# Welcome

From security questions to solutions in minutes

Sola is an AI-powered security solution that connects to your tech stack, automatically builds your complete security system, and uncovers what matters most.

## **How can we help?**

*Ask your question and our AI assistant will guide you.*

<p align="center"><button type="button" class="button primary" data-action="search" data-icon="magnifying-glass">Search for anything...</button></p>

***

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Quickstart</strong></td><td>No fluff, just actions</td><td><a href="/files/ytVYW9ojotx8cL41dssm">/files/ytVYW9ojotx8cL41dssm</a></td><td><a href="/pages/pKC9eBv6wESz09LAfQfv">/pages/pKC9eBv6wESz09LAfQfv</a></td></tr><tr><td><strong>Sola AI</strong></td><td>Security intelligence, at your fingertips</td><td><a href="/files/CI8jPgxIF3egrwcjlhHF">/files/CI8jPgxIF3egrwcjlhHF</a></td><td><a href="/pages/7XPYh4JoRc5ho7QvZ6em">/pages/7XPYh4JoRc5ho7QvZ6em</a></td></tr><tr><td><strong>What's New</strong></td><td>Stay up to date</td><td><a href="/files/lQwIVb3qrkG79suW43E5">/files/lQwIVb3qrkG79suW43E5</a></td><td><a href="/pages/NfgYJjEiAxoQWOzhnUyR">/pages/NfgYJjEiAxoQWOzhnUyR</a></td></tr><tr><td><strong>Data Sources</strong></td><td>Plug in your data</td><td><a href="/files/hqsmmJOhlP6t0mTm78Gm">/files/hqsmmJOhlP6t0mTm78Gm</a><a href="/files/hqsmmJOhlP6t0mTm78Gm">/files/hqsmmJOhlP6t0mTm78Gm</a></td><td><a href="/pages/vYlag84wtwlnfmuULiEh">/pages/vYlag84wtwlnfmuULiEh</a></td></tr><tr><td><strong>Connectors</strong></td><td>Act on findings</td><td><a href="/files/67Rcv0hS1GZGpd1p5QuO">/files/67Rcv0hS1GZGpd1p5QuO</a></td><td><a href="/pages/rbkjXI8u4MU5mYr6onVw">/pages/rbkjXI8u4MU5mYr6onVw</a></td></tr><tr><td><strong>FAQs</strong></td><td>You're in good company</td><td><a href="/files/UQxLALqAQpcxCGKbhMl2">/files/UQxLALqAQpcxCGKbhMl2</a><a href="/files/UQxLALqAQpcxCGKbhMl2">/files/UQxLALqAQpcxCGKbhMl2</a></td><td><a href="/pages/l475eAXRVB6STtjIdCmm">/pages/l475eAXRVB6STtjIdCmm</a></td></tr><tr><td><strong>Security and Privacy</strong></td><td>We practice what we preach</td><td><a href="/files/mQVUegGtWoGjIhhBeOiG">/files/mQVUegGtWoGjIhhBeOiG</a></td><td><a href="https://trust.sola.security/">https://trust.sola.security/</a></td></tr><tr><td><strong>Templates</strong></td><td>Start with a template</td><td><a href="/files/KgdqLvPGgoLpUpOIiVg5">/files/KgdqLvPGgoLpUpOIiVg5</a></td><td><a href="/pages/EhdsUerkrtXYzSxUPqhP">/pages/EhdsUerkrtXYzSxUPqhP</a></td></tr><tr><td><strong>Glossary</strong></td><td>Jargon, decoded</td><td><a href="/files/Mbzdjdw9ohXQKl6WZbgx">/files/Mbzdjdw9ohXQKl6WZbgx</a></td><td><a href="/pages/tzp59YuwcbH9pWjfXZXJ">/pages/tzp59YuwcbH9pWjfXZXJ</a></td></tr></tbody></table>


# Quickstart

Create your own security solutions

&#x20; Sola makes it easy to get security done, your way. Follow these steps to get up and running.

## **Step-by-step guide**

{% stepper %}
{% step %}

### Connect your [data sources](/integrations/data-sources)

You’ll need them to answer your questions.

{% hint style="info" %}
Don’t have access to connect your data now? Skip this step and complete it later.
{% endhint %}

<picture><source srcset="/files/btWV6zrR9zQl8acnTAGW" media="(prefers-color-scheme: dark)"><img src="/files/bFQXS9b9YzQeGnoW8CN3" alt="Connect your first data source"></picture>
{% endstep %}

{% step %}

### Chat with [Sola AI](/getting-started/sola-ai)

Describe your security challenge. Sola AI will guide you as you explore your environment, and uncover what matters most.

{% hint style="success" %}
**Pro tip:** Use our ready-made prompts to easily get started.
{% endhint %}

![](/files/eUDFeoD0Rqr1gmXF5NY3)
{% endstep %}

{% step %}

### Explore [triggered alerts](/workspace/projects/alerts) and [canvases](/workspace/projects/canvases) <a href="#step-8-set-up-alerts" id="step-8-set-up-alerts"></a>

See what Sola uncovered, and start reviewing to investigate and resolve issues.

<picture><source srcset="/files/0yW2moJ44bKCGy9cJgtr" media="(prefers-color-scheme: dark)"><img src="/files/dsa6ImNcFKMYdY5LGw53" alt="Set up alerts to trigger events based on your queries"></picture>   ![](/files/txYPayy22F9qeWaXvuHA)
{% endstep %}
{% endstepper %}


# Overview

Security is now simple

## Welcome to Sola!

Sola is an AI-powered cybersecurity platform that allows practitioners of all skill levels generate security solutions in minutes.

Here you can create the security space that you need.

{% tabs %}
{% tab title="Answer security questions" %}
From **everyday risks to large-scale threats**, every security solution begins with a question.

Create your own security solution by asking questions.
{% endtab %}

{% tab title="Cover missing security gaps" %}
Even with the best-of-breed security tools, there’s always going to be a **missing piece**!

Create your own security solution by defining what's missing.
{% endtab %}

{% tab title="Discover expert-built security solutions" %}
You don’t have to start from scratch.

Create your own security solution by using [ready-to-use security templates](/getting-started/templates), and customize them to fit your needs.
{% endtab %}
{% endtabs %}

### ![](/files/u9RHZRvhr64TfNP6IjXP) ***This is where Sola comes in.***

Sola provides you with a studio to get answers to your security questions, and build your custom security tool. All within an easy to use, collaborative environment that incorporates AI tools throughout.

{% embed url="<https://sola.security/blog/cybersecurity-trends-and-predictions/>" %}

## How Sola works

Sola users create and customize their own unique security solutions their way, without any barriers that large-scale security solutions have.

Sola lets you create custom security solutions for your specific security use cases.

![](/files/u9RHZRvhr64TfNP6IjXP) **Projects and Chats are composed of 4 building blocks.**

[**Queries**](/workspace/projects/queries) for data inquiry. Use queries to **create**, **view**, and **share data insights** that answer your cyber security questions.

[**Canvases**](/workspace/projects/canvases) for data visualization. Create canvases to build **dashboards**, **reports**, and **interactive views** that display your insights and results in easy-to-understand **tables**, **charts**, and **graphs**.

[**Alerts**](/workspace/projects/alerts) for monitoring and alert rules. Convert your important questions into alerts to **track security risks and get notified** when important events occur.

[**Workflows**](/workspace/projects/workflows) for **automation** and **remediation**. Automate security actions to **respond faster and reduce manual effort**.

## Lumina Signals

[Lumina Signals](/workspace/lumina-signals) is Sola's proactive intelligence layer. Every day, it analyzes your entire connected environment and surfaces a ranked feed of pre-investigated security risk signals, each with context, reasoning, blast radius, and recommended actions, ready to act on.

## Pricing and plans

Sola offers four plans designed for individuals, teams, and organizations of all sizes.

![](/files/u9RHZRvhr64TfNP6IjXP) **Shoreline (Free) - Perfect for trying out Sola and personal projects**

Get started with Sola's AI-powered security platform at no cost. Connect your data, chat, build projects, and explore core AI features.

![](/files/u9RHZRvhr64TfNP6IjXP) **Tidewater - For solo professionals and small teams ready to scale**

Everything in Shoreline, plus increased capacity, more data sources, agentic workflows, and expanded AI usage for growing security and automation needs.

![](/files/u9RHZRvhr64TfNP6IjXP) **Open Sea - For teams and departments running mission-critical applications**

Everything in Tidewater, with higher limits, more data sources, onboarding support, email support, and expanded team capacity.

![](/files/u9RHZRvhr64TfNP6IjXP) **Deep Blue - For organizations with custom requirements and scale**

Tailored plans with dedicated support, custom limits, unlimited data sources and team members, and enterprise-grade security, compliance, and deployment options.

{% hint style="info" %}
For full details, visit our [pricing page](https://sola.security/pricing/).
{% endhint %}

{% embed url="<https://sola.security/pricing/>" %}

### Credit and usage types

Sola uses **AI credits**, **workflow credits**, and **data records** for managing usage.&#x20;

**AI credits (copilot)** are the units Sola uses to represent actions completed by [Sola AI](/getting-started/sola-ai), including asking questions, generating canvases, creating workflows, or refining logic. Each credit represents an average AI interaction. Simple tasks use fewer credits, more complex tasks use more. *AI Credits refresh weekly.*

**Workflow credits** represent AI usage for running [agentic workflows](/workspace/projects/workflows). Each credit represents a typical workflow execution across its steps. *Workflow credits refresh weekly.*

**Data records** represent the data entries Sola processes from your connected [data tables](/integrations/data-sources#data-source-tables). Each row from a connected data source is counted as one data record. *Data record limits reset daily.*

Sola plans offer varying allowances for AI credits, workflow credits, and data records. Higher tiers provide increased limits to meet your team’s usage and growth.

{% hint style="info" %}
**Credit resets**\
Credit allowances vary by plan and reset on schedule. Credits do not roll over.
{% endhint %}

<figure><img src="/files/395zJYJ5odFuW6gbxw6H" alt="Create security solutions, your way"><figcaption><p>Create security solutions, your way</p></figcaption></figure>


# Sola AI

Build security solutions with AI security expertise

## The intelligence behind your security

Sola AI is your built-in security expert. Use it to uncover security risks and generate insights in [chats](/workspace/chats), and build custom security [projects](/workspace/projects) tailored to your security use cases.

Sola AI guides you as you explore your environment, and uncover what matters most.

<figure><img src="/files/9SHiql8HJ5YbYZNXXbed" alt="Chat with Sola"><figcaption><p>Chat with Sola AI</p></figcaption></figure>

{% hint style="info" %}
**Pricing and plans**\
Learn more about your [AI credits and usage](#ai-credits-and-usage).
{% endhint %}

{% embed url="<https://sola.security/pricing/>" %}

## Ask Sola from anywhere

Connect [Sola's MCP to any MCP-compatible tool](/getting-started/sola-ai/sola-mcp) and your full security environment comes with it. Bring [Sola into Slack](/getting-started/sola-ai/sola-slack-ai-assistant) and get the same intelligence directly in your channels.

**One connection to Sola's intelligence layer gives you and any AI agent you've built full visibility across every connected source.**

<div><figure><img src="/files/JSOTddU0xcxirWJSnh5D" alt="Sola AI Assistant in Slack"><figcaption><p>Sola AI Assistant in Slack</p></figcaption></figure> <figure><img src="/files/vWZd1vM2uefcwMfevJHM" alt="Sola MCP"><figcaption><p>Sola MCP</p></figcaption></figure></div>

## Build security projects

Start with a security concern and get a project, complete with queries, dashboards, and alerts tailored to your use case, in minutes.

### How it works

Create a new project and submit a prompt describing your security challenge. Sola AI will work with you to build out the queries, dashboards, and alerts tailored to your use case.

{% hint style="info" %}
**Sola AI prompt tip** ![](/files/DESMoC6l1Gr9uaynao5N)\
Use our ready-made prompts to easily get started.
{% endhint %}

As you work on your project, you’ll see a full summary of what the project monitors, why it matters, the security context, and key security insights from your environment.

<figure><img src="/files/eUDFeoD0Rqr1gmXF5NY3" alt="Build an app with Sola AI for your security needs"><figcaption><p>Build a project for your security needs</p></figcaption></figure>

## Gain deeper insights into your security posture

Each [project](/workspace/projects) includes a dedicated Sola AI copilot to help you investigate your environment and uncover security risks, gaps, and exposures across your connected data sources. Sola AI provides detailed, actionable insights to help you understand and prioritize remediation.

### How it works

Go to your [project](/workspace/projects), and ask a security question. Sola AI will analyze your connected data and provide detailed insights about what was detected, why it matters, and the queries used to generate these insights.

## Graph-enhanced research

Uncover deep insights with [Sola's security graph](/getting-started/sola-ai/security-graph), an advanced reasoning intelligence layer in Sola AI that maps the relationships and connections between resources, security controls, and risks across your connected data sources. It provides complete, grounded answers to complex questions, backed by visual evidence and contextual analysis.

## Expand your project with new queries, canvases, alerts, and workflows

#### ![](/files/DESMoC6l1Gr9uaynao5N) Grow your project, one prompt at a time.

Use the Sola copilot to generate new queries, alerts, and canvases directly within any existing project. This allows you to add more coverage, track new risks, or build purpose-specific views

{% hint style="info" %}
**Sola AI prompt tip** ![](/files/DESMoC6l1Gr9uaynao5N)

Ask specifically for the queries, alerts, or dashboards you want to build.

For example: “Create a dashboard for my executive team that summarizes open critical vulnerabilities.”
{% endhint %}

### How it works

Go to your [project](/workspace/projects) and describe what you need, such as an insight, alert flow, or dashboard. Sola AI will create the new resources based on your prompt, and add them for you.

Asking for canvases or alerts also creates the required queries.

**Use this to**:

* Build multiple canvases in a single prompt. For example: "Create a comprehensive security dashboard for my CISO, and a high-level one for my CEO"
* Keep everything you need in one project.
* Add use-case-specific dashboards for different teams.\
  For example: DevOps, Engineering, Executives
* Expand existing projects as your risk coverage grows.

{% hint style="info" %}
**Sola AI in queries**

Access Sola AI from within any [query in the queries tab](/workspace/projects/queries) to explain, refine, or optimize individual queries as you build. It can help you identify the right tables and columns that contain the data you need or refine SQL syntax for more accurate results.
{% endhint %}

## AI credits and usage

AI credits power everything you do with Sola AI, from quick questions to full project generation.\
Simple tasks use only a few credits, while deeper reasoning and heavier builds use more.

Each AI operation, such as exploring data, creating canvasses and workflows, consumes credits based on complexity.

**Your AI credit allowance refreshes weekly** on the same day your subscription began.\
There is no rollover.

{% hint style="info" %}
***Need more room to build?*** [Upgrade your plan](https://sola.security/pricing/) for higher weekly limits.
{% endhint %}

{% embed url="<https://sola.security/pricing/>" %}


# Security Graph

AI with unparalleled visibility into your environment

Sola's **security graph** is an advanced reasoning intelligence layer in [Sola AI](/getting-started/sola-ai) that maps the relationships and connections between resources, security controls, and risks across your connected data sources.

It uses a **proprietary analysis infrastructure and framework**, to answer complex questions with a holistic view, contextualized data, and visually-backed responses.

This allows Sola to surface deep insights, providing:

* **Enterprise-grade reasoning** - Responses are grounded in a security graph built from Sola's domain expertise.
* **Valuable insights for complex cross-environment analysis** - Each insight is traceable to relationships across entities and controls.
* **Security intelligence built-in** - Combines context-aware reasoning with proven knowledge of risk, exposure paths, and misconfigurations.
* **Deep analysis, intuitive results** - Sola analyzes and maps your assets, identities, and security controls to surface connections and risks across your environment.

{% hint style="info" %}
**Pricing and plans**\
Security graph is available on [paid plans](https://sola.security/pricing/).&#x20;
{% endhint %}

{% embed url="<https://sola.security/pricing/>" %}

## What security graph reveals

Sola's security graph goes beyond basic analysis to provide you with contextual, robust, precise insights based on your connected data.

Each insight is complete and grounded in real security context, validated through identified connections between assets and controls.

* **Connection insights** - Surface previously unseen connections and dependencies between different types of environments and assets.
* **Toxic combinations** - Detect risky interdependencies across platforms (e.g. overly permissive GitHub access combined with exposed AWS assets).
* **Blast radius for critical issues** - Understand the full scope of impact from a single misconfiguration or compromised entity.
* **Security impact on infrastructure** - Trace how issues in one part of your environment affect services, workloads, and teams elsewhere.

## How it works

Sola's security graph is built from proprietary knowledge of cybersecurity architecture and risk patterns, mapping the connections between a wide range of asset types, security controls, and their relationships.

This knowledge is combined with your connected data sources to create a graph of real-time entities (such as users, roles, buckets, workloads, and more) and security controls (such as IAM, access levels, encryption, MFA, and more).

When analyzing your environment, Sola AI:

* Identifies relevant asset types.
* Discovers meaningful relationships and connections across systems.
* Generates grounded traceable insights based on entity interconnections.

### Lumina Signals and the security graph

[Lumina Signals](/workspace/lumina-signals) is powered by Sola's intelligence layer, a combination of AI reasoning, graph analysis, and security domain expertise that processes signals across all your connected data sources. It maps your environment as a relational graph, understanding how resources interact, exposing dependencies, access paths, and potential blast radius.

{% hint style="info" %}
Lumina Signals is [available on paid plans](https://sola.security/pricing/).
{% endhint %}

{% embed url="<https://sola.security/pricing/>" %}

The Graph View tab within each signal provides a visual representation of the security graph behind it, showing the assets involved, their relationships, and potential attack vectors.

<figure><img src="/files/5196ToBTyS6WGCtdTuoU" alt="Lumina - Graph View"><figcaption><p>Lumina Signals - Graph View</p></figcaption></figure>

Every signal is the result of security graph analysis across your entire connected environment, compressing thousands of data points into focused, ranked risk clusters. Each signal arrives with context, reasoning, blast radius, and recommended actions already assembled.

<p align="right"><img src="/files/u9RHZRvhr64TfNP6IjXP" alt=""> <strong>Learn more about</strong> <a href="https://sola.security/insights/ai-native-asset-intelligence/"><strong>AI-native asset intelligence</strong></a></p>

***

## FAQs

### What is Sola's security graph?

Sola's security graph is an advanced reasoning intelligence layer in Sola AI that maps the relationships and connections between resources, security controls, and risks across your connected data sources. It uses proprietary knowledge of cybersecurity architecture to surface context, trace risk paths, and identify cross-environment dependencies.

### How does the security graph work?

The security graph combines Sola's built-in security knowledge with real-time data from your connected sources, creating a relational map of entities and controls. When analyzing your environment, it identifies asset types, discovers meaningful relationships across systems, and generates grounded, traceable insights.

### What makes the security graph different from regular analysis?

Regular analysis looks at individual data points within a single system. The security graph maps relationships across your entire environment, revealing cross-platform dependencies, toxic combinations, and blast radius from a single misconfiguration or compromised entity.

### Where do I see the security graph in action?

The security graph powers [Lumina Signals](/workspace/lumina-signals), Sola's daily feed of security risk signals. Each signal includes a Graph View tab with a visual map of the assets involved, their relationships, and potential attack vectors.


# Sola MCP

Bring your full security environment into any AI assistant

The **Sola MCP (Model Context Protocol)** server connects your AI assistant directly to your Sola workspace, giving you access to your security data, connected sources, and intelligence without leaving your workflow.

Use it to explore your environment, investigate security risks, and run queries using natural language, from any AI-powered tool.

Query your security data from any AI tool.

<div><figure><img src="/files/kEOUo8kPpvDW4LgURhvP" alt="Sola MCP"><figcaption></figcaption></figure> <figure><img src="/files/vWZd1vM2uefcwMfevJHM" alt="Sola MCP"><figcaption></figcaption></figure></div>

## **Supported clients**

**Claude**, **Claude Code**, **Cursor**, **OpenAI Codex**, **VS Code**, and **any MCP-compatible tools**.

[See how to connect your client below.](#connect-your-client)

## **Security and permissions**

The Sola MCP server provides read-only access to your Sola workspace, including your connected data sources, projects, queries, and vendor tables. Your data can never be modified through the MCP. Access is scoped to the workspace the token was generated in.

## Available tools

The Sola MCP exposes the following tools to your AI assistant.

<table><thead><tr><th width="210.223876953125">Tool</th><th>Description</th></tr></thead><tbody><tr><td><p><strong>List Projects</strong></p><p>(<code>list_projects</code>)</p></td><td><p>List all projects in your workspace with their IDs and names.</p><p>Returns project IDs, names, and direct links.</p><p>Use <code>get_project_details</code> for full information, or <code>explore_data</code> to query an project's data directly with natural language.</p></td></tr><tr><td><strong>Get Project Details</strong> (<code>get_project_detail</code>s)</td><td><p>Return full details about an project, including integrations, connectors, vendors, tables, queries, canvases, and monitor rules.</p><p>Each vendor has integrations with statuses. Tables may be in different states per integration: syncing, disabled, or missing.</p></td></tr><tr><td><strong>Get Project Queries</strong> (<code>get_project_queries_tool</code>)</td><td><p>Retrieve saved SQL queries for a specific project.</p><p>Returns query names, descriptions, SQL, referenced tables, and whether they use cross_revisions (historical view).</p><p>Use <code>list_projects</code> first to find the <code>project_id</code>.</p></td></tr><tr><td><strong>Get Vendor Tables</strong> (<code>get_vendor_tables</code>)</td><td><p>Discover all vendor tables available in your workspace.</p><p>Optionally filter by vendor name.</p><p>Tables are populated by vendor integrations.<br>Use this to see what data is available before running a query.</p></td></tr><tr><td><strong>Get Vendor Schemas</strong> (<code>get_vendor_schemas</code>)</td><td><p>Get column-level schema details (names, types, descriptions) for specific vendor tables.</p><p>Use this to discover columns before writing SQL queries.</p></td></tr><tr><td><strong>Execute SQL Query</strong> (<code>execute_sql</code>)</td><td><p>Run read-only SQL queries directly against your project data source tables. </p><p>Only SELECT statements are allowed, with safety validation.</p><p>Use this for specific queries. </p><p>For natural language exploration, use <code>explore_data</code>.</p></td></tr><tr><td><strong>Explore Data</strong> (<code>explore_data</code>)</td><td><p>Ask natural language questions about your environment, security posture, compliance, and more. </p><p>Uses Sola's graph intelligence and security domain expertise for complex queries.</p><p>Also ideal when you want to explore in natural language without writing SQL.</p></td></tr></tbody></table>

## Example prompts

Here are a few examples of what you can ask your AI assistant using the Execute SQL Query and Explore Data tools.

{% code title="Explore your environment (explore\_data)" overflow="wrap" %}

```
What data sources do I have connected?
```

{% endcode %}

{% code title="Investigate access (explore\_data)" overflow="wrap" %}

```
Who has admin access across my cloud accounts?
```

{% endcode %}

{% code title="Review posture (explore\_data) " overflow="wrap" %}

```
What are the most critical misconfigurations in my AWS environment?
```

{% endcode %}

{% code title="Analyze identity (explore\_data) " overflow="wrap" %}

```
Which users have not logged in for more than 90 days? 
```

{% endcode %}

{% code title="Check compliance (explore\_data)" overflow="wrap" %}

```
Show me all resources that are out of compliance with our policies.
```

{% endcode %}

{% code title="Run a specific query (execute\_sql) " overflow="wrap" %}

```
Run the following SQL:
SELECT name, region, public_access_block_enabled
FROM aws_s3_bucket
WHERE public_access_block_enabled = false 
```

{% endcode %}

{% code title="Ask your AI to write and execute (execute\_sql)" overflow="wrap" %}

```
Write and execute an SQL query that shows all IAM users who have not logged in for more than 90 days.
```

{% endcode %}

## Connecting your client

To connect your client, follow the steps below for your tool. When you connect, you'll be prompted to log in to Sola, or create a new account if you don't have one yet.

{% hint style="info" %}
**Workspace scope**

Each connection is scoped to a single workspace. The MCP can only access one workspace at a time.
{% endhint %}

{% hint style="info" %}
**Project permissions**&#x20;

MCP actions on a project are limited by your role on that project. For example, if you have Viewer access on an project, Execute SQL Query will fail for that project.
{% endhint %}

### Connect Your Client

{% tabs %}
{% tab title="Claude" %}
1\. From your settings, go to ***Connectors*** and click ***Add custom connector***.

2\. Add the name and server URL, and click ***Add***.

{% code overflow="wrap" %}

```
Name: Sola
Remote MCP server URL: https://api.sola.security/mcp
```

{% endcode %}
{% endtab %}

{% tab title="Claude Code" %}
1\. Run the following command in your CLI:

{% code overflow="wrap" %}

```shellscript
claude mcp add --transport http \
    --callback-port 9876 \
    sola "https://api.sola.security/mcp"
```

{% endcode %}

2\. Start a Claude session using the `claude` command and run `/mcp` to authenticate.
{% endtab %}

{% tab title="Cursor" %}
1\. From your settings, go to ***Tools & MCPs***.

2\. Click on **New MCP Server**.

3\. Add the following to your file and save:

{% code overflow="wrap" %}

```json
{
   "mcpServers": {
     "sola": {
       "type": "http",
       "url": "https://api.sola.security/mcp"
     }
   }
 }
```

{% endcode %}

4\. Go to ***Tools & MCPs*** and connect the **Sola MCP**.
{% endtab %}

{% tab title="Other" %}
Update the `mcp.json` file for your client with the following:

{% code overflow="wrap" %}

```json
{
   "mcpServers": {
     "sola": {
       "type": "http",
       "url": "https://api.sola.security/mcp"
     }
   }
 }
```

{% endcode %}
{% endtab %}
{% endtabs %}

{% hint style="info" %}
**Using a different MCP client?** [Contact us](https://help.sola.security/support/tickets/new?ticket_form=ideas%2Ffeature_request) and our team will get you set up.
{% endhint %}

## MCP settings

Configure the Sola MCP by adding headers to your config file. [See example below](https://docs.google.com/document/d/1JnmpO-rZlkmFQRqh8n7gpMvbwzRXdkcNlfDbbori-5w/edit?tab=t.0#heading=h.rdlahxok79ir).

### Global

<table><thead><tr><th width="210.3411865234375">Settings</th><th width="441.1007080078125">Description</th><th>Default</th></tr></thead><tbody><tr><td><p>Create Resources</p><p>(<code>x-create-resources</code>)</p></td><td>When using Explore Data, controls whether Sola saves generated queries and canvases to your workspace.</td><td><p>false</p><p><br></p></td></tr></tbody></table>

### Query

<table><thead><tr><th width="208.8271484375">Settings</th><th width="247.2943115234375">Description</th><th>Default</th><th>Max</th></tr></thead><tbody><tr><td><p>Query Timeout</p><p>(<code>x-query-timeout</code>)</p></td><td>How long Sola waits before stopping a query.</td><td>300 (5 min)</td><td>600 (10 min)</td></tr><tr><td><p>Query Rows Limit</p><p>(<code>x-query-rows-limit</code>)</p></td><td>Maximum number of rows returned.</td><td>100000</td><td>100000</td></tr><tr><td><p>Query Memory Limit</p><p>(<code>x-query-memory-limit</code>)</p></td><td>Maximum size of the query response.</td><td>1048576 (1 MiB)</td><td>10,485,760 (10 MiB)</td></tr></tbody></table>

### Example config with settings applied

{% code overflow="wrap" %}

```json
{
   "mcpServers": {
     "sola": {
       "type": "http",
       "url": "https://api.sola.security/mcp"
     },
	"headers": {
       "x-create-resources": "true"
     }
   }
 }
```

{% endcode %}


# Sola Slack AI Assistant

Bring your full security environment into Slack

The Sola Slack AI Assistant brings Sola AI directly into Slack. Ask questions about your security posture, projects, and issues and get answers grounded in your actual Sola workspace data. The same intelligence you get in Sola, without leaving your conversation.

<figure><img src="/files/JSOTddU0xcxirWJSnh5D" alt="Sola AI Assistant in Slack"><figcaption><p>Sola AI Assistant in Slack</p></figcaption></figure>

The assistant can:

* **List Projects** - List all projects in your workspace with their IDs and names.
* **Get Project Details** - Return full details about an project, including integrations, connectors, vendors, tables, queries, and canvases.
* **Explore Data** - Ask natural language questions about your environment, security posture, compliance, and more. Uses Sola's graph intelligence and security domain expertise.
* **Run Existing Query** - Run a saved query from your workspace by name or ID. Just ask the assistant to run a specific query and it will return the results directly in Slack.

For example, you can ask the assistant:

```
What projects do I have in my workspace?
```

```
Show me the details of my AWS security project
```

```
What are my most critical misconfigurations across AWS and Okta?
```

```
Run my "Admin access review" query
```

## Connecting the Sola Slack AI Assistant

To connect the Sola Slack AI Assistant, you'll need to install it in your Slack workspace and link your Sola account.

### Install Sola AI Assistant

This step requires a **Slack workspace admin**. Review and approve the permissions on Slack's OAuth consent screen.

Once approved, the assistant will be installed in your **Slack workspace app list**.

<a href="https://api.sola.security/api/slack-bot/install" class="button primary" data-icon="slack">Add to Slack</a>

### Link your Sola account

Once the Sola AI Assistant is installed, each user can link their own Sola account.

**Send any message** to the assistant to start the linking process, click the authorization link, and log in with your Sola credentials.

On success, return to Slack and start using the assistant.

{% hint style="info" %}
**One-time setup**

Your account link persists across sessions. No need to re-link each time.
{% endhint %}

## Using the Sola Slack AI Assistant

Open a DM with the Sola AI Assistant and start asking questions. Answers reflect what's actually in your Sola workspace, with Sola's AI reasoning through it all.

The assistant keeps track of your conversation for context, supporting multi-turn conversations.

<figure><img src="/files/ZpTJrcrL1zgs0gNcjEBV" alt="Sola AI Assistant welcome message"><figcaption><p>Sola AI Assistant welcome message</p></figcaption></figure>


# Prompt Guide

Tips, ideas, and best practices for building with Sola AI

[Sola AI](/getting-started/sola-ai) helps you build, explore, and investigate your security posture. A clear prompt gives Sola the context it needs to deliver the right output, faster and with better focus.

This guide explains how to write effective prompts for Sola AI. It shares practical tips and examples, drawn from real usage in the field, to help you get better results.

For now, the focus is on **building** [**canvases**](/workspace/projects/canvases) **with Sola AI**. More best practices will be added over time.

{% hint style="success" %}
**Prompting with Sola AI is a collaborative process.**

Start with a clear direction, refine with follow-ups, and use the recommendations Sola provides to shape the right project, canvas, or insight.
{% endhint %}

## How to use this guide

Prompting in Sola AI can serve different goals, from creating new projects, to building canvases, to investigating risks, and creating workflows.&#x20;

This first version focuses on [canvas](/workspace/projects/canvases) best practices. The recommendations are not strict rules, but tips you can apply as needed to get better results.

## Canvas best practices

These best practices are grouped into three themes: [Start](#id-1.-start), [Refine](#id-2.-refine), [Expand](#id-3.-expand), and [Troubleshoot](#id-4.-troubleshoot).

### 1. Start

Begin with broad prompts to set the direction.

#### ![](/files/DESMoC6l1Gr9uaynao5N) Start broad, then iterate

Provide Sola AI with a general theme and refine your prompt step-by-step until the output matches your needs.

For example,

* “What are my top AWS security issues?”
* “Show me insights on GitHub access risks.”

#### ![](/files/DESMoC6l1Gr9uaynao5N) Keep prompts short and clear

Sola AI works best with concise prompts. While prompts can be up to \~3000 characters, shorter inputs are more effective and easier to refine.

For example:

* **Less effective**: “Create a canvas with detailed breakdowns of all services, including every AWS account, Okta user, GitHub repo, permissions, vulnerabilities, and historical changes…”
* **Better**: “Show me my top AWS security issues, grouped by account, with a chart of failed logins.”

#### ![](/files/DESMoC6l1Gr9uaynao5N) Reference your data

Start with referencing specific queries and ask Sola AI to create a canvas based on these queries or project data.

For example,

“Create a canvas based on the queries for inactive Okta users and failed logins.”

{% hint style="info" %}
As a best practice, before starting a new canvas, make sure relevant [queries](/workspace/projects/queries) already exist for what you want to build. If any are missing, Sola AI will complete them automatically as part of the canvas creation.
{% endhint %}

### 2. Refine

Shape Sola’s output to better match your needs.

#### ![](/files/DESMoC6l1Gr9uaynao5N) Add layout and structure early

Include any layout or style that you have in mind as early as possible, even in the first prompt. The earlier you set expectations, the better Sola can match your vision.

For example,

* “Show me my top AWS security issues, split into sub-pages by logical grouping, and make it Star Trek themed.”

#### ![](/files/DESMoC6l1Gr9uaynao5N) Give Sola context

Use Sola terminology, such as “canvas”, “project”, “project queries”, and “integrations”, to help Sola AI understand your intent.

Be specific about chart types or views if you want them.

For example,&#x20;

* “table of admin users”&#x20;
* “bar chart of open vulnerabilities by repo”

#### ![](/files/DESMoC6l1Gr9uaynao5N) Use interactive elements

Sola canvases can include interactive features to make insights more actionable.

For example:

* Add links to view the underlying data or queries.
* Highlight data trends with arrows and colors.
* Include toggles or tabs for different views.
* Add insights that summarize trends automatically.

### 3. Expand

Grow and explore beyond the basics.

#### ![](/files/DESMoC6l1Gr9uaynao5N) Invite clarification

Ask Sola AI to confirm before building. This helps align expectations and save time

For example,

* "Before you start building, make sure everything is clear. Ask me any clarification question you might have"

#### ![](/files/DESMoC6l1Gr9uaynao5N) Ask the Sola AI copilot

When in doubt, ask Sola AI what it can do. This will help you discover new directions.

For example,

* “What kind of canvases can I build from this project?”
* “What insights can I generate from this data?”
* “How do workflows work?”
* “What can I do with canvases?”

### 4. Troubleshoot

Fix issues and polish your canvas.

Even with clear prompts, canvases may need some adjustments. With Sola AI, if something doesn’t look right, you have the tools to fix it.

#### ![](/files/DESMoC6l1Gr9uaynao5N) Refine the prompt

Re-run with a smaller scope or clearer instructions.

#### ![](/files/DESMoC6l1Gr9uaynao5N) Tweak the layout

Resize charts, adjust text, or move elements directly in the canvas editor.

#### ![](/files/DESMoC6l1Gr9uaynao5N) Check for UX issues

Adjust overflowing text, small buttons in tabs, or charts that don’t fit well.

Use queries as building blocks

If a visualization isn’t working, make sure the underlying query returns the data you expect.

#### ![](/files/DESMoC6l1Gr9uaynao5N) Iterate with Sola AI

Ask the copilot to adjust or fix issues, such as:

* “Make the chart labels shorter.”
* “Increase the tab button size.”
* “Move the legend to the right side.”

#### ![](/files/DESMoC6l1Gr9uaynao5N) Use the chat to resolve errors

If you encounter an error while building, try using Sola AI to resolve it. Describe the issue directly in the Sola AI chat. Ask the copilot to look into it and fix the problem.

## Advanced ideas

Once you’re comfortable with the basics, try creative prompts to push canvases further:

* “Build a CISO dashboard and a separate engineering dashboard, each on its own tab.”
* “Make a canvas themed for executives with high-level summaries and traffic-light colors for risk.”
* “Add a toggle that switches between today’s results and 30-day trends.”
* “Show MFA adoption over time with arrows indicating increases and decreases.”
* “Add links from charts to the queries powering them.”

***This guide will continue to grow with more best practices.***


# Templates

Get inspired with ready-to-use templates made by our expert security team

## Explore expert-built security projects

Browse ready-made templates designed by security experts.

Each template is built to help you answer critical security questions, track risks, and strengthen your security posture, without starting from scratch.

![](/files/bKdo3yzED39AfQ5Oyclq) [Start exploring templates](https://app.sola.security/templates).

<figure><img src="/files/BkI72YuQKANnmZ9S9Szt" alt="Templates"><figcaption><p>Sola Templates</p></figcaption></figure>

## Customize to make it your own

Every template can be customized. Start with a template, modify queries, adjust dashboards, and set up alerts to tailor it to your specific security needs.

![](/files/bKdo3yzED39AfQ5Oyclq) [Start exploring templates](https://app.sola.security/templates).

## How it works

{% stepper %}
{% step %}

### Browse and import a template

Find a template that aligns with your security focus, and add it to your workspace.
{% endstep %}

{% step %}

### Connect your data

Add your [data sources](/integrations/data-sources) to gain insights on your environment.&#x20;
{% endstep %}

{% step %}

### &#x20;Customize

Adjust [queries](/workspace/projects/queries), [visualizations](/workspace/projects/canvases), and [alerts](/workspace/projects/alerts), to fit your needs.
{% endstep %}
{% endstepper %}


# What’s New

Release notes: Get the latest updates, features, and news from Sola

**July 12, 2026**

Here’s the latest on what’s new and improved at Sola.

## *New* Agents and Skills

Investigate alerts, triage incidents, and take action across your connected environment with [**agents**](/workspace/agents) you @mention from any chat or project. Agents work asynchronously while you stay in the conversation. Start with a pre-built agent from Sola or build your own, each with its own instructions, tools, and memory.

Apply domain-specific expertise to any investigation with [**skills**](/workspace/skills) you invoke with / in chat, or assign to agents to extend what they know without rewriting their instructions. Start with pre-built skills from Sola or build your own.

<div><figure><img src="/files/fMNBujNnnBuJjkuY6avq" alt="Custom agents, ready when you need them"><figcaption><p>Custom agents, ready when you need them</p></figcaption></figure> <figure><img src="/files/Ay7qNfZy4EUoQsa9Kwef" alt="Reusable skills your whole workspace can use"><figcaption><p>Reusable skills your whole workspace can use</p></figcaption></figure></div>

***Available on*** [***paid plans***](https://sola.security/pricing/)***.***

{% embed url="<https://sola.security/pricing/>" %}

## *New* in Lumina Signals: investigate your risks in chat and view them in a focused feed

A new [**feed view**](/workspace/lumina-signals#feed) shows your most important risks grouped by security domain, led by a personalized brief that highlights the day's top priorities.

Start a [**chat**](/workspace/lumina-signals#investigating-signals-in-chat) from any signal to investigate it with full context, ask follow-up questions, and dig into several signals at once. Your investigation stays in your workspace to reference and build on, even after the signal resolves.

<div><figure><img src="/files/nT4Fu3ZloYchiZXON2RP" alt="Lumina Signals"><figcaption><p>Your most critical risks, pre-investigated and prioritized across your entire environment</p></figcaption></figure> <figure><img src="/files/2kGrqQRbXRzTOwLKEaSD" alt="Investigate any signal in a chat"><figcaption><p>Investigate any signal in a chat</p></figcaption></figure></div>

## Integrations

<figure><img src="/files/g7x1w4NtfmdyQVzs3YcJ" alt=""><figcaption></figcaption></figure>

### Data Sources

***New***: Claude Enterprise Analytics

[Monitor how Claude](/integrations/data-sources/claude-enterprise-analytics) is adopted and used across your organization. Track per-user activity, active users and seats, skill, connector, and project adoption, and token and cost usage.

[**Try these updates now**](https://auth.sola.security/oauth/account/login)

<a href="/pages/tdAsgMxEjtk7c059Lt7i" class="button secondary" data-icon="megaphone">Read the full product updates changelog</a>


# July 12, 2026

Release notes

## *New* Agents and Skills

Investigate alerts, triage incidents, and take action across your connected environment with [**agents**](/workspace/agents) you @mention from any chat or project. Agents work asynchronously while you stay in the conversation. Start with a pre-built agent from Sola or build your own, each with its own instructions, tools, and memory.

Apply domain-specific expertise to any investigation with [**skills**](/workspace/skills) you invoke with / in chat, or assign to agents to extend what they know without rewriting their instructions. Start with pre-built skills from Sola or build your own.

<div><figure><img src="/files/fMNBujNnnBuJjkuY6avq" alt="Custom agents, ready when you need them"><figcaption><p>Custom agents, ready when you need them</p></figcaption></figure> <figure><img src="/files/Ay7qNfZy4EUoQsa9Kwef" alt="Reusable skills your whole workspace can use"><figcaption><p>Reusable skills your whole workspace can use</p></figcaption></figure></div>

***Available on*** [***paid plans***](https://sola.security/pricing/)***.***

{% embed url="<https://sola.security/pricing/>" %}

## *New* in Lumina Signals: investigate your risks in chat and view them in a focused feed

A new [**feed view**](/workspace/lumina-signals#feed) shows your most important risks grouped by security domain, led by a personalized brief that highlights the day's top priorities.

Start a [**chat**](/workspace/lumina-signals#investigating-signals-in-chat) from any signal to investigate it with full context, ask follow-up questions, and dig into several signals at once. Your investigation stays in your workspace to reference and build on, even after the signal resolves.

<div><figure><img src="/files/nT4Fu3ZloYchiZXON2RP" alt="Lumina Signals"><figcaption><p>Your most critical risks, pre-investigated and prioritized across your entire environment</p></figcaption></figure> <figure><img src="/files/2kGrqQRbXRzTOwLKEaSD" alt="Investigate any signal in a chat"><figcaption><p>Investigate any signal in a chat</p></figcaption></figure></div>

## Integrations

<figure><img src="/files/g7x1w4NtfmdyQVzs3YcJ" alt=""><figcaption></figcaption></figure>

### Data Sources

***New***: Claude Enterprise Analytics

[Monitor how Claude](/integrations/data-sources/claude-enterprise-analytics) is adopted and used across your organization. Track per-user activity, active users and seats, skill, connector, and project adoption, and token and cost usage.

## Notes and reminders

Stay tuned for more coming soon! 🚀

—

*The Sola Team*


# June 30, 2026

Release notes

## *Improved*: Sola Apps are now Projects

Build, customize, and collaborate on security solutions in your workspace, just under a new name. [Templates](/getting-started/templates) now live as a tab inside [Projects](/workspace/projects), alongside *Your Projects* and *Workspace Projects*.

## *New*: Stop response, course-correct mid-answer

Stop an AI response while it's in progress and redirect without waiting it out. The stream halts immediately and leaves a clean record in your chat history.

<figure><img src="/files/IpxUaQRR8gEtSkxnAq1B" alt=""><figcaption></figcaption></figure>

## Integrations

<figure><img src="/files/m8PXSt8vr29hsQ7eykXu" alt=""><figcaption></figcaption></figure>

### *New*: Manual sync, refresh data on demand

Get the latest data from a connected source whenever you need it, without waiting for the daily scheduled sync. [Trigger a manual run](/integrations/data-sources#triggering-a-manual-sync) and Sola refreshes the data source on demand.

### Data Sources

***New***: Snowflake&#x20;

Connect your [Snowflake](/integrations/data-sources/snowflake) data warehouse to Sola and query security data in real time, without syncs or exports. Investigate incidents and run cross-system queries directly against your live warehouse data.

***New***: Sentinel Data Lake&#x20;

Connect [Microsoft Sentinel](/integrations/data-sources/sentinel-data-lake), Defender, and Entra to Sola and query your security events in real time. Investigate alerts, correlate identity activity, and surface threats directly from your Microsoft security stack.

***Improved***: Cloudflare Zero Trust&#x20;

The [Cloudflare](/integrations/data-sources/cloudflare) integration now imports Zero Trust data. Track access control, device posture, gateway filtering, DLP, tunnels, and risk scoring alongside existing DNS and network tables. Existing connections update automatically, no reconnect required.

