Reco
Reco is the leader in SaaS & AI Security, providing full visibility and control across your SaaS ecosystem and AI agents.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- Reco
Configuration parameters
- url — Server URL (e.g. https://host.reco.ai/api/v1) (required)
- api_token — JWT app token (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- incidentType — Incident type
- isFetch — Fetch incidents
- max_fetch — Max fetch
- source — Source
- before — Before
- after — After
- risk_level — Minimum risk level (e.g. MEDIUM fetches medium and higher)
- first_fetch — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)
- incidentFetchInterval — Incidents Fetch Interval
Commands (37)
- reco-add-comment-to-alert — Add a comment to an alert in Reco.
- reco-add-exclusion-filter — Add exclusion filter to Reco Classifier.
- reco-add-leaving-org-user-label — Tag a user as leaving org user in Reco.
- reco-add-risky-user-label — Tag a user as risky in Reco.
- reco-change-alert-status — update alert status in Reco.
- reco-get-3rd-parties-accessible-to-data-list — Get 3rd parties accessible to sensitive assets.
- reco-get-alert-ai-summary — Get alert ai summary from Reco.
- reco-get-apps — Get app discovery data from Reco. Fetches all available apps using pagination.
- reco-get-assets-by-id — Get all assets from Reco by id.
- reco-get-assets-shared-externally — Get files user has access to from Reco.
- reco-get-assets-user-has-access-to — Get all files user has access to from Reco.
- reco-get-files-exposed-to-email-address — Get files user has access to from Reco.
- reco-get-files-shared-with-3rd-parties — Get files shared with 3rd parties.
- reco-get-link-to-user-overview-page — Generate a magic link for reco UI (overview page).
- reco-get-private-email-list-with-access — Get Private emails with access.
- reco-get-risky-users — Get Risky Users from Reco.
- reco-get-sensitive-assets-by-id — Get all sensitive assets from Reco by id.
- reco-get-sensitive-assets-by-name — Get all sensitive assets from Reco by name.
- reco-get-sensitive-assets-with-public-link — Get all sensitive assets with public link from Reco.
- reco-get-user-context-by-email-address — Get user context by email address from Reco.
- reco-list-accounts — Lists accounts (SaaS user accounts) from Reco using the external API.
- reco-list-ai-agents — Lists AI agents detected by Reco using the external API.
- reco-list-app-instances — Lists integrated app instances (app portfolio) from Reco using the external API. Only returns instances with an active integration status.
- reco-list-audit-logs — Lists Reco platform audit logs using the external API.
- reco-list-business-units — Lists external business units from Reco using the external API.
- reco-list-devices — Lists devices from Reco using the external API.
- reco-list-events — Lists SaaS events from Reco using the external API.
- reco-list-exclusions — Lists alert suppression exclusion rules from Reco using the external API.
- reco-list-groups — Lists SaaS groups from Reco using the external API.
- reco-list-ip-addresses — Lists observed IP addresses from Reco using the external API.
- reco-list-posture-checks — Lists posture check definitions from Reco using the external API.
- reco-list-posture-issues — Lists posture issues from Reco using the external API.
- reco-list-saas-to-saas — Lists SaaS-to-SaaS OAuth grants and integrations from Reco using the external API.
- reco-list-threat-detection-policies — Lists threat detection policies from Reco using the external API.
- reco-resolve-visibility-event — Resolve an event in Reco Finding. Reco Findings contains aggregations of events. This command resolves the event in the Reco Finding.
- reco-set-app-authorization-status — Set authorization status for an application in Reco.
- reco-update-incident-timeline — Add a comment to an alert in Reco.