From f9a8a3f246dd87f3573d2f263d27171e0f784da4 Mon Sep 17 00:00:00 2001 From: jenny hajee Date: Mon, 13 Jul 2026 21:20:38 -0500 Subject: [PATCH 01/11] added scanner provider prerequisites reference with discover, import and read policy creds --- .../exp-provider-prerequisites-reference.adoc | 219 ++++++++++++++++++ .../exp-scanners-prerequisites-reference.adoc | 219 ++++++++++++++++++ 2 files changed, 438 insertions(+) create mode 100644 modules/ROOT/pages/exp-provider-prerequisites-reference.adoc create mode 100644 modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc diff --git a/modules/ROOT/pages/exp-provider-prerequisites-reference.adoc b/modules/ROOT/pages/exp-provider-prerequisites-reference.adoc new file mode 100644 index 000000000..a52f58409 --- /dev/null +++ b/modules/ROOT/pages/exp-provider-prerequisites-reference.adoc @@ -0,0 +1,219 @@ += Scanner Prerequisites Reference +:keywords: scanner prerequisites, exchange scanners, provider scanners, required roles, required credentials, scanner setup + +Scanner prerequisites by provider help you confirm required roles, credentials, and permissions before creating a scanner. Use this reference to prevent connection test failures and incomplete discovery by validating provider-specific access in advance. Each scanner still requires Exchange Administrator permission and the correct business group context. + +== Before You Begin + +Before adding any scanner, make sure you have: + +* Exchange Administrator permission. +* Access to, and active context in, the business group where you want to add the scanner. + +== Scanner Prerequisites Cross-Reference + +In the table, bullets prefixed with *Policy Read* identify permissions, roles, or scopes required specifically for policy-read scanning. + +[cols="1,1,1,2",options="header"] +|=== +| Scanner +| Scanner Type +| Required Roles +| Required Credentials and Permissions + +| Amazon Bedrock +| Agent +| Exchange Administrator +a| +* AWS region knowledge +* Access key ID and secret access key +* `bedrock:ListAgents` +* `bedrock:GetAgent` +* `bedrock:ListAgentAliases` +* `bedrock:GetAgentAlias` +* `bedrock:ListAgentVersions` +* `bedrock:GetAgentVersion` +* Optional for agent invocation workflows: `bedrock:InvokeModel`, `bedrock:InvokeAgent`, `bedrock:InvokeInlineAgent` +* Policy Read permissions: `bedrock:ListAgents`, `bedrock:GetAgent`, and `bedrock:ListAgentAliases` +* Agents must have an alias linked to a version and an invocable URL + +| Amazon Bedrock AgentCore Runtime +| Agent +| Exchange Administrator +a| +* Active AWS account and AgentCore access +* AWS region +* Access key ID and secret access key +* `bedrock-agentcore:ListAgentRuntimes` +* `bedrock-agentcore:ListAgentRuntimeEndpoints` +* `bedrock-agentcore:GetAgentCard` +* `bedrock-agentcore:GetAgentRuntime` +* `bedrock-agentcore:ListAgentRuntimeVersions` +* `bedrock:GetAgent` +* `bedrock:ListAgents` +* Agents must be published with an active endpoint/version + +| Anthropic Claude Managed Agents +| Agent +| Exchange Administrator +a| +* Paid Anthropic account +* Claude API key + +| Databricks Agent Bricks +| Agent +| Exchange Administrator +a| +* Databricks workspace access +* Workspace URL +* Client ID and client secret +* Service principal `CAN_QUERY` on serving endpoints +* `CAN_VIEW` or higher on endpoint metadata APIs +* Discoverable agents must be custom Unity Catalog models in `READY` state + +| GoDaddy ANS +| Agent +| Exchange Administrator +a| +* API key +* API secret + +| Google Gemini Agent Enterprise Platform +| Agent +| Exchange Administrator, Vertex AI Viewer +a| +* GCP project ID +* Service account email +* Private key + +| LangChain LangSmith +| Agent +| Exchange Administrator +a| +* LangSmith Plus plan (or higher) workspace +* LangSmith API key +* LangSmith workspace ID +* Optional API host for region routing (for example, US or EU cloud host) + +| Microsoft Azure Copilot +| Agent +| Exchange Administrator, Copilot Studio Scanner Role +a| +* Azure app registration +* Tenant ID, client ID, client secret +* App added as an Application User in Power Platform +* Scope set to Dataverse environment URL + +| Microsoft Foundry +| Agent +| Exchange Administrator, Azure AI Developer +a| +* Active Azure subscription +* Azure app registration +* Tenant ID, client ID, client secret +* Project endpoint URLs (discovery is project-specific) + +| Snowflake Cortex AI +| Agent +| Exchange Administrator, Snowflake ACCOUNTADMIN +a| +* Snowflake account with Cortex Agents enabled (Enterprise edition) +* A user with `ACCOUNTADMIN` privileges for one-time setup only +* At least one Cortex Agent created in a schema to be scanned +* Scanner egress IP ranges from your Anypoint deployment team (``) +* Snowflake account URL +* Programmatic access token (PAT) + +| Amazon API Gateway +| API +| Exchange Administrator +a| +* IAM read-only policy for