> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://docs.brainframe.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Integrations

# 🔗 **Integrations**

> **"Connect Brainframe GRC to the tools your teams already use — and work with that data inside your compliance workspace."**
> *Browse available connectors, configure credentials once, then import or link live records into folders, documents and tables without leaving Brainframe.*

Brainframe supports a growing catalogue of third-party integrations. From **Workspace Settings → Integrations** (also available as the standalone **Integrations** area), you connect external platforms so their data can be browsed, imported as Brainframe documents, or linked as tasks — depending on the connector.

This article is a **general overview**. For platform-specific setup (API tokens, OAuth apps, permissions, filters and field mapping), open the dedicated documentation article from each integration’s **Show documentation** badge, or from the matching changelog entry when published.

---

## 1️⃣ Where to find integrations

| Entry point | What you get |
| ---- |
| **Workspace Settings → Integrations** | Full catalogue of connectors with status, search and category filters |
| **Integrations** in the left sidebar | Shortcut to configured integrations that are enabled for your user/group |
| **NEW → Add from integrations** (folder) | Import browser for bringing external records into a folder |
| **Cloud** button on a table view | Same import browser, with the current table’s document type pre-selected when applicable |
| Document **bolt (⚡) → Task from integrations** | Link or create **task**-category work items on the open document |

Configuration screens for credentials are usually reached via the **⚙️ / Configure** action on an integration card or page (workspace administrators for shared setup; some connectors also allow individual credentials).

---

## 2️⃣ Browsing the catalogue

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/screenshot-2026-06-16-at-22081_auqxuy.png)
The integrations overview lists every connector Brainframe knows about. Use the tabs at the top to filter:

**All · Active · Assets · Documents · Identities · Incidents · Misconfigurations · Tasks · Vulnerabilities**

You can also **search** by name. Each card shows:

* Platform **name** and **logo**
* **Categories** (badges) — one connector may belong to several (for example Assets + Documents)
* A short **description** of what the integration surfaces
* **Status** relative to your workspace and user

### Typical card statuses

| Status | Meaning |
| ---- |
| **Setup required** | Credentials or connection are not configured yet — open configuration to continue |
| **Enabled / available** | Ready to use (exact label depends on scope and licence) |
| **Coming soon** | Listed in the catalogue but not yet configurable in your Brainframe version |

Cards marked **Setup required** prompt you to configure credentials. Already-enabled integrations expose a settings control to review or rotate the connection.

---

## 3️⃣ Configuring an integration (general)
![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/screenshot-2026-06-16-at-22081_1gove4f.png =705xauto)

Opening **Configure** for an integration takes you through that platform’s setup wizard or credential form. Details differ by product, but the pattern is the same:

1. Provide the credentials or OAuth app details Brainframe needs (domain, email + API token, client ID/secret, Azure app permissions, …).
2. Complete any consent or permission steps in the external tool.
3. Optionally map what to browse (projects, schemas, object types, modules, …) when the connector supports it.
4. Save and test — Brainframe validates the connection through its backend before treating the integration as active.

> 📌 Secrets and tokens are stored on the Brainframe server. After save, the browser only sees safe metadata (connected site, masked IDs, capability status). API calls to the third party are **proxied** — credentials are not re-exposed to the client.

### Credential scope

Many integrations support two scopes:

| Scope | Who configures | Who can use |
| ---- |
| **Individual** | Any authenticated user (where offered) | Only that user, with their own credentials |
| **Workspace** | Workspace administrators | Everyone who has access to the enabled integration |

**Individual credentials take priority** over workspace credentials when both exist for the same user.

Some modern connectors use **OAuth** (user consent) or share an existing app registration (for example Microsoft Defender reusing Entra ID). The configuration screen explains which model applies; the dedicated article for that platform covers the exact fields and external console steps.

> || ⚠️ Removing or rotating **workspace**-scoped credentials affects all users of that integration. Individual scope only affects your own access.

### Finishing setup outside Brainframe

Many platforms require an extra step before Brainframe can call them successfully — creating an API token, granting admin consent, enabling a licence module, or registering a redirect URL. Those steps live in each integration’s own guide. Use **Show documentation** on the integration page when available.

---

## 4️⃣ How integrations are used in daily work

Integrations fall into patterns based on their catalogue **categories**. You do not need every pattern for every connector.

### Dedicated integration page

Once configured, most connectors have a main page under **Integrations → [Platform]** with search, filters, KPIs (when available), and import actions. Use **Refresh** to reload data and **Configure** to return to setup.

### Import into folders and tables — **Add from integrations**

Use this for **Assets**, **Documents**, **Identities**, **Vulnerabilities**, **Incidents**, **Misconfigurations**, and similar inventory-style records:

1. From a folder: **NEW → Add from integrations**
2. Or from a table view: **cloud** button
3. Pick the connector from the catalogue (optionally filter by category)
4. Browse and **import** one or many records into the chosen folder / document type

Imported documents typically stay **linked** to the source so opening them can show **live** data from the external system (when the connector supports it).

