Communications surveillance

Compiled inspects communications as they happen — surfacing conduct, data-handling, and market-abuse risk — and routes the elevated few to your team, inside your own tenant.

Teams ingestion flow — captured by Graph, decrypted and scored in your tenant, findings to your SOC.

How it works

  1. Capture. Messages are captured through each platform's native API — for Microsoft Teams, a Microsoft Graph change-notification subscription delivered to an endpoint in your tenant. (Microsoft removed metering from these APIs in 2025, so full-coverage capture carries no per-message charge.)
  2. Inspect in-tenant. Each message is decrypted and scored inside your tenant — never sent to Compiled.
  3. Triage. Only elevated messages become findings, sorted by risk, each with an explainable attribution your analysts and examiners can stand behind.
  4. Route. Findings (scored metadata, never raw content) flow to your SIEM / SOAR and the review queue.

What makes it different

Channels

Microsoft Teams, Slack, and email (M365 / Exchange journaling and Gmail) are live connectors, all real-time and in-tenant. The same in-tenant pipeline accepts any channel through the connector interface. To stand them up, see Microsoft Teams, Slack, and Email tenant setup (sign-in required).

Coverage and calibration

Detection quality depends on calibration to your traffic. Compiled calibrates thresholds against your own benign baseline before go-live, so "elevated" means elevated for your environment, not a generic benchmark.