Connect Teramind
Teramind is an employee monitoring and insider-threat platform. It records what people do on their work computers — applications and websites, keystrokes, email and instant-messaging content, file…
Written By Christopher Scaminaci
Last updated 6 days ago
Teramind is an employee monitoring and insider-threat platform. It records what people do on their work computers — applications and websites, keystrokes, email and instant-messaging content, file transfers, printed documents, console commands and screen sessions — and it runs behavior rules over that stream that can warn a user, block an action or lock the machine. On the same instance it also does workforce management: schedules, time records, productivity profiles and task costing. StackJack talks to Teramind through its dashboard API.
Connecting Teramind to StackJack gives your AI assistant a family of teramind_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Run the monitoring reports — web and application use, emails, instant messaging and full conversations, keystrokes, searches, printed documents, file transfers, network activity, storage, console commands, voice calls, sessions and the system audit log
- Ask business-intelligence questions — grids and charts over activity, work time, input rate, behavior alerts, login sessions, web searches, printed documents, social media, keystrokes, emails and file events, plus the filter values available on each
- Review alerts and policies — the behavior alerts that fired, the policies and rule groups behind them, anomaly rules and their templates, monitoring profiles and the shared lists rules match against
- Audit the estate — dashboard users, computers, departments, license consumption, agent deployment status and computers that have stopped reporting in
- Report on the workforce — time cards, time records by day, schedules and schedule templates, tasks, task and agent cost reports, productivity profiles and the time tracker's current state
- Work with recorded sessions — the video data available for a session, session timeline tags, aggregated activity and the body of a captured email
- Manage people and machines (on Pro plans) — create, update and delete dashboard users, computers and departments, and turn a computer's monitoring on or off
- Change what is enforced (on Pro plans) — create, update, clone, import, reorder and delete behavior policies and rule groups, anomaly rules, monitoring policies and monitoring rules, and choose who each one applies to
- Run the workforce side (on Pro plans) — build schedules and templates, assign them, create and update tasks, add time records, start and stop the time tracker, and manage productivity profiles
- Administer the instance (on Pro plans) — directory sync settings and group membership, account settings, the per-report settings including scheduled email export, and export a screen recording
Before you connect: what this connector can read
Teramind is a surveillance product, and this connector can read what it records. That includes keystrokes, the content of emails and instant-message conversations, browsing and search history, the documents people printed, the files they moved and the metadata of their recorded screen sessions.
That is the point of the product, but it makes this connector different from the rest of your stack in two ways worth deciding on before you turn it on:
- Give it only to people who are already entitled to that data. Anyone who can ask your AI assistant a question can reach anything the connector can reach.
- Check your own obligations first. Depending on where your people work and what you agreed with them, monitoring data can carry notice, consent or works-council requirements that are yours rather than Teramind's.
How StackJack authenticates to Teramind
Teramind uses a single long-lived access token that you create in the Teramind dashboard. You paste it into StackJack and that is the whole credential — there is no client ID, no second secret, no sign-in flow and nothing that renews on a schedule.
The permission decision happens before you create the token
This is the one thing to get right, because Teramind gives you no second chance at it. A Teramind access token inherits the full authority of the dashboard user who created it, and there is no way to narrow it afterward. Teramind offers no scopes, no consent screen and no per-token permission list. Its roles — Employee, Administrator, Operational Admin and Infrastructure Admin — are the only granularity, and the role is fixed at the moment you pick which user creates the token.
So least privilege here means one thing: create the token from a purpose-made dashboard user whose role covers only what you want StackJack to reach, rather than from your own full administrator account.
You also need your instance address
There is no single Teramind service address. Every customer talks to their own server:
- Teramind Cloud gives you an assigned subdomain, such as
https://yourcompany.teramind.co. - On-premise and private cloud run on whatever hostname you deployed them to.
Either way, the address StackJack needs is the one you sign in to. Both are supported, and StackJack does not require the address to end in teramind.co.
Steps
- Note your instance address — the hostname you sign in to.
- Decide which dashboard user should own the token, as above. Create a purpose-made user with the narrowest role that covers what you want, rather than reusing a full administrator.
- Create the access token in the Teramind dashboard, signed in as that user, from the Administrator menu's access token area.
- Copy the token straight away and store it securely. Treat it as a password — anyone holding it can read and act on your Teramind instance as that user.
- Paste it into StackJack. Open Connectors, choose Teramind, enter your instance address and paste the token.