### Tasks on a document — **Task from integrations**

Use this only for **Tasks**-category connectors (for example JIRA issues, Asana, Monday.com, Azure DevOps, SolarWinds Service Desk tasks):

1. Open a saved document
2. Bolt (⚡) menu → **Task from integrations**
3. Select the task provider, then **link** an existing item or create a new one

Linked tasks appear in the document’s task / activity context and can open an inline viewer for the live external item.

> 📌 **Add from integrations** and **Task from integrations** share the same browser shell, but the bolt menu is filtered to **Tasks**. Asset/CMDB and document connectors are reached from folders and tables, not from the task bolt menu.

### Sidebar shortcuts

When an integration is configured and **enabled** in **Workspace Settings → Menu interface**, it can appear under **Integrations** in the left sidebar for allowed users. Greyed-out entries usually mean the menu item is visible in configuration but not enabled or not accessible for your account.

---

## 5️⃣ Available integrations

The catalogue below reflects connectors currently listed in Brainframe. **Configurable** means you can set up credentials and use the product today; others may appear as **Coming soon** until enabled for your workspace or release.

| Integration | Categories | Description |
| ---- |
| Aikido.dev | Vulnerabilities | Code, container, cloud and application security |
| **Asana** | Tasks | Task and project management |
| **Azure DevOps** | Tasks | Development lifecycle management and CI/CD |
| **Confluence** | Documents | Team collaboration and knowledge management |
| **Google Drive** | Documents | Cloud storage and file sharing |
| **JIRA** | Tasks | Issue tracking and project management |
| **JIRA Assets** | Assets, Documents | Schema-defined CMDB and asset registry from Atlassian Assets |
| **Microsoft Defender** | Vulnerabilities, Incidents, Assets, Misconfigurations, Tasks | Endpoint protection and threat detection |
| **Microsoft Defender for Cloud** | Assets, Misconfigurations, Vulnerabilities, Incidents, Tasks, Documents | Cloud security posture, compliance and workload protection |
| **Microsoft Entra ID** | Identities | Cloud identity, access management and directory services |
| **Microsoft Intune** | Assets, Misconfigurations | Endpoint management, compliance and device configuration |
| Monday.com | Tasks | Work management and collaboration platform |
| **SharePoint** | Documents | Link documents from OneDrive and SharePoint into Brainframe folders |
| **Solarwinds Service Desk** | Tasks, Assets, Incidents | Incident, problem, change and CMDB management |

Planned integrations (Let us know if you want other integrations on support@brainframe.com)

| Integration | Categories | Description |
| **CrowdStrike Falcon** | Incidents, Vulnerabilities | Endpoint detection and response, threat intelligence |
| **Google Workspace** | Identities | Cloud identity, directory, SSO and device management |
| **Lansweeper** | Assets | IT asset discovery, inventory and management |
| **Linear** | Tasks | Task management and to-do lists |
| **Microsoft Todo** | Tasks | Task management and to-do lists |
| **Nessus** | Vulnerabilities | Code, container, cloud and application security |
| **Outkept** | Compliance | Verify phishing protection and training compliance |
| **Okta** | Identities | Identity and access management, SSO and MFA |
| **SentinelOne** | Vulnerabilities | AI-powered endpoint security and threat intelligence |
| **ServiceNow** | Vulnerabilities, Incidents, Assets, Misconfigurations, Tasks | Full integration with relevant information from the service |
| **Tenable** | Vulnerabilities | Code, container, cloud and application security |

For step-by-step setup, field mapping and troubleshooting, open the **dedicated article** for that platform (via **Show documentation** on the integration page when published).

---

## 6️⃣ Managing active integrations

Return to **Workspace Settings → Integrations** at any time to:

* Filter **Active** to see what is currently connected
* Open an integration to browse data or import records
* Update or rotate credentials via **Configure** / ⚙️
* Disconnect or clear credentials when a connection should no longer be used
* Control sidebar visibility under **Menu interface** (who sees which integration shortcut)

Imported Brainframe documents remain in your folders if you later disconnect an integration; live refresh simply depends on whether Brainframe can still call the external API with valid credentials.

---

## 7️⃣ Tips for GRC programmes

| Goal | Typical approach |
| ---- |
| Keep an **asset / CMDB register** current | Use Assets-category connectors (JIRA Assets, Defender devices, Intune, …) via **Add from integrations** |
| Attach **remediation work** to a risk or finding | Use a Tasks connector via **Task from integrations** |
| Pull **policies or evidence** from collaboration tools | Use Documents connectors (Confluence, SharePoint, …) |
| Track **vulnerabilities and incidents** for audits | Use Vulnerabilities / Incidents connectors; import into governed folders with live refresh |
| Align **identities** with access reviews | Use Identities connectors (Entra ID, …) alongside asset ownership records |

Prefer **workspace** credentials for a shared service account when the whole GRC team should see the same data; use **individual** credentials when access must stay personal or consultant-scoped.

---

## Related reading

Open each platform’s own documentation article for configuration details. The general **Menu interface** article explains how integration shortcuts appear in the sidebar for users and groups.
