Integrations/Kaseya SaaS Alerts
SECURITY INTEGRATION

Every SaaS Alerts ticket, investigated.

Neo reads the event behind each SaaS Alerts ticket, checks the user's other activity and account, and writes its verdict in an internal note. Suppressions and Respond actions run only when you allow them.

01Capabilities

What Neo does with Kaseya SaaS Alerts.

01
INVESTIGATE

The event behind the ticket

Neo finds the event from the ticket's Event ID, with its severity, IP, location and operation, then reads the user's other events around it.

02
CONTEXT

Account and client checks

Checks whether the account is enabled and holds an admin role, reads the client's approved locations, and counts how often the event type fires for that client.

03
RESPOND

Suppress and respond

Suppresses a recurring event for one client, sets approved locations, and runs Respond actions on Microsoft 365 accounts. Every Respond action asks a technician first.

02Workflows

Concrete work Neo handles in Kaseya SaaS Alerts.

ALERT TRIAGE

An alert ticket, with a verdict

Neo looks up the event, reads the user's recent activity, weighs the severity and IP threat flags, and writes what it found in an internal note.

KNOWN-GOOD

Quiet an expected event

An event your team confirms is expected gets a suppression for that one client or for named users, with a reason and an end date.

LOCATIONS

Approve a new location

A user starts to work from a new country or office. Neo adds the country, IP range or ASN to the approved locations, so that activity stops raising alerts.

CONTAIN

Block a risky account

When the evidence points to a compromise, Neo proposes a Respond action such as Block Sign In. A technician approves it, then Neo confirms the result.

03Setup

Live in under an hour.

Connect, configure, go. No code, no long implementation.

01

Connect SaaS Alerts

Copy the partner API key from Settings > API in SaaS Alerts and save it in Neo. One key covers every client in your account. Neo checks it before it saves.

02

Set access per agent

Pick Read Only, Helpdesk, IT Admin or Full Automation for each agent, or set each area by hand. Read Only is enough to investigate alerts.

03

Go live

Check the Organization Mapping tab, then tell your triage agent what to do with SaaS Alerts tickets. Its findings land on the ticket as internal notes.

FAQ

Questions about the Kaseya SaaS Alerts integration.

What can Neo change in SaaS Alerts?+

Only what you allow per agent. With write access, Neo can manage suppressions, approved locations, Respond rules, customers, connections, devices, PSA mapping and reports, and run Respond actions on Microsoft 365 accounts. With the Read Only profile it changes nothing.

Which actions need technician approval?+

Under every profile, a technician approves each Respond action on an account, each approve, reject or manual remediation of a rule trigger, deleting a customer or an application connection, and turning Respond off. The profile you pick decides the rest. Neo also never sends a suppression that covers every client.

What credentials does Neo need?+

One SaaS Alerts partner API key, from Settings > API > Manage API. It covers every client in your SaaS Alerts account. Do not reset the key after you connect it, or Neo loses access until you save the new one.

How are SaaS Alerts customers matched to PSA companies?+

Neo matches by name first, then by the domain of the customer's contact email, then with AI for the rest. Name matches go straight to your agents. Domain and AI matches wait on the Organization Mapping tab for you to confirm, and you can set any mapping by hand.

Ready to wire up Kaseya SaaS Alerts?

14-day free trial. No credit card. Live in under an hour, right inside your stack.