Skip to main content
The SaaS Alerts API tool gives Neo agents access to the SaaS Alerts Reports, Manage and Respond APIs. The common use is the alert ticket that SaaS Alerts writes in your PSA: the agent reads the event behind it, the user’s other activity, the account and the client, and writes its verdict in an internal note.
Automatically enabled when you configure SaaS Alerts permissions in your agent workflow.

What It Does

  • Find the event behind a SaaS Alerts ticket from its Event ID, with its severity, IP, location and operation
  • Read the user’s other events around the alert, and count how often the event type fires for the client
  • Read the user’s account (enabled or not, admin role) and the client’s SaaS Alerts customer record and approved locations
  • Read pending Respond rule triggers and the recommended actions
  • Create, change or delete suppressions for one client or for named users of one client
  • Set the approved countries, IP ranges and ASNs of a client or of named users, so activity from there stops raising alerts
  • Run Respond actions on Microsoft 365 accounts (block sign-in, expire sessions, reset or force a password change, set up MFA, delete the user), and approve, reject, ignore or manually remediate a rule trigger
  • Manage Respond rules, application connections, Unify devices, PSA mapping and scheduled reports

How the agent handles an alert ticket

SaaS Alerts writes the ticket on the PSA company it maps to the SaaS Alerts customer. The body carries the Event ID, the user, the severity and a link with the SaaS Alerts customer id. The agent looks up the event by its id, reads the same user’s events over a wider window, and checks whether the account is enabled and holds an admin role. It weighs the severity, the IP threat flags, the history and the recommended action, and writes what it found in an internal note. An alert on an anonymous SharePoint link (urn:spo:tenantanon#...) names no person, so the agent checks no account.

Permission Groups

Access Profiles

Safety Controls

How to Configure

1

Connect SaaS Alerts

Save your partner API key in the Neo Dashboard under the Security integrations category. See Connecting SaaS Alerts to Neo.
2

Configure permissions

In your agent workflow’s Integrations tab, choose an access profile or set each permission group by hand.
Start with Read Only. Investigating an alert needs only reads in SaaS Alerts; the note on the ticket is written with the PSA tools.