- Run a Test Connection to confirm StackJack can reach your instance with the token.
To rotate the token later, delete it in the Teramind dashboard, create a new one and paste it into StackJack. Teramind publishes no expiry, so a token stays valid until someone removes it — rotation is a decision you make, not something that happens to you.
What to know before your AI uses this connector
Some tools change what Teramind does to a person
Most of this connector reports on what Teramind recorded. A smaller set changes what Teramind enforces, and those read very differently to the person on the other end:
- Creating or changing a behavior policy or rule changes what happens to people. A rule can warn a user, block what they are doing or lock the session. Importing or cloning one arms it the same way authoring it does.
- Reordering rule groups changes which rule wins. Evaluation order decides the outcome when two rules disagree, so a reorder changes enforcement without editing a single rule.
- Turning monitoring on or off for a computer changes what is recorded from that moment. Turning it off is quiet: nothing breaks, the machine simply stops being watched.
- Choosing who a monitoring policy applies to puts people in or out of scope of everything that policy does.
- Creating or updating a dashboard user can grant administrator access to your Teramind instance.
- Deleting is permanent — dashboard users, computers, departments, policies, rules, shared lists, schedules and tasks all delete outright.
- Replacing the entries of a shared list can switch off a block. The tool that adds entries to a shared list also accepts the vendor's flag for replacing every entry it already holds, and your behavior rules match against those lists, so a replace can stop a rule from firing.
- Saving report settings can start mailing a monitoring report. Each report's settings carry a scheduled-export recipient list, so saving one can begin sending activity data to an address on a timer.
- Exporting a screen recording produces video of a person's session as a downloadable file.
Every one of these requires the Pro tier and is marked destructive. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Review that setting, and grant only what you want an AI to reach.
Reading a report changes nothing, including the ones that look like they do something. Running a report, asking a business-intelligence question and listing your report exports all leave your instance exactly as they found it, so they are unmarked and available on the Free tier. They are still employee-monitoring data, so grant them as deliberately as any other tool.
Plans and limits
Read tools are available on the Free tier. Everything that writes, enforces, deploys or deletes is Pro. Business reaches the same tools as Pro and differs by monthly call quota.
See the generated Teramind tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
Teramind's own limits are about how many conversations it will hold at once rather than how fast you can ask. Teramind Cloud allows 20 requests a second per address and 16 concurrent sessions per instance; on-premise defaults to six connections. StackJack paces requests well under those numbers so agent traffic does not crowd out your own dashboard, which usually makes a large report slower rather than failed. Pacing is not a guarantee: retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.
Several customers
Every customer has their own Teramind server. Add one connection per customer from the connector's card, name it after the customer, and your AI names it on each call. Omit the name and the call runs against your default connection. Pin an endpoint to one connection when an AI should never reach past a single customer. See Several connections of one connector.
Troubleshooting
"Teramind rejected the access token" — the token has been deleted or replaced in the dashboard. There is nothing to refresh and nothing cached to clear: create a new token, paste it into StackJack and run a Test Connection.
"Teramind accepted the token but refused this operation" — almost always the token's reach rather than a fault. The token can do exactly what its creating user can do, so a token minted from a limited role will be refused on anything that role cannot reach. If you need those tools, create the token from a user with the role that covers them and re-enter it.
The connection test fails but the dashboard works fine — check the address you entered. It must be the hostname you sign in to, over HTTPS. A Teramind Cloud subdomain and an on-premise hostname are both fine, but the general company website is not.
A report comes back empty for a period you expected data in — check whether monitoring was enabled on those computers for that window before assuming nothing happened. A computer with monitoring turned off produces no records at all, and that looks exactly like a quiet week.
Time comparisons look shifted by hours — Teramind resolves report periods against your instance's own clock. If a report boundary looks off, ask your AI for the server time first and compare it with the window you meant.
Teramind tools
teramind_ · 222 tools · Free 119 · Pro 103
Agent deployment
Computers
Departments
Employees
Licensing
Server
Report exports
Reports
Business intelligence
Business intelligence filters
Alerts
Anomaly rules
Behavior policies
Monitoring policies
Monitoring profiles
Monitoring rules
Shared lists
Productivity profiles
Schedules
Tasks
Time tracker tasks
Time tracking reports
Activities
Session player
Session tags
Video exports
Access tokens
Data ingestion
Instance
LDAP directory
Report settings
SMTP
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team