> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neoagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Hornetsecurity API

> Search a client's email in Hornetsecurity 365 Total Protection, release held email, and allow or deny senders — deleting email always requires technician approval

The Hornetsecurity API tool gives Neo agents access to the Hornetsecurity Control Panel API, which also serves Proofpoint 365 Total Protection. An agent finds the email behind a "my email never arrived" ticket, releases it to the user, and allows the sender when the ticket asks.

<Info>
  Automatically enabled when you configure Hornetsecurity permissions in your agent workflow.
</Info>

## What It Does

* Find the client from the [Organization Mapping](/integrations/hornetsecurity/overview#your-clients-are-mapped-automatically), or by its domain
* Search the client's email log by user, sender, subject and date, and read one email's detail and header
* Release a held email to its recipient, or release it and allow the sender in one step
* Add or remove allow and deny list entries for a client or one user
* Look up mailboxes, aliases and protected domains

## How the agent releases an email

The agent searches the client's email log for the email the ticket describes. If more than one email could match, it lists them and asks. It checks the result of every release, because Hornetsecurity reports success per email. It releases an email classified as a threat only when a technician asked for that exact email.

## Permission Groups

| Group              | Access levels                       | Always waits on a technician |
| ------------------ | ----------------------------------- | ---------------------------- |
| Emails             | Disabled, Read Only                 | —                            |
| Quarantine Actions | Disabled, Read Only, Read and Write | Deleting an email            |
| Allow & Deny Lists | Disabled, Read Only, Read and Write | —                            |
| Customers          | Disabled, Read Only                 | —                            |
| Mailboxes          | Disabled, Read Only                 | —                            |
| Domains            | Disabled, Read Only                 | —                            |

## Setup

See [Connecting Hornetsecurity to Neo](/integrations/hornetsecurity/connecting-to-neo).
