News

Omer Saraf
|
|
Reading Time:
3
min

Introducing the Ocean MCP: Email Security Inside Your Agent
Ask questions about your email threats, reported phishing, and security posture in plain language, from the AI tools your team already uses. Available now in early access.
Your analysts spend their day in an agent. Ocean now works there too.
Today we are opening the Ocean MCP to customers in early access. Connect it once, and the threats Ocean caught, the emails your users reported, the decisions the platform made on your behalf, and the metrics your leadership asks for are all reachable from Claude, ChatGPT, Cursor, or any other MCP-compatible tool. No exports, no scripts, no waiting on an integration.
What an MCP actually changes
An API is what turns a product from a destination into a building block. It lets a platform meet the tools a customer already runs and lets teams build the workflows they actually want instead of the ones someone else designed. Ocean has been API-native from day one.
But an API asks for setup time. Someone has to read the reference, learn the endpoints, and write the code. That is worth it for a workflow you will run a thousand times. It is rarely worth it for the question you have once, right now, in the middle of an investigation.
The Model Context Protocol closes that gap. MCP lets an agent operate a deterministic API on your behalf: it picks the right calls, handles the parameters, and joins the results, so you can ask in plain language and get an answer grounded in your own data rather than a generic one. Every major AI tool now speaks it, which means connecting Ocean once makes it available everywhere your team works.
What your team can do with it
Your agent works with the same email security data your team investigates in the Portal: the threats Ocean caught and the remediation it performed on each one, the emails your users reported, the decisions the platform made, and your threat metrics over time.
In practice, that looks like asking things such as:
What did users report this week, and what still needs a person?
Have we seen this sender before?
Which domains reached us for the first time this month?
Summarize our email threats this quarter for a leadership update?
The more interesting part is what happens when Ocean is not the only thing your agent can reach. Because the same conversation can also touch your SIEM, your ticketing system, or your directory, a question can cross tools in a single turn without anyone building an integration for that specific pair.
And once an agent can ask these questions, it can ask them on a schedule. A question someone asks by hand today can become a check that runs on its own tomorrow, in whatever format or frequency your team needs rather than the what's provided by the constraints of a dashboard.
Designed around questions, not endpoints
Wrapping a set of endpoints in an MCP is straightforward. Whether it answers a real question well is a different problem. A developer building an integration gets to iterate over days; an agent gets one pass, picking a tool from the description in front of it while an analyst waits.
So we designed it around questions rather than small pieces of data. An endpoint hands back its piece and leaves the assembly to whoever called it. We wanted each tool to answer something an analyst would actually ask, treating the agent as an analyst rather than as a client of our API. That's the same instinct behind Ray, which reaches its verdicts by investigating intent and context rather than scoring an email against a pattern or baseline.
Where to find it
The Ocean MCP is available in the directories your team already installs from.