Integrations
What it connects to
The point of consolidation is not to replace everything you own. It is to stop you maintaining the joins between them. QueGuard speaks the standards your estate already speaks, so connecting it is configuration rather than a project.
Your people systems
Workday, SAP SuccessFactors and other HR platforms drive joiner, mover and leaver directly. The moment someone is terminated in HR, that is the moment their access starts to go.
Your applications
Business applications, cloud platforms and anything that speaks a standard sign-on protocol. Access is granted, reviewed and removed in the same place.
Your existing directory
Keep the directory you have, or use ours. Either way it is governed rather than merely connected.
Your infrastructure
Servers, network devices and the administrative access to them — including the sessions worth recording.
Your monitoring
Everything we record can flow into the monitoring platform you already run. We are not asking you to watch a second screen.
Your AI agents
Agents get an identity and short-lived access instead of a credential of their own. How that works →
How connecting works
Standards, not bespoke plumbing
QueGuard speaks the protocols your estate already speaks. In most cases connecting a system is a configuration step, not an integration project.
SAML 2.0, OIDC & FIDO2 / WebAuthn
Federation and passwordless sign-on for anything that speaks a standard protocol — including passkeys. Users authenticate once; access is granted, reviewed and removed in one place.
SCIM 2.0 & HR-driven JML
Joiner, mover and leaver flows driven from your HR platform. A termination in HR is the moment access starts to go.
LDAP, Active Directory & Entra ID
Keep the directory you have, or use ours. Either way it is governed rather than merely connected.
Syslog / CEF & webhooks
Everything recorded can flow into the SIEM and ITSM you already run — alerts, logs and evidence on your screen, not a second one.
SSH, RDP & short-lived tokens
Administrative sessions are brokered and recorded. Agents and services receive credentials that expire in minutes, not secrets of their own.
Outbound-only, mTLS / TLS 1.3
The connector reaches out to us. There is no inbound path from QueGuard into your network — the trust model your architecture already assumes.
Per-tenant connectors
Wired once, isolated per customer
Each tenant runs its own isolated set of connections. Nothing is shared across tenants, and no connector reaches across the silo boundary.
Email & SaaS
Okta, Entra ID and other identity providers, plus the SaaS your teams live in. Federated in, governed centrally.
SIEM & ITSM
Splunk, Microsoft Sentinel, ServiceNow and equivalents. Events, tickets and evidence land where your operations team already works.
Cloud & SaaS apps
Microsoft 365, Google Workspace, Salesforce and the platforms that hold your working data — access reviewed and revoked from one record.
Threat intel & EDR
CrowdStrike, SentinelOne and other risk signals feed conditional access, so posture and context change what a session is allowed to do.
Customer-specific
The unusual internal system with no standard protocol. We will tell you early whether it connects cleanly — sometimes the answer is no.
Keep what you own. Stop maintaining the joins between it.
The honest limit
The largest vendors have longer catalogues of ready-made connections, particularly to agent platforms. If your estate depends on an unusual application with no standard sign-on support, ask us about it specifically before you get excited — the answer is sometimes no, and you should hear that early.