## New Templates

Now available in Templates:

* [Cross-System Identity Access Review](https://sola.security/templates/identity-access-review-cross-platform/)

## Notes and reminders

Stay tuned for more coming soon! 🚀

—

*The Sola Team*


# May 31, 2026

Release notes

## ***New***: Chats

Workspace-level chats are now available.

Explore and investigate across your entire Sola workspace, with full visibility across all your connected data. [Workspace chats](/workspace/chats) are private, and available to workspace admins and owners.

<figure><img src="/files/oPcITEN9ul6kPzWWfDDC" alt="Ask questions across your entire workspace in private chats"><figcaption><p>Ask questions across your entire workspace in private chats</p></figcaption></figure>

## *New*: Prompt Library

Browse a [curated library of expert security prompts](/resources/prompt-library) and run them directly in Sola chat.

Prompts cover six security domains: cloud posture, identity, DLP, SaaS, incident readiness, and supply chain. Each prompt runs in chat using your connected data.

<div><figure><img src="/files/Htva7lBToZ9XrCSROeHH" alt=""><figcaption></figcaption></figure> <figure><img src="/files/MLlMKRdCI1cJhQemb1Ho" alt=""><figcaption></figcaption></figure></div>

## Integrations

### Data Sources

***New*****:** Claude Enterprise

Monitor compliance activity, user behavior, and admin actions across your [Claude Enterprise](/integrations/data-sources/claude-enterprise) organization. Track chat history, project access, group membership, and audit activity to support eDiscovery and DLP investigations.

## Notes and reminders

Stay tuned for more coming soon! 🚀

—

*The Sola Team*


# May 19, 2026

Release notes

## *New*: Lumina Signals, AI-powered risk signals surfaced daily

[Lumina Signals](/workspace/lumina-signals) is a daily feed of decision-ready security risk signals, surfaced across your entire environment and recalibrated against your business context.

<figure><img src="/files/H27XJq6IzZ0QvjHyQVaU" alt=""><figcaption></figcaption></figure>

<div><figure><img src="/files/irs1XETLSpPRdvlyXQa3" alt=""><figcaption></figcaption></figure> <figure><img src="/files/3i7MaZHIOz5ddE4utniR" alt=""><figcaption></figcaption></figure> <figure><img src="/files/t9H4IDeohJrC2aucB8sP" alt=""><figcaption></figcaption></figure> <figure><img src="/files/NRrCu9doDNJSTlg30qND" alt=""><figcaption></figcaption></figure> <figure><img src="/files/5196ToBTyS6WGCtdTuoU" alt=""><figcaption></figcaption></figure></div>

Every signal arrives pre-investigated, with reasoning, blast radius, and recommended actions already assembled. Each signal tells you what's at risk, why it matters, how far it spreads, and what to do next.

* **Intelligent grouping**: thousands of findings compressed into meaningful risk clusters
* **Cross-domain**: all connected sources analyzed as one unified environment
* **Business context**: risk scoring specific to your organization, not a generic average
* **Always fresh**: daily analysis, live feed, reflects your environment right now
* **Pre-investigated**: every signal arrives with context, reasoning, blast radius, and recommended actions already assembled

[Available on paid plans.](https://sola.security/pricing/)

{% embed url="<https://sola.security/pricing/>" %}

## *New*: Real time data sources

Sola now supports real time data sources, starting with [Google Sheets](/integrations/data-sources/google-sheets), a new integration type that queries live data directly from the source with no scheduled syncs or data exports. Connect your data and start asking questions immediately, always working with the latest version of your data.

## Integrations

<figure><img src="/files/IsnJV7C9ZwwnBGSvW7Oj" alt=""><figcaption></figcaption></figure>

### Data Sources

***New*****: Google Sheets**

Connect any [Google spreadsheet](/integrations/data-sources/google-sheets) directly to Sola and query it in real time. Ask questions and run cross-system investigations using your spreadsheet data.

### Connectors

***New*****: Shodan**

Investigate [internet-facing assets](/integrations/connectors/shodan) directly from Sola AI. Look up IP address details, search for exposed devices, query CVE and CPE data, and perform DNS lookups during active investigations.

## Notes and reminders

Stay tuned for more coming soon! 🚀

—

*The Sola Team*


# April 30, 2026

Release notes

## ![](/files/DESMoC6l1Gr9uaynao5N) *New*: Sola MCP Server, your security data in any AI tool

Query your security data from any AI tool.

[Connect Sola to Claude, Cursor, Claude Code, VS Code, or any MCP-compatible tool](/getting-started/sola-ai/sola-mcp) and your full security workspace comes with it.

Ask natural language questions, explore your environment, run queries, and investigate risks, without leaving the tool you're already working in. No more switching contexts.

<div><figure><img src="/files/kEOUo8kPpvDW4LgURhvP" alt="Sola MCP"><figcaption></figcaption></figure> <figure><img src="/files/vWZd1vM2uefcwMfevJHM" alt="Sola MCP"><figcaption></figcaption></figure></div>

## ![](/files/DESMoC6l1Gr9uaynao5N) *New*: Sola Slack AI Assistant, security intelligence right in Slack

[DM the Sola bot in Slack](/getting-started/sola-ai/sola-slack-ai-assistant) and get the same security intelligence you'd get in the product.

Ask questions about your security posture, apps, and environment and get answers grounded in your actual Sola workspace data. Multi-turn conversations, saved queries, and natural language exploration, without leaving Slack.

<figure><img src="/files/JSOTddU0xcxirWJSnh5D" alt="Sola AI Assistant in Slack"><figcaption><p>Sola AI Assistant in Slack</p></figcaption></figure>

## Updated Sola pricing and plans&#x20;

Sola's pricing structure has been updated with [four new plans](https://sola.security/pricing/). More flexibility, expanded AI capacity, and clearer feature access as your team grows.

![](/files/u9RHZRvhr64TfNP6IjXP) **Shoreline (*****Free*****) - Perfect for trying out Sola and personal projects**

![](/files/u9RHZRvhr64TfNP6IjXP) **Tidewater - For solo professionals and small teams ready to scale**

![](/files/u9RHZRvhr64TfNP6IjXP) **Open Sea - For teams and departments running mission-critical applications**

![](/files/u9RHZRvhr64TfNP6IjXP) **Deep Blue - For organizations with custom requirements and scale**

## Workflows

### *New*: Workflow webhook trigger&#x20;

Workflows can now be [triggered by incoming webhooks](/workspace/projects/workflows#webhook-trigger) from external systems. Connect any security tool, alerting platform, or HTTP-capable service to kick off workflow executions automatically when events occur.

## Integrations

<figure><img src="/files/D59no2WdaZPrX0F5EXYI" alt="NetSuite, Anthropic, Mosyle data source integrations"><figcaption></figcaption></figure>

### Data Sources

***New*****: NetSuite**

Connect NetSuite to monitor user access and permissions, identify privilege risks, detect stale tokens, and track authentication activity across your NetSuite environment. Imports data on users, roles, permissions, access tokens, and login activity.

***New*****: Anthropic**

Monitor user access, permissions, and authentication activity across your Anthropic environment. Surface privilege risks and stale tokens to keep your AI infrastructure secure.

***New*****: Mosyle**

Get full visibility into your Apple device fleet across macOS, iOS, and iPadOS. Monitor device compliance, user and group data, and administrative activity to support security monitoring and asset management.

***Improved*****: GCP Organization-level connection**

GCP integration can now connect at the organization level. Connect your entire GCP Organization and manage multiple projects at scale through a single integration.

***Improved*****: GCP Vertex AI tables**

The GCP data source now includes Vertex AI tables, giving security teams visibility into AI models, endpoints, and workloads running in Google Cloud. Monitor access, detect misconfigurations, maintain governance over your AI infrastructure, and surface Shadow AI activity such as unauthorized usage and unsanctioned tools.

***Improved*****: Slack connector**\
The Slack connector now supports three additional Bot Token Scopes, expanding what Sola can do on your behalf in Slack:

* `files:write`: Upload, edit, and delete files as Sola
* `remote_files:write`: Add, edit, and delete remote files on a user's behalf
* `users:read.email`: View email addresses of people in a workspace

***Improved*****: Salesforce OAuth 2.0 connection**&#x20;

The Salesforce data source can now be connected using OAuth 2.0 Client Credentials, providing a more secure connection that does not require a username and password. Username and Password authentication remains available until Salesforce deprecates this method.

### Connectors

***New*****: AbuseIPDB**

Check suspicious IPs against the AbuseIPDB database directly from Sola AI. During active investigations, surface abuse confidence scores, country and ISP details, and report history, report malicious IPs with abuse categories, and query the AbuseIPDB blacklist without leaving your workflow.

## New Templates

Now available in [Templates](/getting-started/templates):

* [Shadow AI Discovery](https://sola.security/app/shadow-ai-discovery-detection/)
* [NetSuite - Security and Access Insights](https://sola.security/app/netsuite-security-access/)
* [Claude Console - Identity and Usage Insights](https://sola.security/app/claude-console-security/)
* [Jamf and EDR - Endpoint Security Coverage](https://sola.security/app/jamf-edr-endpoint-security-coverage/)

## Notes and reminders

Stay tuned for more coming soon! 🚀

—

*The Sola Team*

{% embed url="<https://sola.security/pricing/>" %}


# March 22, 2026

Release notes

## ![](/files/DESMoC6l1Gr9uaynao5N) Sola AI&#x20;

### Voice chat with Sola AI

Talk to Sola without typing and get responses read aloud.\
[Available on paid plans.](https://sola.security/pricing/)

{% embed url="<https://files.gitbook.com/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FMkiDTkdEK7CdyQX8KZZH%2Fuploads%2Fe84sfKysLX6TYxlyxg1P%2FVoice%20mode%20.mp4?alt=media&token=a67c20c3-efbb-4c10-a575-9e610b60f147>" %}

<p align="center">Chat with Sola AI</p>
{% endembed %}

### Manage alert Slack notifications with Sola AI&#x20;

Sola AI can now create and edit Slack notifications for alert rules. Choose which channels or DMs to notify when a rule triggers or new evidence is discovered.

Send a test notification directly from the chat to confirm everything is set up correctly.

## Alerts

### Improved alert rule editing&#x20;

Fingerprint, grouping, and alert scope settings on existing [alert rules](/workspace/projects/alerts#managing-alert-rules) can now be edited. Modifying these fields will deprecate existing triggered alerts and recalculate the rule to generate new alerts based on the updated configuration.

## Canvases

### Canvas widget focus mode&#x20;

Select any widget on your [canvas](#canvases) and run AI prompts that apply changes directly to it, without touching the rest of your canvas.

{% embed url="<https://files.gitbook.com/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FMkiDTkdEK7CdyQX8KZZH%2Fuploads%2FM62FRbRej6jS6AQaIa9Y%2FFocus%20mode.mp4?alt=media&token=56c35672-de2a-4d3f-9a14-17fb95a8d9b9>" %}

<p align="center">Canvas focus mode</p>
{% endembed %}

## Integrations

### Data Sources

***New*****: JumpCloud**

Unified directory and device management data including managed users, group memberships, device inventory, and system attributes.

{% embed url="<https://files.gitbook.com/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FMkiDTkdEK7CdyQX8KZZH%2Fuploads%2FNjqX5xIjDbwmXam6nA4A%2FJumpCloud%20data%20source.mp4?alt=media&token=3c2cebcc-52cc-4f8a-b445-9af5d3f7a299>" %}

***Improved*****: Okta service account connection**

Okta can now be connected using a service account for a more secure, least-privilege setup.

***Improved*****: Table-level sync status**

Previously, a single failed data source entity would mark an entire table as out of sync with no data. Now, only the problematic entities are skipped while the rest of your data continues syncing normally. A new Partial Sync status makes this visible, and you can drill into any table to see exactly which entities failed and why.

## New Templates

Now available in [Templates](/getting-started/templates):

* [Azure Security Posture Rule Set](https://sola.security/app/azure-security-posture/)
* [GitHub and Google Workspace - App Monitoring](https://sola.security/app/github-app-oauth-app-security/)

## Notes and reminders

Stay tuned for more coming soon! 🚀

—

*The Sola Team*

{% embed url="<https://sola.security/pricing/>" %}


# February 9, 2026

Release notes

## ![](/files/DESMoC6l1Gr9uaynao5N) Sola AI&#x20;

**Start working in your app** right away with enhanced conversational guidance for exploring or building.

### *New*: Ready-made prompts

Guided prompts walk you through key security scenarios from inside your app, with security expertise. **Ask** questions to explore your security posture. **Build** dashboards, reports, and alerts.

Guided prompts walk you through key security scenarios from inside your app, with security expertise. Ask questions to explore your security posture. Build dashboards, reports, alerts, and more.

<figure><img src="/files/7xE9jlpyXmOMdic9JjNh" alt="Onboard with security expert-guided prompts"><figcaption><p>Onboard with security expert-guided prompts</p></figcaption></figure>

### *Improved*: Chat experience

Sola AI intuitively recognizes when you ask about [data sources](#data-sources) that aren't connected yet and prompts you to connect them instantly as part of the conversation flow. Get the data you need without interruption.

<figure><img src="/files/DGtkKtgmLoGPeACXUsBH" alt="Connect data sources seamlessly in your chat"><figcaption><p>Connect data sources seamlessly in your chat</p></figcaption></figure>

## Sola Studio

### Fast onboarding flow

Get started with Sola faster with a new simplified onboarding experience. New users can now move from signup to building their first security app in minutes.

<figure><img src="/files/V6h0PcEUTGNjNY7MLIli" alt="Simplified onboarding experience"><figcaption><p>Simplified onboarding experience</p></figcaption></figure>

### One app to get you started

New users now start with a single ready-to-use app that includes guided chat suggestions to help you explore Sola's capabilities. Ask questions about your security posture or build queries, canvases, and alerts, all from one place.

Access workspace settings and browse templates directly from the navigation bar while working in your app for added convenience. When you return to Sola, you'll land right back in your app, keeping your workspace clean and focused.

<figure><img src="/files/iOkEcpn3dPQPHLyArG7o" alt="Navigate easily while working in your app"><figcaption><p>Navigate easily while working in your app</p></figcaption></figure>

### Recent activity in app overview

App Overview now shows Recent Activity alongside your app summary, making it easier to track changes and understand what your app monitors.

<figure><img src="/files/N6KU1sBRLUk4jta9578Z" alt="Stay updated with recent activity"><figcaption><p>Stay updated with recent activity</p></figcaption></figure>

## Templates

### Install templates

Add templates to your existing apps, in addition to creating them as new apps.

<figure><img src="/files/0RphvYF7P93FkVCKRtEQ" alt="Add to your app or create new"><figcaption><p>Add to your app or create new</p></figcaption></figure>

## Notes and reminders

Stay tuned for more coming soon! 🚀

—

*The Sola Team*

{% embed url="<https://sola.security/pricing/>" %}


# January 22, 2026

Release notes

## ![](/files/DESMoC6l1Gr9uaynao5N) Sola AI&#x20;

### *New*: Chat history and multiple chats

Work with [Sola AI](/getting-started/sola-ai) across multiple conversations in each app without losing your chat history. Start new chats, switch between conversations, and revisit past discussions whenever you need them.

<figure><img src="/files/jLpMAzxcEPvdgJyQc9xa" alt="Access your chat history from any app"><figcaption><p>Access your chat history from any app</p></figcaption></figure>

## Canvases

### Canvas code editor

Advanced users can view and edit canvas source code directly with the new [canvas code editor](/workspace/projects/canvases#canvas-code-editor) for precise control over layout, styling, and behavior.

<div><figure><img src="/files/beh8Rs6PbN1PfnLGgEdy" alt="Canvas code editor split screen"><figcaption><p>Canvas code editor split screen</p></figcaption></figure> <figure><img src="/files/hk4lapEkSxp1pPsq3qh0" alt="Code editor button in canvas toolbar"><figcaption><p>Code editor button in canvas toolbar</p></figcaption></figure></div>

Work in split-screen mode with your canvas visible beside the code, making it easy to customize and debug without AI. Access version history to review or restore previous iterations.

## Alerts

### Slack notifications for alerts

Receive [alert notifications](/workspace/projects/alerts#creating-alert-rules) directly in Slack channels, and keep your team informed about critical security issues in your main work environment.

<figure><img src="/files/k1X290KbpgoPRmmcB2Tm" alt="Receive alert notifications directly in Slack"><figcaption><p>Receive alert notifications directly in Slack</p></figcaption></figure>

## Integrations

### Data Sources

***New*****: GitHub organization apps table**

Added new `github_organization_app_installation` table to the [GitHub integration](/integrations/data-sources/github), providing visibility into all GitHub Apps installed on your GitHub organization.

## Templates

Now available in [Templates](#templates):

* [Employee Offboarding - Risk Monitoring](https://app.sola.security/gallery/employee-offboarding-risk)

## Notes and reminders

Stay tuned for more coming soon! 🚀

—

*The Sola Team*

{% embed url="<https://sola.security/pricing/>" %}


# December 31, 2025

Release notes

Happy new year! :tada:

## Pricing and plans

Choose the plan that fits your team with [new pricing tiers](https://sola.security/pricing/) designed to scale with your security needs.&#x20;

Upgrade instantly through self-service options, manage your subscription flexibly, and get clear visibility into feature entitlements and usage limits across Free, Individual, Team, and Enterprise plans.

{% embed url="<https://sola.security/pricing/>" %}

## Workflows

### Manual workflow actions

Build and edit workflows without AI assistance. New hover actions let you manually create, duplicate, delete, and configure workflow blocks, attach and delete edges, giving you complete control over your automation logic.&#x20;

<figure><img src="/files/VbQ05TlmdltTMUfwjVod" alt="Build workflows manually with full control"><figcaption><p>Build workflows manually with full control</p></figcaption></figure>

### Workflows Send Email block action

Workflows can now send automated, customizable emails, including output from previous workflow steps, making it easier to share reports and results with stakeholders.

<figure><img src="/files/3OtTFgn9wU2CkL4bjwvD" alt=""><figcaption><p>Send automated emails from your workflows</p></figcaption></figure>

### Enable/disable workflows

Control which workflows are actively running with a simple toggle. Temporarily disable workflows for testing or maintenance, then turn them back on when ready.

<figure><img src="/files/M0uIDhv9RJLjinVEXSr7" alt="Enable and disable workflows"><figcaption><p>Enable and disable workflows</p></figcaption></figure>

## Integrations

<figure><img src="/files/De06hAFbA0s204knlIZ1" alt=""><figcaption></figcaption></figure>

### Data Sources

#### Data Sources

***New*****: HiBob**

Connect HiBob to bring employee context into your security workflows. Use data such as departments, titles, and employment status to strengthen identity reviews, validate access, and improve overall organizational visibility.

## New Templates

Now available in [Templates](/getting-started/templates):

* [GitHub - React CVE-2025-55182 Analyzer](https://sola.security/app/github-react-cve-2025-55182-analyzer/)

{% embed url="<https://sola.security/blog/shai-hulud-supply-chain-attack-nov-24/>" %}

## Notes and reminders

Stay tuned for more coming soon! 🚀

—

*The Sola Team*


# November 24, 2025

Release notes

## Workflows improvements

Enhancements to make workflows more flexible, transparent, and easier to manage:

### New schedule intervals

Workflows can now run on weekly and monthly schedules, giving teams more control over long-term reporting and automation.

### Improved Slack message signatures

Workflow-generated Slack messages now include a workflow signature and direct link, while chat-initiated messages continue to appear as sent by the user.

<figure><img src="/files/ZaA1L9AvXlF8iQstszJT" alt=""><figcaption></figcaption></figure>

### Updated workflows library card view

A new default card layout provides a clearer overview of each workflow, making it easier to browse and discover automation flows.

<figure><img src="/files/fEaNO6zvvX1vOKAonFZQ" alt=""><figcaption></figcaption></figure>

## Canvas

### Canvas version history

Track and revert changes with a full version history for your canvases.This makes it easy to review updates, undo mistakes, and iterate safely.&#x20;

<figure><img src="/files/aw51E2TUSqjJmZSylOVP" alt=""><figcaption></figcaption></figure>

### Canvas query details

Get full visibility into the data behind your canvases. Each widget now provides the option to view the query data that powers it, helping you understand data sources, troubleshoot issues, and maintain or refine canvases.

<div><figure><img src="/files/K8uaMbLUwgm7VpT5zV5w" alt=""><figcaption></figcaption></figure> <figure><img src="/files/XvK17d3ZhPujjf2lXSiW" alt=""><figcaption></figcaption></figure></div>

## Integrations

<figure><img src="/files/TaC1sQnp0oZQsrOYEVbA" alt=""><figcaption></figcaption></figure>

### Data Sources

***New*****: Jamf Security Cloud (formerly RADAR)**

Connect Jamf Security Cloud to bring device risk-state and threat insights into your Apple fleet monitoring.

## New Templates

Now available in [Templates](/getting-started/templates):

* [GitHub - Shai Hulud Supply-Chain Attack V2](https://sola.security/app/github-shai-hulud-second-supply-chain-attack/)

{% embed url="<https://sola.security/blog/shai-hulud-supply-chain-attack-nov-24/>" %}

## Notes and reminders

Stay tuned for more coming soon! 🚀

—

*The Sola Team*


# September 17, 2025

Release notes

## ![](/files/DESMoC6l1Gr9uaynao5N) *New*: Vibe canvases

### Transform security data into fully customizable interactive interfaces.

[Vibe canvases](/workspace/projects/canvases) let you create dynamic charts, tables, and guides with natural language prompts, giving you unlimited flexibility in layout, style, and use cases, from monitoring cloud posture to building executive reports, and more.

{% hint style="info" %}
See the [Prompt Guide](https://docs.sola.security/getting-started/sola-ai/prompt-guide) for tips and examples to refine your prompts and get the best results.
{% endhint %}

<figure><img src="/files/UGYKUlJhbBYBKhbDiiku" alt=""><figcaption></figcaption></figure>

## ![](/files/DESMoC6l1Gr9uaynao5N) *New*: Agentic workflows

### Structure and automate security operations with AI-native flows.

[Agentic workflows](/workspace/projects/workflows) bring intelligent step-by-step orchestration to your apps, enabling investigations, remediation, and reporting across data sources and connectors. Built with Sola AI, workflows combine reasoning with automation for flexible, transparent, and resilient execution.

<figure><img src="/files/ORnQMPUCCWM8w4BEGrqM" alt="New: Agentic workflows"><figcaption></figcaption></figure>

## Notes and reminders

Stay tuned for more coming soon! 🚀

—

*The Sola Team*


# September 10, 2025

Release notes

## ![](/files/DESMoC6l1Gr9uaynao5N) Sola AI

### Send CSV to Slack

Send any CSV export from Sola AI directly to Slack as part of a message, making it easier to share data with your team in real time.

## Sola Studio

### Explore data over time with historical snapshots

Access [historical snapshots of your data ](/integrations/data-sources#snapshots-and-incremental-data-updates)in Sola to explore the history of your data, investigate changes in posture and configurations, using queries or by asking Sola AI. To activate, include “*snapshots*” in your prompt or toggle on “Include historical snapshots” in the SQL query window.

For example, ask Sola AI to:

* Show AWS EC2 inventory across multiple data snapshots.
* Investigate snapshots of Github users granted admin access in the last few days.
* Find Okta role or policy that has changed in the last 3 days across snapshots and how.

## Integrations

<figure><img src="/files/bAro3PLYlGwahsQXcgMg" alt=""><figcaption></figcaption></figure>

### Data Sources

***New*****: SentinelOne**

Integrate SentinelOne to monitor endpoint agents, threat detections, vulnerabilities, installed applications, and security policies.

***New*****: Jira Cloud**

Integrate Jira Cloud to surface issue and project data, enabling visibility into remediation projects, tasks, sprints, boards, users and more.

## New Templates

Now available in [Templates](/getting-started/templates):

* [AWS Security Posture Rule Set](https://app.sola.security/gallery/aws-security-posture-misconfigurations)

## Notes and reminders

Stay tuned for more coming soon! 🚀

—

*The Sola Team*


# August 10, 2025

Release notes

Here’s the latest on what’s new and improved at Sola.

## ![](/files/DESMoC6l1Gr9uaynao5N) Sola AI

### Build queries, alerts, and canvases, one prompt at a time

Sola Copilot now lets you [build canvases, alerts, and queries](/getting-started/sola-ai#expand-your-apps-with-new-queries-alerts-and-canvases) directly within existing apps. Expand coverage, add new use cases, and generate full dashboards, all from a conversation with the copilot.

Create multiple canvases in a single request, each tailored to different teams or goals. This update makes it easier than ever to grow and evolve your apps with natural language.

## Integrations

<figure><img src="/files/wBUyjHU8xsuTmWmsnT8E" alt=""><figcaption></figcaption></figure>

### Data Sources

***New*****: Lovable App Scanner**

Connect Lovable to monitor and assess the security posture of your Lovable applications, including vulnerabilities, misconfigurations, and hidden exposures that traditional tools may overlook.

## Templates

Now available in [Templates](/getting-started/templates):

* [Lovable App Scanner - Security Posture](https://app.sola.security/gallery/lovable-security-vulnerabilities-scanner)

## Notes and reminders

Stay tuned for more coming soon! 🚀

—

*The Sola Team*


# July 23, 2025

Release notes

Here’s the latest on what’s new and improved at Sola.

## ![](/files/DESMoC6l1Gr9uaynao5N) Sola AI

### Graph-enhanced research in Sola AI

Sola AI now includes [graph-enhanced research](/getting-started/sola-ai/security-graph), a deep analysis mode that uses **Sola’s proprietary security graph** to answer complex questions with rich context and clarity. It maps relationships between resources, controls, and risks to deliver **grounded**, **complete responses** backed by visual evidence and cross-environment reasoning.

<div><figure><img src="/files/XxOjZooZFXVTdIGSP7In" alt=""><figcaption><p>Graph research mode in AI copilot</p></figcaption></figure> <figure><img src="/files/O9PgVkJ9kYln1tCI4FEE" alt=""><figcaption><p>Graph research visual representation</p></figcaption></figure></div>

## Notes and reminders

Stay tuned for more coming soon! 🚀

—

*The Sola Team*


# July 21, 2025

Release notes

Here’s the latest on what’s new and improved at Sola.

## ![](/files/DESMoC6l1Gr9uaynao5N) Sola AI

### Your AI Security Copilot: AI-First Sola app layout

[Sola AI](/getting-started/sola-ai) is now integrated throughout your security apps.

The new design lets you ask questions, explore data, and investigate issues while viewing alerts, dashboards, and queries.

<figure><img src="/files/Xn1drnKVvO7Qe5k3MxtB" alt=""><figcaption></figcaption></figure>

## Integrations

<figure><img src="/files/DPbndkEsRiiL7y4vcRZ1" alt=""><figcaption></figcaption></figure>

### Data Sources

#### ***New***: Upwind

Integrate Upwind to surface cloud security data from Upwind, including threat policies, threat detections, and vulnerabilities.

#### ***New***: Jamf Pro

Connect Jamf Pro for Apple device management on enrolled devices, configurations, user associations, and security posture across your Apple fleet.

### Connectors

#### ***New***: [Jira](/integrations/connectors/jira)

Bring Sola AI into your Jira projects to create and track issues directly from in-chat conversations and streamline remediation workflows.

## Sola Studio

### Export canvas as PDF

Download your canvas as a PDF to share insights or report on findings. The file includes all widgets and layout.

{% hint style="info" %}
PDF export is available for manual canvases. Vibe canvases do not support PDF export.
{% endhint %}

### Export alert tables as CSV

Export [triggered alerts](/workspace/projects/alerts) and alert evidence tables with Sola apps directly to CSV files. Exported files reflect your customized view (filters, sorting, and selected columns).

## New Templates

Now available in [Templates](/getting-started/templates):

* [EntraID - Security and Access Insights](https://app.sola.security/gallery/microsoft-entra-id-security-insights)

## Notes and reminders

Stay tuned for more coming soon! 🚀


# June 30, 2025

Release notes

Here’s the latest on what’s new and improved at Sola

## Connectors: Real-time actions from in-chat AI copilot

Sola now supports [Connector integrations](/integrations/connectors) that let you interact with external services in real time, directly from Sola AI conversations.

Use the new [Slack connector](/integrations/connectors/slack) to share findings during analysis, escalate issues for remediation, and offload insights to the right stakeholders or channels across your organization.

## ![](/files/DESMoC6l1Gr9uaynao5N) Sola AI

### Ask AI copilot about triggered alerts

[Sola AI](/getting-started/sola-ai) can now help you review and investigate triggered alerts.

Get on-demand insights into triggered alerts to help you prioritize and take action.\
Ask questions like ***“What alerts should I focus on today?”*** or ***“How can I remediate these issues?”*** to get a structured summary of relevant alerts, key findings, and recommended next steps directly from the Sola AI copilot.

### Ask AI copilot to send to Slack&#x20;

[Sola AI](/getting-started/sola-ai) can now share findings, insights, or summaries directly to Slack.

Use prompts like ***“Send this to my SecOps channel”*** or ***“Notify the team in Slack”*** to streamline collaboration and keep stakeholders informed without leaving the conversation.&#x20;

<div><figure><img src="/files/7ZVJ9RiXjgYmi987rZ9j" alt="Send to Slack from AI copilot"><figcaption><p>Send to Slack from AI copilot</p></figcaption></figure> <figure><img src="/files/i8bVXJIanmlF6Ad0izHc" alt="Slack Sola Agent"><figcaption><p>Slack Sola Agent</p></figcaption></figure></div>

### Export AI-generated tables as CSV

[Sola AI](/getting-started/sola-ai) can now export tables it generates during a conversation as CSV files.

Ask the copilot to export any result table, such as investigation findings, user lists, or issue breakdowns, for easier sharing, reporting, or deeper analysis in external tools.

<figure><img src="/files/7iBYiaBMeFSEXVJNhpdn" alt="Export AI-generated tables as CSV"><figcaption><p>Export CSV from AI copilot</p></figcaption></figure>

## Integrations

<figure><img src="/files/T4AnyH3l8aJCPdQ3ABsA" alt=""><figcaption></figcaption></figure>

### Data Sources

#### ***New***: OX Security

Connect Ox Security to monitor code vulnerabilities, secrets exposure, container risks, SBOM insights, and more.

#### ***New***: WordPress Scanner

Integrate WordPress to surface publicly exposed sites, and potential security risks across your web infrastructure.

#### ***Improved***: Cloudflare

Now supports custom firewall rule sets and rules at both Account and Zone levels, providing deeper visibility into web application protection and access control configurations.

#### ***Improved***: Google Workspace&#x20;

Now includes Google Directory, enabling insights into organizational structure, user status, and access visibility.

### Connectors

#### ***New***: Slack

Send findings, summaries, alerts and more directly from Sola AI copilot to Slack.

## Sola Studio

### Export query results to CSV file

Export [query](/workspace/projects/queries) results directly to CSV files. Exported files reflect your customized view (filters, sorting, and selected columns).&#x20;

### Filter canvas widgets

Apply filters to individual widgets in your [canvas](/workspace/projects/canvases), in both edit and view mode, to focus on specific data slices. This lets you refine the scope and create multiple widgets from a single query, without duplicating or modifying the original query.

## New Templates

Now available in [Templates](/getting-started/templates):

* [CrowdStrike - Hosts and Alerts Insights](https://app.sola.security/gallery/crowdstrike-endpoint-security-alerts)

## Notes and reminders

Stay tuned for more coming soon! 🚀

—

*The Sola Team*


# May 20, 2025

Release notes

Here’s the latest on what’s new and improved at Sola.

## ![](/files/DESMoC6l1Gr9uaynao5N) Sola AI

### From prompt to app, powered by Sola AI

[Sola AI](/getting-started/sola-ai) now builds complete security apps from a single prompt.

Whether you’re tackling a known issue or exploring new risks, Sola AI turns your prompt into a working security solution in minutes.

Just describe the security use case you want to investigate, and Sola AI will generate a full app, complete with tailored dashboards, alerts, and key insights from your connected data.

<figure><img src="/files/oT2k05LU532sLytyGFjb" alt=""><figcaption><p>Build an app for your security needs</p></figcaption></figure>

## Notes and reminders

Stay tuned for more coming soon! 🚀

—

*The Sola Team*


# May 14, 2025

Release notes

Here’s the latest on what’s new and improved at Sola.

## Integrations

<figure><img src="/files/QszSDwdx1Uuu3cHrYliC" alt=""><figcaption></figcaption></figure>

### *New*: Open AI Platform

Connect your OpenAI account to monitor users, API keys, projects, audit activity, and more, to uncover potential risks across your OpenAI environment.

### *New*: Sola Web Checker

Add domains, URLs, or host endpoints to uncover hidden risks, and continuously monitor the security posture of your public assets.

## New Templates

Now available in [Templates](/getting-started/templates):

* [Google Workspace](https://sola.security/app/google-workspace-files/)
* [Sola Web Checker](https://sola.security/app/web-domain-security-insights/)

## Sola Studio

### Alert email notification

Add members or valid email addresses to receive email notifications when a [new alert](/workspace/projects/alerts#creating-alert-rules) is triggered.

### Canvas widget overview

Expand widgets in your [app canvases](/workspace/projects/canvases) to easily view a detailed overview of the query and data results.

### Filter queries in alert creation

Apply an additional filter layer on top of a selected query when creating [alert rules](/workspace/projects/alerts#creating-alert-rules). This lets you refine the scope and create multiple alert rules from a single query, without duplicating efforts.

### Filter query view&#x20;

Apply table filters when [viewing query results](/workspace/projects/queries#managing-queries) to refine the data.

## Notes and reminders

Stay tuned for more coming soon! 🚀

—

*The Sola Team*


# April 20, 2025

Release notes

Here’s the latest on what’s new and improved at Sola.

## ![](/files/DESMoC6l1Gr9uaynao5N) Sola AI

### New Sola AI insights agent

Get deep visibility into your security posture with a new [AI insights agent](#sola-ai).

Apps now include a dedicated Sola AI tab to help you investigate your environment and uncover security risks by asking security questions. Ask specific or broad questions like “What’s my AWS security posture?” or “What are the top security issues with my GitHub repositories?”, and Sola AI will return targeted queries, generate insights, and surface what matters most.

Whether you’re exploring new risks or validating your controls, this AI-powered agent helps you dig deeper, faster.

<figure><img src="/files/2tcI9o2KHYG4Wwt2EMP9" alt=""><figcaption><p>New Sola AI insights agent</p></figcaption></figure>

## Integrations

<figure><img src="/files/juS2llbhhakyT6wYe9GY" alt=""><figcaption></figcaption></figure>

### *New*: Microsoft Entra ID (formerly Azure AD)

Integrate your Microsoft Entra ID environment to monitor identity and access management across your organization.

### *New*: Google Workspace

Connect your Google Workspace accounts to gain insights and build apps around Workspace users, Gmail settings, and files in Google Drive.

### *Improved*: GitHub Cloud - Sola GitHub App

The Sola GitHub App is now available as a fast and secure way to connect your GitHub Cloud account with your Sola workspace.

This predefined integration simplifies setup, making it easier to get started and begin analyzing your GitHub environment.

## Security and Privacy

<figure><img src="/files/JnEpCBTW2wf4sNwEmvNe" alt=""><figcaption></figcaption></figure>

### SOC 2 Type II compliance

Sola is now SOC 2 compliant, meeting the highest standards for security, availability, and confidentiality. We are committed to protecting your data with industry-leading practices and trusted security controls.

Learn more about our other key industry certifications, such as ISO 27001, and our latest  security and compliance documentation, in the [Trust Center](https://trust.sola.security/).

## Notes and reminders

Stay tuned for more coming soon! 🚀

—

*The Sola Team*


# Changelog

Stay up to date with all the latest releases, improvements, and fixes in Sola

For major announcements and feature deep-dives, see [What’s New](/getting-started/release-notes).

## August 2026

<mark style="color:$info;">**August 12, 2026**</mark>

***Integrations***\
**New**:  Claude Code\
Added a new [Claude Code](/integrations/data-sources/claude-code) data source, coding agent integration, providing visibility into the security posture and usage of Claude Code across your organization. Inventory installed plugins, marketplaces, skills, and MCP server connections, audit permission rules, hooks, and security settings, and correlate configured cloud profiles with identity and access data across your environment. Also tracks developer sessions and tool call activity within Claude Code.

<mark style="color:$info;">**August 4, 2026**</mark>

***Sola AI***\
**New**: Routines\
Automate your recurring investigations, monitoring, and status reports with [Routines](/workspace/routines). Configure a task, an agent, and a project scope once, and it runs on its own from then on. Every run is logged, ready for you to pick up and continue investigating in chat.

## July 2026

<details>

<summary>Expand to see updates</summary>

<mark style="color:$info;">**July 15, 2026**</mark>

***Sola AI***\
**New**: Move a chat to a project\
[Move any chat into a new project ](/workspace/chats#moving-a-chat-to-a-project)your team can join and collaborate on. Your chat stays private to you, while the queries, canvases, alerts, and workflows you built along the way move into the project and become available to your team.

<mark style="color:$info;">**July 12, 2026**</mark>

***Sola AI***\
**New**: Agents\
Investigate alerts, triage incidents, and take action across your connected environment with [agents](/workspace/agents) you @mention from any chat or project. Agents work asynchronously while you stay in the conversation. Start with a pre-built agent from Sola or build your own, each with its own instructions, tools, and memory.\
Available on [paid plans](https://sola.security/pricing/).

***Sola AI***\
**New**: Skills\
Apply domain-specific expertise to any investigation with [skills](/workspace/skills) you invoke with / in chat, or assign to agents to extend what they know without rewriting their instructions. Start with pre-built skills from Sola or build your own.\
Available on [paid plans](https://sola.security/pricing/).

<mark style="color:$info;">**July 8, 2026**</mark>

***Sola AI***\
**Improved**: MCP authentication\
[MCP authentication](/getting-started/sola-ai/sola-mcp) has been simplified. It no longer requires generating a Personal Access Token or Client ID beforehand. Connect from Claude, Cursor, or any MCP client, log in or create an account if you don't have one, and you're ready to query your environment right in your client.

<mark style="color:$info;">**July 6, 2026**</mark>

***Lumina Signals***\
**Improved**: Lumina Signals\
The [Lumina Signals](/workspace/lumina-signals) experience has three new capabilities. \
You can now [ask about your risk in chat](/workspace/lumina-signals#investigating-signals-in-chat) and get answers from the Signal Specialist. Ask it anything about a signal and it investigates deep, pulling information from across Sola, your workflows, and MCP. The [Feed](/workspace/lumina-signals#feed) is a new view of your top signals with a card layout, bulk actions, and per-user preferences, and includes a daily brief summarizing the day's signals and where to focus. \
The [Context](https://docs.sola.security/getting-started/pages/wbH3cWtCMl3PK7nAu4jE#id-2.-business-context) experience has been redesigned. Add your organization's knowledge with a natural-language prompt or by uploading a file, and Sola uses it to prioritize signals more accurately for your environment.

<mark style="color:$info;">**July 1, 2026**</mark>

***Integrations***\
**New**:  Claude Enterprise Analytics\
Added a new [Claude Enterprise Analytics](/integrations/data-sources/claude-enterprise-analytics) data source, providing visibility into how Claude is adopted and used across your organization, including per-user activity, active users and seats, skill, connector, and project adoption, and token consumption and spend.

</details>

## June 2026

<details>

<summary>Expand to see updates</summary>

<mark style="color:$info;">**June 30, 2026**</mark>

***Integrations***\
**New**: Manual sync for data sources\
Refresh a [data source](/integrations/data-sources#triggering-a-manual-sync) on demand instead of waiting for the daily scheduled sync. Trigger a manual run, for the entire data source or a single table, to pull the latest data whenever you need it.

<mark style="color:$info;">**June 15, 2026**</mark>

***Integrations***\
**New**:  Claude Enterprise Analytics\
Added a new [Claude Enterprise Analytics](/integrations/data-sources/claude-enterprise-analytics) data source, providing visibility into how Claude is adopted and used across your organization, including per-user activity, active users and seats, skill, connector, and project adoption, and token consumption and spend.

<mark style="color:$info;">**June 15, 2026**</mark>

***Templates***\
**New**: Cross-System Identity Access Review\
Added a new template to [review identity access across HR and connected systems](https://app.sola.security/projects/templates/identity-access-review-cross-platform), cross-referencing HiBob employee records with Okta, Entra ID, JumpCloud, Google Workspace, AWS, GitHub, and Salesforce. Surfaces terminated users with active access, admins without MFA, onboarding and offboarding gaps, and identity risks, with drill-down by user, system, or role.

***Templates***\
**Improved**: Templates in Projects\
[Templates](/getting-started/templates) are now accessible as a tab inside the Projects section, alongside Your Projects and Workspace Projects.

***Sola Studio***\
**Improved**: Projects\
Sola Apps have been renamed to [Projects](/workspace/projects). Build, customize, and collaborate on security solutions in your workspace, just under a new name.

<mark style="color:$info;">**June 7, 2026**</mark>

***Integrations***\
**New**:  Cloudflare Zero Trust tables\
Added Zero Trust data to the [Cloudflare integration](/integrations/data-sources/cloudflare). The integration now imports data across access control, device posture, gateway filtering, DLP, tunnels, risk scoring, and digital experience monitoring, in addition to existing DNS, zone, and network infrastructure tables. Existing Cloudflare connections are automatically updated. There is no need to reconnect, just update your current integration with the new tables you want to add.

<mark style="color:$info;">**June 4, 2026**</mark>

***Sola AI***\
**New**: Stop response\
Stop an AI response while it's in progress and course-correct without waiting it out. The stream halts immediately and leaves a clean record in the chat history.

***Integrations***\
**New**: Sentinel Data Lake\
Added a new [Sentinel Data Lake real-time data source](/integrations/data-sources/sentinel-data-lake), connecting Microsoft Sentinel, Defender, and Entra as a real-time security data stream. Investigate incidents and correlate security events using live data from your Microsoft security environment.

***Integrations***\
**New**: Snowflake\
Added a new [Snowflake real time data source](/integrations/data-sources/snowflake), allowing you to query and analyze your Snowflake data directly in Sola in real time. Investigate incidents and surface risks using live data from your Snowflake environment.

</details>

## May 2026

<details>

<summary>Expand to see updates</summary>

<mark style="color:$info;">**May 31, 2026**</mark>

***Integrations***\
**New**: Claude Enterprise\
Added a new [Claude Enterprise](/integrations/data-sources/claude-enterprise) data source, providing visibility into compliance activity, organizational users and groups, custom RBAC roles, projects, and chat conversations across your Claude Enterprise organization.

<mark style="color:$info;">**May 26, 2026**</mark>

***Sola AI***\
**New**: Chats\
Workspace admins and owners can now create private, [workspace-level Chats](/workspace/chats) with access to all connected data sources across the workspace. Chats include the full set of project building blocks (queries, canvases, alerts, and workflows), and are connected to the entire workspace rather than a single app. Chats are private per admin and not visible to members.

***Templates***\
**Improved**: Templates\
The App Gallery has been renamed to [Templates](/getting-started/templates). Browse and import pre-built projects, queries, and canvases for your security use cases, just under a new name.

<mark style="color:$info;">**May 20, 2026**</mark>

***Sola AI***\
**New**: Prompt Library\
A curated [library of security prompts](/resources/prompt-library) is now available directly in the Sola chat interface. Browse prompts across security domains: Cloud Security Posture, Identity Security, DLP & File Exposure, SaaS Posture Management, Incident Readiness & Backup Resilience, and CI/CD & Supply Chain Security.

<mark style="color:$info;">**May 19, 2026**</mark>

***Lumina Signals***\
**New**: Lumina Signals (*Beta*)\
Introducing [Lumina Signals](/workspace/lumina-signals), a daily feed of ranked security risk signals surfaced across your entire connected environment. Sola's intelligence layer analyzes your environment, applies business context, and pre-investigates each signal, delivering context, reasoning, blast radius, and recommended actions ready to act on.

