Skip to main content
One connection reaches two OpenText products through the Webroot Unity API: OpenText Secure Cloud (formerly AppRiver), for customers, users, licences and charges, and the Webroot (OpenText Core) console, for sites and endpoints. Each area is a permission group you turn on per agent, and the agent reaches only the groups you enable.
Automatically enabled when you configure OpenText Secure Cloud permissions in your agent workflow. No manual toggle needed. Calls go through the Vendor API tool with the vendor id opentext.
Agents load the OpenText Secure Cloud API skill first. It carries the onboarding and offboarding steps, the user and service body shapes, and the charge search. A sub-skill covers the Webroot console, agent status and usage reports.

What It Does

  • Find the Secure Cloud customer behind a PSA company, or take it from the company mapping
  • Read a customer’s users with their services and Microsoft 365 licences
  • Read which services, licences and domains a customer can assign
  • Create a user with services and licences, change a user’s details, and add, change or remove a user’s services (giving a user a role uses Admins & Roles)
  • Read subscriptions with seat counts, terms and renewal dates, and search charges and charge events
  • Read Webroot licences and order status, place an order and start a trial
  • Read Webroot sites, endpoints, groups, policies, commands and threat history
  • Scan, clean up, restart or isolate named endpoints, move them between groups and apply a policy
  • Read DNS Protection policies and traffic, and change a site’s policy mappings
  • Read agent status, statistics and usage reports, and fetch event notifications

Permission Groups

Each group has an access level: Disabled, Read Only, or Read/Write. Subscriptions & Charges and Status & Reports offer only Disabled and Read Only.

Access Profiles

All groups Read Only. The agent looks up customers, users, licences, charges and Webroot endpoints, and never changes anything.
Customers & Users and Webroot Endpoints & Groups at Read/Write, everything else Read Only. Every write in those two groups requires technician approval.
Every writable group at Read/Write. The agent manages users, licences, orders, sites and endpoints autonomously. Admins & Roles, DNS Protection and Event Notifications writes require technician approval, as do the changes listed under Full Automation.
Every supported write runs autonomously. Only Admins & Roles changes, changing an endpoint’s keycode, uninstalling or deactivating Webroot on endpoints, suspending or deactivating a site, and cancelling a product require technician approval.

Safety Controls

How to Configure

1

Connect OpenText Secure Cloud

Save your Client ID, Client secret and refresh token in the Neo Dashboard under the Cloud Marketplace integrations category, with your GSM keycode if you use Webroot. See Connecting OpenText Secure Cloud to Neo.
2

Configure permissions

In your agent workflow’s Integrations tab, choose an access profile or customize each permission group.
3

Set approval requirements

Decide per permission group whether writes need a technician. Admins & Roles changes, keycode changes, removing endpoint protection, suspending or deactivating a site, and cancelling a product always do.
Start with Read Only to see how an agent finds the client, its users and its subscriptions. Helpdesk then lets it set up and remove licences, with a technician approving each change.