Integration

Current + SentinelOne integration

A view-only SentinelOne feed that brings protected endpoints, open threats, and licence use into strategic business reviews.

Michael Baas
Written by the Current MSP team · Reviewed by Michael Baas, Efficiency Engineer, ITPartners+
Last updated September 5, 2026

SentinelOne Singularity is where a lot of MSPs run endpoint protection: the agent on every workstation and server, the detections it raises, and the licences that cover them. Current's SentinelOne integration is a view-only feed into the SBR/QBR module and the company alert band. It reads what SentinelOne already knows and never writes back.

What the integration does

Current authenticates to your SentinelOne console with a read-only Service User token, walks your sites, endpoints, and open threats every six hours, and stages the result as evidence for AI-assisted Strategic Business Reviews. Instead of exporting an agent list the week of the review, the protection numbers are already sitting on the company record when you open it.

What data flows

  • Sites — the SentinelOne partner roster, matched to your Current companies so every signal below lands on the right record, along with each site's plan tier and licence count.
  • Protected endpoints — machines with an active, non-decommissioned agent, split by server and workstation where SentinelOne reports which.
  • Agent health — whether each agent is reporting, how long it has been quiet, and whether it is behind on the agent version.
  • Open threats — detections that are unresolved or being worked, from the last 90 days, with classification, confidence, and what an analyst decided.
  • Licence use — active against total licences per site, so a partner close to their ceiling shows up before the renewal conversation.

Read-only by construction

The SentinelOne API is a full response and control plane: it can isolate a machine from the network, kill and quarantine processes, roll back a disk, and uninstall an agent. Current's connector holds a list of five read addresses and checks every request against it before sending, so none of those paths are reachable — not by configuration, but because they are absent from the code. Current also leaves forensic detail where it belongs: file paths, hashes, sign-in names, and network addresses stay in the partner's own console, and the company record links out to it.

Unknown reads as unknown

Where SentinelOne does not report something, Current leaves it blank rather than showing a zero. If the threat list could not be read on a run, open threats show as unknown rather than as a clean estate, and a site running unlimited licences reads unlimited rather than a percentage that would be about the connector instead of the partner. A protection number built by treating silence as a pass is a number you cannot defend when a partner asks which machines it covered.

Where it shows up

The security section is where business reviews tend to go vague, because the protection numbers live in the EDR console and the review lives somewhere else. An MSP running SentinelOne for a partner like Northwind Traders can open the account and see how many endpoints are actually protected, how many agents have gone quiet, what is open right now, and whether the site is close to its licence ceiling — without anyone assembling an export first. The review becomes a conversation about what the data says rather than about where the data came from.

Endpoint protection also joins the numbers Current already tracks. Open critical detections fold into the same security alert your other security feeds raise, including Huntress, so a partner-facing reader sees one line about critical issues being open rather than one per product. Protected endpoint counts sit beside the managed device count from your RMM, which is what turns how many machines do you have into how many of them are covered.

Sources

  1. 1.SentinelOne Singularity platformSentinelOne

Keep reading

See it live

Real data. No slideware.

We’ll show you Current on a real book — the pipeline, the dependency engine, the AI briefs, and how time flows straight into your PSA billing.

A 30-minute tour tailored to how your team sells and delivers
Straight answers on Halo, ConnectWise, Autotask, Microsoft 365, and HubSpot sync
A clear path to rolling it out across your team and co-managed clients
Or drop us a note
We'll get right back to you to set up your walkthrough.

We'll only use your details to set up your Current walkthrough.

See our Privacy Policy.