<p align="right"><img src="/files/u9RHZRvhr64TfNP6IjXP" alt=""> <a href="https://sola.security/blog/lumina-signals-risk-intelligence/"><strong>Learn more in the Sola blog</strong></a> </p>

<mark style="color:$info;">**May 18, 2026**</mark>

***Integrations***\
**New**: Google Sheets\
Connect any [Google spreadsheet](/integrations/data-sources/google-sheets) directly to Sola and query it in [real time](/integrations/data-sources#real-time-data-sources-usage). Ask questions and run cross-system investigations using your spreadsheet data. Data is always up to date with no scheduled syncs required.

***Integrations***\
**New**: Real time data sources\
Introducing support for real time data sources, starting with [Google Sheets](/integrations/data-sources/google-sheets), a new integration type that queries data live from the source with no scheduled syncs. Queries run directly against the source at runtime, keeping your data always up to date.

<mark style="color:$info;">**May 7, 2026**</mark>

***Integrations***\
**New**: Shodan Connector\
Added a new [Shodan connector](/integrations/connectors/shodan), enabling security teams to investigate internet-facing assets directly from Sola AI. Look up IP address details, search for exposed devices, query CVE and CPE data, and perform DNS lookups during active investigations.

</details>

## April 2026

<details>

<summary>Expand to see updates</summary>

<mark style="color:$info;">**Apr 30, 2026**</mark>

***Sola Update***\
**New**: Pricing plans\
Introducing an updated Sola pricing structure with four new revised plans: Shoreline (*Free*), Tidewater, Open Sea, and Deep Blue, designed to give teams more flexibility, expanded AI capacity, and clearer feature access as you grow. Visit the [Sola pricing page](https://sola.security/pricing/) to learn more.

***Integrations***\
**Improved**: Salesforce - OAuth 2.0 connection method\
Salesforce data source can now be connected using OAuth 2.0 Client Credentials, providing a more secure connection that does not require a username and password. Username and Password authentication remains available until Salesforce deprecates this method.

***Workflows***\
**New**: Workflow Webhook Trigger\
Workflows can now be [triggered by incoming webhooks](/workspace/projects/workflows#webhook-trigger) from external systems. Connect security tools, alerting platforms, or any HTTP-capable service to kick off workflow executions automatically when events occur.

***Integrations***\
**New**: AbuseIPDB Connector\
Added a new [AbuseIPDB connector](/integrations/connectors/abuseipdb), enabling security teams to investigate suspicious IPs during active investigations. Check IP addresses for abuse confidence scores, country, ISP, and report history, report malicious IPs with abuse categories, and query the AbuseIPDB blacklist directly from Sola AI.

<mark style="color:$info;">**Apr 29, 2026**</mark>

***Templates***\
**New**: Jamf and EDR - Endpoint Security Coverage\
Added a new template to monitor [endpoint coverage and fleet health across Jamf MDM and your EDR](https://app.sola.security/gallery/jamf-edr-endpoint-security-coverage) platform, CrowdStrike or SentinelOne. Surfaces coverage gaps, flags devices missing EDR agents, and highlights MDM risk issues across your macOS fleet.

<p align="right"><img src="/files/u9RHZRvhr64TfNP6IjXP" alt=""> <a href="https://sola.security/blog/shadow-ai-discovery/"><strong>Learn more in the Sola blog</strong></a> </p>

***Templates***\
**New**: Claude Console - Identity and Usage Insights\
Added a new template to monitor identity, API key security, and usage across the [Claude Console](/integrations/data-sources/claude-console) platform. Surfaces risks like unscoped keys, stale credentials, and orphaned accounts, with optional Okta enrichment to detect offboarding gaps and provisioning mismatches.

<mark style="color:$info;">**Apr 20, 2026**</mark>

***Integrations***\
**New**: Semgrep\
Added a new [Semgrep data source](/integrations/data-sources/semgrep), providing visibility into security findings from code scans, policy enforcement data, and AppSec metadata to support application security posture and connect engineering activity with security outcomes.

<mark style="color:$info;">**Apr 19, 2026**</mark>

***Integrations***\
**New**: Mosyle\
Added a new Mosyle data source, providing visibility into Apple device inventory across macOS, iOS, and iPadOS, user and group data, device compliance segmentation, and administrative activity logs to support security monitoring and asset management.

<mark style="color:$info;">**Apr 16, 2026**</mark>

***Sola AI*** \
**New**: Sola MCP\
Connect any [MCP-compatible AI assistant](/getting-started/sola-ai/sola-mcp) directly to your Sola workspace. One connection gives you access to your full security environment to explore, investigate risks, and run queries in natural language without leaving your workflow. Supported clients include Claude, Claude Code, Cursor, OpenAI Codex, VS Code, and any MCP-compatible tool.

<p align="right"><img src="/files/u9RHZRvhr64TfNP6IjXP" alt=""> <a href="https://sola.security/blog/sola-mcp-server/"><strong>Learn more in the Sola blog</strong></a> </p>

***Sola AI*** \
**New**: Sola Slack AI Assistant\
[Sola AI is now in Slack](/getting-started/sola-ai/sola-slack-ai-assistant). Ask questions about your security posture, apps, and environment and get answers grounded in your Sola workspace data. The assistant supports multi-turn conversations and can list apps, return app details, explore your environment in natural language, and run saved queries directly in Slack. Security answers, without leaving your daily flow.

<mark style="color:$info;">**Apr 13, 2026**</mark>

***Integrations***\
**New**: Claude Console\
Added a new [Claude Console](/integrations/data-sources/claude-console), providing visibility into user access and permissions, privilege risks, stale tokens, and authentication activity across your Claude environment.

<mark style="color:$info;">**Apr 12, 2026**</mark>

***Templates***\
**New**: NetSuite Security and Access Insights\
Added a new template to [monitor and secure your NetSuite environment](https://app.sola.security/gallery/netsuite-security-access) with visibility into access risks, identity gaps, OAuth token exposure, and login threats. Surfaces security control failures across users, roles, and integrations, and includes additional query coverage for environments using Okta as their identity provider.

<mark style="color:$info;">**Apr 10, 2026**</mark>

***Templates***\
**New**: Shadow AI Discovery\
Added a new template to [discover and assess AI tool risk across your organization](https://app.sola.security/gallery/shadow-ai-discovery-detection). Surfaces Shadow AI exposure across identity platforms, endpoints, code repositories, and cloud infrastructure, giving security teams visibility into which AI tools are in use, by whom, and at what risk level.

<p align="right"><img src="/files/u9RHZRvhr64TfNP6IjXP" alt=""> <a href="https://sola.security/blog/shadow-ai-discovery/"><strong>Learn more in the Sola blog</strong></a> </p>

<mark style="color:$info;">**Apr 5, 2026**</mark>

***Integrations***\
**Improved**: Slack connector - new required scopes\
Added three new Bot Token Scopes to the [Slack](/integrations/connectors/slack#connect-slack-to-sola) connector:

* `files:write` - Upload, edit, and delete files as Sola
* `remote_files:write` - Add, edit, and delete remote files on a user's behalf
* `users:read.email` - View email addresses of people in a workspace

<mark style="color:$info;">**Apr 2, 2026**</mark>

***Integrations***\
**Improved**: GCP - Vertex AI tables\
Added new Vertex AI tables to the [Google Cloud Platform (GCP)](/integrations/data-sources/gcp) data source, giving security teams visibility into AI models, endpoints, and workloads running in Google Cloud. Use it to monitor access, detect misconfigurations, maintain governance over your AI infrastructure, and surface Shadow AI activity such as unauthorized usage and unsanctioned tools.

</details>

## March 2026

<details>

<summary>Expand to see updates</summary>

<mark style="color:$info;">**Mar 24, 2026**</mark>

***Integrations***\
**Improved**: GCP Organization support\
GCP integration can now connect at the organization level. [Connect your entire GCP Organization](/integrations/data-sources/gcp#connect-gcp-to-sola) and manage multiple projects at scale through a single integration.\
Available on [paid plans](https://sola.security/pricing/).

***Integrations***\
**New**: NetSuite\
Added a new [NetSuite data source](/integrations/data-sources/netsuite), providing data on users, roles, permissions, access tokens, and login activity to support access governance, least privilege enforcement, and security compliance monitoring.

<mark style="color:$info;">**Mar 17, 2026**</mark>

***Integrations***\
**Improved**: Table-level sync status\
Partially synced integrations now include a detailed sync breakdown. Drill into any affected table to see exactly which resources failed to sync and why, with the option to include historical snapshots from the last 3 days, making it easier to identify and resolve sync issues.

<mark style="color:$info;">**Mar 10, 2026**</mark>

***Sola AI and Alerts***\
**New**: Create and edit Slack notifications for alerts with Sola AI\
Sola AI can now add and edit Slack notifications to [alert rules](/workspace/projects/alerts#alert-rules), including choosing which channels or DMs to notify when a rule triggers or new evidence is discovered.

***Sola AI and Alerts***\
**New**: Test alert notifications with Sola AI\
Sola AI can now send a test Slack notification for any [alert rule](/workspace/projects/alerts#alert-rules) to confirm the setup is working.

<mark style="color:$info;">**Mar 8, 2026**</mark>

***Canvases***\
**New**: Canvas widget focus mode\
Select any widget on your [canvas](/workspace/projects/canvases#managing-canvases) and run AI prompts that apply changes directly to it. Changes affect only the selected widget, giving you precise control over individual components without modifying the rest of your canvas.

<mark style="color:$info;">**Mar 3, 2026**</mark>

***Templates***\
**New**: Azure Security Posture Rule Set\
Added a new template to [uncover and address critical misconfigurations across Azure environments](https://app.sola.security/gallery/azure-security-posture) using a curated security rule set. Covers key security domains including IAM, network exposure, storage, containers, and databases to help teams detect risk, enforce least privilege, and align with security benchmarks.

***Sola AI***\
**New**: Voice chat with Sola\
Added voice mode to [Sola AI](/getting-started/sola-ai). Talk to Sola without typing and get responses read aloud.\
Available on [paid plans](https://sola.security/pricing/).

</details>

## February 2026

<details>

<summary>Expand to see updates</summary>

<mark style="color:$info;">**Feb 26, 2026**</mark>

***Alerts***\
***Improved***: Alert rule editing\
Fingerprint, grouping, and alert scope settings on existing alert rules can now be edited. Modifying these fields will deprecate existing triggered alerts and recalculate the rule to generate new alerts based on the updated configuration.

***Integrations***\
***Improved***: Okta service account connection\
Okta data source can now be [connected using a service account](/integrations/data-sources/okta#how-do-i-set-up-an-okta-data-source-using-a-service-account), providing a more secure and least-privilege approach without requiring an admin account.

<mark style="color:$info;">**Feb 25, 2026**</mark>

***Integrations***\
***New***: JumpCloud

Added a new JumpCloud data source, providing unified directory and device management data including managed users, group memberships, device inventory, and system attributes to support identity context, governance, and security monitoring across your organization.

<mark style="color:$info;">**Feb 22, 2026**</mark>

***Templates***\
***New***: GitHub and Google Workspace - App Monitoring

Added a new template to [track GitHub App installations and Google Workspace OAuth authorizations](https://app.sola.security/gallery/github-app-oauth-app-security) with permission analysis and risk scoring. Identifies high-risk integrations and scope grants across both platforms. Includes built-in [workflows](/workspace/projects/workflows) that trigger on alerts, assess app permissions, and send risk summaries to Slack.

<mark style="color:$info;">**Feb 10, 2026**</mark>

***Docs and Content***\
***New***: Google Workspace setup video guide

Added new how to connect video to [Google Workspace data source](/integrations/data-sources/google-workspace) page. More videos coming soon.

<mark style="color:$info;">**Feb 9, 2026**</mark>

***Docs and Content***\
***New***: Prompt Library\
Added new [Prompt Library](/resources/prompt-library) to Sola docs with curated security use cases and ready-to-use prompts. Including key security concepts and prompt examples for exploring and building with Sola AI. More categories coming soon.

***Sola AI***\
***New***: Ask and Build modes with ready-made prompts\
Added Ask and Build modes to Sola AI chat with guided prompts for key security scenarios. Ask mode for exploring security posture with questions, Build mode for creating queries, dashboards, reports, and alerts.

***Sola AI***\
***Improved***: Chat experience\
Sola AI intuitively recognizes when you ask about data sources that aren't connected yet and prompts you to connect them instantly as part of the conversation flow.&#x20;

***Sola Studio***\
***New***: Fast onboarding flow\
Introducing a redesigned onboarding experience to help new users get started faster with Sola.

***Sola Studio***\
***New***: Start in your app\
New users now start in a ready-to-use app with guided chat suggestions, making it easy to explore Sola's capabilities immediately. No more landing on workspace home, your app is the first thing you see when you log in.

***Sola Studio***\
***Improved***: App navigation\
Workspace navigation bar now stays visible inside apps. Access workspace settings and browse templates directly from the navigation bar while working in your app.

***Sola Studio***\
***Improved***: Recent activity in app overview\
App Overview now displays Recent Activity alongside app members, showing recent changes to canvases, workflows, and alert rules for improved visibility into app updates.

***Sola Studio***\
***Improved***: App Overview tab\
Updated App Overview tab with enhanced layout displaying app information, connected integrations, team members, and recent activity in a redesigned dashboard view.

***Templates***\
***New***: Install templates\
[Templates](/getting-started/templates) can now be added to existing apps, in addition to creating them as new standalone apps. Combine multiple templates into comprehensive security solutions.

</details>

## January 2026

<details>

<summary>Expand to see updates</summary>

<mark style="color:$info;">**Jan 22, 2026**</mark>

***Templates***\
***New***: Employee Offboarding - Risk Monitoring\
Added a new template to [monitor departing employee Google Workspace activity during offboarding](https://app.sola.security/gallery/employee-offboarding-risk). Integrates HiBob data with Google Workspace audit logs to detect potential data exfiltration, unauthorized sharing, and access risks before employee termination dates.

<mark style="color:$info;">**Jan 20, 2026**</mark>

***Sola AI***\
***New***: Chat history and multiple chats\
Work across multiple Sola AI conversations within each app. Start new chats, switch between conversations, and revisit past discussions without losing context.

***Integrations***\
***New***: Google Workspace OAuth tokens table\
Added new `googleworkspace_oauth_tokens` table to the Google Workspace integration, providing visibility into third-party applications authorized by users via OAuth tokens and their granted scopes. Requires the `admin.directory.user.security` scope. Existing Google Workspace integrations will need to add this scope to the Sola API client in Google Admin console (domain-wide delegation) to access this table. Label: Integrations

<mark style="color:$info;">**Jan 14, 2026**</mark>

***Canvases***\
***New***: Canvas code editor\
View and manually edit canvas source code directly in the [canvas code editor](/workspace/projects/canvases#canvas-code-editor). Advanced users can make precise adjustments to layout, styling, and behavior without using AI. Access version history to review or restore previous iterations.

***Alerts***\
***New***: Slack notifications for alerts\
Receive [alert notifications](/workspace/projects/alerts#creating-alert-rules) directly in Slack channels for faster visibility into critical security issues.

<mark style="color:$info;">**Jan 13, 2026**</mark>

***Canvases***\
***New***: Canvas building accuracy and performance\
Improved canvas reliability and speed for more accurate editing and faster iteration.

<mark style="color:$info;">**Jan 5, 2026**</mark>

***Integrations***\
**Improved**: AWS Organization support\
AWS integration can now connect at the organization level. Connect your entire AWS Organization and manage multiple accounts at scale through a single integration.\
Available on [paid plans](https://sola.security/pricing/).

<mark style="color:$info;">**Jan 4, 2026**</mark>

***Integrations***\
**New**: GitHub organization apps table\
Added new `github_organization_app_installation` table to the GitHub integration, providing visibility into all GitHub Apps installed on your GitHub organization.

</details>

## December 2025

<details>

<summary>Expand to see updates</summary>

<mark style="color:$info;">**Dec 21, 2025**</mark>

***Workflows***\
***New***: Manual workflow actions\
Added the option to create and edit workflow blocks without using Sola AI. Manually add, remove, connect (attach or detach), and configure workflow blocks.

<mark style="color:$info;">**Dec 17, 2025**</mark>

***Integrations***\
***Improved***: Google Workspace drive files performance\
The `googleworkspace_drive_file` table has been split into `googleworkspace_shared_drive_file` and `googleworkspace_private_drive_file` for faster data synchronization and better user-control on the type of files to sync (from users private drives or shared drives). Update existing queries to use the new table names.

<mark style="color:$info;">**Dec 9, 2025**</mark>

***Workflows***\
***New***: Workflows email block\
Workflows can now send automated, customizable emails, including output from previous steps, making it easier to share reports and results.

<mark style="color:$info;">**Dec 8, 2025**</mark>

***Sola Update***\
***New***: Pricing and plans\
Introducing Sola’s new [pricing and plans](https://sola.security/pricing/), designed to scale with your team, unlock more AI usage, and give you clearer control over how you build and secure your environment.

<mark style="color:$info;">**Dec 4, 2025**</mark>

***Workflows***\
***New***: Enable/disable workflows\
New enable/disable toggle in [workflows](/workspace/projects/workflows). As part of the upgrade, all workflows will be disabled, except those that use a connector, which remain enabled.

<mark style="color:$info;">**Dec 3, 2025**</mark>

***Templates***\
***New***: GitHub - React CVE-2025-55182 Analyzer\
Added a template to [detect GitHub repositories using React versions impacted by the critical CVE-2025-55182 vulnerability](https://app.sola.security/gallery/github-react-cve-2025-55182-analyzer), helping teams assess exposure and prioritize remediation.

<mark style="color:$info;">**Dec 2, 2025**</mark>

***Integrations***\
***New***: HiBob\
Added a new HiBob data source, providing employee directory context such as departments, titles, and employment status to support identity reviews and access validation.

</details>

## November 2025

<details>

<summary>Expand to see updates</summary>

<mark style="color:$info;">**Nov 24, 2025**</mark>

***Templates***\
**New**: GitHub - Shai Hulud Supply-Chain Attack V2\
Added a new template to [identify repositories and packages impacted by the Shai Hulud supply-chain attack](https://app.sola.security/gallery/github-shai-hulud-second-supply-chain-attack), helping teams quickly assess exposure and prioritize remediation.\
[Learn more in the Sola Blog](https://sola.security/blog/shai-hulud-supply-chain-attack-nov-24/)

***Sola Studio***\
**New**: Filters experience\
Filters now display operator labels (e.g., contains) improving readability and making them easier to see at a glance.

<mark style="color:$info;">**Nov 23, 2025**</mark>

***Integrations***\
**Fixed**: Slack connector maintenance

A maintenance update was applied to the [Slack connector](/integrations/connectors/slack). Please re-authorize your existing Slack connectors to keep them active.

<mark style="color:$info;">**Nov 17, 2025**</mark>

***Workflows***\
**Updated**: Card view in workflow library

Updated the [workflow library](/workspace/projects/workflows) with a new default card view, offering a clearer layout and additional workflow details.

***Integrations***\
**New**: Jamf Security Cloud (formerly RADAR)

Added new Jamf Security Cloud data source, providing device risk-state data for improved Apple fleet visibility.

***Workflows***\
**Improved**: Slack message signatures

Workflow-generated Slack messages now include a workflow signature and link, while chat messages continue to appear as sent by the user.

<mark style="color:$info;">**Nov 10, 2025**</mark>

***Workflows***\
**New**: Workflow schedule intervals

Added weekly and monthly scheduling options for greater flexibility in automated workflow runs.

<mark style="color:$info;">**Nov 9, 2025**</mark>

***Canvas***\
**New**: Canvas version history

Added version history for [canvases](/workspace/projects/canvases), allowing users to review changes and restore previous iterations.

***Canvas***\
**New**: Canvas query details

Added the ability to see the queries powering each widget directly from your canvas. Use this to verify data sources, debug issues, or refine how your visuals are built.

***Canvas***\
**Improved**: Create canvases from any tab

Create canvases with Sola AI chat while working on any tab in your app, without having to switch to the Canvases tab.

<mark style="color:$info;">**Nov 4, 2025**</mark>

***Docs and Content***\
**New**: Cloudflare and Okta setup video guide

Added new how to connect videos to [Cloudflare](/integrations/data-sources/cloudflare) and [Okta](/integrations/data-sources/okta) data source pages. More videos coming soon.

</details>

## October 2025

<details>

<summary>Expand to see updates</summary>

<mark style="color:$info;">**Oct 30, 2025**</mark>

***Integrations***\
**New**: Entra ID authentication table

Added new `azuread_authentication_methods_policy` table to the Microsoft Entra ID integration, providing visibility into authentication method configurations and tenant-level policy settings.

***Integrations***\
**Removed**: Tables from Wiz data source integration

Removed the following tables from the Wiz integration to align with Wiz WIN program guidelines:\
`wiz_config_rule, wiz_control`, `wiz_project, wiz_security_category`, `wiz_security_framework`, `wiz_subscription`

<mark style="color:$info;">**Oct 29, 2025**</mark>

***Canvases***\
**Deprecated**: Manual Canvas creation with Sola AI

Manual Canvases are being phased out and can no longer be created through Sola AI.

<mark style="color:$info;">**Oct 27, 2025**</mark>

***Integrations***\
**Improved:** Google Workspace data source integration

Drive Files table now supports incremental syncs instead of full refreshes, enabling faster performance and data records efficiency.

<mark style="color:$info;">**Oct 17, 2025**</mark>

***Canvases***\
**Improved**: Vibe Canvases

Refactored iteration flow for faster load times and smoother experience when editing canvases.

<mark style="color:$info;">**Oct 11, 2025**</mark>

***Sola AI***\
**Improved**: AI wait-time experience (“Thoughts and Actions”)

Optimized the wait-time flow with clearer reasoning steps and a new timer for better transparency and user feedback.

<mark style="color:$info;">**Oct 5, 2025**</mark>

***Sola AI***\
**Improved**: Sola AI’s data exploration

Improved Sola AI’s data exploration for sharper, faster, more reliable context-aware answers.

</details>


# Workspace Home

Create your own security solutions

A Sola workspace is a collaborative studio environment that lets you create and share custom security projects. It is a virtual space for all [projects](/workspace/projects) you are a member in and can join, within an organization. You can be a member of multiple workspaces.

<figure><img src="/files/D7SJ58hrdfqDwqWEVnvm" alt=""><figcaption><p>Sola workspace home</p></figcaption></figure>

Your workspace is a central place where you can ideate and map out **your security gaps and use cases**, and create custom solutions to address them. Each custom solution can cover a specific use case.

Key components you’ll need:

1. [**Data sources**](/integrations/data-sources) - Secure connections to the data of services used within your organization.
2. [**Projects**](/workspace/projects) - Customizable tools designed to address specific cyber security use cases or needs.

{% hint style="success" %}
**Pro tip: Start by** [**connecting your data sources**](/workspace/projects#connecting-data-sources).\
This will allow you to start getting answers to your security questions and create projects quickly.
{% endhint %}


# Lumina Signals

AI-powered security signals, proactively surfaced across your entire environment

Lumina Signals is a daily feed of decision-ready security risk signals, surfacing what Sola's autonomous intelligence layer detected and prioritized across your connected data sources.

**Each day**, Sola analyzes your entire environment and surfaces what matters most right now. **Every signal has already been investigated before it reaches you**, arriving with context, reasoning, and recommended actions pre-assembled, ready for your team to act on.

<figure><img src="/files/nT4Fu3ZloYchiZXON2RP" alt="Lumina Signals"><figcaption><p>Your most critical risks, pre-investigated and prioritized across your entire environment</p></figcaption></figure>

Sola understands every resource and the connections between them, identifying deviations and risk patterns, and grouping related assets into signals. Each signal represents a compression of thousands of data points into a **focused set of meaningful risk clusters**, scored and prioritized based on what each asset means to your organization.

The most critical signals are surfaced in your daily feed. **This is a live feed that changes with your environment, not an alert queue**. There are no open or closed states. If a risk is resolved, it disappears. If it persists, it reappears.

Lumina signals operate at the workspace level, giving you a unified view across all your connected data sources.

{% hint style="info" %}
Lumina Signals is [available on paid plans](https://sola.security/pricing/).
{% endhint %}

{% embed url="<https://sola.security/pricing/>" %}

### **What makes Lumina Signals different**

* Intelligent grouping: thousands of findings compressed into meaningful risk clusters
* Cross-domain: all connected sources analyzed as one unified environment
* Context: risk scoring specific to your organization, not a generic average
* Always fresh: daily analysis, live feed, reflects your environment right now
* Pre-investigated: every signal arrives with context, reasoning, blast radius, and recommended actions already assembled

## Navigating Lumina Signals

Lumina Signals includes three main views:

Lumina Signals includes three main views:

1. **Feed** - A curated feed of your top signals, organized by security domain. Includes a personalized highlights brief summarizing the key themes and top priorities across your environment.
2. **List** - A ranked list of the top signals surfaced for your environment.
3. **Matrix** - A Risk vs. Anomaly scatter plot for visual prioritization across your signals.

<div><figure><img src="/files/nT4Fu3ZloYchiZXON2RP" alt="Lumina Signals - Feed"><figcaption><p>Feed</p></figcaption></figure> <figure><img src="/files/gab71AticD7mb5NXxCq0" alt="Lumina Signals - List"><figcaption><p>List</p></figcaption></figure> <figure><img src="/files/6ursIVSj7uMoT8livAfg" alt="Lumina Signals - Matrix"><figcaption><p>Matrix</p></figcaption></figure></div>

## How Lumina Signals works

Lumina Signals is powered by Sola's intelligence layer, a combination of AI reasoning, graph analysis, and security domain expertise that processes signals across all your connected data sources.

Each day, Sola runs the following process:

{% stepper %}
{% step %}

### Collects and unifies signals

Ingests data from all connected sources of your assets, identities, and relationships to create a single unified view.
{% endstep %}

{% step %}

### Maps your environment as a relational graph

Understands how resources interact, exposing dependencies, access paths, and potential blast radius. [Learn about Sola's security graph](/getting-started/sola-ai/security-graph).
{% endstep %}

{% step %}

### Identifies and evaluates risk signals

Analyzes risks across different security domains (misconfigurations, anomalies, attack paths, toxic combinations) in full context, not in isolation.
{% endstep %}

{% step %}

### Applies contextual reasoning and clustering

Groups related assets into meaningful risk patterns using environment, usage, and context.
{% endstep %}

{% step %}

### Surfaces what actually requires attention most

Outputs the top, focused, high-confidence signals, centrally ranked across all connected domains by impact and urgency. The most critical risks always rise to the top.
{% endstep %}
{% endstepper %}

![](/files/u9RHZRvhr64TfNP6IjXP) **The result: A curated, prioritized feed of the most critical signals across your entire environment, in one unified view.**

{% embed url="<https://sola.security/insights/ai-native-asset-intelligence/>" %}

## Context

Sola uses **context** to understand your environment and refine risk scoring.&#x20;

Context is a set of AI-inferred labels describing each asset's role, environment, and exposure profile. These labels are a key part of what makes risk scoring specific to your organization, rather than a generic industry average.

Context adjusts severity scoring in both directions. A finding can be amplified (for example, from High to Critical if the asset is production-critical) or downgraded (for example, from Critical to High if it applies to a non-production environment). When context changes a finding's severity, the signal shows both the original and adjusted score.

### Business context

**Business context** labels are inferred automatically from asset configurations, tags, names, and relationships, factoring in business function, data sensitivity, environment classification, and blast radius. They reflect what each asset actually is, how critical it is to the business, and how far a compromise could spread.

Labels are displayed in `Category: Value` format, for example:

* `Environment: Production`
* `Control Role: Orchestrator`
* `Data Type: Regulated / Sensitive`
* `Blast Radius Category: Identity Control Plane`

Click any label on a signal to see the AI reasoning behind it, including why it was assigned and how many assets it applies to.

### Adding business context

Sola infers business context automatically, but you can add context it cannot learn on its own, such as naming conventions, environment classifications, or asset priorities specific to your organization. When you add context in plain language, Sola maps it to the same business context labels and applies it across your environment, adjusting severity scoring for the affected signals.

{% hint style="info" %}
**When change apply**

Context updates take effect from the next daily analysis. Changes you add today will be reflected tomorrow.
{% endhint %}

Click **+ Context** to open the context window.

Each entry includes:

<table data-header-hidden data-search="false"><thead><tr><th width="168.5225830078125"></th><th></th></tr></thead><tbody><tr><td><strong>Description</strong></td><td>The plain-language input describing this context rule, as entered by the user.</td></tr><tr><td><strong>AI Description</strong></td><td>The context rule as Sola interpreted and applied it.</td></tr><tr><td><strong>Category</strong></td><td>The type of business context defined, such as environment type, resource role, or data type. For example: Environment, Functional Role, Control Role.</td></tr><tr><td><strong>Impact / Value</strong></td><td>The value assigned to the selected category and how it affects risk scoring across your assets. For example: Production, Core Business Function, Orchestrator.</td></tr><tr><td><strong>Applies to</strong></td><td>Where this context applies: all resource types (Global) or a specific type, such as aws_s3_bucket.</td></tr><tr><td><strong>Affected Signals</strong></td><td>The signals affected by this context rule.</td></tr><tr><td><strong>Context type</strong></td><td>The category of context this rule belongs to.</td></tr><tr><td><strong>Created by</strong></td><td>Who added the context entry.</td></tr></tbody></table>

## Reviewing signals

Your signals are available to review in the [**Feed**](#feed) and the [**List**](#list) views.

The Feed gives you a curated view of your top risks, and the List shows the full picture ranked by risk score.

Open any signal for a full breakdown of the risk, assets, and recommended actions, or start a chat to investigate further.

### Feed

The **Feed** view displays your top signals organized by security domain, with each domain showing the two highest-priority signals and an option to view all for that domain in the List.

**View all** on any domain opens the List view filtered to that domain, showing all of its signals.

Each signal card shows the Sola risk score, signal title, and a short summary of the risk and its impact, along with the connected data sources, the number of assets and findings, and a signal ID you can use to reference it in chat.

The toolbar helps you find and focus your signals:

* **Search**: find signals by keyword
* **Unreads**: show only signals you haven't reviewed
* **Sort**: change the sort order
* **Domains**: filter by security domain
* **Select**: enter selection mode for bulk actions

To mark a signal as read, open the actions menu on its card and select **Mark as read**.

### List

The **List** view displays all your signals ranked by risk score, available in card view or table view.

Each signal card highlights the most important details you need at a glance, including the **Sola Risk Score**, **signal title**, **connected data sources**, **number of assets** and **findings**, and when the signal was **last calculated**.

### Exploring a signal

Click any signal to open a detailed breakdown across five tabs: [**Overview**](#id-1.-overview), [**Business context**](#business-context), [**Assets**](#id-3.-assets), [**Findings**](#id-4.-findings), and [**Graph view**](#id-5.-graph-view).

Every signal panel shows the Name, Sola Risk Score, and Labels at the top, visible across all tabs. The Sola Risk Score is a 0–10 score where the color indicates severity level: Critical, High, Medium, Low, or Info.

#### 1. Overview

The **Overview** tab gives you a full overview of the detected risk, the assets involved, and the recommended steps to address it.

<div><figure><img src="/files/3WcAhDqrJDqJoA67JCS7" alt="Lumina - Signal list sidepanel - overview"><figcaption></figcaption></figure> <figure><img src="/files/irs1XETLSpPRdvlyXQa3" alt="Lumina - Signal list sidepanel - overview"><figcaption></figcaption></figure></div>

<table data-header-hidden><thead><tr><th width="253.3011474609375"></th><th></th></tr></thead><tbody><tr><td><strong>Summary</strong></td><td>A description of what was detected and why it matters.</td></tr><tr><td><strong>Integrations</strong></td><td>The connected data sources associated with the signal.</td></tr><tr><td><strong>Asset type</strong></td><td>The type of resource from your connected data sources at the center of this signal, such as a user, role, or cloud resource.</td></tr><tr><td><strong>Configuration anomaly</strong></td><td>How statistically unusual the asset's configuration is compared to similar assets: Baseline, Moderate, Strong, or Extreme.</td></tr><tr><td><strong>Business context</strong></td><td>AI-inferred labels describing the role, environment, and exposure profile of the assets involved. Click any chip to see the full detail in the Business Context tab.</td></tr><tr><td><strong>Recommended Remediations</strong></td><td>Recommended steps to address the risk, listed in order of priority.</td></tr></tbody></table>

#### 2. Context

The **Context** tab shows the labels assigned to assets in this signal and the reasoning behind each one.

<div><figure><img src="/files/SCycJd1jvhFJAIX9nZ3i" alt="Lumina - Signal list sidepanel - Business context"><figcaption></figcaption></figure> <figure><img src="/files/3i7MaZHIOz5ddE4utniR" alt="Lumina - Signal list sidepanel - Business context"><figcaption></figcaption></figure></div>

Labels are displayed as chips in the format `Category: Value,` for example:\
`Control Role: Orchestrator` or `Environment: Development`.

Click any label to see the AI reasoning behind it, including why it was assigned and the number of assets it applies to.

To refine business context with your own organizational knowledge, click [**+ Context**](#adding-business-context) from the main Lumina Signals page.

#### 3. Assets

The **Assets** tab shows all assets associated with this signal.

Expand any asset to see its properties. Business context chips are shown inline for each asset. Properties vary by asset type. Use search and filter to narrow down the list.

<div><figure><img src="/files/p7zgRg1SYPfT3Ah5Q8oL" alt="Lumina - Signal list sidepanel - Assets"><figcaption></figcaption></figure> <figure><img src="/files/t9H4IDeohJrC2aucB8sP" alt="Lumina - Signal list sidepanel - Assets"><figcaption></figcaption></figure></div>

#### 4. Findings

The **Findings** tab lists all security findings that contributed to this signal.

Each finding shows the name and severity. Expand any finding to see the full description and risk information.

<div><figure><img src="/files/hO9vwkflI5zXgEfkv6xw" alt="Lumina - Signal list sidepanel - Findings"><figcaption></figcaption></figure> <figure><img src="/files/NRrCu9doDNJSTlg30qND" alt="Lumina - Signal list sidepanel - Findings"><figcaption></figcaption></figure></div>

#### 5. Graph

The **Graph** view tab shows a visual map of the assets involved and how they relate to each other. It can be expanded to fullscreen.

* **Evidence**: A visual map of the asset and its relationships.
* **Blast radius**: The potential scope of impact if the risk is exploited.
* **Attack vector**: How the risk could be exploited.

<figure><img src="/files/5196ToBTyS6WGCtdTuoU" alt="Lumina - Graph View"><figcaption></figcaption></figure>

## Investigating signals in chat

Start a chat to investigate your signals with Sola AI. Sola opens a workspace-level chat grounded in your signal context, where you can ask questions and dig into the details.

<div><figure><img src="/files/uhYaHtDf8FCXaRdE9spR" alt="Investigate any signal in a chat"><figcaption></figcaption></figure> <figure><img src="/files/2kGrqQRbXRzTOwLKEaSD" alt="Investigate any signal in a chat"><figcaption><p>Investigate any signal in a chat</p></figcaption></figure></div>

There are three ways to start a chat:

* **From the chat box**: type any question in the Ask anything about your signals box at the bottom of the feed to open a chat grounded in your signals.
* **From a signal**: open the actions menu on a signal card and select Start chat to open a chat preloaded with that signal's context.
* **From multiple signals**: click Select, choose the signals you want to explore, and start a chat with context from all of them in one session.

## Acting on insights

Once you've reviewed an insight, there are several ways to act on it.

### Recommended Remediations

Each insight includes a prioritized list of recommended steps to address the risk. Review them in the Summary tab and assign or action them as needed.

### Save as a query or configure as an alert

From the Findings tab, review the findings that contributed to an insight to understand the underlying risk in detail. From there, save any finding as a query to use in a canvas or workflow, or configure it as an alert to monitor it going forward.

***

## FAQs

### How can I get Lumina Signals?

Lumina Signals is available on paid plans. [Contact Sola to learn more](https://sola.security/pricing/).

### How does Lumina Signals work?

Lumina Signals is powered by Sola's intelligence layer, which processes signals across all your connected data sources daily. For a full breakdown of the process, see [How Lumina Signals works](#how-lumina-signals-works).

### Who can access Lumina Signals?

Lumina Signals is available to workspace Admins and Owners. At least one data source must be connected to your workspace to generate insights.

### What data sources does Lumina Signals support?

Lumina Signals works with any data source connected to your Sola workspace.

Support for third-party security tools is currently not yet part of Lumina Signals. We're working on expanding coverage to include them.

### How often is my feed refreshed?&#x20;

Lumina Signals generates a fresh set of signals every day. Each daily feed reflects the latest analysis of your environment based on your connected data sources.

### Why don't I see the same insights every day?

Lumina Signals is a live feed, not an alert queue. Each day's view reflects a fresh analysis of your environment. If a risk is resolved, it disappears. If it persists, it reappears.

### Can I customize how signals are scored?&#x20;

Yes, click Add context to provide organizational knowledge, such as environment type, resource role, or data type, that influences how risks are scored and prioritized.

### What is Sola's intelligence layer?&#x20;

Sola's intelligence layer is the engine that powers Lumina Signals.

It combines AI reasoning, graph analysis, and security domain expertise to process signals across all your connected data sources, map relationships between assets, and reason across your entire environment to surface high-confidence, prioritized signals.

### Can I investigate signals in Sola AI chat?

Yes. Start a chat from the chat box at the bottom of the feed, from a single signal, or from several signals at once, and Sola opens a chat grounded in your signal context. Use it to run a deep investigation into specific findings, or to ask broader questions about risk posture and prioritization.

You can also ask risk and posture questions from any workspace or project chat. When you're in the Lumina context, Sola routes them to the Lumina specialist and surfaces the relevant signals.


# Chats

Ask questions across your entire workspace in private chats

Chats give admins a private, workspace-level chat to ask questions across all connected data sources.

They work just like a project, with every data source in your workspace connected.

**Key differences between Chats and projects**\
Chats and [projects](/workspace/projects) share the same building blocks, but differ in a few important ways:

* **Who can use it**: Chats are available to workspace admins and owners only. Projects can include any workspace member.
* **Data access**: Chats connect to every data source in your workspace. Projects connect only to the data sources assigned to them.
* **Visibility**: Chats are private to the admin who created them. Projects are visible to all their members.
* **Collaboration**: Chats are for individual use and cannot be shared. Projects are built for team collaboration, with shared workspaces, member roles, and permissions.

## Using Chats

Chats appear in the sidebar, with your most recent ones listed there for quick access. Click **Chats** to view your full list, or **New Chat** to start a fresh one.

<figure><img src="/files/oPcITEN9ul6kPzWWfDDC" alt="Workspace level chats"><figcaption><p>Workspace level chats</p></figcaption></figure>

Inside a chat, ask questions in natural language across every connected data source in your workspace. You can ask questions that span your entire environment without switching between projects.

As you investigate, create queries, canvases, alerts, and workflows directly from the conversation. All assets are owned by that chat.

Your chats are persistent. Return to any previous chat from the sidebar and pick up where you left off.

## Moving a chat to a new project

Move a chat into a new project your team can join and collaborate on.

To move a chat, open its three-dot menu, from the chat header or from the sidebar, and select Move to a new project.

{% hint style="info" %}
**Privacy and sharing when moving a chat**

After moving a chat to a new project, the chat conversation stays private to you, just as it always has. Its [queries](/workspace/projects/queries), [canvases](/workspace/projects/canvases), [alerts](/workspace/projects/alerts), and [workflows](/workspace/projects/workflows) move into the project and become available to your team.
{% endhint %}

***

## FAQs

### Can I share a chat with another admin?

No. Chats are private to the workspace admin or owner who created them and cannot be shared, even with other admins or owners.

### Can members see my chats?

No. The Chats section is only visible to admins. Members do not see it and their experience in projects is unchanged.

### What happens to assets I create in a chat?

Chat assets (queries, canvases, alerts, and workflows) are owned by that chat and stay with it. You can access them any time by returning to the chat.

### Can I turn a chat into a project?

Yes. Open the chat's three-dot menu and select Move to a new project. It creates a new project with the chat's queries, canvases, alerts, and workflows added, ready for your team to build on, and takes you there.

### Can I move a chat into an existing project?

No. Moving a chat always creates a new project. There's no option to add it to a project that already exists.


# Projects

Create custom security projects, your way

A Sola project is a custom security tool that you create, tailored for your specific security needs and area of interest. Each project you create is autonomous and supports its own use case. It can be limited to one or more data sources with different [workspace](/workspace/workspace-home) members as creators and consumers.

The project you create can range from basic and simple use cases, to specific or complex scenarios. Projects can be shared with your team members, depending on their [member roles](/system-management/settings#members). Public projects are open to all workspace members with the selected default role. Private projects require an invite.

Projects are connected to relevant data sources that allow you to [query](/workspace/projects/queries#queries) your data and gain security insights into your organization.

**Each project is made up of 5 building blocks:**

1. [**Sola AI Copilot**](/getting-started/sola-ai) - Ask questions and get insights about your security.
2. [**Queries**](/workspace/projects/queries) - Expose the underlying data from your sources.
3. [**Canvases**](/workspace/projects/canvases) - Vibe-code your data into fully interactive interfaces.
4. [**Alerts**](/workspace/projects/alerts) - Turn key questions into rules that monitor your data.
5. [**Workflows**](/workspace/projects/workflows) - Structure and automate actions with AI-native flows.

{% hint style="success" %}
**Pro tip: Create security projects your way**

![](/files/u9RHZRvhr64TfNP6IjXP) Sola gives you the flexibility to structure your projects based on your security priorities.

For example, you can create projects by security use case (e.g., Identity and Access Management), by data source (e.g., AWS Security Posture, GitHub Security Posture), or a combination of both (e.g., AWS Identity and Access Management, Salesforce Identity and Access Management).

*How you create your projects is entirely up to you. C*hoose what makes the most sense for your security needs.
{% endhint %}

## **Creating** project**s**

Your projects can be as simple or as complex as you need. Depending on how technical you want to get, the [queries](/workspace/projects/queries) component of your project provides the flexibility to query your data using natural language with Sola AI and SQL queries.

Create a new project from scratch, [move an existing chat](/workspace/chats#moving-a-chat-to-a-new-project) into a new project, join an existing one in your workspace, or use a prebuilt [template](/getting-started/templates) made by our expert security team.

{% hint style="info" %}
**Who can create and install projects?**

Only **workspace owners** and **admins** can create projects, join existing projects, or install [templates](/getting-started/templates).
{% endhint %}

<figure><img src="/files/0DGipttKgpaGrSXMtnp7" alt="Joining a workspace"><figcaption><p><em>Joining a workspace</em></p></figcaption></figure>

<figure><img src="/files/BkI72YuQKANnmZ9S9Szt" alt="Creating a new app from templates"><figcaption><p>Creating a new project from templates</p></figcaption></figure>

![](/files/DESMoC6l1Gr9uaynao5N) Sola AI helps you quickly generate queries and refine them, making it easier to explore your data and uncover insights.

<figure><img src="/files/KYNJIDENyGbNeG2amXSJ" alt="Using Sola AI to query data and fine-tuning the generated SQL query"><figcaption><p><em>Using Sola AI to query data and fine-tuning the generated SQL query</em></p></figcaption></figure>

## Connecting data sources

To create a new project, you’ll need to connect it to one or more [data sources](/integrations/data-sources).

Connecting your data source is important because it allows you to get answers to your questions that are relevant to your data. By linking your data sources, you can easily find security insights and answers based on your organizational data.

{% hint style="info" %}
You can skip this step for now and use a placeholder data source, which includes only the table schema (without data). Connect your data source later when you're ready.&#x20;
{% endhint %}

## Viewing and collaborating on projects

Sola provides two ways to access projects in your workspace:

* **My Projects** - Projects that you are a member in, whether created by you or someone else
* **Workspace Projects** - Projects in your workspace that you can join.

