> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neoagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# OpenText Secure Cloud API

> Set up users with Microsoft 365 licences, remove licences, answer billing questions, and act on Webroot endpoints, with approvals you set per agent

One connection reaches two OpenText products through the Webroot Unity API: OpenText Secure Cloud (formerly AppRiver), for customers, users, licences and charges, and the Webroot (OpenText Core) console, for sites and endpoints. Each area is a permission group you turn on per agent, and the agent reaches only the groups you enable.

<Info>
  Automatically enabled when you configure OpenText Secure Cloud permissions in your agent workflow. No manual toggle needed. Calls go through the [Vendor API](/agents/tools/vendor-api) tool with the vendor id `opentext`.
</Info>

<Tip>
  Agents load the OpenText Secure Cloud API skill first. It carries the onboarding and offboarding steps, the user and service body shapes, and the charge search. A sub-skill covers the Webroot console, agent status and usage reports.
</Tip>

## What It Does

* Find the Secure Cloud customer behind a PSA company, or take it from the company mapping
* Read a customer's users with their services and Microsoft 365 licences
* Read which services, licences and domains a customer can assign
* Create a user with services and licences, change a user's details, and add, change or remove a user's services (giving a user a role uses Admins & Roles)
* Read subscriptions with seat counts, terms and renewal dates, and search charges and charge events
* Read Webroot licences and order status, place an order and start a trial
* Read Webroot sites, endpoints, groups, policies, commands and threat history
* Scan, clean up, restart or isolate named endpoints, move them between groups and apply a policy
* Read DNS Protection policies and traffic, and change a site's policy mappings
* Read agent status, statistics and usage reports, and fetch event notifications

## Permission Groups

| Permission Group | What It Covers |
| - | - |
| **Customers & Users** | Secure Cloud customers, their users, and each user's services and Microsoft 365 licences |
| **Subscriptions & Charges** | Subscriptions, seat counts, charges and charge events: **read-only** |
| **Orders & Trials** | Carts, orders, trials and product licences |
| **Webroot Sites** | The Webroot GSM console and its sites |
| **Webroot Endpoints & Groups** | Endpoints, groups, policies, agent commands, threat history and blocked URLs |
| **DNS Protection** | DNS Protection policies, site mappings and traffic |
| **Status & Reports** | Agent status, statistics, security awareness activity and usage reports: **read-only** |
| **Admins & Roles** | Webroot console and site administrators, and Secure Cloud users created or updated with a role |
| **Event Notifications** | Event notification subscriptions and their webhooks |

Each group has an access level: **Disabled**, **Read Only**, or **Read/Write**. Subscriptions & Charges and Status & Reports offer only Disabled and Read Only.

## Access Profiles

<AccordionGroup>
  <Accordion title="Read Only">
    All groups Read Only. The agent looks up customers, users, licences, charges and Webroot endpoints, and never changes anything.
  </Accordion>

  <Accordion title="Helpdesk">
    Customers & Users and Webroot Endpoints & Groups at Read/Write, everything else Read Only. Every write in those two groups requires technician approval.
  </Accordion>

  <Accordion title="IT Admin">
    Every writable group at Read/Write. The agent manages users, licences, orders, sites and endpoints autonomously. Admins & Roles, DNS Protection and Event Notifications writes require technician approval, as do the changes listed under Full Automation.
  </Accordion>

  <Accordion title="Full Automation">
    Every supported write runs autonomously. Only Admins & Roles changes, changing an endpoint's keycode, uninstalling or deactivating Webroot on endpoints, suspending or deactivating a site, and cancelling a product require technician approval.
  </Accordion>
</AccordionGroup>

## Safety Controls

| Control | Behavior |
| - | - |
| **Technician-in-the-Loop** | Require human approval for writes, configurable per group |
| **Admin access** | Every Admins & Roles write always requires technician approval: adding, changing or removing a Webroot console or site admin, requesting admin access to a console, a Secure Cloud user create or update that sets a role, and making a user a Microsoft 365 administrator or removing it. Each changes who holds admin access |
| **Keycode changes** | A `changekeycode` agent command always requires technician approval, because it moves endpoints to the site whose keycode it names |
| **Protection removal** | An `uninstall` or `deactivate` agent command, deactivating endpoints, suspending or deactivating a site, and cancelling a product always require technician approval, because each removes the client's protection or service |
| **Seat quantities** | Changing a subscription's seat quantity is refused. The agent tells the technician to change it in Secure Cloud |
| **Named targets only** | A site-level command, move, policy change, reactivation or deactivation must list its endpoints in `EndpointsList` (a move may name a source group instead). Webroot applies an empty list to the whole site, so Neo refuses it |
| **Documented operations only** | Every call must match an operation in the Unity API reference with its own method, and any other is refused |
| **Secrets** | The two `webconsoleurl` operations, which return a link that signs its holder in to the Webroot console, are refused |

## How to Configure

<Steps>
  <Step title="Connect OpenText Secure Cloud">
    Save your Client ID, Client secret and refresh token in the Neo Dashboard under the **Cloud Marketplace** integrations category, with your GSM keycode if you use Webroot. See [Connecting OpenText Secure Cloud to Neo](/integrations/opentext/connecting-to-neo).
  </Step>

  <Step title="Configure permissions">
    In your agent workflow's **Integrations** tab, choose an access profile or customize each permission group.
  </Step>

  <Step title="Set approval requirements">
    Decide per permission group whether writes need a technician. Admins & Roles changes, keycode changes, removing endpoint protection, suspending or deactivating a site, and cancelling a product always do.
  </Step>
</Steps>

<Tip>
  Start with **Read Only** to see how an agent finds the client, its users and its subscriptions. **Helpdesk** then lets it set up and remove licences, with a technician approving each change.
</Tip>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.