Connect with Armorcode
Integrate Harness AIDI with Armorcode.
Armorcode is an Application Security Posture Management (ASPM) platform that aggregates and normalizes security findings from multiple scanners. This integration provides a unified view of security posture, remediation progress, and team-level ownership using data aggregated from all security tools connected to Armorcode.
Once connected, the Open vulnerabilities by severity metric updates on the Security Insights dashboard in the Security tab of the Insights page.
Security findings are mapped to teams, enabling visibility into open vulnerabilities owned by each engineering team, remediation velocity trends per team, and alignment with your existing Harness AIDI Org Tree structure.
Prerequisites
Ensure that you have the SEI Admin role and an ArmorCode Service Account API token.
Create an Armorcode API token
In Armorcode, create a Service Account API token with read-only access to the following scopes:
Products: Applications and business units
Findings: Vulnerabilities and security issues
Assets: Repositories, container images, and cloud resources
Scans: Scan history and scan status
Add the integration
From the SEI navigation menu, click Account Management.
On the Integrations page, select the Available Integrations tab.
Locate the Armorcode integration and click Add Integration.
In the Overview section, provide a name for the integration (for example,
Armorcode Production) and optionally, add tags.Click Continue.
Add your Armorcode instance URL (for example,
https://app.armorcode.com) in theArmorcode URLfield.Enter your Armorcode Service Account API token in the
API Tokenfield. To add another API token, click + Add another token.Click Validate & Continue.
Validate that the connection is successful and click Continue.
In the Configure Filters section, limit the data ingested from Armorcode by configuring one or more of the security tools detected in your Armorcode instance (for example, Wiz or Snyk).
For each tool:
Enter or select the Tool Name. At least one tool name is required.
Select an Aggregate By field to group findings by (pick a single value, for example
repositoryName). This determines the aggregation dimension used in the Vulnerabilities Drilldown section of the Security Insights dashboard.Optionally, select a Tag Key and manually enter one or more Tag Key Values (for example, a GP ID such as
gp4013). These values are not pulled from discovered filters, and populate the Group Value shown in the Vulnerabilities Drilldown section of the Security Insights dashboard.Configure up to 5 Filters to limit ingested findings by attributes such as status, category, type, severity, and environment. The page shows how many filters are configured (for example,
Filters · 5 of 5 configured).
Click Continue.
Under Spot Check, click Run spot check to preview severity counts for your configured filters before finishing setup.
Review the results and click Save to complete the integration.
Once the integration has been created, Harness AIDI imports products, assets, users, and team-related metadata from Armorcode. No manual refresh is required after setup.
Products
Applications and business units defined in Armorcode.
Assets
Repositories, container images, and cloud resources.
Findings
Security vulnerabilities and issues from all connected tools.
Users
Developer and ownership information used for team mapping.
Scan Status
Scan health, freshness, and execution status.
Data is automatically synchronized every 8 hours across Security Insights metrics and dashboards.
Integration monitoring
To monitor the status of the Armorcode integration, navigate to the Monitoring tab. This page provides visibility into data ingestion, availability, and overall integration health.
The following health indicators are displayed: Healthy, Unhealthy, Pending, or No Data. These indicators help ensure data freshness and identify issues impacting security reporting.
You can use the time range selector to switch between Last 7 Days and Last 30 Days. Changing the time range updates both the Security Issues Ingested and Data Availability sections, along with their associated charts.
Security Issues Ingested
The Security Issues Ingested section shows the volume of security findings ingested from Armorcode during the selected time range (for example, Ingested in Last 30 Days: 126). This count updates automatically based on the selected time range (Last 7 Days or Last 30 Days).
Data Availability
The Data Availability timeline visualizes the health of data ingestion across the selected time range (for example, from 30 days ago through today). Each segment reflects the integration status at a given point in time:
Healthy: Data was successfully ingested
Unhealthy: Ingestion failed or encountered errors
Pending: Ingestion is in progress
No Data: No data was received for the time window
Next steps
Once you've configured the Armorcode integration, you can:
Select the Armorcode integration from the
Security Toolssection on the Integrations tab in Team SettingsMap security data to teams and scope findings on the Security tab in Team Settings
Examine the Security Insights dashboard to analyze organization and team-level security posture
Troubleshooting
Last updated
Was this helpful?