Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
71 changes: 39 additions & 32 deletions integrations-catalog/README.md

Large diffs are not rendered by default.

189 changes: 126 additions & 63 deletions integrations-catalog/index.json

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion integrations-catalog/integrations/15five.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
"authConfig": {
"type": "api_key",
"config": {
"setupInstructions": "1. Log in to 15Five at https://my.15five.com\n2. Go to Settings → Integrations → API\n3. Generate an API key\n4. Enter it below",
"setupInstructions": "1. Log in to 15Five at https://my.15five.com\n2. Go to Settings → Integrations → API\n3. Generate an API key\n4. Enter it below\n5. If you get a 401 error, try regenerating the API key (15Five keys expire 1 year from creation; API access may vary by plan tier).",
"credentialFields": [
{
"label": "API Key",
Expand Down
2 changes: 1 addition & 1 deletion integrations-catalog/integrations/1password.json
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,7 @@
{
"slug": "onepassword_signin_attempts",
"name": "Employee Access",
"description": "Reviews recent 1Password sign-in attempts for unauthorized access and suspicious activity",
"description": "Reviews recent 1Password sign-in attempts via the Events API and surfaces aggregate evidence (success/failure counts, unique users, unique IPs, latest sign-in). Fails if the Events Reporting token is missing the \"signinattempts\" scope or no sign-ins are returned.",
"defaultSeverity": "high",
"enabled": true
}
Expand Down
2 changes: 1 addition & 1 deletion integrations-catalog/integrations/360learning.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
"authConfig": {
"type": "custom",
"config": {
"setupInstructions": "1. Log in to 360Learning as an admin\n2. Go to Settings > API\n3. Copy your Company ID and API Key (v1 credentials)\n4. If you don't have API credentials, contact your 360Learning Customer Success Partner (CSP)\n5. Enter both values below\n\nNote: API v2 credentials are NOT compatible. Use API v1 credentials only.",
"setupInstructions": "1. Log in to 360Learning as an admin\n2. Go to Settings > API\n3. Copy your Company ID and API Key (v1 credentials)\n4. If you don't have API credentials, contact your 360Learning Customer Success Partner (CSP)\n5. Enter both values below\n\nNote: API v2 credentials are NOT compatible. Use API v1 credentials only.\n\nNote: this integration uses 360Learning API v1, which the vendor plans to sunset in mid-2027. A migration to API v2 will be required before then.",
"credentialFields": [
{
"label": "API Key",
Expand Down
8 changes: 4 additions & 4 deletions integrations-catalog/integrations/activtrak.json
Original file line number Diff line number Diff line change
Expand Up @@ -33,22 +33,22 @@
"checks": [
{
"slug": "activtrak_monitoring_alerting",
"name": "Monitoring & Alerting",
"description": "Verifies ActivTrak activity monitoring is active by checking for recent activity data collected by deployed agents",
"name": "ActivTrak User Activity (Last 7 Days)",
"description": "Confirms ActivTrak agents are reporting activity by reading the working-hours report for the last 7 days; surfaces per-user totals as evidence. Note: this is not an alarm/alert configuration check — it verifies end-to-end monitoring is functioning.",
"defaultSeverity": "medium",
"enabled": true
},
{
"slug": "activtrak_employee_access",
"name": "Employee Access",
"description": "Lists all ActivTrak console users (consumers) with their roles and group access permissions",
"description": "Lists all ActivTrak console users (consumers) with email, SSO status, and viewable groups for access-review evidence. Uses Authorization: Bearer auth.",
"defaultSeverity": "medium",
"enabled": true
},
{
"slug": "activtrak_device_list",
"name": "Device List",
"description": "Lists all monitored devices (user agents/clients) registered in ActivTrak",
