Deploy into your existing architecture.
Tether acts as a specialized data source for the security tools you already operate. It pushes events to your SIEM, pulls identity from your IdP, and integrates directly into your current SOC workflows.
A short version of this also appears on How it works and Pilot. Nothing to rip out — Tether extends the stack you already trust.
Write the audit trail where it belongs.
AI traffic shouldn't live in a siloed vendor dashboard. Tether forwards every cryptographically signed event to your SIEM natively.
Splunk
Shipped- Tether events land in your Splunk Cloud or on-prem instance natively — no connector to build.
- Each event carries the policy version, identity, agent, host, and verdict, so your existing searches and dashboards just work.
- The access token lives in your Splunk; Tether holds it write-only.
Microsoft Sentinel
Shipped- Streams into Log Analytics with no app registration to stand up.
- A distinct log type per event family means your Sentinel analytics rules can target Tether's stream directly.
- Configured per workspace; your security team keeps full control of detection logic.
Syslog (air-gap clean)
Shipped- Targets on-prem Splunk, rsyslog, or any standards-compliant collector — with no internet dependency.
- Part of an architecturally coherent air-gap path: pair it with an on-prem control plane and a local judge, and every component supports running with no internet dependency.
- Same reliable delivery as the other adapters.
Signed webhooks
Shipped- For anything else downstream — SOAR, a ticketing system, your own pipeline — Tether posts signed, verifiable events.
- Filter each receiver to only the event types and verdicts it cares about.
- Secrets are write-only and redacted everywhere after registration.
Exact routes, signing algorithms, retry timing, and the event envelope are in the technical brief →
Identity, authentication, and lifecycle.
We defer to your IdP. Sign-on, role assignment, and offboarding are controlled entirely by your existing enterprise directory via SSO and SCIM.
Single sign-on
Shipped- SAML 2.0 and OIDC — your team signs in with the identity provider you already run.
- Upload your IdP metadata and SSO is live; no per-user setup.
- Every session is scoped to a role: admin, operator, or viewer.
Directory sync
Shipped- Create, update, and remove operators directly from your directory — no parallel user list to keep in step.
- Group membership maps to role, so access stays correct as people change teams.
- A deprovision in Okta or Entra cuts access here, and every change lands in the audit trail.
The SSO/SCIM endpoints, signature scheme, and group-to-role mapping are in the technical brief →
A machine that's drifted out of compliance
drops out of device trust on its own.
Your conditional-access policy reads whether a developer's machine is actually running Tether and current on policy — in the format your IdP already understands. No converter to write, no translation for your Okta or Entra team.
Okta Device Trust
Shipped- Tether posture drops straight into Okta's conditional-access rules with no custom integration.
- Carries the signals that matter: whether the agent is live and on the current policy.
- A non-compliant machine falls out of the trusted set automatically.
Microsoft Entra
Shipped- Mirrors the managed-device shape Entra Conditional Access already reads.
- Tether's signal sits out of the way of your existing Intune data — no schema change.
- Your Microsoft team works with a format they already know.
Tether-native
Shipped- Full per-host detail for your own conditional-access broker or scheduled pulls.
- Filter to compliant-only or to changes since a given time.
- Read-only — posture reporting, never a write path.
CSV
Shipped- Clean, spreadsheet-safe export for ad-hoc audits and evidence packets.
- Drops into incident-response timelines without surprises.
- The format your compliance team will ask for anyway.
Export routes, the exact field shapes, and filter parameters are in the technical brief →
A change log of every policy decision —
ready for your auditor.
Append-only policy audit
- Every policy publish, revert, and fleet acknowledgement is recorded — who did it, why, and what changed.
- Reads directly against a SOC 2 CC8 change-management evidence requirement; pull it on a schedule into your own systems.
- The record lives in your cloud storage, inside your tenant — not on a Tether server.
Export route, file format, and storage location are in the technical brief →
Stand up an adapter in an afternoon.
A platform engineer who knows Splunk or Sentinel registers the adapter in one call. We can pair on it during the pilot.