Integrations
Connect every system.Normalize every identity.
Five connectors read identities, credential metadata, permissions and MCP tools from AWS, GitHub, Kubernetes, HashiCorp Vault and MCP servers — read-only, least-privilege, and every other system labelled planned.
5 available · 52 planned
Connectors
Browse by system, category or status
Search what a connector reads, then filter by category or availability. Status reflects the connector contract roadmap, not a marketing claim.
-
AWS IAM
AvailableCloud
Reads Roles, machine users, access-key metadata, trust, inline policy statements
-
Azure / Entra ID
PlannedCloud
Reads Service principals, app registrations, managed identities, role assignments
-
Google Cloud IAM
PlannedCloud
Reads Service accounts, keys, workload identity, IAM bindings
-
Kubernetes
AvailableCloud
Reads Service accounts, role bindings, workloads that run as them
-
Oracle Cloud
PlannedCloud
Reads Users, dynamic groups, API keys, policies
-
Okta
PlannedIdentity
Reads Applications, API tokens, service users, OAuth grants
-
Microsoft Entra ID
PlannedIdentity
Reads Enterprise apps, OAuth consents, credentials, owners
-
Active Directory
PlannedIdentity
Reads Service accounts, gMSAs, SPNs, delegation
-
Ping Identity
PlannedIdentity
Reads OAuth clients, applications, grants
-
HashiCorp Vault
AvailableSecrets & Vaults
Reads AppRoles, machine identity entities, auth mounts, policy names
-
AWS Secrets Manager
PlannedSecrets & Vaults
Reads Secrets, rotation status, resource policies
-
Azure Key Vault
PlannedSecrets & Vaults
Reads Secrets, keys, certificates, access policies
-
GCP Secret Manager
PlannedSecrets & Vaults
Reads Secrets, versions, IAM bindings
-
CyberArk Conjur
PlannedSecrets & Vaults
Reads Hosts, variables, policies
-
Akeyless
PlannedSecrets & Vaults
Reads Items, auth methods, roles
-
1Password
PlannedSecrets & Vaults
Reads Service accounts, vault access
-
GitHub
AvailableCode & CI/CD
Reads App installations, bot members, repositories and their visibility
-
GitLab
PlannedCode & CI/CD
Reads Tokens, deploy keys, CI variables, runners
-
Bitbucket
PlannedCode & CI/CD
Reads App passwords, access keys, pipeline variables
-
Jenkins
PlannedCode & CI/CD
Reads Credentials store, service users, job bindings
-
CircleCI
PlannedCode & CI/CD
Reads Contexts, environment variables, OIDC
-
Buildkite
PlannedCode & CI/CD
Reads Agent tokens, cluster queues
-
Terraform Cloud
PlannedCode & CI/CD
Reads Workspaces, variable sets, team tokens
-
Azure DevOps
PlannedCode & CI/CD
Reads Service connections, PATs, pipelines
-
JFrog Artifactory
PlannedCode & CI/CD
Reads Access tokens, service users
-
Slack
PlannedCollaboration & SaaS
Reads Apps, bot tokens, scopes, installers
-
Microsoft 365
PlannedCollaboration & SaaS
Reads App consents, mailbox delegations, Graph permissions
-
Google Workspace
PlannedCollaboration & SaaS
Reads OAuth apps, domain-wide delegation, service accounts
-
Salesforce
PlannedCollaboration & SaaS
Reads Connected apps, integration users, OAuth tokens
-
Atlassian Jira & Confluence
PlannedCollaboration & SaaS
Reads API tokens, OAuth apps, service accounts
-
ServiceNow
PlannedSecurity & ITSM
Reads Integration users, OAuth apps, ticket workflows
-
Notion
PlannedCollaboration & SaaS
Reads Integrations, tokens, shared pages
-
Zendesk
PlannedCollaboration & SaaS
Reads API tokens, OAuth clients
-
Workato
PlannedCollaboration & SaaS
Reads Connections, recipes, service identities
-
Snowflake
PlannedData
Reads Service users, key-pair auth, roles, grants
-
Databricks
PlannedData
Reads Service principals, tokens, workspace permissions
-
PostgreSQL
PlannedData
Reads Roles, grants, connection identities
-
MongoDB Atlas
PlannedData
Reads Database users, API keys, roles
-
Amazon S3
PlannedData
Reads Bucket policies, access points, reachability
-
BigQuery
PlannedData
Reads Dataset IAM, service-account access
-
Elasticsearch
PlannedData
Reads API keys, service tokens, roles
-
Model Context Protocol
AvailableAI & MCP
Reads MCP servers and their tools, with publisher-declared effect
-
OpenAI Platform
PlannedAI & MCP
Reads API keys, service accounts, projects
-
Anthropic Claude
PlannedAI & MCP
Reads API keys, workspaces
-
Azure OpenAI
PlannedAI & MCP
Reads Deployments, keys, managed identity access
-
Amazon Bedrock
PlannedAI & MCP
Reads Invocation roles, knowledge base access
-
Vertex AI
PlannedAI & MCP
Reads Service accounts, IAM bindings
-
LangChain / LangGraph
PlannedAI & MCP
Reads Tool registries, credentials
-
CrowdStrike Falcon
PlannedSecurity & ITSM
Reads API clients
-
Wiz
PlannedSecurity & ITSM
Reads Cloud findings, identity exposure context
-
Splunk
PlannedSecurity & ITSM
Reads Findings export, detection events
-
Microsoft Sentinel
PlannedSecurity & ITSM
Reads Findings export, incident workflows
-
Datadog
PlannedSecurity & ITSM
Reads API and application keys
-
PagerDuty
PlannedSecurity & ITSM
Reads Incident routing, API keys
-
SPIFFE / SPIRE
PlannedIdentity
Reads SVIDs, trust domains, workload registrations
-
Docker Hub
PlannedCode & CI/CD
Reads Access tokens, organization members
-
Webhook / generic
PlannedSecurity & ITSM
Reads Evidence export and remediation callbacks
Product names are used nominatively to identify supported systems. Status reflects the connector contract roadmap and is never a claim of certification or partnership.
