Skip to content
Last updated

Drata integration

Drata is a compliance automation platform for managing controls, evidence, risks, vendors, and policies across security frameworks.

Agen.co connects to Drata through Drata's own hosted MCP server as an Official connector. Each user authorizes with their own Drata account, and agents can only reach what both the granted scopes and that user's Drata role allow.


Prerequisites

  • A Drata administrator must first set up OAuth for your Drata tenant on the MCP Configuration page, which only administrators can open. Until that is done, users cannot authorize the connection.
  • A Drata account for each person whose agents will use the connector.

The connector uses Drata's US endpoint, https://mcp.drata.com/mcp/. Drata also runs EU and APAC endpoints, which the connector does not offer a field for.

Set up OAuth in Drata

A Drata administrator creates the OAuth configuration once for the tenant:

  1. In Drata, open the MCP Configuration page.
  2. Enter a name and a description for the OAuth configuration.
  3. Set an expiration date for the configuration.
  4. Select the scopes you want to allow.
  5. Save the configuration.

Users only ever get the intersection of the scopes you select and the permissions their Drata role already has, so a broad scope selection does not widen anyone's access. When the configuration expires, users can no longer authorize, so renew it before the expiration date.

AreaScopes the MCP server publishes
Controls and frameworksread:controls, create:control, update:control, read:framework, read:monitor-test
Evidenceread:evidence, create:evidence, update:evidence, delete:evidence
Riskread:risk, create:risk, update:risk, delete:risk, read:risk-registers
Policiesread:policy, read:assigned-policies
Vendorsread:vendor, create:vendor, update:vendor, delete:vendor, read:vendor-security-review, read:vendor-document
Personnel and devicesread:personnel, update:personnel, create-restricted:personnel, read:device, create:background-checks, create:user-document
Workspace and usersread:workspace, read:company, read:users, read:user

Connect Drata in Agen.co

Drata registers Agen.co automatically, so there is no client ID or secret to copy and no callback URL to allowlist.

  1. In the Agen.co portal, go to Connectors → My connectors and click Add connector.

  2. In the Select connector drawer, search for Drata and select it. The Add Drata panel opens.

  3. Fill in the field:

    FieldRequiredDescription
    Instance SlugYesNamespaces this instance — it prefixes each imported tool as slug__tool, so several instances of the same MCP can coexist. Prefilled with drata. Use lowercase kebab-case. You can change it later from the connector's settings.
  4. Click Connect. Drata opens in a new tab, and the panel shows Waiting for authorization — complete it in the opened tab…

  5. On the Sign in to Drata page, enter your Drata email address, finish signing in, and approve the requested access.

  6. Back in Agen.co, the panel switches to Select the tools to import from Drata. Every tool is toggled on; turn off any you don't want to import, then click Add.

The connector is created and its tools imported only when you click Add. If you close the panel before that, nothing is saved, even if the Drata tab reported success.

What it covers

AreaWhat it covers
Controls and evidenceSearch, create, and update controls, manage evidence, and read framework requirements
RiskSearch, create, update, and delete risks, and list risk registers
Personnel and devicesList and search personnel and devices, review compliance status, and update employment records
VendorsList, create, update, and delete vendors, and read vendor documents and security reviews
Policies and workspaceList policies and assigned policies, and read workspace and user data

The list follows Drata's MCP documentation (checked 2026-10-05) and can change.

Enabling the Drata connector isn't enough on its own. Tool calls remain denied until you create a policy that grants access to the specific tools you want to expose.

Additional resources