---
title: Sonrai Security
description: >-
  Every privileged access decision in your cloud — PoD requests, JIT sessions,
  audits — visible in Datadog
breadcrumbs: Docs > Integrations > Sonrai Security
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Sonrai Security
Supported OS Integration version1.0.0
{% callout %}
# Important note for users on the following Datadog sites: us2.ddog-gov.com

{% alert level="info" %}
To find out if this integration is available in your organization, see your [Datadog Integrations](https://app.datadoghq.com/integrations) page or ask your organization administrator.

To initiate an exception request to enable this integration for your organization, email [support@ddog-gov.com](mailto:support@ddog-gov.com).
{% /alert %}

{% /callout %}
   Eliminate privilege risk — now visible in your Datadog dashboard.Getting to know the Cloud Permission Firewall
## Overview{% #overview %}

Sonrai's Cloud Permissions Firewall, the leading cloud PAM solution, gets cloud access under control, slashes the privileged attack surface, and automates least privilege - for both humans and agents - all without impeding DevOps. The Cloud Permissions Firewall uses privileged permission intelligence and usage monitoring to determine who needs what permissions in your cloud. Then, with one-click, it eliminates all unused privileged privileges across your entire multi-cloud estate. Just-in-time access and exceptions are granted to roles on the fly as new needs come up so development goes uninterrupted.

Sonrai sends its full audit and access lifecycle to Datadog as logs, giving security and platform teams a single pane over both the workloads they already observe and the privileged identities acting on them. Pivot from a Datadog alert to the Permission on Demand approvals that touched the same scope, build monitors on denial spikes or unusual JIT activity, and share dashboards with SecOps, DevOps, and audit teams - without leaving Datadog. The integration installs a parsed log pipeline, facets (@event.family, @usr.email, @sonrai.*), and a prebuilt dashboard covering PoD, JIT, identity, and cloud governance out of the box.

## Setup{% #setup %}

Complete the following steps to connect Datadog to Sonrai.

1. Click the **Connect Accounts** button at the top of the page.
1. Sign in to your Sonrai tenant.
1. Click **Connect** to authorize the integration.

Sonrai immediately begins streaming audit, Permission on Demand (PoD), JIT session, and governance events into Datadog.

## Uninstallation{% #uninstallation %}

To disconnect Sonrai from Datadog, follow the instructions for [removing the webhook](https://docs.sonraisecurity.com/cpf-public/developer/webhook-reference/cpf-webhook-intro/) in the Sonrai documentation.

Once this integration has been uninstalled, any previous authorizations are revoked."

Additionally, ensure that all API keys associated with this integration have been disabled by searching for the integration name on the [API Keys page](https://app.datadoghq.com/organization-settings/api-keys?filter=Seagence).

## Support{% #support %}

Need Help? Contact [Sonrai Security Support](mailto:support@sonraisecurity.com)

## Further Reading{% #further-reading %}

Additional helpful documentation, links, and articles:

- [Cloud Permissions Firewall - Sonrai | Enterprise Cloud Security Platform](https://sonraisecurity.com/cloud-security-platform/cloud-permissions-firewall/)
- [The Cloud Permissions Firewall for AI Agents](https://sonraisecurity.com/resource/the-cloud-permissions-firewall-for-ai-agents/)
- [PIB Group Cloud Access Control Case Study Sonrai Cloud Permissions Firewall - Sonrai](https://sonraisecurity.com/customer-success/pib-gains-real-control-over-cloud-access/)
