Orchestrated security investigation and remediation with Amazon Quick Suite
Tines and AWS show how Amazon Quick Suite can connect through MCP to a Tines server to analyze and remediate security events across multiple IT and security systems. The workflow uses agentic AI to query tools such as VirusTotal, Okta, BambooHR, CloudTrail, and CrowdStrike, then visualize timelines, maps, and remediation status. The pattern centralizes governed integrations and enables analysts to ask natural-language questions without custom scripts.
- Organization
- Tines
- Industry
- Tech & Comms
- Location
- United States
- Published
- March 2026
Why do we believe this deployment?Customer identity, provider attribution, maturity, and source checks
- Customer
- Tines
- Provider
- AWS
- Maturity
- Production
- Linked source
- AWS Machine Learning Blog
It reduces the need for custom integration code and provides centralized governance, standardized data retrieval, and improved operational visibility
Primary read
Use case focus
Showing 2 of 2
- 1Workflow automation
- 2AI agents
- Build an MCP-based integration where Amazon Quick Suite connects to a Tines MCP server.
- Use Tines tools to retrieve, normalize, enrich, and expose data from external security and IT APIs so Quick Suite can query them through natural language.
- Support analysis dashboards and analyst-approved remediation actions from within Quick Suite.
- The post says this approach leads to faster decision-making and less manual effort.
- It reduces the need for custom integration code and provides centralized governance, standardized data retrieval, and improved operational visibility.
Architecture
Quick Suite connects to a Tines MCP server, which exposes security and IT APIs through MCP tools. Analysts can query the integrated data in Quick Suite chat and dashboards, while Tines can perform retrieval, normalization, enrichment, and analyst-approved remediation actions across systems such as VirusTotal, Okta, BambooHR, CloudTrail, and CrowdStrike.
Sources & evidence1
- Customer explicitly identified
- Deployment status explicitly supported
- Technical implementation details available
AI-generated summary. Verify important details with the linked sources before relying on this case.
Explore related AI use cases
Was this useful?
Community
Comments
No published comments yet.
Comments could not be loaded.