Singularity Endpoint
Use selected SentinelOne Singularity Endpoint records in Pomerium policy through a customer-owned external data source.
Overview
Singularity Endpoint is the SentinelOne endpoint protection and detection product. API access, data fields, and entitlements depend on the customer tenant. A customer-owned adapter can map a reviewed export to Pomerium Enterprise external data.
Selected Singularity Endpoint data can add organization, inventory, or security context to an access decision. A small, reviewed record set is easier to understand and protect than a broad export of the source system.
Pomerium can evaluate selected Singularity Endpoint records after a customer-owned adapter maps them to supported request or user keys. Pomerium does not call the vendor API directly and does not manage the source system.
How it works
Use the customer tenant API or approved export contract that is available for SentinelOne Singularity Endpoint. Select the exact fields and credentials from the tenant documentation.
Map only the fields that policy needs. Each imported record must use a Pomerium-supported foreign key: user.id, user.email, request.ip, or request.client_certificate.fingerprint.
Publish the records through a protected JSON, CSV, tar, or ZIP source. Configure Pomerium Enterprise to poll that source. Evaluate the imported fields with a Pomerium Policy Language record matcher.
Example
An adapter imports a narrow organization-defined endpoint state from the customer tenant and maps it to a supported user or certificate key. Pomerium evaluates the imported record. A SentinelOne endpoint ID is not treated as proof of the current request device.
Considerations
- Public product information does not define one fixed customer API contract for this pattern.
- API access, fields, and licensed entitlements depend on the selected SentinelOne tenant.
- This is a customer-owned connector pattern, not a built-in Pomerium connector.
- External data sources need Pomerium Enterprise and update on a polling schedule.
- A vendor device or asset ID does not prove which device made the current Pomerium request.