API Gateway (for example, `apigateway:GET`) +* Policy Read permission: `apigateway:GET` +* Policy Read action group: `apigateway:GET*` on REST and HTTP API resources +* Policy Read resource scope (REST APIs): `arn:aws:apigateway:{region}::/restapis/*` +* Policy Read resource scope (HTTP APIs): `arn:aws:apigateway:{region}::/apis/*` +* Policy Read note: for WAF-oriented extraction, scanner integrations also use WAFv2 and Route53 SDK access +* AWS region knowledge +* AWS access key ID and secret access key + +| Azure API Management +| API +| Exchange Administrator, API Management Service Reader +a| +* Policy Read role scope: API Management Service Reader at APIM resource or resource group scope +* Policy Read OAuth scope: `https://management.azure.com/.default` +* Tenant ID +* Client ID +* Client secret +* Subscription ID +* Resource group +* Service name + +| Google Apigee +| API +| Exchange Administrator, Apigee Read-only Admin +a| +* Policy Read role: service account with Viewer role or an Apigee permission role with equivalent read access +* GCP project ID +* Service account email +* Private key + +| Kong Gateway +| API +| Exchange Administrator, Kong Control Plane Viewer +a| +* Kong Gateway region +* Personal access token (PAT) + +| Akamai Security +| API Security +| Exchange Administrator +a| +* Akamai Security base URL +* Akamai Security client ID +* Akamai Security client secret +* Access to create service accounts in Akamai Security +* Access to apply Akamai correlation policy in target environments +* Existing services in *Portfolio* catalogs for correlation targets + +| Amazon Bedrock AgentCore MCP +| MCP +| Exchange Administrator +a| +* Active AWS account +* AWS region +* Access key ID and secret access key +* `bedrock-agentcore:ListAgentRuntimes` +* `bedrock-agentcore:GetAgentRuntime` +* `bedrock-agentcore:ListAgentRuntimeVersions` +* `bedrock-agentcore:ListAgentRuntimeEndpoints` +* `bedrock-agentcore:InvokeAgentRuntime` +* Policy Read permissions: runtime read actions, including `bedrock-agentcore:ListAgentRuntimes` and `bedrock-agentcore:GetAgentRuntime` + +| Azure API Management MCP Server +| MCP +| Exchange Administrator, API Management Service Reader +a| +* Tenant ID +* Client ID +* Client secret +* Subscription ID +* Resource group +* Service name + +| Snowflake MCP Server +| MCP +| Exchange Administrator, Snowflake ACCOUNTADMIN +a| +* Snowflake Enterprise account with MCP servers enabled +* Snowflake account URL +* Programmatic access token (PAT) + +|=== + +== See Also + +* xref:exp-scanners-add-from-providers.adoc[] +* xref:exp-providers-manage.adoc[] +* xref:exp-scanners-manage.adoc[] diff --git a/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc b/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc new file mode 100644 index 000000000..ca978630f --- /dev/null +++ b/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc @@ -0,0 +1,219 @@ += Provider Prerequisites Reference +:keywords: scanner prerequisites, exchange scanners, provider scanners, required roles, required credentials, scanner setup + +Scanner prerequisites by provider help you confirm required roles, credentials, and permissions before creating a scanner. Use this reference to prevent connection test failures and incomplete discovery by validating provider-specific access in advance. Each scanner still requires Exchange Administrator permission and the correct business group context. + +== Before You Begin + +Before adding any scanner, make sure you have: + +* Exchange Administrator permission. +* Access to, and active context in, the business group where you want to add the scanner. + +== Scanner Prerequisites Cross-Reference + +In the table, bullets prefixed with *Policy Read* identify permissions, roles, or scopes required specifically for policy-read scanning. + +[cols="1,1,1,2",options="header"] +|=== +| Scanner +| Scanner Type +| Required Roles +| Required Credentials and Permissions + +| Amazon Bedrock +| Agent +| Exchange Administrator +a| +* AWS region knowledge +* Access key ID and secret access key +* `bedrock:ListAgents` +* `bedrock:GetAgent` +* `bedrock:ListAgentAliases` +* `bedrock:GetAgentAlias` +* `bedrock:ListAgentVersions` +* `bedrock:GetAgentVersion` +* Optional for agent invocation workflows: `bedrock:InvokeModel`, `bedrock:InvokeAgent`, `bedrock:InvokeInlineAgent` +* Policy Read permissions: `bedrock:ListAgents`, `bedrock:GetAgent`, and `bedrock:ListAgentAliases` +* Agents must have an alias linked to a version and an invocable URL + +| Amazon Bedrock AgentCore Runtime +| Agent +| Exchange Administrator +a| +* Active AWS account and AgentCore access +* AWS region +* Access key ID and secret access key +* `bedrock-agentcore:ListAgentRuntimes` +* `bedrock-agentcore:ListAgentRuntimeEndpoints` +* `bedrock-agentcore:GetAgentCard` +* `bedrock-agentcore:GetAgentRuntime` +* `bedrock-agentcore:ListAgentRuntimeVersions` +* `bedrock:GetAgent` +* `bedrock:ListAgents` +* Agents