Collaborate in real time to share insights, refine security findings, and build on each other's work. See who else is active in the same project or building block as you create.

<figure><img src="/files/QZDf7w57AOcf2P22P8Gb" alt="Collaborate in real time"><figcaption><p>Collaborate in real time</p></figcaption></figure>

***

## FAQs

### Who can create or install projects in Sola?

Only workspace owners and admins can create projects, join existing projects, or install [templates](/getting-started/templates). If you don’t have the necessary permissions, reach out to your workspace admin.

### How does Sola AI assistant use my data?

Sola AI assistant follows strict security practices to keep your data safe. Your data is stored securely according to [our standard security policies](https://sola.security/privacy-policy/).

Sola AI assistant does not use your data to train our models. Any data processed through Sola AI is used solely to generate responses and is not retained for training purposes.

### Can I enable or disable the Sola AI Assistant?

Yes. You can enable or disable the option to skip the Sola AI assistant when creating new queries.

<br>


# Queries

Query your security data for insights

Queries help you analyze security risks by retrieving relevant data from your connected sources. Querying your data allows you to explore your security posture across different environments, detect potential threats, and uncover critical security insights.

Queries are one of the building blocks that make up a [project](/workspace/projects), alongside [canvases](/workspace/projects/canvases), [alerts](/workspace/projects/alerts), and [workflows](/workspace/projects/workflows).

<figure><img src="/files/aj3BM13VZntQpYlvm3Pg" alt="Query real-time collaboration"><figcaption><p>Query real-time collaboration</p></figcaption></figure>

## Creating queries

There are two ways to create queries:

* **Use Sola AI** to ask security-related questions in natural language and generate queries automatically.
* **Write your queries** from scratch using the SQL query editor.

{% hint style="info" %}
**Pro tip: Enhance your SQL queries with** ![](/files/DESMoC6l1Gr9uaynao5N) **Sola AI**

Sola AI can help you identify the right tables and columns that contain the data you need or refine SQL syntax for more accurate results.
{% endhint %}

Once created, queries can be **saved**, **published**, and **modified** to refine your insights over time.

## Publishing queries

A query extracts a specific dataset from your connected data sources. Publishing a query saves the retrieved dataset as a table in your project. This makes the data set available across your project for:

* [Canvases](/workspace/projects/canvases) - Turn query results into charts, graphs, and tables.
* [Alerts](/workspace/projects/alerts) - Set up alerts based on query results.&#x20;
* [Workflows](/workspace/projects/workflows) (*coming soon*) - Automate security actions.

## Managing queries

The **Query Library** is where you can access all queries in your project.

Queries can be:

* **Published** - Available for use across the project building blocks and accessible to all project members.
* **Private drafts** - Visible only to you until shared.

<figure><img src="/files/ouGRYFwQQvZ4A8Mu5y7L" alt="Public and private queries in query library"><figcaption><p>Public and private queries in query library</p></figcaption></figure>

Queries have two modes:

* **View mode** - Displays the last published version of the query.
* **Edit mode** - A real-time shared draft, where multiple users can collaborate, edit together, and see changes live before publishing.

{% hint style="info" %}
Edits are only applied and visible to all project members once published. When you publish, all changes you and others have made are published together.
{% endhint %}

In the query library, depending on your role permission, you can:

* **View** all available queries in your project.
* **Create** and **modify** queries.
* **Duplicate** a query to modify it without changing the original.
* **Delete** a query.\
  *Note*: This action cannot be undone. Assets using the query, such as canvases or alert rules, will break or stop working.

{% hint style="info" %}
To manage your **project role permissions**, go to *Workspace Settings* > [*Project Permissions*](/system-management/settings#app-permissions).
{% endhint %}

{% hint style="success" %}
**Pro tip: Refine your SQL queries with Sola AI**

![](/files/DESMoC6l1Gr9uaynao5N) Access Sola AI from the query sidebar, or use the AI icon next to Run Query for quick actions:

* **Optimize** - Improve query efficiency.
* **Explain** - Understand what the query does.
* **Debug** - Identify syntax issues and get suggested fixes.
  {% endhint %}


# Canvases

Vibe-code your data into fully interactive interfaces

Canvases are an **AI-powered** way to transform your security data into **fully customizable interactive interfaces**. Think of it as a vibe-coding app builder, driven by Sola’s unique capabilities to ingest, understand, and query your security data.

Use natural language prompts to create any interactive dashboard or report with dynamic charts, tables, filters, and other interactive visuals, from your [query results](/workspace/projects/queries) and [connected data](/integrations/data-sources).

Get the exact results you want with unlimited flexibility in layout, customization, colors, fonts, and styles.

Canvases are one of the building blocks that make up an [project](/workspace/projects), alongside [queries](/workspace/projects/queries), [alerts](/workspace/projects/alerts), and [workflows](/workspace/projects/workflows).

<figure><img src="/files/UGYKUlJhbBYBKhbDiiku" alt="Vibe-code your security data into fully interactive dashboards"><figcaption><p><em>Vibe-code your security data into fully interactive dashboards</em></p></figcaption></figure>

<div><figure><img src="/files/Q6lkTw9T3ZXvV8mnd4IJ" alt=""><figcaption></figcaption></figure> <figure><img src="/files/KDtYfvZVoGhqcfkpqkuy" alt=""><figcaption></figcaption></figure> <figure><img src="/files/t5wuxJtaJL9hdfEyFbCK" alt=""><figcaption></figcaption></figure> <figure><img src="/files/kIwWYLN6zqkyO4JqP2we" alt=""><figcaption></figcaption></figure> <figure><img src="/files/uX9oZeBnBdWrVyIcFbA2" alt=""><figcaption></figcaption></figure> <figure><img src="/files/I42oSoIdOEluSZSyWUjG" alt=""><figcaption></figcaption></figure></div>

## Creating canvases

**To create a canvas**, click *New canvas* from the *Canvases* tab and describe the dashboard or insights you want in a prompt. Sola AI will generate your canvas.

Once the canvas is created, it is automatically published and available to all project members.

{% hint style="success" %}
See the [Prompt Guide](/getting-started/sola-ai/prompt-guide) for tips and examples to refine your prompts and get the best results.
{% endhint %}

## Managing canvases&#x20;

The **Canvas Library** is where you can access all canvases in your project.

Canvases are live, interactive interfaces that update as you change them. Edits by collaborators are applied in real time and visible to all project members.

Canvases are tied to your connected data, they continuously update to reflect the latest query results and configurations, ensuring insights stay current without manual refresh.

## Editing canvases

Canvases can be edited using Sola AI or the canvas code editor. Sola AI allows you to modify canvases with natural language prompts, generating the layout, components, and styling based on your description. Advanced users can use the canvas code editor to directly modify canvas source code with full control over layout, styling, and behavior.

### Canvas code editor

View and edit canvas source code directly with the code editor. Work in split-screen mode with your canvas visible beside the code, making it easy to debug, customize, and iterate without leaving the canvas. Access version history to review or restore previous iterations.

<div><figure><img src="/files/mxPUBBlLMi1cphUZZrEz" alt="Canvas code editor split screen"><figcaption><p>Canvas code editor split screen</p></figcaption></figure> <figure><img src="/files/B848JoykyiHxyTvrd8kb" alt="Code editor button in canvas toolbar"><figcaption><p>Code editor button in canvas toolbar</p></figcaption></figure></div>

## Examples and use cases

Canvases are flexible and support a wide range of security use cases, such as monitoring, tracking, and guiding.

### Monitor

Track security posture, exposures, and compliance checks in one place.

For example,

* Cloud Security Posture (CSPM) dashboard.
* Attack Surface Management (ASM) exposure tracking.
* Vulnerability management reports by severity/repo.

### Explore

Drill into assets, vulnerabilities, and risks to follow changes over time.

For example,

* Asset inventory boards (with filters and drill-down).
* Threat intel trackers with prioritized IOCs.
* Patch tracking dashboards.
* Access review boards (Okta/Azure AD risky accounts).

### Report

Provide high-level summaries and compliance views for leadership and audits.

For example:

* Executive reports highlighting key risks, posture trends, and KPIs.
* Compliance summaries for SOC2/ISO readiness and audit preparation.
* Risk heatmaps and scoring across business units or domains.
* Posture overview dashboards tailored for board or CISO reporting.

### Guide

Provide structured security knowledge and step-by-step instructions for teams.

For example,

* Developer onboarding security guides.
* SOC runbooks with step-by-step instructions.
* Secure coding quizzes/games.
* Attack simulation walkthroughs.

{% hint style="success" %}
Each canvas is generated with Sola AI prompts.&#x20;

See the [Prompt Guide](/getting-started/sola-ai/prompt-guide) for tips and examples of how to phrase your requests for different use cases.
{% endhint %}

***

## FAQs

### What kinds of visualizations can I add to a canvas?

Canvases support a wide range of visuals to fit different use cases. You can add dynamic charts (bar, line, pie, stacked), interactive tables, scorecards, and counters for KPIs. Beyond data, canvases also allow you to embed text blocks, images, and layouts—making it possible to build narrative-driven dashboards, security guides, or even fully branded executive reports.

### Can I create canvases that combine data from multiple sources?

Yes. Canvases can unify insights from multiple sources in a single view. For example, you can correlate AWS cloud configurations, GitHub repository settings, and Okta identity data side by side to reveal risks, toxic combinations, or compliance gaps across your environment.

### Can I share canvases?

Canvases are only visible within your project.<br>


# Alerts

Stay informed about security risks and policy violations

Alerts help you track security risks, misconfigurations, and policy violations by notifying you when query records meet specific conditions. They allow you to proactively monitor security events and respond quickly when risks arise.

Alerts are one of the building blocks that make up an [project](/workspace/projects), alongside [queries](/workspace/projects/queries), [canvases](/workspace/projects/canvases), and [workflows](/workspace/projects/workflows).

<figure><img src="/files/dsa6ImNcFKMYdY5LGw53" alt="Reviewing triggered alerts"><figcaption><p>Reviewing triggered alerts</p></figcaption></figure>

## Creating alert rules

Alerts allow you to track security risks by monitoring query records and triggering notifications when conditions are met.

To create an alert rule, from the *Alerts* tab of your project, go to *Alert Rules* > click *New rule*.

Define the following in the Sola wizard:

* **Rule query** - Select the query you want to monitor. Use an existing published query.
* **Query record fingerprint** - Specify which columns uniquely identify your records for deduplication. By default, all columns are included.
* **Grouping** - Configure how query records are grouped into alerts with findings.
* **Alert scope** - Choose whether to apply the rule to all existing query records or only new ones, after the rule is enabled.\
  Note: Simulation will run on existing records.
* **Alert name** - Use the rule name or a custom alert name. Insert dynamic placeholders for dynamic alert names.\
  *Note*: Use $ to add a dynamic placeholder (e.g., ${id}, ${created\_at})
* **Alert description** - Add a description that will appear with the triggered alert. Insert dynamic placeholders for dynamic alert descriptions.\
  Note: Use $ to add a dynamic placeholder (e.g., ${id}, ${created\_at})
* **Steps to remediate** - Add guidance on how to fix or address this issue.
* **Alert severity** - Select the alert severity level.
* **Activate rule** - Enable to start enforcing this rule on the selected query.
* **Alert email notifications** - Add members or valid email addresses to get email notifications when this alert is triggered.
* **Alert Slack notifications** - Send notifications to Slack channels and direct messages when alerts are triggered or new evidence is discovered. Requires [Slack connector](/integrations/connectors/slack) integration. Make sure to add the Sola integration @Sola app to your Slack channel before sending to enable notifications.

{% hint style="info" %}
**Email notifications are sent for:**

* New alerts (excluding those triggered during the initial alert rule setup)
* Newly discovered evidence in existing alerts
  {% endhint %}

{% hint style="info" %}
**Available dynamic placeholders depend on the Grouping setting**

* If no grouping is applied, all query columns can be used as dynamic placeholders.
* If grouping is based on specific columns, only those columns will be available as dynamic placeholders.

This applies to both Alert Name and Alert Description.
{% endhint %}

Once configured, alerts will automatically track matching query records and display them in the [triggered alerts](#triggered-alerts) view.

## Managing alert rules

Alerts are managed in two views:

### Triggered alerts

The *Triggered Alerts* view is where you can:

* **View** all triggered alerts and their severity.
* **Investigate** findings and update the alert status as you resolve them.
* **Assign** alerts to team members for resolution.

### Alert rules

The *Alert Rules* view is where you can:

* **Create and edit** alert rules to track security findings.
* **Enable or disable** rules as needed.
* **Delete** rules that are no longer relevant.

{% hint style="info" %}
**Your permissions depend on your project role**&#x20;

Project permissions, such as create and edit, are based on your project role.\
To see available permission levels and check your role, go to Settings > [Workspace Settings](https://docs.sola.security/workspace/projects/pages/l69Cxh11wZLxhFByYYn5#id-2.-workspace-settings).
{% endhint %}

{% hint style="warning" %}
**Editing an alert rule**: Once an alert rule is created, you can edit the name, description, severity, remediation steps, fingerprint, grouping, and alert scope.

Modifying fingerprint, grouping, or alert scope will deprecate existing triggered alerts and recalculate the rule to generate new alerts based on the updated configuration.

The query cannot be modified, to change the query, create a new rule.
{% endhint %}

## Alert lifecycle evidence

When an alert is triggered, it includes supporting evidence that helps you understand why the alert was triggered. Evidence is categorized into three states, which impact the alert lifecycle:

1. **Active evidence** - Evidence found in the last alert calculation.
2. **Excluded evidence** - Evidence found that was manually excluded from the active evidence list. Excluded evidence can be re-activated if needed.
3. **Old evidence** - Evidence that existed in a previous calculation but is no longer detected.

To review evidence for a triggered alert, click on an alert from the triggered alerts view.

Managing evidence enables you to control when an alert remains active, is resolved or suppressed.

## Reviewing alerts

After an alert is triggered, you can review its details, investigate findings, and take action.

Opening an alert shows the matching query records and why it was triggered.

You can assign alerts to team members and update their status as you work through them.

### Alert statuses

<table><thead><tr><th width="216">Status</th><th>Description</th></tr></thead><tbody><tr><td>Open</td><td>A new alert has been triggered and requires investigation.</td></tr><tr><td>In Progress</td><td>The alert is being reviewed or worked on.</td></tr><tr><td>Suppressed</td><td>The alert is acknowledged but does not require action.</td></tr><tr><td>Resolved</td><td>The issue has been addressed and no longer needs attention.</td></tr><tr><td>Auto-Resolved</td><td>The issue has been automatically resolved by the system, since there is no active evidence.</td></tr><tr><td>Deprecated</td><td>The alert has been deprecated, since the query used in the alert rule, representing the rule logic, has changed.</td></tr></tbody></table>


# Workflows

Structure and automate your security operations with AI-native flows

**Agentic Workflows** bring intelligent Directed Acyclic Graph (DAG) structure and automation to your security projects. Use workflows to structure multi-step actions, orchestrate investigations, and automate across [data sources](/integrations/data-sources) and [connectors](/integrations/connectors).

Workflows are one of the building blocks that make up an [project](/workspace/projects), alongside [queries](/workspace/projects/queries), [canvases](/workspace/projects/canvases), and [alerts](/workspace/projects/alerts).

<figure><img src="/files/4KeqJFTXMMJ9NsLpKrNk" alt="Agentic Workflows"><figcaption><p>AI-powered workflows</p></figcaption></figure>

{% hint style="success" %}
Workflows combine **AI-native reasoning** with **structured execution** to overcome single prompts and old school automation limitations, bringing flexibility, transparency, and real-world resilience **to your security operations**.

<p align="right"><img src="/files/u9RHZRvhr64TfNP6IjXP" alt=""> <a href="https://sola.security/blog/agentic-workflows-security-operations/"><strong>Learn more in the Sola blog</strong></a> </p>
{% endhint %}

{% hint style="info" %}
**Pricing and plans**

Workflows can be created on the Free plan.\
Execution and automatic enablement are available on [paid plans](https://sola.security/pricing/).
{% endhint %}

{% embed url="<https://sola.security/pricing/>" %}

## Workflow components

Workflows are made up of key components that define how they start, run, and deliver results.

{% hint style="info" %}
**Single-step AI block**

In Sola Workflows, each **AI block (step)** is like an AI agent. It takes input from the previous block, uses the necessary data sources and tools, and performs the task defined in the prompt.
{% endhint %}

<table data-header-hidden><thead><tr><th width="177.31640625">Component</th><th>Description</th></tr></thead><tbody><tr><td><strong>Trigger</strong></td><td><p>Defines when a workflow starts, such as on a schedule (e.g., daily at 10 AM), in response to an event (e.g., a new alert), or manually.</p><p><br>Defines when a workflow starts. Supported trigger types: <strong>Schedule</strong> (at a defined time or interval), <strong>Alert</strong> (when a specific alert fires), <strong>On-demand</strong> (triggered manually), or <a href="#webhook-trigger"><strong>Webhook</strong></a> (triggered by an incoming HTTP request from an external system).</p></td></tr><tr><td><strong>Step / Block</strong></td><td>A single action in the workflow, such as running security queries, filtering results, performing cross-platform checks, sending notifications, or sending emails.</td></tr><tr><td><strong>Prompt</strong></td><td>The AI instruction that guides a workflow step.</td></tr><tr><td><strong>Automation</strong></td><td>The ability to automatically gather, analyze, and take action on data (e.g., find users without MFA, determine who has the most permissions, send a Slack message, send an email, or create a ticket).</td></tr><tr><td><strong>Integrations</strong></td><td><a href="/pages/vYlag84wtwlnfmuULiEh">Data sources</a> and <a href="/pages/rbkjXI8u4MU5mYr6onVw">connectors</a> (e.g., AWS, GitHub, Slack, Jira) for coordinated actions.</td></tr><tr><td><strong>Notifications and reporting</strong></td><td>Configurable outputs at the end of a workflow to share results, alerts, or summaries with relevant stakeholders.</td></tr><tr><td><strong>Execution</strong></td><td>A single run of a workflow from trigger to completion, with all steps performed and results tracked for review.</td></tr><tr><td><strong>Directed Acyclic Graph (DAG)</strong></td><td>The structured visual representation of workflow steps, showing the order, logic, and connections without loops.</td></tr></tbody></table>

## Creating workflows

Workflows enable multi-step orchestration and automations that use queries, [connectors](/integrations/connectors), and AI to respond to security issues, coordinate actions, and reduce manual effort. They can be used for remediation, enrichment, reporting, and other structured flows directly inside your project.

Each workflow is structured as a Directed Acyclic Graph (DAG), giving you precise control over the order, conditions, and logic of each step. Ensuring consistent, repeatable responses to security events.

**To create a workflow**, use [Sola AI](/getting-started/sola-ai) to describe the outcome you want.&#x20;

Sola AI will build your workflow, adding AI blocks (steps) with **prompts**, **connectors**, and **logic** based on your request. You can then review and adjust each prompt, connected data sources, and actions.

{% hint style="info" %}
Workflows can only be created with Sola AI, not by manually building steps.

Describe the workflow you need, and Sola AI will generate the blocks and logic for you, which you can adjust manually or with Sola AI.
{% endhint %}

## Running and managing workflows

Workflows can be run manually, on a schedule, or triggered by events within Sola. When a workflow runs, each AI block executes in sequence according to the defined sequential logic.

**To run a workflow**:

* **On-demand** - Trigger the workflow manually from the project.
* **Schedule** - Run the workflow automatically at a defined time or interval.
* **Alert** - Start a workflow when a specific alert fires.
* **Webhook** - Start a workflow automatically when an external system sends an HTTP request to the workflow's webhook URL.

After a run completes, you can review the output for every step to see what actions were taken, what data was used, and the results produced. This provides visibility to validate the workflow’s effectiveness and debug issues.

**To manage a workflow**:

* **Edit step prompts** - Adjust the instructions for each step manually or with Sola AI.
* **Update connectors** - Change or add integrations used by the workflow.
* **Adjust logic** - Modify conditions, branching, or sequence to adapt to evolving needs.

### Webhook trigger

The webhook trigger lets you start a workflow automatically from any external system that can send an HTTP request, such as a security tool, alerting platform, or custom script.

To set up a webhook trigger:

1. Open a workflow and click the Trigger block to open the side panel.
2. Select the Webhook trigger, name the tigger,&#x20;
3. Give the trigger a name (optional).
4. Click Save. The webhook URL is generated automatically after the first save.
5. Copy the URL and configure it in your external system.

Optionally, add Advanced filters to control which incoming payloads trigger the workflow.

{% hint style="info" %}
**Rotating your webhook URL**

Use Refresh token in the trigger side panel to rotate your webhook URL. Make sure to update any external systems using the old URL.
{% endhint %}

## What makes Sola workflows different

![](/files/u9RHZRvhr64TfNP6IjXP) **AI-native, not just AI-supported**\
Sola Workflows don’t just use AI, they are AI native. AI drives the logic, flow, and outcomes. This means they can reason and adapt dynamically, making them far more flexible and effective than traditional automations.

![](/files/u9RHZRvhr64TfNP6IjXP) **Resilient and adaptive execution**\
Traditional automations fail when they hit friction such as missing data, edge cases, or unexpected inputs. Sola’s AI-led workflows adapt in real time. They’re designed to creatively solve blockers, improvise when needed, and maintain progress toward meaningful outcomes.

![](/files/u9RHZRvhr64TfNP6IjXP) **Deterministic where it matters**\
Sola combines the flexibility of AI with the control of determinism. Enforcing strict and reliable logic for actions where precision is critical. Ensuring predictability and auditability.

![](/files/u9RHZRvhr64TfNP6IjXP) **Security intelligence built-in**\
Every workflow is grounded in Sola’s domain expertise and understanding of security context. Instead of just executing tasks, workflows reason over identity, access, risk severity, and posture impact, turning automations into intelligent responses.

## Workflow credits and usage

Workflow credits power AI usage for running agentic workflows. Each workflow run consumes workflow credits based on the number of steps and the complexity of the workflow.

**Your workflow credit allowance refreshes weekly** on the same day your subscription began. Workflow credits do not roll over. If you reach your weekly workflow credit limit, workflow executions pause until credits refresh.

[**Upgrade your plan for higher limits.**](https://sola.security/pricing/)

{% embed url="<https://sola.security/pricing/>" %}

***

## FAQs

### Are workflows only for automating scheduled processes?

No. A single prompt can be used in most cases. However, when running complex and multiple step investigations, workflows can help create a relatively more deterministic outcome, be simpler to debug and provide more transparency into the outcome of each step in a long process.

### What data sources and connectors can workflows use?

Workflows can potentially utilize any data source or connector associated with the project it is built in. To do this, data sources and connectors must be associated with the project beforehand. In addition, like the chat, workflows have the native ability to use the web for fetching specific information (with the same compliance and guardrails of the Sola chat).<br>


# Agents

AI agents that investigate, reason, and act on your behalf

Agents are AI-powered intelligence units that reason and act on your behalf. Use them to investigate alerts, triage incidents, and take action across your connected data, each with its own instructions, tools, and memory.

<figure><img src="/files/fMNBujNnnBuJjkuY6avq" alt="Sola AI Agents"><figcaption><p>Sola AI Agents</p></figcaption></figure>

{% hint style="info" %}
Agents are [available on paid plans](https://sola.security/pricing/).
{% endhint %}

{% embed url="<https://sola.security/pricing/>" %}

## Adding agents

Install a pre-built ready to use agent or create a custom agent built for your team's specific workflows and needs. Creating, editing, and managing agents requires Owner or Admin access.

To add an agent, go to **Agents** and click **Add agent**. You can also create an agent directly from Sola AI by describing the agent you need in the chat.

### Installing pre-built agents

Browse ready-made agents from Sola, each designed and tested for a specific security domain. Installing one makes it immediately available to everyone in your workspace.

<figure><img src="/files/l7h65UDhqyEcfDLIslYy" alt="Ready-made agent templates"><figcaption><p>Ready-made agent templates</p></figcaption></figure>

#### Available agents

<table data-view="cards"><thead><tr><th align="center"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td align="center"><strong>Tier 1 Investigator</strong><br>Triages vendor alerts, enriches IOCs, and delivers a T1 summary with an escalate, close, or monitor recommendation.</td><td><a href="https://app.sola.security/agents?gallery=&#x26;galleryAgent=6a2af95457ccaa1217955493">https://app.sola.security/agents?gallery=&#x26;galleryAgent=6a2af95457ccaa1217955493</a></td></tr><tr><td align="center"><strong>IT Security</strong><br>Audits identity and endpoint hygiene across your stack: MFA gaps, dormant accounts, privileged access sprawl, and offboarding exposure.</td><td><a href="https://app.sola.security/agents?gallery=&#x26;galleryAgent=6a37dc4133322fe92aed6b59">https://app.sola.security/agents?gallery=&#x26;galleryAgent=6a37dc4133322fe92aed6b59</a></td></tr><tr><td align="center"><p><strong>Offboarding Risk Monitoring</strong></p><p>Identifies upcoming and recent leavers and flags terminated users with active access or ongoing exposure.</p></td><td><a href="https://app.sola.security/agents?gallery=&#x26;galleryAgent=6a2ac3681b88b3a42533f7da">https://app.sola.security/agents?gallery=&#x26;galleryAgent=6a2ac3681b88b3a42533f7da</a></td></tr></tbody></table>

### Creating custom agents

Custom agents give you full control over how an agent thinks, what it can access, and how it behaves. Each custom agent has its own instructions, tools, and [skills](#skills), and is available in your workspace to your entire team.

#### **Tools**

* **Web search** - Search the web for up-to-date information
* **Canvases** - Generate and save visual canvases
* **Alerts** - Set up recurring alerts based on findings
* **Workflows** - Create and modify automated workflows
* **Slack** - Send messages and interact with Slack
* **Jira** - Create and update Jira issues
* **AbuseIPDB** - Query IP reputation data from AbuseIPDB
* **Shodan** - Search internet-connected devices via Shodan

{% hint style="info" %}
Agents always run within the scope of the chat or project they're called from, and can only access the tools you explicitly allow. They do not own data.
{% endhint %}

#### Skills

[Skills](/workspace/skills) are domain-specific instruction sets that shape how an agent handles specific scenarios. Assigning skills to an agent extends its knowledge beyond its core instructions, without having to rewrite them.

Select from skills already installed in your workspace, or add new ones.

{% hint style="info" %}
**Disabling skills**

To disable a skill, remove it from any active agents first.
{% endhint %}

#### Instructions

Instructions are the agent's system prompt. They define its role, what it should and shouldn't do, and how it should communicate. The more specific your instructions, the more consistently the agent will behave.

* Role & responsibility: The agent's primary goal and area of focus.
* Constraints and limitations: What the agent should and should not do.
* Response style: How the agent should communicate and format its output.

## Invoking an agent

When you @mention an agent in chat, it receives your message, reasons over it using its approved tools and connected data, and returns a response in the thread. Agents run asynchronously. You can continue your conversation while the agent works.

**To invoke an agent manually**, type @ in the chat input to open the agent picker. Select the agent, add your message, and send.

You can continue your main chat while the agent works. When the agent is ready, its response will appear in the thread referencing your original message.

<figure><img src="/files/TT4J9204q58duCCM5V2H" alt="Invoke an agent with @mention"><figcaption><p>Invoke an agent with @mention</p></figcaption></figure>

{% hint style="info" %}
**Active agents**\
When an agent is running in the chat, an indicator bar appears above the chat input, allowing you to monitor active sessions.
{% endhint %}

**To run an agent automatically**, use [Routines](/workspace/routines) to schedule it, instead of invoking it manually each time. This is useful for recurring investigations or ongoing monitoring.

## Agent memory

Agents remember context across chat sessions. Memory is a persistent store the agent reads and writes across conversations, it retains relevant information from past interactions and applies it to new ones, without you having to repeat yourself.

The agent updates its memory independently when it determines that information is worth keeping, such as confirmed findings, preferences, or decisions made during an investigation. You can also explicitly ask an agent to remember something.

## Managing agents

The Agents page gives you a workspace-wide view of all installed and custom agents. From here you can see what's active, control which agents are enabled, and manage settings for each one.

**To manage your agents**, go to ***Agents***.

From the Agents page you can:

* See all installed and custom agents at a glance.
* Enable or disable any agent.
* Try in project, Try in chat, Edit, Duplicate, or Delete.
* Add new agents.

## Agents, workflows, skills, and routines

**Agents think. Workflows orchestrate. Skills guide. Routines automate.**

**Agents** reason dynamically and act on your behalf across connected tools and data. @mention them in chat to investigate, triage, and take action. They are best for open-ended investigations and flexible tasks.

[**Workflows**](/workspace/projects/workflows) execute a predefined sequence of steps in a specific order. Trigger them manually or on a schedule to automate repeatable tasks. They are best for repeatable, structured automations.

[**Skills**](#skills) shape how an agent or Sola AI behaves in a specific domain. Assign them to an agent or apply them in chat to extend its knowledge. They are best for specializing an agent's focus or expertise.

[**Routines**](/workspace/routines) run an agent automatically on a schedule or trigger. Configure one with a task, an agent, and a project scope, and Sola runs it for you. They are best for recurring investigations where the path to the answer may vary.

***

## FAQs

### How are agents different from workflows?

Agents and [workflows](/workspace/projects/workflows) are complementary, not interchangeable. Agents reason dynamically: given a question, they decide how to investigate and respond. Workflows execute a predefined sequence of steps in a specific order. Use agents for open-ended investigations and flexible tasks. Use workflows for repeatable, structured automations where each step is defined in advance.

### How are agents different from skills?

[Skills](/workspace/skills) are instruction sets that shape how an agent (or Sola AI) behaves in a specific domain. An agent is the actor, with its own role, memory, and approved tools. A skill is a specialization applied on top. You can assign multiple skills to a single agent to broaden what it knows.

### Does the agent have access to all my data?

No. Agents do not own or have standing access to data. When invoked, an agent runs within the context of the chat or project it's called from, and can only access the data sources and connectors available in that context. You control which tools the agent can use when you configure it.

### Can I invoke multiple agents in the same chat?

Yes. You can @mention different agents within the same chat. Each invocation runs independently. The active agents indicator bar above the chat input shows which agents are currently running.

### What happens when an agent creates an artifact?

By default, agents suggest artifacts ([queries](/workspace/projects/queries), [canvases](/workspace/projects/canvases), [alerts](/workspace/projects/alerts), or [workflows](/workspace/projects/workflows)) and wait for your confirmation before saving them when invoked in chat. This keeps your workspace clean and ensures you stay in control of what's created. When an agent runs through a [Routine](/workspace/routines) on a schedule, it creates artifacts automatically, since there's no one present to confirm.

### Can an agent remember something specific about how I work?

Yes. You can tell an agent to remember something directly in the conversation: "Remember that we always exclude test accounts from user audits." The agent will store this in its memory and apply it in future sessions. Memories are shared across all workspace members who invoke the agent.

### Who can create and manage agents?

Owners and Admins can create, add, edit, delete, duplicate, manage, and invoke agents. Contributors can invoke agents via @mention.

### Can I run an agent automatically, without invoking it myself?

Yes. [Routines](/workspace/routines) run an agent automatically on a schedule you define, using the same instructions, tools, and skills the agent already has. Use routines for recurring investigations or monitoring; use @mention for one-off, interactive requests.


# Skills

AI skills that bring domain expertise to any chat or project

Skills are instruction sets built around a specific domain. Apply them in [chat](/workspace/chats) or assign them to [agents](/workspace/agents).

<figure><img src="/files/Ay7qNfZy4EUoQsa9Kwef" alt="Sola AI Skills"><figcaption><p>Sola AI Skills</p></figcaption></figure>

{% hint style="info" %}
Skills are [available on paid plans](https://sola.security/pricing/).
{% endhint %}

{% embed url="<https://sola.security/pricing/>" %}

## Adding skills

Install a ready-made skill from Sola, or create a custom skill built for your team's specific workflows. Once installed or created, skills are available across your entire workspace to use in chat and assign to agents. Creating, editing, and deleting skills requires admin access.

To add a skill, go to Skills and click Add skill.

### Installing pre-built skills

Browse ready-made skills from Sola, each designed and tested for a specific security task. Search by name or description, and open any skill to see what it does before installing.

<figure><img src="/files/Njxe44gnDTuOBpUIORM2" alt="Ready-made skill templates"><figcaption><p>Ready-made skill templates</p></figcaption></figure>

#### Available skills

<table data-view="cards"><thead><tr><th align="center"></th></tr></thead><tbody><tr><td align="center"><strong>Okta Expert</strong><br>Reads Okta sign-ins, MFA, admin, and OAuth activity to spot impossible travel, MFA fatigue, session hijack, and weak-factor use, and enriches any user across vendors.</td></tr><tr><td align="center"><strong>Entra ID Expert</strong><br>Reviews Microsoft Entra sign-ins, MFA posture, Conditional Access gaps, admin and PIM roles, guest access, and Identity Protection risk detections with license-tier awareness.</td></tr><tr><td align="center"><strong>Google Workspace Expert</strong> Investigates Google sign-ins, admin actions, Drive sharing and downloads, Gmail forwarding, OAuth grants, and Domain-Wide Delegation to run account-compromise, 2SV, and post-departure audits.</td></tr><tr><td align="center"><strong>HiBob Expert</strong><br>Adds HR truth to any user: employment status, tenure, termination date, role, department, and manager. Catches HR-to-IT deprovisioning gaps and the contractor blind spot.</td></tr><tr><td align="center"><strong>CrowdStrike Expert</strong><br>Explains Falcon detections, walks alert triage and false-positive tuning, and covers sensor policy, Spotlight vulnerabilities, cross-vendor identity joins, and ATT&#x26;CK coverage.</td></tr><tr><td align="center"><strong>SentinelOne Expert</strong><br>Explains SentinelOne threats and the full Storyline attack chain, plus mitigation state, agent health, analyst review status, and false-positive tuning per detection type.</td></tr><tr><td align="center"><strong>Azure Sentinel Expert</strong><br>Unpacks Microsoft Sentinel incidents back to the source system that fired them and covers analytics rule types, UEBA scores, MITRE mapping, sign-in tradecraft, and what data is actually flowing in.</td></tr><tr><td align="center"><strong>Datadog Expert</strong><br>Interprets Datadog Cloud SIEM signals, suppression, and content packs, and flags when Datadog is running as pure observability with no real security detection coverage.</td></tr><tr><td align="center"><strong>Wiz Expert</strong><br>Analyzes Wiz cloud issues, misconfigurations, attack paths, and toxic combinations across AWS, Azure, and GCP, and separates prioritized Issues from raw Findings noise based on which modules are deployed.</td></tr><tr><td align="center"><strong>MITRE ATT&#x26;CK Exper</strong>t<br>Maps detections, alerts, and attacker behavior to ATT&#x26;CK tactics and techniques, highlights coverage gaps, and handles per-vendor technique fields honestly.</td></tr><tr><td align="center"><strong>EPSS-KEV Expert</strong><br>Prioritizes vulnerabilities using real-world exploitation signals, EPSS probability and CISA's Known Exploited Vulnerabilities catalog, instead of CVSS alone.</td></tr></tbody></table>

### Creating custom skills

Custom skills give you full control over how Sola AI behaves for a specific task.

* Name - A unique, human-readable name for the skill
* Description - What the skill does and when to use it
* Instructions - The skill's system prompt, defining its core logic and behavior

{% hint style="info" %}
**How to make your skills more effective**

Sola uses the name and description of each skill as a directory to know when to load it into context at runtime. The more precise they are, the more consistently the right skill activates.
{% endhint %}

### Instructions

The **Instructions** field is the core of the skill. The more specific your instructions, the more consistently the skill applies its expertise.

* **Domain focus**: What area or tool the skill specializes in, and the context it needs to reason well.
* **Scope**: What the skill should and should not do.
* **Response style**: How it should communicate and format its output.

{% hint style="info" %}
**Tips for creating skills**

* **Start from a Sola skill** as a reference. Open it to see how its instructions are structured and use that as a starting point.
* **Test your skill in chat** before assigning it to agents to make sure it behaves as expected.
* **Keep it focused**. A skill works best when it targets one domain or task. The narrower the scope, the more consistent the results.
* **Write instructions, not descriptions**. The Instructions field is a system prompt, not a summary. Tell the skill how to think and respond, not just what it covers.
  {% endhint %}

## Invoking a skill

Skills activate in chat when you invoke them explicitly or when your message matches a skill's domain.

**To invoke a skill**, type / in the chat input and select the skill you want.

Once active, a skill applies its instructions to your conversation and stays active across follow-up messages as long as the conversation stays in its domain. To stop a skill, ask it to stop or switch to a different one.

<figure><img src="/files/0puX1Z7nXcmYoKcp1lXV" alt="Invoke a skill with /"><figcaption><p>Invoke a skill with /</p></figcaption></figure>

## Managing skills

The Skills page gives you a workspace-wide view of all your skills. From here you can see what's active, control which skills are enabled, and manage your custom skills.

**To manage your skills**, go to ***Skills***.

From the Skills page you can:

* See all your skills at a glance.
* Enable or disable any skill.
* Edit, Duplicate, or Delete custom skills.
* Add new skills.

## Skills and agents

Skills and agents work together. A skill is a specialization; an agent is the actor that applies it. Assigning one or more skills to an agent extends what the agent knows beyond its core instructions, without you having to rewrite its instructions.

See [Agents](/workspace/agents) for how to assign skills when creating or editing an agent.

{% hint style="info" %}
**Disabling skills**\
To disable a skill, remove it from any active agents first.
{% endhint %}

## Agents, workflows, skills, and routines

**Agents think. Workflows orchestrate. Skills guide. Routines automate.**

[**Agents**](/workspace/agents) reason dynamically and act on your behalf across connected tools and data. @mention them in chat to investigate, triage, and take action. They are best for open-ended investigations and flexible tasks.

[**Workflows**](/workspace/projects/workflows) execute a predefined sequence of steps in a specific order. Trigger them manually or on a schedule to automate repeatable tasks. They are best for repeatable, structured automations.

**Skills** shape how an agent or Sola AI behaves in a specific domain. Assign them to an agent or apply them in chat to extend its knowledge. They are best for specializing an agent's focus or expertise.

[**Routines**](/workspace/routines) run an agent automatically on a schedule or trigger. Configure one with a task, an agent, and a project scope, and Sola runs it for you. They are best for recurring investigations where the path to the answer may vary.

***

## FAQs

### How are skills different from agents?

A skill is a set of instructions for performing a specific task. An [agent](/workspace/agents) is the actor that carries out work, with its own role, memory, and approved tools. You apply a skill in chat or assign it to an agent to specialize how it behaves. One agent can use multiple skills.

### How are skills different from workflows?

Skills guide how Sola AI reasons through a task. [Workflows](/workspace/projects/workflows) execute a fixed sequence of steps in a set order. Use a skill to shape the quality and focus of a response; use a workflow to automate a repeatable, structured process.

### Who can create and manage skills?

Admins can install, enable, create, edit, and delete skills. Any workspace member can use installed skills in chat.

### Do I need to invoke a skill with / every time?

No. Installed and enabled skills can activate automatically when your message matches their domain. Use / when you want to invoke a specific skill explicitly. Otherwise, Sola evaluates your message against active skills and applies the right one on its own.

### Do skills apply when an agent runs on a schedule?

Yes. Any skills assigned to an agent apply every time that agent runs, whether invoked directly with @mention or run automatically through a [Routine](/workspace/routines).


# Routines

AI routines that automate your agents, on a schedule

Routines are scheduled [agent](/workspace/agents) runs that execute automatically.

Configure one with a set of instructions, an agent, a schedule, and a project scope, and Sola handles the rest. Every run is logged and auditable, and you can continue investigating in chat.

<figure><img src="/files/1k0XuhbUmGM2acnxwCk7" alt="Sola Agent Routines"><figcaption><p>Sola Agent Routines</p></figcaption></figure>

{% hint style="info" %}
Routines are [available on paid plans](https://sola.security/pricing/).
{% endhint %}

{% embed url="<https://sola.security/pricing/>" %}

## Creating routines

A routine ties together an [**agent**](/workspace/agents), a **task**, a **schedule**, and a **project scope**. Once created, it runs on its own at the configured frequency.

Creating and managing routines requires Owner or Admin access. Contributors can view run history for projects they have access to.

**To set up a routine, complete the following:**

* **Name** - Enter a short, descriptive name for the routine.
* **Task** - Write a clear, self-contained prompt describing what the agent should do on each run, up to 1000 characters.
* **Agent** - Select the agent to run the routine. If your workspace has no custom agents, the Sola default agent is selected automatically; if it does, the default agent still appears as an option alongside them. The agent's instructions, tools, and skills apply to every run.
* **Project** - Assign the routine to an existing project, start a new one, or create one from a template.
* **Schedule** - Set how often the routine runs: every hour, day, week, or month, with a specific day, date, or time where relevant.

## Reviewing run history

Every run is logged, showing exactly what the agent did, what it found, and what it produced.

**To review a routine's run history**, go to ***Routines*** and open the routine.

The routine's overview shows its schedule, assigned agent, project, and current status: **Active**, **Paused**, or **In progress**. Below that, run history lists every past run, each with its own status: **completed**, **In progress**, or **Failed**.

Open any run to see the run details and output.

To continue investigating a run, click **Continue in chat** to open it in a new chat session grounded in that run's context.

## Managing routines

The Routines page gives you a workspace-wide view of all your routines.

From this page you can:

* See all routines at a glance, with last run time and status.
* Enable or disable any routine.
* Filter by status, agent, or project.
* Add new routines.

## Routines and workflows

**Automate work with routines**. Routines and workflows are both ways to automate work, but they work differently.

**Routines** run an agent on a schedule. The agent reasons over the task, uses its tools, and decides how to proceed. Use routines for recurring investigations or monitoring tasks where the path to the answer may vary.

**Workflows** execute a fixed sequence of predefined steps in order. Use workflows for repeatable, structured processes where each step is known in advance.

***

## FAQs

### How are routines different from agents?

A routine is a saved configuration that runs an agent automatically, on a schedule. An agent is the actor: it has its own instructions, tools, and memory, and reasons over the task it's given. You can invoke an agent directly in chat with @mention, or let a routine invoke it for you on a recurring basis.

### How are routines different from workflows?

Routines run an agent on a schedule. The agent reasons over the task, uses its tools, and decides how to proceed. Workflows execute a fixed sequence of predefined steps in order. Use routines for recurring investigations where the path to the answer may vary; use workflows for repeatable, structured processes where each step is known in advance.

### Who can create and manage routines?

Owners and Admins can create, edit, enable, disable, and delete routines. Contributors can view run history for routines in projects they're a member of.


# Data Sources

Connect Sola to your data sources and create your solutions

A data source is a secure connection from your [Sola workspace](/workspace/workspace-home) to your organizational data.

Data can be imported from various sources, including cloud providers, cloud services, operational applications, security tools, and any other source desired.

{% hint style="info" %}
Learn more about [data privacy](https://trust.sola.security/).

