Connections
Every tool Reagent connects to, grouped the way the Connections page groups them, with the setup guide for each.
Reagent adds no sensors. Every signal comes from a connection to something you already own, or from telemetry the AI tools themselves emit. The Connections page lists every tool as a tile in seven numbered sections. Click a tile, follow its form, and save. Tiles that offer a Test Connection button run it before saving; the rest report their status after the credential health check.
Connecting requires the manage integrations permission. Some tiles share one credential and activate on their own once the extra permission is granted; those are marked alias below.
01 Identity provider
Resolves who is using AI. Lights up AI app sign-ups and OAuth grants, AI meeting bots, and AI features inside sanctioned SaaS. Recommended first connection.
| Tile | Connector | Auth | Requires |
|---|---|---|---|
| Okta | okta-management | OAuth 2.0 client credentials, private key JWT | any plan |
| Google Workspace | google-workspace | OAuth sign-in, service account, or keyless WIF with Okta | any plan |
| Microsoft Graph | microsoft-graph | Your own Azure app registration, or consent to a Zaun-managed app | any Microsoft 365 plan; Defender tier needs Business Premium, E3, or E5 |
Setup: Identity provider.
02 EDR
Sees AI desktop apps, local LLM runtimes, IDE coding agents, local MCP servers, embedded AI libraries, agent skills, and local model files on managed devices. Enables host containment.
| Tile | Connector | Auth | Requires |
|---|---|---|---|
| CrowdStrike | crowdstrike-falcon-v3 | OAuth 2.0 client credentials | any Falcon tenant; Falcon Discover recommended |
| SentinelOne | sentinelone | API token | any tenant; add-on roles for Deep Visibility and application inventory |
| Microsoft Defender for Endpoint | microsoft-graph (alias) | shares the Microsoft Graph credential | Microsoft 365 with Defender tier |
Setup: EDR.
03 AI tools
The AI platforms your teams use, read through their admin, compliance, or audit APIs, plus the coding agents and desktop apps that push telemetry from developer machines.
Platforms and assistants
| Tile | Connector | Auth | Requires |
|---|---|---|---|
| Claude API Console Admin | anthropic-admin | Admin API key | Claude Console organization, admin role |
| Claude Enterprise Analytics | anthropic-enterprise-analytics | Analytics API key | Claude Enterprise plan, primary owner |
| Claude Enterprise Compliance | anthropic-compliance | Compliance Access Key | Claude Enterprise plan, Compliance API enabled |
| ChatGPT | openai-compliance | Compliance API key plus Workspace ID | ChatGPT Enterprise or Edu |
| Microsoft 365 Copilot | microsoft-graph (alias) | shares the Microsoft Graph credential | Microsoft 365 Copilot |
| Microsoft 365 Copilot Cowork | microsoft-graph (alias) | shares the Microsoft Graph credential | Microsoft 365 Copilot |
| Copilot Studio | copilot-studio | Entra app registration, Power Platform API | Power Platform Administrator to consent |
| Atlassian Rovo | atlassian-admin | Organization API key | Atlassian Guard Standard or Premium, or Enterprise |
| Atlassian Guard Detect | atlassian-guard | Account email plus API token | Atlassian Guard Premium |
| Snowflake Cortex AI | snowflake-cortex | Programmatic access token | a role that can read ACCOUNT_USAGE |
| ServiceNow AI Agents | servicenow | Basic auth or OAuth2 | AI Agent Studio plugin |
| Slack AI Apps & Agents | slack-admin | Org-level token, admin.* scopes | Slack Enterprise Grid |
| Slack Audit Logs | slack-audit-logs | User token, auditlogs:read | Slack Enterprise Grid |
| Slack Response Actions | slack-api | Bot token | any plan |
| Gemini | gemini-workspace | reuses the Google Workspace service account | Gemini in Workspace; the Code Assist lane needs the GCP connection plus Code Assist logging opt-in |
| Salesforce Agentforce | salesforce-agentforce | OAuth 2.0 client credentials External Client App | My Domain |
| Devin | devin | Enterprise API key | Devin Enterprise |
| Glean | glean-events | Compliance Export to an S3 delivery bucket | Glean Compliance Export |
| Perplexity Enterprise | perplexity | Audit Logs webhook, Bearer token | Perplexity Enterprise |
| Replit | replit | WorkOS Log Stream webhook, X-API-Key | Replit Enterprise |
| AWS Bedrock | aws-aws (alias) | additional IAM policy on the AWS role | AWS connection |
| Azure AI Foundry | azure-monitor (alias) | Cognitive Services Reader and Cost Management Reader | Azure connection |
| Google Vertex | gcp-security (alias) | Vertex AI Viewer | GCP connection |
| Lovable | coming soon |
Setup: AI tools.