must be published with an active endpoint/version + +| Anthropic Claude Managed Agents +| Agent +| Exchange Administrator +a| +* Paid Anthropic account +* Claude API key + +| Databricks Agent Bricks +| Agent +| Exchange Administrator +a| +* Databricks workspace access +* Workspace URL +* Client ID and client secret +* Service principal `CAN_QUERY` on serving endpoints +* `CAN_VIEW` or higher on endpoint metadata APIs +* Discoverable agents must be custom Unity Catalog models in `READY` state + +| GoDaddy ANS +| Agent +| Exchange Administrator +a| +* API key +* API secret + +| Google Gemini Agent Enterprise Platform +| Agent +| Exchange Administrator, Vertex AI Viewer +a| +* GCP project ID +* Service account email +* Private key + +| LangChain LangSmith +| Agent +| Exchange Administrator +a| +* LangSmith Plus plan (or higher) workspace +* LangSmith API key +* LangSmith workspace ID +* Optional API host for region routing (for example, US or EU cloud host) + +| Microsoft Azure Copilot +| Agent +| Exchange Administrator, Copilot Studio Scanner Role +a| +* Azure app registration +* Tenant ID, client ID, client secret +* App added as an Application User in Power Platform +* Scope set to Dataverse environment URL + +| Microsoft Foundry +| Agent +| Exchange Administrator, Azure AI Developer +a| +* Active Azure subscription +* Azure app registration +* Tenant ID, client ID, client secret +* Project endpoint URLs (discovery is project-specific) + +| Snowflake Cortex AI +| Agent +| Exchange Administrator, Snowflake ACCOUNTADMIN +a| +* Snowflake account with Cortex Agents enabled (Enterprise edition) +* A user with `ACCOUNTADMIN` privileges for one-time setup only +* At least one Cortex Agent created in a schema to be scanned +* Scanner egress IP ranges from your Anypoint deployment team (``) +* Snowflake account URL +* Programmatic access token (PAT) + +| Amazon API Gateway +| API +| Exchange Administrator +a| +* IAM read-only policy for API Gateway (for example, `apigateway:GET`) +* Policy Read permission: `apigateway:GET` +* Policy Read action group: `apigateway:GET*` on REST and HTTP API resources +* Policy Read resource scope (REST APIs): `arn:aws:apigateway:{region}::/restapis/*` +* Policy Read resource scope (HTTP APIs): `arn:aws:apigateway:{region}::/apis/*` +* Policy Read note: for WAF-oriented extraction, scanner integrations also use WAFv2 and Route53 SDK access +* AWS region knowledge +* AWS access key ID and secret access key + +| Azure API Management +| API +| Exchange Administrator, API Management Service Reader +a| +* Policy Read role scope: API Management Service Reader at APIM resource or resource group scope +* Policy Read OAuth scope: `https://management.azure.com/.default` +* Tenant ID +* Client ID +* Client secret +* Subscription ID +* Resource group +* Service name + +| Google Apigee +| API +| Exchange Administrator, Apigee Read-only Admin +a| +* Policy Read role: service account with Viewer role or an Apigee permission role with equivalent read access +* GCP project ID +* Service account email +* Private key + +| Kong Gateway +| API +| Exchange Administrator, Kong Control Plane Viewer +a| +* Kong Gateway region +* Personal access token (PAT) + +| Akamai Security +| API Security +| Exchange Administrator +a| +* Akamai Security base URL +* Akamai Security client ID +* Akamai Security client secret +* Access to create service accounts in Akamai Security +* Access to apply Akamai correlation policy in target environments +* Existing services in *Portfolio* catalogs for correlation targets + +| Amazon Bedrock AgentCore MCP +| MCP +| Exchange Administrator +a| +* Active AWS account +* AWS region +* Access key ID and secret access key +* `bedrock-agentcore:ListAgentRuntimes` +* `bedrock-agentcore:GetAgentRuntime` +* `bedrock-agentcore:ListAgentRuntimeVersions` +* `bedrock-agentcore:ListAgentRuntimeEndpoints` +* `bedrock-agentcore:InvokeAgentRuntime` +* Policy Read permissions: runtime read actions, including `bedrock-agentcore:ListAgentRuntimes` and `bedrock-agentcore:GetAgentRuntime` + +| Azure API Management MCP Server +| MCP +| Exchange Administrator, API Management Service Reader +a| +* Tenant ID +* Client ID +* Client secret +* Subscription ID +* Resource group +* Service name + +| Snowflake MCP Server +| MCP +| Exchange Administrator, Snowflake ACCOUNTADMIN +a| +* Snowflake Enterprise account with MCP servers enabled +* Snowflake account URL +* Programmatic access token (PAT) + +|=== + +== See Also + +* xref:exp-scanners-add-from-providers.adoc[] +* xref:exp-providers-manage.adoc[] +* xref:exp-scanners-manage.adoc[] From cde42101c6aaf4de587973fa93112fa7bd969d2f Mon Sep 17 00:00:00 2001 From: jenny hajee Date: Mon, 13 Jul 2026 21:26:16 -0500 Subject: [PATCH 02/11] edit for aws api scanner