OktaIdentity & accessSync users, groups and MFA enrollment to validate access and authentication controls.
Command reads live configuration from the identity, cloud, endpoint, code and email tools you already pay for, and turns it into control evidence. No agents to babysit, no quarterly screenshot request.
Fig. 01 · Program metrics, read from live connections
An integration that only imports alerts gives you one more inbox. Command reads the configuration behind the tool, and asks whether the control you claim is actually implemented, so a connection produces evidence instead of noise.
You connect a tool once. Command reads its live configuration, decides which controls that configuration evidences, attaches the proof, and raises a finding the moment the configuration drifts away from what the control requires.
EntraActiveMicrosoft Entra IDLast synced Jul 24, 11:00 PM
AWSActiveAmazon Web ServicesLast synced Jul 24, 11:00 PM
CloudflareActiveCloudflareLast synced Jul 24, 11:00 PM
GCPActiveGoogle CloudLast synced Jul 24, 11:00 PM
WorkspaceActiveGoogle WorkspaceLast synced Jul 24, 11:00 PMCommand decides which controls a connection speaks to, attaches the live reading as evidence, and re-reads it nightly.
12 of 214 users are exempt from MFA.
That is not an alert. It is a control you are claiming, partially implemented, with the number attached and someone to fix it. The moment that number moves the wrong way, it is a finding with a due date.
Each connection is an OAuth consent screen and a read-only scope. No agents to deploy, no network changes, nothing for your team to maintain afterwards.
Command scans each connection to test whether the control is genuinely implemented, turning real configuration into evidence and drift into findings.
Live metrics land on the Command dashboard the moment a tool is connected. Findings route into the ticketing and on-call queues that own the fix, and briefings arrive in the channels your team already uses.
Twelve categories, weighted toward the systems that actually carry control evidence: identity, cloud, endpoint and code. More are added every release.
OktaIdentity & accessSync users, groups and MFA enrollment to validate access and authentication controls.
Microsoft Entra IDIdentity & accessPull identities and conditional-access policy as live evidence for your access controls.
Cisco DuoIdentity & accessVerify multi-factor coverage across the workforce and flag the exemptions automatically.
JumpCloudIdentity & accessValidate directory, SSO and device policy from a single connected source.
OneLoginIdentity & accessConfirm SSO and access-policy enforcement across your application estate.
Ping IdentityIdentity & accessEvidence SSO and MFA enforcement across the apps Ping protects.
ManageEngine AD360Identity & accessRead Active Directory accounts, groups and password policy as evidence for on-premises access controls.
1PasswordIdentity & accessValidate vault policy and confirm workforce credential hygiene across the team.
LastPassIdentity & accessConfirm password manager enrollment and vault security policy across users.
CyberArkPrivileged accessValidate privileged-access controls and vault policy across admin and service accounts.
BeyondTrustPrivileged accessEvidence privileged session control and least-privilege enforcement across the estate.
SaviyntIdentity governanceBring access certifications and entitlement reviews in as evidence for your access-review controls.
Amazon Web ServicesCloudScan account configuration for control validation and catch drift as it happens.
Microsoft AzureCloudValidate cloud posture and resource configuration against your control set.
Google CloudCloudCheck GCP configuration and IAM against control requirements continuously.
CloudflareCloudVerify edge, DNS and WAF configuration against your network control baseline.
WizCloud securityBring cloud risks and misconfigurations in as findings, tracked to closure.
Palo Alto NetworksNetwork securityRead firewall and threat-prevention policy to evidence perimeter controls at their current setting.
FortinetNetwork securityConfirm firewall rule, segmentation and threat-feed configuration across the FortiGate estate.
Cisco MerakiNetwork securityRead firewall, VLAN and wireless configuration across Meraki networks to evidence segmentation controls.
ZscalerSecure edgeEvidence web and private-access policy enforcement for every user, on or off the network.
NetskopeSecure edgeValidate SaaS, web and data policy across the apps your workforce actually reaches.
Cisco UmbrellaSecure edgeEvidence DNS-layer protection and web policy enforcement for every user and site.
CrowdStrikeEndpoint & devicePull endpoint coverage and detections into findings, mapped to your controls.
SentinelOneEndpoint & deviceConfirm agent coverage across the fleet and surface detections automatically.
