Ecosystem and open API
Guardian fits the stack you already have — and never becomes the thing you cannot leave
400+ certified connectors, a fully documented REST and GraphQL API, four maintained SDKs and signed webhooks on every event. Every capability in the console is available over the API, because a platform that reserves features for its own UI is a platform you cannot automate.
How it fits together
One connector bus, two directions, no bespoke middleware
Connectors are not scripts someone wrote once. Each is a versioned, monitored, rate-aware component with health telemetry, automatic backoff, replay on failure and a published schema contract. When a vendor changes an API, Guardian ships the fix — not you.
Scroll horizontally to see the full diagram on a small screen.
Connector catalogue
A representative selection of the 400+ certified connectors
Every connector below is first-party, maintained by Guardian, covered by the platform SLA, and validated against each vendor release. Direction indicates whether Guardian reads, writes, or both.
SIEM, analytics and data platforms
Splunk Enterprise Security
BothStreams OCSF-normalised detections and raw telemetry to indexers or Splunk Cloud; accepts notable-event updates back into the Guardian case.
Microsoft Sentinel
BothNative data connector plus incident synchronisation, so a Guardian case and a Sentinel incident stay in lockstep with shared status and owner.
IBM QRadar
OutboundLEEF and CEF over syslog or the REST offense API, with automatic mapping to QRadar's low- and high-level categories.
Elastic Security
BothECS-mapped documents via the Elasticsearch bulk API, with alert closure flowing back from Kibana into the Guardian timeline.
Google SecOps
OutboundUDM-formatted events over the ingestion API, with entity context preserved so SecOps rules can join to Guardian assets.
Exabeam Fusion
OutboundDetection and identity risk streaming into Exabeam's user and entity behaviour timelines.
Snowflake
OutboundContinuous export to your own security data lake in OCSF, partitioned and compressed, with schema evolution handled automatically.
Databricks
OutboundDelta Lake sink with an accompanying notebook library for hunting, enrichment and long-horizon analytics on retained telemetry.
ITSM, ticketing and on-call
ServiceNow ITSM & SecOps
BothCreates security incidents and change records, reads CMDB for asset context, and binds approval gates to CAB governance.
Jira Service Management
BothTwo-way issue sync with custom field mapping, transition mirroring and comment threading into the Guardian case timeline.
PagerDuty
BothRota-aware paging with approval actions delivered as first-class incident responses and acknowledgement flowing back.
Atlassian Opsgenie
BothEscalation policies honoured, with Guardian severity mapped to Opsgenie priority and auto-close on case resolution.
Zendesk
OutboundRaises user-facing tickets for coaching workflows, such as a blocked transfer requiring a business justification.
Freshservice
BothIncident and change creation with asset lookup, for teams standardised on the Freshworks suite.
Slack
BothInteractive approval cards, case channels created on demand, and slash commands for triage without leaving the conversation.
Microsoft Teams
BothAdaptive cards for approvals and briefings, plus automatic incident channel creation with the evidence bundle attached.
Cloud and infrastructure
Amazon Web Services
BothCloudTrail, GuardDuty, VPC flow, Config and Security Hub ingest; response via IAM, EC2, Security Groups and Systems Manager.
Microsoft Azure
BothActivity Log, Defender for Cloud and Arc ingest; response via NSG rules, VM isolation and role assignment removal.
Google Cloud
BothCloud Audit Logs and Security Command Center ingest; response via IAM policy edits, firewall rules and instance quarantine.
Kubernetes
BothAudit log ingest and admission control, with pod eviction, network policy application and namespace isolation as response actions.
HashiCorp Vault
BothSecret rotation as a first-class response action, plus audit-device ingest to detect anomalous secret access.
Terraform Cloud
BothPlan-time policy checks and automatic pull requests that fix the module responsible for a live misconfiguration.
GitHub & GitLab
BothAudit-log ingest, secret-leak detection, and playbook-driven revocation of exposed tokens with an issue raised on the owning repository.
VMware vSphere
BothHypervisor event ingest plus guest snapshot, network detach and power-state response for virtualised estates.
Identity, access and privilege
Microsoft Entra ID
BothSign-in and audit ingest, risky-user publication, continuous access evaluation, token revocation and role removal.
Okta
BothSystem log ingest, Risk Events API in both directions, session clear, factor reset and group membership changes.
Ping Identity
BothPingOne risk predictor feed and PingFederate session termination tied to the Guardian identity risk score.
