What you need
A Wiz service account, with permission to read Issues and to update the status of, and comment on, both issues and threats. Wiz’s API uses OAuth2 client credentials, so a service account is the only way to authenticate. See Wiz’s documentation for creating one and for the scopes it offers. Note that Wiz shows the client secret only once, when the account is created.Connecting Wiz
Go to Settings → Integrations in incident.io, find Wiz, and click Connect. You need three values from your service account:- Client ID
- Client secret
- Region, which Wiz calls your Tenant Data Center. It looks like
us17oreu2, and Wiz shows it under Tenant Info in your portal.
Choosing what resolving does
Once connected, the integration’s settings let you choose how resolving an alert in incident.io affects Wiz. You set this separately for two groups, because Wiz treats them differently:- Posture issues, covering toxic combinations and cloud configuration findings
- Threats, from Wiz Defend
When incident.io resolves a Wiz Issue, Wiz requires a reason, so you choose which one we
send. The options differ by group:
- Posture issues: False positive, Exception, Won’t fix
- Threats: Malicious threat, Not malicious, Security test, Planned action, Inconclusive
If incident.io resolves an alert while the Wiz Issue is still open, Wiz can reopen the alert on its next update, so
the two systems drift apart. Leaving Wiz as the source of truth keeps them in step.