Skip to main content

Wiz + Native

Turn Wiz risk context into cloud controls that hold.

Wiz gives security teams visibility into risk across their cloud environments. Native brings that context into the Cloud Security Control Plane so teams can use it to inform the controls, guardrails and enforcement that protect their environment.

Better together

Wiz

Find and prioritize cloud risk

Native

Bring risk context into cloud policy and enforcement

AWS / Azure / Google Cloud / OCI

Simulate and deploy provider-native controls

  • Bring Wiz findings and cloud context into Native.
  • See Wiz risk alongside the cloud accounts, zones and policies Native is protecting.
  • Use risk context to help move from finding issues to putting stronger preventative controls in place.

See risk context alongside the controls protecting your cloud

Native surfaces Wiz risk context within the same views security teams use to understand cloud accounts, zones and policies, making it easier to connect what Wiz is finding with the controls governing the environment.

Wiz risks and findings surfaced inside a Native policy, grouped into risks, misconfigurations and threat detections across the environments the policy covers.
Wiz risk context inside a Native policy: open risks, misconfigurations and threat detections for the environments the policy governs.

How the integration works

Connect Wiz

Connect Native to your Wiz environment using a Wiz service account.

Bring Wiz context into Native

Native pulls relevant Wiz findings plus cloud account, resource and data-classification context.

Use that context in Native

Native surfaces Wiz context alongside its model of your cloud environment and the policies and controls protecting it.

Set up the Wiz integration

Step 1: Configure Wiz

Create the service account in Wiz, following Wiz’s own documentation. Wiz is the source of truth for its setup flow, so we don’t reproduce it here.

Step 2: Grant the permissions required by Native

The Wiz service account used by Native requires the following read-only permissions. These define the Wiz data Native needs to access for the integration to function. Native reads from Wiz and never writes back to it.

You don’t have to grant all of them on day one. The five marked Core are enough to run the integration. You can add the rest later without recreating or reconnecting the service account, and Native picks up the newly available data on the next sync.

Wiz also offers a read:all permission that covers every read-only scope at once. We’d recommend granting the individual scopes you need instead, so the service account stays least-privilege.

Native also needs the service account configured with:

  • Type: Custom Integration (GraphQL API)
  • Projects: left empty, for tenant-wide access
PermissionWhat Native uses it forCore
read:resourcesRead cloud accounts and resources, so Native can match Wiz data to the right accounts in your environmentCore
read:configuration_findingRead CSPM configuration findingsCore
read:data_findingRead DSPM and data classification findings, which feed Native's data classificationCore
read:vulnerability_findingRead vulnerability findingsCore
read:issuesRead Wiz Issues, which Native surfaces as RisksCore
read:access_findingRead access-related findings
read:excessive_access_findingRead excessive access findings
read:inventory_findingRead inventory findings
read:attack_surface_findingRead attack surface findings
read:ai_security_findingRead AI security findings
read:malware_findingRead malware findings
read:iac_findingRead Infrastructure-as-Code findings
read:penetration_test_findingRead penetration testing findings
read:sast_findingRead static application security testing (SAST) findings
read:software_supply_chain_findingRead software supply chain findings
read:cloud_cost_monitor_findingRead cloud cost optimization findings. Requires a Wiz Cost Optimization license

If a permission isn’t granted, Native skips that data type and keeps synchronizing everything else. The integration doesn’t fail, it just shows less.

Step 3: Connect Wiz in Native

Once the Wiz service account is ready:

  1. Open Integration Center → Wiz in Native.
  2. Enter your Wiz tenant region.
  3. Enter the Client ID.
  4. Enter the Client Secret.
  5. Click Connect.
  6. Confirm the connection is Healthy.
  7. Confirm the last successful sync.
The Wiz integration setup screen in Native, with fields for the tenant data center, Client ID and Client Secret.
Entering the Wiz service account credentials in Native: tenant data center, Client ID and Client Secret.
The connected Wiz integration in Native, showing connection status, last sync, findings ingested and the sync state of each connected cloud organization.
A healthy Wiz connection: last sync, findings ingested, and the state of every connected cloud organization.

Need the complete customer guide? Open the full Wiz integration guide in Native Docs (Native login required)

Technical details

See how Native turns cloud security intent into controls that hold.