Monitoring ID rights question

I have started at a new company and inherited a SQL Monitor environment running version  The Domain ID was given ADMIN rights at the Windows level to the Servers it monitors and 'sa' rights into the SQL Servers it monitors.  My question becomes what actual rights does the domain ID need at the Window Server level and what rights does the ID within SQL Server need.  The auditors are balking at sysadmin rights for monitoring for SOX compliancy reasons.

