---
title: "Connected Tools"
description: "Connected Tools allow you to integrate our platform with various external services, enhancing its capabilities by connecting to your existing infrastructure and applications. These integrations ena..."
last_updated: "2026-05-06T07:36:18.471599+00:00"
canonical_url: "https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/guide/section-6/connected-tools"
---

Connected Tools allow you to integrate our platform with various external services, enhancing its capabilities by connecting to your existing infrastructure and applications. These integrations enable features like automated employee data synchronization, cloud security posture management, and browser-based task automation.

By connecting your tools, you can centralize data, automate routine tasks, and gain deeper insights into your organization's security and compliance posture, all from within our platform. This page guides you through setting up and managing these valuable connections.

### Key Concepts

Before you begin, understanding a few key terms will be helpful:

*   **Provider**: An external service or application you want to connect to (e.g., AWS, Google Workspace, Rippling, JumpCloud, Ramp).
*   **Connection**: A specific link established between our platform and one of your external service accounts. Each connection stores the necessary credentials and configuration to interact with that service.
*   **Authentication Type**: The method used to verify your identity and grant our platform access to your external service. Common types include:
    *   **API Key**: A secret key or token you provide directly.
    *   **OAuth2**: A secure authorization flow where you grant permission through the provider's website, without sharing your direct login credentials.
    *   **Custom**: Specific credentials tailored to a particular provider, such as IAM Role ARN and External ID for AWS.
*   **Employee Sync**: A feature that automatically imports and manages your organization's user accounts by synchronizing with an external Identity Provider (IdP) or Human Resources Information System (HRIS). This ensures that user statuses (active, suspended, removed) are kept up-to-date.
*   **Cloud Security Scan**: A process that analyzes your connected cloud environments for security vulnerabilities, misconfigurations, and compliance deviations, often leveraging services like AWS Security Hub.
*   **Browser Automation**: A capability to record and replay browser actions, allowing you to automate repetitive web-based tasks or data collection from web applications.

---

### Connecting a New Tool

Connecting a new tool typically involves selecting the provider, providing authentication details, and confirming the connection.

<Steps>
<Step>
### Browse Available Providers
Navigate to the "Integrations" or "Connected Tools" section in your platform settings. You will see a list of all available providers.
</Step>
<Step>
### Select a Provider
Choose the tool you wish to connect. The platform will guide you through the specific authentication steps required for that provider.
</Step>
<Step>
### Provide Authentication Details
Depending on the provider, you will either:
*   **Be redirected to the provider's website (OAuth2)**: You'll log in to the provider and grant our platform the necessary permissions. After authorization, you'll be redirected back to our platform.
*   **Enter API keys or other credentials directly**: You'll copy and paste API keys, tokens, or other required information into designated fields.
*   **Enter custom credentials (e.g., AWS)**: For providers like AWS, you'll provide specific details such as an IAM Role ARN and an External ID.

<Callout title="Important for OAuth2" variant="info">
Ensure that your browser allows pop-ups and redirects, as the OAuth2 flow will temporarily take you to the provider's website.
</Callout>
</Step>
<Step>
### Validate and Activate the Connection
After providing the credentials, the platform will attempt to validate them. If successful, your connection will be activated. For some providers, like AWS, this validation includes checking for necessary permissions and service enablement (e.g., Security Hub).

<Callout title="AWS Specific Validation" variant="warning">
For AWS connections, the platform verifies that:
1.  The provided IAM Role ARN and External ID are correct and allow our platform to assume the role.
2.  AWS Security Hub is enabled in all specified AWS regions.
If validation fails, you will receive a specific error message guiding you on how to resolve the issue.
</Callout>
</Step>
</Steps>

---

### Managing Existing Connections

You can view, test, update, and remove your connected tools at any time.