Coding agents and desktop telemetry
These push telemetry from developer machines into the environment's data lake. Prerequisite: the data lake must be active (open Lake in the sidebar).
| Tile | Connector | How it connects | Requires |
|---|---|---|---|
| Claude Code | claude-code | Native OpenTelemetry via managed settings pasted into claude.ai Organization settings → Claude Code → Managed settings | Anthropic org Primary Owner or Owner |
| Claude Cowork | cowork | Native OpenTelemetry configured under Organization settings → Cowork → Monitoring | Anthropic org Primary Owner or Owner |
| Cursor IDE Agent Monitoring | cursor-ide | Generated hook install script, deployed by MDM | Cursor |
| OpenAI Codex CLI | codex | OpenTelemetry in config.toml (observe) or openai_base_url pinned to the gateway (control) | Codex CLI |
| GitHub Copilot | github-copilot | OpenTelemetry settings keys in VS Code, single machine or managed | Copilot Chat or Copilot CLI |
| Gemini CLI | gemini-cli | OpenTelemetry in .gemini/settings.json | Gemini Code Assist Enterprise licensing |
| Kiro | kiro | Generated hook script in .kiro/hooks/ | Kiro for Enterprise |
| Claude Desktop 3P | managed setup | MDM-delivered managed client configuration; every request routes through the Zaun gateway | Zaun Agent Gateway enabled |
Setup: Coding agents and desktop telemetry.
04 AI Gateway
The inline control point for agent LLM and MCP traffic. The Zaun Agent Gateway is not a Connections tile. It is enabled from Enforce → Gateways and needs the manage agent enforcement permission; see the AI Gateway guide.
| Tile | Connector | Auth | Requires |
|---|---|---|---|
| LiteLLM | litellm | Bearer, scoped admin virtual key | LiteLLM proxy |
| agentgateway | agentgateway | Kubernetes ServiceAccount token | agentgateway on Kubernetes |
| Kong AI Gateway | kong-ai-gateway | Konnect System Account token | Kong Konnect |
| AWS AgentCore Gateway | aws-aws (alias) | additional IAM policy statement on the AWS role | AWS connection |
| Azure AI Foundry Gateway | azure-monitor (alias) | Cognitive Services Contributor | Azure connection |
| Google Agent Gateway | gcp-security (alias) | network services read roles on the GCP service account | GCP connection |
Setup: AI Gateway.
05 Cloud
Inventories deployed models, model usage, custom agents, and MCP servers in your cloud accounts.
| Tile | Connector | Auth | Requires |
|---|---|---|---|
| AWS | aws-aws | Cross-account role assumption (Zaun-managed role, or an IAM user with sts:AssumeRole) | CloudFormation templates deployed |
| Azure | azure-monitor | Service principal, client credentials | Reader, Log Analytics Reader, Cost Management Reader |
| GCP | gcp-security | Service account JSON key, or keyless WIF | roles bound at the organization node |
| Wiz | wiz | OAuth2 client credentials, service account | Wiz tenant |
| Upwind | upwind | OAuth 2.0 client credentials plus Organization ID | Upwind tenant |
Setup: Cloud.
06 Networking
The egress-observation layer: which AI apps people reach, and with what data.
| Tile | Connector | Auth | Requires |
|---|---|---|---|
| Alkira Network Cloud | alkira | API key | Alkira portal admin |
| Cato SASE Cloud | cato-networks | API key, GraphQL | Cato Management Application |
| Cisco Firepower | cisco-firepower | FMC username and password, token auth | dedicated FMC service user with a read-only admin or REST API role |
| Cisco Meraki | meraki-firewall | Dashboard API key | API access enabled |
| Cloudflare | cloudflare | API token plus Account ID | custom token permissions |
| PAN-OS | paloalto-firewall | XML API key | dedicated API admin with Permitted IPs |
| Netskope | netskope | REST API v2 token | endpoints assigned to the token |
| FortiGate | fortigate-firewall | REST API admin token | admin profile and trusted hosts |
| Zscaler | zscaler-zia | OAuth 2.0 client credentials | ZIA admin portal |
| LayerX | layerx | Client ID plus Secret Key | LayerX console API token |
Setup: Networking.
07 Developer platform
| Tile | Connector | Auth | Requires |
|---|---|---|---|
| GitHub | github-org | Personal Access Token, classic or fine-grained | alert APIs work on any plan and return alerts only for repositories where the feature is enabled; private repositories need GitHub Advanced Security; the organization audit log API needs GitHub Enterprise Cloud; Copilot seat data needs a Copilot Business or Enterprise plan |
Setup: Developer platform.
Don't see your tool?
The catalog grows continuously. If something you rely on is not listed, email [email protected] with the platform name and what you want Reagent to see from it.