Can AI agents automate Wiz?
Wiz · saas · enterpriseobservability
Wiz is automatable today through a vendor-declared first-party MCP server. This record is the Wiz CNAPP / Security Graph platform, including Issues, threats, Wiz AI Agents, and Wiz AI Skills reachable through Wiz MCP. It is not CrowdStrike Falcon or Snyk. A July 2026 Wiz blog announces general availability of Wiz MCP for AI assistants, custom agents, and AI-powered applications, grounded in the Security Graph and reusable Wiz AI Skills. The earlier April 2025 preview post says Wiz built the server and that it translates natural-language queries into Wiz operations such as listing critical issues, examining an issue, and inventory search. Public blogs do not publish a tool table, transport URL, or authentication contract. Customer documentation at docs.wiz.io returned a bot checkpoint on this pass and was not used. A public Wiz CISA Secure-by-Design page states that all programmatic interaction with the Wiz SaaS platform uses an authenticated GraphQL endpoint and that custom integrations use Service Accounts with a per-request short-lived API token flow. That page does not publish the GraphQL URL, header names, or schema. No official CLI or language SDK was established from the opened pages. iPaaS catalogs were not opened. Computer-use viability is unassessed. MCP scores 6 because it is official and generally available but the public-doc gap on tools and auth keeps it in the limited-official band. The GraphQL API scores 5 for the same public-contract gap.
Best path today: mcp · Overall automatability: 6/10
Modalities
| Modality | Status | Detail |
|---|---|---|
| API | yes | graphqlservice-account-short-lived-token coverage: unknown |
| SDK | unknown | official: unknown |
| MCP | yes | verdict: official |
| Integrations | unknown | |
| CLI | unknown | |
| Extensibility | unknown | webhooks: unknown |
| Data access | export: unknown · import: unknown | |
| RPA / UI automation | unknown | web-dom No repeatable UI probe was run. Public pages establish a first-party Wiz MCP and a GraphQL API used through Service Accounts. Browser automation remains unassessed.
|
| Computer use | unknown | measured verdicts only — "unknown" means not yet probed by us |
Scores
| api | mcp | integrations | cli | rpa | computer use | overall |
|---|---|---|---|---|---|---|
| 5 | 6 | — | — | — | — | 6 |
Evidence
| Fact | Tier | Source | Date |
|---|---|---|---|
homepage | declared | source | 2026-09-04 |
license | declared | source | 2026-09-04 |
modalities.api.exists | declared | source | 2026-09-04 |
modalities.api.kinds[0] | declared | source | 2026-09-04 |
modalities.api.auth[0] | declared | source | 2026-09-04 |
modalities.api.coverage | declared | source | 2026-09-04 |
modalities.mcp.first_party | declared | source | 2026-09-04 |
modalities.agent_docs.llms_txt | declared | source | 2026-09-04 |
verdict.scores.api | declared | source | 2026-09-04 |
verdict.scores.mcp | declared | source | 2026-09-04 |
freshness.watch[0].url | declared | source | 2026-09-04 |
freshness.watch[1].url | declared | source | 2026-09-04 |
freshness.watch[2].url | declared | source | 2026-09-04 |
freshness.watch[3].url | declared | source | 2026-09-04 |
freshness.watch[4].url | declared | source | 2026-09-04 |
Related tools
Other products in this database that share a category with Wiz.
Last verified 2026-09-04 · volatility high · JSON record