What’s in This Release
- A direct API integration with SentinelOne EDR, connected from the client account
- 14 endpoint posture checks across deployment, configuration, and hygiene
- Findings that flag risk, including end-of-life systems and unmanaged devices
- Findings that link to tasks in three states, with coverage that follows the license
Endpoint Posture, Read Straight from the SentinelOne Management API
Cynomi reads the SentinelOne Management API directly and converts what it finds into findings. Each finding evaluates a single question across all of a client’s endpoints, such as whether EDR is deployed and actively protecting every device, and rolls the answer up into one result you can act on rather than a per-machine list.
That result links to the relevant Cynomi tasks. Endpoint posture data populates the task plan automatically, instead of arriving as a console export that somebody has to interpret and then transcribe. The integration sits alongside the rest of the connected tooling on the integrations page.
Why this matters
Endpoint posture data used to be collected per task, per client, by a person. It now arrives as a linked finding. The task plan and the real state of the estate stay aligned without anyone reconciling them by hand.
14 Endpoint Posture Checks
The integration ships 14 checks, grouped across three areas:
- Deployment and protection – EDR coverage, up-to-date anti-malware, and detect-only versus protect mode
- Configuration controls – firewall, disk encryption, device control, and application control
- Inventory and hygiene – asset and software inventory, policy exclusions, and admin activity cadence
It also surfaces findings that flag risk: prohibited or high-risk software, end-of-life operating systems, and unmanaged devices on the network. These findings can help surface endpoint risks that may not otherwise be visible in routine client reviews.
Together the checks give you a current picture of endpoint risk across workstations and servers, without a scheduled review meeting to assemble it.
Findings That Map to Tasks, in Three States
Every check reports one of three states:
- Pass – compliant, so the task can be marked complete
- Gap – a clear shortfall, which keeps the task open
- at risk – partial coverage that needs review
The At Risk state captures partial coverage that requires review rather than a simple pass-or-fail determination. Each finding links directly to one or more Cynomi tasks, and a single task can be mapped to more than one check, so a control backed by several endpoint conditions shows all of them.
Your task plan in security program management and your endpoint reality stay in step without a manual pass over both, and the finding behind a status is visible on the task rather than in somebody’s export folder.
Coverage That Follows Each Client’s License
Coverage adapts to each tenant’s SentinelOne license. Checks available on every paid tier run for all tenants, while checks that require a higher tier or a paid add-on are skipped where the license does not support them.
The practical effect is that a client only ever sees the checks their license actually supports, rather than a list of gaps that are really licensing limits. It also means two clients on different SentinelOne tiers will show different numbers of checks, so check counts may differ between clients on different license tiers.
What This Changes for Your Delivery Team
Endpoint posture collection is a recurring manual task in many security engagements. Reading endpoint posture directly, turning it into findings, and mapping those findings to the tasks they relate to reduces manual administration for clients running SentinelOne, leaving your team to focus on reviewing and prioritizing the gaps.