"description": "Lists all monitored ActivTrak agents (clients) with id/name/domain/alias. Uses Authorization: Bearer auth.",
"defaultSeverity": "medium",
"enabled": true
}
Expand Down
22 changes: 17 additions & 5 deletions integrations-catalog/integrations/airbyte.json
Original file line number Diff line number Diff line change
Expand Up @@ -4,17 +4,29 @@
"description": "Monitor Airbyte data integration pipelines for connection status and workspace access compliance",
"category": "Cloud",
"docsUrl": "https://reference.airbyte.com/reference/getting-started",
"baseUrl": "https://api.airbyte.com/",
"baseUrl": "https://api.airbyte.com",
"authConfig": {
"type": "api_key",
"type": "custom",
"config": {
"setupInstructions": "1. Log in to Airbyte Cloud at https://cloud.airbyte.com\n2. Go to Settings → API Keys\n3. Generate a new API key\n4. Copy and enter it below",
"setupInstructions": "1. Log in to Airbyte Cloud at https://cloud.airbyte.com (or your self-hosted instance).\n2. Go to Settings > Applications.\n3. Create a new Application; copy the Client ID and Client Secret (secret shown only once).\n4. Paste them above. For self-hosted Airbyte, also enter your API Base URL.\n5. Comp will exchange these for short-lived access tokens automatically.",
"credentialFields": [
{
"label": "API Key",
"label": "Client ID",
"type": "text",
"required": true,
"helpText": "Airbyte Cloud Application Client ID. Settings > Applications > Create Application."
},
{
"label": "Client Secret",
"type": "password",
"required": true,
"helpText": "Found in Airbyte Cloud Settings → API Keys"
"helpText": "Airbyte Cloud Application Client Secret. Shown once at application creation."
},
{
"label": "API Base URL (optional, self-hosted only)",
"type": "text",
"required": false,
"helpText": "Defaults to https://api.airbyte.com for Airbyte Cloud. For self-hosted Airbyte, enter your instance URL (e.g. https://airbyte.example.com/api/public)."
}
]
}
Expand Down
20 changes: 16 additions & 4 deletions integrations-catalog/integrations/aircall.json
Original file line number Diff line number Diff line change
Expand Up @@ -6,11 +6,23 @@
"docsUrl": "https://developer.aircall.io/api-references/",
"baseUrl": "https://api.aircall.io",
"authConfig": {
"type": "basic",
"type": "custom",
"config": {
"setupInstructions": "1. Log in to Aircall Dashboard at https://dashboard.aircall.io\n2. Go to Company Settings\n3. In the API Keys section, click 'Add a new API key'\n4. Copy the API ID and API Token\n5. Enter them below",
"usernameField": "api_id",
"passwordField": "api_token"
"setupInstructions": "IMPORTANT: Do not enter your Aircall account email and password here. Aircall requires a separate API key, which generates an API ID and API Token. Paste those values below — NOT your account login.\n\nYou must be an Admin or Owner in Aircall to create company-level API keys.\n\n1. Log in to the Aircall Dashboard at https://dashboard.aircall.io\n2. Click on the gear icon, then go to Company Settings > Integrations & API > API Keys\n3. Click \"Add a new API key\" and give it a name (e.g. \"Comp AI\")\n4. Aircall will show you the API ID and API Token once. Both are long random strings.\n5. Copy BOTH values immediately — they are shown only once\n6. Paste the API ID into the \"API ID\" field below and the API Token into the \"API Token\" field\n\nIf the integration shows 403 Forbidden errors later, the API key has likely been regenerated or revoked on the Aircall side. Create a new one and update the values here.",
"credentialFields": [
{
"label": "API ID",
"type": "text",
"required": true,
"helpText": "The API ID generated in Aircall Dashboard > Company Settings > Integrations & API > API Keys. This is a long random string, NOT your Aircall account email."
},
{
"label": "API Token",
"type": "password",
"required": true,
"helpText": "The API Token shown alongside the API ID. This is a long random string, NOT your Aircall account password. Aircall shows it only once at creation time."
