From 173355caa1a3e308a0e1dc76ac760a71eca16c44 Mon Sep 17 00:00:00 2001 From: jenny hajee Date: Wed, 8 Jul 2026 17:14:10 -0500 Subject: [PATCH 01/21] added new scanner prerequisites topic --- .../ROOT/exp-scanners-add-from-providers.adoc | 0 modules/ROOT/nav.adoc | 1 + modules/ROOT/pages/exp-providers-manage.adoc | 7 +- .../exp-scanners-add-from-providers.adoc | 7 +- .../exp-scanners-prerequisites-reference.adoc | 205 ++++++++++++++++++ .../pages/exp-services-add-to-portfolio.adoc | 1 + 6 files changed, 217 insertions(+), 4 deletions(-) create mode 100644 modules/ROOT/exp-scanners-add-from-providers.adoc create mode 100644 modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc diff --git a/modules/ROOT/exp-scanners-add-from-providers.adoc b/modules/ROOT/exp-scanners-add-from-providers.adoc new file mode 100644 index 000000000..e69de29bb diff --git a/modules/ROOT/nav.adoc b/modules/ROOT/nav.adoc index 96f9abae4..326c67b59 100644 --- a/modules/ROOT/nav.adoc +++ b/modules/ROOT/nav.adoc @@ -16,6 +16,7 @@ *** xref:exp-services-add-semantic.adoc[] *** xref:exp-services-view-details.adoc[] ** xref:exp-scanners-add-from-providers.adoc[] + *** xref:exp-scanners-prerequisites-reference.adoc[] *** xref:exp-scanners-manage.adoc[] ** xref:exp-providers-manage.adoc[] ** xref:exp-instances-add.adoc[] diff --git a/modules/ROOT/pages/exp-providers-manage.adoc b/modules/ROOT/pages/exp-providers-manage.adoc index 5e295b5c6..5cf841d45 100644 --- a/modules/ROOT/pages/exp-providers-manage.adoc +++ b/modules/ROOT/pages/exp-providers-manage.adoc @@ -76,12 +76,13 @@ For detailed scanner setup instructions, see xref:exp-scanners-add-from-provider The enhanced experience supports connections to these providers: +* Akamai * Amazon * Anthropic * Databricks -* GoDaddy ANS -* Google Cloud -* Kong Konnect +* GoDaddy +* Google +* Kong * Langchain * Microsoft * Snowflake diff --git a/modules/ROOT/pages/exp-scanners-add-from-providers.adoc b/modules/ROOT/pages/exp-scanners-add-from-providers.adoc index 8a18607b4..d76bded0a 100644 --- a/modules/ROOT/pages/exp-scanners-add-from-providers.adoc +++ b/modules/ROOT/pages/exp-scanners-add-from-providers.adoc @@ -20,6 +20,7 @@ Before getting started, make sure you have: -- + For more information, see xref:exp-home-start.adoc#permissions[Enhanced Experience Permissions]. +For provider-specific roles, credentials, and permission scopes, see xref:exp-scanners-prerequisites-reference.adoc[]. == Benefits of Provider Scanners @@ -43,9 +44,12 @@ Start from the general *Add Services* area and choose the path that connects a p * *Providers* + Use the area dedicated to provider and scanner management if your navigation includes it. Add or refine scanners alongside other provider work. ++ +The Akamai API Security scanner discovers security vulnerabilities in your Akamai-based applications and services. * *Portfolio* + -Open the catalog that matches the service type you want (*Agents*, *APIs*, *MCP Servers*, and others your tenant supports). Use that catalog's add control—the label indicates the type (for example *Add API*)—then choose provider connection to scan and discover services to add to that catalog. +Open the catalog that matches the service type you want (*Agents*, *APIs*, *MCP Servers*, and others your tenant supports). Use that catalog's add control—the label indicates the type (for example *Add API*)—then choose provider connection to scan and discover services to add to that catalog. Not all services have a catalog. If the service doesn't have a catalog, you can still add it to the system by using the *Add Service* button on the *Providers* page. + include::partial$exp-navigation-labels.adoc[tag=ExpNavigationLabels] @@ -61,6 +65,7 @@ For ongoing operations (pause, edit, or delete), see xref:exp-scanners-manage.ad == See Also +* xref:exp-scanners-prerequisites-reference.adoc[] * xref:exp-services-connect-providers-to-add.adoc[] * xref:exp-scanners-manage.adoc[] * xref:exp-services-add-to-portfolio.adoc[] diff --git a/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc b/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc new file mode 100644 index 000000000..d0ecac550 --- /dev/null +++ b/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc @@ -0,0 +1,205 @@ += Scanner Prerequisites by Provider +:keywords: scanner prerequisites, exchange scanners, provider scanners, required roles, required credentials, scanner setup + +Scanner prerequisites by provider help you confirm required roles, credentials, and permissions before creating a scanner. Use this reference to prevent connection test failures and incomplete discovery by validating provider-specific access in advance. Each scanner still requires Exchange Administrator permission and the correct business group context. + +== Before You Begin + +Before adding any scanner, make sure you have: + +* Exchange Administrator permission. +* Access to, and active context in, the business group where you want to add the scanner. + +== Scanner Prerequisites Cross-Reference + +[cols="1,1,1,2",options="header"] +|=== +| Scanner +| Scanner Type +| Required Roles +| Required Credentials and Permissions + +| Amazon Bedrock +| Agent +| Exchange Administrator +a| +* AWS region knowledge +* Access key ID and secret access key +* `bedrock:ListAgents` +* `bedrock:GetAgent` +* `bedrock:ListAgentAliases` +* `bedrock:GetAgentAlias` +* `bedrock:ListAgentVersions` +* `bedrock:GetAgentVersion` +* Optional for agent invocation workflows: `bedrock:InvokeModel`, `bedrock:InvokeAgent`, `bedrock:InvokeInlineAgent` +* Agents must have an alias linked to a version and an invocable URL + +| Amazon Bedrock AgentCore Runtime +| Agent +| Exchange Administrator +a| +* Active AWS account and AgentCore access +* AWS region +* Access key ID and secret access key +* `bedrock-agentcore:ListAgentRuntimes` +* `bedrock-agentcore:ListAgentRuntimeEndpoints` +* `bedrock-agentcore:GetAgentCard` +* `bedrock-agentcore:GetAgentRuntime` +* `bedrock-agentcore:ListAgentRuntimeVersions` +* `bedrock:GetAgent` +* `bedrock:ListAgents` +* Agents must be published with an active endpoint/version + +| Anthropic Claude Managed Agents +| Agent +| Exchange Administrator +a| +* Paid Anthropic account +* Claude API key + +| Databricks Agent Bricks +| Agent +| Exchange Administrator +a| +* Databricks workspace access +* Workspace URL +* Client ID and client secret +* Service principal `CAN_QUERY` on serving endpoints +* `CAN_VIEW` or higher on endpoint metadata APIs +* Discoverable agents must be custom Unity Catalog models in `READY` state + +| GoDaddy ANS +| Agent +| Exchange Administrator +a| +* API key +* API secret + +| Google Gemini Agent Enterprise Platform +| Agent +| Exchange Administrator, Vertex AI Viewer +a| +* GCP project ID +* Service account email +* Private key + +| LangChain LangSmith +| Agent +| Exchange Administrator +a| +* LangSmith Plus plan (or higher) workspace +* LangSmith API key +* LangSmith workspace ID +* Optional API host for region routing (for example, US or EU cloud host) + +| Microsoft Azure Copilot +| Agent +| Exchange Administrator, Copilot Studio Scanner Role +a| +* Azure app registration +* Tenant ID, client ID, client secret +* App added as an Application User in Power Platform +* Scope set to Dataverse environment URL + +| Microsoft Foundry +| Agent +| Exchange Administrator, Azure AI Developer +a| +* Active Azure subscription +* Azure app registration +* Tenant ID, client ID, client secret +* Project endpoint URLs (discovery is project-specific) + +| Snowflake Cortex AI +| Agent +| Exchange Administrator, Snowflake ACCOUNTADMIN +a| +* Snowflake account with Cortex Agents enabled (Enterprise edition) +* A user with `ACCOUNTADMIN` privileges for one-time setup only +* At least one Cortex Agent created in a schema to be scanned +* Scanner egress IP ranges from your Anypoint deployment team (``) +* Snowflake account URL +* Programmatic access token (PAT) + +| Amazon API Gateway +| API +| Exchange Administrator +a| +* IAM read-only policy for API Gateway (for example, `apigateway:GET`) +* AWS region knowledge +* AWS access key ID and secret access key + +| Azure API Management +| API +| Exchange Administrator, API Management Service Reader +a| +* Tenant ID +* Client ID +* Client secret +* Subscription ID +* Resource group +* Service name + +| Google Apigee +| API +| Exchange Administrator, Apigee Read-only Admin +a| +* GCP project ID +* Service account email +* Private key + +| Kong Gateway +| API +| Exchange Administrator, Kong Control Plane Viewer +a| +* Kong Gateway region +* Personal access token (PAT) + +| Akamai Security +| API Security +| Exchange Administrator +a| +* Akamai Security base URL +* Akamai Security client ID +* Akamai Security client secret +* Access to create service accounts in Akamai Security + +| Amazon Bedrock AgentCore MCP +| MCP +| Exchange Administrator +a| +* Active AWS account +* AWS region +* Access key ID and secret access key +* `bedrock-agentcore:ListAgentRuntimes` +* `bedrock-agentcore:GetAgentRuntime` +* `bedrock-agentcore:ListAgentRuntimeVersions` +* `bedrock-agentcore:ListAgentRuntimeEndpoints` +* `bedrock-agentcore:InvokeAgentRuntime` + +| Azure API Management MCP Server +| MCP +| Exchange Administrator, API Management Service Reader +a| +* Tenant ID +* Client ID +* Client secret +* Subscription ID +* Resource group +* Service name + +| Snowflake MCP Server +| MCP +| Exchange Administrator, Snowflake ACCOUNTADMIN +a| +* Snowflake Enterprise account with MCP servers enabled +* Snowflake account URL +* Programmatic access token (PAT) + +|=== + +== See Also + +* xref:exp-scanners-add-from-providers.adoc[] +* xref:exp-providers-manage.adoc[] +* xref:exp-scanners-manage.adoc[] diff --git a/modules/ROOT/pages/exp-services-add-to-portfolio.adoc b/modules/ROOT/pages/exp-services-add-to-portfolio.adoc index 6146e0d30..4abb6349c 100644 --- a/modules/ROOT/pages/exp-services-add-to-portfolio.adoc +++ b/modules/ROOT/pages/exp-services-add-to-portfolio.adoc @@ -63,6 +63,7 @@ For more information about registering any of these types, see xref:exp-services == See Also +* xref:exp-scanners-prerequisites-reference.adoc[] * xref:exp-services-connect-providers-to-add.adoc[] * xref:exp-services-register-manually.adoc[] * xref:exp-scanners-add-from-providers.adoc[] From 68dc21e17fe1acd08bfc4e0cf69ad978369d0e97 Mon Sep 17 00:00:00 2001 From: jenny hajee Date: Wed, 8 Jul 2026 18:21:48 -0500 Subject: [PATCH 02/21] added akamai integration topic and updated existing topics --- modules/ROOT/nav.adoc | 1 + .../exp-akamai-api-security-scanner.adoc | 64 +++++++++++++++++++ modules/ROOT/pages/exp-providers-manage.adoc | 4 ++ .../exp-scanners-add-from-providers.adoc | 14 +++- .../exp-scanners-prerequisites-reference.adoc | 2 + .../pages/exp-services-add-to-portfolio.adoc | 4 ++ 6 files changed, 87 insertions(+), 2 deletions(-) create mode 100644 modules/ROOT/pages/exp-akamai-api-security-scanner.adoc diff --git a/modules/ROOT/nav.adoc b/modules/ROOT/nav.adoc index 326c67b59..6db2ed8d8 100644 --- a/modules/ROOT/nav.adoc +++ b/modules/ROOT/nav.adoc @@ -16,6 +16,7 @@ *** xref:exp-services-add-semantic.adoc[] *** xref:exp-services-view-details.adoc[] ** xref:exp-scanners-add-from-providers.adoc[] + *** xref:exp-akamai-api-security-scanner.adoc[] *** xref:exp-scanners-prerequisites-reference.adoc[] *** xref:exp-scanners-manage.adoc[] ** xref:exp-providers-manage.adoc[] diff --git a/modules/ROOT/pages/exp-akamai-api-security-scanner.adoc b/modules/ROOT/pages/exp-akamai-api-security-scanner.adoc new file mode 100644 index 000000000..7a6aff311 --- /dev/null +++ b/modules/ROOT/pages/exp-akamai-api-security-scanner.adoc @@ -0,0 +1,64 @@ += Using Akamai API Security Scanner for Risk Correlation +:keywords: akamai api security scanner, akamai integration, security risk, vulnerability findings, incident correlation, portfolio catalogs + +Use Akamai API Security scanner to correlate security findings and risk signals with services that already exist in *Portfolio* catalogs. The scanner does not import or register third-party services. It applies Akamai security correlation so teams can review risk scores, findings, and incidents in one governance workflow for APIs, agents, and MCP services. + +== How Akamai Scanner Differs from Import Scanners + +Most provider scanners discover metadata in external platforms and import services into *Portfolio* catalogs. The Akamai API Security scanner works differently. It enriches existing services with security data from Akamai instead of creating new service records. + +== Before You Begin + +Before setting up the Akamai scanner, make sure you have: + +* Exchange Administrator permission in the target business group. +* Akamai Security base URL, client ID, and client secret. +* Access to apply Akamai correlation policy in the environments you want to scan. +* Existing APIs and MCP services in *Portfolio* catalogs for correlation targets. + +For credential and role details, see xref:exp-scanners-prerequisites-reference.adoc[]. + +== Set Up the Akamai Scanner + +. From *Platform* > *Providers*, select *Akamai*. +. Enter connection values, and test the connection. +. Enter scanner metadata, such as scanner name, description, frequency, and time. +. Apply the Akamai correlation policy to selected environments. +. Save the scanner and run a discovery scan. + +== Where Security Results Appear + +After a successful run, Akamai results appear on existing services: + +* API list views show values in the *Security Risk* column. +* API detail pages show Akamai security data in *Conformance*. +* Security sections display