API endpoints exist for 'Get Alerts' and 'Get Threats' and could be polled for new alerts. New alerts could generate enriched tickets via Connectwise (or other PSA) API, Teams messages via Webhook, PagerDuty escalations for certain classifications (e.g. hacktool, ransomware). Out of the box, MSPs only have access to email/syslog as mechanisms to pull S1 info into their PSA, with limited integration.