# Clarion Documentation ## Docs - [Welcome to Clarion](https://docs.clarion.cantina.xyz/introduction.md) - [Support](https://docs.clarion.cantina.xyz/support.md): How to reach the Clarion team when you run into a problem or need help. - [Introduction](https://docs.clarion.cantina.xyz/knowledge-base/introduction.md): A collection of answers to frequently asked questions. - [Getting started](https://docs.clarion.cantina.xyz/knowledge-base/getting-started.md): Set up your Clarion workspace, create your first agent, and start triaging issues. - [Introduction](https://docs.clarion.cantina.xyz/learn/introduction.md): An overview of how Clarion's core concepts fit together, from incoming events to issues to response. - [Issues](https://docs.clarion.cantina.xyz/learn/issues/introduction.md): How issues get created, and what you can do with one. - [Introduction](https://docs.clarion.cantina.xyz/learn/tasks/introduction.md): Track follow-up work, agent improvements, and operational actions across your team. - [Introduction](https://docs.clarion.cantina.xyz/learn/agents/introduction.md): Learn how agents triage issues, investigate them, and execute response actions in your security stack. - [Creating agents](https://docs.clarion.cantina.xyz/learn/agents/creating-agents.md): Build an agent from a template, customize its skills and monitors, and put it into production. - [Monitors](https://docs.clarion.cantina.xyz/learn/agents/monitors.md): Configure the event sources your agents listen to: webhooks, polling integrations, and active checks. - [Introduction](https://docs.clarion.cantina.xyz/learn/skills/introduction.md): Reusable playbooks that teach agents how to handle specific classes of tasks to a known standard. - [Introduction](https://docs.clarion.cantina.xyz/learn/tools/introduction.md): The integrations agents use to take action: send messages, change DNS, file tickets, and more. - [Introduction](https://docs.clarion.cantina.xyz/learn/notifications/introduction.md): Stay in the loop and respond when an agent needs your input across Slack, Teams, SMS, email, and more. - [Introduction](https://docs.clarion.cantina.xyz/learn/settings/introduction.md): Configure your workspace, manage members and access, and customize how your team works in Clarion. - [Members](https://docs.clarion.cantina.xyz/learn/settings/members.md): Invite teammates, set communication preferences, and manage workspace access. - [Workspace](https://docs.clarion.cantina.xyz/learn/settings/workspace.md): Name your workspace and customize agent system prompts. - [SSO](https://docs.clarion.cantina.xyz/learn/settings/sso.md): Enforce single sign-on through Microsoft Entra ID for centralized identity and access. - [MCP access](https://docs.clarion.cantina.xyz/learn/settings/mcp-access.md): Connect external MCP clients (Claude Code, Cursor, CI scripts) to your Clarion workspace. - [1Password](https://docs.clarion.cantina.xyz/integrations/1password.md): Connect 1Password to Clarion to monitor audit events, sign-in attempts, and item usage events from your 1Password Business account. - [Apex](https://docs.clarion.cantina.xyz/integrations/apex.md): Connect Apex to Clarion to ingest security findings from your repositories and code scanning workflows. - [AWS](https://docs.clarion.cantina.xyz/integrations/aws.md): Connect your AWS account to Clarion for CloudTrail events, CloudWatch alarms, GuardDuty findings, and IAM agent tools. - [AWS via EventBridge and SNS](https://docs.clarion.cantina.xyz/integrations/aws/eventbridge.md): Connect your AWS account to Clarion for CloudTrail events, CloudWatch alarms, GuardDuty findings, and IAM agent tools. - [CloudTrail via existing S3 bucket](https://docs.clarion.cantina.xyz/integrations/aws/cloudtrail-s3.md): Ingest CloudTrail events into Clarion from an existing S3 bucket using S3 event notifications and SNS — ideal for centralized, organization-wide