Any system connected.
Before the coffee's cold.
14 vendor templates — Entra ID, Active Directory, Exchange Online, Google Workspace, Workday, SuccessFactors, Salesforce, ServiceNow, Box, AFAS, TOPdesk, Nmbrs, Atlassian and GitHub — plus six generic engines: REST, SCIM 2.0, LDAP, SQL, SFTP-CSV and SMB/NTFS: 20 production connectors. Guided, live-tested, and gated until you trust it.
The wizard
Configuration you confirm, not author.
Pick the system, drop in credentials, and the wizard auto-discovers the schema, pre-fills the mappings and tests every step against live records from your own system.
- Live endpoint test at every gate — you never configure blind
- Attribute selection decides, per field, what gets imported at all
- Account types & ownership rules classify what you'll find
- You choose where the secret lives: EU vault, your vault (BYOV), or on the agent
- A vendor that needs a one-time browser consent (OAuth2 authorization-code — Nmbrs is one) runs it in the wizard: the redirect URI is shown to copy before the draft exists, you click Connect and sign in once, and it runs unattended on its refresh token from then on — rotated tokens included, because a provider that burns each token on use would otherwise work exactly once. The consent is stamped: who, when, which scopes
- Private-CA and self-signed TLS: add your internal CA once, tenant-wide — verification stays on. Read by the HTTP-based connectors (REST, SCIM); the vendor-SDK connectors use the system trust store
- Changing a live system is staged: you edit, you read the diff, you apply on purpose. A connector's configuration cannot drift by autosave
Shareable templates
A working connector becomes a portable artifact.
The fourteenth vendor template is not ours. Nmbrs was contributed as a package against this SDK — which is the whole point: the long tail does not have to wait on our roadmap.
Export a working REST or SCIM connector as a secret-free, versioned template — import it into another tenant, or publish it to the community registry with provenance. This is how the connector long-tail solves itself: a new vendor template is days of work on the generic engines, not a roadmap quarter.
- Secret-free by construction — credentials never travel with the template
- Signed per publisher, versioned, with provenance and trust-tiers in the registry
- Clone a working connector into dev, acceptance and production — config carries over, secrets never do
- New vendor templates built alongside onboarding customers, at no extra cost
Gated go-live
Provisioning from day one — writes gated until you release them.
Every new connector provisions from the start, but every write queues for your batch approval until you remove the gate, per system. You watch the platform make the right calls before you let it act.
- Batch approval queue per system — see exactly what would change
- Per-object visibility-only mode: observe before you govern
- Blast-radius safety limits cap runaway writes at the threshold
- Every sync run keeps what it changed — searchable per object, over the whole delta and not a 200-row sample. “Did this run touch Jan Peeters?” is a query, not a guess
- Letting a held import through shows every change it would make, searchable, all of them — and refuses to proceed without a written reason. A bypassed limit with no reason is not evidence
Unstructured data
Your riskiest access isn't in an app — it's in a folder.
The scan family reads SharePoint and OneDrive, Google Drive, Box and on-prem SMB/NTFS file shares — and turns folders into governed objects: sensitivity classification, who-can-access per folder, and risk flags for the shares nobody owns, the ones shared outside the organisation, and the ones living entirely outside IGA scope.
- Folder inventory with sensitivity + risk flags: external · over-shared · no owner · outside IGA
- Who-can-access resolved to people — external collaborators marked per person
- Assign an owner or bring a share into scope, one click each
Related
Reconciliation & provisioning
What happens after the first sync: expected vs actual, per grant.
Read more → ArchitectureTier-3 agent & BYO-vault
Reach behind the firewall — credentials stay in your network.
Read more → Hands-onClick through the wizard
Take the onboarding steps yourself — no login needed.
Read more →See a system connected on your own data.
A 30-minute kickoff connects your HR feed and one system — working POC the same day.
Bring your HR feed plus one system you trust us to read — that is all the kickoff needs. No NDA, no second call with a sales engineer, no procurement form.