}
]
}
},
"capabilities": [
Expand Down
15 changes: 12 additions & 3 deletions integrations-catalog/integrations/airtable.json
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,16 @@
"baseUrl": "https://api.airtable.com/",
"authConfig": {
"type": "api_key",
"config": {}
"config": {
"setupInstructions": "1. Go to https://airtable.com/create/tokens and sign in.\n2. Click \"Create new token\".\n3. Grant the following scopes:\n - schema.bases:read (list bases and their permission levels)\n - user.email:read (identify the token owner)\n4. Under \"Access\", choose \"All current and future bases in all current and future workspaces\".\n5. Create the token and copy the value (starts with \"pat\").\n6. Paste it into the Personal Access Token field above.\n\nNote: Listing all workspaces requires an Airtable Enterprise plan and additional enterprise scopes. These checks operate at the bases level so they work for every plan tier.",
"credentialFields": [
{
"label": "Personal Access Token",
"type": "password",
"required": true
}
]
}
},
"capabilities": [
"checks"
Expand All @@ -18,14 +27,14 @@
{
"slug": "airtable_employee_access",
"name": "Employee Access",
"description": "Reviews Airtable bases and verifies workspace is properly configured",
"description": "Verifies the Personal Access Token owner and the bases reachable for employee access auditing.",
"defaultSeverity": "medium",
"enabled": true
},
{
"slug": "airtable_access_review",
"name": "Access Review Log",
"description": "Reviews Airtable workspace configuration for access controls",
"description": "Reviews Airtable bases and their permission levels to support access reviews.",
"defaultSeverity": "medium",
"enabled": true
}
Expand Down
20 changes: 17 additions & 3 deletions integrations-catalog/integrations/amplitude.json
Original file line number Diff line number Diff line change
Expand Up @@ -4,10 +4,24 @@
"description": "Monitor Amplitude projects and user access for product analytics compliance",
"category": "Monitoring",
"docsUrl": "https://www.docs.developers.amplitude.com/analytics/apis/management-api/",
"baseUrl": "https://management.us.amplitude.com/",
"baseUrl": "https://core.amplitude.com",
"authConfig": {
"type": "api_key",
"config": {}
"type": "custom",
"config": {
"setupInstructions": "1. Sign in to Amplitude as an Organization Admin.\n2. Go to Settings > Organization > SCIM (requires the SCIM/SSO add-on on your plan).\n3. Generate a SCIM API token and copy it (starts with scim_).\n4. Paste the token above and select your data region (US or EU).\n5. Note: SCIM endpoints require the SCIM add-on. If your plan does not include SCIM, the Employee Access check will return an actionable failure.",
"credentialFields": [
{
Comment thread
tofikwest marked this conversation as resolved.
"label": "SCIM Token",
"type": "password",
"required": true
},
{
"label": "Region",
"type": "select",
"required": true
}
]
}
},
"capabilities": [
"checks"
Expand Down
14 changes: 10 additions & 4 deletions integrations-catalog/integrations/anodot.json
Original file line number Diff line number Diff line change
Expand Up @@ -4,17 +4,23 @@
"description": "Anodot AI-powered monitoring and anomaly detection",
"category": "Monitoring",
"docsUrl": "https://docs.anodot.com/",
"baseUrl": "https://app.anodot.com/api/v1",
"baseUrl": "https://app.anodot.com",
"authConfig": {
"type": "custom",
"config": {
"setupInstructions": "1. Log in to Anodot\n2. Settings → Access Tokens\n3. Create a new token\n4. Paste it below",
"setupInstructions": "1. Sign in to Anodot as a customer-admin user.\n2. Settings → API Tokens → +Add → name it and copy the Access Key.\n3. Paste it below as the Access Key.\n4. (Optional) Set Base URL to match your Anodot region.",
"credentialFields": [
{
"label": "Access Token",
"label": "Access Key",
"type": "password",
"required": true,
"helpText": "Anodot → Settings → Access Tokens"
"helpText": "Anodot → Settings → API Tokens → create an Access Key as a customer-admin user."
},
{
"label": "Anodot Base URL",
"type": "text",
"required": false,
"helpText": "Region URL. Defaults to https://app.anodot.com. Examples: https://eu.anodot.com, https://ap.anodot.com, https://in.anodot.com, https://app-oregon.anodot.com."
