{"version":1,"pages":[{"id":"2c5bL4gsc81fnImQpcAY","title":"What is P0?","pathname":"/","siteSpaceId":"sitesp_4wGG6","description":"P0 Security is a cloud-native Privileged Access Management platform. Enforce just-in-time access and least-privilege governance across multi-cloud environments."},{"id":"fQpbbGMQOmIuAkMUWvaH","title":"P0 dashboard","pathname":"/readme/p0-dashboard","siteSpaceId":"sitesp_4wGG6","emoji":"1f39b","description":"Track access security with automated reporting. View identities, posture findings, JIT access metrics, and request trends from the P0 dashboard.","breadcrumbs":[{"label":"What is P0?"}]},{"id":"Gtv7FF0r3wGs1iPQlkiM","title":"Access inventory","pathname":"/readme/access-inventory","siteSpaceId":"sitesp_4wGG6","emoji":"1f50e","description":"Discover production assets, identities, and access risks across AWS, Google Cloud, Kubernetes, Okta, and Google Workspace with P0's access inventory.","breadcrumbs":[{"label":"What is P0?"}]},{"id":"e2hny5Ivp27MvmR6YIiR","title":"Posture","pathname":"/readme/posture","siteSpaceId":"sitesp_4wGG6","emoji":"1fa91","description":"Automatically scan your cloud environment for access risks. P0 Security detects overprivileged accounts, stale credentials, and security vulnerabilities.","breadcrumbs":[{"label":"What is P0?"}]},{"id":"WsKD3kAwkLlLemZ66gzA","title":"Just-in-time access","pathname":"/readme/just-in-time-access","siteSpaceId":"sitesp_4wGG6","emoji":"23f1","description":"Grant tailored, short-lived privileges to specific cloud resources on demand. Reduce standing access and enforce least privilege with P0 Security's JIT access.","breadcrumbs":[{"label":"What is P0?"}]},{"id":"hhZ4MzKwvI9Ecw8E2GRn","title":"P0 connectors","pathname":"/readme/connectors","siteSpaceId":"sitesp_4wGG6","emoji":"1f9e9","description":"Understand P0 connectors: stateless, versioned runtimes you deploy in your own cloud account to broker just-in-time access, so no standing credentials sit on laptops or in P0's SaaS.","breadcrumbs":[{"label":"What is P0?"}]},{"id":"6HPbVZFQzDkPANdeZLvV","title":"P0 AuthZ Control Plane for Agents","pathname":"/readme/agentic-control-plane","siteSpaceId":"sitesp_4wGG6","emoji":"1f916","description":"Verify the human and the agent, enforce least-privilege policy on every MCP tool call, and keep a complete audit trail with P0 AuthZ Control Plane for Agents and self-hosted AI Gateway.","breadcrumbs":[{"label":"What is P0?"}]},{"id":"KpIZuocJSZsC39c6tb36","title":"Service-account key rotation","pathname":"/readme/service-account-key-rotation","siteSpaceId":"sitesp_4wGG6","emoji":"267b","description":"Manage rotation of static service account credentials for third-party systems. P0 discovers owners, creates fresh credentials, and coordinates updates.","breadcrumbs":[{"label":"What is P0?"}]},{"id":"tJsL5jEkznAVvQmOUPOv","title":"Set up P0 for your organization","pathname":"/getting-started/p0-security-onboarding","siteSpaceId":"sitesp_4wGG6","emoji":"1f331","description":"Deploy P0 Security, integrate your cloud environments, and establish just-in-time access for human and non-human identities. For security and DevOps teams.","breadcrumbs":[{"label":"Getting started"}]},{"id":"cWEkviSlSZEc0aoxwfEQ","title":"Supported identity providers","pathname":"/getting-started/p0-security-onboarding/supported-identity-providers","siteSpaceId":"sitesp_4wGG6","emoji":"1f441","description":"","breadcrumbs":[{"label":"Getting started"},{"label":"Set up P0 for your organization","emoji":"1f331"}]},{"id":"BiPMcxX33BXeahsmJQoC","title":"Okta sign-in setup","pathname":"/getting-started/p0-security-onboarding/supported-identity-providers/okta-sign-in-setup","siteSpaceId":"sitesp_4wGG6","emoji":"1f511","description":"","breadcrumbs":[{"label":"Getting started"},{"label":"Set up P0 for your organization","emoji":"1f331"},{"label":"Supported identity providers","emoji":"1f441"}]},{"id":"6mT3zY0ieUBhYJv40X6C","title":"Request access to a resource","pathname":"/getting-started/request-access-quickstart","siteSpaceId":"sitesp_4wGG6","emoji":"1f680","description":"Request your first just-in-time access to a cloud resource through Slack, Microsoft Teams, the P0 web app, or the CLI. A quickstart for developers and engineers.","breadcrumbs":[{"label":"Getting started"}]},{"id":"FmMMjsspYmwy2Vjg11nm","title":"Govern what your AI agents can do","pathname":"/getting-started/govern-what-your-ai-agents-can-do","siteSpaceId":"sitesp_4wGG6","emoji":"1f916","description":"Deploy the P0 AI Gateway, expose your cloud to agents under policy, and connect Claude Code, so every tool call your agents make is authenticated, authorized, and attributable.","breadcrumbs":[{"label":"Getting started"}]},{"id":"kn3Mg03ByLowqw155BWv","title":"Grant just-in-time access to your cloud","pathname":"/getting-started/getting-started-with-just-in-time-access","siteSpaceId":"sitesp_4wGG6","emoji":"2b07","description":"Install P0 Security, configure approval workflows, and make your first just-in-time access request. A step-by-step guide for security and DevOps teams.","breadcrumbs":[{"label":"Getting started"}]},{"id":"vLS3zdeib11Nn8kLdFdJ","title":"Configure your first access policy","pathname":"/getting-started/configure-your-first-access-policy","siteSpaceId":"sitesp_4wGG6","emoji":"1f6e1","description":"Create an access policy in P0 Security's Policy Studio to control who can request access, what they can access, and who approves. A step-by-step tutorial for security administrators.","breadcrumbs":[{"label":"Getting started"}]},{"id":"zDNfx68iPZKfrDwlzEeJ","title":"Find risky access with Posture","pathname":"/getting-started/getting-started-with-posture","siteSpaceId":"sitesp_4wGG6","emoji":"2b07","description":"Connect your cloud environment, run your first posture scan, and triage access risk findings with P0 Security's posture management product.","breadcrumbs":[{"label":"Getting started"}]},{"id":"FrWOI2q2fuGcI6Q5CXo7","title":"Explore who has access to what with Access Inventory","pathname":"/getting-started/getting-started-with-access-inventory","siteSpaceId":"sitesp_4wGG6","emoji":"1f50e","description":"Connect your cloud environment, navigate the Access Inventory page, run your first query, investigate access risks, and save a monitor with P0 Security.","breadcrumbs":[{"label":"Getting started"}]},{"id":"IAduKA4lydyslBZKgwVk","title":"Manage integrations as code with the P0 Terraform provider","pathname":"/getting-started/get-started-with-the-p0-terraform-provider","siteSpaceId":"sitesp_4wGG6","emoji":"1f3d7","description":"Configure the P0 Terraform provider, authenticate with an API token, and install your first integration as code with an end-to-end AWS just-in-time access example.","breadcrumbs":[{"label":"Getting started"}]},{"id":"JbcIpLcrwcpRwIpfYRWd","title":"Work from the command line with the P0 CLI","pathname":"/getting-started/getting-started-with-the-p0-cli","siteSpaceId":"sitesp_4wGG6","emoji":"1f4bb","description":"Install the P0 CLI, authenticate, send your first permission request, and open your first SSH session with just-in-time access, all from the command line.","breadcrumbs":[{"label":"Getting started"}]},{"id":"7GB97pXtp8YPYxzO1iJh","title":"Access inventory","pathname":"/inventory/access-inventory","siteSpaceId":"sitesp_4wGG6","emoji":"1f5fa","description":"Browse and query your entire IAM configuration. Combine data from identity providers, IAM policies, access logs, and P0's IAM Privilege Catalog.","breadcrumbs":[{"label":"Inventory"}]},{"id":"BdqgY99GYHRIZqHuCgVu","title":"Result details","pathname":"/inventory/result-details","siteSpaceId":"sitesp_4wGG6","emoji":"1f52c","description":"","breadcrumbs":[{"label":"Inventory"}]},{"id":"xiOSGy9WwpwaaeUy9jmG","title":"Inventory export API","pathname":"/inventory/inventory-export-api","siteSpaceId":"sitesp_4wGG6","emoji":"1f50c","description":"List your P0 environments and export their access inventory as JSON. Pull credentials, identities, grants, and resources programmatically for custom integrations.","breadcrumbs":[{"label":"Inventory"}]},{"id":"L2wI3IpOjLw28xzCzBuJ","title":"Query search","pathname":"/inventory/query-search","siteSpaceId":"sitesp_4wGG6","emoji":"2754","description":"","breadcrumbs":[{"label":"Inventory"}]},{"id":"Y64PyK6KkSgUxSLMMalZ","title":"Query language basics","pathname":"/inventory/query-search/query-language-basics","siteSpaceId":"sitesp_4wGG6","emoji":"1f9ed","description":"A beginner's guide to querying P0's Access Inventory. Learn the core search terms (identity, credential, entitlement, risk), the colon, arrow, and reverse-arrow operators, the type argument, and how t","breadcrumbs":[{"label":"Inventory"},{"label":"Query search","emoji":"2754"}]},{"id":"FddBxtUzoCKPNP4SpT5v","title":"Search reference","pathname":"/inventory/query-search/search-reference","siteSpaceId":"sitesp_4wGG6","emoji":"1f4d6","description":"","breadcrumbs":[{"label":"Inventory"},{"label":"Query search","emoji":"2754"}]},{"id":"fY3XLGooxAve9jAw9zwJ","title":"Posture overview","pathname":"/posture/posture-overview","siteSpaceId":"sitesp_4wGG6","emoji":"2696","description":"Detect access vulnerabilities with automated monitors. View scan results, define custom policies, and enforce organization-specific access controls with P0.","breadcrumbs":[{"label":"Posture"}]},{"id":"EXW1ZN7qmKyCkN4B4RVD","title":"Create a custom monitor","pathname":"/posture/create-a-custom-monitor","siteSpaceId":"sitesp_4wGG6","emoji":"1f6e0","description":"Build a custom posture monitor in P0 to continuously detect a specific access vulnerability, such as unused privileged grants, across every environment scan.","breadcrumbs":[{"label":"Posture"}]},{"id":"LmlcBvmyjVJ8tQdyp6DX","title":"Monitor results","pathname":"/posture/monitor-results","siteSpaceId":"sitesp_4wGG6","icon":"list-radio","description":"","breadcrumbs":[{"label":"Posture"}]},{"id":"VrsjpXr5XHXWg0moQ2Kn","title":"Finding