violation totals, findings, incidents, and endpoint context. +* Finding detail views show fields such as status, type, endpoint path, and mapped frameworks. + +== Interpret Risk Status Levels + +The *Security Risk* column shows the risk level assigned to correlated Akamai findings: + +Low:: +Lower urgency risk. Review and remediate in your normal security lifecycle. + +Medium:: +Moderate risk. Prioritize remediation after high-risk issues. + +High:: +Elevated risk. Investigate and remediate first. + +== Troubleshoot Missing Akamai Findings + +If a scan completes but results do not appear: + +* Verify correlation policy is applied in the same environment as the service instance. +* Confirm the target service already exists in *Portfolio* catalogs. +* Confirm scanner scope and business group match the service location. +* Re-run the scanner after connection or policy changes. + +== See Also + +* xref:exp-scanners-add-from-providers.adoc[] +* xref:exp-providers-manage.adoc[] +* xref:exp-scanners-manage.adoc[] diff --git a/modules/ROOT/pages/exp-providers-manage.adoc b/modules/ROOT/pages/exp-providers-manage.adoc index 5cf841d45..3e951615d 100644 --- a/modules/ROOT/pages/exp-providers-manage.adoc +++ b/modules/ROOT/pages/exp-providers-manage.adoc @@ -57,11 +57,14 @@ To see detailed information about a scanner, including scan history and settings Overview:: Displays services count, instances count, and scan history. Each scan history entry shows status (Success, Failed), timestamp, and number of new services discovered. ++ +For Akamai API Security scanners, the overview reflects correlation and security enrichment activity for existing services. Akamai scanners do not import new services. Settings:: Shows scanner configuration including provider, created date, last scanned time, and services count. Use this tab to modify scanner settings or delete the scanner. For information about managing scanners, see xref:exp-scanners-manage.adoc[]. +For Akamai-specific setup and result interpretation, see xref:exp-akamai-api-security-scanner.adoc[]. == Connect a New Provider @@ -97,6 +100,7 @@ The specific providers available depend on your organization's enabled products == See Also * xref:exp-services-connect-providers-to-add.adoc[] +* xref:exp-akamai-api-security-scanner.adoc[] * xref:exp-scanners-add-from-providers.adoc[] * xref:exp-scanners-manage.adoc[] * xref:exp-services-add-to-portfolio.adoc[] diff --git a/modules/ROOT/pages/exp-scanners-add-from-providers.adoc b/modules/ROOT/pages/exp-scanners-add-from-providers.adoc index d76bded0a..d676f0f54 100644 --- a/modules/ROOT/pages/exp-scanners-add-from-providers.adoc +++ b/modules/ROOT/pages/exp-scanners-add-from-providers.adoc @@ -45,13 +45,22 @@ Start from the general *Add Services* area and choose the path that connects a p + Use the area dedicated to provider and scanner management if your navigation includes it. Add or refine scanners alongside other provider work. + -The Akamai API Security scanner discovers security vulnerabilities in your Akamai-based applications and services. +The Akamai API Security scanner does not import services; it scans third-party provider security policies and surfaces vulnerability findings for related APIs, agents, and MCP services already in *Portfolio* catalogs. * *Portfolio* + Open the catalog that matches the service type you want (*Agents*, *APIs*, *MCP Servers*, and others your tenant supports). Use that catalog's add control—the label indicates the type (for example *Add API*)—then choose provider connection to scan and discover services to add to that catalog. Not all services have a catalog. If the service doesn't have a catalog, you can still add it to the system by using the *Add Service* button on the *Providers* page. -include::partial$exp-navigation-labels.adoc[tag=ExpNavigationLabels] +include::_partials/exp-navigation-labels.adoc[tag=ExpNavigationLabels] + +[IMPORTANT] +==== +The Akamai API Security scanner behaves differently from import-based scanners. It does not discover and import services from third-party providers into *Portfolio* catalogs. + +Instead, it scans third-party provider security policies and observed security data, correlates those results to existing services, and surfaces risk scores and vulnerability findings in related *Portfolio* catalogs. +==== + +For Akamai-specific setup and result interpretation, see xref:exp-akamai-api-security-scanner.adoc[]. == Scanner Configuration Overview @@ -66,6 +75,7 @@ For ongoing operations (pause, edit, or delete), see xref:exp-scanners-manage.ad == See Also * xref:exp-scanners-prerequisites-reference.adoc[] +* xref:exp-akamai-api-security-scanner.adoc[] * xref:exp-services-connect-providers-to-add.adoc[] * xref:exp-scanners-manage.adoc[] * xref:exp-services-add-to-portfolio.adoc[] diff --git a/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc b/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc index d0ecac550..bbfec81a2 100644 --- a/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc +++ b/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc @@ -163,6 +163,8 @@ a| * Akamai Security client ID * Akamai Security client secret * Access to create service accounts in Akamai Security +* Access to apply Akamai correlation policy in target environments +* Existing services in *Portfolio* catalogs for correlation targets | Amazon Bedrock AgentCore MCP | MCP diff --git a/modules/ROOT/pages/exp-services-add-to-portfolio.adoc b/modules/ROOT/pages/exp-services-add-to-portfolio.adoc index 4abb6349c..cc8d77d5a 100644 --- a/modules/ROOT/pages/exp-services-add-to-portfolio.adoc +++ b/modules/ROOT/pages/exp-services-add-to-portfolio.adoc @@ -10,6 +10,9 @@ Your *Portfolio* is organized into catalogs: *Agents*, *MCP Servers*, *LLM Proxi |xref:exp-services-connect-providers-to-add.adoc[] |You add a provider scanner from *Home* or from a catalog in *Portfolio*. Scans discover services on supported cloud platforms and register them in the matching catalog. +|xref:exp-akamai-api-security-scanner.adoc[] +|Akamai API Security scanner does not import or register services. It correlates Akamai security data to existing services and surfaces risk scores, findings, and incidents in catalog views. + |xref:exp-services-register-manually.adoc[] |You start an *Add …* workflow from *Home* or from the catalog for that service type. You supply metadata, specifications, endpoints, or cards to register the service without a provider scanner. |=== @@ -64,6 +67,7 @@ For more information about registering any of these types, see xref:exp-services == See Also * xref:exp-scanners-prerequisites-reference.adoc[] +* xref:exp-akamai-api-security-scanner.adoc[] * xref:exp-services-connect-providers-to-add.adoc[] * xref:exp-services-register-manually.adoc[] * xref:exp-scanners-add-from-providers.adoc[] From cf55b6ae2e46af2cc5f989b1cc4e5a79f30d249d Mon Sep 17 00:00:00 2001 From: jenny hajee Date: Wed, 8 Jul 2026 18:48:20 -0500 Subject: [PATCH 03/21] added scanner details page --- modules/ROOT/nav.adoc | 1 + .../exp-akamai-api-security-scanner.adoc | 8 ++++ modules/ROOT/pages/exp-providers-manage.adoc | 11 ++--- .../pages/exp-scanners-view-detail-tabs.adoc | 45 +++++++++++++++++++ 4 files changed, 57 insertions(+), 8 deletions(-) create mode 100644 modules/ROOT/pages/exp-scanners-view-detail-tabs.adoc diff --git a/modules/ROOT/nav.adoc b/modules/ROOT/nav.adoc index 6db2ed8d8..939f0d2bf 100644 --- a/modules/ROOT/nav.adoc +++ b/modules/ROOT/nav.adoc @@ -18,6 +18,7 @@ ** xref:exp-scanners-add-from-providers.adoc[] *** xref:exp-akamai-api-security-scanner.adoc[] *** xref:exp-scanners-prerequisites-reference.adoc[] + *** xref:exp-scanners-view-detail-tabs.adoc[] *** xref:exp-scanners-manage.adoc[] ** xref:exp-providers-manage.adoc[] ** xref:exp-instances-add.adoc[] diff --git a/modules/ROOT/pages/exp-akamai-api-security-scanner.adoc b/modules/ROOT/pages/exp-akamai-api-security-scanner.adoc index 7a6aff311..0cc3f223b 100644 --- a/modules/ROOT/pages/exp-akamai-api-security-scanner.adoc +++ b/modules/ROOT/pages/exp-akamai-api-security-scanner.adoc @@ -26,6 +26,13 @@ For credential and role details, see xref:exp-scanners-prerequisites-reference.a . Apply the Akamai correlation policy to selected environments. . Save the scanner and run a discovery scan. +== Review Scanner Detail Tabs + +After you select a configured Akamai scanner from the provider list, use scanner detail tabs to monitor scanner status, related services, and configuration values. + +For common tab behavior across scanners, see xref:exp-scanners-view-detail-tabs.adoc[]. +For Akamai scanners, the *Overview* tab highlights correlation policy status and enrichment activity for existing services. + == Where Security Results Appear After a successful run, Akamai results appear on existing services: @@ -61,4 +68,5 @@ If a scan completes but results do not appear: * xref:exp-scanners-add-from-providers.adoc[] * xref:exp-providers-manage.adoc[] +* xref:exp-scanners-view-detail-tabs.adoc[] * xref:exp-scanners-manage.adoc[] diff --git a/modules/ROOT/pages/exp-providers-manage.adoc b/modules/ROOT/pages/exp-providers-manage.adoc index 3e951615d..4920c5bc7 100644 --- a/modules/ROOT/pages/exp-providers-manage.adoc +++ b/modules/ROOT/pages/exp-providers-manage.adoc @@ -53,15 +53,9 @@ To view scanners for a specific provider, select the provider from the sidebar. == View Scanner Details -To see detailed information about a scanner, including scan history and settings, select the scanner name in the scanner list. The scanner detail page opens with two tabs: +To see detailed information about a scanner, including scan history and configuration, select the scanner name in the scanner list. The scanner detail page includes *Overview*, *Services*, and *Settings* tabs. -Overview:: -Displays services count, instances count, and scan history. Each scan history entry shows status (Success, Failed), timestamp, and number of new services discovered. -+ -For Akamai API Security scanners, the overview reflects correlation and security enrichment activity for existing services. Akamai scanners do not import new services. - -Settings:: -Shows scanner configuration including provider, created date, last scanned time, and services count. Use this tab to modify scanner settings or delete the scanner. +For detailed tab behavior and scanner-type differences, see xref:exp-scanners-view-detail-tabs.adoc[]. For information about managing scanners, see xref:exp-scanners-manage.adoc[]. For Akamai-specific setup and result interpretation, see xref:exp-akamai-api-security-scanner.adoc[]. @@ -101,6 +95,7 @@ The specific providers available depend on your organization's enabled products * xref:exp-services-connect-providers-to-add.adoc[] * xref:exp-akamai-api-security-scanner.adoc[] +* xref:exp-scanners-view-detail-tabs.adoc[] * xref:exp-scanners-add-from-providers.adoc[] * xref:exp-scanners-manage.adoc[] * xref:exp-services-add-to-portfolio.adoc[] diff --git a/modules/ROOT/pages/exp-scanners-view-detail-tabs.adoc b/modules/ROOT/pages/exp-scanners-view-detail-tabs.adoc new file mode 100644 index 000000000..8f4942b09 --- /dev/null +++ b/modules/ROOT/pages/exp-scanners-view-detail-tabs.adoc @@ -0,0 +1,45 @@ += Viewing Scanner Detail Tabs +:keywords: scanner detail tabs, scanner overview tab, scanner services tab, scanner settings tab, provider scanners + +Use scanner detail tabs to review scanner health, related services, and configuration values after you select a configured scanner from the provider list. All scanners expose the same tab structure: *Overview*, *Services*, and *Settings*. The information shown in each tab varies by scanner type and provider capabilities. + +== Open Scanner Detail Tabs + +. From *Platform* > *Providers*, open a connected provider. +. Select a configured scanner from the scanner list. +. Use the tabs to review scanner results and configuration. + +== Overview Tab + +Use *Overview* to check scanner summary information, such as: + +* Services and instances counts. +* Scan history and run status. +* Last scan time and scanner health indicators. + +For Akamai API Security scanners, the overview represents correlation and security enrichment activity for existing services. Akamai scanners do not import new services. + +== Services Tab + +Use *Services* to review services linked to the scanner and open service details for investigation. The tab reflects scanner-managed output for those services. + +For import scanners, this tab reflects discovered services imported by scan runs. For Akamai API Security scanners, it reflects existing services associated with correlated security data. + +== Settings Tab + +Use *Settings* to review and update scanner configuration values, such as provider connection details, run schedule, and scanner metadata. You can also delete the scanner from this tab. + +== How Tab Content Varies by Scanner Type + +Import scanners:: +Show imported discovery activity in scanner tabs, including newly discovered services. + +Akamai API Security scanner:: +Shows correlation and governance enrichment activity for existing services, including risk and findings signals. + +== See Also + +* xref:exp-providers-manage.adoc[] +* xref:exp-scanners-add-from-providers.adoc[] +* xref:exp-akamai-api-security-scanner.adoc[] +* xref:exp-scanners-manage.adoc[] From 5fd56fa698de61cdf31e8c51ab1d17dde631401a Mon Sep 17 00:00:00 2001 From: jenny hajee Date: Wed, 8 Jul 2026 19:14:05 -0500 Subject: [PATCH 04/21] edits --- modules/ROOT/nav.adoc | 2 +- modules/ROOT/pages/exp-akamai-api-security-scanner.adoc | 4 ++-- modules/ROOT/pages/exp-providers-manage.adoc | 4 ++-- ...view-detail-tabs.adoc => exp-scanners-view-details.adoc} | 6 +++--- 4 files changed, 8 insertions(+), 8 deletions(-) rename modules/ROOT/pages/{exp-scanners-view-detail-tabs.adoc => exp-scanners-view-details.adoc} (77%) diff --git a/modules/ROOT/nav.adoc b/modules/ROOT/nav.adoc index 939f0d2bf..8267256a7 100644 --- a/modules/ROOT/nav.adoc +++ b/modules/ROOT/nav.adoc @@ -18,7 +18,7 @@ ** xref:exp-scanners-add-from-providers.adoc[] *** xref:exp-akamai-api-security-scanner.adoc[] *** xref:exp-scanners-prerequisites-reference.adoc[] - *** xref:exp-scanners-view-detail-tabs.adoc[] + *** xref:exp-scanners-view-details.adoc[] *** xref:exp-scanners-manage.adoc[] ** xref:exp-providers-manage.adoc[] ** xref:exp-instances-add.adoc[] diff --git a/modules/ROOT/pages/exp-akamai-api-security-scanner.adoc b/modules/ROOT/pages/exp-akamai-api-security-scanner.adoc index 0cc3f223b..d501dae88 100644 --- a/modules/ROOT/pages/exp-akamai-api-security-scanner.adoc +++ b/modules/ROOT/pages/exp-akamai-api-security-scanner.adoc @@ -30,7 +30,7 @@ For credential and role details, see xref:exp-scanners-prerequisites-reference.a After you select a configured Akamai scanner from the provider list, use scanner detail tabs to monitor scanner status, related services, and configuration values. -For common tab behavior across scanners, see xref:exp-scanners-view-detail-tabs.adoc[]. +For common tab behavior across scanners, see xref:exp-scanners-view-details.adoc[]. For Akamai scanners, the *Overview* tab highlights correlation policy status and enrichment activity for existing services. == Where Security Results Appear @@ -68,5 +68,5 @@ If a scan completes but results do not appear: * xref:exp-scanners-add-from-providers.adoc[] * xref:exp-providers-manage.adoc[] -* xref:exp-scanners-view-detail-tabs.adoc[] +* xref:exp-scanners-view-details.adoc[] * xref:exp-scanners-manage.adoc[] diff --git a/modules/ROOT/pages/exp-providers-manage.adoc b/modules/ROOT/pages/exp-providers-manage.adoc index 4920c5bc7..12d021658 100644 --- a/modules/ROOT/pages/exp-providers-manage.adoc +++ b/modules/ROOT/pages/exp-providers-manage.adoc @@ -55,7 +55,7 @@ To view scanners for a specific provider, select the provider from the sidebar. To see detailed information about a scanner, including scan history and configuration, select the scanner name in the scanner list. The scanner detail page includes *Overview*, *Services*, and *Settings* tabs. -For detailed tab behavior and scanner-type differences, see xref:exp-scanners-view-detail-tabs.adoc[]. +For detailed tab behavior and scanner-type differences, see xref:exp-scanners-view-details.adoc[]. For information about managing scanners, see xref:exp-scanners-manage.adoc[]. For Akamai-specific setup and result interpretation, see xref:exp-akamai-api-security-scanner.adoc[]. @@ -95,7 +95,7 @@ The specific providers available depend on your organization's enabled products * xref:exp-services-connect-providers-to-add.adoc[] * xref:exp-akamai-api-security-scanner.adoc[] -* xref:exp-scanners-view-detail-tabs.adoc[] +* xref:exp-scanners-view-details.adoc[] * xref:exp-scanners-add-from-providers.adoc[] * xref:exp-scanners-manage.adoc[] * xref:exp-services-add-to-portfolio.adoc[] diff --git a/modules/ROOT/pages/exp-scanners-view-detail-tabs.adoc b/modules/ROOT/pages/exp-scanners-view-details.adoc similarity index 77% rename from modules/ROOT/pages/exp-scanners-view-detail-tabs.adoc rename to modules/ROOT/pages/exp-scanners-view-details.adoc index 8f4942b09..6e1277c87 100644 --- a/modules/ROOT/pages/exp-scanners-view-detail-tabs.adoc +++ b/modules/ROOT/pages/exp-scanners-view-details.adoc @@ -1,7 +1,7 @@ -= Viewing Scanner Detail Tabs += Viewing Scanner Details :keywords: scanner detail tabs, scanner overview tab, scanner services tab, scanner settings tab, provider scanners -Use scanner detail tabs to review scanner health, related services, and configuration values after you select a configured scanner from the provider list. All scanners expose the same tab structure: *Overview*, *Services*, and *Settings*. The information shown in each tab varies by scanner type and provider capabilities. +View details about a scanner and its scan history by selecting a configured scanner from the provider list. Scanner details show information about the provider, when if was created, last completed scan, and scan history. After you select a configured scanner, use *Overview*, *Services*, and *Settings* tabs to review scanner state and configuration, noting that tab content varies by scanner type and provider capabilities. == Open Scanner Detail Tabs @@ -17,7 +17,7 @@ Use *Overview* to check scanner summary information, such as: * Scan history and run status. * Last scan time and scanner health indicators. -For Akamai API Security scanners, the overview represents correlation and security enrichment activity for existing services. Akamai scanners do not import new services. +For Akamai API Security scanners, the overview represents correlation and security enrichment activity for existing services. Akamai scanners don't import new services. == Services Tab From c72a751dd9eba5701267b97b393a74cc05c53b5f Mon Sep 17 00:00:00 2001 From: jenny hajee Date: Wed, 8 Jul 2026 19:18:14 -0500 Subject: [PATCH 05/21] changed the nav order for scanners --- modules/ROOT/nav.adoc | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/modules/ROOT/nav.adoc b/modules/ROOT/nav.adoc index 8267256a7..14aa11146 100644 --- a/modules/ROOT/nav.adoc +++ b/modules/ROOT/nav.adoc @@ -16,10 +16,11 @@ *** xref:exp-services-add-semantic.adoc[] *** xref:exp-services-view-details.adoc[] ** xref:exp-scanners-add-from-providers.adoc[] - *** xref:exp-akamai-api-security-scanner.adoc[] + *** xref:exp-scanners-prerequisites-reference.adoc[] *** xref:exp-scanners-view-details.adoc[] *** xref:exp-scanners-manage.adoc[] + *** xref:exp-akamai-api-security-scanner.adoc[] ** xref:exp-providers-manage.adoc[] ** xref:exp-instances-add.adoc[] ** xref:exp-governance-work-with-strategies.adoc[] From f35062112f1558c33d7a6231b2640793add3970d Mon Sep 17 00:00:00 2001 From: jenny hajee Date: Wed, 15 Jul 2026 15:07:32 -0500 Subject: [PATCH 06/21] merged doc drift pr --- modules/ROOT/pages/exp-providers-manage.adoc | 13 ++++++++-- .../exp-scanners-add-from-providers.adoc | 26 +++++++++++++++++++ modules/ROOT/pages/exp-scanners-manage.adoc | 13 +++++++--- .../ROOT/pages/exp-services-view-details.adoc | 4 +-- 4 files changed, 48 insertions(+), 8 deletions(-) diff --git a/modules/ROOT/pages/exp-providers-manage.adoc b/modules/ROOT/pages/exp-providers-manage.adoc index 12d021658..ebf8c193d 100644 --- a/modules/ROOT/pages/exp-providers-manage.adoc +++ b/modules/ROOT/pages/exp-providers-manage.adoc @@ -65,15 +65,22 @@ For Akamai-specific setup and result interpretation, see xref:exp-akamai-api-sec To add a provider connection: . From *Platform* > *Providers*, select a provider from the *Not Connected* section. -. Follow the connection workflow to authenticate and configure scanner settings. +. Follow the connection workflow to authenticate and configure scanner settings. The wizard walks through three steps: *Choose Provider*, *Connect to Provider*, and *Connection Setup*. For detailed scanner setup instructions, see xref:exp-scanners-add-from-providers.adoc[]. +== Akamai API Security Data in Portfolio + +When Akamai API Security is connected and scans have completed, security risk data appears on the detail pages of scanned APIs: + +* A *Security Risk* column in the *Instances* tab shows a color-coded risk level per instance: Low, Medium, High, or Critical. +* An *Akamai* section in the *Conformance Report* tab shows full findings and incidents from the scan. + == Supported Providers The enhanced experience supports connections to these providers: -* Akamai +* Akamai API Security * Amazon * Anthropic * Databricks @@ -87,6 +94,8 @@ The enhanced experience supports connections to these providers: [NOTE] ==== When scanning Kong Konnect, the enhanced experience discovers gateway-level plugin information in addition to services. + +*Akamai API Security* is available only when your administrator has enabled the feature for your organization. When enabled, it appears in the *Not Connected* section of the Providers sidebar. ==== The specific providers available depend on your organization's enabled products and enhanced experience configuration. diff --git a/modules/ROOT/pages/exp-scanners-add-from-providers.adoc b/modules/ROOT/pages/exp-scanners-add-from-providers.adoc index d676f0f54..896c628a5 100644 --- a/modules/ROOT/pages/exp-scanners-add-from-providers.adoc +++ b/modules/ROOT/pages/exp-scanners-add-from-providers.adoc @@ -62,6 +62,32 @@ Instead, it scans third-party provider security policies and observed security d For Akamai-specific setup and result interpretation, see xref:exp-akamai-api-security-scanner.adoc[]. +NOTE: *Akamai API Security* appears in the provider list only when your administrator has enabled the Akamai API Security feature for your organization. + +== Akamai API Security Scanner + +When you add an Akamai API Security scanner, the wizard includes a final step — *Apply Akamai Correlation Policy* — after the scanner is saved. This step is required for Akamai to attribute its security findings back to your MuleSoft APIs. The policy stamps two correlation headers on API responses, so Akamai can match its scan results to the right instances. + +In this step: + +. Select the environments to apply the policy across. All environments are selected by default. +. Review the policy artifacts fetched live from Exchange (policy definition, Flex Gateway implementation, and Mule 4 implementation). The policy is zero-config and applies in the response phase only. +. Select *Apply policy & finish* to start the policy application, or *Skip — apply later* to proceed to the scanner detail page and apply from there. + +The time to apply varies by the number of API instances in the selected environments (typically one to six minutes for most organizations). API instances created after the policy is applied are automatically covered — no re-apply is needed. + +=== Monitor Correlation Policy Status + +After creating an Akamai scanner, the scanner detail page shows an *Akamai Correlation Policy* section with the live policy application status: + +* *Correlation policy not applied* — amber warning with an *Apply now* button. +* Partial — a progress indicator showing how many environments are covered while the apply workflow runs. +* *Applied* — green badge confirming all environments are covered. + +When the policy is applied, the section shows a table with one row per (environment, runtime) combination. Columns: Environment, Runtime (Flex Gateway or Mule 4), Status (Applied or Disabled), APIM Policy ID, and Asset Version. + +If some environments show no policy binding, select *Retry N missing* to retry the policy application for those environments only. The operation is safe to repeat. + == Scanner Configuration Overview Regardless of entry point, adding a scanner establishes trust and scope. You specify which provider platform to reach, how the system authenticates, and how you validate connectivity. You also name and schedule the scanner—or configure another trigger—so discovery runs on the cadence your team expects. Saving the configuration activates the scanner for the catalogs and features your administrator enabled. diff --git a/modules/ROOT/pages/exp-scanners-manage.adoc b/modules/ROOT/pages/exp-scanners-manage.adoc index f5a8685d9..ab8db3d1f 100644 --- a/modules/ROOT/pages/exp-scanners-manage.adoc +++ b/modules/ROOT/pages/exp-scanners-manage.adoc @@ -5,21 +5,26 @@ After you configure scanners, you run them day to day. Most of that work happens == Available Scanner Actions -* Run discovery on demand. +* *Run Discovery Scan* + Start a manual scan when you want fresh metadata without waiting for the next scheduled window. Successful runs update or add services in the matching *Portfolio* catalogs according to your rules. * Review status and history. + Inspect connection health, the last completed run, and scan history to verify whether discovery is healthy, slow, or failing authentication. -* Pause scheduled scans. +* *Pause Scheduled Runs* + Temporarily stop scheduled triggers when you need a quiet period—for example during maintenance or while you fix credentials—without deleting the scanner. -* Edit configuration. +* *Resume Scheduled Runs* + -Change names, descriptions, credentials, provider scope, or scan-related settings your product exposes, then save so future runs use the new definition. +Re-enable scheduled scanning after a pause. +* *Edit Settings* ++ +Change names, descriptions, credentials, provider scope, or scan-related settings your product exposes, then save, so future runs use the new definition. * Delete a scanner. + Remove the scanner from *Providers* when the provider link is no longer authorized or useful. Consider the impact on discovered services in *Portfolio* and on dependent teams before you delete the scanner. ++ +NOTE: When you delete an Akamai API Security scanner, the system attempts to remove the Akamai correlation policy from the scanner's environments. If the removal fails, the correlation policy may remain applied; check *Automated Policies* to verify. Discovered services remain in your portfolio regardless. == How Scanners Run diff --git a/modules/ROOT/pages/exp-services-view-details.adoc b/modules/ROOT/pages/exp-services-view-details.adoc index ec3023aa2..20f8c38d4 100644 --- a/modules/ROOT/pages/exp-services-view-details.adoc +++ b/modules/ROOT/pages/exp-services-view-details.adoc @@ -33,7 +33,7 @@ The page is organized into tabs. The following table lists each tab, what it sho |Yes |Yes |Yes |Yes |Yes |*Instances* -|Deployed instances, environments (for example production or sandbox), and gateways when that catalog type supports instances. +|Deployed instances, environments (for example production or sandbox), and gateways when that catalog type supports instances. When Akamai API Security is enabled and scan data is available for this service, the table also shows a *Security Risk* column with a color-coded risk level per instance (Low, Medium, High, or Critical). Risk levels are per-instance — the same API can show different risk levels across environments. |Yes |Yes |Yes |Each LLM Proxy is exactly one instance so there is no *Instances* tab. |No |*Policies* @@ -45,7 +45,7 @@ The page is organized into tabs. The following table lists each tab, what it sho |Yes |Yes |Yes |Yes |No |*Conformance Report* -|Compliance score and rule-level analysis for conformance reporting where that tab is available. +|Compliance score and rule-level analysis for conformance reporting where that tab is available. When Akamai API Security is enabled, the tab includes an *Akamai* section with a risk score overview, a findings table (endpoint-level vulnerabilities with severity, OWASP API Top-10 tags, and compliance framework tags), and an incidents table (aggregated security incidents). Select a finding to view details and see recommended remediation policies you can apply directly from this page. |Yes |Yes |Yes |No |No |=== From 7c4bbce37661bcaab392560b533e1da1aebbe494 Mon Sep 17 00:00:00 2001 From: jenny hajee Date: Thu, 16 Jul 2026 09:58:34 -0500 Subject: [PATCH 07/21] edits --- modules/ROOT/pages/exp-akamai-api-security-scanner.adoc | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/modules/ROOT/pages/exp-akamai-api-security-scanner.adoc b/modules/ROOT/pages/exp-akamai-api-security-scanner.adoc index d501dae88..26d227ee8 100644 --- a/modules/ROOT/pages/exp-akamai-api-security-scanner.adoc +++ b/modules/ROOT/pages/exp-akamai-api-security-scanner.adoc @@ -1,11 +1,11 @@ = Using Akamai API Security Scanner for Risk Correlation :keywords: akamai api security scanner, akamai integration, security risk, vulnerability findings, incident correlation, portfolio catalogs -Use Akamai API Security scanner to correlate security findings and risk signals with services that already exist in *Portfolio* catalogs. The scanner does not import or register third-party services. It applies Akamai security correlation so teams can review risk scores, findings, and incidents in one governance workflow for APIs, agents, and MCP services. +Use Akamai API Security scanner to correlate security findings and risk signals with services that already exist in *Portfolio* catalogs. The scanner doesn't import or register third-party services. It applies Akamai security correlation so teams can review risk scores, findings, and incidents in one governance workflow for APIs and MCP services. == How Akamai Scanner Differs from Import Scanners -Most provider scanners discover metadata in external platforms and import services into *Portfolio* catalogs. The Akamai API Security scanner works differently. It enriches existing services with security data from Akamai instead of creating new service records. +Most provider scanners discover metadata in external platforms and import services into *Portfolio* catalogs. The Akamai API Security scanner works differently. It enriches existing services with security data from Akamai instead of creating new services. == Before You Begin @@ -57,7 +57,7 @@ Elevated risk. Investigate and remediate first. == Troubleshoot Missing Akamai Findings -If a scan completes but results do not appear: +If a scan completes but results don't appear: * Verify correlation policy is applied in the same environment as the service instance. * Confirm the target service already exists in *Portfolio* catalogs. From 04627afc43c46dddb6c212a0218cd00cbcab54d0 Mon Sep 17 00:00:00 2001 From: jenny hajee Date: Thu, 16 Jul 2026 11:27:37 -0500 Subject: [PATCH 08/21] added more info about the scanner details page and added Services and Settings tabs --- modules/ROOT/pages/exp-akamai-api-security-scanner.adoc | 2 ++ modules/ROOT/pages/exp-providers-manage.adoc | 2 ++ 2 files changed, 4 insertions(+) diff --git a/modules/ROOT/pages/exp-akamai-api-security-scanner.adoc b/modules/ROOT/pages/exp-akamai-api-security-scanner.adoc index 26d227ee8..c67406c39 100644 --- a/modules/ROOT/pages/exp-akamai-api-security-scanner.adoc +++ b/modules/ROOT/pages/exp-akamai-api-security-scanner.adoc @@ -32,6 +32,8 @@ After you select a configured Akamai scanner from the provider list, use scanner For common tab behavior across scanners, see xref:exp-scanners-view-details.adoc[]. For Akamai scanners, the *Overview* tab highlights correlation policy status and enrichment activity for existing services. +The *Services* tab lists services associated with the scanner and shows which existing services are receiving correlated Akamai security data. +The *Settings* tab shows scanner configuration values, including schedule and provider connection values, and provides options to edit or delete the scanner. == Where Security Results Appear diff --git a/modules/ROOT/pages/exp-providers-manage.adoc b/modules/ROOT/pages/exp-providers-manage.adoc index ebf8c193d..bb5ad046e 100644 --- a/modules/ROOT/pages/exp-providers-manage.adoc +++ b/modules/ROOT/pages/exp-providers-manage.adoc @@ -76,6 +76,8 @@ When Akamai API Security is connected and scans have completed, security risk da * A *Security Risk* column in the *Instances* tab shows a color-coded risk level per instance: Low, Medium, High, or Critical. * An *Akamai* section in the *Conformance Report* tab shows full findings and incidents from the scan. +In list and card views, the numeric *Security Risk* value is the raw Akamai risk score, and the color-coded label (Low, Medium, High, or Critical) is the severity band derived from that score. + == Supported Providers The enhanced experience supports connections to these providers: From 4914fde2034c6248edc4003b539bf3e77458fb66 Mon Sep 17 00:00:00 2001 From: jenny hajee Date: Thu, 16 Jul 2026 12:59:24 -0500 Subject: [PATCH 09/21] edits --- .../ROOT/pages/exp-akamai-api-security-scanner.adoc | 13 ++++++++++++- modules/ROOT/pages/exp-providers-manage.adoc | 2 +- modules/ROOT/pages/exp-services-view-details.adoc | 2 +- 3 files changed, 14 insertions(+), 3 deletions(-) diff --git a/modules/ROOT/pages/exp-akamai-api-security-scanner.adoc b/modules/ROOT/pages/exp-akamai-api-security-scanner.adoc index c67406c39..45bf7168b 100644 --- a/modules/ROOT/pages/exp-akamai-api-security-scanner.adoc +++ b/modules/ROOT/pages/exp-akamai-api-security-scanner.adoc @@ -31,10 +31,21 @@ For credential and role details, see xref:exp-scanners-prerequisites-reference.a After you select a configured Akamai scanner from the provider list, use scanner detail tabs to monitor scanner status, related services, and configuration values. For common tab behavior across scanners, see xref:exp-scanners-view-details.adoc[]. -For Akamai scanners, the *Overview* tab highlights correlation policy status and enrichment activity for existing services. +For Akamai scanners, the *Overview* tab highlights correlation policy status and shows whether existing services are being updated with Akamai risk, findings, and incident data. The *Services* tab lists services associated with the scanner and shows which existing services are receiving correlated Akamai security data. The *Settings* tab shows scanner configuration values, including schedule and provider connection values, and provides options to edit or delete the scanner. +== Apply Missing Correlation Policies + +If some environments show that correlation policy isn't applied, you can apply missing policies from the scanner detail page: + +. Open *Platform* > *Providers* and select the configured Akamai scanner. +. In *Overview*, check the *Akamai Correlation Policy* status. +. If status shows missing environments, click *Retry * to apply policy only to those environments. +. Wait for status to change to *Applied* and confirm all target environments are covered. + +If policy application fails, verify your Admin API write permissions and environment access, then retry. + == Where Security Results Appear After a successful run, Akamai results appear on existing services: diff --git a/modules/ROOT/pages/exp-providers-manage.adoc b/modules/ROOT/pages/exp-providers-manage.adoc index bb5ad046e..1bb366bd8 100644 --- a/modules/ROOT/pages/exp-providers-manage.adoc +++ b/modules/ROOT/pages/exp-providers-manage.adoc @@ -76,7 +76,7 @@ When Akamai API Security is connected and scans have completed, security risk da * A *Security Risk* column in the *Instances* tab shows a color-coded risk level per instance: Low, Medium, High, or Critical. * An *Akamai* section in the *Conformance Report* tab shows full findings and incidents from the scan. -In list and card views, the numeric *Security Risk* value is the raw Akamai risk score, and the color-coded label (Low, Medium, High, or Critical) is the severity band derived from that score. +In list and card views, the numeric value shows Akamai correlation policy coverage (applied policies compared to total required policies), while the color-coded *Security Risk* label (Low, Medium, High, or Critical) shows the severity level of correlated security findings. == Supported Providers diff --git a/modules/ROOT/pages/exp-services-view-details.adoc b/modules/ROOT/pages/exp-services-view-details.adoc index 20f8c38d4..5736de2d3 100644 --- a/modules/ROOT/pages/exp-services-view-details.adoc +++ b/modules/ROOT/pages/exp-services-view-details.adoc @@ -44,7 +44,7 @@ The page is organized into tabs. The following table lists each tab, what it sho |Runtime metrics and analytics for health and usage when the system surfaces them for the service or gateway you are viewing. |Yes |Yes |Yes |Yes |No -|*Conformance Report* +|*Conformance* |Compliance score and rule-level analysis for conformance reporting where that tab is available. When Akamai API Security is enabled, the tab includes an *Akamai* section with a risk score overview, a findings table (endpoint-level vulnerabilities with severity, OWASP API Top-10 tags, and compliance framework tags), and an incidents table (aggregated security incidents). Select a finding to view details and see recommended remediation policies you can apply directly from this page. |Yes |Yes |Yes |No |No From c5d1fba6f3352b58bf800baead616ccc417c3ff4 Mon Sep 17 00:00:00 2001 From: jenny hajee Date: Thu, 16 Jul 2026 13:27:44 -0500 Subject: [PATCH 10/21] added how to remediate the akamai scanner findings in the Conformance tab of the API portfolio --- .../pages/exp-akamai-api-security-scanner.adoc | 14 +++++++++++++- 1 file changed, 13 insertions(+), 1 deletion(-) diff --git a/modules/ROOT/pages/exp-akamai-api-security-scanner.adoc b/modules/ROOT/pages/exp-akamai-api-security-scanner.adoc index 45bf7168b..97d9b86dc 100644 --- a/modules/ROOT/pages/exp-akamai-api-security-scanner.adoc +++ b/modules/ROOT/pages/exp-akamai-api-security-scanner.adoc @@ -41,7 +41,7 @@ If some environments show that correlation policy isn't applied, you can apply m . Open *Platform* > *Providers* and select the configured Akamai scanner. . In *Overview*, check the *Akamai Correlation Policy* status. -. If status shows missing environments, click *Retry * to apply policy only to those environments. +. If status shows missing environments, click *Retry N missing* to apply policy only to those environments. . Wait for status to change to *Applied* and confirm all target environments are covered. If policy application fails, verify your Admin API write permissions and environment access, then retry. @@ -68,6 +68,18 @@ Moderate risk. Prioritize remediation after high-risk issues. High:: Elevated risk. Investigate and remediate first. +== Remediate Risks from the API Conformance Tab + +Use the API *Conformance* tab in *Portfolio* to triage and remediate Akamai findings: + +. Open the API from the *APIs* catalog in *Portfolio*. +. Select *Conformance* and review the *Akamai* section, including findings and incidents. +. Select a finding to open details, such as endpoint, severity, and mapped standards. +. Apply recommended remediation policies directly from the finding detail view when available. +. Re-run the scanner after remediation to confirm updated findings and risk levels. + +If no direct remediation policy is available for a finding, use the finding details to update the API configuration in your gateway or upstream system, then scan again to verify the result. + == Troubleshoot Missing Akamai Findings If a scan completes but results don't appear: From 94f35d9e01a200f75aa24cd0969c23010e8a6aba Mon Sep 17 00:00:00 2001 From: jenny hajee Date: Thu, 16 Jul 2026 13:37:12 -0500 Subject: [PATCH 11/21] edit --- modules/ROOT/pages/exp-services-view-details.adoc | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/modules/ROOT/pages/exp-services-view-details.adoc b/modules/ROOT/pages/exp-services-view-details.adoc index 5736de2d3..407d56578 100644 --- a/modules/ROOT/pages/exp-services-view-details.adoc +++ b/modules/ROOT/pages/exp-services-view-details.adoc @@ -53,7 +53,7 @@ The page is organized into tabs. The following table lists each tab, what it sho ==== * *Instances* tab is available on *Agents*, *MCP Servers*, and *APIs*; *LLM