## Drata integration Drata is a compliance automation platform for managing controls, evidence, risks, vendors, and policies across security frameworks. Agen.co connects to Drata through Drata's own hosted MCP server as an **Official** connector. Each user authorizes with their own Drata account, and agents can only reach what both the granted scopes and that user's Drata role allow. Prerequisites - A Drata administrator must first set up OAuth for your Drata tenant on the **MCP Configuration** page, which only administrators can open. Until that is done, users cannot authorize the connection. - A Drata account for each person whose agents will use the connector. The connector uses Drata's US endpoint, `https://mcp.drata.com/mcp/`. Drata also runs EU and APAC endpoints, which the connector does not offer a field for. ### Set up OAuth in Drata A Drata administrator creates the OAuth configuration once for the tenant: 1. In Drata, open the **MCP Configuration** page. 2. Enter a name and a description for the OAuth configuration. 3. Set an expiration date for the configuration. 4. Select the scopes you want to allow. 5. Save the configuration. Users only ever get the intersection of the scopes you select and the permissions their Drata role already has, so a broad scope selection does not widen anyone's access. When the configuration expires, users can no longer authorize, so renew it before the expiration date. | Area | Scopes the MCP server publishes | | --- | --- | | Controls and frameworks | `read:controls`, `create:control`, `update:control`, `read:framework`, `read:monitor-test` | | Evidence | `read:evidence`, `create:evidence`, `update:evidence`, `delete:evidence` | | Risk | `read:risk`, `create:risk`, `update:risk`, `delete:risk`, `read:risk-registers` | | Policies | `read:policy`, `read:assigned-policies` | | Vendors | `read:vendor`, `create:vendor`, `update:vendor`, `delete:vendor`, `read:vendor-security-review`, `read:vendor-document` | | Personnel and devices | `read:personnel`, `update:personnel`, `create-restricted:personnel`, `read:device`, `create:background-checks`, `create:user-document` | | Workspace and users | `read:workspace`, `read:company`, `read:users`, `read:user` | ### Connect Drata in Agen.co Drata registers Agen.co automatically, so there is no client ID or secret to copy and no callback URL to allowlist. 1. In the Agen.co portal, go to **Connectors** → **My connectors** and click **Add connector**. 2. In the **Select connector** drawer, search for `Drata` and select it. The **Add Drata** panel opens. 3. Fill in the field: | Field | Required | Description | | --- | --- | --- | | **Instance Slug** | Yes | Namespaces this instance — it prefixes each imported tool as `slug__tool`, so several instances of the same MCP can coexist. Prefilled with `drata`. Use lowercase kebab-case. You can change it later from the connector's settings. | 4. Click **Connect**. Drata opens in a new tab, and the panel shows **Waiting for authorization — complete it in the opened tab…** 5. On the **Sign in to Drata** page, enter your Drata email address, finish signing in, and approve the requested access. 6. Back in Agen.co, the panel switches to **Select the tools to import from Drata.** Every tool is toggled on; turn off any you don't want to import, then click **Add**. The connector is created and its tools imported only when you click **Add**. If you close the panel before that, nothing is saved, even if the Drata tab reported success. ### What it covers | Area | What it covers | | --- | --- | | Controls and evidence | Search, create, and update controls, manage evidence, and read framework requirements | | Risk | Search, create, update, and delete risks, and list risk registers | | Personnel and devices | List and search personnel and devices, review compliance status, and update employment records | | Vendors | List, create, update, and delete vendors, and read vendor documents and security reviews | | Policies and workspace | List policies and assigned policies, and read workspace and user data | The list follows Drata's MCP documentation (checked 2026-10-05) and can change. Enabling the Drata connector isn't enough on its own. Tool calls remain denied until you create a [policy](/agen-for-work/policies/overview) that grants access to the specific tools you want to expose. ### Additional resources - [Drata MCP server documentation](https://developers.drata.com/developer-portal/v2/mcp-server/) - [Drata MCP setup and usage guide](https://help.drata.com/en/articles/13379899-drata-mcp-setup-usage-guide)