details","pathname":"/posture/finding-details","siteSpaceId":"sitesp_4wGG6","emoji":"1f914","description":"","breadcrumbs":[{"label":"Posture"}]},{"id":"AewPrlSwjZQPZjXip6rR","title":"Just-in-time access","pathname":"/access-management/just-in-time-access","siteSpaceId":"sitesp_4wGG6","emoji":"23f0","description":"Set up ephemeral, on-demand access to production resources. Requests are approved, provisioned, and automatically revoked within minutes using P0 Security.","breadcrumbs":[{"label":"Access management"}]},{"id":"Pycv2zpswUhdyvHKxEiy","title":"Requesting access","pathname":"/access-management/just-in-time-access/requesting-access","siteSpaceId":"sitesp_4wGG6","emoji":"1f590","description":"Request just-in-time access to cloud resources using P0.","breadcrumbs":[{"label":"Access management"},{"label":"Just-in-time access","emoji":"23f0"}]},{"id":"lvWsM8xV0c4OXMG8PIaC","title":"For another party","pathname":"/access-management/just-in-time-access/requesting-access/for-another-party","siteSpaceId":"sitesp_4wGG6","emoji":"1f449","description":"","breadcrumbs":[{"label":"Access management"},{"label":"Just-in-time access","emoji":"23f0"},{"label":"Requesting access","emoji":"1f590"}]},{"id":"LyruI2Mo17TcLe5VLanl","title":"Web request modal","pathname":"/access-management/just-in-time-access/requesting-access/web-request-modal","siteSpaceId":"sitesp_4wGG6","emoji":"1f310","description":"","breadcrumbs":[{"label":"Access management"},{"label":"Just-in-time access","emoji":"23f0"},{"label":"Requesting access","emoji":"1f590"}]},{"id":"LEpPCfZRZaUPjdmUjQZm","title":"Approving access","pathname":"/access-management/just-in-time-access/approving-access","siteSpaceId":"sitesp_4wGG6","emoji":"1f3c1","description":"This page describes how to review and approve just-in-time access requests","breadcrumbs":[{"label":"Access management"},{"label":"Just-in-time access","emoji":"23f0"}]},{"id":"BT8H4PEFDfcqHFBDye4y","title":"Auto-approve access for on-call engineers","pathname":"/access-management/just-in-time-access/approving-access/auto-approve-on-call-access","siteSpaceId":"sitesp_4wGG6","description":"Configure P0 to automatically grant just-in-time access to engineers who are on-call, using your PagerDuty or Incident.io schedule. Give responders fast, time-boxed access during incidents without man","breadcrumbs":[{"label":"Access management"},{"label":"Just-in-time access","emoji":"23f0"},{"label":"Approving access","emoji":"1f3c1"}]},{"id":"p58hWw8c5pKTucK8Tsyp","title":"Pre-approving access","pathname":"/access-management/just-in-time-access/approving-access/pre-approving-access","siteSpaceId":"sitesp_4wGG6","icon":"stamp","description":"","breadcrumbs":[{"label":"Access management"},{"label":"Just-in-time access","emoji":"23f0"},{"label":"Approving access","emoji":"1f3c1"}]},{"id":"5ZpAdOENFxZCVrDldhsY","title":"P0 allow modal, CLI, and UI","pathname":"/access-management/just-in-time-access/approving-access/p0-allow-workflows","siteSpaceId":"sitesp_4wGG6","icon":"stamp","description":"Configure P0 allow pre-approvals from Slack, the CLI, or the P0 web app.","breadcrumbs":[{"label":"Access management"},{"label":"Just-in-time access","emoji":"23f0"},{"label":"Approving access","emoji":"1f3c1"}]},{"id":"y4l6dkEIYt8pNrgTXX70","title":"Access policies","pathname":"/access-management/just-in-time-access/access-policies","siteSpaceId":"sitesp_4wGG6","emoji":"1f500","description":"","breadcrumbs":[{"label":"Access management"},{"label":"Just-in-time access","emoji":"23f0"}]},{"id":"Dt6C1lQB59EXTshSMmQe","title":"Configuring access policies","pathname":"/access-management/just-in-time-access/access-policies/configure-your-first-access-policy","siteSpaceId":"sitesp_4wGG6","description":"Configure access policies in P0 Security's Policy Studio to control who can request access to which resources, and how those requests are approved. Includes the Policy Studio walkthrough, the full pol","breadcrumbs":[{"label":"Access management"},{"label":"Just-in-time access","emoji":"23f0"},{"label":"Access policies","emoji":"1f500"}]},{"id":"sgi256wuLS6N4FubFhiO","title":"Google Cloud filtering","pathname":"/access-management/just-in-time-access/access-policies/google-cloud-filtering","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"Access management"},{"label":"Just-in-time access","emoji":"23f0"},{"label":"Access policies","emoji":"1f500"}]},{"id":"HcSRaJN6UWmSGQVOENtQ","title":"AWS filtering","pathname":"/access-management/just-in-time-access/access-policies/aws-filtering","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"Access management"},{"label":"Just-in-time access","emoji":"23f0"},{"label":"Access policies","emoji":"1f500"}]},{"id":"lNBQGsIsGWStAVGvMt7m","title":"Microsoft Azure filtering","pathname":"/access-management/just-in-time-access/access-policies/microsoft-azure-filtering","siteSpaceId":"sitesp_4wGG6","description":"This document covers the various ways fine-grained just-in-time access for Microsoft Azure can be configured by using P0's access policies.","breadcrumbs":[{"label":"Access management"},{"label":"Just-in-time access","emoji":"23f0"},{"label":"Access policies","emoji":"1f500"}]},{"id":"BN5ZHIMhdIi7o58HPk8E","title":"SSH filtering","pathname":"/access-management/just-in-time-access/access-policies/ssh-filtering","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"Access management"},{"label":"Just-in-time access","emoji":"23f0"},{"label":"Access policies","emoji":"1f500"}]},{"id":"uo6UZ93RDDYYPSaE1fh1","title":"Agentic access policies","pathname":"/access-management/just-in-time-access/access-policies/agentic-access-policies","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"Access management"},{"label":"Just-in-time access","emoji":"23f0"},{"label":"Access policies","emoji":"1f500"}]},{"id":"47JOuPQyyu7p7JaPDvxx","title":"Access bundles","pathname":"/access-management/just-in-time-access/access-bundles","siteSpaceId":"sitesp_4wGG6","emoji":"1f4e6","description":"Group several resource accesses into a single requestable Access Bundle in P0 Security, so users request everything they need for a task in one step.","breadcrumbs":[{"label":"Access management"},{"label":"Just-in-time access","emoji":"23f0"}]},{"id":"YU7Cy4yN6oXJESnAYFe7","title":"Session recording","pathname":"/access-management/just-in-time-access/session-recording","siteSpaceId":"sitesp_4wGG6","emoji":"1f5d2","description":"Session Recording in P0 allows you to view detailed activity that occurs within a privileged session.","breadcrumbs":[{"label":"Access management"},{"label":"Just-in-time access","emoji":"23f0"}]},{"id":"VVT1O9x1aG5hisaTgRIz","title":"AWS","pathname":"/access-management/just-in-time-access/session-recording/aws","siteSpaceId":"sitesp_4wGG6","emoji":"1f4e6","description":"View CloudTrail activity taken within a privileged session.","breadcrumbs":[{"label":"Access management"},{"label":"Just-in-time access","emoji":"23f0"},{"label":"Session recording","emoji":"1f5d2"}]},{"id":"R9k5SxYuWHS1UIUOEyhl","title":"Just-in-time API","pathname":"/access-management/just-in-time-access/just-in-time-api","siteSpaceId":"sitesp_4wGG6","emoji":"1f50c","description":"","breadcrumbs":[{"label":"Access management"},{"label":"Just-in-time access","emoji":"23f0"}]},{"id":"wOGRo8SHGfbXYs68YoqZ","title":"Command API","pathname":"/access-management/just-in-time-access/just-in-time-api/command-api","siteSpaceId":"sitesp_4wGG6","description":"Enable external systems to programmatically initiate access requests, enabling automation and integration with internal tools, bots, and security workflows.","breadcrumbs":[{"label":"Access management"},{"label":"Just-in-time access","emoji":"23f0"},{"label":"Just-in-time API","emoji":"1f50c"}]},{"id":"TAtzfcgQ9qhwTcL8B4lm","title":"Access requests API","pathname":"/access-management/just-in-time-access/just-in-time-api/access-requests-api","siteSpaceId":"sitesp_4wGG6","description":"Enable programmatic approval, denial, and revocation of access, enabling seamless integration with internal tools, bots, and security workflows for automated access escalation.","breadcrumbs":[{"label":"Access management"},{"label":"Just-in-time access","emoji":"23f0"},{"label":"Just-in-time API","emoji":"1f50c"}]},{"id":"wKSEIn0Mlff81HwlNQv7","title":"Access policies API","pathname":"/access-management/just-in-time-access/just-in-time-api/access-policies-api","siteSpaceId":"sitesp_4wGG6","description":"Create, read, update, and delete the access policies that route just-in-time access requests to approval paths — with the endpoints, schema, authentication, errors, and worked examples you need to imp","breadcrumbs":[{"label":"Access management"},{"label":"Just-in-time access","emoji":"23f0"},{"label":"Just-in-time API","emoji":"1f50c"}]},{"id":"KnXmvLyP1g8I1M8Gx0KG","title":"Agentic gateway","pathname":"/agentic-access/agentic-gateway","siteSpaceId":"sitesp_4wGG6","emoji":"1f916","description":"Configure the P0 AI Gateway and the upstream MCP servers and agents it fronts, so P0-managed AI agents can reach them under runtime authorization policy.","breadcrumbs":[{"label":"Agentic access"}]},{"id":"ocbFm2427Jzh2aMt71Y6","title":"Gateway","pathname":"/agentic-access/agentic-gateway/gateway","siteSpaceId":"sitesp_4wGG6","description":"What registering a P0 AI Gateway with P0 establishes, and how to register a gateway you deployed yourself.","breadcrumbs":[{"label":"Agentic access"},{"label":"Agentic gateway","emoji":"1f916"}]},{"id":"DxDPvztKcu10tMdbyT9p","title":"Deploying the gateway","pathname":"/agentic-access/agentic-gateway/gateway/deploy","siteSpaceId":"sitesp_4wGG6","description":"Deploy the self-hosted P0 AI Gateway and OAuth server from the P0 console, with the batteries-included