Data sources and records quota are subject to [pricing and packages](https://sola.security/pricing/).
{% endhint %}

## Available data source integrations

<table data-view="cards"><thead><tr><th align="center"></th><th data-hidden></th><th data-hidden></th><th data-hidden data-card-target data-type="content-ref"></th><th data-hidden data-card-cover data-type="image">Cover image</th></tr></thead><tbody><tr><td align="center">Amazon Web Services (AWS)</td><td>Microsoft Azure</td><td>Google Cloud Platform(GCP)</td><td><a href="/pages/dTeg8rm9ZrHE2ZOqoJF8">/pages/dTeg8rm9ZrHE2ZOqoJF8</a></td><td data-object-fit="cover" data-alt="Amazon Web Services (AWS)"><a href="/files/XbvHTR1eZP2voGGslPq3">/files/XbvHTR1eZP2voGGslPq3</a></td></tr><tr><td align="center">Google Cloud Platform (GCP)</td><td>Google Directory</td><td>Cloudflare</td><td><a href="/pages/cniC9rCUmBxof0YbUjRo">/pages/cniC9rCUmBxof0YbUjRo</a></td><td data-object-fit="cover" data-alt="Google Cloud Platform (GCP)"><a href="/files/SxKhGXL3KOmmYiN3Uxg5">/files/SxKhGXL3KOmmYiN3Uxg5</a></td></tr><tr><td align="center">Microsoft Azure</td><td>Datadog</td><td>MongoDB Atlas</td><td><a href="/pages/cDh1ety5oMBT4cYOUf9z">/pages/cDh1ety5oMBT4cYOUf9z</a></td><td data-object-fit="cover" data-alt="Microsoft Azure"><a href="/files/Ulaa2Q4aRTyppuT50jaM">/files/Ulaa2Q4aRTyppuT50jaM</a></td></tr><tr><td align="center">Google Workspace</td><td></td><td></td><td><a href="/pages/GqpaolDH8ngPhm9VFFl9">/pages/GqpaolDH8ngPhm9VFFl9</a></td><td data-object-fit="cover" data-alt="Google Workspace"><a href="/files/yYigK45Y4sbvR5VG70Xj">/files/yYigK45Y4sbvR5VG70Xj</a></td></tr><tr><td align="center">GitHub Cloud</td><td>1Password</td><td>Wiz</td><td><a href="/pages/ngusUTzcPccv3taD1T2D">/pages/ngusUTzcPccv3taD1T2D</a></td><td data-object-fit="cover" data-alt="GitHub Cloud"><a href="/files/ylW3TJHHgqPkATKxSVJ3">/files/ylW3TJHHgqPkATKxSVJ3</a></td></tr><tr><td align="center">Microsoft Entra ID</td><td></td><td></td><td><a href="/pages/am0RidgfPNbmYVnV1l3B">/pages/am0RidgfPNbmYVnV1l3B</a></td><td data-object-fit="cover" data-alt="Microsoft Entra ID"><a href="/files/T78Gar4isXQ7PNh16uCP">/files/T78Gar4isXQ7PNh16uCP</a></td></tr><tr><td align="center">Okta</td><td></td><td></td><td><a href="/pages/MDUj4HuDu6ONUzCnQuC6">/pages/MDUj4HuDu6ONUzCnQuC6</a></td><td data-object-fit="cover" data-alt="Okta"><a href="/files/PeEmTOhdNSTJ33pd7Pyg">/files/PeEmTOhdNSTJ33pd7Pyg</a></td></tr><tr><td align="center">MongoDB Atlas</td><td></td><td></td><td><a href="/pages/c3qttjsYfP9xXIqW4UyC">/pages/c3qttjsYfP9xXIqW4UyC</a></td><td data-object-fit="cover" data-alt="MongoDB Atlas"><a href="/files/Lye4TWbVicllwHZfhvzB">/files/Lye4TWbVicllwHZfhvzB</a></td></tr><tr><td align="center">Wiz</td><td></td><td></td><td><a href="/pages/Gkkl9bhJQM6dTMSj4taf">/pages/Gkkl9bhJQM6dTMSj4taf</a></td><td data-object-fit="cover" data-alt="Wiz"><a href="/files/Rm9K9RwKAokWNXaY6IZb">/files/Rm9K9RwKAokWNXaY6IZb</a></td></tr><tr><td align="center">Upwind</td><td></td><td></td><td><a href="/pages/DwhMl653jjgb1MW0fUGx">/pages/DwhMl653jjgb1MW0fUGx</a></td><td data-object-fit="cover" data-alt="Upwind"><a href="/files/DBt4sx1voML0d9WefNwE">/files/DBt4sx1voML0d9WefNwE</a></td></tr><tr><td align="center">WordPress</td><td></td><td></td><td><a href="/pages/o9P8WoZVElnTW0OHtWaa">/pages/o9P8WoZVElnTW0OHtWaa</a></td><td data-object-fit="cover" data-alt="WordPress"><a href="/files/VwRPV8ukwkUnulBfLot8">/files/VwRPV8ukwkUnulBfLot8</a></td></tr><tr><td align="center">Sola Web Checker</td><td></td><td></td><td><a href="/pages/LDAE231AqRCX1f6C7DlB">/pages/LDAE231AqRCX1f6C7DlB</a></td><td data-object-fit="cover" data-alt="Sola Web Checker"><a href="/files/s2zSMCCscFPpUoa0k8eF">/files/s2zSMCCscFPpUoa0k8eF</a></td></tr><tr><td align="center">Lovable App Scanner</td><td></td><td></td><td><a href="/pages/imhSHAqFq9BwDgV0FikP">/pages/imhSHAqFq9BwDgV0FikP</a></td><td data-object-fit="cover" data-alt="Lovable App Scanner"><a href="/files/6ih4Oer83Gz4P2mnonKS">/files/6ih4Oer83Gz4P2mnonKS</a></td></tr><tr><td align="center">CSV File</td><td></td><td></td><td><a href="/pages/n7xXqeXUSfuPplBAF3dh">/pages/n7xXqeXUSfuPplBAF3dh</a></td><td data-object-fit="cover" data-alt="CSV File"><a href="/files/BcLkInfkrEhDj6O5UQuF">/files/BcLkInfkrEhDj6O5UQuF</a></td></tr><tr><td align="center">Zoom</td><td></td><td></td><td><a href="/pages/K5TytZBSd4tkTTDVg3TG">/pages/K5TytZBSd4tkTTDVg3TG</a></td><td data-object-fit="cover" data-alt="Zoom"><a href="/files/aWtX6H4RSawxkyr2ZEZE">/files/aWtX6H4RSawxkyr2ZEZE</a></td></tr><tr><td align="center">Jira Cloud</td><td></td><td></td><td><a href="/pages/7AODKITipXp7A2zJcPf4">/pages/7AODKITipXp7A2zJcPf4</a></td><td data-object-fit="cover" data-alt="Jira Cloud"><a href="/files/8rysYG2OWe7yHs1q07mI">/files/8rysYG2OWe7yHs1q07mI</a></td></tr><tr><td align="center">Cloudflare</td><td></td><td></td><td><a href="/pages/rc9eTKo2Gc6NLTBzl1Gw">/pages/rc9eTKo2Gc6NLTBzl1Gw</a></td><td data-object-fit="cover" data-alt="Cloudflare"><a href="/files/PUIIHjZttsHDNSerrG4a">/files/PUIIHjZttsHDNSerrG4a</a></td></tr><tr><td align="center">SentinelOne</td><td></td><td></td><td><a href="/pages/wWRQ8SK8uhIxb9jtO6yW">/pages/wWRQ8SK8uhIxb9jtO6yW</a></td><td data-object-fit="cover" data-alt="SentinelOne"><a href="/files/b3lrtmkwIz5llZe0yDEV">/files/b3lrtmkwIz5llZe0yDEV</a></td></tr><tr><td align="center">Claude Console</td><td></td><td></td><td><a href="/pages/08Upvgf5ojdl2NRKWbd3">/pages/08Upvgf5ojdl2NRKWbd3</a></td><td data-object-fit="cover" data-alt="Claude Console"><a href="/files/MJQM6D07VOtJgJKRQ2Jj">/files/MJQM6D07VOtJgJKRQ2Jj</a></td></tr><tr><td align="center">Claude Enterprise</td><td></td><td></td><td><a href="/pages/bIfESan1qX0wxOWPsNNk">/pages/bIfESan1qX0wxOWPsNNk</a></td><td data-object-fit="cover" data-alt="Claude Enterprise"><a href="/files/MJQM6D07VOtJgJKRQ2Jj">/files/MJQM6D07VOtJgJKRQ2Jj</a></td></tr><tr><td align="center">Claude Enterprise Analytics</td><td></td><td></td><td><a href="/pages/8JeOsgPzCFFFaoVayCXT">/pages/8JeOsgPzCFFFaoVayCXT</a></td><td><a href="/files/MJQM6D07VOtJgJKRQ2Jj">/files/MJQM6D07VOtJgJKRQ2Jj</a></td></tr><tr><td align="center">Claude Code (Coding agent)</td><td></td><td></td><td><a href="/pages/EjWEEH9K3nh7Hz6foKYj">/pages/EjWEEH9K3nh7Hz6foKYj</a></td><td><a href="/files/6V58vJMJ0MNUrcwB6FlI">/files/6V58vJMJ0MNUrcwB6FlI</a></td></tr><tr><td align="center">NetSuite</td><td></td><td></td><td><a href="/pages/fPVAWZ7ZzW31zaZZGxfg">/pages/fPVAWZ7ZzW31zaZZGxfg</a></td><td data-object-fit="cover" data-alt="NetSuite"><a href="/files/FEcedv5fv3hs8RovLzND">/files/FEcedv5fv3hs8RovLzND</a></td></tr><tr><td align="center">Semgrep</td><td></td><td></td><td><a href="/pages/D4GdWCYlyZssLZZGoaci">/pages/D4GdWCYlyZssLZZGoaci</a></td><td data-object-fit="cover" data-alt="Semgrep"><a href="/files/imUrIgVFlBklKmvZAeHG">/files/imUrIgVFlBklKmvZAeHG</a></td></tr><tr><td align="center">Google Sheets<br>(<em>Real time</em>)</td><td></td><td></td><td><a href="/pages/0Y6wxtTpG7smmKHTQRrT">/pages/0Y6wxtTpG7smmKHTQRrT</a></td><td data-object-fit="cover" data-alt="Google Sheets"><a href="/files/TZfvVv95gWK05vKZPYG5">/files/TZfvVv95gWK05vKZPYG5</a></td></tr><tr><td align="center">Sentinel Data Lake<br>(<em>Real time</em>)</td><td></td><td></td><td><a href="/pages/3JSnDBAGdwPUa2Bp7Jsx">/pages/3JSnDBAGdwPUa2Bp7Jsx</a></td><td><a href="/files/iTEdjfMDN8hYY9BX9rlY">/files/iTEdjfMDN8hYY9BX9rlY</a></td></tr><tr><td align="center">Snowflake<br>(<em>Real time</em>)</td><td></td><td></td><td><a href="/pages/668L3n4Gyq5myXeroogr">/pages/668L3n4Gyq5myXeroogr</a></td><td><a href="/files/UF2GUVD11FStQnwtEf1G">/files/UF2GUVD11FStQnwtEf1G</a></td></tr><tr><td align="center">CircleCI</td><td></td><td></td><td></td><td data-object-fit="cover" data-alt="CircleCI"><a href="/files/hj621P602hr8ZUJenuA8">/files/hj621P602hr8ZUJenuA8</a></td></tr><tr><td align="center">Datadog</td><td>CSV</td><td><br></td><td></td><td data-object-fit="cover" data-alt="Datadog"><a href="/files/8ye35Gb9jF4QzrRK8eNI">/files/8ye35Gb9jF4QzrRK8eNI</a></td></tr><tr><td align="center">Crowdstrike</td><td></td><td></td><td></td><td data-object-fit="cover" data-alt="Crowdstrike"><a href="/files/bOwoGDusmZFZGdUEL0X8">/files/bOwoGDusmZFZGdUEL0X8</a></td></tr><tr><td align="center">Salesforce</td><td></td><td></td><td></td><td data-object-fit="cover" data-alt="Salesforce"><a href="/files/XVffDOcX9f47B7L0OYL6">/files/XVffDOcX9f47B7L0OYL6</a></td></tr><tr><td align="center">OpenAI Platform</td><td></td><td></td><td></td><td data-object-fit="cover" data-alt="OpenAI Platform"><a href="/files/SWFoUmTKrUya1Nov6bqR">/files/SWFoUmTKrUya1Nov6bqR</a></td></tr><tr><td align="center">OX Security</td><td></td><td></td><td></td><td data-object-fit="cover" data-alt="OX Security"><a href="/files/gfpGCDEgvY2C3dRgV3kX">/files/gfpGCDEgvY2C3dRgV3kX</a></td></tr><tr><td align="center">Jamf Pro</td><td></td><td></td><td></td><td data-object-fit="cover" data-alt="Jamf Pro"><a href="/files/KrEqhQcWW469awijhsgZ">/files/KrEqhQcWW469awijhsgZ</a></td></tr><tr><td align="center">Jamf Security Cloud (formerly RADAR)</td><td></td><td></td><td></td><td data-object-fit="cover" data-alt="Jamf Security Cloud (formerly RADAR)"><a href="/files/KrEqhQcWW469awijhsgZ">/files/KrEqhQcWW469awijhsgZ</a></td></tr><tr><td align="center">HiBob</td><td></td><td></td><td></td><td data-object-fit="cover" data-alt="HiBob"><a href="/files/ngUNpxDMoiH7vyQiev6u">/files/ngUNpxDMoiH7vyQiev6u</a></td></tr><tr><td align="center">JumpCloud</td><td></td><td></td><td></td><td data-object-fit="cover" data-alt="JumpCloud"><a href="/files/4pKkSOiwqxxNhJyJwk2Q">/files/4pKkSOiwqxxNhJyJwk2Q</a></td></tr><tr><td align="center">Mosyle</td><td></td><td></td><td></td><td data-object-fit="cover" data-alt="Mosyle"><a href="/files/6JkGH4vbrHoXzXduf8UC">/files/6JkGH4vbrHoXzXduf8UC</a></td></tr></tbody></table>

## Data source tables

Each **data source** contains multiple **tables** that store structured data retrieved from your connected source. This data is organized for easy analysis and is available for [queries](/workspace/projects/queries), [visualizations](/workspace/projects/canvases), and [alerts](/workspace/projects/alerts).

### Sync status

Sola syncs **your data daily** to ensure your insights stay up to date, and you can trigger a [manual sync](#triggering-a-manual-sync) at any time to refresh on demand. Sync cycle times vary based on the data size.

Real-time integrations, such as [Google Sheets](/integrations/data-sources/google-sheets) (Snowflake and Sentinel Data Lake coming soon) are always up to date and do not follow a scheduled sync cycle.

{% hint style="info" %}
**Data availability during a sync**

During a sync, your most recent data stays available to query. Sola updates it once the sync completes.
{% endhint %}

#### Checking sync status

To check the status of your data:

* **Data Sources page** - Click on a [data source](/integrations/data-sources) to see the sync status of its tables.
* **Query Library** - Click on a specific [query](/workspace/projects/queries) to check which data tables are being used and their sync status.

#### Last sync information

Sync details are available at two levels:

* **Data source level** - Displays the overall sync status and total number of records synced during the last update.
* **Table level** - Shows individual table sync status and the number of records synced per table.

{% hint style="info" %}
**Table sync dependencies**

Some table data depends on other tables to sync successfully. If a parent table fails to sync, its dependent (child) tables will also fail.

For example, an AWS user roles table depends on successfully retrieving AWS users. If the AWS users table fails to sync, the AWS user roles table will also fail.
{% endhint %}

#### Triggering a manual sync

Sola syncs your data automatically on a daily cycle. You can also trigger a sync on demand instead of waiting for the next scheduled cycle, for the entire data source or a single table.

To trigger a manual sync, go to ***Integrations*** > ***Data Sources***. To sync the entire data source, select **Manual run** from the main list. To sync a single table, open the data source and table you want to refresh, and select **Manual run**. Sola refreshes the data and shows its sync status and progress while the sync runs.

{% hint style="info" %}
**How manual runs work**

There is no limit on how often you can trigger a manual sync. Like scheduled syncs, the records a manual run pulls count toward your daily records limit. Your existing data stays available to query while the sync is in progress, and updates once the run completes.
{% endhint %}

{% hint style="info" %}
**Manual run and real-time data sources**

Manual runs apply to data sources that sync on a schedule. Real-time data sources, such as Google Sheets and Snowflake, are queried live at runtime and their data is always up to date.
{% endhint %}

### Sync status types

| Data source sync status                                                 | Table sync status                                                                                   |
| ----------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------- |
| **Synced** - All tables successfully synced in the last sync cycle.     | **Synced** - The table or tables under the same group successfully synced in the last sync cycle.   |
| **Partially Synced** - Some tables did not sync in the last sync cycle. | **Syncing** - The table or tables under the same group are currently syncing.                       |
| **Out of Sync** - The last sync failed.                                 | **Tables failed** - The table or tables under the same group failed to sync in the last sync cycle. |
| **Real-time** - Data is queried in real time.                           | **Disabled** - This table has been disabled and is not synced.                                      |
|                                                                         | **Enabled** - This table has been enabled and will sync in the next scheduled sync.                 |
|                                                                         | **Real-time** - Data is queried in real time.                                                       |

{% hint style="success" %}
**Disabling and Enabling Tables**

Disable a table if you no longer need its data to be included in sync cycles, reducing unnecessary data updates, and records quota.

* Disabled tables will no longer sync or be available for queries, canvases, or alerts.
* Disabling a parent table will also disable any child tables that depend on it.
* Re-enable a table at any time to resume syncing and restore access to its data.
  {% endhint %}

### Snapshots and incremental data updates

Data source tables support historical data collection, allowing you to explore changes over time.

Table’s data is updated in one of two methods:

* **Snapshots** - capture a single point-in-time state of the data.
* **Incremental** - continuously collect changes, building a stream of historical records over time.

To view and use historical snapshots saved by Sola and not only the latest snapshot, include the word “snapshots” in your query or Sola AI prompt.

By querying snapshots or incremental tables, you can explore the history of your data,&#x20;

investigate posture changes in posture, track configuration drift, and review past states.

For example, ask Sola AI to:

* Show AWS EC2 inventory across multiple data snapshots.
* Investigate snapshots of Github users granted admin access in the last few days.
* Find Okta role or policy that has changed in the last 3 days across snapshots and how.

{% hint style="info" %}
Historical snapshots are available up to 90 days back, limited by when your data source was connected.
{% endhint %}

## Data records and usage

Data records represent the data entries Sola processes from connected data tables. Each row from a connected data source counts as one data record.

Data record limits reset daily. If you reach your daily data record limit, data processing pauses until your next daily limit resets.

**Upgrade your plan for higher limits.**

{% embed url="<https://sola.security/pricing/>" %}

{% hint style="info" %}
**Downgrading and data sync limits**

If you downgrade your plan, existing connected data sources stay connected.&#x20;

After the downgrade takes effect, Sola applies the new plan limits going forward, which means data syncs fetch only the number of records included in the new plan.
{% endhint %}

{% hint style="info" %}
**Daily data record limits and your data source sync**

If a data source's initial sync doesn't complete before your daily limit resets, Sola continues it the next day, and keeps going day by day until it's complete. Once fully synced, later syncs only pull new and changed records, using far fewer records than the initial sync.
{% endhint %}

### Real time data sources usage

Real time data sources such as [Google Sheets](/integrations/data-sources/google-sheets), [Snowflake](/integrations/data-sources/snowflake), and [Sentinel Data Lake](/integrations/data-sources/sentinel-data-lake), do not count toward your data record usage.

These integrations operate as live connections rather than imported datasets. No copy of your data is stored in Sola. Queries run directly against the source system at runtime. When a row is added to a Google Sheet, a table is updated, or new records added, your data in Sola reflects those changes immediately.

Usage is governed by the license for each integration and the source system's own limits, not by Sola's data record quota.

{% hint style="info" %}
**How real-time sync works**\
When you connect a real-time data source, Sola inspects it to learn its structure and checks periodically for any changes.
{% endhint %}

## Coding agents data sources

Coding agent data sources connect the AI coding tools your developers use, such as [Claude Code](/integrations/data-sources/claude-code), to your Sola workspace.

They give your security team visibility into AI-assisted development activity across your organization, including developer sessions, tool calls, and prompts. With this visibility, you can detect data leakage risks, audit how AI coding tools are used, and correlate coding agent activity with the rest of your security environment.

***

## FAQs

### Why should I connect my data sources?

Connecting your data sources allows you to find answers to your security questions using your own organizational data.

The collected data is used to [create projects](/workspace/projects#creating-projects).

### Why should I trust Sola with my data?

At Sola, we prioritize the [security and privacy](https://trust.sola.security/) of your data through strong encryption, strict access controls, and compliance with industry standards. Our systems are regularly audited, monitored for threats, and undergo continuous security improvements to ensure your sensitive data remains protected.

### What happens with my data?

Sola has **read-only** access to your data. Once connected, your data is securely stored in **structured tables** that uniquely map the data content and its sources. This is what makes it easy to query and find answers to your specific use cases. **Sola AI** brings an additional layer of security knowledge available for you to use.

### What happens if I don’t connect my data?

If you don’t connect a data source, you’ll only be able to explore **sample data** within Sola. While this allows you to see how things work, you won’t get **real insights** based on your organization’s security data.

### Why does Sola need wide permission-level read access to my data?

The answers to your questions could be hidden anywhere in your data. Limiting access to your data will limit the insights and answers you can gather.

[Learn more about data privacy](https://trust.sola.security/)<br>

### What happens if my data source sync hits the daily data record limit partway through?

Sola picks up the sync where it left off. If a data source's initial sync doesn't finish before your daily data record limit resets, it continues the next day, and keeps continuing day by day until the data source is fully synced, you may see this reflected as a [**Partially Synced**](#sync-status-types) status in the meantime. Once the initial sync completes, later syncs only pull new and changed records instead of the full dataset, which uses far fewer records and is unlikely to hit the limit again.


# Amazon Web Services (AWS)

Connect Sola and AWS to get security insights

The [Amazon Web Services (AWS)](https://aws.amazon.com/) integration connects data from your AWS account to your Sola workspace, making it easy to search and find answers to your specific use cases.

{% embed url="<https://youtu.be/8_Cpzudh5MY>" %}

## Overview

The AWS integration gives you a complete view of your AWS environment, allowing you to monitor and analyze AWS security posture and potential threats.

With the AWS integration, you can:

* Ensure cloud security best practices
* Gain full visibility into your cloud resources
* Identify security risks across your cloud environment

{% hint style="warning" %}
**Your data can only be retrieved, never modified.**

Once connected, your data is securely stored, and access is restricted to retrieving configurations and metadata only. Authentication methods ensure secure delegation of permissions while maintaining data integrity.
{% endhint %}

{% hint style="info" %}
**No hidden indirect cloud provider charges**\
The Sola integration won’t use resources that increase your cloud costs.
{% endhint %}

## Set up AWS data source integration with Sola

{% columns %}
{% column width="75%" %}
Go to ***Integrations*** > [***Data Sources***](https://app.sola.security/integrations/data-sources) > click ***New data source*** > select ***AWS***.

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="25%" %} <a href="https://app.sola.security/integrations/data-sources?integration=aws" class="button primary">Set up AWS -></a>

{% endcolumn %}
{% endcolumns %}

### Connect AWS Organization to Sola

To connect AWS, you'll need an AWS Organization with permissions to create IAM roles via CloudFormation StackSets.

{% hint style="success" %}
**Recommended:** connect at the organization level to manage multiple AWS accounts through a single integration.
{% endhint %}

{% hint style="info" %}
AWS organization connection method is available on [paid plans](https://sola.security/pricing/).
{% endhint %}

{% tabs %}
{% tab title="IAM Role (Recommended)" %}
**Connect at the organization level** to manage multiple AWS accounts through a single integration.

This method utilizes an IAM role, deployed at the organization root via AWS CloudFormation StackSets, to securely grant Sola read-only access to your AWS services and resources across all accounts.

* CloudFormation
  {% endtab %}
  {% endtabs %}

Follow the step-by-step guide below to complete the setup.

<details>

<summary><strong>How do I set up an AWS Organization data source using CloudFormation?</strong></summary>

**Prerequisites**

* Log into your management account with a user that has the IAMFullAccess managed policy, or any other policy that grants permissions to create CloudFormation stacks, manage IAM roles and policies, and view identity details.
* Ensure that trusted access between AWS CloudFormation StackSets and AWS Organizations is enabled. [Learn more](https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/stacksets-orgs-activate-trusted-access.html).
* Get your AWS Organization Root ID (e.g. r-XXXX). [Learn more](https://docs.aws.amazon.com/organizations/latest/userguide/orgs_view_ou.html).

**Integration setup**

1. Launch CloudFormation from the Sola wizard. Add your AWS **Organization Root ID**, and optionally any Excluded Member Account IDs.\
   Review, acknowledge, and create the stack. This may take a few minutes.
2. Once the stack is created, copy the **IAM Role ARN** and **Stack Region** from the Outputs tab in the CloudFormation stack. The output parameter names are **SolaOrgAccess** and **StackRegion**. Paste them below.
3. Click **Test Connection** to validate the details and continue.

</details>

### Connect AWS to Sola

To connect AWS, you’ll need an AWS account, with the necessary permissions to create an IAM role.

{% tabs %}
{% tab title="Cross-Account Role" %}
Recommended for secure, production environments. These methods use an IAM role delegation within your account to securely grant Sola read-only access to your AWS services and resources.

* CloudFormation (Recommended)
* Terraform
  {% endtab %}

{% tab title="Access Token" %}
AWS IAM access and secret keys.

Create an access key pair from within your AWS Management Console. Your IAM user must have at least SecurityAudit permissions on all AWS services.

* IAM Credentials
  {% endtab %}
  {% endtabs %}

## Sync behavior and limitations

Some tables have specific sync constraints due to data size, retention policies, or performance considerations. Below are special cases to be aware of:

<table><thead><tr><th width="233.73828125">Table</th><th>Sync details</th></tr></thead><tbody><tr><td>aws_securityhub_finding</td><td>Includes only findings with an Active status.</td></tr></tbody></table>

## Explore AWS templates

![](/files/bKdo3yzED39AfQ5Oyclq) Get started with [AWS-focused security templates](https://sola.security/templates/?search=aws), built by our expert security team.

<figure><img src="/files/EYSxWBsjJObxu0ax5UoK" alt="AWS"><figcaption></figcaption></figure>


# Google Cloud Platform (GCP)

Connect Sola and GCP to get security insights

## Overview

The [Google Cloud Platform (GCP)](https://cloud.google.com/) integration connects data from your GCP account to your Sola workspace, making it easy to search and find answers to your specific use cases.

The GCP integration gives you a complete view of your GCP environment, allowing you to monitor and analyze GCP security posture and potential threats.

With the GCP integration, you can:

* Ensure cloud security best practices
* Gain full visibility into your cloud resources
* Identify security risks across your cloud environment

{% hint style="warning" %}
**Your data can only be retrieved, never modified.**

Once connected, your data is securely stored, and access is restricted to retrieving configurations and metadata only. Authentication methods ensure secure delegation of permissions while maintaining data integrity.
{% endhint %}

{% hint style="info" %}
**No hidden indirect cloud provider charges**\
The Sola integration won’t use resources that increase your cloud costs.
{% endhint %}

## Set up GCP data source integration with Sola

{% columns %}
{% column width="75%" %}
Go to ***Integrations*** > [***Data Sources***](https://app.sola.security/integrations/data-sources) > click ***New data source*** > select ***GCP***.

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="25%" %} <a href="https://app.sola.security/integrations/data-sources?integration=gcp" class="button primary">Set up GCP -></a>

{% endcolumn %}
{% endcolumns %}

### Connect GCP Organization to Sola <a href="#gcp-organization" id="gcp-organization"></a>

To connect GCP, you'll need a GCP account with the necessary permissions to create a service account.

{% hint style="success" %}
**Recommended:** connect at the organization level to manage multiple GCP projects through a single integration.
{% endhint %}

{% hint style="info" %}
GCP organization connection method is available on [paid plans](https://sola.security/pricing/).
{% endhint %}

{% tabs %}
{% tab title="Service Account" %}
**Connect at the organization level** to manage multiple GCP projects through a single integration.

This method utilizes a GCP Service Account at the organization root to securely grant Sola read-only access to your GCP services and resources across all projects.

* Service Account Key

{% hint style="info" %}
The **setup script**, provided in the Sola wizard, creates the relevant resources needed for accessing GCP data and extracting it to Sola:

1. **Enabling services**: `admin`, `alloydb`, `apikeys`, `appengine`, `bigquery`, `bigtableadmin`, `cloudasset`, `cloudbilling`, `cloudfunctions`, `cloudkms`, `cloudresourcemanager`, `cloudscheduler`, `composer`, `compute`, `container`, `dataplex`, `dataproc`, `dns`, `file`, `groupssettings`, `iam`, `logging`, `metastore`, `recommender`, `redis`, `run`, `secretmanager`, `servicemanagement`, `serviceusage`, `spanner`, `storage`, `vpcaccess`
2. **Creating a service account** in the provided Sola project
3. **Binding the service account roles** at organization root
4. **Creating a deny policy** for each excluded project or folder, if applicable
5. **Creating a service account key**

**For troubleshooting**, see [setup script common errors](#troubleshooting-gcp-organization-setup-script-common-errors) below.
{% endhint %}
{% endtab %}
{% endtabs %}

#### Troubleshooting GCP Organization setup script common errors

Use the table below to troubleshoot errors returned in your GCP console by the setup script.

| Error code           | Description                                                                                                 | Resolution                                                                                                                                                                                                                           |
| -------------------- | ----------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| MISSING\_PERMISSIONS | Your GCP account lacks a required IAM permission.                                                           | Ensure all required roles are assigned to your account and re-run the script: Organization Administrator, Organization Policy Administrator, Billing Account Administrator, Deny Admin (if excluded projects/folders are specified). |
| RESOURCE\_NOT\_FOUND | A required GCP resource does not exist or is not visible to you.                                            | Verify the ID in the GCP Console and re-run the script.                                                                                                                                                                              |
| RESOURCE\_EXISTS     | A resource with the requested name already exists.                                                          | Re-run the script.                                                                                                                                                                                                                   |
| QUOTA\_EXCEEDED      | A GCP quota limit has been reached.                                                                         | Delete unused resources or request a quota increase in the GCP Console.                                                                                                                                                              |
| BILLING\_DISABLED    | Billing is not enabled on the selected project                                                              | Enable billing at <https://console.cloud.google.com/billing> and re-run.                                                                                                                                                             |
| UNAUTHENTICATED      | The gcloud CLI is not authenticated.                                                                        | Run `gcloud auth login` and try again.                                                                                                                                                                                               |
| POLICY\_BLOCKED      | An organization policy is blocking the operation.                                                           | Check organization policies in the GCP Console or contact your org admin and try again.                                                                                                                                              |
| PROPAGATION\_TIMEOUT | A GCP change (service account creation or policy update) did not propagate within the expected time window. | Wait a few minutes and try again.                                                                                                                                                                                                    |
| UNEXPECTED\_ERROR    | An unexpected error occurred.                                                                               | Try again and [contact Sola Support](https://help.sola.security/support/tickets/new) if the issue persists.                                                                                                                          |

### Connect GCP Single Project to Sola <a href="#gcp-single-project" id="gcp-single-project"></a>

To connect GCP, you'll need a GCP account with the necessary permissions to create a service account.

{% tabs %}
{% tab title="Service Account" %}
**Connect a single GCP project.**

Recommended for secure, production environments. These methods utilize a GCP Service Account within your project to securely grant Sola read-only access to your GCP services and resources.

* Service Account Key (Recommended)
* Terraform

{% hint style="info" %}
The **setup script**, provided in the Sola wizard, creates the relevant resources needed for accessing GCP data and extracting it to Sola:

1. **Creating service account** - Creates a service account in the project and binds it the roles: `viewer`, `iam.securityReviewer`, `cloudasset.viewer`
2. **Enabling services** - Enables the following APIs: `admin`, `alloydb`, `apikeys`, `appengine`, `bigquery`, `bigtableadmin`, `cloudasset`, `cloudbilling`, `cloudfunctions`, `cloudkms`, `cloudresourcemanager`, `cloudscheduler`, `composer`, `compute`, `container`, `dataplex`, `dataproc`, `dns`, `file`, `groupssettings`, `iam`, `logging`, `metastore`, `recommender`, `redis`, `run`, `secretmanager`, `servicemanagement`, `serviceusage`, `spanner`, `storage`, `vpcaccess`
3. **Creating service account key** - Temporarily disables the `iam.disableServiceAccountKeyCreation` org policy, waits for propagation, creates the key, then re-enables the policy

**For troubleshooting**, see [setup script common errors](#troubleshooting-azure-setup-script-common-errors) below.
{% endhint %}
{% endtab %}
{% endtabs %}

#### Troubleshooting Single Project setup script common errors <a href="#troubleshooting-azure-setup-script-common-errors" id="troubleshooting-azure-setup-script-common-errors"></a>

| Error Code           | Description                                                                                             | Resolution                                                                                                                                        |
| -------------------- | ------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- |
| MISSING\_PERMISSIONS | Your GCP account lacks a required IAM permission.                                                       | Ensure all required roles are assigned to your account and re-run the script: **Project Owner or Editor**, **Organization Policy Administrator**. |
| RESOURCE\_NOT\_FOUND | A required GCP resource does not exist or is not visible to you.                                        | Verify the project ID in the GCP Console and re-run the script.                                                                                   |
| RESOURCE\_EXISTS     | A resource with the requested name already exists.                                                      | Re-run the script (a new random name will be generated).                                                                                          |
| QUOTA\_EXCEEDED      | A GCP quota limit has been reached (e.g. max service accounts per project).                             | Delete unused resources or request a quota increase in the GCP Console, then re-run.                                                              |
| BILLING\_DISABLED    | Billing is not enabled on the selected project.                                                         | Enable billing at <https://console.cloud.google.com/billing> and re-run.                                                                          |
| UNAUTHENTICATED      | The gcloud CLI is not authenticated.                                                                    | Run `gcloud auth login` and try again.                                                                                                            |
| POLICY\_BLOCKED      | An organization policy is blocking the operation (e.g. key creation policy enforced at a parent level). | Check organization policies in the GCP Console or contact your org admin and try again.                                                           |
| PROPAGATION\_TIMEOUT | A GCP change did not propagate within the expected time window.                                         | Wait a few minutes and try again.                                                                                                                 |
| UNEXPECTED\_ERROR    | An unexpected error occurred.                                                                           | Try again. Contact Sola support if the issue persists.                                                                                            |

## Explore GCP templates

![](/files/bKdo3yzED39AfQ5Oyclq) Get started with [GCP-focused security templates](https://sola.security/templates/?search=gcp), built by our expert team.

<figure><img src="/files/FU8ZgDl6zarBkOtxNXma" alt="GCP"><figcaption></figcaption></figure>


# Microsoft Azure

Connect Sola and Azure to get security insights

## Overview

The [Azure](https://azure.microsoft.com/) integration connects data from your Azure account to your Sola workspace, making it easy to search and find answers to your specific use cases.

The Azure integration gives you a complete view of your Azure environment, allowing you to monitor and analyze Azure security posture and potential threats.&#x20;

With the Azure integration, you can:

* Ensure cloud security best practices
* Gain full visibility into your cloud resources
* Identify security risks across your cloud environment

{% hint style="warning" %}
**Your data can only be retrieved, never modified.**

Once connected, your data is securely stored, and access is restricted to retrieving configurations and metadata only. Authentication methods ensure secure delegation of permissions while maintaining data integrity.
{% endhint %}

{% hint style="info" %}
**No hidden indirect cloud provider charges**\
The Sola integration won’t use resources that increase your cloud costs.
{% endhint %}

## Set up Azure data source integration with Sola

{% columns %}
{% column width="75%" %}
Go to ***Integrations*** > [***Data Sources***](https://app.sola.security/integrations/data-sources) > click ***New data source*** > select ***Microsoft Azure***.

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="25%" %} <a href="https://app.sola.security/integrations/data-sources?integration=azure" class="button primary">Set up Azure -></a>

{% endcolumn %}
{% endcolumns %}

### Connect Azure to Sola

To connect Azure, you'll need an Azure account with the necessary permissions to create and configure an App Registration:

* **Azure subscription:** Owner, or Contributor with User Access Administrator.
* **Azure AD (Microsoft Entra ID):** Application Administrator, Cloud Application Administrator, or Global Administrator, to grant admin consent.

{% tabs %}
{% tab title="App Registration" %}
These methods use an Azure App Registration within your subscription to securely grant Sola read-only access to your Azure services and resources.

* App Registration (Recommended)
* Terraform

{% hint style="info" %}
The **setup script**, provided in the Sola wizard, creates the relevant resources needed for accessing Azure data and extracting it to Sola:

1. **Verifying prerequisites** - Confirms your account has the required Azure AD and subscription roles, and stops early if any are missing
2. **Connecting to Azure** - Authenticates to Azure and Azure AD using the active Cloud Shell session
3. **Setting credentials** - Resolves tenant name and switches to the specified subscription
4. **Creating service principal** - Creates an Azure AD application and service principal for Sola
5. **Creating custom role** - Creates a custom read-only role scoped to the subscription with the minimal required permissions
6. **Adding Microsoft Graph API permissions** - Grants the service principal Microsoft Graph reading permissions: `User.Read.All`, `Application.Read.All`
7. **Granting admin consent** - Automatically grants admin consent for the Microsoft Graph permissions, so you no longer need to approve them manually in the Azure portal
8. **Assigning roles** - Assigns the custom role and the built-in Reader role to the service principal on the subscription
   {% endhint %}
   {% endtab %}
   {% endtabs %}

#### Troubleshooting Azure setup script common errors <a href="#troubleshooting-azure-setup-script-common-errors" id="troubleshooting-azure-setup-script-common-errors"></a>

| Error Code           | Description                                                                       | Resolution                                                                                                                                                                                                                                                            |
| -------------------- | --------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| MISSING\_PERMISSIONS | Your Azure account lacks a required permission on the subscription.               | Ensure your account has an Azure subscription role (**Owner**, or **Contributor** with **User Access Administrator**) and an Azure AD role (**Application Administrator**, **Cloud Application Administrator**, or **Global Administrator**), then re-run the script. |
| UNAUTHENTICATED      | The Azure CLI session is not authenticated or no valid account is detected.       | Re-open Cloud Shell, ensure you are logged in, and re-run the script.                                                                                                                                                                                                 |
| RESOURCE\_NOT\_FOUND | A required Azure resource (e.g. subscription) was not found or is not accessible. | Verify the subscription ID in the Azure Portal and re-run the script.                                                                                                                                                                                                 |
| NULL\_SECRET         | The service principal client secret was created but returned an empty value.      | Re-run the script. If the issue persists, contact Sola support.                                                                                                                                                                                                       |
| UNEXPECTED\_ERROR    | An unexpected error occurred during the setup.                                    | Try again. Contact Sola support if the issue persists.                                                                                                                                                                                                                |

## ExploreAzure templates

![](/files/bKdo3yzED39AfQ5Oyclq) Get started with [Azure-focused security templates](https://sola.security/templates/?search=azure), built by our expert team.

<figure><img src="/files/eIo7FKJx36SbMGsPMl8F" alt="Microsoft Azure"><figcaption></figcaption></figure>


# Microsoft Entra ID

Connect Sola and Entra ID to get security insights

## Overview

The Microsoft Entra ID integration connects data from your Entra ID tenant to your Sola workspace, making it easy to search and find answers to your specific use cases.

The integration gives you a complete view of your identity and access environment, allowing you to monitor and understand your Entra ID configurations and user activity across your organization.

With the Microsoft Entra ID integration, you can:

* Monitor user accounts, groups, and roles across your Entra ID tenant
* Review conditional access and authorization policies
* Track device registrations and sign-in activity
* See admin consent workflows and service principal role assignments
* Monitor directory settings, domains, and audit records
* Access identity providers and security defaults

{% hint style="warning" %}
**Your data can only be retrieved, never modified.**

Once connected, your data is securely stored, and access is restricted to retrieving configurations and metadata only. Authentication methods ensure secure delegation of permissions while maintaining data integrity.
{% endhint %}

## Set up Entra ID data source integration with Sola

{% columns %}
{% column width="66.66666666666666%" %}
Go to ***Integrations*** > [***Data Sources***](https://app.sola.security/integrations/data-sources) > click ***New data source*** > select ***Microsoft Entra ID***.

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="33.33333333333334%" %} <a href="https://app.sola.security/integrations/data-sources?integration=azuread" class="button primary">Set up Entra ID -></a>

{% endcolumn %}
{% endcolumns %}

To connect Entra ID, you’ll need a Microsoft Entra ID account with the necessary permissions to create and configure an App Registration.

{% tabs %}
{% tab title="App Registration" %}
These methods use an Azure App Registration within your subscription to securely grant Sola read-only access to your Azure services and resources.

* App Registration (Recommended)
* Terraform

{% hint style="info" %}
The **setup script**, provided in the Sola wizard, creates the relevant resources needed for accessing Entra ID data:

1. **Connecting to Azure AD** - Authenticates to Azure AD using the active Cloud Shell session
2. **Creating service principal** - Creates an Azure AD application and service principal for Sola
3. **Adding Microsoft Graph API permissions** - Grants the service principal the following Microsoft Graph reading permissions: `Application.Read.All`, `AuditLog.Read.All`, `Directory.Read.All`, `Domain.Read.All`, `Group.Read.All`, `IdentityProvider.Read.All`, `Policy.Read.All`, `User.Read.All`
   {% endhint %}
   {% endtab %}
   {% endtabs %}

#### Troubleshooting Entra ID setup script common errors <a href="#troubleshooting-azure-setup-script-common-errors" id="troubleshooting-azure-setup-script-common-errors"></a>

| Error Code           | Description                                                                       | Resolution                                                                                                            |
| -------------------- | --------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------- |
| MISSING\_PERMISSIONS | Your Azure AD account lacks the required directory role to perform the operation. | Ensure your account has the **Global Administrator** or **Privileged Role Administrator** role and re-run the script. |
| UNAUTHENTICATED      | The Azure AD session is not authenticated or has expired.                         | Re-open Cloud Shell, ensure you are connected to Azure AD, and re-run the script.                                     |
| NULL\_SECRET         | The service principal client secret was created but returned an empty value.      | Re-run the script. If the issue persists, contact Sola support.                                                       |
| UNEXPECTED\_ERROR    | An unexpected error occurred during the setup.                                    | Try again. Contact Sola support if the issue persists.                                                                |

## Explore Entra ID templates

![](/files/bKdo3yzED39AfQ5Oyclq) Get started with [Entra ID-focused security templates](https://sola.security/templates/?search=entra-id), built by our expert team.

<figure><img src="/files/BANDd9IzwAwB05rZYIOu" alt="Entra ID"><figcaption></figcaption></figure>


# Google Workspace

Connect Sola and Google Workspace to get security insights

The Google Workspace integration connects data from your Google Workspace to your Sola workspace, making it easy to search and find answers to your specific use cases.

{% embed url="<https://www.youtube.com/watch?v=GHNEochvVyU>" %}

## Overview

The Google Workspace gives you visibility into drive and file-sharing activity across Google Workspace, enabling you to identify exposure risks and maintain compliance across your organization.

With the Google Workspace integration, you can:

* Detect publicly or externally shared files.
* Monitor file sharing permissions to prevent unauthorized access.
* Investigate access levels granted to third parties.
* Maintain compliance with internal and external data-sharing policies.

{% hint style="warning" %}
**Your data can only be retrieved, never modified.**

Once connected, your data is securely stored, and access is restricted to retrieving configurations and meta-data only. Authentication methods ensure secure delegation of permissions while maintaining data integrity.
{% endhint %}

## Set up Google Workspace data source integration with Sola

{% columns %}
{% column width="58.333333333333336%" %}
Go to ***Integrations*** > [***Data Sources***](https://app.sola.security/integrations/data-sources) > click ***New data source*** > select ***Google Workspace***.

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="41.666666666666664%" %} <a href="https://app.sola.security/integrations/data-sources?integration=googleworkspace" class="button primary">Set up Google Workspace -></a>

{% endcolumn %}
{% endcolumns %}

### Connect Google Workspace to Sola

This integration links a **Google Cloud Platform (GCP) service accoun**t with a Google Workspace user.