read cred --- .../exp-provider-prerequisites-reference.adoc | 219 ------------------ .../exp-scanners-prerequisites-reference.adoc | 2 +- 2 files changed, 1 insertion(+), 220 deletions(-) delete mode 100644 modules/ROOT/pages/exp-provider-prerequisites-reference.adoc diff --git a/modules/ROOT/pages/exp-provider-prerequisites-reference.adoc b/modules/ROOT/pages/exp-provider-prerequisites-reference.adoc deleted file mode 100644 index a52f58409..000000000 --- a/modules/ROOT/pages/exp-provider-prerequisites-reference.adoc +++ /dev/null @@ -1,219 +0,0 @@ -= Scanner Prerequisites Reference -:keywords: scanner prerequisites, exchange scanners, provider scanners, required roles, required credentials, scanner setup - -Scanner prerequisites by provider help you confirm required roles, credentials, and permissions before creating a scanner. Use this reference to prevent connection test failures and incomplete discovery by validating provider-specific access in advance. Each scanner still requires Exchange Administrator permission and the correct business group context. - -== Before You Begin - -Before adding any scanner, make sure you have: - -* Exchange Administrator permission. -* Access to, and active context in, the business group where you want to add the scanner. - -== Scanner Prerequisites Cross-Reference - -In the table, bullets prefixed with *Policy Read* identify permissions, roles, or scopes required specifically for policy-read scanning. - -[cols="1,1,1,2",options="header"] -|=== -| Scanner -| Scanner Type -| Required Roles -| Required Credentials and Permissions - -| Amazon Bedrock -| Agent -| Exchange Administrator -a| -* AWS region knowledge -* Access key ID and secret access key -* `bedrock:ListAgents` -* `bedrock:GetAgent` -* `bedrock:ListAgentAliases` -* `bedrock:GetAgentAlias` -* `bedrock:ListAgentVersions` -* `bedrock:GetAgentVersion` -* Optional for agent invocation workflows: `bedrock:InvokeModel`, `bedrock:InvokeAgent`, `bedrock:InvokeInlineAgent` -* Policy Read permissions: `bedrock:ListAgents`, `bedrock:GetAgent`, and `bedrock:ListAgentAliases` -* Agents must have an alias linked to a version and an invocable URL - -| Amazon Bedrock AgentCore Runtime -| Agent -| Exchange Administrator -a| -* Active AWS account and AgentCore access -* AWS region -* Access key ID and secret access key -* `bedrock-agentcore:ListAgentRuntimes` -* `bedrock-agentcore:ListAgentRuntimeEndpoints` -* `bedrock-agentcore:GetAgentCard` -* `bedrock-agentcore:GetAgentRuntime` -* `bedrock-agentcore:ListAgentRuntimeVersions` -* `bedrock:GetAgent` -* `bedrock:ListAgents` -* Agents must be published with an active endpoint/version - -| Anthropic Claude Managed Agents -| Agent -| Exchange Administrator -a| -* Paid Anthropic account -* Claude API key - -| Databricks Agent Bricks -| Agent -| Exchange Administrator -a| -* Databricks workspace access -* Workspace URL -* Client ID and client secret -* Service principal `CAN_QUERY` on serving endpoints -* `CAN_VIEW` or higher on endpoint metadata APIs -* Discoverable agents must be custom Unity Catalog models in `READY` state - -| GoDaddy ANS -| Agent -| Exchange Administrator -a| -* API key -* API secret - -| Google Gemini Agent Enterprise Platform -| Agent -| Exchange Administrator, Vertex AI Viewer -a| -* GCP project ID -* Service account email -* Private key - -| LangChain LangSmith -| Agent -| Exchange Administrator -a| -* LangSmith Plus plan (or higher) workspace -* LangSmith API key -* LangSmith workspace ID -* Optional API host for region routing (for example, US or EU cloud host) - -| Microsoft Azure Copilot -| Agent -| Exchange Administrator, Copilot Studio Scanner Role -a| -* Azure app registration -* Tenant ID, client ID, client secret -* App added as an Application User in Power Platform -* Scope set to Dataverse environment URL - -| Microsoft Foundry -| Agent -| Exchange Administrator, Azure AI Developer -a| -* Active Azure subscription -* Azure app registration -* Tenant ID, client ID, client secret -* Project endpoint URLs (discovery is project-specific) - -| Snowflake Cortex AI -| Agent -| Exchange Administrator, Snowflake ACCOUNTADMIN -a| -* Snowflake account with Cortex Agents enabled (Enterprise edition) -* A user with `ACCOUNTADMIN` privileges for one-time setup only -* At least one Cortex Agent created in a schema to be scanned -* Scanner egress IP ranges from your Anypoint deployment team (``) -* Snowflake account URL -* Programmatic access token (PAT) - -| Amazon API Gateway -| API -| Exchange Administrator -a| -* IAM read-only policy for API Gateway (for example, `apigateway:GET`) -* Policy Read permission: `apigateway:GET` -* Policy Read action group: `apigateway:GET*` on REST and HTTP API resources -* Policy Read resource scope (REST APIs): `arn:aws:apigateway:{region}::/restapis/*` -* Policy Read resource scope (HTTP