Skip to main content
SentinelOne Singularity is an EDR and XDR platform: it detects threats on your clients’ endpoints, and it can kill, quarantine or roll back what it finds. Connect SentinelOne to Neo, and your agents can read the threat behind a ticket and check the endpoint it hit. They can then record the verdict and close the threat in SentinelOne. A technician does not need to open the SentinelOne console.
SentinelOne uses one service-user API token per MSP. Connect it once and every agent you enable can use it, with permissions you control per agent.

What Neo can do with SentinelOne

Threats & Alerts

Read threats, STAR alerts and unified alerts with their detection details and timeline. Set the analyst verdict and incident status, add notes, and write the PSA ticket number on the threat. Mitigation always waits on a technician.

Endpoints

Find an endpoint by name, user or IP. Read its status, threats and installed software. Run a scan and collect logs or files. Network isolation, reboot and uninstall always wait on a technician.

Exclusions & Blocklist

Read exclusions and blocked hashes. Every change waits on a technician, because an exclusion stops SentinelOne from seeing a file.

Deep Visibility & Activities

Search endpoint events with Deep Visibility or PowerQuery, read the console activity log, and check a hash’s verdict. Read only.

Remote Scripts

Read your script library and the results of script runs. Every run waits on a technician.

Accounts, Sites & Groups

Your SentinelOne client hierarchy, used to scope every other lookup to the right client.
Users & Roles is also available, read only, for access reviews.

Your clients are mapped automatically

Neo matches your SentinelOne sites to the companies in your PSA. The mapping is on the SentinelOne card’s Organization Mapping tab. Neo refreshes it on each PSA metadata sync and when you save the token. Matching is by name. Neo tries an exact match first, then a match after it removes a legal-form suffix (Ltd, Inc, LLC). The last step is an AI match for names the first two steps miss. Neo matches on the site name alone. A site has an externalId field that SentinelOne describes as an external CRM id, and Neo does not use it until a live console shows what MSPs store there. Your agents get an exact or suffix match, or a match you confirm, directly. They then scope every lookup to the ticket’s client without searching for it. A match from the AI step is only a suggestion. It stays on the Organization Mapping tab until someone confirms it. You can set a mapping by hand on the same tab, and it survives every later sync.

Why connect SentinelOne

  • Threat tickets arrive with the detail already gathered. An agent reads the threat and its timeline. It then checks whether the endpoint is online and whether SentinelOne already mitigated the threat. The technician gets a summary, and does not need to open the console.
  • The console and the PSA agree. When a ticket is resolved, the agent sets the verdict and incident status on the threat and writes the ticket number on it. The next run finds the same threat by that number and does not open a duplicate ticket.
  • Response actions always require a technician’s sign-off, whatever the agent’s automation level. This covers mitigation, network isolation, reboot, exclusions and remote scripts. The SentinelOne API tool reference lists the full set.

How agents reach SentinelOne

When you enable any SentinelOne permission group on an agent, Neo adds the SentinelOne tool to that agent’s toolbox. There is nothing to install. The agent uses the token you saved in the dashboard, and every call stays inside the areas and access levels you allowed.

Where to go next

Connecting SentinelOne to Neo

Setup steps for the service user and token, per-agent access levels, and the safety controls that stay in place.