Active Directory
BothDomain sensor telemetry plus account disable, Kerberos ticket purge, password reset and protected-group removal.
CyberArk
BothPrivileged session termination, just-in-time checkout revocation and vault audit ingest for privileged credential use.
SailPoint IdentityIQ
BothEntitlement context on ingest, and certification campaigns triggered by Guardian shadow-admin findings.
Cisco Duo
BothAuthentication log ingest, push-fatigue detection, and factor suspension as a response action.
JumpCloud
BothDirectory insights ingest with account suspension and device policy enforcement for cloud-first estates.
Email, network and data security
Microsoft 365 Defender
BothMessage trace and Graph ingest, plus mailbox-wide message retraction and sender blocking as response actions.
Google Workspace
BothAdmin SDK and Gmail audit ingest, OAuth grant revocation, and Drive sharing policy enforcement.
Proofpoint
BothThreat insight ingest correlated with endpoint detonation results, and campaign-wide retraction triggered from a Guardian case.
Mimecast
BothMessage and attachment telemetry ingest with blocked-sender list management as a response action.
Palo Alto Networks NGFW
BothTraffic and threat log ingest, dynamic address group updates, and policy-based blocking of command-and-control destinations.
Zscaler
BothWeb and private access log ingest, with URL category and destination blocking applied directly from a playbook.
Fortinet FortiGate
BothSyslog ingest and address-object updates for rapid egress blocking across distributed sites.
Cloudflare
BothLogpush ingest plus WAF rule and firewall list management for edge-level containment.
Integration detail
Direction, authentication, latency and supported actions
The specifics that decide whether an integration survives an architecture review. Latency figures are p50 measured across the fleet in the trailing 30 days.
Scroll horizontally to see the full chart on a small screen.
| Integration | Category | Direction | Authentication | Delivery | p50 latency | Response actions |
|---|---|---|---|---|---|---|
| Splunk Enterprise Security | SIEM | Bidirectional | HEC token | Streaming | 1.2 s | 4 |
| Microsoft Sentinel | SIEM | Bidirectional | Entra app (OAuth 2.0) | Streaming | 2.4 s | 6 |
| ServiceNow SecOps | ITSM | Bidirectional | OAuth 2.0 + mutual TLS | Webhook + poll | 3.1 s | 11 |
| PagerDuty | On-call | Bidirectional | Events API v2 key | Webhook | 0.9 s | 5 |
| Amazon Web Services | Cloud | Bidirectional | IAM role assumption | EventBridge + API | 4.6 s | 38 |
| Microsoft Entra ID | Identity | Bidirectional | Entra app (certificate) | Streaming + API | 1.4 s | 14 |
| Okta | Identity | Bidirectional | OAuth 2.0 private key JWT | Event hook + API | 1.1 s | 12 |
| Microsoft 365 Defender | Bidirectional | Entra app (certificate) | Streaming API | 6.8 s | 9 | |
| Palo Alto Networks NGFW | Network | Bidirectional | API key + mutual TLS | Syslog + XML API | 0.7 s | 7 |
| Kubernetes | Cloud | Bidirectional | Service account token | Audit webhook | 0.4 s | 10 |
| HashiCorp Vault | Secrets | Bidirectional | AppRole | Audit device + API | 1.8 s | 6 |
| Snowflake | Data lake | Outbound | Key pair | Batch (5 min) | 5 min | 0 |
Scroll horizontally to see all columns.
No connector requires an inbound firewall rule to your network. All communication is initiated outbound from the Guardian collector or directly from the vendor's cloud API.
API and SDKs
Everything the console does, the API does first
The Guardian console is built on the same public API you get. There is no privileged internal endpoint, no undocumented capability and no feature that requires clicking. Versioned, rate-documented, and supported for 24 months after a version is superseded.
Resource-oriented, cursor-paginated, and consistent across every object type. Rate limits are returned on every response so a client can back off gracefully rather than guess.
