InvestigationAI Architecture
A Microsoft-native agentic investigation stack — from stakeholder question to governed evidence, in one continuous trust boundary.
01
User Layer
Stakeholders
- CISO
- Corporate Security
- Legal
- Privacy Office
- HR
- Compliance Teams
02
Agent Layer
Built with
- Copilot Studio
- Azure AI Foundry
- Multi-Agent Orchestration
Agents
- Evidence Collection Agent
- Timeline Agent
- Communication Intelligence Agent
- Data Impact Agent
- Regulatory Compliance Agent
- Root Cause Agent
- Response Recommendation Agent
- Reporting Agent
03
Investigation Data Sources
Microsoft 365
- Outlook
- Teams
- SharePoint
- OneDrive
- Microsoft 365 Copilot
Security Sources
- Defender
- Sentinel
- Purview
Business Sources
- Dynamics 365
- ServiceNow
- Fabric
04
Security & Governance Layer
Microsoft Purview
- DLP
- Information Protection
- Insider Risk
Microsoft Defender
- Endpoint
- Identity
- Cloud Apps
Microsoft Sentinel
- Event Correlation
- Security Analytics
Security Copilot
- Investigation Acceleration
- Incident Summarization
05
Data Layer
Microsoft Fabric
- OneLake
- Dataverse
- Enterprise Systems