Proxies* and *Gateways* do not include an *Instances* tab. See xref:exp-overview.adoc[]. -* *Conformance Report* on the detail page aligns with *Agents*, *APIs*, and *MCP Servers*; for gateways, compliance work is framed through *Governance* and related flows at the scope the system supports. See xref:exp-overview.adoc[]. +* *Conformance* on the detail page aligns with *Agents*, *APIs*, and *MCP Servers*; for gateways, compliance work is framed through *Governance* and related flows at the scope the system supports. See xref:exp-overview.adoc[]. ==== == Open a Service Detail Page From 8c194d191913893eb4643ca1327bd3682d7f961a Mon Sep 17 00:00:00 2001 From: Luana Dos Santos Date: Thu, 16 Jul 2026 16:42:05 -0300 Subject: [PATCH 12/21] W-23480092 docs: document Akamai security integration in exp-governance- topics - exp-governance-manage-strategies: fix column list, change filter description from dropdown to tabs, add View Strategy Details section for Governed Services tab + Security Risk column, add Akamai-Generated Strategy section - exp-governance-work-with-strategies: add Akamai Security Findings in Conformance Reports section covering KPI impact, Security Findings and Incidents tables, severity-to-tier mapping, finding and incident detail panels, and remediation workflow Co-Authored-By: Claude Sonnet 4.6 --- .../exp-governance-manage-strategies.adoc | 8 +++-- .../exp-governance-work-with-strategies.adoc | 32 +++++++++++++++++++ 2 files changed, 38 insertions(+), 2 deletions(-) diff --git a/modules/ROOT/pages/exp-governance-manage-strategies.adoc b/modules/ROOT/pages/exp-governance-manage-strategies.adoc index 129d17a36..368ed13b0 100644 --- a/modules/ROOT/pages/exp-governance-manage-strategies.adoc +++ b/modules/ROOT/pages/exp-governance-manage-strategies.adoc @@ -5,7 +5,7 @@ Keep governance strategies aligned with your portfolio by adjusting scope, rules == Display Governance Strategies -Go to *Governance* > *Governance Strategies* to view all strategies. Check the name, type, status, governed services, and last modified time. +Go to *Governance* > *Governance Strategies* to view all strategies. Check the strategy name, type, environment, target, status, governed services count, and last modified time. == Available Strategy Actions @@ -19,7 +19,7 @@ Go to *Governance* > *Governance Strategies* to view all strategies. Check the n Use the controls above the table to narrow the list: -* Use the strategy type filter to select *All*, *Controls*, or *Automated Policies*. +* Use the strategy type tabs to show *All*, *Controls*, or *Automated Policies*. * Use the status filter to select *Any Status*, *Active*, or *Disabled*. * Enter text in the search field to match strategy names. @@ -35,6 +35,10 @@ Review the summary cards: Use these cards to spot governance gaps quickly. +== Akamai-Generated Strategy + +When you connect Akamai API Security as a provider, the system automatically creates a pre-configured Akamai security strategy in the strategy list. This strategy attributes Akamai security findings to your MuleSoft APIs and MCP servers. Do not delete it unless you also remove the Akamai scanner, because deleting the strategy stops security findings from appearing in conformance reports. + == When to Adjust a Strategy Edit or disable a strategy when: diff --git a/modules/ROOT/pages/exp-governance-work-with-strategies.adoc b/modules/ROOT/pages/exp-governance-work-with-strategies.adoc index 382d8d1a0..6d240f0d0 100644 --- a/modules/ROOT/pages/exp-governance-work-with-strategies.adoc +++ b/modules/ROOT/pages/exp-governance-work-with-strategies.adoc @@ -38,6 +38,38 @@ Work with your governance lead when strategy changes affect production or compli * Review conformance reporting for xref:exp-overview.adoc[supported catalog types]. * Apply policies to services from *Portfolio*. See xref:exp-services-view-details.adoc[]. +== Akamai Security Findings in Conformance Reports + +When Akamai API Security is connected as a provider, the *Violations*, *Warnings*, and *Info* counts in the conformance report include Akamai security findings alongside governance rule results. A service can show a *Non-Conformant* status even when no governance rules are violated, if Akamai findings contribute violations. + +The Conformance tab includes a dedicated Akamai section with two tables: + +* *Security Findings*: Individual security issues detected by Akamai through live traffic inspection, broken down per instance and per endpoint. +* *Incidents*: Recurring threats aggregated over time, with first- and last-seen timestamps and occurrence counts. + +Both tables have the following columns, each sortable: *Finding*, *Instance*, *Endpoint*, and *Risk*. + +Akamai severity levels map to conformance tiers as follows: + +* Critical and High map to violations. +* Medium maps to warnings. +* Low and Info map to informational findings. + +The *Severity* filter at the top of the Conformance tab applies to both the governance rule results and the Akamai tables. + +=== Review a Finding + +Select a row in the *Security Findings* table to open the finding detail panel, which shows: + +* *Triggered On*: The endpoint path where the issue was detected. +* *Risk*: The severity level. +* *Exposure*: Whether the endpoint is internet-facing. +* *Remediation Opportunities*: Curated recommended policies for this finding type. Select *Apply This Policy* to open the policy-apply flow with the policy pre-selected. Select *Browse in Policy Library* if no curated policy is listed. After a policy is applied, Akamai re-inspects live traffic and updates the finding status automatically. + +=== Review an Incident + +Select a row in the *Incidents* table to open the incident detail panel, which shows: *Detection Time*, *Type*, *Triggered On*, *Severity*, *Occurrences*, *Exposure*, OWASP tags, and Compliance Frameworks. + == See Also * xref:exp-governance-create-strategy.adoc[] From 9711f52526399e3b20103dae46b52ac6770b2eb0 Mon Sep 17 00:00:00 2001 From: Luana Dos Santos <84200607+luanamulesoft@users.noreply.github.com> Date: Thu, 16 Jul 2026 16:45:09 -0300 Subject: [PATCH 13/21] Update exp-governance-manage-strategies.adoc --- modules/ROOT/pages/exp-governance-manage-strategies.adoc | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/modules/ROOT/pages/exp-governance-manage-strategies.adoc b/modules/ROOT/pages/exp-governance-manage-strategies.adoc index 368ed13b0..6cd558115 100644 --- a/modules/ROOT/pages/exp-governance-manage-strategies.adoc +++ b/modules/ROOT/pages/exp-governance-manage-strategies.adoc @@ -37,7 +37,7 @@ Use these cards to spot governance gaps quickly. == Akamai-Generated Strategy -When you connect Akamai API Security as a provider, the system automatically creates a pre-configured Akamai security strategy in the strategy list. This strategy attributes Akamai security findings to your MuleSoft APIs and MCP servers. Do not delete it unless you also remove the Akamai scanner, because deleting the strategy stops security findings from appearing in conformance reports. +When you connect Akamai API Security as a provider, the system automatically creates a pre-configured Akamai security strategy in the strategy list. This strategy attributes Akamai security findings to your MuleSoft APIs and MCP servers. Don't delete it unless you also remove the Akamai scanner. Deleting the strategy stops security findings from appearing in conformance reports. == When to Adjust a Strategy From 6e3af1f7240e3a111833deafebbc0ea39e42b54e Mon Sep 17 00:00:00 2001 From: Luana Dos Santos <84200607+luanamulesoft@users.noreply.github.com> Date: Thu, 16 Jul 2026 16:47:39 -0300 Subject: [PATCH 14/21] Update exp-governance-work-with-strategies.adoc --- modules/ROOT/pages/exp-governance-work-with-strategies.adoc | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/modules/ROOT/pages/exp-governance-work-with-strategies.adoc b/modules/ROOT/pages/exp-governance-work-with-strategies.adoc index 6d240f0d0..49fda78df 100644 --- a/modules/ROOT/pages/exp-governance-work-with-strategies.adoc +++ b/modules/ROOT/pages/exp-governance-work-with-strategies.adoc @@ -47,7 +47,7 @@ The Conformance tab includes a dedicated Akamai section with two tables: * *Security Findings*: Individual security issues detected by Akamai through live traffic inspection, broken down per instance and per endpoint. * *Incidents*: Recurring threats aggregated over time, with first- and last-seen timestamps and occurrence counts. -Both tables have the following columns, each sortable: *Finding*, *Instance*, *Endpoint*, and *Risk*. +Both tables have these sortable columns: *Finding*, *Instance*, *Endpoint*, and *Risk*. Akamai severity levels map to conformance tiers as follows: From c1acd44ab7913fc5c764e8e712f55aca09b33cf9 Mon Sep 17 00:00:00 2001 From: jenny hajee Date: Thu, 23 Jul 2026 15:46:30 -0500 Subject: [PATCH 15/21] edits for Managing scanners > Available Scanner actions --- modules/ROOT/pages/exp-scanners-manage.adoc | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/modules/ROOT/pages/exp-scanners-manage.adoc b/modules/ROOT/pages/exp-scanners-manage.adoc index ab8db3d1f..e6d81a226 100644 --- a/modules/ROOT/pages/exp-scanners-manage.adoc +++ b/modules/ROOT/pages/exp-scanners-manage.adoc @@ -8,7 +8,7 @@ After you configure scanners, you run them day to day. Most of that work happens * *Run Discovery Scan* + Start a manual scan when you want fresh metadata without waiting for the next scheduled window. Successful runs update or add services in the matching *Portfolio* catalogs according to your rules. -* Review status and history. +* *View Scanner* + Inspect connection health, the last completed run, and scan history to verify whether discovery is healthy, slow, or failing authentication. * *Pause Scheduled Runs* @@ -17,10 +17,10 @@ Temporarily stop scheduled triggers when you need a quiet period—for example d * *Resume Scheduled Runs* + Re-enable scheduled scanning after a pause. -* *Edit Settings* +* *Scanner Settings* + Change names, descriptions, credentials, provider scope, or scan-related settings your product exposes, then save, so future runs use the new definition. -* Delete a scanner. +* *Delete Scanner*. + Remove the scanner from *Providers* when the provider link is no longer authorized or useful. Consider the impact on discovered services in *Portfolio* and on dependent teams before you delete the scanner. + From a921f92feb89418f256fb742e454e8a05b19c351 Mon Sep 17 00:00:00 2001 From: jenny hajee Date: Mon, 27 Jul 2026 14:04:27 -0500 Subject: [PATCH 16/21] edits to scanner reference table --- modules/ROOT/nav.adoc | 5 +- ....adoc => exp-akamai-risk-correlation.adoc} | 9 +- modules/ROOT/pages/exp-providers-manage.adoc | 16 ++-- .../exp-scanners-add-from-providers.adoc | 26 ++---- .../exp-scanners-prerequisites-reference.adoc | 88 +++++++++++-------- .../ROOT/pages/exp-scanners-view-details.adoc | 2 +- .../pages/exp-services-add-to-portfolio.adoc | 4 +- 7 files changed, 75 insertions(+), 75 deletions(-) rename modules/ROOT/pages/{exp-akamai-api-security-scanner.adoc => exp-akamai-risk-correlation.adoc} (89%) diff --git a/modules/ROOT/nav.adoc b/modules/ROOT/nav.adoc index 14aa11146..120ab8c45 100644 --- a/modules/ROOT/nav.adoc +++ b/modules/ROOT/nav.adoc @@ -15,13 +15,12 @@ *** xref:exp-services-create-mcp-server.adoc[] *** xref:exp-services-add-semantic.adoc[] *** xref:exp-services-view-details.adoc[] + ** xref:exp-akamai-risk-correlation.adoc[] ** xref:exp-scanners-add-from-providers.adoc[] - *** xref:exp-scanners-prerequisites-reference.adoc[] *** xref:exp-scanners-view-details.adoc[] *** xref:exp-scanners-manage.adoc[] - *** xref:exp-akamai-api-security-scanner.adoc[] - ** xref:exp-providers-manage.adoc[] + ** xref:exp-providers-manage.adoc[] ** xref:exp-instances-add.adoc[] ** xref:exp-governance-work-with-strategies.adoc[] *** xref:exp-governance-create-strategy.adoc[] diff --git a/modules/ROOT/pages/exp-akamai-api-security-scanner.adoc b/modules/ROOT/pages/exp-akamai-risk-correlation.adoc similarity index 89% rename from modules/ROOT/pages/exp-akamai-api-security-scanner.adoc rename to modules/ROOT/pages/exp-akamai-risk-correlation.adoc index 97d9b86dc..ea867e768 100644 --- a/modules/ROOT/pages/exp-akamai-api-security-scanner.adoc +++ b/modules/ROOT/pages/exp-akamai-risk-correlation.adoc @@ -1,7 +1,7 @@ -= Using Akamai API Security Scanner for Risk Correlation += Using Akamai for Risk Correlation :keywords: akamai api security scanner, akamai integration, security risk, vulnerability findings, incident correlation, portfolio catalogs -Use Akamai API Security scanner to correlate security findings and risk signals with services that already exist in *Portfolio* catalogs. The scanner doesn't import or register third-party services. It applies Akamai security correlation so teams can review risk scores, findings, and incidents in one governance workflow for APIs and MCP services. +Use Akamai to correlate security findings and risk signals with services that already exist in *Portfolio* catalogs. The scanner doesn't import or register third-party services. It applies Akamai security correlation so teams can review risk scores, findings, and incidents in one governance workflow for APIs and MCP services. == How Akamai Scanner Differs from Import Scanners @@ -41,7 +41,7 @@ If some environments show that correlation policy isn't applied, you can apply m . Open *Platform* > *Providers* and select the configured Akamai scanner. . In *Overview*, check the *Akamai Correlation Policy* status. -. If status shows missing environments, click *Retry N missing* to apply policy only