Meeting prep · Alvarez & Marsal · 7 Aug 2026

“Harmonic tooling on an Azure-centric estate”
— what that actually means

A&M kept a Microsoft/Azure backbone for identity, endpoints and security, but chose a non-Microsoft AI layer — Anthropic's Claude, Claude Code and Claude Cowork — instead of defaulting to Copilot. That best-of-breed choice opens a control gap that Microsoft's native tooling doesn't fully cover. Harmonic is the seam that closes it. Understanding that seam is the highest-value thing you can walk into this meeting with.

<200ms
Harmonic's inline policy decision time, using on-device small language models that classify intent, not keywords
1,000+
AI surfaces Harmonic covers — browser, embedded SaaS AI, desktop apps, and MCP agent traffic
~20%
Share of A&M's European revenue already attributed to AI — Europe leads the firm
50%
Share of A&M's services projected to be AI within three years, per COO Steve Wallace

The architecture, layer by layer

Click any component for detail. Solid dots are confirmed in A&M's own job specifications; hollow dots are standard-for-Azure inferences you should treat as hypotheses to test in the room, not facts to assert.

View
Confirmed in A&M job specs Inferred — standard for an Azure estate Flow reads top → bottom: person → AI → controls → data

Why A&M built it this shape

Azure governs the enterprise

A&M's AI Security Engineer specification asks for “proficiency in cloud security across Microsoft Azure, including cloud-native security controls, CSPM tooling, and secure API gateway configuration,” plus enterprise IAM with “zero-trust architectures, role-based access control (RBAC), and privileged access management (PAM).” The certifications it names — AZ-500 and SC-100 — are both Microsoft. This is an Azure-first shop: identity in Entra, devices under Intune, posture managed with CSPM, telemetry into a SIEM. That's the “Azure-centric estate.”

Anthropic supplies the intelligence

The same document names the AI applications to be secured: “Claude, Claude Code, Claude Cowork.” Not Copilot. For a Microsoft-shop this is a deliberate, best-of-breed decision, and it fits A&M's operator culture — pick the tool that does the job rather than the one that comes bundled. It also means the AI layer sits outside the Microsoft trust boundary, reached over the public internet through a third-party API.

Harmonic is the seam between them

Microsoft's native data-protection stack is deepest where Microsoft owns both ends — M365 content and Copilot. When the AI layer is a third-party desktop app, a CLI running in a developer's terminal, and an agent making tool calls to MCP servers, the Microsoft control plane sees the device and the network egress, but not the prompt, not the tool call, and not the agent's intent. Harmonic Security — an AI governance and control platform whose CEO Alastair Paterson co-founded Digital Shadows — closes exactly that gap by sitting on the device rather than on the network: a browser extension, a desktop hook for Claude Desktop and Cursor, and a local MCP gateway. It deploys through the same MDM A&M already runs (Intune), which is why it slots into an Azure estate without friction.

Why this is your opening

A&M's commercial model is selling to clients what it has proven on itself. It is, right now, building the reference implementation of governed enterprise agentic AI — and staffing it: A&M's current search results date the Harmonic/Claude security role to 27 July 2026. If you can speak fluently about this seam, you are not pitching generic capability. You are describing the thing they are currently building and will need to sell.

Hard truth — the gap they haven't closed

Harmonic's own practitioner guide to Claude Cowork states that Cowork activity is excluded from Anthropic's Audit Logs, Compliance API and Data Exports, and advises against using Cowork for any workflow requiring a regulatory audit trail until that closes. OpenTelemetry gives partial visibility but needs custom plumbing into a SIEM. For a firm doing restructuring, disputes and regulated-client work, that is a live constraint on how far agentic deployment can go.

Raise it — carefully, as an architecture question you have already thought about, never as a criticism of their choices. “How are you handling the Cowork audit-trail gap for regulated engagements — OTel into Sentinel, or scoping Cowork away from those workflows?” is the single highest-signal sentence available to you in that room. It proves you have operated this stack, not just read about it.

Questions this architecture earns you

  1. Is Harmonic internal-only, or part of the client offer? If A&M is deploying it on client engagements too, the pre-sales role is substantially about selling governed agentic AI — and the reference story is A&M itself.
  2. Where does the MCP server allowlist live, and who owns it? Central managed-mcp.json pushed via MDM is the mature answer. The answer tells you how far along they actually are versus how far along the press release sounds.
  3. Azure for infrastructure but Anthropic for AI — was that a deliberate best-of-breed call, and does it hold for client-facing solutions? This asks about architectural conviction and vendor strategy in one move, which is what an architect is paid to have.
  4. How much of the estate is Claude Code and Cowork versus chat? Chat is productivity. Code and Cowork are agentic — file access, browser automation, unattended scheduled tasks. The ratio tells you whether “agentic” in your job title is real or aspirational.
  5. What does the value case look like on an agentic engagement? A&M measures in EBITDA, working capital and diligence cycle time. If they can already quantify it, they have production deployments. If they can't, that gap is your opening contribution.