Security & Identity · Integration
Skyhigh Security
Add Skyhigh Security to your product for your customers, and give your AI agents governed access to it.
Skyhigh Security is the service edge a customer puts between their people and the cloud services they use, and it comes from the same lineage as the original Skyhigh CASB that later shipped inside McAfee. What it holds is therefore an inventory of governance: which people and groups exist, which devices they work from, which cloud services they reach and whether those are sanctioned, the policies deciding all of that, and the incidents raised when data moves somewhere it should not. An embedded integration reads that context and can apply an access change within scoped permissions. The blast radius is large, which is why scopes stay narrow and every call is recorded: an access change nobody can trace is worse than one nobody made. fastn stores the credentials per tenant and keeps the connector current as the API moves.
In your product
Embedded for your customers. Per-tenant auth, no per-customer code, maintained by fastn.
Let each customer connect their own Skyhigh Security tenant so your product sees the user, group and device context it governs.
Read incidents so your product can explain that a file or an application was blocked by policy, and by which one.
Read the cloud service inventory so your product knows what a customer's people are genuinely using.
Apply an approved access change, such as a group membership that alters which policy applies, within scoped permissions.
For your AI agents
Governed, audited access for the agents you build, through the MCP server.
An agent explains why a user could not reach a service by reading that tenant's own policy and incident detail.
An agent gathers the users, devices and services involved in an incident and summarises the exposure.
An agent applies a reviewed access change and leaves an attributable record of having done it.
Example prompt
Why did this upload get blocked, and which policy and group decided it?
Set up Skyhigh Security in 4 steps
- 01Enable the Skyhigh Security connector in your fastn dashboard.
- 02Have each customer authorise their own tenant with only the scopes the actions you enable require.
- 03Map the user, group, device and incident fields your product uses, per customer.
- 04Call it from your product and expose the same connection to your agents through the MCP gateway.
Why teams use the Skyhigh Security integration
What you get by embedding it with fastn instead of building it yourself.
- Ship a Skyhigh Security integration without building it. Your customers connect their own Skyhigh Security account inside your product and work their users, groups and roles there, with no per-customer code on your side.
- Handle the part that actually costs time: the blast radius of an error is large, so least-privilege and auditability are non-negotiable. fastn owns the auth, token refresh, rate limits, pagination and breaking-change fixes, so a Skyhigh Security update is not your on-call problem.
- One integration serves your product and your agents. The same governed Skyhigh Security connection powers in-product features and gives AI agents scoped, audited access, so you keep access and identity in step across a customer's estate without wiring it twice.
Used by these teams
Compare with
Often used alongside
Tools the same teams tend to run next to Skyhigh Security, across other categories.
Skyhigh Security integration FAQ
How do I add a Skyhigh Security integration to my product?
Enable the Skyhigh Security connector in your fastn dashboard, then let each customer authenticate their own Skyhigh Security account. fastn handles the OAuth flow, token storage and refresh per tenant, so there is no Skyhigh Security client code in your app and no per-customer branch in your codebase. Setup is 4 steps.
Do my customers each connect their own Skyhigh Security account?
Yes. Every connection is scoped to the individual customer, so each authorises their own Skyhigh Security account and only ever sees their own users, groups and roles. That per-tenant isolation is the point of an embedded integration: you support the long tail of customer setups without maintaining an integration per customer.
Can AI agents use this Skyhigh Security integration?
Yes. The same connection is exposed to your agents through the fastn MCP gateway, with permissions scoped per tenant and every call audited. An agent explains why a user could not reach a service by reading that tenant's own policy and incident detail.
Who maintains the Skyhigh Security integration?
fastn does. When Skyhigh Security changes an endpoint, deprecates a field or alters its auth, the fix lands in the connector rather than in your backlog, and your customers' connections keep working.
What permissions does the Skyhigh Security integration need?
Only the scopes required for the actions you enable. Each customer grants access to their own Skyhigh Security tenant, permissions are scoped per tenant, and every call is recorded so an access change can be traced to its source.
Can access changes be automated safely?
Yes. Provisioning and deprovisioning can be driven from your product or an agent within governed permissions, with every action audited, which is what makes automated access changes reviewable after the fact.
What can I build with the Skyhigh Security integration?
A common starting point: let each customer connect their own Skyhigh Security tenant so your product sees the user, group and device context it governs. Teams also use it for the other use cases listed above, and expose it to agents for governed reads and writes.
How much does the Skyhigh Security integration cost?
It is included. Pricing is based on connected accounts, not on how many connectors you enable, so adding Skyhigh Security does not change your per-connector cost. You can start free with 3 connected accounts.
Add Skyhigh Security to your product
Start free with 3 connected accounts. No sales call required, and no per-customer integration code.