Commvault has announced a new integration with CrowdStrike that makes Commvault cyber recovery actions available as native steps within Charlotte Agentic SOAR workflows.
The integration enables joint customers to automate Commvault recovery actions as part of security workflows, helping accelerate response and forensic investigations while reducing manual coordination between security and recovery teams.
Automating recovery at machine speed
AI-driven automation is helping organisations detect, investigate, and respond to threats at machine speed, yet fragmented tools and workflows can slow security teams at critical moments.
The new purpose-built connector enables security teams to incorporate Commvault cyber recovery actions directly into workflows orchestrated by Charlotte Agentic SOAR, rapidly accelerating investigation, response, and recovery.
Key capabilities include the ability to restrict access in Commvault to help prevent unauthorised changes during an active incident, and to preserve clean recovery options by automatically suspending Commvault backup data aging policies to retain viable recovery points during active incidents.
The integration also accelerates forensic investigations by restoring potentially compromised assets into Commvault Cleanroom, enabling investigators to begin analysis without disrupting production systems.
“Security and recovery teams need to move quickly and in coordination during an incident,” said Vidya Shankaran, field CTO at Commvault. “Our integration with CrowdStrike Charlotte Agentic SOAR makes Commvault cyber recovery actions available directly within security workflows, helping joint customers reduce manual handoffs and accelerate investigation and response. This strengthens cyber resilience and simplifies how security and recovery teams work together seamlessly.”
Deepening CrowdStrike partnership
The announcement is the latest in a series of integrations between Commvault and CrowdStrike. Falcon Insight XDR brought CrowdStrike threat intelligence into Commvault Cloud, while Falcon Next-Gen SIEM extended visibility.
The new Charlotte Agentic SOAR integration enables Commvault cyber recovery actions to be incorporated directly into automated security workflows, closing the loop between detection, investigation, and recovery.
For chief information security officers, the integration addresses a persistent operational gap: the manual handoffs and tool fragmentation that can delay containment and recovery during a cyber incident.
By embedding recovery actions into SOAR playbooks, security teams can execute coordinated response at the pace of modern threats, while maintaining forensic integrity and preserving clean recovery points.
The integration is available now to joint customers of Commvault and CrowdStrike.