logging. - [Cloudflare](https://docs.clarion.cantina.xyz/integrations/cloudflare.md): Connect Cloudflare to Clarion for Cloudflare Notifications webhooks, Logpush detection monitors, and optional API-powered DNS and analytics agent tools. - [Cloudflare Logpush](https://docs.clarion.cantina.xyz/integrations/cloudflare-logpush.md): Send Cloudflare firewall_events Logpush batches to Clarion for L7 DDoS-like detection windows. - [Confluence](https://docs.clarion.cantina.xyz/integrations/confluence.md): Connect Confluence Cloud to Clarion with an Atlassian service account so agents can read and search documentation for context during triage. - [CrowdStrike Falcon](https://docs.clarion.cantina.xyz/integrations/crowdstrike.md): Connect CrowdStrike Falcon to Clarion to poll detections and cases from your Falcon tenant and surface them as signals and issues. - [Custom MCP](https://docs.clarion.cantina.xyz/integrations/custom-mcp.md): Connect any MCP-compatible HTTP server to extend Clarion agents with your own tools. - [Datadog](https://docs.clarion.cantina.xyz/integrations/datadog.md): Connect Datadog so agents can query your logs, APM, events, and service catalog — and manage Datadog cases — during triage. - [Generic Webhook](https://docs.clarion.cantina.xyz/integrations/generic-webhook.md): Send events from any service to Clarion via HTTP webhook for AI-powered triage and response. - [Google Cloud](https://docs.clarion.cantina.xyz/integrations/gcp.md): Connect Google Cloud monitors and runtime credentials for agent triage. - [GCP Cloud Logging](https://docs.clarion.cantina.xyz/integrations/gcp-cloud-logging.md): Send Google Cloud audit logs to Clarion with one monitor per GCP project. - [GCP Cloud Monitoring](https://docs.clarion.cantina.xyz/integrations/gcp-cloud-monitoring.md): Send Google Cloud Monitoring incidents to Clarion from selected alert policies. - [GCP Security Command Center](https://docs.clarion.cantina.xyz/integrations/gcp-security-command-center.md): Send active Google Security Command Center findings to Clarion. - [Google Calendar](https://docs.clarion.cantina.xyz/integrations/google-calendar.md): Sync the on-call rotation to a Google Calendar so anyone on the team can see who is on call at a glance. - [Google Workspace](https://docs.clarion.cantina.xyz/integrations/google-workspace.md): Connect Google Workspace Alert Center to Clarion for real-time security alert ingestion and AI-powered triage. - [Grafana](https://docs.clarion.cantina.xyz/integrations/grafana.md): Connect Grafana to Clarion to receive alerting notifications for AI-powered triage and response. - [Guardrail](https://docs.clarion.cantina.xyz/integrations/guardrail.md): Connect Guardrail to Clarion to receive Guard alerts for AI-powered triage and response. - [Halo](https://docs.clarion.cantina.xyz/integrations/halo.md): Connect Halo (HaloPSA) to Clarion so agents can search, create, update, close, and comment on Halo tickets during alert triage. - [Hexagate](https://docs.clarion.cantina.xyz/integrations/hexagate.md): Connect Hexagate to Clarion to receive on-chain monitor alerts for AI-powered triage and response. - [Huntress](https://docs.clarion.cantina.xyz/integrations/huntress.md): Connect Huntress to Clarion for endpoint detection and response (EDR) data enrichment during alert triage. - [Hypernative](https://docs.clarion.cantina.xyz/integrations/hypernative.md): Connect Hypernative to Clarion for on-chain threat monitoring and AI-powered alert triage. - [incident.io](https://docs.clarion.cantina.xyz/integrations/incident-io.md): Connect incident.io to Clarion so agents can create alerts in incident.io and use its incident-management tools during triage. - [Iru](https://docs.clarion.cantina.xyz/integrations/iru.md): Connect Iru to Clarion so agents can look up devices, users, applications, and vulnerabilities from your Iru tenant during alert