Microsoft DefenderEndpoint & deviceValidate endpoint protection coverage and pull alerts into the program.
Cisco Secure EndpointEndpoint & deviceConfirm connector coverage across the fleet and pull malware detections into findings.
Microsoft IntuneEndpoint & deviceEvidence device compliance and MDM enrollment across managed endpoints.
JamfEndpoint & deviceEvidence Apple device compliance and MDM enrollment across the Mac fleet.
HuntressManaged EDRPull managed detection coverage and analyst-reviewed incidents into the findings queue.
QualysVulnerabilityBring vulnerability scan results in as tracked findings with owners and due dates.
Rapid7VulnerabilitySync vulnerability findings and remediation status into the security program.
TenableVulnerabilityIngest exposure data and track remediation through to closure.
AxoniusAsset managementReconcile the full asset inventory and surface the gaps your controls do not cover.
JiraTicketingPush remediation into the queues your team already works, with status synced back.
ServiceNowITSMRoute findings and changes through the ITSM workflows your org already runs.
PagerDutyOn-callTrack incidents against runbooks and connect on-call response to the program.
SlackCommunicationDeliver briefings, approvals and alerts where your team already talks.
Microsoft TeamsCommunicationSend briefings and approval requests straight to your Teams channels.
Google WorkspaceProductivitySync documents and evidence, and validate workspace security configuration.
SalesforceCRMValidate org security settings, permission sets and MFA enforcement across your Salesforce users.
Scan repository and org settings, and connect code controls to your program.
Scan repository, group and CI/CD settings, and tie code controls to your program.
BitbucketCodeScan repository and workspace settings, and tie code controls to your program.
SemgrepCodePull static analysis findings into the program and confirm scanning coverage.
SnykCodeBring dependency and code vulnerability findings into one remediation queue.
Aikido SecurityCodePull code, dependency and container findings into one queue, and confirm scanning coverage.
ProofpointEmail & awarenessConfirm email threat protection and data-loss policies are enforced across users.
MimecastEmail & awarenessValidate email security gateway and DMARC enforcement straight from live configuration.
Abnormal SecurityEmail & awarenessBring inbound email attack and account-takeover signals into findings for triage.
KnowBe4Email & awarenessEvidence security-awareness training completion across the workforce.
BarracudaEmail & awarenessConfirm email gateway protection and inbound threat filtering are enforced.
ForcepointData loss preventionConfirm data-loss-prevention and web-security policy enforcement across users.
CyberhavenData loss preventionConfirm data-flow policy coverage and bring exfiltration incidents in as findings.
Microsoft PurviewData governanceConfirm sensitivity labels, DLP policies and retention are enforced across Microsoft 365.
VeeamBackup & recoveryEvidence backup coverage and recovery readiness across protected workloads.
AWS BackupBackup & recoveryConfirm backup policy and retention are enforced across your AWS accounts.
SplunkSIEM & monitoringPull detection signals and log-based findings into a single remediation queue.
Microsoft SentinelSIEM & monitoringConfirm log ingestion and analytics-rule coverage, and bring incidents in as findings.
Elastic SecuritySIEM & monitoringEvidence detection-rule coverage and pull log-based findings into the remediation queue.
Confirm log and monitor coverage across the stack, and bring security signals in as findings.
HPE OpsRampIT operationsEvidence infrastructure monitoring coverage and route operational alerts into the program.
NebulockThreat huntingBring hunt results and detection coverage gaps in as findings, tracked to closure.
ZeroFoxExternal threatsTrack brand impersonation and external exposure alongside the rest of the program.
WorkdayHR & peopleSync the workforce record so access reviews and offboarding track real joiners and leavers.
HiBobHR & peopleSync the employee roster and joiner-mover-leaver events to keep access reviews current.
BambooHRHR & peoplePull HR records and onboarding events into your access review workflows.
GustoHR & peopleSync workforce records so access reviews and offboarding stay tied to real headcount.
RipplingHR & peopleSync headcount, devices and app access so joiner-mover-leaver events stay current.
No integration matches that. Tell us what you run and we will get it on the roadmap.
Showing all 69 integrationsMore added every release
Send us the stack. If something you depend on is not here yet, it goes on the roadmap, and we will tell you honestly whether it is weeks or quarters away.