Reagent Docs

Connections

Every tool Reagent connects to, grouped the way the Connections page groups them, with the setup guide for each.

Reagent adds no sensors. Every signal comes from a connection to something you already own, or from telemetry the AI tools themselves emit. The Connections page lists every tool as a tile in seven numbered sections. Click a tile, follow its form, and save. Tiles that offer a Test Connection button run it before saving; the rest report their status after the credential health check.

Connecting requires the manage integrations permission. Some tiles share one credential and activate on their own once the extra permission is granted; those are marked alias below.

01 Identity provider

Resolves who is using AI. Lights up AI app sign-ups and OAuth grants, AI meeting bots, and AI features inside sanctioned SaaS. Recommended first connection.

TileConnectorAuthRequires
Oktaokta-managementOAuth 2.0 client credentials, private key JWTany plan
Google Workspacegoogle-workspaceOAuth sign-in, service account, or keyless WIF with Oktaany plan
Microsoft Graphmicrosoft-graphYour own Azure app registration, or consent to a Zaun-managed appany Microsoft 365 plan; Defender tier needs Business Premium, E3, or E5

Setup: Identity provider.

02 EDR

Sees AI desktop apps, local LLM runtimes, IDE coding agents, local MCP servers, embedded AI libraries, agent skills, and local model files on managed devices. Enables host containment.

TileConnectorAuthRequires
CrowdStrikecrowdstrike-falcon-v3OAuth 2.0 client credentialsany Falcon tenant; Falcon Discover recommended
SentinelOnesentineloneAPI tokenany tenant; add-on roles for Deep Visibility and application inventory
Microsoft Defender for Endpointmicrosoft-graph (alias)shares the Microsoft Graph credentialMicrosoft 365 with Defender tier

Setup: EDR.

03 AI tools

The AI platforms your teams use, read through their admin, compliance, or audit APIs, plus the coding agents and desktop apps that push telemetry from developer machines.

Platforms and assistants

TileConnectorAuthRequires
Claude API Console Adminanthropic-adminAdmin API keyClaude Console organization, admin role
Claude Enterprise Analyticsanthropic-enterprise-analyticsAnalytics API keyClaude Enterprise plan, primary owner
Claude Enterprise Complianceanthropic-complianceCompliance Access KeyClaude Enterprise plan, Compliance API enabled
ChatGPTopenai-complianceCompliance API key plus Workspace IDChatGPT Enterprise or Edu
Microsoft 365 Copilotmicrosoft-graph (alias)shares the Microsoft Graph credentialMicrosoft 365 Copilot
Microsoft 365 Copilot Coworkmicrosoft-graph (alias)shares the Microsoft Graph credentialMicrosoft 365 Copilot
Copilot Studiocopilot-studioEntra app registration, Power Platform APIPower Platform Administrator to consent
Atlassian Rovoatlassian-adminOrganization API keyAtlassian Guard Standard or Premium, or Enterprise
Atlassian Guard Detectatlassian-guardAccount email plus API tokenAtlassian Guard Premium
Snowflake Cortex AIsnowflake-cortexProgrammatic access tokena role that can read ACCOUNT_USAGE
ServiceNow AI AgentsservicenowBasic auth or OAuth2AI Agent Studio plugin
Slack AI Apps & Agentsslack-adminOrg-level token, admin.* scopesSlack Enterprise Grid
Slack Audit Logsslack-audit-logsUser token, auditlogs:readSlack Enterprise Grid
Slack Response Actionsslack-apiBot tokenany plan
Geminigemini-workspacereuses the Google Workspace service accountGemini in Workspace; the Code Assist lane needs the GCP connection plus Code Assist logging opt-in
Salesforce Agentforcesalesforce-agentforceOAuth 2.0 client credentials External Client AppMy Domain
DevindevinEnterprise API keyDevin Enterprise
Gleanglean-eventsCompliance Export to an S3 delivery bucketGlean Compliance Export
Perplexity EnterpriseperplexityAudit Logs webhook, Bearer tokenPerplexity Enterprise
ReplitreplitWorkOS Log Stream webhook, X-API-KeyReplit Enterprise
AWS Bedrockaws-aws (alias)additional IAM policy on the AWS roleAWS connection
Azure AI Foundryazure-monitor (alias)Cognitive Services Reader and Cost Management ReaderAzure connection
Google Vertexgcp-security (alias)Vertex AI ViewerGCP connection
Lovablecoming soon

Setup: AI tools.

