Platform capability
Normalized Event Stream
Single schema for third-party OAuth events across IdPs — webhook, batched HTTP, or S3 sink delivery to Splunk, Datadog, Elastic, and Sumo Logic.
Start a 30-day trial06 · EVENTS
Normalized Event Stream
Every connector emits events. Every IdP and every SaaS app speak slightly different dialects of those events. ScopeMantle normalizes them into a single schema — actor, action, target, scopes, source, risk — so your SIEM doesn't have to. The schema is documented at /docs/event-schema, versioned, and stable across connector updates.
Delivery is your choice: webhook for low-latency, batched HTTP for systems that prefer pulls, or direct S3 sink for cold storage and your data lake. Splunk, Datadog, Elastic, and Sumo Logic have first-class destinations; everything else gets a documented JSON contract. Twelve months of retention is the default, configurable up or down per workspace.
- Single normalized schema across Okta, Google Workspace, and (soon) Entra
- Webhook, batched HTTP, and S3 sink delivery — pick what your stack prefers
- Splunk, Datadog, Elastic, Sumo Logic — first-class SIEM destinations
- Risk tagging on every event from the same engine that drives policy
- 12-month retention by default, configurable per workspace
- Slack and PagerDuty alerting filtered by policy tags or scope patterns
Frequently asked
Platform — common questions
Find the Context.ai in your org before the attacker does.
15-minute connection. First inventory in an hour. Vendor risk scores for every third party by tomorrow.
Book a demo to see the inventory on your own tenant.