Datadog v2 Application and Cloud Security
Datadog v2 application security, agentless scanning, CSM threats, and sensitive data scanning. Generated from Datadog's immutable hash-pinned official v2 OpenAPI schema. Reads are uncached; sensitive reads are marked sensitive-read. Every mutation is grant-off and approval-gated, destructive operations are labeled explicitly, and unsafe JSON integers remain exact decimal strings. Provider pagination is walked only when its cursor can be replayed through the original admitted route without changing the documented request shape; nested JSON-body cursors remain explicit.
What this pack installs
- datadog-v2-appsec-csm Ingredient
Trust & control
What installing this whole pack would let it do. Recued grants these permissions at install — review them there before approving.
What it's allowed to do
Destructive
Web APIs
datadog-v2-appsec-csm
external change
Admin: v2.create_application_security_waf_custom_rule · Always asksAdmin: v2.create_application_security_waf_exclusion_filter · Always asksAdmin: v2.create_application_security_waf_policy · Always asksAdmin: v2.create_aws_on_demand_task · Always asksAdmin: v2.create_aws_scan_options · Always asksAdmin: v2.create_azure_scan_options · Always asksAdmin: v2.create_cloud_workload_security_agent_rule · Always asksAdmin: v2.create_csm_threats_agent_policy · Always asksAdmin: v2.create_csm_threats_agent_rule · Always asksAdmin: v2.create_gcp_scan_options · Always asksAdmin: v2.create_scanning_group · Always asksAdmin: v2.create_scanning_rule · Always asksDestructive: v2.delete_application_security_waf_custom_rule · Always asksDestructive: v2.delete_application_security_waf_exclusion_filter · Always asksDestructive: v2.delete_application_security_waf_policy · Always asksDestructive: v2.delete_aws_scan_options · Always asksDestructive: v2.delete_azure_scan_options · Always asksDestructive: v2.delete_cloud_workload_security_agent_rule · Always asksDestructive: v2.delete_csm_threats_agent_policy · Always asksDestructive: v2.delete_csm_threats_agent_rule · Always asksDestructive: v2.delete_gcp_scan_options · Always asksDestructive: v2.delete_scanning_group · Always asksDestructive: v2.delete_scanning_rule · Always asksRead: v2.download_cloud_workload_policy_file · Asks approvalRead: v2.download_csm_threats_policy · Asks approvalRead: v2.get_application_security_waf_custom_rule · Asks approvalRead: v2.get_application_security_waf_exclusion_filter · Asks approvalRead: v2.get_application_security_waf_policy · Asks approvalRead: v2.get_aws_on_demand_task · No approvalRead: v2.get_aws_scan_options · No approvalRead: v2.get_azure_scan_options · No approvalRead: v2.get_cloud_workload_security_agent_rule · No approvalRead: v2.get_csm_threats_agent_policy · Asks approvalRead: v2.get_csm_threats_agent_rule · Asks approvalRead: v2.get_gcp_scan_options · No approvalRead: v2.list_application_security_waf_custom_rules · Asks approvalRead: v2.list_application_security_waf_exclusion_filters · Asks approvalRead: v2.list_application_security_waf_policies · Asks approvalRead: v2.list_aws_on_demand_tasks · No approvalRead: v2.list_aws_scan_options · No approvalRead: v2.list_azure_scan_options · No approvalRead: v2.list_cloud_workload_security_agent_rules · No approvalRead: v2.list_csm_threats_agent_policies · Asks approvalRead: v2.list_csm_threats_agent_rules · Asks approvalRead: v2.list_gcp_scan_options · No approvalRead: v2.list_scanning_groups · Asks approvalRead: v2.list_standard_patterns · Asks approvalAdmin: v2.reorder_scanning_groups · Always asksAdmin: v2.update_application_security_waf_custom_rule · Always asksAdmin: v2.update_application_security_waf_exclusion_filter · Always asksAdmin: v2.update_application_security_waf_policy · Always asksAdmin: v2.update_aws_scan_options · Always asksAdmin: v2.update_azure_scan_options · Always asksAdmin: v2.update_cloud_workload_security_agent_rule · Always asksAdmin: v2.update_csm_threats_agent_policy · Always asksAdmin: v2.update_csm_threats_agent_rule · Always asksAdmin: v2.update_gcp_scan_options · Always asksAdmin: v2.update_scanning_group · Always asksAdmin: v2.update_scanning_rule · Always asks