APIs): `arn:aws:apigateway:{region}::/apis/*` -* Policy Read note: for WAF-oriented extraction, scanner integrations also use WAFv2 and Route53 SDK access -* AWS region knowledge -* AWS access key ID and secret access key - -| Azure API Management -| API -| Exchange Administrator, API Management Service Reader -a| -* Policy Read role scope: API Management Service Reader at APIM resource or resource group scope -* Policy Read OAuth scope: `https://management.azure.com/.default` -* Tenant ID -* Client ID -* Client secret -* Subscription ID -* Resource group -* Service name - -| Google Apigee -| API -| Exchange Administrator, Apigee Read-only Admin -a| -* Policy Read role: service account with Viewer role or an Apigee permission role with equivalent read access -* GCP project ID -* Service account email -* Private key - -| Kong Gateway -| API -| Exchange Administrator, Kong Control Plane Viewer -a| -* Kong Gateway region -* Personal access token (PAT) - -| Akamai Security -| API Security -| Exchange Administrator -a| -* Akamai Security base URL -* Akamai Security client ID -* Akamai Security client secret -* Access to create service accounts in Akamai Security -* Access to apply Akamai correlation policy in target environments -* Existing services in *Portfolio* catalogs for correlation targets - -| Amazon Bedrock AgentCore MCP -| MCP -| Exchange Administrator -a| -* Active AWS account -* AWS region -* Access key ID and secret access key -* `bedrock-agentcore:ListAgentRuntimes` -* `bedrock-agentcore:GetAgentRuntime` -* `bedrock-agentcore:ListAgentRuntimeVersions` -* `bedrock-agentcore:ListAgentRuntimeEndpoints` -* `bedrock-agentcore:InvokeAgentRuntime` -* Policy Read permissions: runtime read actions, including `bedrock-agentcore:ListAgentRuntimes` and `bedrock-agentcore:GetAgentRuntime` - -| Azure API Management MCP Server -| MCP -| Exchange Administrator, API Management Service Reader -a| -* Tenant ID -* Client ID -* Client secret -* Subscription ID -* Resource group -* Service name - -| Snowflake MCP Server -| MCP -| Exchange Administrator, Snowflake ACCOUNTADMIN -a| -* Snowflake Enterprise account with MCP servers enabled -* Snowflake account URL -* Programmatic access token (PAT) - -|=== - -== See Also - -* xref:exp-scanners-add-from-providers.adoc[] -* xref:exp-providers-manage.adoc[] -* xref:exp-scanners-manage.adoc[] diff --git a/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc b/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc index ca978630f..32b8d221a 100644 --- a/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc +++ b/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc @@ -133,7 +133,7 @@ a| * Policy Read action group: `apigateway:GET*` on REST and HTTP API resources * Policy Read resource scope (REST APIs): `arn:aws:apigateway:{region}::/restapis/*` * Policy Read resource scope (HTTP APIs): `arn:aws:apigateway:{region}::/apis/*` -* Policy Read note: for WAF-oriented extraction, scanner integrations also use WAFv2 and Route53 SDK access +* Policy Read note: For web application firewall (WAF) policies, the scanner also uses `software.amazon.awssdk:wafv2` and `software.amazon.awssdk:route53` * AWS region knowledge * AWS access key ID and secret access key From 8d38a3d8a3ab1d6e0276cacdecece3c3d3f87a80 Mon Sep 17 00:00:00 2001 From: jenny hajee Date: Mon, 13 Jul 2026 21:41:36 -0500 Subject: [PATCH 03/11] removed Akamai security scanner because the release was delayed to 8/6 --- .../pages/exp-scanners-prerequisites-reference.adoc | 11 +---------- 1 file changed, 1 insertion(+), 10 deletions(-) diff --git a/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc b/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc index 32b8d221a..955ee83d9 100644 --- a/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc +++ b/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc @@ -165,17 +165,8 @@ a| a| * Kong Gateway region * Personal access token (PAT) +* Policy Apply write scope: Admin API write permission required to apply policy in target environments -| Akamai Security -| API Security -| Exchange Administrator -a| -* Akamai Security base URL -* Akamai Security client ID -* Akamai Security client secret -* Access to create service accounts in Akamai Security -* Access to apply Akamai correlation policy in target environments -* Existing services in *Portfolio* catalogs for correlation targets | Amazon Bedrock AgentCore MCP | MCP From c9a2a7e7861d88e72531ac02f1dad6f4a0a95d83 Mon Sep 17 00:00:00 2001 From: jenny hajee Date: Mon, 13 Jul 2026 21:53:11 -0500 Subject: [PATCH 04/11] edits --- modules/ROOT/pages/exp-scanners-add-from-providers.adoc | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/modules/ROOT/pages/exp-scanners-add-from-providers.adoc b/modules/ROOT/pages/exp-scanners-add-from-providers.adoc index 8a18607b4..068061d0f 100644 --- a/modules/ROOT/pages/exp-scanners-add-from-providers.adoc +++ b/modules/ROOT/pages/exp-scanners-add-from-providers.adoc @@ -1,7 +1,7 @@ = Adding Scanners from Providers :keywords: scanners, providers, add scanner, scanner configuration, workflow, anypoint platform, security scanning -A scanner is the configured link between the system and a supported cloud provider that lets discovery jobs find services—such as APIs, agents, and MCP servers—and register them in the right *Portfolio* catalogs. Scanners enable automated discovery so your catalogs stay current without manual registration. Configure a scanner once to turn on discovery for a provider, then extend it as your organization adds catalogs or enabled features. +A scanner is the configured link between the system and a supported cloud provider that lets discovery jobs find services—such as APIs, agents, and MCP servers—and register them in the right *Portfolio* catalogs, and to discover and read policies from API configurations. Scanners enable automated discovery so your catalogs stay current without manual registration. Configure a scanner once to turn on discovery for a provider, then extend it as your organization adds catalogs or enabled features. For how provider connection and catalogs fit together, see xref:exp-services-connect-providers-to-add.adoc[] and xref:exp-services-add-to-portfolio.adoc[]. From b577a23971feee37c5d60f90859b23e0a578e6fa Mon Sep 17 00:00:00 2001 From: jenny hajee Date: Mon, 13 Jul 2026 22:02:34 -0500 Subject: [PATCH 05/11] edits --- modules/ROOT/pages/exp-scanners-add-from-providers.adoc | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/modules/ROOT/pages/exp-scanners-add-from-providers.adoc b/modules/ROOT/pages/exp-scanners-add-from-providers.adoc index 068061d0f..f3b5d55e6 100644 --- a/modules/ROOT/pages/exp-scanners-add-from-providers.adoc +++ b/modules/ROOT/pages/exp-scanners-add-from-providers.adoc @@ -33,6 +33,10 @@ Discovered services appear in *Portfolio* where teams can govern, monitor, and d + Scheduled or on-demand scans pick up releases and configuration drift according to the options your administrator allows. +* Policy-visibility ++ +When a scanner is enabled, it can discover and read policies from API configurations. This allows the system to enforce policies on the discovered services. This is especially useful for API-based policies, such as web application firewall (WAF) policies. + == Workflow Entry Points for Adding a Scanner The system exposes the same underlying connect-and-configure wizard from more than one place; the label depends on context: From 4a16ece1896c5d78e65d4bb456cf0cf06d4c915a Mon Sep 17 00:00:00 2001 From: jenny hajee Date: Thu, 16 Jul 2026 16:28:49 -0500 Subject: [PATCH 06/11] clarify scanner read policy visibility and troubleshooting paths Document where users can view read policies imported by Amazon API Gateway, Google Apigee, Azure API Management, and Kong scanners so governance checks are easier to validate. Add practical guidance on what appears in the Policies tab and what affects visibility when scanner scopes or runs are incomplete. Co-authored-by: Cursor --- .../pages/exp-scanners-add-from-providers.adoc | 2 ++ modules/ROOT/pages/exp-services-view-details.adoc | 15 +++++++++++++-- 2 files changed, 15 insertions(+), 2 deletions(-) diff --git a/modules/ROOT/pages/exp-scanners-add-from-providers.adoc b/modules/ROOT/pages/exp-scanners-add-from-providers.adoc index f3b5d55e6..990209a72 100644 --- a/modules/ROOT/pages/exp-scanners-add-from-providers.adoc +++ b/modules/ROOT/pages/exp-scanners-add-from-providers.adoc @@ -61,6 +61,8 @@ Regardless of entry point, adding a scanner establishes trust and scope. You spe When the scanner is active, it applies discovery results according to its settings and your organization's rules. You review outcomes on the *Providers* page and on scanner detail pages, and you manage discovered services from the relevant *Portfolio* catalogs. +For API scanners, policy-read results are visible from each discovered API in *Portfolio* > *APIs* > *Policies*. This includes read policies from Amazon API Gateway, Google Apigee, Azure API Management, and Kong Gateway. Use this view to verify imported controls and confirm scanner coverage by provider. + For ongoing operations (pause, edit, or delete), see xref:exp-scanners-manage.adoc[]. == See Also diff --git a/modules/ROOT/pages/exp-services-view-details.adoc b/modules/ROOT/pages/exp-services-view-details.adoc index ec3023aa2..ba1970fdb 100644 --- a/modules/ROOT/pages/exp-services-view-details.adoc +++ b/modules/ROOT/pages/exp-services-view-details.adoc @@ -1,7 +1,7 @@ = View Service Details :keywords: view service details, service detail page, anypoint exchange, exchange services, service tabs, mulesoft exchange -Open a catalog entry in *Portfolio* to see its service detail page: a single view of one service, such as an