Quick Setup Reference
Supported Integrations
Okta
Full read/write accessQuery users, groups, apps, policies, and logs. Suspend users, clear sessions, manage groups.
AWS
Full read/write accessSearch CloudTrail, analyze IAM roles. Terminate instances, disable users, block IPs in WAF.
CrowdStrike
Full read/write accessQuery detections, ingest alerts. Contain hosts, update alert status.
Datadog
Read-onlySearch logs by user, IP, hostname, or custom query. Correlate with other integrations.
Wiz
Read-only + Deep linkingImport cloud security findings. Deep link from Wiz for instant AI analysis.
GitHub
Mostly read-onlyCheck branch protection, query audit logs. Can enable basic branch protection.
Google Workspace
Read-onlyQuery users, groups, devices, login activity, third-party apps. No actions available.
Slack
Alerts and botSend alerts to channels, respond to @mentions. Reset sessions (Enterprise Grid only).
Integration Capabilities
Connecting Integrations
All integrations are managed from Settings > Integrations.1
Navigate to Settings
Click Settings in the left sidebar, then select Integrations.
2
Select an integration
Find the integration you want to connect and click Connect.
3
Authorize access
Follow the specific setup flow for that integration (OAuth, API credentials, etc.).
4
Verify connection
Hiro will test the connection and show a success message.
Recommended Order
For the best experience, connect integrations in this order:1
Okta (or Google Workspace)
Identity first. Most investigations involve users, so start with your identity provider.
2
AWS
Cloud infrastructure. CloudTrail provides rich API logs that Hiro correlates with identity data.
3
CrowdStrike
Endpoint detection. Hiro automatically ingests detections and correlates with identity and cloud.
4
GitHub
Source code security. Analyze branch protection and audit repository access.
5
Slack
Alerts and bot. Receive security alerts and interact with Hiro from Slack.
Managing Integrations
View Status
Go to Settings > Integrations to see all connected integrations and their status:Disconnect
To remove an integration:- Go to Settings > Integrations
- Click on the integration
- Click Disconnect
Next Steps
Okta
Connect identity management.
AWS
Connect cloud infrastructure.