It allows Sola to **impersonate workspace users** and securely sync their data without needing individual credentials.

{% tabs %}
{% tab title="Google Cloud Platform (GCP) Prerequisites" %}

* **GCP project with owner permissions** - Use an existing project or [create a new](https://developers.google.com/workspace/guides/create-project) one for this integration.

{% hint style="info" %}
The **setup script**, provided in the Sola wizard, creates the relevant resources needed for accessing Google Workspace data:

1. **Enabling APIs** - Enables the following Google Workspace APIs: `admin`, `drive`, `gmail`, `people`, `drivelabels`, `cloudidentity`
2. **Creating service account** - Creates a service account in the project for Sola
3. **Creating service account key** - Creates a service account key
   {% endhint %}
   {% endtab %}

{% tab title="Google Workspace Prerequisites" %}

* **Google Workspace** [**business plan**](https://workspace.google.com/pricing.html) (starter or above).
* **Super admin user** - Required for the initial integration setup, and will not be used by Sola.
  {% endtab %}
  {% endtabs %}

#### Troubleshooting Google Workspace setup script common errors <a href="#troubleshooting-azure-setup-script-common-errors" id="troubleshooting-azure-setup-script-common-errors"></a>

| Error Code           | Description                                                                           | Resolution                                                                                                     |
| -------------------- | ------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- |
| MISSING\_PERMISSIONS | Your GCP account lacks a required IAM permission on the project.                      | Ensure your account has the **Service Account Admin** and **Service Usage Admin** roles and re-run the script. |
| RESOURCE\_NOT\_FOUND | A required GCP resource does not exist or is not visible to you.                      | Verify the project ID in the GCP Console and re-run the script.                                                |
| RESOURCE\_EXISTS     | A service account with the requested name already exists.                             | Re-run the script (a new random name will be generated).                                                       |
| QUOTA\_EXCEEDED      | A GCP quota limit has been reached (e.g. max service accounts or keys per project).   | Delete unused resources or request a quota increase in the GCP Console, then re-run.                           |
| UNAUTHENTICATED      | The gcloud CLI is not authenticated.                                                  | Run `gcloud auth login` and try again.                                                                         |
| PROPAGATION\_TIMEOUT | The service account did not propagate within the expected time window after creation. | Wait a few minutes and try again.                                                                              |
| UNEXPECTED\_ERROR    | An unexpected error occurred.                                                         | Try again. Contact Sola support if the issue persists.                                                         |

## Explore Google templates

![](/files/bKdo3yzED39AfQ5Oyclq) Get started with [Google Workspace-focused security templates](https://sola.security/templates/?search=google-workspace), built by our expert team.

<figure><img src="/files/eLAqJSoDxVQlIw3JJS0J" alt="Google Workspace"><figcaption></figcaption></figure>


# GitHub Cloud

Connect Sola and GitHub Cloud to get security insights

## Overview

The GitHub Cloud integration connects data from your GitHub account to your Sola workspace, making it easy to search and find answers to your specific use cases.

The GitHub integration gives you a complete view of your GitHub organization, allowing you to monitor and analyze GitHub security posture and potential threats.

With the GitHub integration, you can:

* Gain full visibility into repository access and permissions.
* Monitor security policies, including branch protection and organization settings.
* Track and manage Dependabot vulnerability alerts.
* Ensure security best practices for your GitHub organization.

{% hint style="warning" %}
**Your data can only be retrieved, never modified.**

Once connected, your data is securely stored, and access is restricted to retrieving configurations and metadata only. Authentication methods ensure secure delegation of permissions while maintaining data integrity.
{% endhint %}

## Set up GitHub data source integration with Sola

{% columns %}
{% column width="75%" %}
Go to ***Integrations*** > [***Data Sources***](https://app.sola.security/integrations/data-sources) > click ***New data source*** > select ***GitHub Cloud***.

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="25%" %} <a href="https://app.sola.security/integrations/data-sources?integration=github" class="button primary">Set up GitHub -></a>
{% endcolumn %}
{% endcolumns %}

### Connect GitHub to Sola

To connect GitHub Cloud, you’ll need a GitHub account with organization owner permissions or admin access to all repositories in your GitHub organization.

{% tabs %}
{% tab title="GitHub App" %}
Recommended for secure, production use.\
This method leverages a GitHub App to grant Sola temporary, permissioned access to your GitHub resources, at either the repository or organization level, based on your choice. It minimizes risks associated with personal tokens and long-term credentials by enforcing strict, scoped access.

* **GitHub App** (*Recommended*)\
  Install Sola’s GitHub App to securely and easily grant access to your organization’s GitHub data.
* **Custom GitHub App**\
  Create and install your own GitHub App for full control over permissions and configuration\
  ([see how-to guide below](#how-do-i-set-up-a-github-data-source-using-custom-github-app))

*Not sure which method to choose?* We recommend starting with the GitHub App for the fastest and most reliable setup.
{% endtab %}

{% tab title="Access Token" %}
Personal access token with read permissions.

**Required scopes**:

* repo
* read:org
* read:user
* user:email
* gist
* read:project
  {% endtab %}
  {% endtabs %}

*Follow the* [*step-by-step guide below*](#how-do-i-set-up-a-github-data-source-using-custom-github-app) *to complete the setup.*

<details>

<summary><strong>How do I set up a GitHub data source using custom GitHub App?</strong> </summary>

Complete the following steps to set up and configure your GitHub App to integrate Sola with GitHub Cloud.

{% hint style="info" %}
[Learn more about creating GitHub Apps](https://docs.github.com/en/apps/creating-github-apps/registering-a-github-app/registering-a-github-app).
{% endhint %}

#### 1. Create and configure your GitHub App

* Log in to your GitHub account and go to ***GitHub Settings*** > ***Developer settings*** > ***GitHub Apps***.
* Click ***New GitHub App*****,** and set:
  * `App Name:` Sola Integration (recommended)
  * `Homepage URL:` [https://app.sola.security](https://app.sola.security/)
  * `Webhook:` Uncheck Active (No webhook required)
  * `Permissions:` We recommend providing ***Read-Only*** permissions for all repository and organization related permissions.
    * To access GitHub workflows, you will need at least ***Read & Write*** permissions.
    * For valuable insights, provide access to at least the following scopes:
      * `repository:administration`
      * `repository:metadata`
      * `repository:webhooks`
      * `organization:administration`
      * `organization:webhooks`
* Click ***Create GitHub App*** and save the ***App ID***.

#### 2. Generate a Private Key

* In your newly created app settings, navigate to ***General*** > ***Private Keys***.
* Click ***Generate a private key***.
* Securely store the downloaded **.pem file**. This is your GitHub App private key.

#### 3. Install the GitHub App

* In the app settings, go to the ***Install App*** tab.
* Select the organization or account where you want to install the app.
* Click **Install** and confirm the installation.

#### 4. Get your installation ID

After installing the app, you will be redirected to the installation page: **<https://github.com/settings/installations/\\>\<app\_installation\_id>**

* Copy and save the **\<app\_installation\_id>**.

#### 5. Provide your credentials to Sola

Complete the integration by providing the following parameters in the Sola wizard:

* [x] GitHub App ID&#x20;
* [x] GitHub App Installation ID&#x20;
* [x] GitHub App private key (.pem file)

</details>

## Sync behavior and limitations

Some tables have specific sync constraints due to data size, retention policies, or performance considerations. Below are special cases to be aware of:

<table><thead><tr><th width="233.73828125">Table</th><th>Sync details</th></tr></thead><tbody><tr><td>github_commit</td><td>Includes data from the last 1 month.</td></tr><tr><td>github_actions_artifact</td><td>Includes data from the last 3 months.</td></tr><tr><td>github_issue</td><td>Includes data from the last 3 months.</td></tr><tr><td>github_issue_comment</td><td>Inherits the 3-month limit from github_issue, as comments are linked to issues.</td></tr><tr><td>github_pull_request</td><td>Includes data from the last 3 months.</td></tr><tr><td>github_release</td><td>Includes data from the last 3 months.</td></tr><tr><td>github_tag</td><td>Includes data from the last 3 months.</td></tr></tbody></table>

## Explore GitHub Cloud templates

![](/files/bKdo3yzED39AfQ5Oyclq) Get started with [GitHub-focused security templates](https://sola.security/templates/?search=github), built by our expert team.

<figure><img src="/files/FNJ6DnRmNSUvDTprjVEx" alt="GitHub Cloud"><figcaption></figcaption></figure>


# Okta

Connect Sola and Okta to get security insights

The Okta integration connects data from your Okta account to your Sola workspace, making it easy to search and find answers to your specific use cases.

{% embed url="<https://youtu.be/i1XnFbQ9TdQ>" %}

## Overview

The Okta integration provides a complete view of your identity and access across your organization, allowing you to monitor and analyze Okta security posture and potential threats.

With the Okta integration, you can:

* Gain visibility into user identities, groups, and roles.
* Monitor Okta activity and get insights into configuration settings.
* Ensure users and applications only have the access they actually need.
* Maintain security best practices for your Okta environment.

{% hint style="warning" %}
**Your data can only be retrieved, never modified.**

Once connected, your data is securely stored, and access is restricted to retrieving configurations and metadata only. Authentication methods ensure secure delegation of permissions while maintaining data integrity.
{% endhint %}

## Set up Okta data source integration with Sola

{% columns %}
{% column width="75%" %}
Go to ***Integrations*** > [***Data Sources***](https://app.sola.security/integrations/data-sources) > click ***New data source*** > select ***Okta***.

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="25%" %} <a href="https://app.sola.security/integrations/data-sources?integration=okta" class="button primary">Set up Okta -></a>
{% endcolumn %}
{% endcolumns %}

### Connect Okta to Sola

To connect Okta, you’ll need an Okta admin account, or an [Okta service account](#how-do-i-set-up-an-okta-data-source-using-a-service-account) with Read-only Administrator access and IAM visibility permissions.

{% tabs %}
{% tab title="API Token" %}
This method uses an [API token](https://help.okta.com/en-us/content/topics/security/api.htm?cshid=ext-create-api-token#create-okta-api-token) to securely grant Sola read-only access to your Okta services and resources.
{% endtab %}
{% endtabs %}

*Follow the* [*step-by-step guide below*](#how-do-i-set-up-an-okta-data-source-using-a-service-account) *to complete the setup.*

<details>

<summary><strong>How do I set up an Okta data source using a service account?</strong></summary>

Complete the following steps to create a dedicated Okta service account with read-only access and connect it to Sola.

**1. Create a service account in Okta**\
You can also use an existing service account.

* In Okta Admin Console, go to ***Directory*** > ***People*** and click ***Add Person***.
* Use a dedicated internal email (e.g “<sola-integration@yourcompany.com>”) and save the user.

**2. Create an IAM resource set (for visibility permissions)**

* Go to ***Security*** > ***Administrators*** and open the ***Resources*** tab.
* Click ***Create resource set,*** then add Identity and Access Management resources (select `All Identity and Access Management resources`).

**3. Create a custom role (for IAM visibility)**

* In ***Security*** > ***Administrators***, open the ***Roles*** tab.
* Click ***Create new role*** and enable `View roles`, `resources`, and `admin assignments`.

**4. Assign permissions to the service account**

* Go to ***Security*** > ***Administrators*** > ***Admins*** and click ***Add administrator***.
* Add two assignments:
  * `Read-only Administrator` with `Entire Organization`
  * The custom role with the IAM resource set you created
* Save changes.

**5. Generate the API token and connect in Sola**

* Log out, then log in to Okta as the service account.
* Go to ***Security*** > ***API*** > ***Tokens*** and click ***Create Token*** (copy the token value).
* In Sola, add the Okta data source and provide:
  * `Okta Domain`
  * `API Token`
* Click Test Connection, then continue.

</details>

## Explore Okta templates

![](/files/bKdo3yzED39AfQ5Oyclq) Get started with [Okta-focused security templates](https://sola.security/templates/?search=okta), built by our expert team.

<figure><img src="/files/4DpqPOft7rGvZybASjYe" alt="Okta"><figcaption></figcaption></figure>


# MongoDB Atlas

Connect Sola and MongoDB Atlas to get security insights

## Overview

The MongoDB Atlas integration connects data from your MongoDB Atlas account to your Sola workspace, making it easy to search and find answers to your specific use cases.

The MongoDB Atlas integration gives you a complete view of your MongoDB environment, allowing you to monitor and analyze MongoDB security posture and potential risks.

With the MongoDB Atlas integration, you can:

* Gain insights into MongoDB user roles, access permissions, and authentication methods.
* Monitor network exposure and cluster security configurations.
* Track user activity trends.
* Ensure security best practices for your MongoDB environment.

{% hint style="warning" %}
**Your data can only be retrieved, never modified.**

Once connected, your data is securely stored, and access is restricted to retrieving configurations and metadata only. Authentication methods ensure secure delegation of permissions while maintaining data integrity.
{% endhint %}

## Set up MongoDB Atlas data source integration with Sola

{% columns %}
{% column width="66.66666666666666%" %}
Go to ***Integrations*** > [***Data Sources***](https://app.sola.security/integrations/data-sources) > click ***New data source*** > select ***MongoDB Atlas***.

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="33.33333333333334%" %} <a href="https://app.sola.security/integrations/data-sources?integration=mongodbatlas" class="button primary">Set up MongoDB -></a>
{% endcolumn %}
{% endcolumns %}

### Connect MongoDB Atlas to Sola

To connect MongoDB Atlas, you’ll need a MongoDB Atlas account with organization owner access to Atlas.

{% tabs %}
{% tab title="API Key" %}
This method uses an [API key](https://www.mongodb.com/docs/atlas/configure-api-access/#grant-programmatic-access-to-an-organization) to securely grant Sola read-only access to your MongoDB Atlas services and resources.
{% endtab %}
{% endtabs %}

## Explore MongoDB templates

![](/files/bKdo3yzED39AfQ5Oyclq) Get started with [MongoDB-focused security templates](https://sola.security/templates/?search=mongodb), built by our expert team.

<figure><img src="/files/4DpqPOft7rGvZybASjYe" alt="MongoDB Atlas"><figcaption></figcaption></figure>


# Wiz

Connect Sola and Wiz to get security insights

## Overview

The Wiz integration connects data from your Wiz account to your Sola workspace, making it easy to search and find answers to your specific use cases.

The Wiz integration provides a complete view of your Wiz environment, allowing you to monitor and analyze security posture and potential risks.

With the Wiz integration, you can:

* Gain visibility into security issues across your Wiz projects.
* Identify misconfigurations, vulnerabilities, compliance risks, and other findings.
* Get a centralized view of the most critical issues detected by Wiz.
* Monitor access controls and manage service accounts.
* Consolidate Wiz insights with other security tools for cross-platform analysis.

{% hint style="warning" %}
**Your data can only be retrieved, never modified.**

Once connected, your data is securely stored, and access is restricted to retrieving configurations and metadata only. Authentication methods ensure secure delegation of permissions while maintaining data integrity.
{% endhint %}

## Set up Wiz data source integration with Sola

{% columns %}
{% column width="75%" %}
Go to ***Integrations*** > [***Data Sources***](https://app.sola.security/integrations/data-sources) > click ***New data source*** > select ***Wiz***.

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="25%" %} <a href="https://app.sola.security/integrations/data-sources?integration=wiz" class="button primary">Set up Wiz -></a>
{% endcolumn %}
{% endcolumns %}

### Connect Wiz to Sola

To connect Wiz, you’ll need a Wiz admin account with the `read:all` scope permissions to create and configure a service account.

{% tabs %}
{% tab title="Service Account" %}
This method uses a Wiz service account to securely grant Sola read-only access to your Wiz findings, issues, and configurations.
{% endtab %}
{% endtabs %}

## Explore Wiz templates

![](/files/bKdo3yzED39AfQ5Oyclq) Get started with [Wiz-focused security templates](https://sola.security/templates/?search=wiz), built by our expert security team.

<figure><img src="/files/kPSg0xJG1X56dt7feuHQ" alt="Wiz"><figcaption></figcaption></figure>


# Upwind

Connect Sola and Upwind to get security insights

## Overview

The Upwind integration connects data from your Upwind account to your Sola workspace, making it easy to search and find answers to your specific use cases.

With the Upwind integration, you can:

* Monitor threat detections and threat policies across your Upwind-connected cloud environment.
* Track vulnerability findings identified by Upwind.
* Review configuration findings and checks, including remediation guidance for identified issues.

{% hint style="warning" %}
**Your data can only be retrieved, never modified.**

Once connected, your data is securely stored, and access is restricted to retrieving configurations and metadata only. Authentication methods ensure secure delegation of permissions while maintaining data integrity.
{% endhint %}

## Set up Upwind data source integration with Sola

{% columns %}
{% column width="75%" %}
Go to ***Integrations*** > [***Data Sources***](https://app.sola.security/integrations/data-sources) > click ***New data source*** > select ***Upwind***.

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="25%" %} <a href="https://app.sola.security/integrations/data-sources?integration=upwind" class="button primary">Set up Wiz -></a>
{% endcolumn %}
{% endcolumns %}

### Connect Upwind to Sola

To connect Upwind, you'll need access to your Upwind console to generate API credentials, along with your Organization ID and region of data center.

{% tabs %}
{% tab title="Service Account" %}
This method uses an Upwind service account to securely grant Sola read-only access to your Upwind threat, vulnerability, and configuration data.
{% endtab %}
{% endtabs %}


# WordPress

Connect Sola and WordPress to get security insights

## Overview

The WordPress integration allows you to enrich Sola Apps with issues found for your WordPress websites, scanning for common vulnerabilities and misconfigurations.

Add your WordPress website URLs to uncover hidden risks and continuously monitor the security posture of your public WordPress websites.

With the WordPress integration, you can:

* Get visibility into security risks across all public WordPress sites
* Uncover hidden exposures that traditional tools can miss
* Monitor the security posture of your assets over time
* Surface exposed admin panels and login endpoints
* Track headers and security best practice compliance

{% hint style="warning" %}
**Your data can only be retrieved, never modified.**

Once connected, your data is securely stored, and access is restricted to retrieving configurations and metadata only. Authentication methods ensure secure delegation of permissions while maintaining data integrity.
{% endhint %}

## Set up WordPress data source integration with Sola

{% columns %}
{% column width="66.66666666666666%" %}
Go to ***Integrations*** > [***Data Sources***](https://app.sola.security/integrations/data-sources) > click ***New data source*** > select ***WordPress***.

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="33.33333333333334%" %} <a href="https://app.sola.security/integrations/data-sources?integration=wordpress" class="button primary">Set up WordPress -></a>
{% endcolumn %}
{% endcolumns %}

### Connect WordPress to Sola

Analyze your WordPress websites using one of two verification methods to confirm ownership and begin scanning for security issues.

{% tabs %}
{% tab title="Company domain matching" %}
**Automatic verification**

This method matches the domain of the WordPress site to the email domain associated with your Sola account.

* Quick and easy setup

{% hint style="warning" %}
Only websites matching your **verified email domain** can be scanned using this method.

For example, if you signed up with *<name@mysecurityorg.com>*, Sola will only be able to scan **\*.mysecurityorg.com** (your domain and any subdomains), such as *blog.mysecurityorg.com* or *wp.mysecurityorg.com*.
{% endhint %}
{% endtab %}

{% tab title="HTTP verification using a TXT file" %}
This method allows HTTP verification by uploading a TXT file to your website.

* Flexible and secure for multi-site environments

**How to set up HTTP verification:**

Upload the provided UUID in the Sola wizard as a ***sola-verification.txt*** file to your WordPress site under the following path:

```
/.well-known/sola-verification.txt
```

For example: `https://my-wordpress-site.com/.well-known/sola-verification.txt`
{% endtab %}
{% endtabs %}

## Explore WordPress templates

![](/files/bKdo3yzED39AfQ5Oyclq) Get started with [WordPress-focused security templates](https://sola.security/templates/?search=wordpress), built by our expert security team.

<figure><img src="/files/CjvKJCfuB5EqMpYlT6Xi" alt="WordPress"><figcaption></figcaption></figure>


# Sola Web Checker

Analyze external domains, websites, and internet-facing infrastructure to get security insights

## Overview

The Sola Web Checker integration allows you to enrich Sola Apps with data from your external domains, URLs, and host endpoints, scanning for common vulnerabilities and misconfigurations.&#x20;

Add your domains, URLs, or IP addresses to uncover hidden risks, validate critical security protections, and continuously monitor the security posture of your public assets.

With the Sola Web Checker integration, you can:

* Monitor TLS protocol versions, cipher suites, and encryption strength
* Detect missing or misconfigured HTTP security headers
* Track certificate validity, expiration, and best practice compliance
* Identify weak configurations and DNS record issues
* Continuously assess domain posture over time

{% hint style="warning" %}
**Your data can only be retrieved, never modified.**

Once connected, your data is securely stored, and access is restricted to retrieving configurations and metadata only. Authentication methods ensure secure delegation of permissions while maintaining data integrity.
{% endhint %}

## Set up Web Checker data source integration with Sola

{% columns %}
{% column width="66.66666666666666%" %}
Go to ***Integrations*** > [***Data Sources***](https://app.sola.security/integrations/data-sources) > click ***New data source*** > select ***Sola Web Checker***.

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="33.33333333333334%" %} <a href="https://app.sola.security/integrations/data-sources?integration=webchecker" class="button primary">Set up Web Checker -></a>
{% endcolumn %}
{% endcolumns %}

### Add domains, URLs and host endpoints

Analyze DNS records, security and response headers, certificates, TLS, and public accessibility by adding your organization’s publicly facing web assets.

## Explore Sola Web Checker templates

![](/files/bKdo3yzED39AfQ5Oyclq) Get started with [Sola Web Checker - Domain Insights security templates](https://sola.security/templates/?search=webchecker), built by our expert security team.

<figure><img src="/files/4T1tHo0MuH0kMJuSlSAD" alt="Sola Web Checker"><figcaption></figcaption></figure>


# Lovable App Scanner

Analyze Lovable apps to detect endpoint, authentication, and exposure risks

## Overview

The Lovable App Scanner integration brings security insights from applications built on the no-code platform Lovable.dev into Sola for analysis and monitoring.

This integration enables external scanning of your live Lovable apps.

With the Lovable App Scanner integration, you can:&#x20;

* Get visibility into security risks across public Lovable apps
* Uncover vulnerabilities, misconfigurations, and hidden exposures
* Get actionable insights to improve your security posture

{% hint style="warning" %}
**Your data can only be retrieved, never modified.**

Once connected, your data is securely stored, and access is restricted to retrieving configurations and metadata only. Authentication methods ensure secure delegation of permissions while maintaining data integrity.
{% endhint %}

## Set up Lovable App Scanner data source integration with Sola

{% columns %}
{% column width="66.66666666666666%" %}
Go to ***Integrations*** > [***Data Sources***](https://app.sola.security/integrations/data-sources) > click ***New data source*** > select ***Lovable App Scanner***.

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="33.33333333333334%" %} <a href="https://app.sola.security/integrations/data-sources?integration=lovable" class="button primary">Set up Lovable -></a>
{% endcolumn %}
{% endcolumns %}

### Add Lovable app public URLs

Uncover potential security risks and continuously monitor their external security posture, without modifying your live app.

## Explore Lovable App Scanner templates

![](/files/bKdo3yzED39AfQ5Oyclq) Get started with [Lovable App Scanner - Security Posture](https://sola.security/templates/?search=lovable), built by our expert security team.

<figure><img src="/files/3vmEeBJP1rOotBArYTJ1" alt="Lovable"><figcaption></figcaption></figure>


# CSV File

Upload CSV files with custom datasets for analysis and insights

## Overview

The CSV File integration allows you to bring unique datasets into Sola by uploading structured CSV files.

Leverage your own data across Sola’s capabilities to uncover insights, and analyze patterns within your custom datasets.

With the CSV file integration you can bring in custom datasets to explore insights beyond standard integrations.

{% hint style="warning" %}
**Your data can only be retrieved, never modified.**

Once connected, your data is securely stored, and access is restricted to retrieving configurations and metadata only. Authentication methods ensure secure delegation of permissions while maintaining data integrity.
{% endhint %}

## Set up CSV File data source integration with Sola

{% columns %}
{% column width="66.66666666666666%" %}
Go to ***Integrations*** > [***Data Sources***](https://app.sola.security/integrations/data-sources) > click ***New data source*** > click the ***Upload CSV*** button (top right of screen).

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="33.33333333333334%" %} <a href="https://app.sola.security/integrations/data-sources?integration=csv" class="button primary">Set up CSV File -></a>
{% endcolumn %}
{% endcolumns %}

### Add CSV files

Start exploring your own data instantly, no connectors or integrations required.

Upload a CSV file as a new data source to analyze custom datasets in Sola. Each CSV upload creates a separate, independent integration.

{% hint style="info" %}
**Updating an existing CSV integration**

An existing CSV integration cannot be replaced, updated, or appended to after upload. To use a new or updated file, create a new CSV integration (add it as a new data source). The original integration remains unchanged and can be deleted if no longer needed.
{% endhint %}

***

## FAQs

### Can I upload a new CSV file to the same integration?

No. CSV integrations cannot be replaced, updated, or appended to after upload. To use a new or updated file, create a new CSV integration.


# Zoom

Connect Sola and Zoom to get security insights

## Overview

The Zoom integration connects data from your Zoom account to your Sola workspace, making it easy to search and find answers to your specific use cases.

The Zoom integration provides a comprehensive view of your Zoom environment including users, roles, meetings, and settings to monitor security posture and compliance.

With Zoom integration you can:

* Gain visibility into configuration changes
* Enforce secure collaboration policies and security best practices
* Ensure compliance with internal policies and industry standards

{% hint style="warning" %}
**Your data can only be retrieved, never modified.**

Once connected, your data is securely stored, and access is restricted to retrieving configurations and metadata only. Authentication methods ensure secure delegation of permissions while maintaining data integrity.
{% endhint %}

## Set up Zoom data source integration with Sola

{% columns %}
{% column width="75%" %}
Go to ***Integrations*** > [***Data Sources***](https://app.sola.security/integrations/data-sources) > click ***New data source*** > select ***Zoom***.

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="25%" %} <a href="https://app.sola.security/integrations/data-sources?integration=zoom" class="button primary">Set up Zoom -></a>
{% endcolumn %}
{% endcolumns %}

### Connect Zoom to Sola

To connect Zoom to Sola, you need a Zoom account with Owner or Admin permissions that allow creating Server-to-Server OAuth apps in the Zoom Marketplace.

<details>

<summary>How do I set up a Zoom data source using Server-to-Server OAuth app?</summary>

Complete the following steps to set up and configure your Zoom app to integrate Sola with Zoom.

1. Sign in to your [Zoom](https://zoom.us/signin) account.
2. Go to [Build App in Zoom Marketplace](https://marketplace.zoom.us/develop/create), select ***Server-to-Server OAuth***, and click ***Create***.
3. Name the app and click ***Create***.
4. Copy and save the generated&#x20;
   * ***Account ID***
   * ***Client ID***
   * ***Client Secret***
5. Complete the ***Information*** and ***Feature*** steps.
6. Add the following scopes:
   * `account:read:lock_settings:admin`
   * `account:read:settings:admin`
   * `account:read:trusted_domains:admin`
   * `account:read:managed_domains:admin`
   * `group:read:list_groups:admin`
   * `group:read:list_members:admin`
   * `role:read:list_roles:admin`
   * `role:read:role:admin`
   * `role:read:list_members:admin`
   * `user:read:list_users:admin`
   * `user:read:user:admin`
   * `meeting:read:list_meetings:admin`
   * `meeting:read:meeting:admin`
   * `cloud_recording:read:list_user_recordings:admin`
   * `cloud_recording:read:list_recording_settings:admin`
7. Activate the app.
8. Complete the integration by providing the following parameters in the Sola wizard:
   * ***Account ID***
   * ***Client ID***
   * ***Client Secret***
9. Click ***Test Connection*** to validate the details, then click ***Next*** to continue.

Learn more about [creating a Server-to-Server OAuth app](https://developers.zoom.us/docs/internal-apps/create/).<br>

</details>


# Jira Cloud

Connect Sola and Jira Cloud to get security insights

## Overview <a href="#overview" id="overview"></a>

The Jira Cloud integration allows you to enrich Sola apps with project and issue tracking data for enhanced visibility and operational insights.

The Jira Cloud integration imports data on projects, issues, tasks, boards, sprints, users, groups, permissions, audit records, and more. This provides security teams with visibility into access configurations and administrative changes, alongside development activity that may affect security posture.

With the Jira Cloud integration, you can:

* Gain visibility into Jira projects, issues, and sprints to understand development activity that may impact security.
* Monitor Jira permission schemes, roles, and security levels to ensure proper access controls.
* Review Jira audit records to track administrative changes and support compliance monitoring.
* Analyze Jira boards and sprints to identify bottlenecks that could delay security-related work.

{% hint style="warning" %}
**Your data can only be retrieved, never modified.**

Once connected, your data is securely stored, and access is restricted to retrieving configurations and metadata only. Authentication methods ensure secure delegation of permissions while maintaining data integrity.
{% endhint %}

## Set up Jira Cloud data source integration with Sola

{% columns %}
{% column width="66.66666666666666%" %}
Go to ***Integrations*** > [***Data Sources***](https://app.sola.security/integrations/data-sources) > click ***New data source*** > select ***Jira Cloud***.

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="33.33333333333334%" %} <a href="https://app.sola.security/integrations/data-sources?integration=jiracloud" class="button primary">Set up Jira Cloud -></a>
{% endcolumn %}
{% endcolumns %}

### Connect Jira Cloud to Sola <a href="#connect-github-to-sola" id="connect-github-to-sola"></a>

To connect Jira Cloud, you need a Jira account with permissions according to the data you want to access, including security, projects, users and groups, and boards, ensuring secure and controlled data access.

{% tabs %}
{% tab title="Jira App" %}
This method leverages a Jira App to securely grant Sola read-only, permissioned access to your Jira resources. It minimizes risks associated with personal tokens and long-term credentials by enforcing strict, scoped access.

When prompted, sign in with your Jira administrator account and approve the requested access.
{% endtab %}
{% endtabs %}


# Cloudflare

Connect Sola and Cloudflare to get security insights

The Cloudflare integration connects your Cloudflare environment to Sola, making it easy to search and find answers to your specific use cases.

{% embed url="<https://youtu.be/bZU_qJXRU8Q?si=Trd2ryucQQCSAkDU>" %}

## Overview <a href="#overview" id="overview"></a>

The Cloudflare integration provides visibility into accounts, services, and configurations for monitoring security posture, allowing you to monitor and analyze access controls, account settings, traffic management, policy enforcement, and audit logs.

With Cloudflare integration you can:

* Gain visibility into access policies and account configurations.
* Monitor and analyze DNS, load balancing, and traffic management.
* Review page rules, workers, and zones for compliance with best practices.
* Track user activity and audit logs across your Cloudflare environment.
* Investigate your Zero Trust environment, including access control, device posture, gateway filtering, DLP, and risk scoring.

{% hint style="warning" %}
**Your data can only be retrieved, never modified.**

Once connected, your data is securely stored, and access is restricted to retrieving configurations and metadata only. Authentication methods ensure secure delegation of permissions while maintaining data integrity.
{% endhint %}

## Set up Cloudflare data source integration with Sola <a href="#set-up-lovable-app-scanner-data-source-integration-with-sola" id="set-up-lovable-app-scanner-data-source-integration-with-sola"></a>

{% columns %}
{% column width="66.66666666666666%" %}
Go to ***Integrations*** > [***Data Sources***](https://app.sola.security/integrations/data-sources) > click ***New data source*** > select ***Cloudflare***.

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="33.33333333333334%" %} <a href="https://app.sola.security/integrations/data-sources?integration=cloudflare" class="button primary">Set up Cloudflare -></a>
{% endcolumn %}
{% endcolumns %}

### Connect Cloudflare to Sola <a href="#add-lovable-app-public-urls" id="add-lovable-app-public-urls"></a>

To connect Cloudflare, you’ll need a Cloudflare user with an administrator role.

{% tabs %}
{% tab title="API Token" %}
This method uses an [API token](https://developers.cloudflare.com/fundamentals/api/get-started/create-token/) to securely grant Sola read-only access to your Cloudflare services and resources.
{% endtab %}
{% endtabs %}


# SentinelOne

Connect Sola and SentinelOne to get security insights

## Overview <a href="#overview" id="overview"></a>

The SentinelOne integration connects endpoint security data to your Sola workspace, making it easy to search and find answers to your specific use cases.

The SentinelOne integration provides a comprehensive view of your endpoint security environment, enabling you to monitor endpoint agents, analyze threat detections, and track overall security posture across your organization.

With the SentinelOne integration, you can:

* Gain visibility into endpoint agents and threat detection events.
* Monitor vulnerabilities, applications, and detection rule activity.
* Review security management policies.
* Track and analyze endpoint activity across your environment.

{% hint style="warning" %}
**Your data can only be retrieved, never modified.**

Once connected, your data is securely stored, and access is restricted to retrieving configurations and metadata only. Authentication methods ensure secure delegation of permissions while maintaining data integrity.
{% endhint %}

## Set up SentinelOne data source integration with Sola <a href="#set-up-wiz-data-source-integration-with-sola" id="set-up-wiz-data-source-integration-with-sola"></a>

To connect SentinelOne, you’ll need a SentinelOne tenant with an administrator user.

{% columns %}
{% column width="66.66666666666666%" %}
Go to ***Integrations*** > [***Data Sources***](https://app.sola.security/integrations/data-sources) > click ***New data source*** > select ***SentinelOne***.

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="33.33333333333334%" %} <a href="https://app.sola.security/integrations/data-sources?integration=sentinelone" class="button primary">Set up SentinelOne -></a>
{% endcolumn %}
{% endcolumns %}

{% tabs %}
{% tab title="API Token" %}
This method uses an [API token](https://help.sumologic.com/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/sentinelone-mgmt-api-source/) to securely grant Sola read-only access to your SentinelOne services and resources.
{% endtab %}
{% endtabs %}


# Claude Console

Connect Sola and Claude Console to get security insights

## Overview <a href="#overview" id="overview"></a>

The Claude Console integration connects data from your Claude account to your Sola workspace, making it easy to search and find answers to your specific use cases.

With the Claude Console integration, you can:

* Gain visibility into user access, roles, and workspace permissions across your Anthropic organization.
* Monitor API key status, creator, and workspace assignment to identify stale or unmanaged keys.
* Track organization invitations, including pending, accepted, and expired, to maintain access governance.
* Monitor token usage and Claude Code activity by model, workspace, and user.

{% hint style="warning" %}
**Your data can only be retrieved, never modified.**

Once connected, your data is securely stored, and access is restricted to retrieving configurations and metadata only. Authentication methods ensure secure delegation of permissions while maintaining data integrity.
{% endhint %}

## Set up Claude Console data source integration with Sola <a href="#set-up-wiz-data-source-integration-with-sola" id="set-up-wiz-data-source-integration-with-sola"></a>

{% columns %}
{% column width="66.66666666666666%" %}
Go to ***Integrations*** > [***Data Sources***](https://app.sola.security/integrations/data-sources) > click ***New data source*** > select ***Claude Console***.

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="33.33333333333334%" %} <a href="https://app.sola.security/integrations/data-sources?integration=anthropic" class="button primary">Set up Claude Console -></a>
{% endcolumn %}
{% endcolumns %}

To connect Claude Console, you'll need an Anthropic Console account with an Admin role.

{% tabs %}
{% tab title="Admin API Key" %}
This method uses an Admin API Key to securely grant Sola read-only access to your Anthropic organization data.
{% endtab %}
{% endtabs %}

## Explore Claude Console templates

![](/files/bKdo3yzED39AfQ5Oyclq) Get started with [Claude-focused security templates](https://sola.security/templates/?search=claude), built by our expert security team.

<figure><img src="/files/mz2ailQdVyGHqQMhMdyl" alt="Anthropic"><figcaption></figcaption></figure>

***

## FAQs

### What is the difference between the Claude data sources?

Sola offers three Anthropic integrations:

* [Claude Console](/integrations/data-sources/claude-console): for API platform customers (Build, Scale, or Team).
* [Claude Enterprise](/integrations/data-sources/claude-enterprise): for seat-based claude.ai plans, with compliance and activity data for eDiscovery and DLP.
* [Claude Enterprise Analytics](/integrations/data-sources/claude-enterprise-analytics): for seat-based claude.ai plans, with usage, adoption, and cost analytics.
* [Claude Code](/integrations/data-sources/claude-code): for organizations using Claude Code as an AI coding agent, with visibility into developer sessions, tool calls, and prompts.

Use Console if you connect to Anthropic through the API platform. If you're on a seat-based claude.ai plan, use the Claude Enterprise integrations; you can connect both.


# Claude Enterprise

Connect Sola and Claude Enterprise to get security insights

## Overview <a href="#overview" id="overview"></a>

The Claude Enterprise integration connects data from your Claude Enterprise account to your Sola workspace, making it easy to search and find answers to your specific use cases.

With the Claude Enterprise integration, you can:

* Monitor user and admin activity across your Claude Enterprise organization, including authentication events, chat interactions, file uploads, and administrative actions.
* Track organizational users, groups, and custom RBAC roles to support access governance and compliance requirements.
* Gain full visibility into projects, including creator, privacy settings, and attached files across your Claude Enterprise organization.
* Monitor chat conversations to support eDiscovery and data loss prevention investigations.

{% hint style="warning" %}
**Your data can only be retrieved, never modified.**

Once connected, your data is securely stored, and access is restricted to retrieving configurations and metadata only. Authentication methods ensure secure delegation of permissions while maintaining data integrity.
{% endhint %}

## Set up Claude Enterprise data source integration with Sola <a href="#set-up-wiz-data-source-integration-with-sola" id="set-up-wiz-data-source-integration-with-sola"></a>

{% columns %}
{% column width="66.66666666666666%" %}
Go to ***Integrations*** > [***Data Sources***](https://app.sola.security/integrations/data-sources) > click ***New data source*** > select ***Claude Enterprise***.

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="33.33333333333334%" %} <a href="https://app.sola.security/integrations/data-sources?integration=anthropiccompliance" class="button primary">Set up Claude Enterprise -></a>
{% endcolumn %}
{% endcolumns %}

To connect Claude Enterprise, you'll need to be the Primary Owner of your Claude.ai parent organization, with the Compliance API enabled for your organization.

{% tabs %}
{% tab title="Compliance API Key" %}
This method uses a Compliance Access Key generated from Claude.ai to grant Sola read-only access to your Claude Enterprise compliance data.
{% endtab %}
{% endtabs %}

***

## FAQs

### What is the difference between the Claude data sources?

Sola offers three Anthropic integrations:

* [Claude Console](/integrations/data-sources/claude-console): for API platform customers (Build, Scale, or Team).
* [Claude Enterprise](/integrations/data-sources/claude-enterprise): for seat-based claude.ai plans, with compliance and activity data for eDiscovery and DLP.
* [Claude Enterprise Analytics](/integrations/data-sources/claude-enterprise-analytics): for seat-based claude.ai plans, with usage, adoption, and cost analytics.
* [Claude Code](/integrations/data-sources/claude-code): for organizations using Claude Code as an AI coding agent, with visibility into developer sessions, tool calls, and prompts.

Use Console if you connect to Anthropic through the API platform. If you're on a seat-based claude.ai plan, use the Claude Enterprise integrations; you can connect both.


# Claude Enterprise Analytics

Connect Sola and Claude Enterprise Analytics to get security insights

## Overview <a href="#overview" id="overview"></a>

The Claude Enterprise Analytics integration connects data from your Claude Enterprise account to your Sola workspace, making it easy to search and find answers to your specific use cases.

Monitor how Claude is adopted and used across your organization to support insider-risk detection, license governance, and access-hygiene reviews.

With the Claude Enterprise Analytics integration, you can:

* Monitor per-user Claude activity across Claude.ai, Claude Code, and the office and cowork apps
* Track organization-level engagement, including active users, seats, and invites
* See how skills, connectors, and chat projects are used across your organization
* Review per-user and organization-level token consumption and spend

{% hint style="warning" %}
**Your data can only be retrieved, never modified.**

Once connected, your data is securely stored, and access is restricted to retrieving configurations and metadata only. Authentication methods ensure secure delegation of permissions while maintaining data integrity.
{% endhint %}

## Set up Claude Enterprise Analytics data source integration with Sola <a href="#set-up-wiz-data-source-integration-with-sola" id="set-up-wiz-data-source-integration-with-sola"></a>

{% columns %}
{% column width="58.333333333333336%" %}
Go to ***Integrations*** > [***Data Sources***](https://app.sola.security/integrations/data-sources) > click ***New data source*** > select ***Claude Enterprise Analytics***.

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="41.666666666666664%" %} <a href="https://app.sola.security/integrations/data-sources?integration=anthropicanalytics" class="button primary">Set up Claude Enterprise Analytics -></a>
{% endcolumn %}
{% endcolumns %}

To connect Claude Enterprise, you'll need to be the Primary Owner of your Claude Enterprise organization. Only the Primary Owner can enable API access and create Analytics API keys.

{% tabs %}
{% tab title="Analytics API Key" %}
This method uses an Analytics API key to securely grant Sola read-only access to your Claude Enterprise usage and activity data.
{% endtab %}
{% endtabs %}

{% hint style="info" %}
**Data freshness**

Engagement data reflects activity up to 3 days prior. This applies to the Usage & Activity, Organization, and Skills, Connectors & Projects tables.
{% endhint %}

***

## FAQs

### What is the difference between the Claude data sources?

Sola offers three Anthropic integrations:

* [Claude Console](/integrations/data-sources/claude-console): for API platform customers (Build, Scale, or Team).
* [Claude Enterprise](/integrations/data-sources/claude-enterprise): for seat-based claude.ai plans, with compliance and activity data for eDiscovery and DLP.
* [Claude Enterprise Analytics](/integrations/data-sources/claude-enterprise-analytics): for seat-based claude.ai plans, with usage, adoption, and cost analytics.
* [Claude Code](/integrations/data-sources/claude-code): for organizations using Claude Code as an AI coding agent, with visibility into developer sessions, tool calls, and prompts.

Use Console if you connect to Anthropic through the API platform. If you're on a seat-based claude.ai plan, use the Claude Enterprise integrations; you can connect both.


# Claude Code

Connect Sola and Claude Code to get security insights

## Overview <a href="#overview" id="overview"></a>

The Claude Code integration allows you to monitor the security posture and usage of Claude Code, your coding agent, across your organization as a real-time data stream, and investigate it alongside your broader security environment.

With the Claude Code integration, you can:

* Get a full inventory of what's installed on each developer's machine, including plugins, trusted marketplaces, custom skills, and subagents.
* Review MCP server connections, permission rules, hooks, and security settings such as bypass mode and auto-update channel, to spot risky configurations before they're exploited.
* See which AWS, GCP, and Azure profiles are configured on each device, without exposing the underlying credentials, and correlate them with identity and access data across your environment.
* Track developer sessions, tool calls, and prompt activity, without exposing prompt content.

{% hint style="warning" %}
**Your data can only be retrieved, never modified.**

Once connected, your data is securely stored, and access is restricted to retrieving configurations and metadata only. Authentication methods ensure secure delegation of permissions while maintaining data integrity.
{% endhint %}

## Set up Claude Code data source integration with Sola <a href="#set-up-wiz-data-source-integration-with-sola" id="set-up-wiz-data-source-integration-with-sola"></a>

{% columns %}
{% column width="66.66666666666666%" %}
Go to ***Integrations*** > [***Data Sources***](https://app.sola.security/integrations/data-sources) > click ***New data source*** > select ***Claude Code***.

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="33.33333333333334%" %} <a href="https://app.sola.security/integrations/data-sources?integration=CLAUDE_CODE" class="button primary">Set up Claude Code -></a>
{% endcolumn %}
{% endcolumns %}

To connect Claude Code, you'll need access to the machine or MDM system where Claude Code is deployed.