Helm chart, or with the basic Helm chart.","breadcrumbs":[{"label":"Agentic access"},{"label":"Agentic gateway","emoji":"1f916"},{"label":"Gateway"}]},{"id":"dTpYGsFvf4WWGEvrXyvA","title":"Install from the P0 console","pathname":"/agentic-access/agentic-gateway/gateway/deploy/install-from-the-p0-console","siteSpaceId":"sitesp_4wGG6","description":"Deploy the gateway with the Terraform the P0 console generates, and register it with P0 in the same pass.","breadcrumbs":[{"label":"Agentic access"},{"label":"Agentic gateway","emoji":"1f916"},{"label":"Gateway"},{"label":"Deploying the gateway"}]},{"id":"ugwAYNqJywNhPPGmTcik","title":"Install the batteries-included Helm chart","pathname":"/agentic-access/agentic-gateway/gateway/deploy/install-the-batteries-included-chart","siteSpaceId":"sitesp_4wGG6","description":"Deploy the p0security/agentic-gateway-stack chart with helm instead of the Terraform the P0 console generates, then register the gateway with P0.","breadcrumbs":[{"label":"Agentic access"},{"label":"Agentic gateway","emoji":"1f916"},{"label":"Gateway"},{"label":"Deploying the gateway"}]},{"id":"p5ryVVs9GVMeChc6rwLf","title":"MCP server","pathname":"/agentic-access/agentic-gateway/mcp-server","siteSpaceId":"sitesp_4wGG6","description":"Configure upstream MCP servers behind the P0 AI Gateway to make them available to P0-managed agents under policy.","breadcrumbs":[{"label":"Agentic access"},{"label":"Agentic gateway","emoji":"1f916"}]},{"id":"cbrtIeLNVOnFTlAUwvUW","title":"AWS MCP server","pathname":"/agentic-access/agentic-gateway/mcp-server/aws","siteSpaceId":"sitesp_4wGG6","description":"Install the predefined AWS MCP server behind the P0 AI Gateway, giving agents policy-scoped, credential-free access to the AWS CLI.","breadcrumbs":[{"label":"Agentic access"},{"label":"Agentic gateway","emoji":"1f916"},{"label":"MCP server"}]},{"id":"584mQfBvYbEEVnCtJy2e","title":"GCP MCP server","pathname":"/agentic-access/agentic-gateway/mcp-server/gcp","siteSpaceId":"sitesp_4wGG6","description":"Install the predefined GCP MCP servers behind the P0 AI Gateway, giving agents policy-scoped, credential-free access to Google Cloud APIs.","breadcrumbs":[{"label":"Agentic access"},{"label":"Agentic gateway","emoji":"1f916"},{"label":"MCP server"}]},{"id":"G0SwnaHocbSK9K5RYyNl","title":"Compute Engine MCP server","pathname":"/agentic-access/agentic-gateway/mcp-server/gcp/compute","siteSpaceId":"sitesp_4wGG6","description":"Install the predefined Compute Engine MCP server behind the P0 AI Gateway, giving agents policy-scoped, credential-free access to the Google Cloud Compute Engine API.","breadcrumbs":[{"label":"Agentic access"},{"label":"Agentic gateway","emoji":"1f916"},{"label":"MCP server"},{"label":"GCP MCP server"}]},{"id":"h8w3SGRbyHJPnln29sMY","title":"Cloud Storage MCP server","pathname":"/agentic-access/agentic-gateway/mcp-server/gcp/storage","siteSpaceId":"sitesp_4wGG6","description":"Install the predefined Cloud Storage MCP server behind the P0 AI Gateway, giving agents policy-scoped, credential-free access to the Google Cloud Storage API.","breadcrumbs":[{"label":"Agentic access"},{"label":"Agentic gateway","emoji":"1f916"},{"label":"MCP server"},{"label":"GCP MCP server"}]},{"id":"ImuH4IHtH75VK4VXTXCK","title":"BigQuery MCP server","pathname":"/agentic-access/agentic-gateway/mcp-server/gcp/bigquery","siteSpaceId":"sitesp_4wGG6","description":"Install the predefined BigQuery MCP server behind the P0 AI Gateway, giving agents policy-scoped, credential-free access to the Google Cloud BigQuery API.","breadcrumbs":[{"label":"Agentic access"},{"label":"Agentic gateway","emoji":"1f916"},{"label":"MCP server"},{"label":"GCP MCP server"}]},{"id":"ddITmYbdTukTYrzI3NDe","title":"Cloud Monitoring MCP server","pathname":"/agentic-access/agentic-gateway/mcp-server/gcp/monitoring","siteSpaceId":"sitesp_4wGG6","description":"Install the predefined Cloud Monitoring MCP server behind the P0 AI Gateway, giving agents policy-scoped, credential-free access to the Google Cloud Monitoring API.","breadcrumbs":[{"label":"Agentic access"},{"label":"Agentic gateway","emoji":"1f916"},{"label":"MCP server"},{"label":"GCP MCP server"}]},{"id":"hwp9G96L1iBw3k25S4Js","title":"IAM MCP server","pathname":"/agentic-access/agentic-gateway/mcp-server/gcp/iam","siteSpaceId":"sitesp_4wGG6","description":"Install the predefined IAM MCP server behind the P0 AI Gateway, giving agents policy-scoped, credential-free access to the Google Cloud IAM API.","breadcrumbs":[{"label":"Agentic access"},{"label":"Agentic gateway","emoji":"1f916"},{"label":"MCP server"},{"label":"GCP MCP server"}]},{"id":"DTGJvD9RoFeAlg5ZgWSj","title":"Custom MCP server","pathname":"/agentic-access/agentic-gateway/mcp-server/custom","siteSpaceId":"sitesp_4wGG6","description":"Define and configure a custom MCP server behind the P0 AI Gateway when P0 does not ship a predefined server for it.","breadcrumbs":[{"label":"Agentic access"},{"label":"Agentic gateway","emoji":"1f916"},{"label":"MCP server"}]},{"id":"eOp8r1F58iL6dh3s8ggJ","title":"A2A bridge","pathname":"/agentic-access/agentic-gateway/a2a-bridge","siteSpaceId":"sitesp_4wGG6","description":"Configure an A2A bridge behind the P0 AI Gateway so P0-managed agents reach upstream agents under runtime authorization policy.","breadcrumbs":[{"label":"Agentic access"},{"label":"Agentic gateway","emoji":"1f916"}]},{"id":"UKZry8lxCkgInDzu3qOi","title":"Identity provider","pathname":"/agentic-access/identity-provider","siteSpaceId":"sitesp_4wGG6","emoji":"1f511","description":"Enroll an identity provider with the P0 AI Gateway so its JWT-authenticated agents are trusted to access the gateway.","breadcrumbs":[{"label":"Agentic access"}]},{"id":"X0ARfqCNcZ5IGLrJ9d2b","title":"AWS OIDC","pathname":"/agentic-access/aws-oidc","siteSpaceId":"sitesp_4wGG6","emoji":"1f4e6","description":"Install the AWS OIDC federation component so P0 can grant and revoke AWS access for OIDC-authenticated agents running through the P0 AI Gateway.","breadcrumbs":[{"label":"Agentic access"}]},{"id":"m5v1AsKgVJsjKd4waW4G","title":"GCP Workload Identity Federation","pathname":"/agentic-access/gcp-wif","siteSpaceId":"sitesp_4wGG6","icon":"shield-keyhole","description":"Install the GCP Workload Identity Federation component so P0 can grant and revoke Google Cloud access for OIDC-authenticated agents running through the P0 AI Gateway.","breadcrumbs":[{"label":"Agentic access"}]},{"id":"5jqMQjBAYbhlJWzRJxKG","title":"Using the P0 Agentic Gateway","pathname":"/agentic-access/using-the-gateway","siteSpaceId":"sitesp_4wGG6","description":"Connect MCP clients and unattended agents to the P0 AI Gateway, and request just-in-time access to the MCP servers behind it.","breadcrumbs":[{"label":"Agentic access"}]},{"id":"UplUJRB1gYoQF5eTBkdt","title":"Connect an MCP client","pathname":"/agentic-access/using-the-gateway/connect-an-mcp-client","siteSpaceId":"sitesp_4wGG6","description":"Register an MCP client and connect it to an MCP server configured behind the P0 AI Gateway.","breadcrumbs":[{"label":"Agentic access"},{"label":"Using the P0 Agentic Gateway"}]},{"id":"cHoZpzbbWI57qIFHKoti","title":"Agentic client registration API","pathname":"/agentic-access/using-the-gateway/connect-an-mcp-client/client-registration-api","siteSpaceId":"sitesp_4wGG6","description":"Register, list, and update the MCP clients that authenticate to a server behind the P0 AI Gateway.","breadcrumbs":[{"label":"Agentic access"},{"label":"Using the P0 Agentic Gateway"},{"label":"Connect an MCP client"}]},{"id":"SzN6nOQ187CcXvT6ufzW","title":"JWT-SVID","pathname":"/agentic-access/using-the-gateway/spiffe-svid","siteSpaceId":"sitesp_4wGG6","description":"Enroll a SPIFFE identity provider with P0, and authenticate an unattended workload to the P0 AI Gateway with an existing JWT-SVID from Python.","breadcrumbs":[{"label":"Agentic access"},{"label":"Using the P0 Agentic Gateway"}]},{"id":"L7Toe5FVrXXYJz7Ym9iR","title":"Requesting access","pathname":"/agentic-access/using-the-gateway/requesting-access","siteSpaceId":"sitesp_4wGG6","description":"How an AI agent requests, checks, uses, and relinquishes just-in-time access to the MCP servers and agents behind the P0 AI Gateway.","breadcrumbs":[{"label":"Agentic access"},{"label":"Using the P0 Agentic Gateway"}]},{"id":"KY5ElNpzG5WySBPKUpJC","title":"Use MCP servers with Claude Code","pathname":"/agentic-access/using-the-gateway/using-mcp-servers","siteSpaceId":"sitesp_4wGG6","description":"Connect your Claude Code client to the MCP servers behind the P0 AI Gateway, so your agent's tool calls are authenticated and governed by policy.","breadcrumbs":[{"label":"Agentic access"},{"label":"Using the P0 Agentic Gateway"}]},{"id":"ilrkC8mJ50JRlggQNpFd","title":"Creating an environment","pathname":"/environments/creating-an-environment","siteSpaceId":"sitesp_4wGG6","emoji":"2601","description":"","breadcrumbs":[{"label":"Environments"}]},{"id":"WceVwwQMzgda9MRb5XC9","title":"Install IAM assessment on Google Cloud","pathname":"/environments/creating-an-environment/install-iam-assessment-google-cloud","siteSpaceId":"sitesp_4wGG6","description":"Install the P0 IAM assessment integration on Google Cloud to collect IAM data. Required to use Access Inventory and Posture for your GCP projects.","breadcrumbs":[{"label":"Environments"},{"label":"Creating an environment","emoji":"2601"}]},{"id":"n58XpY7oroa4ra7L5nPJ","title":"Install IAM assessment on AWS","pathname":"/environments/creating-an-environment/install-iam-assessment-aws","siteSpaceId":"sitesp_4wGG6","description":"Install the P0 IAM assessment integration on AWS to collect IAM data. Required to use Access Inventory and Posture for your AWS accounts.","breadcrumbs":[{"label":"Environments"},{"label":"Creating an environment","emoji":"2601"}]},{"id":"1sM95YbyCt2Pa7pcqDT9","title":"Install