# List open critical cases and isolate the affected host
curl -s "https://api.guardian.com/v3/cases?severity=critical&status=open&limit=50" \
-H "Authorization: Bearer $GDN_TOKEN"
curl -s -X POST "https://api.guardian.com/v3/actions" \
-H "Authorization: Bearer $GDN_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"action": "endpoint.isolate",
"target": { "asset_id": "ast_7f31c9" },
"params": { "keep_agent": true },
"reason": "INC-88214 confirmed ransomware behaviour",
"reversible": true
}'
# 202 Accepted
# X-RateLimit-Limit: 600 X-RateLimit-Remaining: 587
# { "action_id": "act_92bd41", "status": "executing",
# "rollback_token": "rbk_1f88ce", "eta_ms": 1800 }
One round trip for the whole investigation graph. Useful when you are building a custom dashboard and do not want eleven REST calls per case.
query CaseContext($id: ID!) {
case(id: $id) {
id severity status openedAt narrative
detections { id technique { id name tactic } confidence }
assets { id hostname criticality owner { team } }
identities { id displayName riskScore privilegeTier }
dataTouched { classification recordCount }
actions { id type status reversible executedAt actor }
intel { adversary { name motivation confidence } }
}
}
# POST https://api.guardian.com/v3/graphql
# Depth limit 12 · complexity budget 5,000 points per query
Maintained SDKs for Python, TypeScript, Go and Java. Typed models, automatic retry with jitter, cursor iteration and streaming support built in.
from guardian import Client
gdn = Client(token=os.environ["GDN_TOKEN"], region="eu-west")
# Stream detections as they happen
for det in gdn.detections.stream(min_confidence=0.85):
if det.technique.id == "T1003.001" and det.asset.criticality >= 3:
action = gdn.actions.run(
"identity.revoke_sessions",
target=det.identity,
reason=f"credential access on {det.asset.hostname}",
)
action.wait(timeout=30)
print(action.status, action.rollback_token)
# Retro-hunt across retained telemetry
hits = gdn.hunt.query(
"process.name = 'rundll32.exe' and network.destination.asn = 209242",
since="90d",
)
The CLI is how playbooks, detections and policies move between environments. It is the same binary used by the Guardian CI action.
# Validate and promote a playbook from staging to production
gdn playbook lint ./playbooks/contain-credential-theft.gdn
gdn playbook test ./playbooks/contain-credential-theft.gdn --fixtures ./fixtures
gdn playbook diff ./playbooks/contain-credential-theft.gdn --env prod
gdn playbook promote ./playbooks/contain-credential-theft.gdn --env prod --tier 2
# Export everything for a compliance evidence request
gdn export cases --since 2026-01-01 --format ocsf --out ./evidence
gdn export audit --since 2026-01-01 --verify-chain
Scoped tokens
OAuth 2.0 client credentials with fine-grained scopes, per-token rate limits, IP allow lists and a maximum lifetime you set. Every call is attributed in the immutable audit log.
Versioned and deprecated slowly
Major versions are supported for 24 months after supersession. Breaking changes are announced twelve months ahead with a migration guide and a compatibility shim.
OpenAPI and sandbox
A complete OpenAPI 3.1 specification, a public Postman collection, and a free sandbox tenant with synthetic incident data so you can build before you buy.
Bulk export, always
Every event, case, action and audit record is exportable in OCSF, CEF or JSON at any time, with no export fee and no throttling penalty. Your data remains yours.
Webhooks
Signed, replayable, and idempotent by design
Subscribe to any of 64 event types with a JSONPath filter, receive an HMAC-SHA256 signature on every delivery, and replay the last 30 days from the console if your endpoint was down. Deliveries carry an idempotency key so a retry never double-executes.
POST /hooks/guardian HTTP/1.1
Content-Type: application/json
X-Guardian-Event: case.action.executed
X-Guardian-Delivery: dlv_4c2e91a7
X-Guardian-Idempotency-Key: idm_88214_act_92bd41
X-Guardian-Signature: t=1786109041,v1=6d1a...c93f
{
"event": "case.action.executed",
"occurred_at": "2026-07-31T09:18:12.418Z",
"tenant": "acme-global",
"case": { "id": "INC-88214", "severity": "critical" },
"action": {
"id": "act_92bd41",
"type": "identity.revoke_sessions",
"status": "succeeded",
"reversible": true,
"rollback_token": "rbk_1f88ce",
"actor": "playbook:[email protected]"
},
"target": { "identity_id": "idn_2f7a10", "tier": 1 }
}
Verify with HMAC-SHA256(secret, t + "." + body) and
reject any delivery whose timestamp is more than five minutes old. Reference implementations for
Python, Node, Go and Java are in the developer documentation.
64 event types
Detections, case lifecycle, action execution and rollback, approval requests and decisions, connector health, policy changes, intelligence publication and audit events. Subscribe to all of them or filter to one.
