Skip to content
04Integrations

One subscription. The whole stack.

AirTee.ai subscribes to your signal and writes back actions — never an extra thing to monitor.

00The map

Hub-and-spoke, by design.

AirTee sits at the centre of your detection, identity, ITSM and comms stack — pulling signal in and pushing action back out.

AirTee integrations map showing connections to Splunk, Microsoft Sentinel, CrowdStrike, ServiceNow, Jira, PagerDuty, Slack, Microsoft Teams, Microsoft Defender, Okta, Microsoft Entra, AWS, Azure and GCP
FIG. 01 — THE INTEGRATION MAP · BI-DIRECTIONAL · OAUTH · SCIM
01Detection & telemetry

SIEM, EDR, observability.

01
Splunk

Bi-directional. AirTee subscribes to notable events; pushes incident records back.

02
Microsoft Sentinel

Native connector with KQL-aware enrichment.

03
CrowdStrike Falcon

Detections become AirTee incidents with MITRE mapping inherited.

04
Datadog

Monitor incidents flow into the AirTee timeline with full trace context.

05
Wiz / Snyk

Cloud and supply-chain findings linked to the affected critical services.

06
Custom webhooks

Anything that can POST JSON can be a signal source.

02Identity & access

Single sign-on and provisioning.

01
Okta

SAML SSO + SCIM provisioning.

02
Microsoft Entra ID

SAML/OIDC + SCIM, conditional access supported.

03
Google Workspace

OIDC SSO.

03ITSM, comms & cloud

Where work actually happens.

01
ServiceNow

Bi-directional incident records, change management linkage.

02
Jira / Jira Service Management

Two-way sync with custom field mapping.

03
PagerDuty

AirTee runs the room, PagerDuty pages.

04
Slack

Channel-as-incident, slash commands, AAR posted.

05
Microsoft Teams

Same model, in Teams channels.

06
AWS / Azure / GCP

Service catalog, IAM and resource graph imports.

— next step

See AirTee in your environment.

We'll model one of your real scenarios live.