Onboard Coveo ↗
For SaaS Security to detect posture risks in your Coveo instance, you must onboard your Coveo instance to SaaS Security. Through the onboarding process, SaaS Security connects to a Coveo API and, through the API, scans your Coveo instance for misconfigured settings. If there are misconfigured settings, SaaS Security suggests a remediation action based on best practices.
To access your Coveo instance, SaaS Security requires the following information, which you specify during the onboarding process.
| Admin API Key | A generated character string that identifies a Coveo administrator to the Coveo API. SaaS Security requires this API key to authenticate to the API. Required permissions: The Admin API key must be generated by an administrator of your organization. |
|---|---|
| Organization ID | A unique identifier that Coveo assigned to your organization. |
To onboard your Coveo instance, complete the following actions.
Step 1: Generate and Configure an Admin API Key for Your Organization
- As an administrator of your organization, log in to the Coveo Administration Console.
- In the left navigation pane, select API Keys. The API Keys item is located in the Organization section of the menu.
- On the API Keys page, click Add key. Coveo displays the Add an API key page, which provides steps for defining the API key.
- Follow the steps on the API key page to define your API key:
- On the Key purpose page, do not choose any of the predefined templates. Instead, select the Custom option to create a custom combination of privileges. Click Next.
- On the Identification page, specify a meaningful Name for the API key, such as SaaS Security Integration. You can optionally specify a longer Description. Click Next.
- On the Privileges page, grant the API key the following privileges. Click Next.
| Groups | View all |
|---|---|
| Organization | View |
- On the Configuration page, set the Expiration date to 1 year. Click Next.
- Do not modify the Access page. Click Next.
- Review the details of your key on the Review page and click Add API key. Coveo generates and displays your API key.
- Copy the API key and paste it into a text file.
Note: Do not continue to the next step unless you have copied the API key. You will provide this key to SaaS Security during the onboarding process.
Step 2: Identify Your Organization ID
- In the left navigation pane of the Coveo Administration Console, select Settings. The Settings item is located in the Organization section of the menu.
- On the Settings page, select the Organization tab.
- View the organization Details, which include your Organization ID.
- Copy your Organization ID and paste it into a text file.
Note: Do not continue to the next step unless you have copied the Organization ID. You will provide this information to SaaS Security during the onboarding process.
Step 3: Connect SaaS Security to Your Coveo Instance
By adding a Coveo app in Cortex, you enable SaaS Security to connect to your Coveo instance.
- Log in to Cortex.
- Select Settings > Data Sources and Integrations > Add New. You can use the Search bar to find the app you want to connect to.
- Click the Coveo tile.
- Under Capabilities, Enter a Name for your application.
- Select Security Posture under Default Capabilities and click Next.
- Under Connections, enter the Admin API Key and Organization ID
- Under Configurations, select a Sync Interval. Choose a meaningful Tag to distinguish between various applications in different environments.
- Click Next to complete the onboarding validation process.