Commvault has made cyber-recovery actions available as native steps in CrowdStrike Charlotte Agentic SOAR workflows, an integration intended to connect backup and recovery tasks more directly to security-operations automation during an incident.
The companies said the connector lets joint customers call Commvault recovery actions from workflows orchestrated by Charlotte Agentic SOAR. Rather than requiring analysts to switch among incident-response and recovery tools, the integration is designed to make certain recovery controls available within the flow handling detection, investigation and response.
The announcement targets a familiar problem in ransomware and other serious incidents. Teams responsible for detection and containment often need data-protection or recovery teams to take time-sensitive actions. That coordination can involve separate consoles, approvals and handoffs while the organization is trying to preserve evidence and limit further change.
Commvault said the integration can restrict access within its environment to help prevent unauthorized changes during an active incident. It can also automatically suspend backup-data aging policies, retaining recovery points that might otherwise be removed under normal retention rules. Those are recovery-administration actions, but placing them in a SOAR workflow could allow them to be initiated alongside other security steps when predefined conditions are met.
The connector also supports restoring potentially compromised assets into Commvault Cleanroom for analysis, according to the release. That approach is intended to give investigators an environment in which to inspect affected systems or data without disrupting production workloads. The company said the workflow connection can accelerate forensic investigation and recovery, though it did not disclose measurements for investigation time, recovery time or workflow accuracy.
Charlotte Agentic SOAR is CrowdStrike’s workflow-orchestration capability for security operations. In practice, an organization would still need to decide which incident signals should trigger a recovery action, who may authorize it, and how that step should interact with existing change-control and disaster-recovery procedures.
That governance question matters because restricting access, retaining backup sets and restoring assets can carry operational consequences. Automating their availability in a workflow does not eliminate the need to define safeguards. Security and recovery teams will need to establish when a workflow can act automatically, when it must request human approval, and how to handle a false positive or an incident affecting shared infrastructure.
Commvault said earlier integrations brought CrowdStrike threat intelligence into Commvault Cloud and extended visibility through Falcon Next-Gen SIEM. This release focuses more specifically on moving recovery actions into automated security workflows. For enterprise security teams, the relevant change is not a replacement for a recovery plan, but a tighter connection between incident response and the actions needed to preserve and investigate recoverable data.
Operationally, the connector will be most useful where security and recovery teams have already documented responsibilities and recovery priorities. It does not establish those decisions on its own. Organizations will still need to test the workflow against their backup architecture, account for legal-hold and retention obligations, and ensure that alerts contain enough context for a recovery action to be appropriate. Those preparatory steps determine whether a faster handoff actually reduces risk during a high-pressure event.