agent, MCP server, LLM proxy, API, or gateway. From this page, review status and cost, relationships to other services, deployments, policies, monitoring, conformance, and change history without switching contexts. +View scanner read policies, deployments, monitoring, and conformance for a service from one detail page in *Portfolio*. Open any service, including an API, agent, MCP server, LLM proxy, or gateway, to review current status, cost, and relationships. Use this page to validate applied controls and track changes without switching contexts. //placeholder for image of service detail page @@ -37,7 +37,7 @@ The page is organized into tabs. The following table lists each tab, what it sho |Yes |Yes |Yes |Each LLM Proxy is exactly one instance so there is no *Instances* tab. |No |*Policies* -|Governance policies attached to the service or its instances (access, data, performance, compliance, and related domains your organization uses). If the instance uses a Kong gateway, the listed policies are gateway-level policies (plugins). Other service-level policies (plugins) can also apply. +|Governance policies attached to the service or its instances (access, data, performance, compliance, and related domains your organization uses). For APIs discovered by scanners, this tab shows read policies from Amazon API Gateway, Google Apigee, Azure API Management, and Kong Gateway. If the instance uses a Kong gateway, the listed policies are gateway-level policies (plugins). Other service-level policies (plugins) can also apply. |Yes |Yes |Yes |Yes |No |*Monitoring* @@ -62,6 +62,17 @@ The page is organized into tabs. The following table lists each tab, what it sho . Use the search box to find the service by name or description, or scan the list or grid. . Select the service card to open its detail page. +== View Read Policies Discovered by Scanners + +When scanner policy-read scopes are configured for the provider, the *Policies* tab shows the discovered policy entries for that API instance. The tab includes policy names and mapped governance context, such as category and apply level when the provider returns that metadata. For providers that expose policy status, the tab also shows whether a policy is enabled so teams can validate scanner coverage and conformance inputs from the latest scan snapshot. + +. In *Portfolio*, open *APIs* and select an API discovered by a provider scanner. +. Open the *Policies* tab on the service detail page. +. Review read policies imported from Amazon API Gateway, Google Apigee, Azure API Management, or Kong Gateway. +. Use the policy list to confirm applied controls before governance reviews or conformance analysis. + +Policy visibility depends on the last successful scanner run, not on a live provider query. If required provider scopes or roles are missing, policy results can be incomplete or unavailable. Policy fields such as status, apply level, and detail can vary by provider. If expected policies are missing, check scanner run status and history in *Providers*. + == See Also * xref:exp-overview.adoc[] From e2117aadf0c88d999c076daa50cea49ee8d38887 Mon Sep 17 00:00:00 2001 From: jenny hajee Date: Thu, 23 Jul 2026 14:58:49 -0500 Subject: [PATCH 07/11] edits --- modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc b/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc index 955ee83d9..c4c8d17b6 100644 --- a/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc +++ b/modules/ROOT/pages/exp-scanners-prerequisites-reference.adoc @@ -165,7 +165,8 @@ a| a| * Kong Gateway region * Personal access token (PAT) -* Policy Apply write scope: Admin API write permission required to apply policy in target environments +* Policy Apply read scope: Admin API read permission required to read policy in target environments +// (for Write policy GA)* Policy Apply write scope: Admin API write permission required to apply policy in target environments | Amazon Bedrock AgentCore MCP From 5e54bfed8039c7d513fd3068925a9a073d59f77c Mon Sep 17 00:00:00 2001 From: jenny hajee Date: Thu, 23 Jul 2026 15:06:40 -0500 Subject: [PATCH 08/11] added scanner prerequisites reference topic to nav --- modules/ROOT/nav.adoc | 1 + 1 file changed, 1 insertion(+) diff --git a/modules/ROOT/nav.adoc b/modules/ROOT/nav.adoc index 96f9abae4..326c67b59 100644 --- a/modules/ROOT/nav.adoc +++ b/modules/ROOT/nav.adoc @@ -16,6 +16,7 @@ *** xref:exp-services-add-semantic.adoc[] *** xref:exp-services-view-details.adoc[] ** xref:exp-scanners-add-from-providers.adoc[] + *** xref:exp-scanners-prerequisites-reference.adoc[] *** xref:exp-scanners-manage.adoc[] ** xref:exp-providers-manage.adoc[] ** xref:exp-instances-add.adoc[] From 506a721b4d4b3d3ddca3bb813f7c6196902fe31f Mon Sep 17 00:00:00 2001 From: jenny hajee Date: Thu, 23 Jul 2026 15:12:03 -0500 Subject: [PATCH 09/11] edits for See Also and scanner prerequisites ref --- modules/ROOT/pages/exp-scanners-add-from-providers.adoc | 1 + 1 file changed, 1 insertion(+) diff --git a/modules/ROOT/pages/exp-scanners-add-from-providers.adoc b/modules/ROOT/pages/exp-scanners-add-from-providers.adoc index 990209a72..c29839636 100644 --- a/modules/ROOT/pages/exp-scanners-add-from-providers.adoc +++ b/modules/ROOT/pages/exp-scanners-add-from-providers.adoc @@ -68,6 +68,7 @@ For ongoing operations (pause, edit, or delete), see xref:exp-scanners-manage.ad == See Also * xref:exp-services-connect-providers-to-add.adoc[] +* xref:exp-scanners-prerequisites-reference.adoc[] * xref:exp-scanners-manage.adoc[] * xref:exp-services-add-to-portfolio.adoc[] * xref:exp-services-view-details.adoc[] From c10a2cb59b5db9559427c27586d9a6a0b13ba6af Mon Sep 17 00:00:00 2001 From: jenny hajee Date: Thu, 23 Jul 2026 15:40:16 -0500 Subject: [PATCH 10/11] edits to managing scanner topic --- modules/ROOT/pages/exp-scanners-manage.adoc | 15 +++++++++------ 1 file changed, 9 insertions(+), 6 deletions(-) diff --git a/modules/ROOT/pages/exp-scanners-manage.adoc b/modules/ROOT/pages/exp-scanners-manage.adoc index f5a8685d9..0ae3c06f4 100644 --- a/modules/ROOT/pages/exp-scanners-manage.adoc +++ b/modules/ROOT/pages/exp-scanners-manage.adoc @@ -5,19 +5,22 @@ After you configure scanners, you run them day to day. Most of that work happens == Available Scanner Actions -* Run discovery on demand. +* *Run Discovery Scan* + Start a manual scan when you want fresh metadata without waiting for the next scheduled window. Successful runs update or add services in the matching *Portfolio* catalogs according to your rules. -* Review status and history. +* *View Scanner* + Inspect connection health, the last completed run, and scan history to verify whether discovery is healthy, slow, or failing authentication. -* Pause scheduled scans. +* *Pause Scheduled Runs* + Temporarily stop scheduled triggers when you need a quiet period—for example during maintenance or while you fix credentials—without deleting the scanner. -* Edit configuration. +* *Resume Scheduled Runs* + -Change names, descriptions, credentials, provider scope, or scan-related settings your product exposes, then save so future runs use the new definition. -* Delete a scanner. +Re-enable scheduled scanning after a pause. +* *Scanner Settings* ++ +Change names, descriptions, credentials, provider scope, or scan-related settings your product exposes, then save, so future runs use the new definition. +* *Delete Scanner* + Remove the scanner from *Providers* when the provider link is no longer authorized or useful. Consider the impact on discovered services in *Portfolio* and on dependent teams before you delete the scanner. From 13d071a8ae2c9cb5fa76c59bbc89d6f2c9fa83ff Mon Sep 17 00:00:00 2001 From: jenny hajee Date: Thu, 23 Jul 2026 15:54:10 -0500 Subject: [PATCH 11/11] edits --- modules/ROOT/pages/exp-services-view-details.adoc | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/modules/ROOT/pages/exp-services-view-details.adoc b/modules/ROOT/pages/exp-services-view-details.adoc index ba1970fdb..28a588d9d 100644 --- a/modules/ROOT/pages/exp-services-view-details.adoc +++ b/modules/ROOT/pages/exp-services-view-details.adoc @@ -3,8 +3,6 @@ View scanner read policies, deployments, monitoring, and conformance for a service from one detail page in *Portfolio*. Open any service, including an API, agent, MCP server, LLM proxy, or gateway, to review current status, cost, and relationships. Use this page to validate applied controls and track changes without switching contexts. -//placeholder for image of service detail page - == Before You Begin Before getting started, make sure you have: @@ -64,7 +62,7 @@ The page is organized into tabs. The following table lists each tab, what it sho == View Read Policies Discovered by Scanners -When scanner policy-read scopes are configured for the provider, the *Policies* tab shows the discovered policy entries for that API instance. The tab includes policy names and mapped governance context, such as category and apply level when the provider returns that metadata. For providers that expose policy status, the tab also shows whether a policy is enabled so teams can validate scanner coverage and conformance inputs from the latest scan snapshot. +If a provider scanner has policy-read scopes configured, the *Policies* tab shows discovered policy entries for that API instance. The tab lists policy names and mapped governance context, such as category and apply level, when the provider returns that metadata. For providers that expose policy status, the tab also shows whether a policy is enabled so teams can validate scanner coverage and conformance inputs from the latest scan snapshot. . In *Portfolio*, open *APIs* and select an API discovered by a provider scanner. . Open the *Policies* tab on the service detail page.