Skip to main content
Forge connects SentinelOne management and Data Lake APIs to bring endpoint identity, installed applications, security activity, and process and network evidence into your AI estate. SentinelOne-backed devices can receive agentless Forge coverage through the agent already deployed in your environment. When explicitly enabled, Forge uses RemoteOps for supported deployment and managed-configuration actions, validation, repair, credential rotation, removal, local inventory, and macOS session backfill and approved remediation. Management API and Data Lake reads continue independently of RemoteOps.

Sources

Management data and Data Lake telemetry are reported as separate capability lanes. One management token and one Data Lake key can serve both connection methods if the token has the corresponding permissions; you do not need to create duplicate credentials.

Connection methods

Device import and RemoteOps endpoint operations: Save the Management connection, then open Device import. Scheduled sync already imports visible devices and links users when SentinelOne supplies a resolvable identity. This tab selects hosts for endpoint operations. Forge copies the saved Management token into a separate server-side endpoint secret, so you do not enter it again. Endpoint actions stay disabled until you explicitly enable SentinelOne RemoteOps on that tab. RemoteOps also requires provider permission, exact agent and site binding, and enabled operation checks. A successful Management read does not prove the RemoteOps execute entitlement. Observe-only: Save the management connection on this page. Forge polls the Management API and Singularity Data Lake on a schedule for visible-scope inventory and passive telemetry. This method does not dispatch endpoint actions and does not require a webhook. A successful management or Data Lake read does not grant RemoteOps authority.

Connection

Create credentials

Use a dedicated service user in the SentinelOne management console, scoped to the account or sites that Forge should read. Generate its API token through the console’s service-user token controls and record the expiry. Role labels and API entitlements vary by tenant; the console’s own API documentation is the source for the exact endpoint permissions listed below. Do not substitute a Data Lake key for a Management token. Start with Management read access for the enabled lanes. If you also need RemoteOps, grant script upload, execution, result retrieval, and cleanup only to the approved scope, and enable that capability separately in Forge. SentinelOne’s RemoteOps overview describes its script library, payloads, and role-based execution controls. Create the optional Data Lake credential in your tenant’s Data Lake API-key settings and verify its region and query access before enabling that lane.

Setup

  1. Open Integrations → SentinelOne and save the management console URL and service-user token.
  2. Add the SentinelOne Data Lake key only when process, network, DNS, and event telemetry are required.
  3. Test tenant scope, endpoint inventory, applications, threats, activity, and telemetry independently. RemoteOps read checks do not prove write access.
  4. Run a sync to import devices, link resolved users, and collect each enabled telemetry lane.
  5. Open Device import and select hosts for endpoint operations. Enable RemoteOps separately for devices that will use SentinelOne for Forge endpoint actions.

Select devices for endpoint operations

Open Device import on the SentinelOne integration page. Forge uses the saved Management credential without asking for another token. Scheduled sync already imports canonical devices and resolved device-user links. Discover and select pilot hosts for endpoint operations, then check agent and site identity. If the Management token is rotated, select Refresh saved credential to update the endpoint connection. Host selection alone does not enable endpoint actions. Explicitly enable SentinelOne RemoteOps on the same tab to allow the supported operations on selected hosts. This also starts the shared scheduled local inventory for app, extension, MCP, skill, and related facts. macOS AI-session backfill and approved remediation use the same operation gate. A management sync or successful connection test does not prove that RemoteOps execution is available. The endpoint credential needs access to these SentinelOne API operations: SentinelOne role names and entitlements depend on the tenant. Use its console API documentation to check the service user’s role and RemoteOps entitlement. Scope the credential to the approved sites. A Data Lake key does not provide RemoteOps access. See Endpoint operations for supported verification, credential rotation, and cleanup.

Sync phases

A sync ends as completed, partial, failed, timed_out, canceled, or abandoned. Partial results remain visible with their lane-specific reason. Management inventory and Data Lake polling use separate schedules. Management provides visible agents and installed application metadata. Data Lake provides historical process, DNS, and connection observations. Those observations can identify a device and an AI destination, but do not by themselves identify the person who used it, prove a login session, or show a current process state. When RemoteOps is enabled, scheduled local inventory uses the shared endpoint collectors for apps, extensions, MCP servers, skills, and other supported facts. Management and Data Lake reads continue when RemoteOps is off or a provider permission is denied. Access-policy remediation still follows the existing approval and operation gates; finding detection alone does not execute it. Forge reconciles SentinelOne endpoints with directory and endpoint sources so the same computer appears as one device with complete source history. Each sync keeps successful data available while clearly identifying anything that needs attention.

Health

For every lane, Forge records operation key, category, status, observed count, page count, permission state, failure class, and recommended next action. An account-list permission denial can coexist with successful site-scoped agent and application reads. Request broader Management read scope only when coverage across accounts outside the token’s visible sites is required. A Data Lake checkpoint behind the current time means telemetry is still catching up; changing the credential does not clear that backlog.

Validate coverage and troubleshoot

First compare one pilot device’s provider agent ID, site, platform, and last-seen time with Forge. Verify Management and Data Lake results separately. For RemoteOps, run one supported inventory action and inspect its terminal task result; an accepted script upload alone is not execution proof. Local MCP, skill, and session evidence requires a supported collector, readable profile paths, and an available helper for that platform. Management application inventory or passive network events alone cannot establish those records. If a lane is denied, correct that lane’s permission or entitlement; do not expand unrelated permissions. For a stale checkpoint, check collection progress and provider throttling before reissuing credentials. After token rotation, refresh the saved endpoint credential when RemoteOps uses a copied credential.

Platform coverage

This is the Forge operation surface, not a promise that every provider tenant or endpoint grants execution. Each action still requires a compatible published helper, provider permissions, an online agent, and the target/profile evidence required by that collector. Provider inventory can include platforms without Forge remote-operation support.