← All integrations

Security alerts, incidents, and logs.

You connect Microsoft Sentinel once, with your Microsoft Sentinel sign-in or an API key, and every workflow you build can use it.

Use it in a workflow

Tell the architect, the AI that builds your workflows, what you want done in your own words. For example:

When Microsoft Sentinel raises a high-severity incident, summarize it and alert the IT team.

Access and security

  • With a sign-in, you grant access on Microsoft Sentinel's own consent screen, and Malleable stores the resulting token, never your password.
  • An API key you enter never appears in chat and is hidden from the AI. A key saved as a reusable connection is stored with your Malleable account and only sent to Microsoft Sentinel.
  • Every run uses the connection the workflow's owner set up, so anyone who can run the workflow acts with that account's access in Microsoft Sentinel. Connect an account or key with only the access the workflow needs.
  • You can revoke access at any time in Microsoft Sentinel's settings.

Malleable is SOC 2 Type II certified and doesn't train AI models on your data. More in Security & data handling and our Trust Center.

Connection details for IT

Microsoft Sentinel publishes its own MCP server, which workflows connect to at https://sentinel.microsoft.com/mcp/data-exploration. Your Microsoft Sentinel admin may need to turn on API access first.

More in IT, security & developer tools