Delivery guarantees
At-least-once delivery with exponential backoff over 24 hours, a dead-letter queue you can inspect, and per-endpoint health metrics. Consistently failing endpoints raise a platform alert rather than being silently disabled.
Mutual TLS available
Present a client certificate for delivery, pin the Guardian certificate on your side, or route webhooks through a private link so nothing traverses the public internet.
Custom connectors
Something missing? Build it in an afternoon.
The connector SDK gives you the same primitives Guardian engineers use: schema mapping, pagination, rate limiting, secret handling, health reporting and replay. You write the vendor-specific part and nothing else.
-
Declare the source
Describe the endpoint, authentication method, pagination style and rate limits in a manifest. The SDK generates the polling loop, backoff behaviour and credential storage for you.
-
Map to OCSF
Write field mappings against the OCSF 1.3 schema with a visual mapper or a declarative file. Unmapped fields are preserved verbatim so nothing is lost, and validation runs on every build.
-
Declare actions
Type each outbound action with its parameters, side effects, reversibility and required permission. Typed actions become available to every playbook and to the API automatically.
-
Test and publish
Run against recorded fixtures, publish privately to your tenant, or submit to Guardian for certification and inclusion in the public catalogue with joint support.
Technology alliance programme
Co-engineering, joint certification, shared support runbooks and listing in the Guardian catalogue. 140 vendors are in the programme today.
Partner with GuardianMSSP multi-tenancy
Tenant-scoped API keys, cross-tenant querying with explicit consent, per-client rate pools and consolidated billing. Built for service providers, not retrofitted.
MSSP programmeMigration assistance
Guardian engineers convert your existing SOAR playbooks, SIEM content and detection rules as part of onboarding. Median conversion for a mature SOC: three weeks.
Talk to consultingWe were sceptical about the open API claim, so we rebuilt our entire executive dashboard against it in a week without opening a support ticket. That has never happened to us with a security vendor.
Questions
What platform teams ask us first
Do connectors cost extra?
No. Every certified connector, the full API, all four SDKs and unlimited webhooks are included in every Guardian Sentinel plan. There is no per-connector fee, no ingest surcharge for third-party sources and no charge for exporting your own data. Pricing is per protected asset — see the pricing page.
What if a connector we depend on breaks after a vendor update?
Guardian monitors every certified connector against vendor release channels and pre-production environments. Connector health, lag and error rate are visible in your console, and a degraded connector raises a platform alert rather than silently dropping data. Certified connectors carry a four-hour response commitment for a total failure, and fixes ship as platform updates with no action required from you.
Can Guardian coexist with our existing SIEM rather than replacing it?
Yes, and most customers run both for at least a year. Guardian streams OCSF-normalised detections and, if you want it, raw telemetry into Splunk, Sentinel, QRadar, Elastic or your own lake. Many teams reduce SIEM licence cost by routing high-volume telemetry to Guardian for detection and forwarding only the enriched output for retention and compliance search.
What network access does a connector require?
None inbound. On-premises collectors initiate outbound TLS 1.3 to a published set of hostnames on port 443, and cloud connectors call vendor APIs directly. Private connectivity is available through AWS PrivateLink, Azure Private Link and Google Private Service Connect for customers who require it.
How are credentials for our third-party systems stored?
In a per-tenant envelope-encrypted secret store with keys held in a FIPS 140-3 validated HSM, optionally your own through bring-your-own-key. Credentials are never written to logs, never visible in the console after entry, and are accessible only to the specific connector runtime that needs them. Certificate and workload-identity authentication is preferred wherever the vendor supports it.
What are the API rate limits?
600 requests per minute per token by default for read operations and 120 per minute for actions, with burst allowances and per-tenant pools that scale with your plan. Every response carries the current limit, remaining quota and reset time. Streaming endpoints and bulk export are not counted against the request budget.
Keep going
What connectors actually carry
Automation and response
The 1,200 typed actions these connectors expose, and the playbooks that call them.
Identity protection
Bidirectional risk publication into Entra ID, Okta and Ping.
Data protection
SaaS and storage connectors that classify and enforce out of band.
Threat intelligence
TAXII, MISP and Sigma delivery into whatever tooling you already run.
Build against it before you buy it
Request a free sandbox tenant with synthetic incident data, full API access and every connector enabled. No sales conversation required to get the credentials.