Platform · Integrations

The number of integrations is the wrong question

Every GRC vendor shows a wall of logos. Almost none of them will tell you which of those connections produces something an assessor accepts — and that is the only distinction that changes your compliance position.

Three kindsOnly one is compliance-grade
EvidenceThe test that matters
Your stackNot the vendor's reference stack
An access decisionSo a vendor assessment too
This page sets out how we think integrations should be evaluated in a GRC platform, including ours. It names no specific connectors on purpose — a list on a webpage goes stale and tells you nothing about what each connection actually does. For what is supported in your environment today, and whether it reads status or collects evidence, ask us and we will answer per system.

Three kinds of integration

From the compliance programmes we build and run in Saudi Arabia: most integrations sold as compliance automation are notification integrations. They are genuinely useful and they change nothing about what you can show an assessor. Knowing which kind you are being offered is the difference between a shorter audit and a nicer inbox.

1 Convenience

Notification

A message when something is assigned, due or overdue, delivered where your team already works. Real value for adoption — a request people see is a request people answer — and zero value as evidence.

2 Context

Status and data

Reading state from another system so you can see it alongside your controls. Useful for knowing where things stand, and still not proof. A dashboard showing a system is configured correctly is not an artefact.

3 Compliance-grade

Evidence collection

Producing an artefact that demonstrates a control operated — dated, attributable, and capable of being handed to an assessor. This is the only kind that changes your position, and it is the rarest.

The test we use when evaluating any integration, ours included: can the output be handed to an assessor without further explanation? If it needs a person to describe what it means, it is context. If it stands on its own with a date and a source, it is evidence.

Automated does not mean sufficient

The trap in evidence automation, and the one that surfaces during fieldwork rather than during the sales cycle.

An integration can collect an artefact perfectly and still not help you, because collection and sufficiency are different judgements. Somebody has to have decided that this artefact demonstrates this control, for this period, to the standard your assessor applies. Automation removes the fetching. It does not remove the decision.

What automation gives you
  • The artefact arrives without anyone being asked
  • It arrives on schedule rather than before an audit
  • Its date and source are recorded automatically
  • Nobody has to interrupt an engineer for it
  • It cannot be quietly forgotten
What still needs a person
  • Deciding this artefact proves this control
  • Deciding the period it covers is the right one
  • Noticing when the control changed and the evidence did not
  • Judging whether an assessor will accept it
  • Spotting that a collection has silently stopped working

The last item on the right is the one that costs most. An integration that breaks quietly produces the appearance of current evidence with none of the substance — and it is discovered during an assessment, which is the worst time and place to find out.

Your stack is not the vendor's reference stack

A platform built for a US or European buyer integrates with what that buyer runs. What runs here is frequently different.

What you runThe usual problemWhat to ask
Government-mandated platforms Country-specific, so no international vendor ships a connector Can we bring data in ourselves, and in what format
On-premise directories and systems Not reachable from a hosted platform without deliberate design What is required to reach them, and who holds the credentials
Local or regional business systems Below the threshold where global vendors build connectors Is there an API we can use, and can we build against it
Systems with no API at all More common than vendors admit, especially in older estates How the platform handles manual evidence properly
Sector-specific platforms Used by a handful of organisations in one country Whether a custom connector is possible and who builds it
Internally built tooling Nobody will ever ship a connector for it Is there an open API we can push to

Read the third column as the actual buying criteria. A long connector list built for another market tells you very little; an open interface you can build against tells you whether the platform will fit an estate nobody else has seen. That question is worth more than any logo wall.

Every integration is an access decision

Connecting a system means granting something the ability to read it. That is a vendor assessment and an asset question before it is a convenience.

Least privilege

Read what, exactly

An integration that requires broad administrative access to read one setting is a poor trade. Ask what the minimum permission is and whether it can be scoped down — the answer tells you how carefully the connector was built.

Direction

Read, or read and write

An integration that can change configuration in a connected system is a materially different risk from one that only observes. Establish which before enabling it, not after.

Credentials

Who holds them, and what happens when they rotate

Service accounts for integrations are among the most commonly forgotten credentials in an estate. They belong in your access review like any other.

Data movement

What actually leaves the system

An integration that pulls a full export where a status flag would do has moved data you now have to account for, including under the PDPL where personal data is involved.

Vendor register

A connected tool is a third party

If it reads your data, it belongs in your vendor register with the rest of the processor chain — including when it arrived as a feature rather than a purchase.

Asset register

And the systems it touches

The connected system's classification determines whether the integration is appropriate at all. This is an asset governance question that people answer after connecting rather than before.

When there is no integration

Which will be true for part of your estate no matter which platform you choose. Worth planning for rather than discovering.

A well-run manual evidence process beats a broken integration comfortably, and it beats an integration nobody trusts by a wider margin. What makes manual evidence work is not effort — it is the same discipline that makes automated evidence work: a named owner, a schedule, a validity period, and a review before it counts.

Requested

From the person who produces it

Not from the compliance team, who will have to ask them anyway. The request goes to the owner, on schedule, with the deadline visible.

Scheduled

On a cycle, before it expires

Evidence with a validity period resurfaces before it lapses. This is what makes manual collection survivable — nobody is remembering anything.

Reviewed

Before it counts

Someone confirms the artefact demonstrates what it is supposed to. The step automated collection also needs, which is why manual is less of a gap than it appears.

