SentinelOne uses one service-user API token per MSP. Connect it once and every agent you enable can use it, with permissions you control per agent.
What Neo can do with SentinelOne
Threats & Alerts
Read threats, STAR alerts and unified alerts with their detection details and timeline. Set the analyst verdict and incident status, add notes, and write the PSA ticket number on the threat. Mitigation always waits on a technician.
Endpoints
Find an endpoint by name, user or IP. Read its status, threats and installed software. Run a scan and collect logs or files. Network isolation, reboot and uninstall always wait on a technician.
Exclusions & Blocklist
Read exclusions and blocked hashes. Every change waits on a technician, because an exclusion stops SentinelOne from seeing a file.
Deep Visibility & Activities
Search endpoint events with Deep Visibility or PowerQuery, read the console activity log, and check a hash’s verdict. Read only.
Remote Scripts
Read your script library and the results of script runs. Every run waits on a technician.
Accounts, Sites & Groups
Your SentinelOne client hierarchy, used to scope every other lookup to the right client.
Your clients are mapped automatically
Neo matches your SentinelOne sites to the companies in your PSA. The mapping is on the SentinelOne card’s Organization Mapping tab. Neo refreshes it on each PSA metadata sync and when you save the token. Matching is by name. Neo tries an exact match first, then a match after it removes a legal-form suffix (Ltd, Inc, LLC). The last step is an AI match for names the first two steps miss. Neo matches on the site name alone. A site has anexternalId field that SentinelOne describes as an external CRM id, and Neo does not use it until a live console shows what MSPs store there.
Your agents get an exact or suffix match, or a match you confirm, directly. They then scope every lookup to the ticket’s client without searching for it. A match from the AI step is only a suggestion. It stays on the Organization Mapping tab until someone confirms it. You can set a mapping by hand on the same tab, and it survives every later sync.
Why connect SentinelOne
- Threat tickets arrive with the detail already gathered. An agent reads the threat and its timeline. It then checks whether the endpoint is online and whether SentinelOne already mitigated the threat. The technician gets a summary, and does not need to open the console.
- The console and the PSA agree. When a ticket is resolved, the agent sets the verdict and incident status on the threat and writes the ticket number on it. The next run finds the same threat by that number and does not open a duplicate ticket.
- Response actions always require a technician’s sign-off, whatever the agent’s automation level. This covers mitigation, network isolation, reboot, exclusions and remote scripts. The SentinelOne API tool reference lists the full set.
How agents reach SentinelOne
When you enable any SentinelOne permission group on an agent, Neo adds the SentinelOne tool to that agent’s toolbox. There is nothing to install. The agent uses the token you saved in the dashboard, and every call stays inside the areas and access levels you allowed.Where to go next
Connecting SentinelOne to Neo
Setup steps for the service user and token, per-agent access levels, and the safety controls that stay in place.
