Who opened what
Private app launches, denied attempts and session context become machine-readable events.
Monitoring integration
Security teams need events where they already investigate incidents. BusinessProxy can deliver signed event notifications and provide stable mappings for SIEM collectors without pretending to be the SIEM.
V1 is signed HTTPS export with deterministic Syslog/CEF adapter mapping. Native syslog transport, OpenTelemetry and vendor-certified marketplace connectors are not included in V1.
SOC workflow
Access review should not depend on an administrator opening the dashboard. Event export gives SOC tooling the data needed for correlation, alerting and incident timelines.
Private app launches, denied attempts and session context become machine-readable events.
Routing and region context helps explain why a work domain used a specific egress path.
Syslog JSON and CEF mappings let teams feed existing collectors without waiting for a marketplace app.
Delivery contract
Event export should be treated as a security integration: signed payloads, replay-safe timestamps, sanitized fields and explicit retry/failure behavior.
Current boundary
BusinessProxy exports the signals; the customer SIEM, SOAR or data lake performs advanced analytics and response orchestration. Response APIs are planned separately and are not a completed SOAR platform.
Next step
The documentation page shows what to configure, how to verify the setup and which operational boundaries to review before rollout.