Sonrai Security

Supported OS Linux Windows Mac OS

Integration version1.0.0

To find out if this integration is available in your organization, see your Datadog Integrations page or ask your organization administrator.

To initiate an exception request to enable this integration for your organization, email support@ddog-gov.com.

Overview

Sonrai’s Cloud Permissions Firewall, the leading cloud PAM solution, gets cloud access under control, slashes the privileged attack surface, and automates least privilege - for both humans and agents - all without impeding DevOps. The Cloud Permissions Firewall uses privileged permission intelligence and usage monitoring to determine who needs what permissions in your cloud. Then, with one-click, it eliminates all unused privileged privileges across your entire multi-cloud estate. Just-in-time access and exceptions are granted to roles on the fly as new needs come up so development goes uninterrupted.

Sonrai sends its full audit and access lifecycle to Datadog as logs, giving security and platform teams a single pane over both the workloads they already observe and the privileged identities acting on them. Pivot from a Datadog alert to the Permission on Demand approvals that touched the same scope, build monitors on denial spikes or unusual JIT activity, and share dashboards with SecOps, DevOps, and audit teams - without leaving Datadog. The integration installs a parsed log pipeline, facets (@event.family, @usr.email, @sonrai.*), and a prebuilt dashboard covering PoD, JIT, identity, and cloud governance out of the box.

Setup

Complete the following steps to connect Datadog to Sonrai.

  1. Click the Connect Accounts button at the top of the page.
  2. Sign in to your Sonrai tenant.
  3. Click Connect to authorize the integration.

Sonrai immediately begins streaming audit, Permission on Demand (PoD), JIT session, and governance events into Datadog.

Uninstallation

To disconnect Sonrai from Datadog, follow the instructions for removing the webhook in the Sonrai documentation.

Once this integration has been uninstalled, any previous authorizations are revoked."

Additionally, ensure that all API keys associated with this integration have been disabled by searching for the integration name on the API Keys page.

Support

Need Help? Contact Sonrai Security Support

Further Reading