Commvault has integrated its cyber recovery actions directly into CrowdStrike’s Charlotte Agentic SOAR workflows, giving joint customers a way to automate incident response without switching between separate security and recovery tools.
Commvault (NASDAQ: CVLT) announced the integration on 1 September 2026, making its cyber recovery actions available as native steps within CrowdStrike‘s Charlotte Agentic SOAR platform. The connector lets security teams restrict access during an active incident, automatically suspend Commvault’s backup data ageing policies to preserve clean recovery points, and restore potentially compromised assets into Commvault Cleanroom for forensic investigation, all from within a single automated workflow.
Closing the gap between security and recovery
The integration is aimed at a familiar pain point in enterprise security operations: fragmented tooling that slows teams down during an active breach. By bringing cyber recovery actions into the same orchestration layer as threat detection and response, Commvault and CrowdStrike say the connector reduces manual handoffs between security and recovery teams.
“Security and recovery teams need to move quickly and in coordination during an incident,” said Vidya Shankaran, Field CTO, Commvault. “Our integration with CrowdStrike Charlotte Agentic SOAR makes Commvault cyber recovery actions available directly within security workflows, helping joint customers reduce manual handoffs and accelerate investigation and response.”
Part of a broader CrowdStrike partnership
The Charlotte Agentic SOAR connector extends a series of prior integrations between the two companies, following earlier work bringing CrowdStrike Falcon Insight XDR threat intelligence into Commvault Cloud and extending visibility through Falcon Next-Gen SIEM.
The integration is generally available now for joint Commvault and CrowdStrike customers, and is also listed on the CrowdStrike Marketplace.



Share your thoughts