What we built: August 2026

By Scout Scholes

Published: September 1, 2026  •  2 minute read



Placeholder image for What we built: August 2026

TL;DR 

  • This is a monthly recap of everything our product team shipped in the last 30 days
  • Questions? Reach out to your Expel contact, or if you don’t have one, connect with us here
  • This month we launched MDR for AI, opened early access for our Anthropic Claude integration, mapped our detection library to MITRE ATLAS inside Workbench, and added CSV exports to Service Review reporting

 

Live this month

MDR for AI

What it is: Expel Managed Detection and Response (MDR) now covers the full AI attack surface—the threats attackers launch with AI, the risk your employees create when they misuse AI tools, and the exposure inside the AI systems your team is building and running. We announced it at Black Hat on August 4, and you can find the full story on our blog

Why it matters: AI security has an ownership problem. Everyone agrees it’s a risk, but ask five people at the same company where that risk lives and you’ll get five different answers. Most teams aren’t stuck because they don’t care—they’re stuck because building a new program from scratch takes expertise, budget, and headcount they don’t have. Extending the MDR you already run is faster. Same operators, same platform, same accountability, pointed at an attack surface that didn’t exist a few years ago.

 

Anthropic Claude integration (early access)

What it is: Our first AI-native coverage area. We pull Claude Enterprise Compliance signals—usage activity and prompt content—directly into our detection pipeline, with detections across both the control plane and the content plane. Early access is open now for Claude.ai. If you’re interested, ask your customer success manager to submit a request.

Why it matters: Most coverage stops at activity logs, which tell you what happened but not why. Our operators work the prompt content itself, so we surface intent instead of just activity. Claude is the first of several AI-native coverage areas we’re rolling out through the rest of 2026 and beyond.

 

AI detection coverage mapped to MITRE ATLAS

What it covers: Our detection library is now labeled everywhere AI is a factor and mapped to MITRE ATLAS, the adversarial threat framework built for AI systems. You can see it live in the Detections tab in Expel Workbench™. 

Why it matters: Last month’s six AI threat hunts cited ATLAS techniques in their write-ups, but you had to take our word for the coverage behind them. Now you can check it yourself—existing detections and the new Claude detections, side by side, against the tactics attackers actually use against AI systems.

 

Reporting updates

CSV exports from the Service Review dashboard

What it covers: Four new standardized exports, available to both customers and Expel users:

  1. Mean time to… metrics—mean time to triage, mean time to investigate, and the rest of the MTTX set.
  2. Top detections, ranked by volume.
  3. Close reason breakdown.
  4. All alerts, investigations, and incidents.

Pull any of them for the past 7, 30, 90, or 180 days. Custom date ranges aren’t supported yet, but they’re on the roadmap. Calculations and methodologies are outlined in the Docs Center. 

Why it matters: MTTX data was available within the Service Review dashboard but was not available for export. This meant users had to query the Workbench API or get Customer Success help to get specific metrics. Now, MTTX and additional information are available as simple downloads, allowing you to build your own reporting on top of Expel’s data.

 

One more thing

New home for Expel product documentation

Our documentation moved to docs.expel.io. Setup and detection strategy guides, Workbench reference information, and release notes all live there now.  The new site also includes improved navigation and readability, enhanced search functionality, and an AI assistant to help you find answers fast.

Old support.expel.io links redirect, so if you’ve bookmarked anything, it still works.

Nothing changes for support. Keep submitting tickets at support.expel.io (or through the other options here). Just look for documentation at docs.expel.io going forward.