M ManySignal

Integrations

Connect your stack in minutes

Declarative connector manifests handle auth, scheduling, checkpointing, and deduplication. Silent sources are flagged before they become blind spots.

AWS CloudTrail

Cloud

GCP Audit Logs

Cloud

Azure AD

Identity

Okta

Identity

Duo

Identity

Google Workspace

SaaS

Microsoft 365

SaaS

Salesforce

SaaS

Slack

Collaboration

Jira

Ticketing

PagerDuty

On-call

CrowdStrike

Endpoint

SentinelOne

Endpoint

GitHub Audit

Code

Cloudflare

Network

Zscaler

Network

Snowflake

Data

Datadog

Observability

Wiz

Cloud security

Splunk forwarding

SIEM

Missing a source? Connectors are declarative YAML — new integrations ship without engine changes.

Integrations built for an agentic SOC

Sources don't just stream — they feed agents that act.

No parsing projects

Declarative manifests normalise telemetry into the OCSF-aligned event model automatically.

Detections included

Curated rules ship per source, staged alert-only until they prove precision in your environment.

One agentic queue

Every source feeds the same AI triage queue — one entity graph, one verdict pipeline, one audit trail.

Health monitoring

Silent or checkpoint-stalled connectors are flagged before they become blind spots.

Deduped at the gate

Duplicate events are dropped at ingestion, keeping the graph and your bill honest.

MDR multi-tenant

MDR providers onboard client sources per tenant with isolated data and per-client reporting.

Integrations: frequently asked questions

How long does a connector take to set up?

Most connectors are live in under an hour: add credentials, and the manifest handles auth, scheduling, checkpointing, and dedup.

Do integrations feed the AI agents directly?

Yes. Every source normalises into the entity graph that ManySignal's agentic SOC reasons over — triage verdicts include cross-source context automatically.

What if a source goes silent?

Connector health monitoring flags silent or stalled sources immediately, so gaps never become blind spots.

Can I request a new integration?

Yes — connectors are declarative manifests, so new sources ship quickly. Contact us with your stack.

Do connectors require read-only access or do they need write permissions?

Log ingestion connectors require read-only access to the source system's API or log stream. Response action connectors (for containment — isolate endpoint, disable account, block IP) require scoped write permissions to the specific action types ManySignal will execute. All permissions are documented per integration in the connector setup guide, and principle of least privilege is applied throughout.

How does ManySignal normalise events from sources with different schemas?

All inbound events are mapped to ManySignal's OCSF-aligned entity event model at the connector layer. The connector manifest defines the field mapping from the source schema to the normalised model. This means detection rules and triage logic operate against a consistent schema regardless of source — a user authentication event from Okta and one from Active Directory have the same fields after normalisation.

What happens if ManySignal's credentials for a connector expire?

Connector health monitoring detects authentication failures immediately and raises a health alert in the operations dashboard and to the configured notification channel. A connector that fails authentication stops ingesting events — the platform does not silently drop events without notification. The health alert includes the specific connector, the failure reason, and a link to the credential update flow.

Can I connect multiple instances of the same tool — for example, multiple Splunk deployments or multiple AWS accounts?

Yes. Multiple instances of the same connector type are fully supported. Each instance is configured independently with its own credentials, scope, and health monitoring. AWS multi-account setups are handled via organisation-level IAM roles that provide read access across accounts from a single connector configuration, or via individual connectors per account.

How are connector updates handled when the source API changes?

ManySignal's connector team monitors API deprecation notices and breaking changes from all integrated sources. Connector manifests are updated before API changes take effect, and updates are deployed transparently without customer action. For breaking API changes that require credential re-authorization, customers are notified in advance with the steps required before the deadline.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.