> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neoagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Connecting BeyondTrust EPM to Neo

> Create a BeyondTrust EPM API account and save it in Neo

You connect BeyondTrust EPM once at the MSP level.

## 1. Create an API account

<Steps>
  <Step title="Open API Settings">
    Sign in to BeyondTrust EPM and open **Configuration** > **Settings** > **API Settings**.
  </Step>

  <Step title="Create the account">
    Click **Create an API Account** and enter a name, such as `Neo`. Copy the **Client ID** and the **Client Secret**. The secret is shown only once.
  </Step>

  <Step title="Set the permissions">
    Set **Read Only** on the **Audit**, **JIT** and **Management** endpoints, then save.
  </Step>
</Steps>

## 2. Find your API host

Your API host is `https://<your-subdomain>-services.pm.beyondtrustcloud.com`. It is the host of your Management API Swagger page, for example `https://yourcompany-services.pm.beyondtrustcloud.com/management-api/swagger/index.html`.

## 3. Add the account in Neo

<Steps>
  <Step title="Open Integrations">
    In the Neo Dashboard, open **Integrations** and find the BeyondTrust EPM card, under Security.
  </Step>

  <Step title="Save the account">
    Paste the API host, the Client ID and the Client Secret and click **Save**. Neo checks them against BeyondTrust before saving, so a wrong host, a wrong secret or a missing permission is rejected straight away.
  </Step>
</Steps>

## 4. Turn BeyondTrust EPM on per agent

Open the agent, go to the Integrations section, and configure the BeyondTrust EPM block. Pick a profile, or set each area:

| Area | Access levels you can pick | Notes |
| - | - | - |
| **JIT Application Access** | Disabled, Read Only, Read / Write | Elevation requests and their audit trail. This is the area an elevation-email agent needs. |
| **JIT Admin Access** | Disabled, Read Only, Read / Write | Admin access requests. |
| **Computers** | Disabled, Read Only, Read / Write | The computer behind a request, its group, domain and policy. |
| **Groups** | Disabled, Read Only, Read / Write | Computer groups. |
| **Policies** | Disabled, Read Only, Read / Write | Policies and application groups. |
| **Console Users and Access** | Disabled, Read Only, Read / Write | Console users, roles and API accounts. |
| **Activity and Events** | Disabled, Read Only | Console activity and endpoint events. |

| Profile | Writes |
| - | - |
| **Read Only** | Not allowed |
| **Helpdesk** | Every write asks a technician |
| **IT Admin** | Computer and group changes run on their own; policy and console-user changes ask a technician |
| **Full Automation** | Run on their own |

Under every profile, approving or denying a request, deleting or deactivating a computer, clearing a group's policy, and deleting a group or policy ask a technician.

## Example: move elevation tickets to the right client

Give the agent that triages your BeyondTrust elevation emails the **Read Only** profile and an instruction like this:

> When a ticket is a BeyondTrust JIT application access request, look up the request and its computer in BeyondTrust EPM and move the ticket to that computer's client.

See [BeyondTrust EPM API](/agents/tools/security/beyondtrust-epm-api) for what the agent can read.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.