> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neoagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Connecting SaaS Alerts to Neo

> Copy your SaaS Alerts partner API key and save it in Neo

You connect SaaS Alerts once at the MSP level. One partner API key covers every client in your SaaS Alerts account.

## 1. Copy the API key

<Steps>
  <Step title="Open the API settings">
    Sign in to SaaS Alerts as a partner admin and open **Settings** > **API**.
  </Step>

  <Step title="Copy the key">
    Under **Manage API**, click **Show key** and copy the key. Copy it before you leave the page.
  </Step>
</Steps>

<Warning>
  Do not reset the key in SaaS Alerts after you connect it. A reset replaces the key, and Neo loses access until you save the new key here.
</Warning>

## 2. Add the key in Neo

<Steps>
  <Step title="Open Integrations">
    In the Neo Dashboard, open [**Integrations** → **SaaS Alerts**](https://dashboard.neoagent.io/integrations?open=saas_alerts), under Security.
  </Step>

  <Step title="Save the key">
    Paste the API key and click **Save settings**. Neo checks it against SaaS Alerts before saving, so a wrong key is rejected straight away.
  </Step>
</Steps>

## 3. Turn SaaS Alerts on per agent

Open the agent, go to the Integrations section, and configure the SaaS Alerts block. Pick a profile, or set each area:

| Area | Access levels you can pick | Notes |
| - | - | - |
| **Events and Alerts** | Disabled, Read Only | The event behind an alert ticket and the user's other events. This is the area an alert-triage agent needs. |
| **Customers and Users** | Disabled, Read Only, Read / Write | SaaS Alerts customers and their users. |
| **Approved Locations** | Disabled, Read Only, Read / Write | Approved countries, IP ranges and ASNs. Reading the current lists needs Customers and Users read access. |
| **Suppressions** | Disabled, Read Only, Read / Write | Suppression rules. |
| **Respond Rules** | Disabled, Read Only, Read / Write | Respond rules and IOC rules. |
| **Respond Triggers and Actions** | Disabled, Read Only, Read / Write | Rule triggers and actions on Microsoft 365 accounts. |
| **Connections and Devices** | Disabled, Read Only, Read / Write | Respond connections and Unify devices. |
| **PSA Mapping** | Disabled, Read Only, Read / Write | Which PSA company gets each client's alert tickets. |
| **Reports** | Disabled, Read Only, Read / Write | Scheduled reports and report emails. |

| Profile | Writes |
| - | - |
| **Read Only** | Not allowed |
| **Helpdesk** | Every write asks a technician |
| **IT Admin** | Ignoring a rule trigger and customer, connection, device and report changes run on their own; suppressions, approved locations, Respond rules and PSA mapping ask a technician |
| **Full Automation** | Run on their own |

Under every profile, a Respond action on an account, approving, rejecting or manually remediating a rule trigger, deleting a customer or an application connection, and turning Respond off ask a technician.

## Example: investigate alert tickets

Give the agent that triages your SaaS Alerts tickets the **Read Only** profile and an instruction like this:

> When a ticket is a SaaS Alerts alert, look up the event and the user's recent activity in SaaS Alerts, judge whether it needs action, and write what you found in an internal note.

See [SaaS Alerts API](/agents/tools/security/saas-alerts-api) for what the agent can read and change.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.