Docs → API & integrations
Requesting a new integration
Want two systems talking to each other? Here is what to tell us and how the request gets vetted.
Last updated: August 2026
At a glance
- Tell us three things: what, who, and what data moves
- Vendors get vetted like new hires, not installed like apps
- A “no” always comes with the reason and an alternative
- One-off exports skip the standing review — just ask
How it works
1
Tell us the goal
What you want connected, who will use it, what data moves. A sentence each — “new web leads landing in the CRM automatically” beats a page of technical guesswork.
2
We vet it
The vendor’s security posture, the access it demands, and whether that scope is proportionate. A standing connection into your environment earns scrutiny.
3
Build, test, own
We configure the connection, test with real cases from your workflow, and add it to the managed inventory — so it has an owner from day one.
Note: we may say no to an integration on security grounds — and we will always say why. “No, because…” is part of the service, and where a safer alternative exists, you get it in the same breath.
Common questions
Can we just install the plugin ourselves?+
On systems we manage, please route it through us — not for control, but because unvetted connections are the classic quiet breach path.
What about one-off data exports?+
Ask anyway. One-offs skip the standing-connection review and usually happen faster.
What happens to integrations when we change vendors?+
We shut the old connection off completely — lingering access from retired tools is a favorite attacker foothold.
Related docs
Integrations we manage →
The platform families and what “managed” means.
Security practices →
Why every connection gets vetted first.
Hosting & DNS changes →
The request flow for the web layer.
Got two systems that should be talking?
One sentence about the goal is enough to start the review.