> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neoagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Overview

> What the BeyondTrust EPM integration brings to your Neo Agent setup

BeyondTrust Endpoint Privilege Management for Windows and Mac (EPM-WM) controls which applications your end users may run with admin rights. Connect your EPM API account to Neo once, at the MSP level.

## What Neo can do with BeyondTrust EPM

<CardGroup cols={2}>
  <Card title="Elevation requests" icon="shield-check">
    Find the JIT request behind a BeyondTrust elevation email from its ticket number, with the user, computer, application, publisher and reason.
  </Card>

  <Card title="Computers and groups" icon="laptop">
    Read the computer behind a request, its group, domain and policy, and move the ticket to the client the computer belongs to.
  </Card>

  <Card title="Policies and console users" icon="user-shield">
    Read policies, application groups, console users and roles. Manage computers, groups and policies when you allow it.
  </Card>

  <Card title="Activity and events" icon="list">
    See who changed what in the console, and search a computer's or user's endpoint events.
  </Card>
</CardGroup>

Approving or denying a request, removing a computer, and clearing or deleting a policy always ask a technician first.

## Your groups are mapped to clients

Neo matches your BeyondTrust EPM computer groups to the companies in your PSA and keeps the mapping on the BeyondTrust EPM card's **Organization Mapping** tab, refreshed on each PSA metadata sync.

Matching uses the group name: exact, then after stripping a legal-form suffix (Ltd, Inc, LLC). Last comes an AI match for the long tail.

**A name match, or one you confirm, is handed straight to your agents**, so they find the computers of the ticket's client. An AI match is not handed to your agents automatically. It shows on the Organization Mapping tab, where you can confirm or correct it.

A group Neo could not match stays unmapped and visible on the same tab, where you can set the right company by hand. A mapping you set by hand survives every later sync. A group that is not a client, such as a policy tier like "Mac Workstations", stays unmapped; you can ignore it.

## Next steps

<Card title="Connect BeyondTrust EPM" icon="plug" href="/integrations/beyondtrust-epm/connecting-to-neo">
  Create an API account in BeyondTrust EPM and save it in Neo.
</Card>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.