IAM assessment on Microsoft Azure","pathname":"/environments/creating-an-environment/install-iam-assessment-azure","siteSpaceId":"sitesp_4wGG6","emoji":"1f537","description":"Install the P0 IAM assessment integration on Microsoft Azure to collect IAM data. Required to use Access Inventory and Posture for your Azure subscriptions.","breadcrumbs":[{"label":"Environments"},{"label":"Creating an environment","emoji":"2601"}]},{"id":"ZTLUTsoAv1icYxRgo2IX","title":"Environment terminology","pathname":"/environments/environment-terminology","siteSpaceId":"sitesp_4wGG6","emoji":"1f4d3","description":"","breadcrumbs":[{"label":"Environments"}]},{"id":"wovfUtcAaK87ioXYdmnX","title":"Settings","pathname":"/environments/settings","siteSpaceId":"sitesp_4wGG6","emoji":"2699","description":"","breadcrumbs":[{"label":"Environments"}]},{"id":"iyWMKLo0XMGfKvIs6c5M","title":"Integrations","pathname":"/integrations/integrations","siteSpaceId":"sitesp_4wGG6","emoji":"1f517","description":"Connect P0 with AWS, Google Cloud, Azure, Kubernetes, Okta, Slack, and other systems. Configure cloud, directory, notifier, and SIEM integrations.","breadcrumbs":[{"label":"Integrations"}]},{"id":"FeDPCH8CJEuDHE4YQSB6","title":"Notifier integrations","pathname":"/integrations/notifier-integrations","siteSpaceId":"sitesp_4wGG6","emoji":"1f4de","description":"","breadcrumbs":[{"label":"Integrations"}]},{"id":"9Ytmb5OpYXghQQZ3M4nS","title":"Slack","pathname":"/integrations/notifier-integrations/slack","siteSpaceId":"sitesp_4wGG6","emoji":"1f4ac","description":"Install the P0 Security Slack integration to request, approve, and receive just-in-time access notifications for cloud resources in Slack.","breadcrumbs":[{"label":"Integrations"},{"label":"Notifier integrations","emoji":"1f4de"}]},{"id":"dpMTwpYrGRzXZQg41UbB","title":"Microsoft Teams","pathname":"/integrations/notifier-integrations/microsoft-teams","siteSpaceId":"sitesp_4wGG6","emoji":"1f46c","description":"Install the P0 Security Microsoft Teams integration to request, approve, and receive just-in-time access notifications for cloud resources in Teams.","breadcrumbs":[{"label":"Integrations"},{"label":"Notifier integrations","emoji":"1f4de"}]},{"id":"RenxcbsWnNUFMI599YJr","title":"Email","pathname":"/integrations/notifier-integrations/email","siteSpaceId":"sitesp_4wGG6","emoji":"2709","description":"Set up the P0 Security email notifier to alert requestors and approvers about just-in-time access requests, approvals, and expirations in real time.","breadcrumbs":[{"label":"Integrations"},{"label":"Notifier integrations","emoji":"1f4de"}]},{"id":"MVEKkomzJnye9c6QeOpw","title":"Custom notifiers","pathname":"/integrations/notifier-integrations/custom-notifiers","siteSpaceId":"sitesp_4wGG6","emoji":"1f4e3","description":"Integrate P0 with any internal notification system you own, or with systems that do not have a built-in notification service yet.","breadcrumbs":[{"label":"Integrations"},{"label":"Notifier integrations","emoji":"1f4de"}]},{"id":"dvXavZMOzsRXVFYsnfl6","title":"AWS Lambda notifier","pathname":"/integrations/notifier-integrations/custom-notifiers/aws-lambda-notifier","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"Integrations"},{"label":"Notifier integrations","emoji":"1f4de"},{"label":"Custom notifiers","emoji":"1f4e3"}]},{"id":"hLTwVHzKnXdfUYlHooV6","title":"Resource integrations","pathname":"/integrations/resource-integrations","siteSpaceId":"sitesp_4wGG6","emoji":"1f511","description":"Configure just-in-time access for AWS, Google Cloud, Azure, Kubernetes, SSH, and more. Install P0 Security resource integrations to manage privileged cloud access.","breadcrumbs":[{"label":"Integrations"}]},{"id":"baaaYyZ5nS00f0uGiG18","title":"AWS","pathname":"/integrations/resource-integrations/aws","siteSpaceId":"sitesp_4wGG6","icon":"aws","description":"Install P0 IAM management on AWS in about 10 minutes. Configure just-in-time access, identity governance, and privilege management for your AWS environment.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"}]},{"id":"JD423Y4L9lhWXr6XAxln","title":"Setting up AWS IAM management","pathname":"/integrations/resource-integrations/aws/installation-methods","siteSpaceId":"sitesp_4wGG6","description":"Install the P0 AWS IAM management integration and choose how P0 provisions and identifies your users — as IAM users, through AWS Identity Center, or through a federated identity provider.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"AWS","icon":"aws"}]},{"id":"1NYeThH7MOoQmWZVpJ8t","title":"IAM","pathname":"/integrations/resource-integrations/aws/installation-methods/iam","siteSpaceId":"sitesp_4wGG6","description":"Configure the P0 AWS IAM management integration to provision users defined in the account's IAM service, matching them by user name or by an email tag.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"AWS","icon":"aws"},{"label":"Setting up AWS IAM management"}]},{"id":"oufJy0qsvENMtGqoOqoM","title":"Identity Center","pathname":"/integrations/resource-integrations/aws/installation-methods/identity-center","siteSpaceId":"sitesp_4wGG6","description":"Configure the P0 AWS IAM management integration to provision users through AWS Identity Center, matching them by user name or by their Identity Center email.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"AWS","icon":"aws"},{"label":"Setting up AWS IAM management"}]},{"id":"maPuAPHcOpl3ld87ma5r","title":"Federated","pathname":"/integrations/resource-integrations/aws/installation-methods/federated","siteSpaceId":"sitesp_4wGG6","description":"Configure the P0 AWS IAM management integration to provision users through an Okta SAML federation, granting IAM roles assigned to your AWS Account Federation app.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"AWS","icon":"aws"},{"label":"Setting up AWS IAM management"}]},{"id":"azU2fJtACdLrhdz0fvH3","title":"Identity Center (merged)","pathname":"/integrations/resource-integrations/aws/identity-center-merged","siteSpaceId":"sitesp_4wGG6","description":"Install the AWS Identity Center (merged) integration and configure the merged login type so P0 provisions access through a single shared permission set per user, avoiding Identity Center permission-se","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"AWS","icon":"aws"}]},{"id":"qA1fOMD4BLkBjquPnr4O","title":"Requesting AWS access","pathname":"/integrations/resource-integrations/aws/requesting-access","siteSpaceId":"sitesp_4wGG6","description":"How to request just-in-time access to AWS IAM policies, groups, and roles through P0 via Slack, Teams, Webex, the P0 CLI, or the P0 dashboard.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"AWS","icon":"aws"}]},{"id":"jJVGC1CUGS6PK9TMT0bS","title":"Permission levels","pathname":"/integrations/resource-integrations/aws/requesting-access/permission-levels","siteSpaceId":"sitesp_4wGG6","description":"Permission levels available when requesting just-in-time access to AWS resources through P0, including P0 curated policies and scoped AWS-managed policies.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"AWS","icon":"aws"},{"label":"Requesting AWS access"}]},{"id":"uOduYVKSO8MEX1zSaJqw","title":"Function invocation","pathname":"/integrations/resource-integrations/aws/function-invocation","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"AWS","icon":"aws"}]},{"id":"d4lhd3xyKjaJBSMSNCXq","title":"Managed services","pathname":"/integrations/resource-integrations/aws/managed-services","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"AWS","icon":"aws"}]},{"id":"WyDqdeCgULcFdDfZlGba","title":"AWS RDS","pathname":"/integrations/resource-integrations/aws/managed-services/aws-rds","siteSpaceId":"sitesp_4wGG6","icon":"database","description":"","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"AWS","icon":"aws"},{"label":"Managed services"}]},{"id":"GIwnl7BHyX5VjPJUzxCQ","title":"Cisco Secure Access","pathname":"/integrations/resource-integrations/cisco-secure-access","siteSpaceId":"sitesp_4wGG6","emoji":"1f510","description":"Installing P0 access management for Cisco Secure Access takes about 15 minutes.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"}]},{"id":"PTTE4c5Lgh3dluyhQ6IX","title":"Installation","pathname":"/integrations/resource-integrations/cisco-secure-access/installation","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Cisco Secure Access","emoji":"1f510"}]},{"id":"ynC7M5fIONWp870wzOUW","title":"Requesting Cisco Secure Access","pathname":"/integrations/resource-integrations/cisco-secure-access/requesting-access","siteSpaceId":"sitesp_4wGG6","description":"How to request just-in-time access to private network resources protected by Cisco Secure Access through P0 via Slack, Teams, Webex, the P0 CLI, or the P0 dashboard.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Cisco Secure Access","emoji":"1f510"}]},{"id":"DozwTIDx9fKmQHWZ48Yf","title":"Cloudflare","pathname":"/integrations/resource-integrations/cloudflare","siteSpaceId":"sitesp_4wGG6","icon":"cloudflare","description":"Managed just-in-time access to Cloudflare account roles","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"}]},{"id":"YGcK9zuJIg5Xf9PaYAQz","title":"Requesting Cloudflare access","pathname":"/integrations/resource-integrations/cloudflare/requesting-access","siteSpaceId":"sitesp_4wGG6","description":"How to request access to a Cloudflare account role via P0","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Cloudflare","icon":"cloudflare"}]},{"id":"EaJfpGOQjDo4Stmwxz0V","title":"Custom application","pathname":"/integrations/resource-integrations/custom-application","siteSpaceId":"sitesp_4wGG6","emoji":"1f50c","description":"Grant just-in-time access to an internal application through a connector you deploy on AWS Lambda or Google Cloud Run. P0 invokes your connector to list, grant and revoke access, and never reads insid","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"}]},{"id":"qlUK9Vo7wMDHMwczuZjy","title":"Deploying a connector to Google Cloud Run","pathname":"/integrations/resource-integrations/custom-application/deploying-a-connector-to-google-cloud-run","siteSpaceId":"sitesp_4wGG6","description":"Build the P0 connector SDK example, deploy it privately to Google Cloud Run, and register it in P0 so requestors can get just-in-time access to your own application.