Security operators and a workspace chat agent (for example Slack). People chat in Slack or Teams, not inside Muster. The agent calls Muster tools to answer fleet, case, and threat-intel questions under time pressure.
Muster is an ops brain for a security stack — not a chat product.
It reads from systems of record and answers operational questions through tools:
| Upstream role | Typical authority |
|---|---|
| Endpoint platform | Fleet health, host last-seen, detections |
| Case / IR platform | Open cases, aging, MTTR / SLA signals |
| Threat-intel API | Context packs for IPs, domains, hashes |
Reference open-source companions (optional, swappable):
Muster exposes:
- HTTP API for bots and automation
- Mastra tools + agent (mastra.ai) for tool-calling hosts
- Thin status UI (optional) — read-only briefing, not the operating surface
Tagline: Ask the stack. Chat stays in Slack.
- Not a replacement for Slack / Teams (no rooms or DMs as product)
- Not the case system of record
- Not an EDR or telemetry warehouse
- Not a TI collector or feed pipeline
- Not an autonomous response engine (no silent isolate/kill without upstream approval)
- Fleet — which hosts are healthy, stale, offline, noisy
- Compromise signal — host alerts + TI context on related observables
- TI lookup — context for an IP, domain, or hash
- IR queue — open cases, aging, unassigned, MTTR hints
- Briefing — one structured “what’s on fire” payload for digests and bots
- Chat UX lives in the workspace; Muster is tools and facts.
- Every answer should cite the upstream source.
- Prefer fail-closed, explicit configuration over silent mocks in production.
- Propose dangerous actions only; execution stays in the authoritative product.
- Small surface: API + Mastra tools first; UI last.
Credible, utilitarian, restrained. Direct and evidence-led. No AI sparkle theatre, no fake autonomy claims.