<Steps>
<Step>
### View Your Connections
Access the "Integrations" or "Connected Tools" section to see a list of all your active and inactive connections. Each connection will display its status (e.g., active, error, paused) and last sync time.
</Step>
<Step>
### Test a Connection
If you suspect an issue with a connection or want to verify its credentials, you can trigger a connection test. This re-validates the credentials and updates the connection's status.
</Step>
<Step>
### Pause or Resume a Connection
You can temporarily pause a connection to stop all automated activities associated with it. When you're ready to resume, simply activate it again.
</Step>
<Step>
### Update Credentials
For connections using API keys or custom authentication, you can update the stored credentials. For OAuth2 connections, you typically need to disconnect and re-establish the connection if the authorization expires or needs to be changed.

<Callout title="OAuth2 Reconnection" variant="warning">
OAuth2 integrations often rely on access tokens that can expire. While the platform attempts to refresh these tokens automatically, if a refresh fails, you may need to disconnect and reconnect the integration to re-authorize access.
</Callout>
</Step>
<Step>
### Disconnect or Delete a Connection
*   **Disconnect**: This performs a soft delete, marking the connection as inactive but retaining its history.
*   **Delete**: This permanently removes the connection and all associated data from the platform. Use this option with caution.
</Step>
</Steps>

---

### Employee Sync

The Employee Sync feature automates the management of user accounts within your organization by integrating with your HRIS or Identity Provider (IdP).

<Steps>
<Step>
### Connect an Employee Sync Provider
Follow the general steps above to connect one of the supported providers:
*   Google Workspace
*   Rippling
*   Ramp
*   JumpCloud
</Step>
<Step>
### Set Your Employee Sync Provider
Once connected, you need to designate which connected tool will be your primary source for employee data.
1.  Go to the "Integrations" or "Connected Tools" section.
2.  Find the "Employee Sync Provider" setting.
3.  Select your desired active connection (e.g., Google Workspace, Rippling) from the dropdown list.
4.  Save your changes.

<Callout title="Impact of Employee Sync" variant="warning">
When an employee sync provider is active:
*   Users found in the external system will be imported or reactivated in our platform.
*   Users marked as suspended, inactive, or removed in the external system will be deactivated in our platform.
*   Changes made directly in our platform for users managed by the sync provider may be overwritten during the next sync.
</Callout>
</Step>
<Step>
### Trigger a Manual Sync
While employee syncs often run automatically on a schedule, you can manually trigger a sync at any time from the provider's connection details page. This is useful after making significant changes in your HRIS/IdP or to quickly update user statuses.
</Step>
</Steps>

---

### Cloud Security Scans (e.g., AWS Security Hub)

For cloud environments, you can connect your accounts to perform automated security scans and identify potential risks.

<Steps>
<Step>
### Connect Your Cloud Provider
Follow the general steps to connect your cloud provider, such as AWS. Ensure you provide the necessary credentials and permissions for security scanning.
</Step>
<Step>
### Trigger a Cloud Security Scan
Once connected, you can initiate a security scan for your cloud environment. This will analyze your resources for security findings based on the configured policies and services (e.g., AWS Security Hub).
</Step>
<Step>
### Monitor Scan Status
You can view the status of your security scans, including any findings, directly within the platform. This allows you to track progress and address identified issues.
</Step>
</Steps>

---

### Browser Automation

Browser Automation allows you to record and execute sequences of actions within a web browser, automating repetitive tasks.

<Steps>
<Step>
### Create a Browser Automation
You can define new browser automations by specifying the steps you want the browser to perform (e.g., navigating to a URL, clicking elements, entering text).
</Step>
<Step>
### Run an Automation
You have several options for running automations:
*   **Start Live**: Executes the automation and provides a live view of the browser session, allowing you to watch the automation in real-time.
*   **Execute on Existing Session**: Runs the automation on a pre-existing browser session.
*   **Run Automation**: Executes the automation and returns the final result, including screenshots if configured.
</Step>
<Step>
### Manage Automations
You can view a list of all your created automations, edit their steps, or delete them if they are no longer needed.
</Step>
<Step>
### View Run History
Access the history of past automation runs to review their outcomes, check for errors, and view any generated artifacts like screenshots.
</Step>
</Steps>

## Sitemap

See the full [sitemap](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/llms.txt) for all pages in this wiki.
