Skip to main content
Panaptico connects to your identity, cloud, security, network, endpoint, and data systems so it can continuously verify your estate. You choose how each system is acquired: Ask for API pulls, Listen for streams, or Test for active probes. This guide explains how to connect providers, scope access, and interpret coverage.

Choose an acquire mode

Every provider connection uses one of three modes. Pick the mode that matches what you need to prove. You can use multiple modes for the same system. For example, Ask for daily IAM policy review and Test for weekly MFA path verification.

Provider categories and examples

Panaptico groups providers by the domain they cover. Scope access to the smallest set of resources you need to verify first. You can expand scope later, and missing permissions surface as coverage gaps rather than silent failures.

Identity

  • Okta — users, groups, devices, policies, sign-in logs
  • SailPoint — access certifications, roles, provisioning events
  • Entra ID (Azure AD) — users, conditional access policies, device compliance

Cloud

  • AWS — IAM, EC2, S3, VPC, CloudTrail, Config
  • Azure — RBAC, NSGs, Key Vault, Activity Logs
  • GCP — IAM, Compute, Firewall rules, Cloud Audit Logs

Security

  • CrowdStrike — device posture, prevention policies, detections
  • Wiz — cloud security posture, vulnerability findings
  • Palo Alto Networks — firewall rules, traffic logs, threat intelligence

Data

  • Snowflake — access history, query audit, role grants
  • Databricks — workspace configs, cluster policies, audit logs
  • ClickHouse — custom telemetry tables, audit streams

Networking

  • Cisco — switch and router configs, VLANs, ACLs
  • Juniper — firewall policies, routing tables, interfaces
  • Aruba — wireless configs, AP status, client associations

Endpoint

  • MDM platforms — device inventory, compliance state, patch level
  • EDR platforms — agent health, detection status, isolation state

Scoped access and coverage gaps

When you connect a provider, Panaptico requests only the permissions needed for the scope you define. If a permission is missing or a resource is excluded from scope, Panaptico does not guess. It marks the result as Unknown or Unobserved and includes the reason in the evidence.
  • Unknown — the provider returned data, but this specific field or resource was not in scope.
  • Unobserved — no data arrived within the expected window, often because the credential lacks permission or the stream is down.
This behavior ensures that missing evidence never becomes a manufactured pass. You see exactly what you can and cannot verify.

Add a provider in the dashboard

  1. Open https://alpha.panaptico.com and go to Providers.
  2. Click Add Provider and choose the system category.
  3. Select the vendor and enter connection details (API key, region, stream endpoint, or probe target).
  4. Define the scope: which resources, which fields, which regions or populations.
  5. Choose the acquire mode and polling interval.
  6. Save and verify the connection. Panaptico shows a coverage summary within minutes.

Next steps

Declaring intent

Define tracked fields, Signals, and Initiatives for the data you just connected.

System Sensor

Learn how always-on sensors read your estate field by field.