Each call carries an API path, an HTTP method, and — where the endpoint needs them — query
parameters, a request body, and headers from the vendor’s allowlist. Neo adds the base URL and
the authentication, so the agent never handles the credentials, and a header outside the
allowlist is rejected. A vendor the agent’s permissions do not cover is rejected before any
HTTP call.
Automatically enabled when you configure permissions for any of the covered vendors in your
agent workflow. No manual toggle needed — and it never appears as a separate tool to configure.
The agent’s instructions list the vendors your permissions enable, with a line on what each one
covers. The endpoint tables, request shapes, and each vendor’s quirks live in that vendor’s
skill, which the agent must load before its first call to the vendor.
What It Does
- Calls the vendor’s REST API directly — reads and (where permitted) writes
- Routes each call through the vendor’s own permission groups, exactly as the former
per-vendor tools did
- Applies the vendor’s approval rules: operations a vendor always gates (Huntress host
isolation, ThreatLocker software approvals and policy edits, ScalePad ControlMap writes)
still require technician approval regardless of automation level
Covered Vendors
Permissions & Billing
Each vendor keeps its own permission groups in the agent’s settings — enabling one vendor
never grants another. Calls bill at the vendor’s credit tier (Standard for all covered
vendors today), and usage reporting keeps the per-vendor split.