> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neoagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Connecting Hornetsecurity to Neo

> Save a Hornetsecurity API access token in Neo, and decide what each agent can do

You connect Hornetsecurity once at the MSP level, then turn it on per agent.

## 1. Create an API access token

<Steps>
  <Step title="Sign in as a partner admin">
    Sign in to the Hornetsecurity Control Panel as an admin at your partner level, so the token reaches every client. A token acts as the user who created it and sees what that user sees.
  </Step>

  <Step title="Create the token">
    Open **User settings** in the top-right menu, then the **API Token** tab, and click **Create token**. Give it a name, set an expiry if you want one, and copy the token.
  </Step>
</Steps>

## 2. Add the token in Neo

<Steps>
  <Step title="Open Integrations">
    In the Neo Dashboard, open **Integrations** and find the Hornetsecurity 365 Total Protection card, under Security.
  </Step>

  <Step title="Save the token">
    Paste the token without the `Token ` prefix and click **Save**. Neo checks it against Hornetsecurity before saving, so a wrong or expired token is rejected straight away. The **Organization Mapping** tab fills separately after the save, and again on each nightly PSA sync.
  </Step>
</Steps>

## 3. Turn Hornetsecurity on per agent

Open the agent, go to the Integrations section, and configure the Hornetsecurity block.

### Pick an access profile

<CardGroup cols={3}>
  <Card title="Read Only" icon="magnifying-glass">
    Search email and look up clients. Nothing is released or changed.
  </Card>

  <Card title="Helpdesk" icon="headset">
    Release held email with technician approval, and edit allow and deny lists.
  </Card>

  <Card title="Full Automation" icon="bolt">
    Release held email and edit allow and deny lists without approval. Deleting email still waits on a technician.
  </Card>
</CardGroup>

### Or set each area by hand

| Area                   | Access levels you can pick          | Notes                                                                                     |
| ---------------------- | ----------------------------------- | ----------------------------------------------------------------------------------------- |
| **Emails**             | Disabled, Read Only                 | Search the email log and read one email's detail and header.                              |
| **Quarantine Actions** | Disabled, Read Only, Read and Write | Release, release and allow the sender, reclassify. Deleting always waits on a technician. |
| **Allow & Deny Lists** | Disabled, Read Only, Read and Write | Entries for a client or one user.                                                         |
| **Customers**          | Disabled, Read Only                 | Client lookup and the partner hierarchy.                                                  |
| **Mailboxes**          | Disabled, Read Only                 | Mailboxes, aliases and groups.                                                            |
| **Domains**            | Disabled, Read Only                 | Protected domains.                                                                        |

## Safety controls

* **Deleting email always waits on a technician.** It cannot be undone. This holds whatever the agent's automation level or profile.
* **Threats are not released on the agent's own judgement.** The agent releases a threat only when a technician asked for that exact email, and Hornetsecurity itself may refuse the release for your account.
* **Only what the job needs.** Neo sends only email search and actions, allow and deny lists, and client, mailbox and domain lookups. Token management, backup, e-learning and every other Control Panel area are unreachable, and so is delivery to Hornetsecurity's support desk.
* **Path safety.** Suspicious URL paths (anything containing `..`, for example) are rejected before they reach Hornetsecurity.

## If Hornetsecurity refuses Neo's requests

| What comes back                                                                            | Cause                                                                               | Fix                                                                                  |
| ------------------------------------------------------------------------------------------ | ----------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------ |
| `401`                                                                                      | The token expired or was deleted                                                    | Create a new token and save it in Neo                                                |
| `403`                                                                                      | The token's user may not act on that client, or may not release that classification | Create the token as a partner-level admin, or release the email in the Control Panel |
| `429`                                                                                      | Rate limited                                                                        | Wait. The agent does not retry within the same run                                   |
| A failed **Hornetsecurity 365 Total Protection Company Mapping** row with a `401` or `403` | The same token problem, met by the nightly mapping                                  | Fix the token as above. The next PSA sync rebuilds the mapping                       |

## Disconnecting Hornetsecurity

In the Neo Dashboard, open **Integrations**, select the Hornetsecurity card, click **Disconnect** and confirm. Neo removes the token from Key Vault. Agents that use Hornetsecurity stop working until you connect it again. Your Organization Mapping is kept, including any mapping you set by hand.

## Security

* The token lives in Azure Key Vault. It is never stored in plaintext.
* All traffic goes over HTTPS to `cp.hornetsecurity.com`.
* Write access is opt in per agent and per area.
