Browse and search documentation

External integrations

Connect cloud accounts, enterprise identity, notifications and AI as needed, validating connectivity, access and actual results separately.

For: Integration and platform administratorsReviewed:
On this page

Define the integration task

TypeInputs to prepareValidation target
Cloud accountProvider, account, regions, read scope and managed credentialsExpected resources synchronize; out-of-scope resources remain inaccessible
Enterprise identityProtocol, identity provider, user mapping and HTTPS callbackSuccessful and rejected login, MFA and emergency local access
Notification channelReceiver, channel and permission to sendActual delivery and acknowledgement are recorded separately
AI serviceEndpoint, model, protocol, credentials and data-handling requirementsConnectivity succeeds, followed by analysis and citation quality checks

General connection procedure

  1. Enable only integrations required for the current scenario, grant minimum necessary access and assign credential and certificate owners.
  2. Submit addresses and authentication through the integration’s dedicated configuration surface, never in ordinary notes or public examples.
  3. Run available connection or protocol tests and resolve classified network, authentication or certificate failures.
  4. Use an authorized test resource for a real task and verify denied-access and unreachable cases too.
  5. Record ownership, rotation and disablement procedures and retest after changes rather than relying on an old validation.

Sign-in and directory synchronization differ

OIDC, LDAP/AD login, SAML and RADIUS have distinct protocol scopes and need provider-specific validation. LDAP/AD login and LDAP/SCIM directory synchronization are different functions; successful sign-in does not mean organizations and groups are synchronized.

Test user mapping, first sign-in, MFA, disabled accounts and emergency local administration before enabling. Do not assume arbitrary SCIM server support, Kerberos/NTLM or every SAML flow.

Validate an AI connection

Check the effective source, model and protocol in Settings → AI model connection, then run the connection test. Distinguish absent or demo configuration from an actual model connection.

An LLM probe does not test the embedding endpoint used by knowledge retrieval. The knowledge base needs an embedding model that returns 1536-dimension vectors. Validate document processing, retrieval and citations separately when using a knowledge base.

Credentials and support

  • Verify real calls after rotation. Record time, integration type and redacted errors without private keys, tokens or connection strings.
  • Do not disable certificate checks, grant global access or modify production data merely to prove connectivity.
Something differs from your environment?

Send your deployment version, page and a redacted description so we can investigate and update the guide.

weiwendi@aiops.red