Security & Identity · Integration
Cisco Umbrella
Add Cisco Umbrella to your product for your customers, and give your AI agents governed access to it.
Embed a Cisco Umbrella integration so your customers can work their own DNS policies, blocked request activity, and identities from inside your product, with least-privilege access per tenant. Only the scopes required for the actions you enable are requested, each customer grants access to their own organisation, and every call is recorded so a policy change can be traced to its source. fastn handles per-customer authorisation and API upkeep.
In your product
Embedded for your customers. Per-tenant auth, no per-customer code, maintained by fastn.
Let customers read their own DNS activity and blocked requests into your product for reporting.
Read policies and identities so administrators can see who a rule applies to inside your app.
Add or remove a destination from a customer's allow or block list within the scopes they grant.
Trigger your product when a request is blocked or a policy is changed.
For your AI agents
Governed, audited access for the agents you build, through the MCP server.
An agent explains why a domain was blocked for a given identity before an exception is granted.
An agent adds a destination to a block list within governed permissions, with the action audited.
An agent reacts to a blocked request pattern and raises it for review.
Example prompt
List the top blocked domains this week and show which identities were affected by each.
Set up Cisco Umbrella in 4 steps
- 01Open the Cisco Umbrella connector from your fastn dashboard.
- 02Have each customer authenticate their Umbrella organisation with least-privilege API credentials.
- 03Map the policies, identities, and activity fields your product uses, then enable actions and triggers.
- 04Call them from your product, or expose them to an agent through the MCP server.
Why teams use the Cisco Umbrella integration
What you get by embedding it with fastn instead of building it yourself.
- Ship a Cisco Umbrella integration without building it. Your customers connect their own Cisco Umbrella account inside your product and work their users, groups and roles there, with no per-customer code on your side.
- Handle the part that actually costs time: the blast radius of an error is large, so least-privilege and auditability are non-negotiable. fastn owns the auth, token refresh, rate limits, pagination and breaking-change fixes, so a Cisco Umbrella update is not your on-call problem.
- One integration serves your product and your agents. The same governed Cisco Umbrella connection powers in-product features and gives AI agents scoped, audited access, so you keep access and identity in step across a customer's estate without wiring it twice.
Used by these teams
Works well with
Often used alongside
Tools the same teams tend to run next to Cisco Umbrella, across other categories.
Cisco Umbrella integration FAQ
How do I add a Cisco Umbrella integration to my product?
Enable the Cisco Umbrella connector in your fastn dashboard, then let each customer authenticate their own Cisco Umbrella account. fastn handles the OAuth flow, token storage and refresh per tenant, so there is no Cisco Umbrella client code in your app and no per-customer branch in your codebase. Setup is 4 steps.
Do my customers each connect their own Cisco Umbrella account?
Yes. Every connection is scoped to the individual customer, so each authorises their own Cisco Umbrella account and only ever sees their own users, groups and roles. That per-tenant isolation is the point of an embedded integration: you support the long tail of customer setups without maintaining an integration per customer.
Can AI agents use this Cisco Umbrella integration?
Yes. The same connection is exposed to your agents through the fastn MCP gateway, with permissions scoped per tenant and every call audited. An agent explains why a domain was blocked for a given identity before an exception is granted.
Who maintains the Cisco Umbrella integration?
fastn does. When Cisco Umbrella changes an endpoint, deprecates a field or alters its auth, the fix lands in the connector rather than in your backlog, and your customers' connections keep working.
What permissions does the Cisco Umbrella integration need?
Only the scopes required for the actions you enable. Each customer grants access to their own Cisco Umbrella tenant, permissions are scoped per tenant, and every call is recorded so an access change can be traced to its source.
Can access changes be automated safely?
Yes. Provisioning and deprovisioning can be driven from your product or an agent within governed permissions, with every action audited, which is what makes automated access changes reviewable after the fact.
What can I build with the Cisco Umbrella integration?
A common starting point: read their own DNS activity and blocked requests into your product for reporting. Teams also use it for the other use cases listed above, and expose it to agents for governed reads and writes.
How much does the Cisco Umbrella integration cost?
It is included. Pricing is based on connected accounts, not on how many connectors you enable, so adding Cisco Umbrella does not change your per-connector cost. You can start free with 3 connected accounts.
Add Cisco Umbrella to your product
Start free with 3 connected accounts. No sales call required, and no per-customer integration code.