Bring identity, endpoint protection, observability, and service management into a clear operating model. Explore how signals reach the right team, how actions are governed, and where evidence is retained.
Explore available connectors and integration blueprints. We confirm licensing, permissions, delivery targets, and control coverage with your team before deployment. Inclusion in this directory does not claim vendor certification or partnership status.
12 integrations shown. Direction is relative to the Bitscaled Control Plane.
Okta
Architecture review
Map identity and session events into an accountable access-review workflow.
These reference flows show how an integration can connect evidence to action. Select a workflow to inspect the handoffs and approval boundaries.
A signal becomes an owned incident.
Reference flow: preserve source context, validate the event, and route a tenant-scoped incident to the team responsible for action.
01
Endpoints & cloud
An authorized source emits an event.
02
Edge & WAF
Bound incoming traffic and apply request controls.
03
Ingestion relay
Verify, normalize, and deduplicate the event.
04
Workspace Control Plane
Resolve tenant scope and attach asset context.
05
Triage & escalation
Apply policy and assign accountable ownership.
06
Client SIEM / Datadog
Send approved evidence and preserve correlation.
Only scoped, authenticated events enter an operational workflow. The final connector and delivery target are agreed during assessment.
Containment follows explicit authority.
Reference flow: a detection can propose containment, while policy, approval, and vendor permissions control whether an action executes.
01
Endpoint detection
Retain the source event and affected device identity.
02
Verified ingestion
Authenticate the sender and bind the tenant.
03
Policy evaluation
Check action scope, target, and blast radius.
04
Human approval
Require approval when the response policy calls for it.
05
Endpoint connector
Dispatch only a supported, authorized action.
06
Ticket & audit record
Record the vendor outcome and remediation owner.
A diagram never grants containment permission. Unsupported actions and missing credentials fail closed; approval requirements remain intact.
Evidence stays traceable to its source.
Reference flow: collect the minimum required evidence, retain provenance, and deliver it to approved destinations for review.
01
Identity & devices
Read the approved controls and inventory scope.
02
Authenticated collector
Use the agreed API permissions and sync schedule.
03
Evidence normalization
Preserve source, timestamp, and control context.
04
Tenant workspace
Enforce access boundaries and redact sensitive fields.
05
Control review
Map evidence to applicable assessment requirements.
06
Approved export
Share with authorized reviewers under agreed retention.
Framework mappings support assessment; they do not certify an organization. Data residency, retention, and transfer requirements are scoped before deployment.