Automatically enabled when you configure SentinelOne permissions in your agent workflow. No manual toggle needed.
What It Does
- Read the threat behind a SentinelOne ticket: classification, confidence, file, hashes, storyline, and whether it is already mitigated
- Read its timeline, notes and storyline events, and the endpoint’s current status
- Set the analyst verdict and incident status, add notes, and write the PSA ticket number on the threat
- Read and update STAR alerts, and read unified alerts through Unified Alert Management
- Find endpoints by name, user, IP or status; run and stop scans; collect logs and files; tag endpoints
- Mitigate threats, isolate or reconnect endpoints, reboot or shut down, with technician approval
- Read and change exclusions and the hash blocklist, with technician approval
- Run Deep Visibility and PowerQuery event searches, and read the console activity log
- Run a library script on named endpoints, with technician approval
Permission Groups
Each group has an access level: Disabled, Read Only, or Read/Write.
Access Profiles
Read Only
Read Only
All groups Read Only. The agent investigates any threat or endpoint and reports, but never changes anything.
Helpdesk
Helpdesk
Threats & Alerts and Endpoints at Read/Write, everything else Read Only. The agent can close threats, scan endpoints and collect logs. Mitigation and isolation still require technician approval.
IT Admin
IT Admin
Every writable group at Read/Write, with technician approval on every write.
Full Automation
Full Automation
Routine triage writes, scans, log and file collection and tags run autonomously. Mitigation, network isolation, reboot, shutdown, uninstall, exclusions, remote scripts and site changes still always require technician approval.
Safety Controls
Network isolation is asynchronous. After the call, the endpoint shows
disconnecting and then disconnected. The agent is instructed to report an endpoint as isolated only after SentinelOne confirms it.How to Configure
1
Connect SentinelOne
Save your console URL and a service-user API token in the Neo Dashboard under the Security integrations category. See Connecting SentinelOne to Neo.
2
Configure permissions
In your agent workflow’s Integrations tab, choose an access profile or customize each permission group.
3
Set approval requirements
Response actions always require technician approval. Decide whether verdicts, status changes and scans should require approval too.
