M ManySignal
MS
CI
Integration

Circleci Integration

CI/CD pipeline audit and job event monitoring for supply chain threat detection.

What this integration does

CircleCI meets agentic SOC

CircleCI's audit log API and webhook event system expose pipeline execution context, environment variable access, job runner details, and Orb usage. ManySignal ingests CircleCI audit events to detect anomalous pipeline behaviour, secrets access during builds, and supply chain compromise indicators in CI/CD workflows.

CircleCI Audit Log API ingestion for organisational events

Pipeline and workflow run event monitoring

Environment variable access anomaly detection

Data collected

  • Audit log events (user actions, project configuration changes)
  • Pipeline and workflow trigger events with actor and VCS context
  • Job run details including executor type and resource class
  • Context and environment variable access events
  • Orb references in pipeline configurations

Actions supported

  • Cancel a running pipeline via CircleCI API on verdict
  • Alert security team on secrets context access from unexpected branch
  • Create GitHub/GitLab issue for investigation
  • Trigger PagerDuty incident on critical CI/CD anomaly

Getting started

Set up in minutes

  1. 1

    Generate a CircleCI API token

  2. 2

    Enable Webhook notifications

  3. 3

    Add the connector in ManySignal

  4. 4

    Configure sensitive context rules

Circleci Integration: frequently asked questions

Can ManySignal detect secrets extracted during a CircleCI build?

ManySignal detects behavioural indicators: a job step that makes an outbound connection to an unexpected endpoint, or environment variable access followed by unusual network activity. Direct secret value monitoring is not possible.

Does this cover self-hosted CircleCI runners?

Yes. CircleCI self-hosted runner events appear in the audit log. ManySignal can also monitor the host system running the runner via endpoint agent for deeper visibility.

How does ManySignal handle CircleCI's audit log retention limits?

CircleCI retains audit logs for 90 days on paid plans. ManySignal backfills on initial setup and maintains its own long-term retention per your plan.

Can I alert on PRs from forks triggering production contexts?

Yes. CircleCI audit events include actor and project metadata. ManySignal can detect when a fork-originated pipeline accesses contexts restricted to the main repository.

Does ManySignal compare CircleCI Orb versions for supply chain risks?

ManySignal tracks Orb references in pipeline configuration changes. A sudden Orb version downgrade or switch to a community Orb is flagged as a supply chain risk indicator.

What happens to events if CircleCI's API is unavailable?

ManySignal implements retry and backoff. On reconnection, audit events within the retention window are backfilled automatically.

Does ManySignal support CircleCI Server (self-hosted)?

CircleCI Server's audit log API is functionally equivalent to CircleCI Cloud. Configure the base API URL to point to your Server instance.

Can I correlate CircleCI jobs with GitHub commits?

Yes. CircleCI pipeline events include the VCS commit SHA and repository. ManySignal correlates these with GitHub push events and repository audit events for end-to-end CI/CD visibility.

How does ManySignal handle parallelism in CircleCI jobs?

Each parallel job step is treated as an individual event in the ManySignal timeline. Parallelism metadata is preserved for investigation context.

Is CircleCI usage at the project level or organisation level?

ManySignal ingests both: project-level pipeline events via webhooks and organisation-level admin events via the Audit Log API.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.