Coverage
Your clouds. Your clusters. Your vaults. Your MCP servers.
Coverage grows where non-human identities actually live — and every tile carries its status.
- AWS IAM
- Azure / Entra IDPlanned
- Google Cloud IAMPlanned
- Kubernetes
- Oracle CloudPlanned
- OktaPlanned
- Microsoft Entra IDPlanned
- Active DirectoryPlanned
- Ping IdentityPlanned
- HashiCorp Vault
- AWS Secrets ManagerPlanned
- Azure Key VaultPlanned
- GCP Secret ManagerPlanned
- CyberArk ConjurPlanned
- AkeylessPlanned
- 1PasswordPlanned
- GitHub
- GitLabPlanned
- BitbucketPlanned
- JenkinsPlanned
- CircleCIPlanned
- BuildkitePlanned
- Terraform CloudPlanned
- Azure DevOpsPlanned
- JFrog ArtifactoryPlanned
- SlackPlanned
- Microsoft 365Planned
- Google WorkspacePlanned
- SalesforcePlanned
- Atlassian Jira & ConfluencePlanned
- ServiceNowPlanned
- NotionPlanned
- ZendeskPlanned
- WorkatoPlanned
- SnowflakePlanned
- DatabricksPlanned
- PostgreSQLPlanned
- MongoDB AtlasPlanned
- Amazon S3Planned
- BigQueryPlanned
- ElasticsearchPlanned
- Model Context Protocol
- OpenAI PlatformPlanned
- Anthropic ClaudePlanned
- Azure OpenAIPlanned
- Amazon BedrockPlanned
- Vertex AIPlanned
- LangChain / LangGraphPlanned
- CrowdStrike FalconPlanned
- WizPlanned
- SplunkPlanned
- Microsoft SentinelPlanned
- DatadogPlanned
- PagerDutyPlanned
- SPIFFE / SPIREPlanned
- Docker HubPlanned
- Webhook / genericPlanned
Contract
One connector contract. Every source.
Every connector implements the same contract, so identities from different systems can be compared, traversed and governed the same way.
- AuthorizeRead-only, least-privilege provider permissions, documented per connector and granted by your administrator
scope: read - EnumerateIdentities, credential metadata, grants and MCP tools are paged through resumable cursors
paginated · resumable - NormalizeProvider objects become typed graph nodes: service accounts, roles, workloads, bots, AppRoles, tools
typed identities - Attach evidenceEach node and edge keeps its source record, timestamps and whether it was observed or inferred
observed · inferred - ReconcileDeltas against the last sync raise new, changed and removed relationships — not a fresh dump
diff, not dump - RetireIdentities no longer seen are marked stale with the last-seen evidence, never silently dropped
last seen kept
Normalized Identity Types
Map provider objects to service accounts, roles, workloads, bots and AppRoles with one schema
Sync Lifecycle
Authorize, enumerate, normalize, attach evidence, reconcile and retire — resumable on every run
Evidence
Keep the source record, timestamps and whether it was observed or inferred for every node and edge
Pagination
Page through large tenants with resumable cursors and rate-limit awareness — never a partial snapshot presented as complete
Tenant Isolation
Run each tenant’s connectors, credentials and evidence in isolation; nothing is shared across tenants
Connector Permissions
Read-only, least-privilege provider permissions, documented per connector before you connect; nothing writes back
Missing a connector? Tell us what it should read.
Connector requests feed the roadmap directly. Name the system, the identity types it holds and the evidence you need from it.