Connect one source, then verify one client
- Open Integrations and add the intended product. Give the connection a name that identifies its account, controller or region.
- Enter the fields for that product below. Obtain credentials through the vendor administrator responsible for the intended account; a field list does not grant API entitlement or permissions.
- Review the saved connection outcome, then use Clients & sites to discover and explicitly assign the correct source records. Compare identifiers as well as names.
- For evidence sources, use Sync now, inspect Sync history, and check one client’s source and observation time. Directory sources instead use Import clients and Refresh client records.
- Compare the available observations with the control’s requirements before running checks.
Choose your product
HaloPSA
HaloPSA
The resource server is your HaloPSA base URL. This connector assumes the authorisation and API server share that origin unless deployment configuration explicitly overrides them. Ticket context is not direct proof of the target account state.Map: Each HaloPSA client ID.
Available observations: Leaver ticket state, Secret-in-ticket signal, Secret reuse count, Change ticket reference.
ConnectWise Manage
ConnectWise Manage
The integrator client ID is distinct from the MSP Company ID. Supply both, with the public/private API key pair and correct instance site. A closed ticket does not prove remediation succeeded.Map: Each company numeric ID, not its renameable company identifier.
Available observations: Ticket state, Ticket closure time, Leaver ticket state, Change ticket reference, Contract type.
Autotask
Autotask
Supply the complete HTTPS zone URL for this account. A valid key sent to the wrong zone fails. Ticket and contract observations do not replace device or directory collection.Map: Each Autotask company numeric ID.
Available observations: Ticket state, Ticket closure time, Leaver ticket state, Change ticket reference, Contract type.
Datto RMM
Datto RMM
Check Platform region before saving; the connector defaults to concord. Antivirus product information is not third-party EDR coverage: use an EDR source for agent presence.Map: Each Datto RMM site UID.
Available observations: Device management, Last management check-in, Device online, Operating system, Patch state, Antivirus product.Use the vendor’s current instructions for credential preparation: Datto RMM API key setup.
NinjaOne
NinjaOne
Use an API Services machine-to-machine application. Region values supported by the form are app, eu, oc, ca and us2. The connector supplies management, reachability and backup-product presence, not backup success or patch compliance.Map: Each NinjaOne organization ID.
Available observations: Device management, Device online, Backup protection provider.Use the vendor’s current instructions for credential preparation: NinjaOne OAuth configuration.
N-able N-central
N-able N-central
Use the N-central User-API Token and your own server URL. The current connector only supplies RMM management presence; it does not supply patch status, online state or check-in time.Map: Each customer ID; parent service-organization records are not clients.
Available observations: Device management.Vendor preparation: N-central token authentication.
Syncro
Syncro
Use a key with customer and asset read access and the correct MSP subdomain. The current connector supplies RMM management presence only; it does not supply patch compliance or check-in time.Map: Each Syncro customer numeric ID.
Available observations: Device management.
Liongard
Liongard
Use the access key/secret and instance subdomain. Inspection status and recency show monitoring activity; they are not a universal copy of each inspector’s underlying configuration.Map: Each Liongard environment ID.
Available observations: Monitored system, Inspection state, Last inspection.Vendor preparation: Liongard API access.