Skip to main content
The SentinelOne API tool gives Neo agents direct access to the SentinelOne Management API (v2.1). An agent can read the threat behind a ticket, check the endpoint and its timeline, record the verdict, and close the threat in the console. With a technician’s approval, it can also mitigate the threat or isolate the endpoint.
Automatically enabled when you configure SentinelOne permissions in your agent workflow. No manual toggle needed.
Agents load the SentinelOne API skill first. The skill carries the site scoping rule, the filter and data body shape, and the endpoint tables for threats, alerts, endpoints and response actions.

What It Does

  • Read the threat behind a SentinelOne ticket: classification, confidence, file, hashes, storyline, and whether it is already mitigated
  • Read its timeline, notes and storyline events, and the endpoint’s current status
  • Set the analyst verdict and incident status, add notes, and write the PSA ticket number on the threat
  • Read and update STAR alerts, and read unified alerts through Unified Alert Management
  • Find endpoints by name, user, IP or status; run and stop scans; collect logs and files; tag endpoints
  • Mitigate threats, isolate or reconnect endpoints, reboot or shut down, with technician approval
  • Read and change exclusions and the hash blocklist, with technician approval
  • Run Deep Visibility and PowerQuery event searches, and read the console activity log
  • Run a library script on named endpoints, with technician approval

Permission Groups

Each group has an access level: Disabled, Read Only, or Read/Write.

Access Profiles

All groups Read Only. The agent investigates any threat or endpoint and reports, but never changes anything.
Threats & Alerts and Endpoints at Read/Write, everything else Read Only. The agent can close threats, scan endpoints and collect logs. Mitigation and isolation still require technician approval.
Every writable group at Read/Write, with technician approval on every write.
Routine triage writes, scans, log and file collection and tags run autonomously. Mitigation, network isolation, reboot, shutdown, uninstall, exclusions, remote scripts and site changes still always require technician approval.

Safety Controls

Network isolation is asynchronous. After the call, the endpoint shows disconnecting and then disconnected. The agent is instructed to report an endpoint as isolated only after SentinelOne confirms it.

How to Configure

1

Connect SentinelOne

Save your console URL and a service-user API token in the Neo Dashboard under the Security integrations category. See Connecting SentinelOne to Neo.
The service user’s role limits what any agent can do: each API operation needs its own permission. Other MSP tools ask for Viewer to read, and for SOC or IR Team to set verdicts and respond to threats.
2

Configure permissions

In your agent workflow’s Integrations tab, choose an access profile or customize each permission group.
3

Set approval requirements

Response actions always require technician approval. Decide whether verdicts, status changes and scans should require approval too.
Start with Read Only or Helpdesk. Both give the agent the threat context for a ticket without any response action.