Browse and search documentation
External integrations
Connect cloud accounts, enterprise identity, notifications and AI as needed, validating connectivity, access and actual results separately.
On this page
Define the integration task
| Type | Inputs to prepare | Validation target |
|---|---|---|
| Cloud account | Provider, account, regions, read scope and managed credentials | Expected resources synchronize; out-of-scope resources remain inaccessible |
| Enterprise identity | Protocol, identity provider, user mapping and HTTPS callback | Successful and rejected login, MFA and emergency local access |
| Notification channel | Receiver, channel and permission to send | Actual delivery and acknowledgement are recorded separately |
| AI service | Endpoint, model, protocol, credentials and data-handling requirements | Connectivity succeeds, followed by analysis and citation quality checks |
General connection procedure
- Enable only integrations required for the current scenario, grant minimum necessary access and assign credential and certificate owners.
- Submit addresses and authentication through the integration’s dedicated configuration surface, never in ordinary notes or public examples.
- Run available connection or protocol tests and resolve classified network, authentication or certificate failures.
- Use an authorized test resource for a real task and verify denied-access and unreachable cases too.
- Record ownership, rotation and disablement procedures and retest after changes rather than relying on an old validation.
Sign-in and directory synchronization differ
OIDC, LDAP/AD login, SAML and RADIUS have distinct protocol scopes and need provider-specific validation. LDAP/AD login and LDAP/SCIM directory synchronization are different functions; successful sign-in does not mean organizations and groups are synchronized.
Test user mapping, first sign-in, MFA, disabled accounts and emergency local administration before enabling. Do not assume arbitrary SCIM server support, Kerberos/NTLM or every SAML flow.
Validate an AI connection
Check the effective source, model and protocol in Settings → AI model connection, then run the connection test. Distinguish absent or demo configuration from an actual model connection.
An LLM probe does not test the embedding endpoint used by knowledge retrieval. The knowledge base needs an embedding model that returns 1536-dimension vectors. Validate document processing, retrieval and citations separately when using a knowledge base.
Credentials and support
- Verify real calls after rotation. Record time, integration type and redacted errors without private keys, tokens or connection strings.
- Do not disable certificate checks, grant global access or modify production data merely to prove connectivity.
Send your deployment version, page and a redacted description so we can investigate and update the guide.
weiwendi@aiops.red