- Overview
- How to connect
- Automated checks
- Useful links
DSALTA connects to SentinelOne using read-only API access to collect compliance evidence automatically. DSALTA syncs the users in your SentinelOne management console (for access reviews) and application CVE risks. Data feeds into your Data Library modules.
Read-only access. DSALTA never modifies, creates, or deletes resources in your SentinelOne account.
DSALTA collects this integration’s data when you connect it — you can refresh it at any time with Sync from integrations on the Integrations page. The compliance checks below re-run once a day at 02:00 America/New_York.
What DSALTA reads
DSALTA reads the SentinelOne user roster — names, emails, creation dates and two-factor status, which appears on your Access page. DSALTA requests no role or account-state field from SentinelOne’s console user API, so every user is listed as an active User. It also reads application CVE risk findings, which appear on your Vulnerabilities page.It calls these SentinelOne endpoints:/web/api/v2.1/system/info/web/api/v2.1/users/web/api/v2.1/application-management/risks
Troubleshooting
Integration shows Disconnected
Integration shows Disconnected
There is no Reconnect button. Open Integrations → Connected, click Manage on the SentinelOne card, and check the Status tab — it shows either Connected and working properly or Connection issues detected. To restore a broken connection you must Disconnect and connect again, which permanently deletes the data and tests collected from SentinelOne. This can happen if the API token was revoked or rotated in the SentinelOne console.
Data is not syncing
Data is not syncing
Confirm the API token is still valid and the Console URL is correct, then click Sync from integrations on the Integrations page (Connected tab) — it refreshes every connected integration at once.
.png?fit=max&auto=format&n=tsMQJyneJ1xquFUo&q=85&s=4d401cc03b547d99b6f75a6bd170c334)



