Communications surveillance
Compiled inspects communications as they happen — surfacing conduct, data-handling, and market-abuse risk — and routes the elevated few to your team, inside your own tenant.
How it works
- Capture. Messages are captured through each platform's native API — for Microsoft Teams, a Microsoft Graph change-notification subscription delivered to an endpoint in your tenant. (Microsoft removed metering from these APIs in 2025, so full-coverage capture carries no per-message charge.)
- Inspect in-tenant. Each message is decrypted and scored inside your tenant — never sent to Compiled.
- Triage. Only elevated messages become findings, sorted by risk, each with an explainable attribution your analysts and examiners can stand behind.
- Route. Findings (scored metadata, never raw content) flow to your SIEM / SOAR and the review queue.
What makes it different
- Behavioral, not keyword. It scores the behavior in a message, not a word list — so coded and paraphrased risk is still surfaced.
- In-tenant, zero egress. The surveillance tool your data-residency and privacy teams will actually approve.
- A triage layer, not an autonomous gatekeeper. Compiled raises the signal; your team confirms or dismisses, and that feedback tunes the system.
Channels
Microsoft Teams, Slack, and email (M365 / Exchange journaling and Gmail) are live connectors, all real-time and in-tenant. The same in-tenant pipeline accepts any channel through the connector interface. To stand them up, see Microsoft Teams, Slack, and Email tenant setup (sign-in required).
Coverage and calibration
Detection quality depends on calibration to your traffic. Compiled calibrates thresholds against your own benign baseline before go-live, so "elevated" means elevated for your environment, not a generic benchmark.