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Custom application","emoji":"1f50c"}]},{"id":"J2wN1CkWulpyIqTIQHMj","title":"Custom resource","pathname":"/integrations/resource-integrations/custom-resource","siteSpaceId":"sitesp_4wGG6","emoji":"1f6e0","description":"Integrate P0 with any internal system you own, or with systems that do not have a built-in integration yet.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"}]},{"id":"FVfLKH81j72iK0OczkHj","title":"Installing a custom resource integration","pathname":"/integrations/resource-integrations/custom-resource/installing-a-custom-resource-integration","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Custom resource","emoji":"1f6e0"}]},{"id":"Tt5x4ZZts5hUUQBaBzdH","title":"File transfer","pathname":"/integrations/resource-integrations/file-transfer","siteSpaceId":"sitesp_4wGG6","emoji":"1f4c1","description":"Set up P0's File Transfer integration to move local files to AWS EC2 instances through a customer-owned S3 bucket, with just-in-time access and full auditing.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"}]},{"id":"XufPt7Oglq6YluPpQAhM","title":"Transfer a file to an instance","pathname":"/integrations/resource-integrations/file-transfer/transferring-files","siteSpaceId":"sitesp_4wGG6","description":"Use the p0 file-transfer command to copy a local file to an AWS EC2 instance through P0's just-in-time File Transfer integration.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"File transfer","emoji":"1f4c1"}]},{"id":"k4ZSvz98HZi7HNreZQwI","title":"GitHub","pathname":"/integrations/resource-integrations/github","siteSpaceId":"sitesp_4wGG6","icon":"github","description":"Managed just-in-time access for GitHub organization teams","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"}]},{"id":"APeF5iiF7X79NUi69pVj","title":"Requesting GitHub access","pathname":"/integrations/resource-integrations/github/requesting-access","siteSpaceId":"sitesp_4wGG6","description":"How to request access to a GitHub team via P0","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"GitHub","icon":"github"}]},{"id":"oOcOnLUMfBQoti6jD1po","title":"Google Cloud","pathname":"/integrations/resource-integrations/google-cloud","siteSpaceId":"sitesp_4wGG6","emoji":"2601","description":"Set up P0's integration for Google Cloud Platform. Configure IAM management, just-in-time access, and privilege governance for your GCP environment.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"}]},{"id":"eHC6Ma3nAVPl7j1WZohb","title":"Security perimeter","pathname":"/integrations/resource-integrations/google-cloud/security-perimeter","siteSpaceId":"sitesp_4wGG6","description":"This page describes how to set up a Cloud Run security perimeter for P0 to manage access in your Google Cloud environment.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Google Cloud","emoji":"2601"}]},{"id":"hr9KHGBsNf5LAJCfCwtw","title":"Requesting Google Cloud access","pathname":"/integrations/resource-integrations/google-cloud/requesting-access","siteSpaceId":"sitesp_4wGG6","description":"How to request access to Google Cloud permissions, roles, and resources through the P0 bot","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Google Cloud","emoji":"2601"}]},{"id":"1g0zk5rStygDXeo1CwXu","title":"Permissions reference","pathname":"/integrations/resource-integrations/google-cloud/permissions-reference","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Google Cloud","emoji":"2601"}]},{"id":"BQh7tMGZbWKS7x8kk0B7","title":"Cloud Storage","pathname":"/integrations/resource-integrations/google-cloud/permissions-reference/cloud-storage","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Google Cloud","emoji":"2601"},{"label":"Permissions reference"}]},{"id":"QOhBcZhlnPTLze6lmkL7","title":"Compute Engine","pathname":"/integrations/resource-integrations/google-cloud/permissions-reference/compute-engine","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Google Cloud","emoji":"2601"},{"label":"Permissions reference"}]},{"id":"Y61z4NZZ36WPeh6dup8B","title":"Cloud Run invocation","pathname":"/integrations/resource-integrations/google-cloud/cloud-run-invocation","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Google Cloud","emoji":"2601"}]},{"id":"wgRCxoU1s9iUISzKVWzR","title":"Google Secret Manager","pathname":"/integrations/resource-integrations/google-cloud/secret-manager","siteSpaceId":"sitesp_4wGG6","description":"Grant just-in-time read access to individual Google Secret Manager secrets through P0, on top of your existing Google Cloud IAM management integration.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Google Cloud","emoji":"2601"}]},{"id":"PtTO0IyneigkQW2RyJGM","title":"Grafana Cloud","pathname":"/integrations/resource-integrations/grafana-cloud","siteSpaceId":"sitesp_4wGG6","icon":"chart-mixed","description":"Connect P0 to Grafana Cloud to grant just-in-time access to Grafana Cloud teams.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"}]},{"id":"YnaVA8ARRcKeS1nYUSpn","title":"Requesting access","pathname":"/integrations/resource-integrations/grafana-cloud/requesting-access","siteSpaceId":"sitesp_4wGG6","description":"How to request just-in-time access to Grafana Cloud teams through P0 via the P0 dashboard, Slack, Teams, or the P0 CLI.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Grafana Cloud","icon":"chart-mixed"}]},{"id":"PmNajuau9q2r5PTTC5b3","title":"Kubernetes","pathname":"/integrations/resource-integrations/kubernetes","siteSpaceId":"sitesp_4wGG6","emoji":"2638","description":"Add and configure P0's Kubernetes integration. Grant just-in-time, least-privilege access to Kubernetes clusters across AWS, Azure, and Google Cloud.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"}]},{"id":"4BKiewrZMbQA1rdh2OP8","title":"Terraform installation","pathname":"/integrations/resource-integrations/kubernetes/terraform-installation","siteSpaceId":"sitesp_4wGG6","description":"How to install the P0 Kubernetes (EKS) integration using Terraform","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Kubernetes","emoji":"2638"}]},{"id":"0hsESSdGUbRp0r99fXzT","title":"Requesting Kubernetes access","pathname":"/integrations/resource-integrations/kubernetes/requesting-access","siteSpaceId":"sitesp_4wGG6","description":"How to request access to Kubernetes permissions, roles, and resources through the P0 bot","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Kubernetes","emoji":"2638"}]},{"id":"JwlfUWxRrl7vyoskDvIs","title":"Advanced requests","pathname":"/integrations/resource-integrations/kubernetes/advanced-requests","siteSpaceId":"sitesp_4wGG6","description":"How to request common Kubernetes access patterns with P0","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Kubernetes","emoji":"2638"}]},{"id":"GmspIXB04o1wtb9EOTSD","title":"Microsoft Azure","pathname":"/integrations/resource-integrations/microsoft-azure","siteSpaceId":"sitesp_4wGG6","emoji":"1f537","description":"Install P0 IAM management on Microsoft Azure in about 10 minutes. Configure just-in-time access and privilege governance for your Azure environment.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"}]},{"id":"Gas928MSxgADMMlSqe4O","title":"Azure app registration","pathname":"/integrations/resource-integrations/microsoft-azure/azure-app-registration","siteSpaceId":"sitesp_4wGG6","description":"Create the Azure app registration that establishes P0's service identity in your tenant.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Microsoft Azure","emoji":"1f537"}]},{"id":"girUBZWTWJpLwtr4clvn","title":"IAM management","pathname":"/integrations/resource-integrations/microsoft-azure/iam-management","siteSpaceId":"sitesp_4wGG6","description":"Enable Just‑in‑Time access to Azure resources by installing IAM management.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Microsoft Azure","emoji":"1f537"}]},{"id":"vffUB0QpJlD6NTzBGaLW","title":"Configure bastion host integration","pathname":"/integrations/resource-integrations/microsoft-azure/configure-bastion-host-integration","siteSpaceId":"sitesp_4wGG6","description":"Choose how P0 connects to your Azure VMs, through an Azure Bastion host or a custom jump host, to enable secure SSH access.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Microsoft Azure","emoji":"1f537"}]},{"id":"ARdIoqJcvWMSVUT5B4Jc","title":"Azure bastion host","pathname":"/integrations/resource-integrations/microsoft-azure/configure-bastion-host-integration/azure-bastion-host","siteSpaceId":"sitesp_4wGG6","description":"Provision SSH access to your Azure VMs through a managed Azure Bastion host.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Microsoft Azure","emoji":"1f537"},{"label":"Configure bastion host integration"}]},{"id":"UMmZTh68lh5aPO5vGQOh","title":"Custom jump host","pathname":"/integrations/resource-integrations/microsoft-azure/configure-bastion-host-integration/custom-jump-host","siteSpaceId":"sitesp_4wGG6","description":"Connect P0 to your Azure VMs through your own virtual machine acting as a jump host.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Microsoft Azure","emoji":"1f537"},{"label":"Configure bastion host integration"}]},{"id":"16UW1xijOJMdCXik21sp","title":"Jump host sizing and tuning","pathname":"/integrations/resource-integrations/microsoft-azure/configure-bastion-host-integration/custom-jump-host/jump-host-sizing-and-tuning","siteSpaceId":"sitesp_4wGG6","description":"Reference sshd configuration and sizing limits for tuning a custom jump host VM, including a sample forwarding-only sshd_config and per-SKU load guidance.