}
]
}
Expand Down
13 changes: 7 additions & 6 deletions integrations-catalog/integrations/anthropic.json
Original file line number Diff line number Diff line change
@@ -1,28 +1,29 @@
{
"slug": "anthropic",
"name": "Anthropic",
"description": "AI safety company building Claude. Monitor API access and usage.",
"description": "AI safety company building Claude. Monitor organization member access, API availability, and sync employees from Anthropic.",
"category": "Cloud",
"docsUrl": "https://docs.anthropic.com/en/api/",
"baseUrl": "https://api.anthropic.com",
"authConfig": {
"type": "custom",
"config": {
"setupInstructions": "1. Go to console.anthropic.com and sign in\n2. Navigate to Settings > Admin API Keys (requires Organization Admin role)\n3. Create a new Admin API key\n4. Copy the key and enter it above\n5. Note: Admin API keys are required for organization-level checks. Regular API keys only work for model access checks.",
"setupInstructions": "1. Go to console.anthropic.com and sign in as an Organization Admin\n2. Navigate to Settings > Admin keys\n3. Create a new Admin API key (it will start with sk-ant-admin01-)\n4. Copy the key and enter it above\n5. Note: Only Admin API keys can list organization members and manage access. Regular API keys will not work for employee access checks.",
"credentialFields": [
{
"label": "API Key",
"label": "Admin API Key",
"type": "password",
"required": true
}
]
}
},
"capabilities": [
"checks"
"checks",
"sync"
],
"supportsMultipleConnections": false,
"syncSupported": false,
"syncSupported": true,
"checks": [
{
"slug": "anthropic_app_availability",
Expand All @@ -34,7 +35,7 @@
{
"slug": "anthropic_employee_access",
"name": "Anthropic Employee Access",
"description": "Review Anthropic organization access by listing API keys, pending invitations, and workspaces",
"description": "Lists all Anthropic organization members with their email, role, and access details for Access Review evidence.",
"defaultSeverity": "medium",
"enabled": true
}
Expand Down
93 changes: 93 additions & 0 deletions integrations-catalog/integrations/aptible.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,93 @@
{
"slug": "aptible",
"name": "Aptible",
"description": "Monitor Aptible for compliance evidence: database backup posture, log and metric drains, service redundancy, endpoint TLS configuration, network exposure, encryption at rest, deploy traceability, and organization member access.",
"category": "Cloud",
"docsUrl": "https://www.aptible.com/docs",
"baseUrl": "https://api.aptible.com",
"authConfig": {
"type": "custom",
"config": {
"setupInstructions": "1. In Aptible, invite a dedicated user for Comp AI (e.g. compliance-bot@yourcompany.com): Settings > Members > Invite.\n2. Create a custom read-only role: grant 'Full Visibility' on the environments you want monitored and do NOT grant 'Sensitive Access' or any manage permissions. Assign the user only this role.\n3. Make sure 2FA is NOT enabled on this user — automated checks cannot complete 2FA challenges.\n4. If your organization enforces SSO, add this user to the SSO bypass allowlist (Settings > Single Sign-On).\n5. Enter the user's email and password below.",
Comment thread
tofikwest marked this conversation as resolved.
"credentialFields": [
{
"label": "Email",
"type": "text",
"required": true,
"helpText": "Email of the dedicated read-only Aptible user created for Comp AI."
},
{
"label": "Password",
"type": "password",
"required": true,
"helpText": "Password of the dedicated read-only user. Stored encrypted and used only to mint short-lived read tokens."
