Insider risk investigations in Microsoft 365 usually start with exporting email, Teams messages and files into an archive. Proofpoint says its Prism Investigator will soon skip that step by connecting directly to Microsoft 365.
Separately, Proofpoint Human Communications Intelligence (HCI) agents now bring interactions with copilots, generative AI tools and AI agents into insider risk investigations.
The capabilities are aimed at security, compliance and legal teams investigating potential insider risk.
Prism Investigator previously analysed content held in Proofpoint Archive. With the new connector, it determines what an investigation needs and retrieves relevant Microsoft 365 content as the matter develops.
Proofpoint says this reduces the manual export and staging that can slow analysis. The tool can correlate Microsoft 365 communications with archived content, logs and other business records to produce a defensible case narrative.
The second change extends HCI agents to feed AI communications governance signals into Proofpoint Insider Threat Management.
Proofpoint argues that prompts, responses and interactions with AI systems are becoming part of the communications trail. Organisations need to capture those interactions, preserve them as business records and monitor them for regulatory and compliance risk.
Capturing what someone enters into an AI tool can identify potential data exposure. Adding their wider communications and behaviour can indicate whether the activity is routine use, a policy violation or potentially malicious.
"While an alert can indicate what happened, it's communications intelligence that can explain the why," said Harry Labana, SVP and general manager, Digital Communications Governance, Proofpoint.
"Like a cockpit voice recorder, it gives investigators more than a simple audio file, providing extensive details to piece together the events and intent behind them."
Insiders and AI in the spotlight
The announcement follows Proofpoint's 2026 Voice of the CISO report, released the same week. It found 79% of CISOs globally now rank human risk as their organisation's biggest cyber vulnerability.
Among organisations that suffered material data loss, malicious or criminal insiders were the leading cause (46%). Misuse or misconfiguration of AI tools was cited by 37%, and 93% said departing employees played a role.
In Australia, compromised insiders were the most common cause of material data loss, cited by 50% of CISOs whose organisations lost data.
HCI agents are available now as an add-on to Proofpoint Capture powered by Nuclei. Prism Investigator connectivity to Microsoft 365 is expected in Q4 2026.