to those environments. +. If status shows missing environments, click *Check again* to apply policy only to those environments. . Wait for status to change to *Applied* and confirm all target environments are covered. If policy application fails, verify your Admin API write permissions and environment access, then retry. @@ -68,6 +68,9 @@ Moderate risk. Prioritize remediation after high-risk issues. High:: Elevated risk. Investigate and remediate first. +Critical:: +Highest urgency risk. Remediate immediately. + == Remediate Risks from the API Conformance Tab Use the API *Conformance* tab in *Portfolio* to triage and remediate Akamai findings: diff --git a/modules/ROOT/pages/exp-providers-manage.adoc b/modules/ROOT/pages/exp-providers-manage.adoc index 1bb366bd8..7bd55bacb 100644 --- a/modules/ROOT/pages/exp-providers-manage.adoc +++ b/modules/ROOT/pages/exp-providers-manage.adoc @@ -15,7 +15,7 @@ Before getting started, make sure you have: ** Exchange: Exchange Contributor ** API Manager: API Creator ** API Manager: Manage Policies --- +-- + For more information, see xref:exp-home-start.adoc#permissions[Enhanced Experience Permissions]. @@ -58,7 +58,7 @@ To see detailed information about a scanner, including scan history and configur For detailed tab behavior and scanner-type differences, see xref:exp-scanners-view-details.adoc[]. For information about managing scanners, see xref:exp-scanners-manage.adoc[]. -For Akamai-specific setup and result interpretation, see xref:exp-akamai-api-security-scanner.adoc[]. +For Akamai-specific setup and result interpretation, see xref:exp-akamai-risk-correlation.adoc[]. == Connect a New Provider @@ -82,20 +82,20 @@ In list and card views, the numeric value shows Akamai correlation policy covera The enhanced experience supports connections to these providers: -* Akamai API Security +* Akamai * Amazon * Anthropic * Databricks -* GoDaddy -* Google -* Kong +* GoDaddy +* Google +* Kong * Langchain * Microsoft * Snowflake [NOTE] ==== -When scanning Kong Konnect, the enhanced experience discovers gateway-level plugin information in addition to services. +When scanning Kong, the enhanced experience discovers gateway-level plugin information in addition to services. *Akamai API Security* is available only when your administrator has enabled the feature for your organization. When enabled, it appears in the *Not Connected* section of the Providers sidebar. ==== @@ -105,7 +105,7 @@ The specific providers available depend on your organization's enabled products == See Also * xref:exp-services-connect-providers-to-add.adoc[] -* xref:exp-akamai-api-security-scanner.adoc[] +* xref:exp-akamai-risk-correlation.adoc[] * xref:exp-scanners-view-details.adoc[] * xref:exp-scanners-add-from-providers.adoc[] * xref:exp-scanners-manage.adoc[] diff --git a/modules/ROOT/pages/exp-scanners-add-from-providers.adoc b/modules/ROOT/pages/exp-scanners-add-from-providers.adoc index 896c628a5..ba23ab39f 100644 --- a/modules/ROOT/pages/exp-scanners-add-from-providers.adoc +++ b/modules/ROOT/pages/exp-scanners-add-from-providers.adoc @@ -53,40 +53,26 @@ Open the catalog that matches the service type you want (*Agents*, *APIs*, *MCP include::_partials/exp-navigation-labels.adoc[tag=ExpNavigationLabels] -[IMPORTANT] -==== -The Akamai API Security scanner behaves differently from import-based scanners. It does not discover and import services from third-party providers into *Portfolio* catalogs. - -Instead, it scans third-party provider security policies and observed security data, correlates those results to existing services, and surfaces risk scores and vulnerability findings in related *Portfolio* catalogs. -==== - -For Akamai-specific setup and result interpretation, see xref:exp-akamai-api-security-scanner.adoc[]. - -NOTE: *Akamai API Security* appears in the provider list only when your administrator has enabled the Akamai API Security feature for your organization. == Akamai API Security Scanner -When you add an Akamai API Security scanner, the wizard includes a final step — *Apply Akamai Correlation Policy* — after the scanner is saved. This step is required for Akamai to attribute its security findings back to your MuleSoft APIs. The policy stamps two correlation headers on API responses, so Akamai can match its scan results to the right instances. - -In this step: +The Akamai API Security scanner behaves differently from import-based scanners. It does not discover and import services from third-party providers into *Portfolio* catalogs. Instead, it scans third-party provider security policies and observed security data, correlates those results to existing services, and surfaces risk scores and vulnerability findings in related *Portfolio* catalogs. *Akamai API Security* appears in the provider list only when your administrator has enabled the Akamai API Security feature for your organization. -. Select the environments to apply the policy across. All environments are selected by default. -. Review the policy artifacts fetched live from Exchange (policy definition, Flex Gateway implementation, and Mule 4 implementation). The policy is zero-config and applies in the response phase only. -. Select *Apply policy & finish* to start the policy application, or *Skip — apply later* to proceed to the scanner detail page and apply from there. +When you save an Akamai API Security scanner, the system automatically starts *Akamai Correlation Policy* application. This policy is required for Akamai to attribute security findings to your MuleSoft APIs by stamping correlation headers on API responses. -The time to apply varies by the number of API instances in the selected environments (typically one to six minutes for most organizations). API instances created after the policy is applied are automatically covered — no re-apply is needed. +For setup details, policy behavior, and result interpretation, see xref:exp-akamai-risk-correlation.adoc[]. === Monitor Correlation Policy Status After creating an Akamai scanner, the scanner detail page shows an *Akamai Correlation Policy* section with the live policy application status: -* *Correlation policy not applied* — amber warning with an *Apply now* button. +* *Correlation policy not applied* — amber warning with an *Apply policy now* button. * Partial — a progress indicator showing how many environments are covered while the apply workflow runs. * *Applied* — green badge confirming all environments are covered. When the policy is applied, the section shows a table with one row per (environment, runtime) combination. Columns: Environment, Runtime (Flex Gateway or Mule 4), Status (Applied or Disabled), APIM Policy ID, and Asset Version. -If some environments show no policy binding, select *Retry N missing* to retry the policy application for those environments only. The operation is safe to repeat. +If some environments show no policy binding, select *Check again* to retry the policy application for those environments only. The operation is safe to repeat. == Scanner Configuration Overview @@ -101,7 +87,7 @@ For ongoing operations (pause, edit, or delete), see xref:exp-scanners-manage.ad == See Also * xref:exp-scanners-prerequisites-reference.adoc[] -* xref:exp-akamai-api-security-scanner.adoc[] +* xref:exp-akamai-risk-correlation.adoc[] * xref:exp-services-connect-providers-to-add.adoc[] * xref:exp-scanners-manage.adoc[] * xref:exp-services-add-to-portfolio.adoc[] diff --git a/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc b/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc index bbfec81a2..2c0f84724 100644 --- a/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc +++ b/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc @@ -12,31 +12,31 @@ Before adding any scanner, make sure you have: == Scanner Prerequisites Cross-Reference -[cols="1,1,1,2",options="header"] +[cols="1,1,2,2",options="header"] |=== | Scanner | Scanner Type -| Required Roles -| Required Credentials and Permissions +| Required Credentials, Roles, and Permissions +| Required Scopes, Endpoints, and Other | Amazon Bedrock | Agent -| Exchange Administrator a| * AWS region knowledge * Access key ID and secret access key -* `bedrock:ListAgents` -* `bedrock:GetAgent` -* `bedrock:ListAgentAliases` -* `bedrock:GetAgentAlias` -* `bedrock:ListAgentVersions` -* `bedrock:GetAgentVersion` +* Amazon Bedrock permissions: +** `bedrock:ListAgents` +** `bedrock:GetAgent` +** `bedrock:ListAgentAliases` +** `bedrock:GetAgentAlias` +** `bedrock:ListAgentVersions` +** `bedrock:GetAgentVersion` * Optional for agent invocation workflows: `bedrock:InvokeModel`, `bedrock:InvokeAgent`, `bedrock:InvokeInlineAgent` -* Agents must have an alias linked to a version and an invocable URL + +| Agents must have an alias linked to a version and an invocable URL | Amazon Bedrock AgentCore Runtime | Agent -| Exchange Administrator a| * Active AWS account and AgentCore access * AWS region @@ -48,90 +48,95 @@ a| * `bedrock-agentcore:ListAgentRuntimeVersions` * `bedrock:GetAgent` * `bedrock:ListAgents` -* Agents must be published with an active endpoint/version + +| Agents must be published with an active endpoint/version | Anthropic Claude Managed Agents | Agent -| Exchange Administrator a| * Paid Anthropic account * Claude API key +| pass:[ ] | Databricks Agent Bricks | Agent -| Exchange Administrator a| * Databricks workspace access * Workspace URL * Client ID and client secret + +a| * Service principal `CAN_QUERY` on serving endpoints * `CAN_VIEW` or higher on endpoint metadata APIs * Discoverable agents must be custom Unity Catalog models in `READY` state | GoDaddy ANS | Agent -| Exchange Administrator a| * API key * API secret +| pass:[ ] | Google Gemini Agent Enterprise Platform | Agent -| Exchange Administrator, Vertex AI Viewer a| * GCP project ID * Service account email * Private key +* Vertex AI Viewer role +| pass:[ ] | LangChain LangSmith | Agent -| Exchange Administrator a| * LangSmith Plus plan (or higher) workspace * LangSmith API key * LangSmith workspace ID -* Optional API host for region routing (for example, US or EU cloud host) + +| Optional API host for region routing (for example, US or EU cloud host) | Microsoft Azure Copilot | Agent -| Exchange Administrator, Copilot Studio Scanner Role a| * Azure app registration * Tenant ID, client ID, client secret * App added as an Application User in Power Platform -* Scope set to Dataverse environment URL + +* Copilot Studio Scanner role +| Scope set to Dataverse environment URL | Microsoft Foundry | Agent -| Exchange Administrator, Azure AI Developer a| * Active Azure subscription * Azure app registration * Tenant ID, client ID, client secret -* Project endpoint URLs (discovery is project-specific) + +* Azure AI Developer role +| Project endpoint URLs (discovery is project-specific) | Snowflake Cortex AI | Agent -| Exchange Administrator, Snowflake ACCOUNTADMIN a| * Snowflake account with Cortex Agents enabled (Enterprise edition) * A user with `ACCOUNTADMIN` privileges for one-time setup only * At least one Cortex Agent created in a schema to be scanned -* Scanner egress IP ranges from your Anypoint deployment team (``) + * Snowflake account URL * Programmatic access token (PAT) +* Snowflake ACCOUNTADMIN role +| Scanner egress IP ranges from your Anypoint deployment team (``) | Amazon API Gateway | API -| Exchange Administrator a| * IAM read-only policy for API Gateway (for example, `apigateway:GET`) * AWS region knowledge * AWS access key ID and secret access key +| pass:[ ] | Azure API Management | API -| Exchange Administrator, API Management Service Reader a| * Tenant ID * Client ID @@ -139,25 +144,28 @@ a| * Subscription ID * Resource group * Service name +* API Management Service Reader role +| pass:[ ] | Google Apigee | API -| Exchange Administrator, Apigee Read-only Admin a| * GCP project ID * Service account email * Private key +* Apigee Read-only Admin role +| pass:[ ] | Kong Gateway | API -| Exchange Administrator, Kong Control Plane Viewer a| * Kong Gateway region * Personal access token (PAT) +* Kong Control Plane Viewer role +| pass:[ ] | Akamai Security | API Security -| Exchange Administrator a| * Akamai Security base URL * Akamai Security client ID @@ -165,23 +173,24 @@ a| * Access to create service accounts in Akamai Security * Access to apply Akamai correlation policy in target environments * Existing services in *Portfolio* catalogs for correlation targets +| pass:[ ] | Amazon Bedrock AgentCore MCP | MCP -| Exchange Administrator a| * Active AWS account * AWS region * Access key ID and secret access key -* `bedrock-agentcore:ListAgentRuntimes` -* `bedrock-agentcore:GetAgentRuntime` -* `bedrock-agentcore:ListAgentRuntimeVersions` -* `bedrock-agentcore:ListAgentRuntimeEndpoints` -* `bedrock-agentcore:InvokeAgentRuntime` +* An IAM user with an inline policy that allows these permissions: +** `bedrock-agentcore:ListAgentRuntimes` +** `bedrock-agentcore:GetAgentRuntime` +** `bedrock-agentcore:ListAgentRuntimeVersions` +** `bedrock-agentcore:ListAgentRuntimeEndpoints` +** `bedrock-agentcore:InvokeAgentRuntime` +| pass:[ ] | Azure API Management MCP Server | MCP -| Exchange Administrator, API Management Service Reader a| * Tenant ID * Client ID @@ -189,14 +198,17 @@ a| * Subscription ID * Resource group * Service name +* API Management Service Reader role +| pass:[ ] | Snowflake MCP Server | MCP -| Exchange Administrator, Snowflake ACCOUNTADMIN a| * Snowflake Enterprise account with MCP servers enabled * Snowflake account URL * Programmatic access token (PAT) +* Snowflake ACCOUNTADMIN role +| pass:[ ] |=== diff --git