> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neoagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Overview

> What the Hornetsecurity 365 Total Protection integration brings to your Neo Agent setup

Hornetsecurity 365 Total Protection filters email for your clients. The same platform is sold as Proofpoint 365 Total Protection. The most common ticket it causes is "an email I need was held, please let it through". Connect Hornetsecurity to Neo and your agents can find the held email, release it to the user, and allow the sender, from the ticket. Nobody opens the Control Panel.

<Info>
  Hornetsecurity uses one API access token per MSP. Connect it once and every agent you enable can use it, with permissions you control per agent.
</Info>

## What Neo can do with Hornetsecurity

<CardGroup cols={2}>
  <Card title="Emails" icon="magnifying-glass">
    Search a client's email log: who sent it, when, how it was classified (spam, threat, content), and whether it was delivered, with the reason.
  </Card>

  <Card title="Quarantine Actions" icon="envelope-open">
    Release a held email to its recipient, release it and allow the sender in one step, or reclassify it. Deleting an email always waits on a technician.
  </Card>

  <Card title="Allow & Deny Lists" icon="list-check">
    Add a sender, domain or IP address to a client's or a user's allow list or deny list, and remove an entry.
  </Card>

  <Card title="Customers" icon="building">
    Find the client behind a ticket by its domain, and list the clients under your partner account.
  </Card>
</CardGroup>

Mailboxes and Domains are also available, read only: a client's protected mailboxes, aliases and domains.

## Your clients are mapped automatically

Neo matches your Hornetsecurity customers to the companies in your PSA and keeps the mapping on the Hornetsecurity card's **Organization Mapping** tab, refreshed on each PSA metadata sync. It reads every customer under your partner account, including those under sub-partners.

Matching starts with the Microsoft 365 tenant: a customer protecting the same tenant Neo has on a company is an exact match. Then comes the name: exact, then after stripping a legal-form suffix (Ltd, Inc, LLC). Then the domain, for customers named by their domain, against the website on each PSA company. Last comes an AI match for the long tail.

**A tenant match, a name match, or one you confirm, is handed straight to your agents**, so they know the client's Hornetsecurity customer without looking it up. A domain match or an AI match is not handed to your agents automatically. It shows on the Organization Mapping tab, where you can confirm or correct it, and an agent that looks the company up can still find it.

Anything Neo could not match stays unmapped and visible on the same tab, where you can set the right company by hand. A mapping you set by hand survives every later sync.

## Next steps

<Card title="Connect Hornetsecurity" icon="plug" href="/integrations/hornetsecurity/connecting-to-neo">
  Save an API access token in Neo and choose what each agent can do.
</Card>