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Microsoft Azure","emoji":"1f537"},{"label":"Configure bastion host integration"},{"label":"Custom jump host"}]},{"id":"hLirLf6EzUFhZmHIh7HY","title":"Create a custom role","pathname":"/integrations/resource-integrations/microsoft-azure/configure-bastion-host-integration/create-a-custom-role","siteSpaceId":"sitesp_4wGG6","description":"Create a custom Azure role with the Azure CLI or Terraform to grant standard or administrator access to VMs reached through a P0 jump host or bastion host.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Microsoft Azure","emoji":"1f537"},{"label":"Configure bastion host integration"}]},{"id":"2p5TTR4m4bEuV1216xc6","title":"Install SSH access","pathname":"/integrations/resource-integrations/microsoft-azure/install-ssh-access","siteSpaceId":"sitesp_4wGG6","description":"Connect P0 to your Azure VMs by installing SSH access.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Microsoft Azure","emoji":"1f537"}]},{"id":"qzi81ICFirDPTcfD2rTG","title":"Jump host management","pathname":"/integrations/resource-integrations/microsoft-azure/jump-host-management","siteSpaceId":"sitesp_4wGG6","description":"Configure the jump host management connector so P0 can send privileged commands, such as terminating a live SSH session, to your Azure jump hosts.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Microsoft Azure","emoji":"1f537"}]},{"id":"WTPjbYgZcq8cdyGJljE6","title":"The jump host connector application","pathname":"/integrations/resource-integrations/microsoft-azure/jump-host-management/jump-host-connector-application","siteSpaceId":"sitesp_4wGG6","description":"Understand the jump host connector application, the session terminator app registration P0 authenticates as, the Function App it protects, and the least-privilege role it uses to manage access to you","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Microsoft Azure","emoji":"1f537"},{"label":"Jump host management"}]},{"id":"Lr3CmPHGwkkXeOx2WlPr","title":"The jump host connector image","pathname":"/integrations/resource-integrations/microsoft-azure/jump-host-management/jump-host-connector-image","siteSpaceId":"sitesp_4wGG6","description":"Understand the jump host connector image (the container that runs P0's Azure function for terminating live SSH sessions) and where it is published.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Microsoft Azure","emoji":"1f537"},{"label":"Jump host management"}]},{"id":"QoSjOzSlJ4FhFnBlNSak","title":"Requesting Microsoft Azure access","pathname":"/integrations/resource-integrations/microsoft-azure/requesting-access","siteSpaceId":"sitesp_4wGG6","description":"How to request just-in-time access to Microsoft Azure subscriptions, resources, and roles through P0 via Slack, Teams, Webex, the P0 CLI, or the P0 dashboard.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Microsoft Azure","emoji":"1f537"}]},{"id":"FOQeT1nYuX2aA247jI04","title":"MySQL","pathname":"/integrations/resource-integrations/mysql","siteSpaceId":"sitesp_4wGG6","emoji":"1f42c","description":"","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"}]},{"id":"7iK2A67k1Fj0SANzyqxB","title":"Installation","pathname":"/integrations/resource-integrations/mysql/installation","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"MySQL","emoji":"1f42c"}]},{"id":"FigRWaXghfo8RY41YZbx","title":"Requesting MySQL access","pathname":"/integrations/resource-integrations/mysql/requesting-access","siteSpaceId":"sitesp_4wGG6","description":"How to request just-in-time access to MySQL databases through P0 using the CLI.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"MySQL","emoji":"1f42c"}]},{"id":"BtoUQpiKMdEQMCpYUvwU","title":"Oracle Cloud","pathname":"/integrations/resource-integrations/oracle-cloud","siteSpaceId":"sitesp_4wGG6","emoji":"1f52e","description":"Installing P0 IAM management on Oracle Cloud Infrastructure (OCI).","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"}]},{"id":"TjcgBBo9y6EeI78rhnUH","title":"Requesting Oracle Cloud access","pathname":"/integrations/resource-integrations/oracle-cloud/requesting-access","siteSpaceId":"sitesp_4wGG6","description":"Requesting access to Oracle Cloud Infrastructure (OCI) groups through P0.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Oracle Cloud","emoji":"1f52e"}]},{"id":"gaEZz0bdySoYYqH98E1x","title":"PostgreSQL","pathname":"/integrations/resource-integrations/postgresql","siteSpaceId":"sitesp_4wGG6","emoji":"1f418","description":"Connecting P0 Security to Google Cloud SQL and Amazon RDS for PostgreSQL","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"}]},{"id":"NDkO56WSHj8e7s9tSnAs","title":"Installing an RDS database","pathname":"/integrations/resource-integrations/postgresql/installing-an-rds-database","siteSpaceId":"sitesp_4wGG6","description":"How to install an AWS RDS database to P0","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"PostgreSQL","emoji":"1f418"}]},{"id":"Ocffxa7zNLB8fc7LW5cm","title":"Installing a Cloud SQL database","pathname":"/integrations/resource-integrations/postgresql/installing-an-cloudsql-database","siteSpaceId":"sitesp_4wGG6","description":"How to install an CloudSQL database to P0","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"PostgreSQL","emoji":"1f418"}]},{"id":"RyXNMIiJlnibc5n0s1Um","title":"Requesting PostgreSQL access","pathname":"/integrations/resource-integrations/postgresql/requesting-access","siteSpaceId":"sitesp_4wGG6","description":"How to request access to PostgreSQL roles through the P0 bot.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"PostgreSQL","emoji":"1f418"}]},{"id":"WB17gpku7oBOSnxK8PQ6","title":"PostgreSQL (new)","pathname":"/integrations/resource-integrations/postgresql-new","siteSpaceId":"sitesp_4wGG6","emoji":"1f418","description":"Connect P0 to PostgreSQL databases on Amazon RDS and Google Cloud SQL, and request either a database role or SQL-scoped access.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"}]},{"id":"ywOQi6JkpcqJnLEZ9iGK","title":"Installing an RDS database","pathname":"/integrations/resource-integrations/postgresql-new/installing-an-rds-database","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"PostgreSQL (new)","emoji":"1f418"}]},{"id":"oJ5xOfAeJ7R4W8f5W8WH","title":"Installing a Cloud SQL database","pathname":"/integrations/resource-integrations/postgresql-new/installing-a-cloudsql-database","siteSpaceId":"sitesp_4wGG6","description":"Install P0 on a Google Cloud SQL for PostgreSQL instance to grant just-in-time database access through a Cloud Run connector and GCP IAM database authentication.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"PostgreSQL (new)","emoji":"1f418"}]},{"id":"ytF8QnSkOYVdB0cvCer2","title":"Requesting PostgreSQL access","pathname":"/integrations/resource-integrations/postgresql-new/requesting-postgresql-access","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"PostgreSQL (new)","emoji":"1f418"}]},{"id":"1JvIfvJTRJth60slIFO6","title":"Salesforce","pathname":"/integrations/resource-integrations/salesforce","siteSpaceId":"sitesp_4wGG6","icon":"salesforce","description":"Managed just-in-time access to Salesforce permission sets","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"}]},{"id":"sDrSCZQvf30LIe2UW04k","title":"Requesting Salesforce access","pathname":"/integrations/resource-integrations/salesforce/requesting-access","siteSpaceId":"sitesp_4wGG6","description":"How to request access to a Salesforce permission set via P0","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Salesforce","icon":"salesforce"}]},{"id":"L3Cnca6oWCOCnTjRmkKb","title":"Snowflake","pathname":"/integrations/resource-integrations/snowflake","siteSpaceId":"sitesp_4wGG6","emoji":"2744","description":"Set up the P0 Security Snowflake integration for just-in-time access to Snowflake databases, roles, and grants with least-privilege control.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"}]},{"id":"a3MVhtBXzRYiJLK6S0Hf","title":"SSH","pathname":"/integrations/resource-integrations/ssh","siteSpaceId":"sitesp_4wGG6","emoji":"1f5a5","description":"How to request SSH permissions for AWS, Microsoft Azure and GCP instances.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"}]},{"id":"XZvaRvHQs0c1Azr5sNxN","title":"Self-hosted","pathname":"/integrations/resource-integrations/ssh/self-hosted","siteSpaceId":"sitesp_4wGG6","description":"Install the P0 SSH Agent on an on-premises or self-managed server and grant developers just-in-time, certificate-based SSH access with no standing credentials.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"SSH","emoji":"1f5a5"}]},{"id":"7wWeCKRzDyQxE3WuWATU","title":"Tailscale","pathname":"/integrations/resource-integrations/tailscale","siteSpaceId":"sitesp_4wGG6","emoji":"1f300","description":"Installing P0 access management for your Tailscale network takes about 5 minutes.