a/modules/ROOT/pages/exp-scanners-view-details.adoc b/modules/ROOT/pages/exp-scanners-view-details.adoc index 6e1277c87..559ea4116 100644 --- a/modules/ROOT/pages/exp-scanners-view-details.adoc +++ b/modules/ROOT/pages/exp-scanners-view-details.adoc @@ -41,5 +41,5 @@ Shows correlation and governance enrichment activity for existing services, incl * xref:exp-providers-manage.adoc[] * xref:exp-scanners-add-from-providers.adoc[] -* xref:exp-akamai-api-security-scanner.adoc[] +* xref:exp-akamai-risk-correlation.adoc[] * xref:exp-scanners-manage.adoc[] diff --git a/modules/ROOT/pages/exp-services-add-to-portfolio.adoc b/modules/ROOT/pages/exp-services-add-to-portfolio.adoc index cc8d77d5a..4fdfcd923 100644 --- a/modules/ROOT/pages/exp-services-add-to-portfolio.adoc +++ b/modules/ROOT/pages/exp-services-add-to-portfolio.adoc @@ -10,7 +10,7 @@ Your *Portfolio* is organized into catalogs: *Agents*, *MCP Servers*, *LLM Proxi |xref:exp-services-connect-providers-to-add.adoc[] |You add a provider scanner from *Home* or from a catalog in *Portfolio*. Scans discover services on supported cloud platforms and register them in the matching catalog. -|xref:exp-akamai-api-security-scanner.adoc[] +|xref:exp-akamai-risk-correlation.adoc[] |Akamai API Security scanner does not import or register services. It correlates Akamai security data to existing services and surfaces risk scores, findings, and incidents in catalog views. |xref:exp-services-register-manually.adoc[] @@ -67,7 +67,7 @@ For more information about registering any of these types, see xref:exp-services == See Also * xref:exp-scanners-prerequisites-reference.adoc[] -* xref:exp-akamai-api-security-scanner.adoc[] +* xref:exp-akamai-risk-correlation.adoc[] * xref:exp-services-connect-providers-to-add.adoc[] * xref:exp-services-register-manually.adoc[] * xref:exp-scanners-add-from-providers.adoc[] From 35a642ca1a117b7d2c7d47db443caa19e7534941 Mon Sep 17 00:00:00 2001 From: jenny hajee Date: Mon, 27 Jul 2026 15:35:16 -0500 Subject: [PATCH 17/21] nav update and fixed indentation --- modules/ROOT/nav.adoc | 12 ++++++------ modules/ROOT/pages/exp-akamai-risk-correlation.adoc | 4 +++- 2 files changed, 9 insertions(+), 7 deletions(-) diff --git a/modules/ROOT/nav.adoc b/modules/ROOT/nav.adoc index 120ab8c45..af8756bde 100644 --- a/modules/ROOT/nav.adoc +++ b/modules/ROOT/nav.adoc @@ -17,15 +17,15 @@ *** xref:exp-services-view-details.adoc[] ** xref:exp-akamai-risk-correlation.adoc[] ** xref:exp-scanners-add-from-providers.adoc[] - *** xref:exp-scanners-prerequisites-reference.adoc[] - *** xref:exp-scanners-view-details.adoc[] *** xref:exp-scanners-manage.adoc[] - ** xref:exp-providers-manage.adoc[] + ** xref:exp-scanners-prerequisites-reference.adoc[] + ** xref:exp-scanners-view-details.adoc[] + ** xref:exp-providers-manage.adoc[] ** xref:exp-instances-add.adoc[] ** xref:exp-governance-work-with-strategies.adoc[] - *** xref:exp-governance-create-strategy.adoc[] - *** xref:exp-governance-manage-strategies.adoc[] - *** xref:exp-governance-view-cost-and-token-usage.adoc[] + *** xref:exp-governance-create-strategy.adoc[] + *** xref:exp-governance-manage-strategies.adoc[] + *** xref:exp-governance-view-cost-and-token-usage.adoc[] ** xref:exp-services-monitoring.adoc[] ** xref:exp-services-view-detailed-metrics.adoc[] ** xref:exp-alerts-configure-notifications.adoc[] diff --git a/modules/ROOT/pages/exp-akamai-risk-correlation.adoc b/modules/ROOT/pages/exp-akamai-risk-correlation.adoc index ea867e768..39439e79b 100644 --- a/modules/ROOT/pages/exp-akamai-risk-correlation.adoc +++ b/modules/ROOT/pages/exp-akamai-risk-correlation.adoc @@ -1,7 +1,7 @@ = Using Akamai for Risk Correlation :keywords: akamai api security scanner, akamai integration, security risk, vulnerability findings, incident correlation, portfolio catalogs -Use Akamai to correlate security findings and risk signals with services that already exist in *Portfolio* catalogs. The scanner doesn't import or register third-party services. It applies Akamai security correlation so teams can review risk scores, findings, and incidents in one governance workflow for APIs and MCP services. +Use Akamai for risk correlation to map external security findings to the right services in *Portfolio*. Teams get one view to triage risk, track incidents, and remediate faster. To enable this correlation, configure an Akamai API Security scanner that connects your Akamai account, runs scheduled scans, and surfaces mapped findings on related services in *Portfolio*. The scanner does not import or register third-party services. It correlates risk scores, findings, and incidents for APIs and MCP services in one governance workflow. == How Akamai Scanner Differs from Import Scanners @@ -20,6 +20,8 @@ For credential and role details, see xref:exp-scanners-prerequisites-reference.a == Set Up the Akamai Scanner +Before you set up the scanner, review the prerequisites for Akamai scanners in xref:exp-scanners-prerequisites-reference.adoc[]. + . From *Platform* > *Providers*, select *Akamai*. . Enter connection values, and test the connection. . Enter scanner metadata, such as scanner name, description, frequency, and time. From 723dde437b34bc37078ab71fd8a994362bac20f6 Mon Sep 17 00:00:00 2001 From: jenny hajee Date: Mon, 27 Jul 2026 15:53:20 -0500 Subject: [PATCH 18/21] removed exp-scanners-add-from-providers.adoc duplicate from ROOT --- modules/ROOT/exp-scanners-add-from-providers.adoc | 0 1 file changed, 0 insertions(+), 0 deletions(-) delete mode 100644 modules/ROOT/exp-scanners-add-from-providers.adoc diff --git a/modules/ROOT/exp-scanners-add-from-providers.adoc b/modules/ROOT/exp-scanners-add-from-providers.adoc deleted file mode 100644 index e69de29bb..000000000 From 3b9c37cc0e0f63ef7b68084225dfea9dbbd4c509 Mon Sep 17 00:00:00 2001 From: jenny hajee Date: Mon, 27 Jul 2026 16:56:51 -0500 Subject: [PATCH 19/21] edits --- modules/ROOT/pages/exp-providers-manage.adoc | 4 ++-- modules/ROOT/pages/exp-scanners-manage.adoc | 2 +- modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc | 4 ++-- modules/ROOT/pages/exp-scanners-view-details.adoc | 2 +- 4 files changed, 6 insertions(+), 6 deletions(-) diff --git a/modules/ROOT/pages/exp-providers-manage.adoc b/modules/ROOT/pages/exp-providers-manage.adoc index 7bd55bacb..7dd211e18 100644 --- a/modules/ROOT/pages/exp-providers-manage.adoc +++ b/modules/ROOT/pages/exp-providers-manage.adoc @@ -24,7 +24,7 @@ For more information, see xref:exp-home-start.adoc#permissions[Enhanced Experien . Sign in to the enhanced experience through your organization's entry point. . In the navigation, select *Platform* > *Providers*. -The Providers page displays the provider list and scanner lists. +The Providers page displays the provider list and scanner list. == Provider List @@ -89,7 +89,7 @@ The enhanced experience supports connections to these providers: * GoDaddy * Google * Kong -* Langchain +* LangChain * Microsoft * Snowflake diff --git a/modules/ROOT/pages/exp-scanners-manage.adoc b/modules/ROOT/pages/exp-scanners-manage.adoc index e6d81a226..aa6a46685 100644 --- a/modules/ROOT/pages/exp-scanners-manage.adoc +++ b/modules/ROOT/pages/exp-scanners-manage.adoc @@ -20,7 +20,7 @@ Re-enable scheduled scanning after a pause. * *Scanner Settings* + Change names, descriptions, credentials, provider scope, or scan-related settings your product exposes, then save, so future runs use the new definition. -* *Delete Scanner*. +* *Delete Scanner* + Remove the scanner from *Providers* when the provider link is no longer authorized or useful. Consider the impact on discovered services in *Portfolio* and on dependent teams before you delete the scanner. + diff --git a/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc b/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc index 2c0f84724..a3ce94ce7 100644 --- a/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc +++ b/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc @@ -1,4 +1,4 @@ -= Scanner Prerequisites by Provider += Scanner Prerequisites by Provider :keywords: scanner prerequisites, exchange scanners, provider scanners, required roles, required credentials, scanner setup Scanner prerequisites by provider help you confirm required roles, credentials, and permissions before creating a scanner. Use this reference to prevent connection test failures and incomplete discovery by validating provider-specific access in advance. Each scanner still requires Exchange Administrator permission and the correct business group context. @@ -65,7 +65,7 @@ a| * Workspace URL * Client ID and client secret -a| +a| * Service principal `CAN_QUERY` on serving endpoints * `CAN_VIEW` or higher on endpoint metadata APIs * Discoverable agents must be custom Unity Catalog models in `READY` state diff --git a/modules/ROOT/pages/exp-scanners-view-details.adoc b/modules/ROOT/pages/exp-scanners-view-details.adoc index 559ea4116..7c7f0a7a6 100644 --- a/modules/ROOT/pages/exp-scanners-view-details.adoc +++ b/modules/ROOT/pages/exp-scanners-view-details.adoc @@ -1,7 +1,7 @@ = Viewing Scanner Details :keywords: scanner detail tabs, scanner overview tab, scanner services tab, scanner settings tab, provider scanners -View details about a scanner and its scan history by selecting a configured scanner from the provider list. Scanner details show information about the provider, when if was created, last completed scan, and scan history. After you select a configured scanner, use *Overview*, *Services*, and *Settings* tabs to review scanner state and configuration, noting that tab content varies by scanner type and provider capabilities. +View details about a scanner and its scan history by selecting a configured scanner from the provider list. Scanner details show information about the provider, when it was created, last completed scan, and scan history. After you select a configured scanner, use *Overview*, *Services*, and *Settings* tabs to review scanner state and configuration, noting that tab content varies by scanner type and provider capabilities. == Open Scanner Detail Tabs From 973e0c33f1868914552a3e14c7b60a62dcc3ed76 Mon Sep 17 00:00:00 2001 From: jenny hajee Date: Tue, 28 Jul 2026 10:20:27 -0500 Subject: [PATCH 20/21] added Akamai tenant setup and updated cross reference prerequisites --- .../pages/exp-akamai-risk-correlation.adoc | 30 +++ .../exp-scanners-prerequisites-reference.adoc | 193 +++++++----------- 2 files changed, 107 insertions(+), 116 deletions(-) diff --git a/modules/ROOT/pages/exp-akamai-risk-correlation.adoc b/modules/ROOT/pages/exp-akamai-risk-correlation.adoc index 39439e79b..1341b9516 100644 --- a/modules/ROOT/pages/exp-akamai-risk-correlation.adoc +++ b/modules/ROOT/pages/exp-akamai-risk-correlation.adoc @@ -3,6 +3,8 @@ Use Akamai for risk correlation to map external security findings to the right services in *Portfolio*. Teams get one view to triage risk, track incidents, and remediate faster. To enable this correlation, configure an Akamai API Security scanner that connects your Akamai account, runs scheduled scans, and surfaces mapped findings on related services in *Portfolio*. The scanner does not import or register third-party services. It correlates risk scores, findings, and incidents for APIs and MCP services in one governance workflow. +The integration relies on a bidirectional sync between your MuleSoft and Akamai API Security tenants: you connect the two tenants with credentials in each direction, Akamai reads your API assets and instances from MuleSoft so it can match its security observations to the correct APIs, and the scanner pulls the resulting findings and incidents back into *Portfolio*. + == How Akamai Scanner Differs from Import Scanners Most provider scanners discover metadata in external platforms and import services into *Portfolio* catalogs. The Akamai API Security scanner works differently. It enriches existing services with security data from Akamai instead of creating new services. @@ -18,6 +20,22 @@ Before setting up the Akamai scanner, make sure you have: For credential and role details, see xref:exp-scanners-prerequisites-reference.adoc[]. +== Set Up Tenant Connectivity + +The integration uses a bidirectional sync between your MuleSoft tenant and your Akamai API Security tenant. You provision and configure both tenants. Each MuleSoft customer tenant (root organization) connects to one Akamai API Security tenant (for example, `mulesoft-partner.example.com`). + +Setup involves credentials in both directions: + +* A *service account* in Akamai, which you configure on the MuleSoft side so the scanner can read findings and incidents from Akamai. +* A *connected app* in MuleSoft, which you configure on the Akamai side so Akamai can pull API asset and instance information from MuleSoft. + +Complete these steps as an organization administrator: + +. *Create a service account in Akamai API Security.* In your Akamai API Security tenant, create a service account and note its client ID, client secret, and organization ID. +. *Configure the scanner in MuleSoft.* Add an Akamai scanner and enter the Akamai service account credentials (client ID, client secret, and organization ID) and the Akamai base URL, along with a scan frequency. See <>. +. *Create a connected app in MuleSoft.* In Anypoint Platform, go to *Access Management* > *Connected Apps* and create an app that acts on its own behalf (client credentials). Add the *Exchange Viewer* or *Asset Viewer* scope so Akamai can read API instance and asset information, then save. Copy the client ID and client secret. +. *Configure the Akamai-side sync.