Connect one source, then verify one client
- Open Integrations and add the intended product. Give the connection a name that identifies its account, controller or region.
- Enter the fields for that product below. Obtain credentials through the vendor administrator responsible for the intended account; a field list does not grant API entitlement or permissions.
- Review the saved connection outcome, then use Clients & sites to discover and explicitly assign the correct source records. Compare identifiers as well as names.
- For evidence sources, use Sync now, inspect Sync history, and check one client’s source and observation time. Directory sources instead use Import clients and Refresh client records.
- Compare the available observations with the control’s requirements before running checks.
Choose your product
Cisco Meraki
Cisco Meraki
For vendor prerequisites, key creation and recovery, follow Connect Cisco Meraki.Enable API access for the relevant Meraki organization and use a key with the needed read access. Confirm organization versus network mapping before linking. A firewall-rule fingerprint detects change; it does not prove rule quality.Map: Meraki organization IDs by default; a connection configured for network scope exposes individual network IDs. Review the displayed organization/network context.
Available observations: Network device role, Hardware model, Firmware version, Management address, Device online, Firmware update available, Licence or entitlement, VPN tunnel membership, Firewall rule fingerprint.Use the vendor’s current instructions for credential preparation: Meraki API authentication.
Auvik
Auvik
Use the account login, API key and correct regional endpoint suffix. Reachability and network segments do not establish patching or firewall policy compliance.Map: Each Auvik client tenant ID.
Available observations: Device online, Management address, Network device role, Network segment type.
Fortinet FortiGate
Fortinet FortiGate
Use an HTTPS appliance management URL and a dedicated REST API token restricted appropriately for your environment. One connection reads one appliance. A policy count is not an assessment of policy correctness.Map: The appliance serial number. Use a separate connection for each appliance.
Available observations: Network device role, Firmware version, VPN tunnel membership, Licence or entitlement, Firewall rule count.
Twingate
Twingate
Use the API key and network subdomain for the intended account. Resource/address observations describe configured access destinations; they do not prove every access path is appropriately restricted.Map: One Twingate account/network subdomain. Remote Networks are locations, not separate client tenants.
Available observations: Directory role, Group membership, Device online, Accessible resource, Resource destination.Vendor preparation: Twingate API preparation.
Alignr Domain Checks
Alignr Domain Checks
No vendor API key is needed. The connection accepts up to 50 public domains. Prefer the client Domains tab for normal setup. Public DNS checks do not perform port scanning or a restore test.Map: Each configured domain.
Available observations: SPF record present, DMARC enforcement policy, Mail routing records present, Name server count.