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"}]},{"id":"vqbN0MrTTPHX5JAqQcSl","title":"Requesting Tailscale access","pathname":"/integrations/resource-integrations/tailscale/requesting-access","siteSpaceId":"sitesp_4wGG6","description":"How to request just-in-time access to Tailscale devices and network resources through P0 via Slack, Teams, Webex, the P0 CLI, or the P0 dashboard.","breadcrumbs":[{"label":"Integrations"},{"label":"Resource integrations","emoji":"1f511"},{"label":"Tailscale","emoji":"1f300"}]},{"id":"ZcsKfC9GWHPrf0JumIzi","title":"Directory integrations","pathname":"/integrations/directory-integrations","siteSpaceId":"sitesp_4wGG6","emoji":"1f465","description":"Connect P0 Security with Okta, Google Workspace, and Microsoft Entra ID. Configure directory integrations for group-based access policies and user provisioning.","breadcrumbs":[{"label":"Integrations"}]},{"id":"IcvYWfeZNF0cujiJ9q0p","title":"Microsoft Entra ID","pathname":"/integrations/directory-integrations/microsoft-entra-id","siteSpaceId":"sitesp_4wGG6","emoji":"1faaa","description":"Integrate P0 Security with Microsoft Entra ID for just-in-time access to directory roles, plus a security perimeter that guards role and group assignments.","breadcrumbs":[{"label":"Integrations"},{"label":"Directory integrations","emoji":"1f465"}]},{"id":"sUVlJJOsqn0tvVwS25N7","title":"Requesting Microsoft Entra ID access","pathname":"/integrations/directory-integrations/microsoft-entra-id/requesting-access","siteSpaceId":"sitesp_4wGG6","description":"Requesting access to Microsoft Entra ID Roles/Groups","breadcrumbs":[{"label":"Integrations"},{"label":"Directory integrations","emoji":"1f465"},{"label":"Microsoft Entra ID","emoji":"1faaa"}]},{"id":"owqPtFbqn8Ub6pTt6EGp","title":"Viewing security perimeter logs","pathname":"/integrations/directory-integrations/microsoft-entra-id/viewing-security-perimeter-logs","siteSpaceId":"sitesp_4wGG6","description":"View and query logs from the P0 Security perimeter Azure Function running in your Microsoft Entra ID environment.","breadcrumbs":[{"label":"Integrations"},{"label":"Directory integrations","emoji":"1f465"},{"label":"Microsoft Entra ID","emoji":"1faaa"}]},{"id":"vVKXZxFXZJ6mVhrRx1Ps","title":"Microsoft Entra ID (legacy)","pathname":"/integrations/directory-integrations/microsoft-entra-id-legacy","siteSpaceId":"sitesp_4wGG6","emoji":"1f5c3","description":"","breadcrumbs":[{"label":"Integrations"},{"label":"Directory integrations","emoji":"1f465"}]},{"id":"qINajMEBNFR1Wdylz1ys","title":"Requesting Microsoft Entra ID access (legacy)","pathname":"/integrations/directory-integrations/microsoft-entra-id-legacy/requesting-access","siteSpaceId":"sitesp_4wGG6","description":"Requesting access to Microsoft Entra ID groups","breadcrumbs":[{"label":"Integrations"},{"label":"Directory integrations","emoji":"1f465"},{"label":"Microsoft Entra ID (legacy)","emoji":"1f5c3"}]},{"id":"GlASQ4uKmfqZvsAF16g0","title":"Google Workspace","pathname":"/integrations/directory-integrations/google-workspace","siteSpaceId":"sitesp_4wGG6","emoji":"1f3e2","description":"Integrate P0 Security with Google Workspace to manage user access and inventory users and groups, including nested memberships, for IAM assessments.","breadcrumbs":[{"label":"Integrations"},{"label":"Directory integrations","emoji":"1f465"}]},{"id":"VHEv66GfE8oHC0BzsbKk","title":"Okta","pathname":"/integrations/directory-integrations/okta","siteSpaceId":"sitesp_4wGG6","emoji":"1f5dd","description":"Integrate P0 Security with Okta to manage user access, provision AWS access via SAML federation, and inventory your directory for IAM assessments.","breadcrumbs":[{"label":"Integrations"},{"label":"Directory integrations","emoji":"1f465"}]},{"id":"xMXtixNwJsDmp4Vc8PKM","title":"Approval integrations","pathname":"/integrations/approval-integrations","siteSpaceId":"sitesp_4wGG6","emoji":"2714","description":"","breadcrumbs":[{"label":"Integrations"}]},{"id":"9mmwSGzt5dScbf2bstRR","title":"PagerDuty","pathname":"/integrations/approval-integrations/pagerduty","siteSpaceId":"sitesp_4wGG6","emoji":"1f514","description":"Integrate P0 Security with PagerDuty to auto-approve just-in-time access requests for on-call engineers and escalate pending access approvals.","breadcrumbs":[{"label":"Integrations"},{"label":"Approval integrations","emoji":"2714"}]},{"id":"LXaRQxg6eT6c3wXayh1m","title":"Incident.io","pathname":"/integrations/approval-integrations/incidentio","siteSpaceId":"sitesp_4wGG6","emoji":"1f6a8","description":"","breadcrumbs":[{"label":"Integrations"},{"label":"Approval integrations","emoji":"2714"}]},{"id":"aY0FikmngYa5zxerOND5","title":"SIEM integrations","pathname":"/integrations/siem-integrations","siteSpaceId":"sitesp_4wGG6","emoji":"26a1","description":"SIEM integrations allow you to stream P0 audit logs to target SIEM tools (Datadog, Splunk).","breadcrumbs":[{"label":"Integrations"}]},{"id":"WUlz6cFtRcIQSy7U8ut4","title":"Audit log format","pathname":"/integrations/siem-integrations/audit-log-format","siteSpaceId":"sitesp_4wGG6","emoji":"1f4c4","description":"Reference for P0 audit log fields, actions, and payload formats streamed to SIEM integrations.","breadcrumbs":[{"label":"Integrations"},{"label":"SIEM integrations","emoji":"26a1"}]},{"id":"F1UWbVQxtQ0t606LLGaS","title":"Datadog setup","pathname":"/integrations/siem-integrations/datadog-setup","siteSpaceId":"sitesp_4wGG6","emoji":"1f415","description":"Integration to send P0 audit logs to Datadog.","breadcrumbs":[{"label":"Integrations"},{"label":"SIEM integrations","emoji":"26a1"}]},{"id":"1m9xSNmkFFHVSDAeJZUB","title":"Splunk HEC setup","pathname":"/integrations/siem-integrations/splunk-hec-setup","siteSpaceId":"sitesp_4wGG6","emoji":"1f4e1","description":"Integration to send P0 audit logs to Splunk instance.","breadcrumbs":[{"label":"Integrations"},{"label":"SIEM integrations","emoji":"26a1"}]},{"id":"lWwxovJexdPpPo6i6Ebs","title":"Tracker integrations","pathname":"/integrations/tracker-integrations","siteSpaceId":"sitesp_4wGG6","emoji":"1f4dd","description":"","breadcrumbs":[{"label":"Integrations"}]},{"id":"aleUh22431lxnIKTauJf","title":"Jira","pathname":"/integrations/tracker-integrations/jira","siteSpaceId":"sitesp_4wGG6","emoji":"1f3ab","description":"Install the P0 Security Jira integration to automatically open, assign, and track access-request tickets for just-in-time access approvals.","breadcrumbs":[{"label":"Integrations"},{"label":"Tracker integrations","emoji":"1f4dd"}]},{"id":"yJ3g4wGoUG85kYknyX2e","title":"Role-based access control","pathname":"/p0-management/role-based-access-control","siteSpaceId":"sitesp_4wGG6","emoji":"1f3a9","description":"Configure role-based access control to enforce least-privileged access for your P0 Security users. Assign roles and manage permissions across your organization.","breadcrumbs":[{"label":"P0 management"}]},{"id":"hI4iFHVsyCyy00CI7f3T","title":"Group-based access control","pathname":"/p0-management/group-based-access-control","siteSpaceId":"sitesp_4wGG6","emoji":"1f465","description":"Grant P0 roles to Okta groups instead of individual users. Configure a groups claim in Okta and map group names to P0 roles so members inherit access when they sign in.","breadcrumbs":[{"label":"P0 management"}]},{"id":"d1PEf9FcmVhBFbbMUDAa","title":"Generating an API key","pathname":"/p0-management/generating-an-api-key","siteSpaceId":"sitesp_4wGG6","emoji":"1f511","description":"Generate an API key to use the P0 Management API or install P0 via Terraform.","breadcrumbs":[{"label":"P0 management"}]},{"id":"khF0PBmoSllxgE0taG4n","title":"Management API","pathname":"/p0-management/management-api","siteSpaceId":"sitesp_4wGG6","emoji":"1f50c","description":"","breadcrumbs":[{"label":"P0 management"}]},{"id":"LqkcvIA1tVAYSd77d3F5","title":"Role management API","pathname":"/p0-management/management-api/role-management-api","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"P0 management"},{"label":"Management API","emoji":"1f50c"}]},{"id":"V8sw0WlvMjJ4b0pGKW2G","title":"Just-in-time settings API","pathname":"/p0-management/management-api/just-in-time-settings-api","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"P0 management"},{"label":"Management API","emoji":"1f50c"}]},{"id":"6oMaC0wA918lJTsH0A0q","title":"API key management API","pathname":"/p0-management/management-api/api-key-management-api","siteSpaceId":"sitesp_4wGG6","description":"Create, list, and delete P0 API keys programmatically with the Management API.","breadcrumbs":[{"label":"P0 management"},{"label":"Management API","emoji":"1f50c"}]},{"id":"vuEMFu9waOArmSHzsiuN","title":"P0 API overview","pathname":"/p0-api/p0-api-overview","siteSpaceId":"sitesp_4wGG6","emoji":"1f50c","description":"A map of every P0 API — access requests, policies, organization settings, inventory export, and integration webhooks — with the shared base URL, authentication, and permissions that apply to all of th","breadcrumbs":[{"label":"P0 API"}]},{"id":"eE92YyqerKptLosXqrDc","title":"Authenticating with the P0 API","pathname":"/p0-api/authenticating-with-the-p0-api","siteSpaceId":"sitesp_4wGG6","emoji":"1f510","description":"Get a bearer token to authenticate with the P0 Management API and the P0 Terraform provider, using a Google Cloud service-account token, the P0 CLI, or an API key.","breadcrumbs":[{"label":"P0 API"}]},{"id":"2vpPMGDm8jMCA5SDDOTM","title":"Automate access requests with the API","pathname":"/p0-api/automate-access-requests-with-the-api","siteSpaceId":"sitesp_4wGG6","emoji":"1f916","description":"Request, approve, deny, and revoke just-in-time access programmatically with the P0 Command and Access Requests APIs. Drive access from bots, CI/CD pipelines, and internal tooling instead of the P0 da","breadcrumbs":[{"label":"P0 API"}]},{"id":"45x01tDUwixt2oQOZxOq","title":"Manage P0 policies and settings as code","pathname":"/p0-api/manage-p0-policies-and-settings-as-code","siteSpaceId":"sitesp_4wGG6","emoji":"1f500","description":"Use the P0 Terraform provider to manage access policies, RBAC role assignments, and just-in-time access settings as code, with worked examples and migration guidance.","breadcrumbs":[{"label":"P0 API"}]},{"id":"V0cJ5ECpdbvaW7o5wdPQ","title":"Installing p0 CLI","pathname":"/p0-cli/installing-p0-cli","siteSpaceId":"sitesp_4wGG6","icon":"hammer","description":"Download and install the P0 CLI on macOS or Windows. Authenticate with your P0 account and start requesting cloud access from the command line.","breadcrumbs":[{"label":"P0 