{% tabs %}
{% tab title="Setup script" %}
This method uses a setup script to install and configure the Sola plugin in your Claude Code environment. Run the script manually on a single machine, or deploy it org-wide using your MDM system.

Creating the connection in the first step in the wizard initializes the incoming data endpoint and creates the integration. To complete the connection you must run the setup script manually or using your MDM system. The script adds Sola to the Claude Code marketplace, installs the plugin, and configures it to work with your integration.

Once the script runs, data will start streaming into the `tools`, `sessions`, and `user_prompts` tables, and you'll see it reflected in your integration's tables. Until the script runs, the integration remains incomplete and these tables stay empty.
{% endtab %}
{% endtabs %}

{% hint style="info" %}
**Data freshness**

Engagement data reflects activity up to 3 days prior. This applies to the Usage & Activity, Organization, and Skills, Connectors & Projects tables.
{% endhint %}

***

## FAQs

### What is the difference between the Claude data sources?

Sola offers three Anthropic integrations:

* [Claude Console](/integrations/data-sources/claude-console): for API platform customers (Build, Scale, or Team).
* [Claude Enterprise](/integrations/data-sources/claude-enterprise): for seat-based claude.ai plans, with compliance and activity data for eDiscovery and DLP.
* [Claude Enterprise Analytics](/integrations/data-sources/claude-enterprise-analytics): for seat-based claude.ai plans, with usage, adoption, and cost analytics.
* [Claude Code](/integrations/data-sources/claude-code): for organizations using Claude Code as an AI coding agent, with visibility into developer sessions, tool calls, and prompts.

Use Console if you connect to Anthropic through the API platform. If you're on a seat-based claude.ai plan, use the Claude Enterprise integrations; you can connect both.


# NetSuite

Connect Sola and NetSuite to get security insights

The NetSuite integration connects data from your NetSuite account to your Sola workspace, making it easy to search and find answers to your specific use cases.

{% embed url="<https://youtu.be/fFQR7GCsOsw>" %}

## Overview <a href="#overview" id="overview"></a>

The NetSuite integration gives you a complete view of your NetSuite environment, allowing you to monitor identity and access risks.

With the NetSuite integration, you can:

* Gain full visibility into user accounts, roles, and permission assignments.
* Monitor access tokens, identify over-privileged configurations, and detect stale or unused tokens.
* Track login activity and detect anomalous access patterns.
* Support least privilege enforcement and security compliance monitoring.

{% hint style="warning" %}
**Your data can only be retrieved, never modified.**

Once connected, your data is securely stored, and access is restricted to retrieving configurations and metadata only. Authentication methods ensure secure delegation of permissions while maintaining data integrity.
{% endhint %}

## Set up NetSuite data source integration with Sola <a href="#set-up-wiz-data-source-integration-with-sola" id="set-up-wiz-data-source-integration-with-sola"></a>

{% columns %}
{% column width="66.66666666666666%" %}
Go to ***Integrations*** > [***Data Sources***](https://app.sola.security/integrations/data-sources) > click ***New data source*** > select ***NetSuite***.

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="33.33333333333334%" %} <a href="https://app.sola.security/integrations/data-sources?integration=netsuite" class="button primary">Set up NetSuite -></a>
{% endcolumn %}
{% endcolumns %}

To connect NetSuite, you'll need a NetSuite account with **Administrator** access.

{% tabs %}
{% tab title="Token-Based Authentication (TBA)" %}
This method uses NetSuite's Token-Based Authentication to securely grant Sola read-only access to your NetSuite data.
{% endtab %}
{% endtabs %}

*Follow the* [*step-by-step guide below*](#how-do-i-set-up-a-netsuite-data-source-using-token-based-authentication) *to complete the setup.*

<details>

<summary><strong>How do I set up a NetSuite data source using Token-Based Authentication?</strong></summary>

Complete the following steps to set up and configure your NetSuite account and connect it to Sola.

{% hint style="info" %}
Setup requires creating an integration record, configuring a role and permissions, assigning a user, and generating an access token in your NetSuite account. Follow the guided steps in this wizard to connect.
{% endhint %}

#### 1. Get your Account ID

* Log in to your NetSuite account and go to ***Setup*** > ***Company*** > ***Company Information***, and copy your **Account ID**.
* You can also find it in your NetSuite URL: https\://\<account\_id>.app.netsuite.com
* Paste the **Account ID** into the Sola wizard.

#### **2. Enable required features**

* Go to ***Setup*** > ***Company*** > ***Enable Features*** and select the **SuiteCloud** tab.
* Under **Manage Authentication**, enable **Token-Based Authentication**.
* Under **SuiteTalk (Web Services)**, enable **REST Web Services**.
* Save the changes.

#### **3. Create an integration record**

* Go to ***Setup*** > ***Integration*** > ***Manage Integrations*** > ***New***.
* In the **Name** field, enter a name for the integration (e.g. sola-api-integration).
* Make sure **State** is set to Enabled.
* Under **Authentication**, enable **Token-Based Authentication** only.
* Save the changes.
* Copy your **Consumer Key** and **Consumer Secret**.\
  ***Important***: *These values are shown only once and cannot be retrieved later.*
* Paste the **Consumer Key** and **Consumer Secret** into the Sola wizard.

#### **4. Create a role with the required permissions**

* Go to **Setup > Users/Roles > Manage Roles > New**.
* In the **Name** field, enter a name for the role (we recommend `Sola API Role`).
* Under **Subsidiary Restrictions**, select **All**.
* In the **Permissions** tab, manually add the following permissions:
  * **Reports** - SuiteAnalytics Workbook
  * **Lists** - Employee Record (View), Employees (View)
  * **Setup** - Access Token Management, Bulk Manage Roles, Integration Application, REST Web Services, User Access Tokens, View Login Audit Trail
* Save the role.

#### **5. Assign the role to a user**

* Go to ***Setup*** > ***Users/Roles*** > ***Manage Users***.
* Select an existing user or create a new one. We recommend using a dedicated account such as `integrations@{your company domain}`.
* In the **Name** column, click the name of the user you want to give access to the **Sola API Role**.
* Click **Edit** under the user's name.
* At the bottom of the page, click the **Access** tab.
* Select the **Sola API Role** you created in Step 4 from the roles dropdown.
* Save the changes.

{% hint style="info" %}
If you need to create a new integration user:

* Go to ***Lists*** > ***Employees*** > ***Employees*** > ***New***.
* Enter a name (e.g. Integration User) and a unique email address.
* Select the appropriate Subsidiary (e.g. top-level parent subsidiary).&#x20;
* In the Access subtab, check the Give Access box.&#x20;
* Assign the Sola API Role you created in Step 4.&#x20;
* Set a temporary password, and optionally check Require Password Change on Next Login (for API-only users with tokens, this is less relevant).
* Click Save.
  {% endhint %}

#### **6. Create an access token**

* Go to ***Setup*** > ***Users/Roles*** > ***Access Tokens*** > ***New***.
* Select the **Application Name** you created in Step 3 (e.g. `sola-api-integration`).
* In the User section, select the User you assigned in Step 5.
* Select the Role you created in Step 4 (Sola API Role).
* In the Token Name field, enter a name for the token (we recommend Sola Integration Token).
* Save the changes.
* Copy the **Token ID** and **Token Secret**.\
  ***Important***: *These values are shown only once and cannot be retrieved later.*
* Paste the **Token ID** and **Token Secret** into the Sola wizard.
* Click **Test Connection** in the Sola wizard.

</details>


# Semgrep

Connect Sola and Semgrep to get security insights

## Overview <a href="#overview" id="overview"></a>

The Semgrep integration connects data from your Semgrep account to your Sola workspace, making it easy to search and find answers to your specific use cases.

With the Semgrep integration, you can:

* Gain visibility into code security findings from SAST scans and supply chain vulnerabilities, including severity, triage state, and CWE/OWASP classifications.
* Track exposed secrets and credentials found in code, including secret type, validation state, and source location.
* Review policy configuration and rule enforcement modes across your Semgrep deployment.
* Analyze scan history and third-party dependency inventory across your repositories.

{% hint style="warning" %}
**Your data can only be retrieved, never modified.**

Once connected, your data is securely stored, and access is restricted to retrieving configurations and metadata only. Authentication methods ensure secure delegation of permissions while maintaining data integrity.
{% endhint %}

## Set up Semgrep data source integration with Sola <a href="#set-up-wiz-data-source-integration-with-sola" id="set-up-wiz-data-source-integration-with-sola"></a>

{% columns %}
{% column width="66.66666666666666%" %}
Go to ***Integrations*** > [***Data Sources***](https://app.sola.security/integrations/data-sources) > click ***New data source*** > select ***Semgrep***.

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="33.33333333333334%" %} <a href="https://app.sola.security/integrations/data-sources?integration=semgrep" class="button primary">Set up Semgrep -></a>
{% endcolumn %}
{% endcolumns %}

To connect Semgrep, you'll need a Semgrep account with admin permissions.

{% tabs %}
{% tab title="API Token" %}
This method uses a Semgrep API token to securely grant Sola read-only access to your Semgrep organization data.
{% endtab %}
{% endtabs %}


# Google Sheets

Connect Sola and Google Sheets to get security insights

## Overview <a href="#overview" id="overview"></a>

The Google Sheets integration allows you to bring any spreadsheet data into Sola in real time.

Connect any Google Sheet to Sola and query your data directly, from user access records and asset inventories to compliance trackers, security context and investigation, and more.

{% hint style="info" %}
Google Sheet names are currently supported in English only. Support for additional languages is not yet available. Data in your sheets can be in any language.
{% endhint %}

{% hint style="warning" %}
**Your data can only be retrieved, never modified.**

Once connected, your data is securely stored, and access is restricted to retrieving configurations and metadata only. Authentication methods ensure secure delegation of permissions while maintaining data integrity.
{% endhint %}

## Set up Google Sheets data source integration with Sola <a href="#set-up-wiz-data-source-integration-with-sola" id="set-up-wiz-data-source-integration-with-sola"></a>

{% columns %}
{% column width="66.66666666666666%" %}
Go to ***Integrations*** > [***Data Sources***](https://app.sola.security/integrations/data-sources) > click ***New data source*** > select ***Google Sheets***.

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="33.33333333333334%" %} <a href="https://app.sola.security/integrations/data-sources?integration=google_sheets" class="button primary">Set up Google Sheets -></a>
{% endcolumn %}
{% endcolumns %}

To connect Google Sheets, you'll need a Google account with access to the spreadsheet you want to connect.

{% tabs %}
{% tab title="Google OAuth" %}
This method uses Google OAuth to securely grant Sola read-only access to your Google Drive.

{% hint style="info" %}
**About Google Drive permissions**\
Sola uses **read-only access** and never edits, creates, or deletes anything in your Google Drive.\
When connecting, Google's consent screen shows edit, create, and delete access. This is the `drive.file` scope, the least privileged scope Google makes available for this integration.

Permissions are granted from the file picker in the Sola wizard. **Sola can only access the specific file you select**. Files you do not pick are never accessible, even if they are in the same folder or Drive.
{% endhint %}
{% endtab %}
{% endtabs %}


# Sentinel Data Lake

Connect Sola and Sentinel Data Lake to get security insights

## Overview <a href="#overview" id="overview"></a>

The Sentinel Data Lake integration allows you to connect Microsoft Sentinel, Defender, and Entra as a real-time security data stream and get continuous, context-aware insights for detection, investigation, and response.

With the Sentinel Data Lake integration, you can:

* Connect Microsoft Sentinel security events as a real-time data stream for continuous analysis and correlation.
* Correlate Sentinel security events with data across your cloud, identity, and SaaS environment.
* Investigate security events in real time with Sola's AI-powered reasoning.
* Support detection, investigation, and response with live security data from your Microsoft environment.

{% hint style="warning" %}
**Your data can only be retrieved, never modified.**

Once connected, your data is securely stored, and access is restricted to retrieving configurations and metadata only. Authentication methods ensure secure delegation of permissions while maintaining data integrity.
{% endhint %}

## Set up Google Sheets data source integration with Sola <a href="#set-up-wiz-data-source-integration-with-sola" id="set-up-wiz-data-source-integration-with-sola"></a>

{% columns %}
{% column width="58.333333333333336%" %}
Go to ***Integrations*** > [***Data Sources***](https://app.sola.security/integrations/data-sources) > click ***New data source*** > select ***Sentinel Data Lake***.

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="41.666666666666664%" %} <a href="https://app.sola.security/integrations/data-sources?integration=sentinel_data_lake" class="button primary">Set up Sentinel Data Lake -></a>
{% endcolumn %}
{% endcolumns %}

To connect connect Sentinel Data Lake, you'll need an Azure user with:

* **Owner** or **User Access Administrator** role on the subscription, and
* **Application Administrator** or **Global Administrator** role in Azure AD.

You'll also need [**Azure Cloud Shell**](https://learn.microsoft.com/en-us/azure/cloud-shell/get-started) configured on your account.

{% tabs %}
{% tab title="Azure Cloud Shell" %}
This method uses Azure Cloud Shell to create an Azure Service Principal with read-only roles on your Sentinel workspace and output the credentials needed to complete the connection.
{% endtab %}
{% endtabs %}


# Snowflake

Connect Sola and Snowflake to get security insights

## Overview <a href="#overview" id="overview"></a>

The Snowflake integration allows you to query and analyze data directly from your warehouse in real time. Turn live data into easy to use natural language security investigations and context.

With the Snowflake integration, you can:

* Query and analyze your Snowflake data directly in Sola in real time, with no scheduled syncs or data exports.
* Get contextual insights based on live data to support faster investigation and decision-making.
* Correlate Snowflake data with activity across your cloud, identity, and SaaS environment.
* Ask natural language questions about your Snowflake data directly in Sola.

{% hint style="warning" %}
**Your data can only be retrieved, never modified.**

Once connected, your data is securely stored, and access is restricted to retrieving configurations and metadata only. Authentication methods ensure secure delegation of permissions while maintaining data integrity.
{% endhint %}

## Set up Google Sheets data source integration with Sola <a href="#set-up-wiz-data-source-integration-with-sola" id="set-up-wiz-data-source-integration-with-sola"></a>

{% columns %}
{% column width="66.66666666666666%" %}
Go to ***Integrations*** > [***Data Sources***](https://app.sola.security/integrations/data-sources) > click ***New data source*** > select ***Snowflake***.

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="33.33333333333334%" %} <a href="https://app.sola.security/integrations/data-sources?integration=snowflake" class="button primary">Set up Snowflake -></a>
{% endcolumn %}
{% endcolumns %}

To connect Snowflake, you'll need **SECURITYADMIN** privileges in your Snowflake account.

{% tabs %}
{% tab title="Workload Identity Federation" %}
This method uses AWS Workload Identity Federation to authenticate Sola to your Snowflake account without storing credentials. Recommended for publicly accessible Snowflake accounts.

{% hint style="info" %}
This method uses a script to create a role that has access to all tables and all future tables. To limit access, manage role permissions directly in the [Snowflake UI](https://docs.snowflake.com/en/user-guide/tutorials/users-and-roles-tutorial#prerequisites), or modify the script to specific schemas or tables before running. For example:

`GRANT USAGE ON SCHEMA my_database.my_schema TO ROLE SOLA_READ_ROLE;`

`GRANT SELECT ON TABLE my_database.my_schema.my_table TO ROLE SOLA_READ_ROLE;`
{% endhint %}
{% endtab %}
{% endtabs %}


# Connectors

Connect Sola to external services and gain real time actionability

A connector is an integration that allows Sola to interact with external services in real time to perform actions, directly through in-chat Sola AI conversations.

Connectors are used to:

* Share findings during analysis and investigation
* Support remediation and incident response by escalating issues directly to the right stakeholders (Sola users or not)
* Offload insights to relevant channels in your organization

{% hint style="info" %}
Learn more about [data privacy](https://trust.sola.security/).
{% endhint %}

## Available connector integrations

<table data-view="cards"><thead><tr><th></th><th data-hidden data-card-cover data-type="image">Cover image</th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td>Slack</td><td><a href="/files/jZtYi2lDDQbNaiJl5PJG">/files/jZtYi2lDDQbNaiJl5PJG</a></td><td><a href="/pages/fIwxgtXg4EozEmPAGIGS">/pages/fIwxgtXg4EozEmPAGIGS</a></td></tr><tr><td>Jira</td><td><a href="/files/WGWOW30uWq0Wq3KocKjN">/files/WGWOW30uWq0Wq3KocKjN</a></td><td><a href="/pages/LKkeO7edWaVWqgfz06x2">/pages/LKkeO7edWaVWqgfz06x2</a></td></tr><tr><td>AbuseIPDB</td><td><a href="/files/2w9Nzv6XujUavofQgxuX">/files/2w9Nzv6XujUavofQgxuX</a></td><td><a href="/pages/mJ1QtjHZ1PaDdL5tkouW">/pages/mJ1QtjHZ1PaDdL5tkouW</a></td></tr><tr><td>Shodan</td><td><a href="/files/4laPKSGC15XlsIJezlQD">/files/4laPKSGC15XlsIJezlQD</a></td><td><a href="/pages/PSAgIvtl7ySrVRbQJFiX">/pages/PSAgIvtl7ySrVRbQJFiX</a></td></tr><tr><td><em>New connectors on the way</em></td><td><a href="/files/aYGup9XDzJlzJUK2Q2pF">/files/aYGup9XDzJlzJUK2Q2pF</a></td><td></td></tr></tbody></table>

## Triggering connectors

After adding a connector to your workspace, you can add it to projects.

Connectors are automatically triggered within the Sola AI chat to:

* Share findings, insights, and results with teammates via Slack.
* Create tickets and epics in Jira (coming soon).

{% hint style="info" %}
**Sola AI prompt tip** ![](/files/DESMoC6l1Gr9uaynao5N)

Connectors enable these actions instantly during conversations.

For example, ask Sola AI to:

***“Send the top 3 most critical issues to my SecOps Slack channel, together with remediation steps”***.
{% endhint %}

## Permissions and actions

Connectors require permission to access, read, or write data in external systems.

There are three levels of guardrails, **workspace**, **project**, and **chat**.

1. **Workspace level**\
   Configure connector permissions and scopes when adding the connector to your workspace.
   * Sola App comes pre-configured with required permissions.
   * Custom app includes a set of recommended permissions\
     **Note:** Not applying the recommended permissions may limit functionality or prevent certain actions from working as expected.
2. **Project level**\
   Control which projects can use a given connector. Projects must be explicitly connected.
3. **Chat level**\
   When an in-chat conversation triggers an action that needs external access, Sola will prompt for one of the following permissions:
   * Deny
   * Allow once
   * Allow for this chat

***

## FAQs

### What’s the difference between connectors and data sources?

Data sources bring in and save large datasets into Sola for querying and analysis.

Connectors are used to enrich, validate, or act on data in real time.

### Can I use connectors without a data source?

Yes. Connectors are used to send information from Sola to external services, this does not depend on a data source being connected.

### Do connectors affect my data quota?

Connectors do not sync or store structured records and do not count toward your data source records quota. However, they can indirectly affect other limits such as your Sola AI requests per week. For more information, [see Sola pricing](https://sola.security/pricing/).


# Slack

Connect Sola and Slack to get security insights

## Overview

The Slack integration brings Sola AI directly into Slack, enabling it to provide insights, escalate issues, and participate in security conversations.

The Slack integration allows you to join public channels, read messages, and send messages to help teams stay informed and take action in context.

With the Slack integration, you can:

* Enable real-time collaboration and assistance directly from Sola inside Slack.
* Receive security alerts and insights without switching tools.
* Keep teams aligned on security actions, investigations, and decisions.

{% hint style="warning" %}
**Sola can only perform the actions you approve.**

Connectors require explicit permission to access or act on external systems. Permissions are securely managed at the workspace, project, and chat level to ensure control at every step.
{% endhint %}

## Set up Slack connector integration with Sola

{% columns %}
{% column width="75%" %}
Go to ***Integrations*** > [***Connectors***](https://app.sola.security/integrations/connectors) > click ***New connector*** > select ***Slack***.

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="25%" %} <a href="https://app.sola.security/integrations/connectors?connector=slack" class="button primary">Set up Slack -></a>

{% endcolumn %}
{% endcolumns %}

### Connect Slack to Sola

To connect Slack, you’ll need a Slack account with a full member Slack role or higher.

{% tabs %}
{% tab title="Slack App" %}
Recommended for secure, production use.\
This method uses a Slack App to grant Sola scoped, permission-based access to your Slack workspace. It reduces the risks associated with user tokens and long-lived credentials by enforcing granular permission scopes and using Slack’s OAuth-based authentication.

* Slack App (Recommended)\
  Install Sola’s Slack App to securely and easily grant access to your organization’s Slack workspace.
* Custom Slack App\
  Create and install your own Slack App for full control over permissions and configuration\
  (see how-to guide below)

*Not sure which method to choose?* We recommend starting with the Slack App for the fastest and most reliable setup.
{% endtab %}
{% endtabs %}

<details>

<summary>How do I set up a Slack connector using custom Slack App? </summary>

Complete the following steps to set up and configure your Slack App to integrate Sola with Slack.

{% hint style="info" %}
[Learn more about creating Slack Apps](https://api.slack.com/quickstart).
{% endhint %}

#### 1. Create your Slack App

* In your Slack [apps page](https://api.slack.com/apps), click ***Create New App***, and select ***From scratch***.
* Set an ***App Name*** (Sola Integration), select a workspace, and click ***Create App***.

#### 2. Configure permissions

* Go to ***OAuth & Permissions*** > ***Scopes*** > ***Bot Token Scopes***, select ***Add an OAuth Scope***.
* Add the following required scopes:
  * `assistant:write` - Allow Sola to act as an app agent.
  * `channels:history` - View messages and other content in public channels that Sola has been added to.
  * `channels:join` - Join public channels in a workspace.
  * `channels:read` - View basic information about public channels in a workspace.
  * `chat:write` - Send messages as @Sola App.
  * `emoji:read` - View custom emoji in a workspace.
  * `files:write` - Upload, edit, and delete files as Sola.
  * `groups:read` - View basic information about private channels that Sola has been added to.
  * `im:read` - View basic information about direct messages that Sola Security has been added to.
  * `reactions:read` - View emoji reactions and their associated content in channels and conversations that Sola Security has been added to.
  * `reactions:write` - Add and edit emoji reactions.
  * `remote_files:write` - Add, edit, and delete remote files on a user's behalf.
  * `users.profile:read` - View profile details about people in a workspace.
  * `users:read` - View people in a workspace.
  * `users:read.email` - View email addresses of people in a workspace.
  * `users:write` - Set presence for Sola.

#### 3. Install the Slack App

* Go to ***Install App***, click ***Install to Workspace***, and copy your ***Bot User OAuth Token***.

#### 4. Paste the *Bot User OAuth Token* in the Sola wizard.

#### 5. Click *Test Connection* to validate the details and continue.

</details>


# Jira

Connect Sola to Jira to expedite remediation

## Overview

The Jira integration brings Sola AI into your Jira projects allowing you to create, update, and track Jira issues directly from in-chat conversations.&#x20;

The Jira integration helps streamline remediation management by turning your security findings into actionable work, keeping teams aligned and responsive.

With the Jira integration, you can:

* Turn security findings into Jira epics, tasks, or stories directly from Sola AI conversations.
* Route issues to the right stakeholders with relevant context for resolution.
* Monitor issue status, transitions, and comments, from detection to closure.

{% hint style="warning" %}
**Sola can only perform the actions you approve.**

Connectors require explicit permission to access or act on external systems. Permissions are securely managed at the workspace, project, and chat level to ensure control at every step.
{% endhint %}

## Set up Jira connector integration with Sola

{% columns %}
{% column width="75%" %}
Go to ***Integrations*** > [***Connectors***](https://app.sola.security/integrations/connectors) > click ***New connector*** > select ***Jira***.

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="25%" %} <a href="https://app.sola.security/integrations/connectors?connector=jira" class="button primary">Set up Jira -></a>

{% endcolumn %}
{% endcolumns %}

### Connect Jira to Sola

{% hint style="warning" %}
To connect Jira, it is recommended to use a **dedicated organization user account**, for the Sola connector, and not a personal account. For example, *<sola.jira.user@company.com>*.
{% endhint %}

{% tabs %}
{% tab title="Jira App" %}
Recommended for secure, production use.\
This method uses a Jira App to grant Sola scoped, permission-based access to your Jira account.

* Jira App (Recommended)\
  Install Sola’s Jira App to securely and easily grant access to your organization’s Jira account.
  {% endtab %}

{% tab title="API Token" %}
This method uses a Jira API token to securely grant Sola access to your Jira account.

The token includes the following classic scopes:

* `read:jira-user`
* `read:jira-work`
* `write:jira-work`
  {% endtab %}
  {% endtabs %}

## Available actions with the Jira connector

* **Create issue** - Create a new Jira issue (Task, Bug, Story, Epic, etc.) with summary, description, assignee, components, and custom fields.
* **Update issue** - Update an existing Jira issue summary, description, priority, assignee, or labels.
* **Get issue** - Retrieve detailed information about a specific Jira issue by its key.
* **Get projects** - List all accessible Jira projects.
* **Get issue types** - List available issue types (Task, Bug, Story, Epic, etc.) for a specific project.
* **Add comment** - Add a comment to an existing Jira issue.
* **Get comments** - Retrieve comments for a specific Jira issue.
* **Transition issue** - Change the status of a Jira issue (e.g., move to In Progress, Done, Closed) using a transition ID.
* **Get transitions** - List all possible status transitions for a Jira issue.
* **Search fields** - Search for available fields in the Jira instance (e.g., custom fields).
* **Create issue link** - Link two Jira issues together (e.g., “relates to”, “blocks”, etc.).
* **Link to epic** - Link an issue to an Epic.
* **Batch create issues** - Create multiple Jira issues in a single batch operation.
* **Get link types** - List all available Jira issue link types.
* **Get project issues** - List issues for a specific Jira project.
* **Search issues** - Search for Jira issues using JQL (Jira Query Language).
* **Get user profile** - Retrieve a Jira user’s profile by identifier (accountId, username, or email).


# AbuseIPDB

Connect Sola and AbuseIPDB to investigate suspicious IP addresses

## Overview

The AbuseIPDB integration brings IP reputation data directly into Sola AI, enabling security teams to enrich investigations with real-world abuse reports, confidence scores, and blacklist data.

With the AbuseIPDB integration, you can:

* Check IP addresses for abuse confidence scores, country, ISP, and report history during active investigations.
* Report malicious IP addresses with relevant abuse categories directly from Sola.
* Query the AbuseIPDB blacklist to surface high-confidence malicious IPs based on your specific criteria.

{% hint style="warning" %}
**Sola can only perform the actions you approve.**

Connectors require explicit permission to access or act on external systems. Permissions are securely managed at the workspace, project, and chat level to ensure control at every step.
{% endhint %}

## Set up AbuseIPDB connector integration with Sola

{% columns %}
{% column width="66.66666666666666%" %}
Go to ***Integrations*** > [***Connectors***](https://app.sola.security/integrations/connectors) > click ***New connector*** > select ***AbuseIPDB***.

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="33.33333333333334%" %} <a href="https://app.sola.security/integrations/connectors?connector=abuseipdb" class="button primary">Set up AbuseIPDB -></a>

{% endcolumn %}
{% endcolumns %}

### Connect AbuseIPDB to Sola

To connect AbuseIPDB, you'll need an [AbuseIPDB account](https://www.abuseipdb.com/) and an API key.

{% tabs %}
{% tab title="API Token" %}
This method uses an AbuseIPDB API token to grant Sola access to your AbuseIPDB account.
{% endtab %}
{% endtabs %}

<details>

<summary>How do I set up an AbuseIPDB connector using an API key? </summary>

To connect, you'll need an [AbuseIPDB account](https://www.abuseipdb.com/).

1. Create your API key
   * In your AbuseIPDB account, go to ***My API*** and select **Keys**.
   * Enter a name for your key (e.g. "Sola Integration") and click **Create**.
   * Copy the generated API key.
2. Paste the API key in the Sola wizard.
3. Click *Test Connection* to validate the details and continue.

</details>

## Available actions with the AbuseIPDB connector

* **Check IP address** - Query the abuse confidence score, country, ISP, and report history for a given IP address.
* **Report IP address** - Submit an abuse report for a suspicious IP address with one or more abuse categories.
* **Get blacklist** - Query the AbuseIPDB blacklist for IP addresses reported for abuse, filtered by confidence score or report count.

## Example prompts

During investigations, you can use the AbuseIPDB connector to:

{% code overflow="wrap" %}

```
Check the reputation of <IP address> using AbuseIPDB
```

{% endcode %}

{% code overflow="wrap" %}

```
Is <IP address> malicious? Check it on AbuseIPDB
```

{% endcode %}

{% code overflow="wrap" %}

```
Get the AbuseIPDB blacklist of the top 10 most reported IPs with a confidence score above 95%
```

{% endcode %}

{% code overflow="wrap" %}

```
Report <IP address> to AbuseIPDB for SSH brute force attempts
```

{% endcode %}

{% code overflow="wrap" %}

```
Check <IP address> on AbuseIPDB and tell me if it's safe to allow traffic from it
```

{% endcode %}


# Shodan

Connect Sola and Shodan to monitor your attack surface and enrich security investigations

## Overview

The Shodan connector brings internet exposure intelligence into Sola AI, enabling security teams to identify vulnerable or misconfigured assets, monitor their attack surface, and track adversary infrastructure. Use it to enrich investigations by looking up IPs, searching for exposed devices, querying CVE details, and performing DNS lookups directly from Sola.

With the Shodan integration, you can:

* Look up internet-facing assets by IP address, including open ports, running services, SSL details, and geolocation.
* Search Shodan's database for internet-connected devices using advanced query filters.
* Query detailed vulnerability intelligence, including CVE severity scores, EPSS ratings, and affected products.
* Perform DNS and reverse DNS lookups for domains and IP addresses during active investigations.

{% hint style="warning" %}
**Sola can only perform the actions you approve.**

Connectors require explicit permission to access or act on external systems. Permissions are securely managed at the workspace, project, and chat level to ensure control at every step.
{% endhint %}

## Set up Shodan connector integration with Sola

{% columns %}
{% column width="66.66666666666666%" %}
Go to ***Integrations*** > [***Connectors***](https://app.sola.security/integrations/connectors) > click ***New connector*** > select ***Shodan***.

*The Sola wizard will take you through the steps.*
{% endcolumn %}

{% column width="33.33333333333334%" %} <a href="https://app.sola.security/integrations/connectors?connector=shodan" class="button primary">Set up Shodan -></a>

{% endcolumn %}
{% endcolumns %}

### Connect Shodan to Sola

To connect Shodan, you'll need a [Shodan account](https://account.shodan.io/) and an API key.

{% tabs %}
{% tab title="API Token" %}
This method uses a Shodan API key to grant Sola access to your Shodan account.
{% endtab %}
{% endtabs %}

<details>

<summary>How do I set up a Shodan connector using an API key?</summary>

To connect, you'll need a [Shodan account](https://account.shodan.io/).

1. Get your API key
   * In your Shodan account, go to ***Account*** > ***API Key***.
   * Copy your **API key**.
2. Paste the API key in the Sola wizard.
3. Click **Test Connection** to validate the details and continue.

</details>

## Available actions with the Shodan connector

* **IP Lookup** - Look up an IP address including open ports, services, banners, and geolocation.
* **Device Search** - Search Shodan's database of internet-connected devices.
* **DNS Lookup** - Resolve domain names to IPs and perform reverse DNS lookups.
* **CVE Lookup** - Query detailed vulnerability information from Shodan's CVEDB.
* **CPE Lookup** - Search for CPE entries by product name.
* **CVEs by Product** - Search vulnerabilities affecting specific products or CPEs.

## Example prompts

During investigations, you can use the AbuseIPDB connector to:

{% code overflow="wrap" %}

```
Look up <IP address> on Shodan and tell me what ports and services are exposed
```

{% endcode %}

{% code overflow="wrap" %}

```
Search Shodan for devices running Apache 2.4 in our IP range
```

{% endcode %}

{% code overflow="wrap" %}

```
Look up <CVE ID> on Shodan and tell me its severity and affected products
```

{% endcode %}

{% code overflow="wrap" %}

```
Check what hostnames are associated with <IP address>
```

{% endcode %}

{% code overflow="wrap" %}

```
What does Shodan know about <domain name>? Resolve it and check the exposure
```

{% endcode %}


# Prompt Library

Curated use cases and prompts for building with Sola AI

Every chat, project, canvas, and investigation in Sola begins with a prompt. The right prompt turns questions into results and unlocks what Sola can do.

The Prompt Library helps you discover the most relevant **security use cases**, with curated examples that you can use to explore, investigate, or build with [Sola AI](/getting-started/sola-ai).

Prompts are organized by category, to make it easy to find what matters most to you.

<table data-view="cards"><thead><tr><th align="center"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td align="center"><strong>Cloud Security Posture (CSPM)</strong></td><td><a href="/pages/YGfptHhMXNuVSNZcj9Id">/pages/YGfptHhMXNuVSNZcj9Id</a></td></tr><tr><td align="center"><strong>Identity Security and Access Analysis (IAM)</strong></td><td><a href="/pages/bmxz83pkrfoYBF5TUhFs">/pages/bmxz83pkrfoYBF5TUhFs</a></td></tr><tr><td align="center"><strong>DLP and File Exposure</strong></td><td><a href="/pages/zhDtv1fJlhRf0Bw4psWX">/pages/zhDtv1fJlhRf0Bw4psWX</a></td></tr><tr><td align="center"><strong>SaaS Posture Management</strong></td><td><a href="/pages/6oTbXebm1dml8wBJfRWH">/pages/6oTbXebm1dml8wBJfRWH</a></td></tr><tr><td align="center"><strong>Incident Readiness and Backup Resilience</strong></td><td><a href="/pages/ZTXolox4hR9RPwsggtUf">/pages/ZTXolox4hR9RPwsggtUf</a></td></tr><tr><td align="center"><strong>CI/CD and Supply Chain Security</strong></td><td><a href="/pages/3sx8ikCEDDjeXJ4f3Yjc">/pages/3sx8ikCEDDjeXJ4f3Yjc</a></td></tr></tbody></table>

<p align="right"><img src="/files/u9RHZRvhr64TfNP6IjXP" alt=""> <strong>Learn more about</strong> <a href="https://sola.security/solutions/cross-domain-security/"><strong>cross-domain security</strong></a></p>

## How to use this library

Each category combines knowledge and ready-to-use prompts to help you explore what’s possible with Sola. It includes key security concepts, what they are, why they matter, and how Sola analyzes them, alongside prompt examples you can try in Sola AI.

**The Prompt Library is available directly from the Sola chat interface**. Click the *Prompt library* icon in the chat box to browse and use prompts.

<div><figure><img src="/files/Htva7lBToZ9XrCSROeHH" alt=""><figcaption></figcaption></figure> <figure><img src="/files/MLlMKRdCI1cJhQemb1Ho" alt=""><figcaption></figcaption></figure></div>

Use the prompts to explore specific questions or build parts of your own project.

{% hint style="success" %}
Combine prompts, projects, and data sources to expand your coverage and build end-to-end security solutions.
{% endhint %}

***The prompt library will continue to grow with more use cases.***


# Sola for Cloud Security

Prompts and use cases for Cloud Security Posture (CSPM)

Cloud environments are dynamic and complex, making continuous visibility essential.

Sola helps you monitor configurations, detect misconfigurations, and ensure alignment with cloud security best practices across [AWS](/integrations/data-sources/aws), [Azure](/integrations/data-sources/azure), and [GCP](/integrations/data-sources/gcp).

This page explains the key concepts behind **Cloud Security Posture Management (CSPM)**, what it is, why it matters, and how Sola helps you analyze it. It also includes [prompt examples](#prompt-examples) you can use directly in [Sola AI](/getting-started/sola-ai).

Get started with these below **ready-made Ask and Build prompts**, or the **Prompt library**, both available directly in the Sola chat interface.

<details>

<summary><img src="/files/DESMoC6l1Gr9uaynao5N" alt=""> <em><strong>Ask</strong>: Show me my cloud security risks</em></summary>

Copy this prompt into [Sola AI](https://app.sola.security/) to get started:

{% code overflow="wrap" %}

```
I want to understand the most critical security risks in my cloud environment. Guide me to identify which cloud provider I should connect first - such as AWS, Azure, or GCP - to quickly discover high-impact misconfigurations like public exposure, overprivileged identities, IAM posture, or missing encryption. If I already have a data source connected, ask me which one I should use. Guide me to the best next step to quickly experience Sola's value. Do this as an interactive conversation, guide me one step at a time, avoid long explanations upfront, and pause for my response.
```

{% endcode %}

</details>

<details>

<summary><img src="/files/DESMoC6l1Gr9uaynao5N" alt=""> <em><strong>Build</strong>: Build cloud security monitoring</em></summary>

Copy this prompt into [Sola AI](https://app.sola.security/) to get started:

{% code overflow="wrap" %}

```
I want to build an app that continuously monitors my cloud security posture. Guide me to identify which cloud provider I should connect first - such as AWS, Azure, or GCP - or if I already have one connected, ask me which to use. Then help me build queries to detect critical misconfigurations like public exposure, overprivileged identities, IAM posture, or missing encryption, create canvases to visualize risks over time, and set up alerts for new issues. Guide me to the best next step to quickly experience Sola's value. Do this as an interactive conversation, guide me one step at a time, avoid long explanations upfront, and pause for my response.
```

{% endcode %}

</details>

{% hint style="info" %}
![](/files/DESMoC6l1Gr9uaynao5N) Explore the cloud security [**prompt library examples**](#prompt-library-examples) and [**more prompt examples**](#prompt-examples) below.
{% endhint %}

## What is Cloud Security Posture Management (CSPM)?

CSPM is the practice of continuously monitoring and assessing your cloud infrastructure to detect risks, misconfigurations, and policy violations. Ensuring that your cloud accounts, services, and resources comply with security benchmarks like CIS, ISO, or SOC2.

In simple terms, CSPM helps answer the question:\
***“Is my cloud configured securely right now?”***

Insights are generated from your [connected data sources](/integrations/data-sources) to identify and remediate risks such as:

* Publicly exposed storage buckets or databases.
* Unencrypted or misconfigured resources.
* Excessive permissions or inactive identities.
* Missing or incomplete logging coverage.
* Non-compliance with established security policies.

## Why is CSPM important

Cloud misconfigurations are among the most common causes of data exposure.

Without continuous monitoring, even minor configuration errors can expose sensitive data, weaken access controls, or impact compliance.

CSPM ensures visibility, enforces security best practices, and reduces the risk of accidental exposure or policy drift across cloud environments.

## CSPM with Sola

Sola isn’t about replacing traditional CSPM solutions, it enables you to build one that fits your organization.

With Sola, you can build a tailored solution to:

* **Monitor** configuration drift, public exposure, and encryption status across AWS, GCP, and Azure.
* **Enforce** security and compliance standards such as CIS, ISO, and SOC2 through automated checks and alerts.
* **Visualize** posture changes and risk trends with dashboards and reports.
* **Automate** remediation workflows to handle recurring or critical misconfigurations.

Each of these components can be queried, visualized, and automated within your Sola projects, giving you full visibility and control over your cloud security posture.

***

## Prompt library examples

Browse and run these prompts directly from the Prompt library in the Sola chat interface.

<img src="/files/MLlMKRdCI1cJhQemb1Ho" alt="Prompt Library" data-size="original">

<details>

<summary><strong>Cloud Risk Summary</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
Summarize the top 20 risks across my cloud environment. Group by service (IAM, compute, storage, serverless, networking). Only include misconfigurations that are actively exploitable or publicly accessible, and rank them by potential blast radius.
```

{% endcode %}

</details>

<details>

<summary><strong>Publicly Exposed Resources</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
List all cloud assets accessible from the internet, storage buckets, API gateways, load balancers, and compute instances. For each, explain the potential impact and identify which identity or workload owns it.
```

{% endcode %}

</details>

<details>

<summary><strong>Identity-Aware Cloud Risk</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
Which cloud resources become high-risk because of who can reach them? Show IAM roles and users with overly permissive access, and map the paths they could use to escalate privileges or move laterally.
```

{% endcode %}

</details>

<details>

<summary><strong>Cloud Attack Path Discovery</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
Find attack paths in my cloud environment where a combination of misconfiguration, permissive IAM, and network exposure creates a real threat. Rank by exploitability and blast radius, and suggest a remediation priority order.
```

{% endcode %}

</details>

<details>

<summary><strong>Stale but Dangerous Resources</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
Identify cloud resources that haven’t been used in 60+ days but still carry open permissions or public exposure. Flag anything that poses ongoing risk despite being inactive.
```

{% endcode %}

</details>

<details>

<summary><strong>Executive Cloud Risk Summary</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
Give me a one-page summary of my cloud security posture: total risk count, top 3 critical findings, and a red/yellow/green status per cloud provider. Format for a CISO-level audience with no assumed technical background.
```

{% endcode %}

</details>

## More prompt examples

Explore the security risks and misconfigurations covered by CSPM for [AWS](/integrations/data-sources/aws).

1. [Identity and access management (IAM)](#id-1.-identity-and-access-management-iam)
2. [Network Security](#id-2.-network-security)
3. [Data protection (S3, RDS, EBS, EFS)](#id-3.-data-protection-s3-rds-ebs-efs)
4. [Compute and container security](#id-4.-compute-and-container-security)
5. [Logging, monitoring and governance](#id-5.-logging-monitoring-and-governance)
6. [Resilience and availability](#id-6.-resilience-and-availability)

<a href="https://app.sola.security/gallery/aws-security-posture-misconfigurations" class="button secondary">Download the template for the complete experience</a>

{% hint style="info" %}
*Copy any prompt into* [*Sola AI*](https://app.sola.security/) *to get started.*
{% endhint %}

🔴 Critical 🟠 High 🟡 Medium

### 1. Identity and access management (IAM)

Prevent misuse of privileges and unauthorized access.

<details>

<summary>🔴 <strong>Detect publicly accessible EC2 instances with admin roles</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
Find all EC2 instances with a public IP address that are attached to IAM roles with admin-level permissions.
```

{% endcode %}

| <p><em>What it checks:</em><br>Detects EC2 instances with public IPs and admin-level roles</p> | <p><em>Why it matters:</em><br>A compromised instance could grant full account access</p> |
| ---------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- |

</details>

<details>

<summary><strong>🔴 Identify Lambda functions with privileged execution roles</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
List all Lambda functions where the execution role has administrator or wildcard (‘*’) permissions.
```

{% endcode %}

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top"><em>What it checks:</em><br>Finds functions using excessive permissions</td><td valign="top"><em>Why it matters:</em><br>Reduces the blast radius of potential compromise</td></tr></tbody></table>

</details>

<details>

<summary>🟠 <strong>Ensure EC2 instances use IAM roles instead of static keys</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
Show EC2 instances not configured with an IAM role or still using hardcoded access keys.
```

{% endcode %}

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top"><em>What it checks:</em><br>Ensures instances are using IAM roles instead of static access keys</td><td valign="top"><em>Why it matters:</em><br>Prevents credential leakage</td></tr></tbody></table>

</details>

<details>

<summary>🟡 <strong>Verify IAM Access Analyzer is enabled in all active region</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
Check whether IAM Access Analyzer is enabled in all active AWS regions.
```

{% endcode %}

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top"><em>What it checks:</em><br>Validates that exposure detection is active</td><td valign="top"><em>Why it matters:</em><br>Identifies unintended cross-account access</td></tr></tbody></table>

</details>

### 2. Network Security

Limit public exposure and enforce segmentation.

