KeyForge AI
Integrations

Built for how each platform actually grants access.

A broad catalog of pre-built connectors, plus AI self-discovery connectors for REST and database targets that onboard in minutes rather than days. We do not compare role names — we resolve inheritance down to the atomic permission in each system, then map those to a common model.

Featured platforms

Six models documented in depth

These six have a page each because their access models differ most — and because cross-application rules usually span them. They are a subset of the catalog, not the extent of it.

Normalisation is what makes a cross-application rule possible. Once an EBS function, a Fusion privilege, a SAP authorization value and a directory group are expressed as the same kind of object, one rule can span all of them — and one exception, one control and one audit record follow it.

Self-discovering connectors

Connectors that map themselves

Most connector work is schema archaeology: reading documentation, mapping attributes by hand, then rebuilding it when the target changes. For REST and database targets the connector does that itself — turning an onboarding that took days into one that takes minutes.

AI Agent

REST Service (AI Agent)

Point it at an API rather than writing an integration against a specification. The connector works out what the endpoint exposes and proposes the mapping for a human to confirm.
AI Agent

Database (AI Agent)

Aim it at a schema and it discovers the tables, columns and relationships that carry identity and entitlement data, instead of requiring them to be specified up front.
AI Agent

Screen Scraper (AI Agent)

For the applications that expose no API and no database at all — the ones that otherwise stay outside governance permanently.
Minutes rather than days is what brings the long tail under governance. The in-house and custom applications that never justified a bespoke connector project — and so stayed outside the access review entirely — are now worth onboarding.

The catalog

Pre-built across the enterprise stack

ERP, HR, directory, cloud, ticketing and the identity platforms you may already run — onboarded through a guided flow rather than a services engagement.

ERP & business applications

  • SAP
  • Oracle E-Business
  • Oracle Fusion Apps
  • PeopleSoft
  • PeopleSoft HR
  • PeopleSoft UM
  • Ariba
  • Salesforce
  • Epic
  • ATG Web Commerce

Directory & access

  • Active Directory
  • AD Domain
  • AD Collector
  • AD PowerShell Connector
  • Global AD Config
  • LDAP
  • Generic LDAP
  • Okta
  • Azure
  • RSA
  • Centrify
  • Unix

Identity platforms

  • SailPoint IdentityIQ
  • SailPoint IIQ Applications
  • Oracle Identity Manager
  • Oracle IDCS
  • Oracle Access Governance
  • OAG Identity Collection
  • OIM/OUD Management
  • E2E Migration Client

Cloud, data & service

  • AWS
  • IBM AS/400
  • Database
  • Database Collector
  • ServiceNow Ticketing
  • Flatfile
  • Logical Application
  • Provisioning Agent
  • Disconnected Application
  • Screen Scraper

Connector catalog

Onboard a system in a guided flow

Select the system, add its details, configure the integration, map the schema, and finish — with connector types spanning ERP, HR, directory, cloud, ticketing and the IGA platforms you may already run.

Integration wizard showing the catalog of supported application types across ERP, directory, cloud and identity platforms
Connector catalog — select system, add details, configure, map schema

Schema mapping

Source attribute to target attribute, explicitly

Every connector declares how its source attributes map onto the identity model, with inbound and outbound transformation, hooks and a provisioning threshold configured per target system.

Schema mapping screen showing source attributes mapped to target attributes with mapping type and default values
Schema mapping — source to target, with transformation and thresholds

Running something that is not on the list?

If it speaks REST or sits on a database, the self-discovery connector handles it — and anything else is a conversation about the extract model, not a rebuild.