Integrations
- 100 %
- inside your org
- 0
- outbound data by default
- 71/255
- controls self-assessed
- 10 min
- to install
The French text governs. This page is the English version of Intégrations FR.
6 capabilities, and one rule governing them all: what goes out is read-only, and what comes in writes only into the product's own objects. No integration gives a third party a write path into your org.
- 6
- capabilities in this family
- 1
- active on installation day, on the Discovery offer
- Discovery
- entry tier of the family
What this family measures
The REST API is open from the Discovery offer: it returns status and findings. Its detailed sub-path — the target and the message of a finding — is closed by default, because the target may carry a user identifier and the message prose naming it. It is the one gate whose default deliberately changes the shape of the response: the detail is not deleted, it is opted into. And even when open, the query still runs with the caller's own rights.
SIEM export (Splunk, Microsoft Sentinel) and ITSM integration (ServiceNow, Jira) sit at the Mid-market tier and go to your destination, with your credentials. Agentforce actions expose the posture to your agents read-only: query, never change. Finally, the only write the product accepts is a PATCH on one of its own incidents, so a ticketing tool can close the loop.
The 6 capabilities, one by one
| Capability | Minimum offer | At install |
|---|---|---|
REST APIREST_API · read-only; the caller sees only what its own permissions already allow | Discovery | Open |
Finding detail in the REST APIREST_Findings_Detail · closed by default: the response carries neither target nor message | Discovery | Closed |
REST incident write (PATCH)Incident_Rest_Write · the only write the product accepts is on ITS OWN incidents, never on your org | Small business | Closed |
SIEM exportSiem_Export · outbound flow to a destination you choose, with your credentials | Mid-market | Closed |
ITSM integrationItsm_Integration · outbound flow to a destination you choose, with your credentials | Mid-market | Closed |
Agentforce actionsAgentforce_Actions · READ actions exposed to your agents: query the posture, never change it | Small business | Closed |
Source: read from the package code at the moment this page is built — FeatureGate.FEATURE_TIER for the offer, FeatureGate.CODE_DEFAULTS for the state at install. The label is the one exception: the in-org feature editor is French only, so the English wording in this column was written for this site. Its French counterpart, on /produit/, is the exact string your administrator reads, and the site build fails if the two lists move apart. “Closed” does not mean absent: the capability is shipped, it is waiting for a human to open it inside the org — and a capability whose implementation nothing in the package can reach appears on none of these pages: the build drops it instead of selling it.
What this family does not do
- No integration writes into your org. The only PATCH accepted is on a finding's incident inside the product.
- No inbound webhook commands a scan or changes a setting: configuration is decided inside the org, by a human.
- The credentials are yours. We store no token towards your systems; every flow goes through a named credential that you install.
- Nothing leaves by default. The three outbound integrations are closed at delivery.
The other families
Is this family in your offer? The grid says so line by line.
See the pricing grid Back to the seven families