Coding agents and desktop telemetry

These push telemetry from developer machines into the environment's data lake. Prerequisite: the data lake must be active (open Lake in the sidebar).

TileConnectorHow it connectsRequires
Claude Codeclaude-codeNative OpenTelemetry via managed settings pasted into claude.ai Organization settings → Claude Code → Managed settingsAnthropic org Primary Owner or Owner
Claude CoworkcoworkNative OpenTelemetry configured under Organization settings → Cowork → MonitoringAnthropic org Primary Owner or Owner
Cursor IDE Agent Monitoringcursor-ideGenerated hook install script, deployed by MDMCursor
OpenAI Codex CLIcodexOpenTelemetry in config.toml (observe) or openai_base_url pinned to the gateway (control)Codex CLI
GitHub Copilotgithub-copilotOpenTelemetry settings keys in VS Code, single machine or managedCopilot Chat or Copilot CLI
Gemini CLIgemini-cliOpenTelemetry in .gemini/settings.jsonGemini Code Assist Enterprise licensing
KirokiroGenerated hook script in .kiro/hooks/Kiro for Enterprise
Claude Desktop 3Pmanaged setupMDM-delivered managed client configuration; every request routes through the Zaun gatewayZaun Agent Gateway enabled

Setup: Coding agents and desktop telemetry.

04 AI Gateway

The inline control point for agent LLM and MCP traffic. The Zaun Agent Gateway is not a Connections tile. It is enabled from Enforce → Gateways and needs the manage agent enforcement permission; see the AI Gateway guide.

TileConnectorAuthRequires
LiteLLMlitellmBearer, scoped admin virtual keyLiteLLM proxy
agentgatewayagentgatewayKubernetes ServiceAccount tokenagentgateway on Kubernetes
Kong AI Gatewaykong-ai-gatewayKonnect System Account tokenKong Konnect
AWS AgentCore Gatewayaws-aws (alias)additional IAM policy statement on the AWS roleAWS connection
Azure AI Foundry Gatewayazure-monitor (alias)Cognitive Services ContributorAzure connection
Google Agent Gatewaygcp-security (alias)network services read roles on the GCP service accountGCP connection

Setup: AI Gateway.

05 Cloud

Inventories deployed models, model usage, custom agents, and MCP servers in your cloud accounts.

TileConnectorAuthRequires
AWSaws-awsCross-account role assumption (Zaun-managed role, or an IAM user with sts:AssumeRole)CloudFormation templates deployed
Azureazure-monitorService principal, client credentialsReader, Log Analytics Reader, Cost Management Reader
GCPgcp-securityService account JSON key, or keyless WIFroles bound at the organization node
WizwizOAuth2 client credentials, service accountWiz tenant
UpwindupwindOAuth 2.0 client credentials plus Organization IDUpwind tenant

Setup: Cloud.

06 Networking

The egress-observation layer: which AI apps people reach, and with what data.

TileConnectorAuthRequires
Alkira Network CloudalkiraAPI keyAlkira portal admin
Cato SASE Cloudcato-networksAPI key, GraphQLCato Management Application
Cisco Firepowercisco-firepowerFMC username and password, token authdedicated FMC service user with a read-only admin or REST API role
Cisco Merakimeraki-firewallDashboard API keyAPI access enabled
CloudflarecloudflareAPI token plus Account IDcustom token permissions
PAN-OSpaloalto-firewallXML API keydedicated API admin with Permitted IPs
NetskopenetskopeREST API v2 tokenendpoints assigned to the token
FortiGatefortigate-firewallREST API admin tokenadmin profile and trusted hosts
Zscalerzscaler-ziaOAuth 2.0 client credentialsZIA admin portal
LayerXlayerxClient ID plus Secret KeyLayerX console API token

Setup: Networking.

07 Developer platform

TileConnectorAuthRequires
GitHubgithub-orgPersonal Access Token, classic or fine-grainedalert APIs work on any plan and return alerts only for repositories where the feature is enabled; private repositories need GitHub Advanced Security; the organization audit log API needs GitHub Enterprise Cloud; Copilot seat data needs a Copilot Business or Enterprise plan

Setup: Developer platform.

Don't see your tool?

The catalog grows continuously. If something you rely on is not listed, email [email protected] with the platform name and what you want Reagent to see from it.