Prepare a pilot
- Choose a small set of devices approved for inventory and remote execution.
- Record each device’s provider ID, hostname, operating system, and owner.
- Create a dedicated credential with the permissions in the provider guide.
- Confirm that the provider agent is online and that remote execution is enabled for the operations you intend to use.
Connect and test
- Open Settings → Integrations and select the provider.
- Save the connection using the provider guide’s fields.
- Select Test connection and review the reported capabilities.
- Resolve failed capabilities before using operations that depend on them.
Import verified devices
Import can start scheduled inventory, which can run provider-backed helpers. Complete the pilot’s execution approval before selecting Import. SentinelOne keeps endpoint actions disabled until SentinelOne RemoteOps is explicitly enabled; passive provider sync and host selection alone do not enable it.- Open Device import, Host import for CrowdStrike, or Sensor import for LimaCharlie.
- Use the available filters and pagination to locate the pilot devices.
- Compare the provider ID, hostname, and platform with your pilot record.
- Select the intended devices and assign their owners where requested.
- Import the selection and check the resulting records in Devices.
Check inventory and actions
- Review the imported device’s inventory schedule and requested collection.
- Wait for a scheduled run or start an approved collection.
- Open the run and inspect each device’s result.
- Check the resulting AI products, MCP servers, skills, hooks, and configuration in Inventory, where supported by the collection.
- On one pilot device, test any repair or remediation action you plan to use.
Rotate or remove a connection
To rotate credentials, update the connection and run Test connection. For a configuration-only edit, leave the existing credential fields empty to retain the saved credential. For CrowdStrike and Defender, leave both the client ID and secret empty; credential rotation requires both values. Before disconnecting, stop the collection schedules and complete any required Forge-managed endpoint cleanup. Disconnecting a provider credential does not uninstall its agent or prove that earlier endpoint configuration was removed. Confirm cleanup results before revoking credentials needed to complete them.Compare collection with enforcement
Inventory, remote execution, and inline routing have separate prerequisites.
Do not infer prompt inspection from a process or DNS event. If collection
succeeds but records are not yet visible, compare the source timestamp with
projection freshness and report the delay; reinstalling the endpoint does not
repair a server-side projection backlog.