> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neoagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Datto BCDR API

> Read Datto SIRIS, ALTO and NAS appliances, their last backups and Datto's screenshot verification, so an agent can check a Datto alert and close the ticket once the backup recovers; read and change SaaS Protection seats

The Datto BCDR API tool gives Neo agents access to the Datto Partner Portal API: SIRIS, ALTO and NAS appliances, Endpoint Backup for PCs and Direct-to-Cloud agents, and SaaS Protection. The common use is a Datto alert ticket: the agent finds the appliance, checks whether the alert is still active, reads the last backups of the protected machine, and closes the ticket or explains why it is still failing.

<Info>
  Automatically enabled when you configure Datto BCDR permissions in your agent workflow.
</Info>

## What It Does

* Find the appliance from the serial number in the ticket title or the ticket's configuration item
* Read an appliance's last check-in, storage and active alerts
* Read a protected machine's last backups, local verification and Datto's screenshot verification result
* Read Endpoint Backup for PCs and Direct-to-Cloud agents and their last backups
* Read the Partner Portal activity log
* Set a Direct-to-Cloud agent's bandwidth limit
* Read SaaS Protection customers, seats and backup history for Microsoft 365 and Google Workspace
* License, pause or unlicense SaaS Protection seats

Neo does not start a backup, run a screenshot or clear an alert in Datto. When a backup is still failing, the agent reports what it found.

The screenshot result is Datto's own verdict: the appliance boots the backup and judges the screenshot itself. The agent reads that result; it does not look at the image.

## How the agent checks a Datto alert

The agent takes the appliance serial from the ticket and reads the appliance and its active alerts. For a backup or screenshot alert, it finds the protected machine and reads its last backups. If a backup newer than the alert succeeded, its screenshot verification passed and the alert is no longer active, the alert has recovered. Otherwise the agent notes the error and the time of the last good backup. If more than one machine could match, the agent lists them in an internal note and routes the ticket to a technician instead of guessing.

## Permission Groups

| Group | Access levels | Covers |
| - | - | - |
| BCDR Appliances | Disabled, Read Only | Appliances, their agents and shares, backups, verification, alerts and VM restores |
| Endpoint Backup | Disabled, Read Only, Read / Write | Endpoint Backup for PCs and Direct-to-Cloud agents; the write sets an agent's bandwidth limit |
| Activity Log | Disabled, Read Only | The Partner Portal activity log |
| SaaS Protection | Disabled, Read Only, Read / Write | SaaS Protection customers, seats, backup history and stats; the write licenses, pauses or unlicenses seats |

A bandwidth limit of zero, or pausing on metered connections, stops an agent's backups. The Helpdesk and IT Admin profiles ask a technician before that change.

Pausing or unlicensing a SaaS Protection seat stops that user's backups, and Datto deletes an unlicensed seat's backed-up data 30 days later, so both ask a technician under every profile. Licensing a seat asks under Helpdesk and runs on its own under IT Admin and Full Automation.

## SaaS Protection

The agent finds the customer by the user's email domain, reads the user's seat and its state, and reads the last backups of each service. To onboard a user, it licenses their seat. To offboard one, it pauses or unlicenses the seat after a technician approves.

Neo does not read the screenshot image or the RMM deploy templates, which carry agent deploy tokens.

## Setup

See [Connecting Datto BCDR to Neo](/integrations/datto-bcdr/connecting-to-neo).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.