLA and Who Owns It

Prompt: “Which open tasks are past SLA, who owns them, and what communication attempts have been made?”

Behind the scenes:

  • Cortex Cloud identifies tasks that are past their SLA.
  • The agent queries Tamnoon MCP for ownership.
  • The agent queries Tamnoon MCP for the initiative’s comment log.
  • The agent reports who owns each task and what outreach has already happened.

Chasing down owners and past outreach usually means pinging people and scrolling through comment history. Here, the agent pulls both in a single pass, so a manager can see who’s accountable and what’s already been tried before the escalation goes out. 

2. Draft the Monthly Security Review

Prompt: “Draft the monthly security review: posture trend, MTTR, SLA compliance, top risks, and what we remediated.”

Behind the scenes:

  • Cortex Cloud provides current posture and issue data.
  • The agent queries Tamnoon MCP for MTTR and remediation history.
  • The agent assembles the report.

A review that used to take hours of manual work becomes a first draft that the team can edit. The remediation side of the picture draws on Tamnoon’s reporting and compliance data to enrich the output.

3. Build an Investigation Plan for Exposed, Sensitive Assets

Prompt: “Generate an investigation plan for any critical alert that touches assets that are public and contain PII or sensitive data.”

Behind the scenes:

  • Cortex Cloud provides the critical alerts.
  • The agent queries Tamnoon MCP for asset classification and retrieves assets labeled as PII or sensitive.
  • Tamnoon groups these alerts into an initiative and runs an investigation, using automations to assign a Remediation Confidence Indicator (RCI) rating to each alert.
  • Tamnoon generates a remediation plan for any alert rated SAFE, meaning the fix has no impact on the production environment.

The hard part of triage is knowing which exposed asset actually holds sensitive data and whether the fix is safe. Tamnoon’s agentic investigation runs the analysis, rates each fix, creates a remediation plan, and executes it once it’s confirmed safe. 

4. Check Crown Jewels Every Morning

Prompt: “Every morning, check for new critical alerts on the most valuable assets in my production environment and open a ticket and Slack ping if any appear.”

Behind the scenes:

  • Cortex Cloud surfaces the new critical alerts.
  • The agent queries Tamnoon MCP for crown-jewel data.
  • The agent correlates the alerts against Tamnoon’s environment mapping to confirm which assets matter.
  • The agent opens a ticket and sends a Slack ping based on your company’s preferences.

This one runs on a schedule with no one watching. The agent checks Cortex Cloud, confirms the assets that matter with Tamnoon, and acts only when a critical alert lands on something you care about.

What’s Next for the Tamnoon MCP

Cortex Cloud is the first integration, and more will follow. We’re also working toward letting an agent trigger a Tamnoon remediation directly, so the same workflow that finds and plans a fix can carry it through to done. 

For now, Tamnoon MCP gives your Cortex Cloud agent the context to investigate, prioritize, and plan with confidence.

Connect the Tamnoon MCP to Cortex Cloud

Cortex Cloud finds the risks in your cloud. Tamnoon gives your agent what it needs to act on them safely, from ownership and classification to a vetted, production-safe fix. Together, they take an alert from detected to resolved with less manual work in between.

Teams that run Tamnoon see MTTR reduction up to 72% without adding headcount. Book a demo to try Tamnoon MCP with your own Cortex Cloud environment, or see the Cortex Cloud integration to learn how the two work together.

Discover the Latest From Tamnoon

There’s always more to learn, see our resources center

Scroll to Top

CNAPP Decoded: Alerts, Remediations, and CNAPP Best Practices 1x a Month

Join 10,000+ Cloud Security leaders looking to master their CNAPP with expert remediation tips and best practices to test in your own CNAPP today.