}
]
}
},
"capabilities": [
"checks"
],
"supportsMultipleConnections": false,
"syncSupported": false,
"checks": [
{
"slug": "aptible_backup_posture",
"name": "Backup Posture",
"description": "Verifies automatic backups are enabled for every Aptible managed database and records the environment backup retention policy (daily/monthly/yearly, PITR).",
"defaultSeverity": "high",
"enabled": true
},
{
"slug": "aptible_monitoring",
"name": "Monitoring & Alerting",
"description": "Verifies each Aptible environment routes logs and metrics to a monitoring destination via log drains and metric drains; production environments without any drain fail.",
"defaultSeverity": "medium",
"enabled": true
},
{
"slug": "aptible_redundancy",
"name": "Service Redundancy",
"description": "Verifies app services in production Aptible environments run 2+ containers so Aptible distributes them across availability zones for high availability.",
"defaultSeverity": "medium",
"enabled": true
},
{
"slug": "aptible_tls_https",
"name": "TLS / HTTPS",
"description": "Verifies every public Aptible endpoint terminates TLS via a default-domain certificate, Managed TLS (ACME), or a custom certificate; raw TCP endpoints are flagged for manual review.",
"defaultSeverity": "medium",
"enabled": true
},
{
"slug": "aptible_public_exposure",
"name": "Network Exposure",
"description": "Inventories Aptible endpoints as internal, IP-filtered, or fully public — informational evidence of the network exposure surface.",
"defaultSeverity": "info",
"enabled": true
},
{
"slug": "aptible_encryption_at_rest",
"name": "Encryption at Rest",
"description": "Records that Aptible encrypts database volumes at rest by default (platform-enforced), enumerating every managed database as evidence.",
"defaultSeverity": "info",
"enabled": true
},
{
"slug": "aptible_deploy_traceability",
"name": "Deploy Traceability",
"description": "Records git ref/commit traceability for every deployed Aptible app from deploy operations and code scan results; Docker-image deploys are noted for manual CI review.",
"defaultSeverity": "info",
"enabled": true
},
{
"slug": "aptible_employee_access",
"name": "Employee Access",
"description": "Lists every member of the Aptible organization with owner/superuser flag, email verification, and 2FA status where reported — one result per person.",
"defaultSeverity": "info",
"enabled": true
}
],
"checkCount": 8,
"isActive": true
}
16 changes: 14 additions & 2 deletions integrations-catalog/integrations/aqua-security.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,13 +8,25 @@
"authConfig": {
"type": "custom",
"config": {
"setupInstructions": "1. Log in to cloud.aquasec.com\n2. Settings → API Keys\n3. Create an API key\n4. Paste it below",
"setupInstructions": "1. Log in to cloud.aquasec.com (Aqua Cloud / CSPM)\n2. Go to Settings → API Keys\n3. Generate an API key — copy both the API Key and the API Secret (secret is shown once)\n4. Paste them below. If your tenant is hosted in EU, change the endpoint to https://eu-1.api.cloudsploit.com",
"credentialFields": [
{
"label": "API Key",
"type": "password",
"required": true,
"helpText": "Aqua Platform → Settings → API Keys"
"helpText": "Aqua Platform → Settings → API Keys → API Key"
},
{
"label": "API Secret",
"type": "password",
"required": true,
"helpText": "Aqua Platform → Settings → API Keys → API Secret (shown once on key creation)"
},
{
"label": "API Endpoint",
"type": "text",
"required": false,
"helpText": "Default: https://api.cloudsploit.com (US). For EU use https://eu-1.api.cloudsploit.com"
}
]
}
Expand Down
8 changes: 4 additions & 4 deletions integrations-catalog/integrations/attio.json
Original file line number Diff line number Diff line change
Expand Up @@ -28,14 +28,14 @@
{
"slug": "attio_employee_access",
"name": "Employee Access",
"description": "Reviews Attio workspace members and their CRM access permissions",
"description": "Lists Attio workspace members with their access level (admin/member/suspended) and emits per-member evidence.",
"defaultSeverity": "medium",
"enabled": true
},
{
"slug": "attio_access_review",
"name": "Access Review Log",
"description": "Audits Attio workspace member roles for access review compliance",
"slug": "attio_app_availability",
"name": "Application Availability",
"description": "Verifies the Attio API token is active and the workspace is reachable via /v2/self.",
"defaultSeverity": "medium",
"enabled": true
}
Expand Down
Loading
Loading