triage. - [Jira](https://docs.clarion.cantina.xyz/integrations/jira.md): Connect Jira Cloud to Clarion with an Atlassian service account so agents can create, look up, and search issues during triage. - [JumpCloud](https://docs.clarion.cantina.xyz/integrations/jumpcloud.md): Connect JumpCloud to Clarion to ingest directory and identity events via Insights Rule webhooks and enable agent-driven investigation and response using a JumpCloud service account. - [Linear](https://docs.clarion.cantina.xyz/integrations/linear.md): Connect Linear to Clarion so agents can create issues authored by the Clarion app, not by a person on your team. - [Microsoft Entra ID](https://docs.clarion.cantina.xyz/integrations/microsoft-entra.md): Connect Microsoft Entra ID (Azure AD) to Clarion to enforce enterprise single sign-on for your organization. - [Microsoft Sentinel](https://docs.clarion.cantina.xyz/integrations/microsoft-sentinel.md): Connect Microsoft Sentinel to Clarion to poll incidents as issues and give triage agents Sentinel and Defender investigation tools. - [Microsoft Teams](https://docs.clarion.cantina.xyz/integrations/microsoft-teams.md): Connect Microsoft Teams to Clarion so agents can post alerts to channels and chats, request approvals via Adaptive Cards, and reach the right people during incidents. - [Notion](https://docs.clarion.cantina.xyz/integrations/notion.md): Connect Notion to Clarion with a connection token so agents can search and read your docs, runbooks, and databases for context during triage. - [Okta](https://docs.clarion.cantina.xyz/integrations/okta.md): Clarion is a security operations platform that helps teams detect, investigate, and respond to identity and access threats. Install the Clarion Okta app from the Okta Integration Network to connect your Okta org to Clarion. - [PagerDuty](https://docs.clarion.cantina.xyz/integrations/pagerduty.md): Connect PagerDuty to Clarion so agents can page your on-call rotation through PagerDuty's Events API v2 during triage. - [SentinelOne](https://docs.clarion.cantina.xyz/integrations/sentinelone.md): Forward Singularity Endpoint threat detections from SentinelOne into Clarion as alerts. - [Slack](https://docs.clarion.cantina.xyz/integrations/slack.md): Install the Clarion app for Slack — what Clarion does, how it works inside Slack, where to find the Add to Slack button, and how your data is handled. - [Splunk](https://docs.clarion.cantina.xyz/integrations/splunk.md): Connect Splunk to Clarion so agents can forward an issue's details and original payload to your Splunk HTTP Event Collector (HEC) during triage. - [Tailscale](https://docs.clarion.cantina.xyz/integrations/tailscale.md): Connect Tailscale to Clarion to receive network and identity events — device approvals, key expiry, policy changes, and user lifecycle — as issues. - [Tenderly](https://docs.clarion.cantina.xyz/integrations/tenderly.md): Connect Tenderly to Clarion to receive smart contract monitoring alerts for AI-powered triage and response. - [Threat Intel](https://docs.clarion.cantina.xyz/integrations/threat-intel.md): Bring vulnerability advisories, supply chain threats, and security feeds into Clarion for AI-powered triage and response. - [Threat Intel webhook](https://docs.clarion.cantina.xyz/integrations/threat-intel/webhook.md): Send structured vulnerability advisories and supply chain threats to Clarion via a signed webhook for AI-powered triage. - [RSS Feed](https://docs.clarion.cantina.xyz/integrations/threat-intel/rss-feed.md): Subscribe Clarion to an RSS or Atom feed — security blogs, CERT/CSIRT bulletins, advisory feeds — and open an issue for each newly-published item. - [Clarion Terms of Service](https://docs.clarion.cantina.xyz/terms.md): Terms governing use of Clarion. - [Clarion Privacy & Legal Disclosures](https://docs.clarion.cantina.xyz/legal.md): Clarion-specific privacy and legal disclosures.