Honest

Recorded as manual

Knowing which evidence is automated and which is not tells you where your programme is fragile. Presenting both as equivalent hides the fragility until it matters.

Our advice to organisations choosing a platform: do not weight the connector list heavily. Weight what happens for the two thirds of your estate that will never have a connector, because that is where most of your evidence will come from regardless of which vendor you pick.

How we approach it in Govrly

Principles rather than a connector list, because the list changes and the principles are what you are actually buying.

Honest labelling

We say which kind it is

Notification, status, or evidence collection. A buyer assessing whether an integration shortens their audit needs to know which one they are being offered, and vendors routinely blur it.

Manual first

The programme works without connectors

Evidence collection, review and validity work the same whether the artefact arrived automatically or from a person. Most Saudi estates need this, so it cannot be the fallback path.

Open interface

You can bring your own

An estate nobody else has seen needs a way in that does not depend on us building a connector for it. Ask us what is available and we will answer specifically for your systems.

Scoped access

Least privilege by default

An integration should ask for the minimum it needs. Where something requires broad access, that is a decision you should make deliberately rather than accept as a setup step.

Visible failure

A broken collection surfaces

Silent failure is the worst property an evidence integration can have, because it produces the appearance of coverage. A connection that stops working should be as visible as evidence that expired.

Still reviewed

Automated evidence is not auto-approved

An artefact that arrives automatically still passes through review before it counts, because sufficiency is a judgement and automation does not make it.

Deciding what to connect

Start from the evidence you need, not from the list of things you could plug in.

  1. List the evidence you collect most oftenAccess reviews, configuration exports, training records, backup confirmations. The artefacts requested several times a year are where automation pays; everything else is a distraction.
  2. Work out which system produces each oneSome evidence comes from a system that could be connected, and some comes from a person's judgement and never will. Separating these takes an hour and sets realistic expectations.
  3. Rank by frequency and painAn artefact requested four times a year from an unresponsive owner is worth connecting. One requested annually from a cooperative team is not.
  4. Ask what kind each integration isNotification, status or evidence. If the answer is unclear, assume it is the first, because that is the most common and the least often admitted.
  5. Check the access it requiresMinimum permission, direction, credentials, what data moves. This is a vendor assessment, and it should follow the same process as any other.
  6. Make the rest work manually, properlyNamed owners, schedules, validity periods, review. This covers most of your estate and it determines whether the programme holds together.
  7. Monitor for silent failureDecide how you will know a collection stopped. An integration nobody checks is worse than no integration, because it produces confidence you have not earned.
  8. Re-check the value after a quarterSome integrations save real effort and some create maintenance nobody budgeted for. The second kind should be retired rather than tolerated.
What this looks like in Govrly

Evidence collection, review and validity work identically whether an artefact arrives from a connected system or from a person — so the two thirds of your estate that will never have a connector are not the fallback path. Tell us your systems and we will answer per system what is possible.

See it in a demo →

Integrations — FAQs

Why is there no list of integrations on this page?

Because a list on a webpage goes stale and tells you nothing about what each connection actually does. A connector that reads status is presented identically to one that collects evidence, and only the second changes your compliance position. Tell us your systems and we will answer per system.

What makes an integration compliance-grade?

It produces an artefact you could hand to an assessor without further explanation — dated, attributable, standing on its own. Notification integrations and status readouts are genuinely useful and neither is evidence. The test is whether the output needs a person to describe what it means.

Does automated evidence still need review?

Yes. Collection and sufficiency are different judgements. Somebody has to have decided that this artefact demonstrates this control for this period to the standard your assessor applies. Automation removes the fetching, not the decision — and an automated artefact that is approved automatically is an assertion nobody made.

Our systems are local and probably unsupported. What then?

That is normal here and worth planning for. A platform built for another market integrates with what that market runs. The questions that matter are whether there is an open interface you can build against, and whether manual evidence is handled properly — because that will cover most of your estate whichever vendor you choose.

Can we reach on-premise systems?

Ask us for your specific environment and we will answer directly. In general this requires deliberate design rather than being a default capability, and any vendor claiming otherwise without asking about your network is not being careful with you.

Is connecting a system a security decision?

Yes, and it should go through the same process as any other vendor access. Establish the minimum permission required, whether the connection can write or only read, who holds the credentials, and what data actually moves. Where personal data is involved, the connected tool belongs in your processor chain.

What happens if an integration breaks?

The failure mode that matters is the silent one. An evidence integration that stops working while appearing fine produces the look of current coverage with none of the substance, and it is discovered during an assessment. Decide in advance how you will know a collection has stopped.

Can we build our own connector?

This is the question worth asking every vendor, because an estate nobody else has seen needs a way in that does not depend on someone building a connector for it. Ask us what is available and we will answer specifically rather than in general terms.

How many integrations should we actually set up?

Fewer than you expect. Connect the evidence you collect several times a year from sources that resist. Everything requested annually from a cooperative team is better handled manually, because each integration carries maintenance and access risk that a once-yearly request does not.

Should the connector list drive our platform choice?

We would weight it lightly. A long list built for another market tells you little about your estate. Weight instead what happens for the systems that will never have a connector — because that is where most of your evidence will come from regardless of which platform you select.

Tell us your systems, not your wishlist

We will tell you per system what is possible, what kind of integration it is, and what stays manual.

GRC Platform Integrations — What Matters | Govrly