<details>

<summary>🔴 <strong>Detect subnets that automatically assign public IPs</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
Find EC2 subnets that are configured to automatically assign public IP addresses to instances.
```

{% endcode %}

| <p><em>What it checks:</em><br>Flags subnets that expose instances to the internet</p> | <p><em>Why it matters:</em><br>Reduces attack surface</p> |
| -------------------------------------------------------------------------------------- | --------------------------------------------------------- |

</details>

<details>

<summary><strong>🔴 Identify security groups with unrestricted inbound access</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
List all security groups with rules allowing inbound traffic from 0.0.0.0/0 or ::/0, and show which ports are exposed.
```

{% endcode %}

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top"><em>What it checks:</em><br>Detects overly broad rules (e.g., 0.0.0.0/0)</td><td valign="top"><em>Why it matters:</em><br>Prevents unauthorized inbound connections</td></tr></tbody></table>

</details>

<details>

<summary><strong>🔴 Find resources with open administrative ports</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
Show all resources with SSH (port 22), RDP (port 3389), or other management ports open to the internet.
```

{% endcode %}

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top"><em>What it checks:</em><br>Scans for open management ports</td><td valign="top"><em>Why it matters:</em><br>Avoids brute-force and RCE attempts</td></tr></tbody></table>

</details>

<details>

<summary>🟠 <strong>Verify default VPC security groups restrict all traffic</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
Check whether the default security group in each VPC blocks all inbound and outbound traffic.
```

{% endcode %}

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top"><em>What it checks:</em><br>Ensures default networks are locked down</td><td valign="top"><em>Why it matters:</em><br>Reduces accidental exposure</td></tr></tbody></table>

</details>

#### 3. Data protection (S3, RDS, EBS, EFS)

<details>

<summary>🔴 <strong>Identify S3 buckets without Block Public Access enabled</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
List all S3 buckets that do not have Block Public Access settings enabled at the bucket or account level.
```

{% endcode %}

| <p><em>What it checks:</em><br>Detects public data exposure</p> | <p><em>Why it matters:</em><br>Common cause of cloud data leaks</p> |
| --------------------------------------------------------------- | ------------------------------------------------------------------- |

</details>

<details>

<summary><strong>🔴 Detect publicly shared snapshots</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
Find all EBS snapshots and RDS snapshots that are shared publicly or with untrusted AWS accounts.
```

{% endcode %}

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top"><em>What it checks:</em><br>Ensures backups are private</td><td valign="top"><em>Why it matters:</em><br>Prevents data theft from shared snapshots</td></tr></tbody></table>

</details>

<details>

<summary>🔴 <strong>Check if CloudTrail logs bucket is publicly accessible</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
Verify that the S3 bucket storing CloudTrail logs is not publicly accessible.
```

{% endcode %}

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top"><em>What it checks:</em><br>Protects audit logs from manipulation</td><td valign="top"><em>Why it matters:</em><br>Maintains integrity of forensic evidence</td></tr></tbody></table>

</details>

<details>

<summary>🟠 <strong>Verify encryption at rest is enabled for data stores</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
Check whether EBS volumes, RDS databases, and EFS file systems have encryption at rest enabled.
```

{% endcode %}

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top"><em>What it checks:</em><br>Verifies EBS, RDS, EFS encryption settings</td><td valign="top"><em>Why it matters:</em><br>Protects data from unauthorized physical access</td></tr></tbody></table>

</details>

<details>

<summary>🟡 <strong>Ensure S3 versioning and MFA delete are enabled</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
List S3 buckets without versioning enabled or MFA delete configured.
```

{% endcode %}

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top"><em>What it checks:</em><br>Guards against accidental or malicious deletion</td><td valign="top"><em>Why it matters:</em><br>Improves recoverability</td></tr></tbody></table>

</details>

#### 4. Compute and container security

<details>

<summary>🔴 <strong>Identify ECS containers running in privileged mode</strong></summary>

{% code title="Prompt" overflow="wrap" %}

```
Find all ECS task definitions where containers are configured to run as privileged or as root.
```

{% endcode %}

| <p><em>What it checks:</em><br>Prevents host-level compromise</p> | <p><em>Why it matters:</em><br>Reduces container escape risk</p> |
| ----------------------------------------------------------------- | ---------------------------------------------------------------- |

</details>

<details>

<summary><strong>🔴 Verify ECR image scanning is enabled</strong></summary>

{% code title="Prompt" overflow="wrap" %}

```
Check whether Amazon ECR repositories have image scanning enabled for vulnerability detection.
```

{% endcode %}

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top"><em>What it checks:</em><br>Ensures image scanning is active</td><td valign="top"><em>Why it matters:</em><br>Prevents deployment of vulnerable builds</td></tr></tbody></table>

</details>

<details>

<summary>🟠 <strong>Detect ECS tasks sharing host process namespace</strong></summary>

{% code title="Prompt" overflow="wrap" %}

```
List ECS task definitions that share the host's process namespace with containers.
```

{% endcode %}

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top"><em>What it checks:</em><br>Enforces container isolation</td><td valign="top"><em>Why it matters:</em><br>Avoids cross-process attacks</td></tr></tbody></table>

</details>

<details>

<summary>🟡 <strong>Identify Lambda functions using deprecated runtimes</strong></summary>

{% code title="Prompt" overflow="wrap" %}

```
List all Lambda functions that are running on deprecated or outdated runtime environments.
```

{% endcode %}

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top"><em>What it checks:</em><br>Checks for deprecated environments</td><td valign="top"><em>Why it matters:</em><br>Reduces CVE exposure</td></tr></tbody></table>

</details>

#### 5. Logging, monitoring and governance

<details>

<summary>🔴 <strong>Verify CloudTrail logs are encrypted and validated</strong></summary>

{% code title="Prompt" overflow="wrap" %}

```
Check whether CloudTrail logs are encrypted with KMS and have log file validation enabled.
```

{% endcode %}

| <p><em>What it checks:</em><br>Ensures log integrity</p> | <p><em>Why it matters:</em><br>Prevents tampering</p> |
| -------------------------------------------------------- | ----------------------------------------------------- |

</details>

<details>

<summary>🟠 <strong>Check if CloudTrail and AWS Config are enabled in all regions</strong></summary>

{% code title="Prompt" overflow="wrap" %}

```
Verify that CloudTrail and AWS Config are enabled and recording in all active AWS regions.
```

{% endcode %}

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top"><em>What it checks:</em><br>Confirms activity tracking coverage</td><td valign="top"><em>Why it matters:</em><br>Core to audits and investigations</td></tr></tbody></table>

</details>

<details>

<summary>🟡 <strong>Ensure VPC Flow Logs and Load Balancer logging are enabled</strong></summary>

{% code title="Prompt" overflow="wrap" %}

```
List VPCs without Flow Logs enabled and load balancers without access logging configured.
```

{% endcode %}

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top"><em>What it checks:</em><br>Tracks network traffic</td><td valign="top"><em>Why it matters:</em><br>Detects anomalies and intrusion attempts</td></tr></tbody></table>

</details>

#### 6. Resilience and availability

<details>

<summary>🟠 <strong>Verify backup recovery points are encrypted</strong></summary>

{% code title="Prompt" overflow="wrap" %}

```
Check whether AWS Backup recovery points are encrypted at rest.
```

{% endcode %}

| <p><em>What it checks:</em><br>Secures stored backups</p> | <p><em>Why it matters:</em><br>Protects backup data from unauthorized access or theft</p> |
| --------------------------------------------------------- | ----------------------------------------------------------------------------------------- |

</details>

<details>

<summary>🟡 <strong>Verify RDS clusters use multiple Availability Zones</strong></summary>

{% code title="Prompt" overflow="wrap" %}

```
Check whether RDS database clusters are configured for Multi-AZ deployment.
```

{% endcode %}

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top"><em>What it checks:</em><br>Checks for high availability configuration</td><td valign="top"><em>Why it matters:</em><br>Prevents single-AZ failures</td></tr></tbody></table>

</details>

<details>

<summary>🟡 <strong>Ensure load balancers span multiple Availability Zones</strong></summary>

{% code title="Prompt" overflow="wrap" %}

```
List all Application and Network Load Balancers that are not configured across multiple Availability Zones.
```

{% endcode %}

<table data-header-hidden><thead><tr><th valign="top"></th><th valign="top"></th></tr></thead><tbody><tr><td valign="top"><em>What it checks:</em><br>Ensures multi-zone redundancy</td><td valign="top"><em>Why it matters:</em><br>Improves uptime</td></tr></tbody></table>

</details>


# Sola for Identity Security

Prompts and use cases for Identity Security & Access Analysis

Identity risk is distributed across multiple platforms, making cross-system visibility essential.

Sola connects identity data across your identity providers, cloud platforms, and SaaS applications to surface access risks, credential misuse, and privilege issues that no single tool sees on its own.

This page explains the key concepts behind **Identity Security and Access Analysis**, what it is, why it matters, and how Sola helps you investigate it.

Get started with these below **ready-made Ask and Build prompts**, or the **Prompt library**, both available directly in the Sola chat interface.

<details>

<summary><img src="/files/DESMoC6l1Gr9uaynao5N" alt=""> <em><strong>Ask</strong>: Find identity and access risks</em></summary>

Copy this prompt into [Sola AI](https://app.sola.security/) to get started:

{% code overflow="wrap" %}

```
I want to understand identity-related security risks across my systems. Guide me to identify which identity data source I should connect first - such as Okta, AWS, Google Workspace, or GitHub - or if I already have one connected, ask me which to use. Then help me discover issues like MFA gaps, dormant accounts, privilege creep, or token misuse that could lead to unauthorized access. Guide me to the best next step to quickly experience Sola's value. Do this as an interactive conversation, guide me one step at a time, avoid long explanations upfront, and pause for my response.
```

{% endcode %}

</details>

<details>

<summary><img src="/files/DESMoC6l1Gr9uaynao5N" alt=""> <em><strong>Build</strong>: Track identity and access risks</em></summary>

Copy this prompt into [Sola AI](https://app.sola.security/) to get started:

{% code overflow="wrap" %}

```
I want to build an app that continuously monitors identity and access risks across my systems. Guide me to identify which identity platforms I should connect first - such as Okta, AWS IAM, Google Workspace, or GitHub - or if I already have one connected, ask me which to use. Then help me build queries to detect issues like MFA gaps, dormant accounts, privilege creep, and token misuse, create canvases showing access patterns over time, and set up alerts for risky identity changes. Guide me to the best next step to quickly experience Sola's value. Do this as an interactive conversation, guide me one step at a time, avoid long explanations upfront, and pause for my response.
```

{% endcode %}

</details>

## What is Identity Security & Access Analysis?

Identity security is the practice of ensuring that the right people have the right access to the right resources. It covers authentication, authorization, and the full lifecycle of user accounts, service accounts, and machine identities across cloud and SaaS systems.

In simple terms, identity security helps answer the question:\
***"Who has access to what, should they, and what is the impact of an identity takeover?"***

Risks addressed include:

* MFA gaps and weak authentication across cloud, SaaS, and identity providers.
* Dormant or orphaned accounts with active permissions.
* Excessive privileges inconsistent with a user's role or team.
* Compromised credentials and suspicious login patterns.
* Service accounts and machine identities with uncontrolled access or no documented owner.

## Why is Identity Security important

Identity is the #1 initial access vector in modern attacks.

A single compromised credential or misconfigured permission can give an attacker access to everything connected to it. The risk is rarely a single account, it is the chain of permissions across systems that creates real exposure.

Investigating identity risk requires correlating data across identity providers, cloud platforms, and SaaS applications. Without a unified view, gaps go undetected.

## Identity security with Sola

Sola's graph model resolves the same person across all connected identity systems and surfaces cross-system privilege risks that siloed tools can potentially miss.

With Sola, you can:

* **Correlate** identity data across identity providers, cloud platforms, and SaaS applications into a single risk view.
* **Detect** MFA gaps, stale accounts, and excessive privileges across all connected systems.
* **Surface** compromise signals including failed logins, new devices, token creation, and privilege escalation.
* **Audit** service accounts and machine identities for missing controls or excessive permissions.
* **Map** privilege chains to identify lateral movement paths before they are exploited.

## Prompt library examples

Browse and run these prompts directly from the Prompt library in the Sola chat interface.

<img src="/files/MLlMKRdCI1cJhQemb1Ho" alt="Prompt Library" data-size="original">

<details>

<summary><strong>MFA &#x26; Authentication Hygiene</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
Show all identities with weak or missing MFA - no MFA enrolled, SMS-only, or MFA bypassed for specific apps. Prioritize privileged accounts, cloud admins, and anyone with access to production systems.
```

{% endcode %}

</details>

<details>

<summary><strong>Cross-System Privilege Audit</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
ist users whose combined permissions across Okta, AWS IAM, and Google Workspace are excessive or inconsistent with their role. Flag anyone with admin access in more than one system, especially accounts that aren’t in IT or Security.
```

{% endcode %}

</details>

<details>

<summary><strong>Stale &#x26; Orphaned Accounts</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
Identify accounts and API tokens that haven’t been used in 30+ days. Prioritize by privilege level - start with cloud and SaaS admins, then any account with production access. Show whether each account has an active owner.
```

{% endcode %}

</details>

<details>

<summary><strong>Service Account &#x26; Non-Human Identity Audit</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
List all service accounts, API keys, and machine identities across cloud and SaaS systems. Flag any with admin-level permissions, no expiration date, no rotation policy, or no documented owner.
```

{% endcode %}

</details>

<details>

<summary><strong>Identity Risk by Team</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
Which teams or departments have the highest identity risk exposure? For each, show average privilege level, MFA coverage, inactive account count, and any open compromise signals.
```

{% endcode %}

</details>


# Sola for Data Security

Prompts and use cases for DLP and File Exposure

Files and data are shared across cloud storage, collaboration tools, and email, often without visibility into who has access.

Sola helps you detect externally shared files, exposed cloud storage, and risky sharing patterns across Google Drive, S3, Slack, and other connected systems.

This page explains the key concepts behind **data loss prevention** and **file exposure**, what it is, why it matters, and how Sola helps you monitor it.

Get started with these below **ready-made Ask and Build prompts**, or the **Prompt Library**, both available directly in the Sola chat interface.

<details>

<summary><img src="/files/DESMoC6l1Gr9uaynao5N" alt=""> <em><strong>Ask</strong>: Check for exposed files</em></summary>

Copy this prompt into [Sola AI](https://app.sola.security/) to get started:

{% code overflow="wrap" %}

```
I want to discover which files and documents are exposed externally or shared too broadly. Guide me to identify which data source I should connect first - such as Google Workspace or AWS S3 - or if I already have one connected, ask me which to use. Then help me find issues like overshared documents, externally shared files, public links, or S3 bucket exposure that could lead to data leaks. Guide me to the best next step to quickly experience Sola's value. Do this as an interactive conversation, guide me one step at a time, avoid long explanations upfront, and pause for my response.
```

{% endcode %}

</details>

<details>

<summary><img src="/files/DESMoC6l1Gr9uaynao5N" alt=""> <em><strong>Build</strong>: Data exposure monitoring</em></summary>

Copy this prompt into [Sola AI](https://app.sola.security/) to get started:

{% code overflow="wrap" %}

```
I want to build an app that continuously monitors file exposure and sharing risks. Guide me to identify which data sources I should connect first - such as Google Workspace or AWS S3 - or if I already have one connected, ask me which to use. Then help me build queries to detect issues like overshared documents, externally shared files, public links, and unusual sharing patterns, create canvases visualizing exposure trends over time, and set up alerts for external data sharing. Guide me to the best next step to quickly experience Sola's value. Do this as an interactive conversation, guide me one step at a time, avoid long explanations upfront, and pause for my response.
```

{% endcode %}

</details>

## What is DLP and File Exposure?

Data loss prevention (DLP) is the practice of detecting and preventing sensitive data from being shared, accessed, or exposed beyond its intended audience. File exposure refers to documents, cloud storage buckets, or data accessible to external users, the public, or individuals who should no longer have access.

In simple terms, DLP and file exposure monitoring helps answer the question:\
***"Who can see my data, and should they be able to?"***

Risks addressed include:

* Google Drive files shared publicly or with external users or domains.
* Cloud storage buckets with public or cross-account access.
* Files shared with former employees or expired contractors.
* Unusual spikes in external sharing activity.
* Sensitive content shared through Slack channels accessible to guests.

## Why is DLP and File Exposure important

Unmonitored file exposure is one of the most common and underreported sources of data leakage.

Public links, misconfigured storage, and files shared with the wrong people create persistent risk that goes undetected without active monitoring. A single improperly shared document can expose sensitive data, and files containing API keys or access tokens can give attackers direct access to internal systems.

Most organizations lack a unified view of where their data is going across Drive, Slack, email, and cloud storage.

## DLP and File Exposure with Sola

Sola unifies file exposure signals across Drive, Slack, email, and cloud storage into a single view.

With Sola, you can:

* **Identify** files shared externally across Google Drive and other collaboration tools.
* **Audit** cloud storage exposure across S3 and other services, including bucket policies and ACLs.
* **Surface** unusual or anomalous sharing behavior and flag statistical outliers.
* **Detect** sensitive content shared with external users, contractors, or the public.
* **Identify** gaps in existing DLP policies, including platforms and data types not covered.

## Prompt library examples

Browse and run these prompts directly from the Prompt library in the Sola chat interface.

<img src="/files/MLlMKRdCI1cJhQemb1Ho" alt="Prompt Library" data-size="original">

<details>

<summary><strong>External File Sharing Overview</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
List all Google Drive files shared externally. Group by exposure type: shared with specific external users, shared with external domains, and ‘anyone with the link.’ Include the file owner, last accessed date, and the sensitivity classification if available.
```

{% endcode %}

</details>

<details>

<summary><strong>High-Risk Document Exposure</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
Identify Drive files with the broadest exposure - ‘anyone with the link’ or shared with 5+ external collaborators. Highlight files owned by Finance, Legal, HR, or Engineering, where data sensitivity is highest.
```

{% endcode %}

</details>

<details>

<summary><strong>Cloud Storage Exposure Audit</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
List S3 buckets and objects with public or cross-account access. Include bucket policies, ACLs, and which identities have read or write permissions. Flag any bucket that has had external access in the last 30 days.
```

{% endcode %}

</details>

<details>

<summary><strong>Anomalous External Sharing Trends</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
Which users or teams have had the largest increase in external file sharing over the last 30 days? Flag anyone whose sharing activity is a statistical outlier compared to their historical baseline or peer group.
```

{% endcode %}

</details>

<details>

<summary><strong>DLP Coverage Gap Analysis</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
Where are the blind spots in my current data loss prevention posture? Identify data types, platforms, or sharing patterns that fall outside existing DLP policies and suggest which gaps present the greatest immediate risk.
```

{% endcode %}

</details>


# Sola for SaaS Security

Prompts and use cases for SaaS Posture Management

SaaS applications store critical business data, yet security controls vary widely across vendors and remain largely invisible to traditional tools.

Sola helps you review security configurations, audit third-party integrations, and surface risky settings across Okta, Google Workspace, GitHub, Salesforce, Slack, and other connected applications.

This page explains the key concepts behind **SaaS Posture Management**, what it is, why it matters, and how Sola helps you monitor it.

Get started with these below **ready-made Ask and Build prompts**, or the **Prompt Library**, both available directly in the Sola chat interface.

<details>

<summary><img src="/files/DESMoC6l1Gr9uaynao5N" alt=""> <em><strong>Ask</strong>: Review SaaS security risks</em></summary>

Copy this prompt into [Sola AI](https://app.sola.security/) to get started:

{% code overflow="wrap" %}

```
I want to understand security risks across my SaaS applications. Guide me to identify which SaaS platform I should connect first - such as Okta, Google Workspace, GitHub, or Salesforce - or if I already have one connected, ask me which to use. Then help me discover issues like insecure configurations, risky OAuth apps, weak authentication settings, or third-party integrations that could expose organizational data. Guide me to the best next step to quickly experience Sola's value. Do this as an interactive conversation, guide me one step at a time, avoid long explanations upfront, and pause for my response.
```

{% endcode %}

</details>

<details>

<summary><img src="/files/DESMoC6l1Gr9uaynao5N" alt=""> <em><strong>Build</strong>: Monitor my SaaS security posture</em></summary>

Copy this prompt into [Sola AI](https://app.sola.security/) to get started:

{% code overflow="wrap" %}

```
I want to build an app that continuously monitors security posture across my SaaS applications. Guide me to identify which SaaS platforms I should connect first - such as Okta, Google Workspace, GitHub, or Salesforce - or if I already have one connected, ask me which to use. Then help me build queries to detect issues like risky OAuth apps, insecure configurations, and weak authentication settings, create canvases showing SaaS security trends over time, and set up alerts for new integrations or weakened security settings. Guide me to the best next step to quickly experience Sola's value. Do this as an interactive conversation, guide me one step at a time, avoid long explanations upfront, and pause for my response.
```

{% endcode %}

</details>

## What is SaaS Posture Management?

SaaS Posture Management is the practice of assessing and improving the security configuration of cloud-based software applications. It covers authentication settings, access controls, OAuth integrations, and admin role assignments across SaaS tools.

In simple terms, SaaS posture management helps answer the question:\
***"Are my SaaS tools configured securely, and who has access to what?"***

Risks addressed include:

* Weak authentication settings or disabled MFA across SaaS platforms.
* OAuth apps with excessive or dangerous permission scopes.
* Admin role proliferation across tools.
* Third-party integrations without a security review.
* External and contractor access that has outlasted its purpose.
* Shadow IT: unapproved apps connected via OAuth or SSO.

## Why is SaaS Posture Management important

SaaS tools now store an organization's most critical data, including customer records, source code, financial data, and communications.

Security controls are inconsistent across vendors and largely invisible to traditional tools. Misconfigurations, risky integrations, and unchecked admin roles create exposure that no single platform surfaces on its own.

Every new SaaS tool adds new access paths and OAuth connections that may never get reviewed without active monitoring.

## SaaS Posture Management with Sola

Sola provides a unified view of security posture across all connected SaaS applications, flagging misconfigurations and risky integrations that siloed tools miss.

With Sola, you can:

* **Review** security configurations across major SaaS platforms from a single interface.
* **Audit** OAuth apps and third-party integrations for excessive permissions or risky scopes.
* **Monitor** admin role assignments and flag accounts inconsistent with job function.
* **Detect** shadow IT and unapproved apps connected via OAuth or SSO.
* **Identify** external and contractor access that has outlasted its purpose.

## Prompt library examples

Browse and run these prompts directly from the Prompt library in the Sola chat interface.

<img src="/files/MLlMKRdCI1cJhQemb1Ho" alt="Prompt Library" data-size="original">

<details>

<summary><strong>OAuth App Risk Review</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
List all OAuth apps connected to Okta and Google Workspace. Highlight apps with dangerous permission scopes - file access, calendar read, send-as email, user impersonation, or admin API access. Show when each app was authorized and by whom.
```

{% endcode %}

</details>

<details>

<summary><strong>SaaS Security Posture Overview</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
Review the security posture across Okta, Google Workspace, GitHub, and Salesforce. Highlight settings that weaken authentication, expose data unnecessarily, or allow access without proper authorization controls.
```

{% endcode %}

</details>

<details>

<summary><strong>Contractor &#x26; Guest Access Audit</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
Show all external users, contractors, and guests with active access across SaaS platforms. Flag anyone with access to sensitive systems who hasn’t been active in 14+ days, or whose contract end date has passed.
```

{% endcode %}

</details>

<details>

<summary><strong>Admin Role Proliferation</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
Identify accounts holding admin roles across SaaS tools. For each, show when the role was granted, whether MFA is enabled, and whether the role appears consistent with the account owner’s job function.
```

{% endcode %}

</details>


# Sola for Incident Readiness

Prompts and use cases for Incident Readiness and Backup Resilience

Incident response depends on knowing your environment and being equipped to respond quickly, before an incident occurs, keeping the impact minimal.

Sola helps you evaluate logging coverage, assess backup configuration, and map blast radius across cloud, identity, and SaaS systems to understand your readiness.

This page explains the key concepts behind **incident readiness** and **backup resilience**, what it is, why it matters, and how Sola helps you assess it.

Get started with these below **ready-made Ask and Build prompts**, or the **Prompt Library**, both available directly in the Sola chat interface.

<details>

<summary><img src="/files/DESMoC6l1Gr9uaynao5N" alt=""> <em><strong>Ask</strong>: How ready am I for an incident</em></summary>

Copy this prompt into [Sola AI](https://app.sola.security/) to get started:

{% code overflow="wrap" %}

```
I want to evaluate whether my organization is prepared to handle a security incident. Guide me to identify which critical system I should connect first - such as AWS, Azure, GCP, or identity providers like Okta - or if I already have one connected, ask me which to use. Then help me assess issues like logging coverage gaps, IAM hygiene problems, backup configuration weaknesses, or monitoring gaps that could slow incident response. Guide me to the best next step to quickly experience Sola's value. Do this as an interactive conversation, guide me one step at a time, avoid long explanations upfront, and pause for my response.
```

{% endcode %}

</details>

<details>

<summary><img src="/files/DESMoC6l1Gr9uaynao5N" alt=""> <em><strong>Build</strong>: Incident readiness tracking</em></summary>

Copy this prompt into [Sola AI](https://app.sola.security/) to get started:

{% code overflow="wrap" %}

```
I want to build an app that continuously monitors my incident readiness and backup resilience. Guide me to identify which systems I should connect first - such as AWS, Azure, or GCP - or if I already have one connected, ask me which to use. Then help me build queries to assess issues like backup coverage, logging gaps, and IAM hygiene, create canvases showing readiness trends over time, and set up alerts for backup failures or degraded response capabilities. Guide me to the best next step to quickly experience Sola's value. Do this as an interactive conversation, guide me one step at a time, avoid long explanations upfront, and pause for my response.
```

{% endcode %}

</details>

## What is  Incident Readiness and Backup Resilience?

Incident readiness is the practice of ensuring your organization can detect, respond to, and recover from a security incident. Backup resilience is the assurance that critical data and systems can be restored after an attack.

In simple terms, incident readiness helps answer the question:\
***"If something went wrong today, would we know? Could we recover?"***

Key areas of focus include:

* Logging coverage across cloud and SaaS systems.
* IAM hygiene and access controls that affect response speed.
* Backup configuration, retention policies, and recovery readiness.
* Alert coverage gaps and detection blind spots.
* Privilege escalation paths that expand blast radius.
* Forensic log retention and audit trail completeness.

### Why is Incident Readiness important

True incident readiness requires more than detection. It requires knowing in advance what your blast radius looks like, where your logging gaps are, and whether your backups would help you quickly resolve an incident.

Discovering these gaps in the middle of an incident is the worst possible time. The organizations that recover fastest are those that assessed their readiness before the incident occurred.

Sola's cross-system graph makes it possible to simulate these scenarios proactively, rather than discovering gaps under pressure.

### Incident Readiness with Sola

Sola connects cloud, identity, and SaaS data to give you a complete picture of your incident readiness.

With Sola, you can:

* **Assess** logging and alerting coverage across cloud, identity, and SaaS environments.
* **Map** blast radius for high-risk accounts, roles, and systems.
* **Audit** backup configuration, retention policies, and recovery readiness.
* **Identify** privilege escalation paths that could expand an attacker's footprint.
* **Evaluate** forensic log retention and audit trail completeness.

## Prompt library examples

Browse and run these prompts directly from the Prompt library in the Sola chat interface.

<img src="/files/MLlMKRdCI1cJhQemb1Ho" alt="Prompt Library" data-size="original">

<details>

<summary><strong>Blast Radius Estimation</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
If a specific user account [or role / system] were compromised right now, what’s the worst-case blast radius? Show every system, dataset, and permission they could access or abuse, including lateral movement paths.
```

{% endcode %}

</details>

<details>

<summary><strong>Backup &#x26; Restore Resilience Audit</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
Assess whether backups are properly configured across cloud workloads and critical SaaS data. Flag missing backups, weak retention policies, single-region storage, and any workloads with no recovery plan.
```

{% endcode %}

</details>

<details>

<summary><strong>Privilege Escalation Path Mapping</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
Map all paths in my environment where an attacker starting from a standard user account could escalate to cloud admin, domain admin, or root. Include identity, cloud, and SaaS vectors in the analysis.
```

{% endcode %}

</details>

<details>

<summary><strong>Forensic Logging Readiness</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
Do I have sufficient log retention and audit trails to investigate an incident that occurred 90 days ago? Show which systems have audit logging enabled and which are gaps, and flag any that may have been disabled recently.
```

{% endcode %}

</details>


# Sola for Supply Chain Security

Prompts and use cases for CI/CD and Supply Chain Security

Software supply chain attacks target CI/CD pipelines, source repositories, and third-party dependencies. The risk sits at the intersection of developer tooling and cloud infrastructure.

Sola connects GitHub, CI/CD systems, cloud environments, and identity data to surface supply chain risks including exposed secrets, overprivileged pipeline tokens, and insecure workflow configurations.

This page explains the key concepts behind **CI/CD** and **supply chain security**, what it is, why it matters, and how Sola helps you identify risks.

## What is CI/CD and Supply Chain Security?

CI/CD security focuses on protecting the build and deployment pipeline from code commit to production release. Supply chain security extends this to cover third-party dependencies, open-source packages, and external actions that enter your codebase.

In simple terms, CI/CD and supply chain security helps answer the questions:\
***"Is my software build pipeline secure, and can I trust what's in my code?"***\
***“Am I exposed if a third-party dependency is compromised?"***

Risks addressed include:

* Secrets and credentials committed to repositories.
* CI/CD service accounts and tokens with excessive cloud or production access.
* Unpinned third-party actions from unverified publishers.
* Weak branch protection rules that allow unreviewed changes to main.
* Dependencies with known vulnerabilities or suspicious ownership changes.
* Uncontrolled access to pipeline definitions.

## Why is CI/CD and Supply Chain Security important

Software supply chain attacks have become one of the fastest-growing threat vectors.

A leaked secret, an unpinned GitHub Action, or an overprivileged pipeline token can each be the entry point for a much larger compromise. These risks live at the intersection of developer tooling and cloud infrastructure, a gap most security tools cannot bridge.

Sola connects both sides of that gap to surface supply chain risks in full context.

## CI/CD and Supply Chain Security with Sola

Sola connects GitHub, CI/CD systems, cloud environments, and identity data to surface supply chain risks that siloed tools miss.

With Sola, you can:

* **Detect** secrets and credentials committed to GitHub repositories.
* **Audit** CI/CD service accounts and tokens for excessive permissions or production access.
* **Identify** unpinned or unverified third-party actions in GitHub workflows.
* **Review** branch protection rules across your GitHub organization.
* **Surface** dependency risks including known CVEs and suspicious ownership changes.
* **Map** which identities can modify pipeline definitions without oversight.

## Prompt library examples

Browse and run these prompts directly from the Prompt library in the Sola chat interface.

<img src="/files/MLlMKRdCI1cJhQemb1Ho" alt="Prompt Library" data-size="original">

<details>

<summary><strong>Unpinned Third-Party Actions</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
Which GitHub Actions workflows use third-party actions not pinned to a specific commit SHA? Flag any actions from unverified publishers, recently transferred repositories, or accounts with a history of security issues.
```

{% endcode %}

</details>

<details>

<summary><strong>Branch Protection Gap Audit</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
Audit branch protection rules across my GitHub organization. Which repositories allow direct pushes to main or master, have no required code reviewers, permit force-pushes, or allow certain users to bypass protections?
```

{% endcode %}

</details>

<details>

<summary><strong>Supply Chain Dependency Risk</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
Identify packages and dependencies in my repositories with known critical CVEs, suspicious recent ownership changes, or unusual version release patterns - common indicators of dependency confusion or typosquatting attacks.
```

{% endcode %}

</details>

<details>

<summary><strong>CI/CD Access Footprint</strong></summary>

{% code title="PROMPT" overflow="wrap" %}

```
Map which identities, human and machine, have permission to modify CI/CD pipeline definitions. Flag cases where developers can edit their own pipelines without a second approver, or where pipeline changes bypass the standard code review process.
```

{% endcode %}

</details>


# Glossary

<figure><img src="/files/7AFz0pijmEM7i8zvM1KE" alt="Coming soon"><figcaption></figcaption></figure>


# FAQs

Find answers to your top questions

Browse the FAQs below or type your question in the search box at the top right, and our AI assistant will guide you.

## About Sola

### What’s unique about Sola?

Sola isn’t just another security tool. It’s a new way to build security solutions, designed for flexibility, speed, and collaboration.

* Build security solutions, your way. No need for an engineering team.
* Create security projects tailored to your needs using Sola AI or SQL.
* From questions to answers, fast. Ask, analyze risks, and trigger alerts.
* Designed for teams. Share insights, track findings, and collaborate.

Sola helps you move from security gaps to solutions, faster than ever.

## Pricing and plans

### How much does Sola cost?&#x20;

Sola offers four plans designed for teams of any size: **Shoreline (*****Free*****)**, **Tidewater** , **Open Sea** , and **Deep Blue**.

Higher plans include increased weekly [AI credits](/getting-started/sola-ai#ai-credits-and-usage), more [data sources](/integrations/data-sources#data-records-and-usage), higher daily record limits, and advanced features such as [agentic workflows](/workspace/projects/workflows#workflow-credits-and-usage), [Lumina Signls](/workspace/lumina-signals), private visibility controls, and enterprise security.

Sola will always remain affordable and accessible as we grow.

For more details, visit our [pricing page](https://sola.security/pricing/).

{% embed url="<https://sola.security/pricing/>" %}

### Can I try before I buy?

Yes. Get started on the Free plan at no cost and explore Sola’s core features before upgrading.

### Can I upgrade or downgrade my plan?

Yes.

**Upgrading**: Your new plan is activated immediately and billing updates automatically.

**Downgrading**: Your current plan stays active until the end of your billing period. Refunds are not issued for unused time. The downgrade takes effect when the billing cycle ends.

### What are AI credits?

[AI credits](/getting-started/sola-ai#ai-credits-and-usage) measure your usage of Sola AI, including chats, project generation, query generation, workflow steps, and conversational requests.

Each plan includes a weekly allowance of AI credits. When credits refresh, your AI features become fully available again.

### What happens if I exceed my limits?

AI Credits: When you run out of weekly AI credits, AI-powered features become unavailable until your credits refresh. You can upgrade anytime to increase your allowance.

**Data Sources**: You cannot add more data sources than your plan allows. [Upgrade](https://sola.security/pricing/) to connect additional sources.

**Daily Data Records**: If you reach your daily data-record limit, processing pauses until midnight UTC. Upgrade for higher daily capacity.

**Projects**: You cannot create additional projects once you reach your plan limit. You can upgrade or archive existing projects to free up space.

### Do unused AI credits roll over?

No. AI credits refresh weekly and do not roll over or accumulate. Each week you receive the full allowance included in your plan.

### Can I add more users without upgrading?

No. User limits are fixed per workspace based on the plan. To add more users, upgrade to a higher plan or contact sales.

### What happens when I cancel a paid plan?

Your workspace remains active until the end of your current billing period.

After the billing period ends:

* Your workspace automatically downgrades to Free plan limits.
* Your data and projects remain accessible.
* Features and limits are reduced according to the Free plan.

### What payment methods do you accept?

We accept all major credit cards (Visa, Mastercard, American Express, Discover) via Stripe. Enterprise customers can arrange invoice-based billing.

## Sola Concepts

### What are projects, and how should I build them?

A [Sola project](/workspace/projects) is a custom security solution you build based on your needs. Each project functions independently and is built to [answer your security questions](/workspace/projects/queries) across different domains.

There’s no single way to structure your projects. Sola gives you the flexibility to organize them however you prefer:

* By security domain. For example, Identity and Access Management, Cloud Security.
* By vendor. For example, AWS Security, GitHub Security.
* By team. For example, SOC Team Monitoring, CISO Dashboard.

Whether you’re building a single-use project or a more complex multi-source security solution, it’s up to you and your use case.

Projects connect to relevant [data sources](/integrations/data-sources) and can be shared with your team for collaboration.

### Who is considered a workspace member?&#x20;

An organization can have multiple [workspaces](/workspace/workspace-home), and users can be members of one or more. As a workspace member, your [role and permissions](https://docs.sola.security/resources/pages/l69Cxh11wZLxhFByYYn5#id-2.-workspace-settings) determine what you can do. Whether it’s managing settings, inviting members, building or viewing projects.

### Do you need to know how to code or SQL to build a security tool in Sola?

Sola offers a no-code experience, making it easy to [create security projects](/workspace/projects#creating-projects) using natural language with Sola AI. You can ask security questions, uncover insights, and set up alerts—no coding required. Start quickly with ready-to-use [templates](/getting-started/templates), built by our expert security team.

### What should I do if I don’t have access to connect a data source?

In the meantime, you can explore Sola using a sandbox environment or placeholder data source to test features and get familiar with the platform before [connecting your own data](/integrations/data-sources).

## Privacy and Security

### Is my data secure?

Sola is built by security people, for security people. Security is at the core of everything we do. We uphold the highest industry standards to protect your data, systems, and operations.

Your data is encrypted at rest and in transit, with access strictly controlled through a secure authentication and authorization process.

Learn more about our security practices in [Sola’s Trust Center](https://trust.sola.security/).

### Where is my data stored?

Sola only provides a managed service. Your data is saved within Sola databases, according to compliance and audit standards.

### What access do you have to my data?

Sola has read-only access to your data and cannot modify or delete any information. Once connected, your data is securely stored, and access is restricted to retrieving configurations and metadata only. Authentication methods ensure secure delegation of permissions while maintaining data integrity.\
Also, you control which data is synced by enabling or disabling specific tables within your data source.

### Is Sola Security SOC 2 certified?

Yes, Sola Security is SOC 2 certified.

Sola has successfully completed the SOC 2 Type II audit, which demonstrates our commitment to maintaining the highest standards for security, availability, and confidentiality. This independent third-party assessment validates that our systems and processes are designed and operated to safeguard customer data.

Learn more about our other key industry certifications, such as ISO 27001, and our latest  security and compliance documentation, in the [Trust Center](https://trust.sola.security/).

### Does Sola support Single Sign-On (SSO)?

Yes. Sola supports SSO via SAML and OpenID, with integrations for identity providers such as Okta, Azure AD, Google, OneLogin, Ping Identity, and JumpCloud. Configure SSO in [Settings](https://docs.sola.security/resources/pages/l69Cxh11wZLxhFByYYn5#id-3.-privacy-and-security).

## Sola AI

### How does Sola AI assistant use my data?

Sola AI assistant follows strict security practices to keep your data safe. Your data is stored securely according to [our standard security policies](https://sola.security/privacy-policy/).

Sola AI assistant does not use your data to train our models. Any data processed through Sola AI is used solely to generate responses and is not retained for training purposes.

### Can I enable or disable Sola AI?

Yes. You can enable or disable the option to skip the Sola AI assistant when creating new queries.

<br>


# Settings

View and manage the settings to your Sola user, workspaces and projects

There are two types of settings categories in Sola: user settings and workspace settings.&#x20;

To access your Sola settings, click ![](/files/YYGUmBMDhoPquWPLwW2h) *Settings* from the sidebar.

## 1. User settings

This is where you can manage your personal Sola user name, email, password, and AI assistant activation.

### ![](/files/DESMoC6l1Gr9uaynao5N) Sola AI assistant

Enable or disable the option to skip the Sola AI assistant when you are creating new queries.

### Deleting your user

Deleting your user permanently removes access to Sola.

You can delete your user only if you are not an owner of any workspace. If you are an owner, transfer workspace ownership to another member first. If you are the only user, [delete your workspace](#deleting-a-workspace). This will also delete your user if this is the only workspace you are a member of.

Once your user is deleted, access is removed and **this action cannot be undone**.

## 2. Workspace settings

This is where you can manage your general [workspace](/workspace/workspace-home) name, members, plans and billing, and more.

### Members

Workspace owners and admins can invite new members to a workspace using a link or by email, and define their roles.

### Leaving a workspace

A workspace requires at least one owner. When leaving a workspace, you must assign a new owner.&#x20;

### Deleting a workspace

Workspace owners can delete a workspace. Deleting a workspace permanently removes all workspace information and associated data.

To delete a workspace that is part of a paid plan, you must first downgrade the workspace to the Free plan. Once the paid plan ends, you can delete the workspace.

Once a workspace is deleted, all members will lose access, and **this action cannot be undone**.

### Roles and permissions

There are two types of roles and permissions levels: workspace permissions and project permissions.

### Workspace permissions

<table><thead><tr><th width="136">Role type</th><th>Permission description</th></tr></thead><tbody><tr><td>Owner</td><td>Full access to manage all workspace settings, members, integrations, projects, and plans.</td></tr><tr><td>Admin</td><td>Manage workspace settings, members, integrations, and projects you are an admin of. Excludes plan, billing, and password reset.</td></tr><tr><td>Member</td><td>View workspace settings, members, integrations, and projects.</td></tr></tbody></table>

### Project permissions

<table><thead><tr><th width="136">Role type</th><th>Permission description</th></tr></thead><tbody><tr><td>Admin</td><td>Full access to manage members, add/edit/delete projects, queries, canvases, and alerts.</td></tr><tr><td>Contributor</td><td><p>View project info, add/edit/delete queries, canvases, and alerts.</p><p>View project info, add/edit/delete queries, canvases, and alerts.</p></td></tr><tr><td>Viewer</td><td>Read-only access to view queries, canvases, and alerts.</td></tr></tbody></table>

### Plans and billing

View and manage workspace subscription, usage, and payment details. Only workspace owners can manage the workspace plans and billing.

Plans and billing includes information on your:

* **Subscription**: Current plan and billing status, including options to upgrade or change the plan.
* **Usage**: Usage and limit totals for the current billing period. Including plan allowances such as AI credits, AI transaction limits, workflow executions, team members, connected data sources, and data source records.
* **Payment details**: Billing information.

{% embed url="<https://sola.security/pricing/>" %}

## 3. Privacy and security settings

This is where you can manage your user settings, including password, authentication methods, session activity, and Single Sign-On (SSO).

To manage your privacy and security settings, go to *Settings* > *Privacy and Security*.

* **My User** - Multi-factor authentication, password, Login sessions
* **Workspace** (applicable for admin and owner users) - Account security, security check up

### Single Sign-On (SSO)

Workspace owners can configure SSO to allow members to sign in to Sola using their organization’s identity provider (IdP).

Go to *Settings* > *Privacy and Security* > *SSO*, click “*Setup SSO connection*” to open the wizard and add a new connection.

Available connection options:

* **SAML**: Okta, Azure AD, Google, OneLogin, Ping Identity, JumpCloud, Rippling, Custom SAML
* **OpenID**: Okta, Custom OpenID

Once configured, SSO centralizes authentication and improves access security across your workspace.

Available on [custom plans](https://sola.security/pricing/).

***

## FAQs

### Can I recover a deleted user?

No. Deleting your user is permanent and cannot be undone. If you’d like to use Sola again, you can create a new user at any time.

### Can I recover a deleted workspace?

No. Deleting a workspace is permanent and cannot be undone.

### Can I delete a workspace on a paid plan?

No. Workspaces on a paid plan cannot be deleted.

To delete a workspace that is part of a paid plan, first downgrade the workspace to the Free plan. Once the paid plan ends, you can delete the workspace. Contact support for help.

### How do upgrades work?

Switching from one paid plan to another counts as an upgrade. Upgrades take effect immediately, and billing is prorated based on the time remaining in the current billing cycle.

### How do downgrades work?

Downgrades take effect at the end of the current billing cycle. Until then, the current plan stays active.

After the downgrade takes effect, existing members and connected data sources stay in the workspace, even if they exceed the new plan limits. Sola applies the new plan limits going forward, which means data syncs fetch only the number of records included in the new plan, and AI credits and usage limits may be lower, and usage may run out faster.

### How do I check my credits balance?

Go to *Settings* > *Plans & Billing*. Under **Usage**, you can view your current credit balance and limits for the billing period, including AI credits and other usage-based allowances.