CLI"}]},{"id":"3jLNxJtiLuFBqOFE2sBe","title":"Windows","pathname":"/p0-cli/installing-p0-cli/windows","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"P0 CLI"},{"label":"Installing p0 CLI","icon":"hammer"}]},{"id":"7r50sITUWOpFiUFJ3qdB","title":"macOS","pathname":"/p0-cli/installing-p0-cli/macos","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"P0 CLI"},{"label":"Installing p0 CLI","icon":"hammer"}]},{"id":"v5hCNmAZM6OaI5UIpII4","title":"p0 commands and usage","pathname":"/p0-cli/p0-commands-and-usage","siteSpaceId":"sitesp_4wGG6","icon":"square-terminal","description":"Complete reference for P0 CLI commands including login, SSH, access requests, AWS role assumption, and Kubernetes configuration.","breadcrumbs":[{"label":"P0 CLI"}]},{"id":"qJNKpnX0b8nnhxGX2dB1","title":"p0 login","pathname":"/p0-cli/p0-commands-and-usage/p0-login","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"P0 CLI"},{"label":"p0 commands and usage","icon":"square-terminal"}]},{"id":"quh6PAnjTyXza9Hzik8K","title":"p0 logout","pathname":"/p0-cli/p0-commands-and-usage/p0-logout","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"P0 CLI"},{"label":"p0 commands and usage","icon":"square-terminal"}]},{"id":"SMGUDyjBsKplZPMHetiK","title":"p0 ssh","pathname":"/p0-cli/p0-commands-and-usage/p0-ssh","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"P0 CLI"},{"label":"p0 commands and usage","icon":"square-terminal"}]},{"id":"MZzfjawm9AIuiD8bAzQ9","title":"p0 request","pathname":"/p0-cli/p0-commands-and-usage/p0-request","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"P0 CLI"},{"label":"p0 commands and usage","icon":"square-terminal"}]},{"id":"ep5DfBBGLeHUW729AguQ","title":"p0 aws role assume","pathname":"/p0-cli/p0-commands-and-usage/p0-aws-role-assume","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"P0 CLI"},{"label":"p0 commands and usage","icon":"square-terminal"}]},{"id":"lUEWfbpZK8RGV0VAEhRq","title":"p0 aws permission-set assume","pathname":"/p0-cli/p0-commands-and-usage/p0-aws-permission-set-assume","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"P0 CLI"},{"label":"p0 commands and usage","icon":"square-terminal"}]},{"id":"kFTK8lrtF8dU5qyo08rJ","title":"p0 aws rds","pathname":"/p0-cli/p0-commands-and-usage/p0-aws-rds","siteSpaceId":"sitesp_4wGG6","description":"Generate RDS database authentication tokens for PostgreSQL and MySQL through P0 just-in-time access.","breadcrumbs":[{"label":"P0 CLI"},{"label":"p0 commands and usage","icon":"square-terminal"}]},{"id":"LGI6Z25oSgQy7QXRUIMo","title":"p0 ls","pathname":"/p0-cli/p0-commands-and-usage/p0-ls","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"P0 CLI"},{"label":"p0 commands and usage","icon":"square-terminal"}]},{"id":"VYj7gR1H3kQE6XFUzUiG","title":"p0 allow","pathname":"/p0-cli/p0-commands-and-usage/p0-allow","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"P0 CLI"},{"label":"p0 commands and usage","icon":"square-terminal"}]},{"id":"9EuQnJvjP8VfcwJMWbNY","title":"p0 grant","pathname":"/p0-cli/p0-commands-and-usage/p0-grant","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"P0 CLI"},{"label":"p0 commands and usage","icon":"square-terminal"}]},{"id":"C3d4kjVVgfFXv8h1687J","title":"p0 kubeconfig","pathname":"/p0-cli/p0-commands-and-usage/p0-kubeconfig","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"P0 CLI"},{"label":"p0 commands and usage","icon":"square-terminal"}]},{"id":"86nNjpWpVySUCIAk49OE","title":"p0 scp","pathname":"/p0-cli/p0-commands-and-usage/p0-scp","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"P0 CLI"},{"label":"p0 commands and usage","icon":"square-terminal"}]},{"id":"WYFLzLVcP9U1Et0FxcCF","title":"p0 file-transfer","pathname":"/p0-cli/p0-commands-and-usage/p0-file-transfer","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"P0 CLI"},{"label":"p0 commands and usage","icon":"square-terminal"}]},{"id":"1lNYC4flQ8IobMsURYuK","title":"p0 rdp","pathname":"/p0-cli/p0-commands-and-usage/p0-rdp","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"P0 CLI"},{"label":"p0 commands and usage","icon":"square-terminal"}]},{"id":"BclWY0o0kCLxb7aksktR","title":"p0 ssh-resolve","pathname":"/p0-cli/p0-commands-and-usage/p0-ssh-resolve","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"P0 CLI"},{"label":"p0 commands and usage","icon":"square-terminal"}]},{"id":"2q5TdwIs1aZS351oIz9I","title":"p0 claude mcp add","pathname":"/p0-cli/p0-commands-and-usage/p0-claude-mcp-add","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"P0 CLI"},{"label":"p0 commands and usage","icon":"square-terminal"}]},{"id":"jbCCwvPszBADoanXjcOy","title":"p0 claude mcp list","pathname":"/p0-cli/p0-commands-and-usage/p0-claude-mcp-list","siteSpaceId":"sitesp_4wGG6","description":"","breadcrumbs":[{"label":"P0 CLI"},{"label":"p0 commands and usage","icon":"square-terminal"}]},{"id":"2zndppUAlnGxScARIvQ4","title":"Troubleshooting","pathname":"/p0-cli/troubleshooting","siteSpaceId":"sitesp_4wGG6","icon":"screwdriver-wrench","description":"","breadcrumbs":[{"label":"P0 CLI"}]},{"id":"6Gx8OBtv9QSVer201k1u","title":"p0 login","pathname":"/p0-cli/troubleshooting/p0-login","siteSpaceId":"sitesp_4wGG6","description":"Fix common p0 login errors, including missing organization IDs, SSO failures, unsupported providers, and token expiry, when authenticating to P0 with the CLI.","breadcrumbs":[{"label":"P0 CLI"},{"label":"Troubleshooting","icon":"screwdriver-wrench"}]},{"id":"DPVKzWbh4GE1aCmCVcyE","title":"p0 ssh","pathname":"/p0-cli/troubleshooting/p0-ssh","siteSpaceId":"sitesp_4wGG6","description":"Diagnose and resolve p0 ssh connection errors, including missing dependencies, SSM and IAP tunnel failures, and host resolution issues, from the P0 CLI.","breadcrumbs":[{"label":"P0 CLI"},{"label":"Troubleshooting","icon":"screwdriver-wrench"}]},{"id":"EYVg9jyKPxbsddz1NnYR","title":"p0 request","pathname":"/p0-cli/troubleshooting/p0-request","siteSpaceId":"sitesp_4wGG6","description":"Resolve common p0 request errors when requesting just-in-time access from the CLI, including flag, provider, network, and approval workflow issues.","breadcrumbs":[{"label":"P0 CLI"},{"label":"Troubleshooting","icon":"screwdriver-wrench"}]},{"id":"IWxquvPeSEErHoGka8vV","title":"p0 aws role assume","pathname":"/p0-cli/troubleshooting/p0-aws-role-assume","siteSpaceId":"sitesp_4wGG6","description":"Fix p0 aws role assume errors, including authentication, role selection, and AWS credential issues, when assuming an AWS IAM role from the P0 CLI.","breadcrumbs":[{"label":"P0 CLI"},{"label":"Troubleshooting","icon":"screwdriver-wrench"}]},{"id":"UbdEw2YNKQX4wnBeTMgQ","title":"p0 aws permission-set assume","pathname":"/p0-cli/troubleshooting/p0-aws-permission-set-assume","siteSpaceId":"sitesp_4wGG6","description":"Resolve p0 aws permission-set assume errors, including IAM Identity Center, authentication, and credential issues, when assuming AWS access from the CLI.","breadcrumbs":[{"label":"P0 CLI"},{"label":"Troubleshooting","icon":"screwdriver-wrench"}]},{"id":"ORqtbXNpzJhFBt84o1Aw","title":"p0 ls","pathname":"/p0-cli/troubleshooting/p0-ls","siteSpaceId":"sitesp_4wGG6","description":"Troubleshoot p0 ls errors when listing available resources from the CLI, including authentication, pagination, invalid filters, and JSON output parsing.","breadcrumbs":[{"label":"P0 CLI"},{"label":"Troubleshooting","icon":"screwdriver-wrench"}]},{"id":"XsVtuOcPsl3GsMf2WDlD","title":"p0 allow","pathname":"/p0-cli/troubleshooting/p0-allow","siteSpaceId":"sitesp_4wGG6","description":"Fix p0 allow errors when pre-approving just-in-time access from the CLI, including authentication, flag, network, and provider validation issues.","breadcrumbs":[{"label":"P0 CLI"},{"label":"Troubleshooting","icon":"screwdriver-wrench"}]},{"id":"C3CTRumiEFNuUEyHZwpD","title":"p0 grant","pathname":"/p0-cli/troubleshooting/p0-grant","siteSpaceId":"sitesp_4wGG6","description":"Resolve p0 grant errors when granting just-in-time access from the CLI, including authentication, flag, network, and provisioning failures.","breadcrumbs":[{"label":"P0 CLI"},{"label":"Troubleshooting","icon":"screwdriver-wrench"}]},{"id":"zTVub9ACKhPIo7O7YmN6","title":"p0 kubeconfig","pathname":"/p0-cli/troubleshooting/p0-kubeconfig","siteSpaceId":"sitesp_4wGG6","description":"Fix p0 kubeconfig errors when configuring Kubernetes cluster access from the CLI, including missing dependencies, invalid formats, and AWS credential conflicts.","breadcrumbs":[{"label":"P0 CLI"},{"label":"Troubleshooting","icon":"screwdriver-wrench"}]},{"id":"3Oh0kHDivgNSjYeztd81","title":"p0 scp","pathname":"/p0-cli/troubleshooting/p0-scp","siteSpaceId":"sitesp_4wGG6","description":"Resolve p0 scp errors when copying files over SSH from the CLI, including remote path, Azure port, host resolution, and underlying scp issues.","breadcrumbs":[{"label":"P0 CLI"},{"label":"Troubleshooting","icon":"screwdriver-wrench"}]},{"id":"x2cvPzxamVADSXdxIUIc","title":"p0 ssh-resolve","pathname":"/p0-cli/troubleshooting/p0-ssh-resolve","siteSpaceId":"sitesp_4wGG6","description":"Fix p0 ssh-resolve errors used in your SSH config, including authentication, argument, key generation, and config file write issues, from the P0 CLI.","breadcrumbs":[{"label":"P0 CLI"},{"label":"Troubleshooting","icon":"screwdriver-wrench"}]},{"id":"vf8vzxjBHkfzvebNFNGd","title":"2026","pathname":"/change-log/2026","siteSpaceId":"sitesp_4wGG6","emoji":"1f4d6","description":"This page has all the current & past feature, updates and changes to the p0 app for 2026.","breadcrumbs":[{"label":"Change log"}]},{"id":"DCbcOVKHIqArHqlnKAjl","title":"2025","pathname":"/change-log/2025","siteSpaceId":"sitesp_4wGG6","emoji":"1f4d6","description":"This page has all the current & past feature, updates and changes to the p0 app for 2025.","breadcrumbs":[{"label":"Change log"}]}]}