* In your Akamai API Security tenant, enter the MuleSoft connected app client ID and client secret so Akamai can pull API asset and instance information from MuleSoft. + == Set Up the Akamai Scanner Before you set up the scanner, review the prerequisites for Akamai scanners in xref:exp-scanners-prerequisites-reference.adoc[]. @@ -28,6 +46,18 @@ Before you set up the scanner, review the prerequisites for Akamai scanners in x . Apply the Akamai correlation policy to selected environments. . Save the scanner and run a discovery scan. +== How the Sync Works + +After both tenants are connected, data flows in two directions: + +MuleSoft to Akamai:: +Akamai periodically pulls API instance and asset information from MuleSoft (typically every few hours) and adds it to its API security inventory. Akamai correlates these API instances with the north-south traffic it observes, so it can attach MuleSoft context — such as organization ID, environment ID, and API instance ID — to the endpoints it monitors. The pull runs at the root organization level. + +Akamai to MuleSoft:: +The scanner pulls security findings and incidents from Akamai on the schedule you set, then correlates and stores them so they appear on the related services in *Portfolio*. + +For Akamai to observe and correlate traffic, the Akamai correlation policy must be applied to your API instances. This out-of-the-box policy (for Flex Gateway and Mule gateways) stamps correlation headers on API responses so Akamai can match observed traffic to the correct MuleSoft API. Akamai observes north-south traffic only for domains you own and control; MuleSoft-owned domains such as `cloudhub.io` are excluded. + == Review Scanner Detail Tabs After you select a configured Akamai scanner from the provider list, use scanner detail tabs to monitor scanner status, related services, and configuration values. diff --git a/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc b/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc index a3ce94ce7..923233900 100644 --- a/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc +++ b/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc @@ -12,203 +12,163 @@ Before adding any scanner, make sure you have: == Scanner Prerequisites Cross-Reference -[cols="1,1,2,2",options="header"] +[cols="1,1,3",options="header"] |=== -| Scanner +| Provider | Scanner Type -| Required Credentials, Roles, and Permissions -| Required Scopes, Endpoints, and Other +| Required Credentials, Roles, and Setup | Amazon Bedrock | Agent a| -* AWS region knowledge -* Access key ID and secret access key -* Amazon Bedrock permissions: -** `bedrock:ListAgents` -** `bedrock:GetAgent` -** `bedrock:ListAgentAliases` -** `bedrock:GetAgentAlias` -** `bedrock:ListAgentVersions` -** `bedrock:GetAgentVersion` -* Optional for agent invocation workflows: `bedrock:InvokeModel`, `bedrock:InvokeAgent`, `bedrock:InvokeInlineAgent` +*Credentials:* Access key ID and secret access key; AWS region -| Agents must have an alias linked to a version and an invocable URL +*Permissions:* `bedrock:ListAgents`, `bedrock:GetAgent`, `bedrock:ListAgentAliases`, `bedrock:GetAgentAlias`, `bedrock:ListAgentVersions`, `bedrock:GetAgentVersion`; optional for agent invocation workflows: `bedrock:InvokeModel`, `bedrock:InvokeAgent`, `bedrock:InvokeInlineAgent` + +*Setup:* Agents must have an alias linked to a version and an invocable URL | Amazon Bedrock AgentCore Runtime | Agent a| -* Active AWS account and AgentCore access -* AWS region -* Access key ID and secret access key -* `bedrock-agentcore:ListAgentRuntimes` -* `bedrock-agentcore:ListAgentRuntimeEndpoints` -* `bedrock-agentcore:GetAgentCard` -* `bedrock-agentcore:GetAgentRuntime` -* `bedrock-agentcore:ListAgentRuntimeVersions` -* `bedrock:GetAgent` -* `bedrock:ListAgents` +*Credentials:* Access key ID and secret access key; AWS region + +*Account:* Active AWS account with AgentCore access -| Agents must be published with an active endpoint/version +*Permissions:* `bedrock-agentcore:ListAgentRuntimes`, `bedrock-agentcore:ListAgentRuntimeEndpoints`, `bedrock-agentcore:GetAgentCard`, `bedrock-agentcore:GetAgentRuntime`, `bedrock-agentcore:ListAgentRuntimeVersions`, `bedrock:GetAgent`, `bedrock:ListAgents` + +*Setup:* Agents must be published with an active endpoint/version | Anthropic Claude Managed Agents | Agent a| -* Paid Anthropic account -* Claude API key -| pass:[ ] +*Credentials:* Claude API key + +*Account:* Paid Anthropic account | Databricks Agent Bricks | Agent a| -* Databricks workspace access -* Workspace URL -* Client ID and client secret +*Credentials:* Workspace URL; client ID and client secret -a| -* Service principal `CAN_QUERY` on serving endpoints -* `CAN_VIEW` or higher on endpoint metadata APIs -* Discoverable agents must be custom Unity Catalog models in `READY` state +*Account:* Databricks workspace access + +*Permissions:* Service principal `CAN_QUERY` on serving endpoints; `CAN_VIEW` or higher on endpoint metadata APIs + +*Setup:* Discoverable agents must be custom Unity Catalog models in `READY` state | GoDaddy ANS | Agent a| -* API key -* API secret -| pass:[ ] +*Credentials:* API key and API secret | Google Gemini Agent Enterprise Platform | Agent a| -* GCP project ID -* Service account email -* Private key -* Vertex AI Viewer role -| pass:[ ] +*Credentials:* GCP project ID; service account email; private key + +*Role:* Vertex AI Viewer | LangChain LangSmith | Agent a| -* LangSmith Plus plan (or higher) workspace -* LangSmith API key -* LangSmith workspace ID +*Credentials:* LangSmith API key; LangSmith workspace ID + +*Account:* LangSmith Plus plan (or higher) workspace -| Optional API host for region routing (for example, US or EU cloud host) +*Setup:* Optional API host for region routing (for example, US or EU cloud host) | Microsoft Azure Copilot | Agent a| -* Azure app registration -* Tenant ID, client ID, client secret -* App added as an Application User in Power Platform +*Credentials:* Azure app registration; tenant ID, client ID, client secret + +*Role:* Copilot Studio Scanner -* Copilot Studio Scanner role -| Scope set to Dataverse environment URL +*Setup:* App added as an Application User in Power Platform; scope set to Dataverse environment URL | Microsoft Foundry | Agent a| -* Active Azure subscription -* Azure app registration -* Tenant ID, client ID, client secret +*Credentials:* Azure app registration; tenant ID, client ID, client secret -* Azure AI Developer role -| Project endpoint URLs (discovery is project-specific) +*Account:* Active Azure subscription + +*Role:* Azure AI Developer + +*Setup:* Project endpoint URLs (discovery is project-specific) | Snowflake Cortex AI | Agent a| -* Snowflake account with Cortex Agents enabled (Enterprise edition) -* A user with `ACCOUNTADMIN` privileges for one-time setup only -* At least one Cortex Agent created in a schema to be scanned +*Credentials:* Snowflake account URL; programmatic access token (PAT) + +*Account:* Snowflake account with Cortex Agents enabled (Enterprise edition) -* Snowflake account URL -* Programmatic access token (PAT) -* Snowflake ACCOUNTADMIN role -| Scanner egress IP ranges from your Anypoint deployment team (``) +*Role:* `ACCOUNTADMIN`, for one-time setup only + +*Setup:* At least one Cortex Agent created in a schema to be scanned; scanner egress IP ranges from your Anypoint deployment team (``) | Amazon API Gateway | API a| -* IAM read-only policy for API Gateway (for example, `apigateway:GET`) -* AWS region knowledge -* AWS access key ID and secret access key -| pass:[ ] +*Credentials:* Access key ID and secret access key; AWS region + +*Permissions:* IAM read-only policy for API Gateway (for example, `apigateway:GET`) | Azure API Management | API a| -* Tenant ID -* Client ID -* Client secret -* Subscription ID -* Resource group -* Service name -* API Management Service Reader role -| pass:[ ] +*Credentials:* Tenant ID; client ID; client secret; subscription ID; resource group; service name + +*Role:* API Management Service Reader | Google Apigee | API a| -* GCP project ID -* Service account email -* Private key -* Apigee Read-only Admin role -| pass:[ ] +*Credentials:* GCP project ID; service account email; private key + +*Role:* Apigee Read-only Admin | Kong Gateway | API a| -* Kong Gateway region -* Personal access token (PAT) -* Kong Control Plane Viewer role -| pass:[ ] +*Credentials:* Personal access token (PAT); Kong Gateway region + +*Role:* Kong Control Plane Viewer | Akamai Security | API Security a| -* Akamai Security base URL -* Akamai Security client ID -* Akamai Security client secret -* Access to create service accounts in Akamai Security -* Access to apply Akamai correlation policy in target environments -* Existing services in *Portfolio* catalogs for correlation targets -| pass:[ ] +*Credentials:* Akamai Security base URL; client ID; client secret; organization ID + +*Permissions:* Access to create service accounts in Akamai Security; access to apply Akamai correlation policy in target environments + +*Setup:* Existing services in *Portfolio* catalogs for correlation targets; create a connected app in MuleSoft; configure Akamai-side sync with the MuleSoft connected app. For details, see xref:exp-akamai-risk-correlation.adoc[]. | Amazon Bedrock AgentCore MCP | MCP a| -* Active AWS account -* AWS region -* Access key ID and secret access key -* An IAM user with an inline policy that allows these permissions: -** `bedrock-agentcore:ListAgentRuntimes` -** `bedrock-agentcore:GetAgentRuntime` -** `bedrock-agentcore:ListAgentRuntimeVersions` -** `bedrock-agentcore:ListAgentRuntimeEndpoints` -** `bedrock-agentcore:InvokeAgentRuntime` -| pass:[ ] +*Credentials:* Access key ID and secret access key; AWS region + +*Account:* Active AWS account + +*Permissions:* IAM user with an inline policy that allows `bedrock-agentcore:ListAgentRuntimes`, `bedrock-agentcore:GetAgentRuntime`, `bedrock-agentcore:ListAgentRuntimeVersions`, `bedrock-agentcore:ListAgentRuntimeEndpoints`, `bedrock-agentcore:InvokeAgentRuntime` | Azure API Management MCP Server | MCP a| -* Tenant ID -* Client ID -* Client secret -* Subscription ID -* Resource group -* Service name -* API Management Service Reader role -| pass:[ ] +*Credentials:* Tenant ID; client ID; client secret; subscription ID; resource group; service name + +*Role:* API Management Service Reader | Snowflake MCP Server | MCP a| -* Snowflake Enterprise account with MCP servers enabled -* Snowflake account URL -* Programmatic access token (PAT) -* Snowflake ACCOUNTADMIN role -| pass:[ ] +*Credentials:* Snowflake account URL; programmatic access token (PAT) + +*Account:* Snowflake Enterprise account with MCP servers enabled + +*Role:* `ACCOUNTADMIN` |=== @@ -217,3 +177,4 @@ a| * xref:exp-scanners-add-from-providers.adoc[] * xref:exp-providers-manage.adoc[] * xref:exp-scanners-manage.adoc[] +* xref:exp-akamai-risk-correlation.adoc[] From a79abca8b254448cbbdb53edb4883c5837438f42 Mon Sep 17 00:00:00 2001 From: jenny hajee Date: Tue, 28 Jul 2026 10:59:32 -0500 Subject: [PATCH 21/21] added Akamai tenant setup --- .../exp-scanners-prerequisites-reference.adoc | 33 +++++++++++++++++-- 1 file changed, 30 insertions(+), 3 deletions(-) diff --git a/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc b/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc index 923233900..77d7deb1d 100644 --- a/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc +++ b/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc @@ -23,7 +23,20 @@ Before adding any scanner, make sure you have: a| *Credentials:* Access key ID and secret access key; AWS region -*Permissions:* `bedrock:ListAgents`, `bedrock:GetAgent`, `bedrock:ListAgentAliases`, `bedrock:GetAgentAlias`, `bedrock:ListAgentVersions`, `bedrock:GetAgentVersion`; optional for agent invocation workflows: `bedrock:InvokeModel`, `bedrock:InvokeAgent`, `bedrock:InvokeInlineAgent` +*Permissions:* + +* `bedrock:ListAgents` +* `bedrock:GetAgent` +* `bedrock:ListAgentAliases` +* `bedrock:GetAgentAlias` +* `bedrock:ListAgentVersions` +* `bedrock:GetAgentVersion` + +*Optional (for agent invocation workflows):* + +* `bedrock:InvokeModel` +* `bedrock:InvokeAgent` +* `bedrock:InvokeInlineAgent` *Setup:* Agents must have an alias linked to a version and an invocable URL @@ -34,7 +47,15 @@ a| *Account:* Active AWS account with AgentCore access -*Permissions:* `bedrock-agentcore:ListAgentRuntimes`, `bedrock-agentcore:ListAgentRuntimeEndpoints`, `bedrock-agentcore:GetAgentCard`, `bedrock-agentcore:GetAgentRuntime`, `bedrock-agentcore:ListAgentRuntimeVersions`, `bedrock:GetAgent`, `bedrock:ListAgents` +*Permissions:* + +* `bedrock-agentcore:ListAgentRuntimes` +* `bedrock-agentcore:ListAgentRuntimeEndpoints` +* `bedrock-agentcore:GetAgentCard` +* `bedrock-agentcore:GetAgentRuntime` +* `bedrock-agentcore:ListAgentRuntimeVersions` +* `bedrock:GetAgent` +* `bedrock:ListAgents` *Setup:* Agents must be published with an active endpoint/version @@ -152,7 +173,13 @@ a| *Account:* Active AWS account -*Permissions:* IAM user with an inline policy that allows `bedrock-agentcore:ListAgentRuntimes`, `bedrock-agentcore:GetAgentRuntime`, `bedrock-agentcore:ListAgentRuntimeVersions`, `bedrock-agentcore:ListAgentRuntimeEndpoints`, `bedrock-agentcore:InvokeAgentRuntime` +*Permissions:* IAM user with an inline policy that allows: + +* `bedrock-agentcore:ListAgentRuntimes` +* `bedrock-agentcore:GetAgentRuntime` +* `bedrock-agentcore:ListAgentRuntimeVersions` +* `bedrock-agentcore:ListAgentRuntimeEndpoints` +* `bedrock-agentcore:InvokeAgentRuntime` | Azure API Management MCP Server | MCP