Threat & Vulnerability · Integration

Lacework

Add Lacework to your product for your customers, and give your AI agents governed access to it.

Embed a Lacework integration so your customers can see their cloud security alerts inside your product rather than in a separate console. Alerts arrive through event triggers instead of polling, are deduplicated per alert so a flapping condition does not create a queue of identical records, and every read is logged per tenant. fastn handles per-customer credentials, token refresh, pagination and API upkeep.

Start freeBook a demo

In your product

Embedded for your customers. Per-tenant auth, no per-customer code, maintained by fastn.

Let customers connect their own Lacework account so your product surfaces their alerts in context.

Read alerts and their severity so your product raises only the ones a customer's team cares about.

Trigger your workflow when a new alert is raised, instead of polling for changes.

Read cloud asset and inventory data so your product knows what a customer is actually running.

For your AI agents

Governed, audited access for the agents you build, through the MCP server.

An agent reads the detail behind an alert before recommending an action.

An agent correlates an alert with the affected account or asset to explain the blast radius.

An agent summarises open alerts by severity, with every read logged per tenant.

Example prompt

Summarise the high severity alerts opened in the last 24 hours and group them by affected cloud account.

Set up Lacework in 4 steps

  1. 01Open the Lacework connector from your fastn dashboard.
  2. 02Have each customer authenticate their own Lacework account with least-privilege scopes.
  3. 03Map the alert severities, accounts and asset fields your product uses, then enable actions and triggers.
  4. 04Call them from your product, or expose them to an agent through the MCP server.

Why teams use the Lacework integration

What you get by embedding it with fastn instead of building it yourself.

  • Ship a Lacework integration without building it. Your customers connect their own Lacework account inside your product and work their findings, detections and assets there, with no per-customer code on your side.
  • Handle the part that actually costs time: a rescan re-reports everything, so the same finding arriving twice must not read as two problems. fastn owns the auth, token refresh, rate limits, pagination and breaking-change fixes, so a Lacework update is not your on-call problem.
  • One integration serves your product and your agents. The same governed Lacework connection powers in-product features and gives AI agents scoped, audited access, so you get security findings in front of the people and systems that act on them without wiring it twice.

Used by these teams

Security & IT

Works well with

DatadogServiceNowOpsgenie

Often used alongside

Tools the same teams tend to run next to Lacework, across other categories.

OktaMicrosoft Entra IDPagerDutyAWS CloudWatch

Lacework integration FAQ

How do I add a Lacework integration to my product?

Enable the Lacework connector in your fastn dashboard, then let each customer authenticate their own Lacework account. fastn handles the OAuth flow, token storage and refresh per tenant, so there is no Lacework client code in your app and no per-customer branch in your codebase. Setup is 4 steps.

Do my customers each connect their own Lacework account?

Yes. Every connection is scoped to the individual customer, so each authorises their own Lacework account and only ever sees their own findings, detections and assets. That per-tenant isolation is the point of an embedded integration: you support the long tail of customer setups without maintaining an integration per customer.

Can AI agents use this Lacework integration?

Yes. The same connection is exposed to your agents through the fastn MCP gateway, with permissions scoped per tenant and every call audited. An agent reads the detail behind an alert before recommending an action.

Who maintains the Lacework integration?

fastn does. When Lacework changes an endpoint, deprecates a field or alters its auth, the fix lands in the connector rather than in your backlog, and your customers' connections keep working.

How does a new Lacework finding reach my product?

Through event triggers rather than polling, delivered per tenant, so your product reacts when a finding is raised or its severity changes rather than on a schedule that is always slightly out of date.

How is Lacework finding noise kept manageable?

Findings are deduplicated per asset so a rescan does not re-raise what you already have, and you can filter by severity and status before anything reaches your product. That matters more here than in most integrations, because the volume is what stops teams acting on any of it.

What can I build with the Lacework integration?

A common starting point: connect their own Lacework account so your product surfaces their alerts in context. Teams also use it for the other use cases listed above, and expose it to agents for governed reads and writes.

How much does the Lacework integration cost?

It is included. Pricing is based on connected accounts, not on how many connectors you enable, so adding Lacework does not change your per-connector cost. You can start free with 3 connected accounts.

Add Lacework to your product

Start free with 3 connected accounts. No sales call required, and no per-customer integration code.

Start freeRead the docs
← All integrations