Integrations
Plugs into the stack you already run
Provision people from your directory, deliver through your gateway, and stream every event into the tools your team already watches. No endpoint agent, no rip-and-replace, and no spreadsheet that somebody has to remember to update.
- 15 min
- directory sync interval
- Immediate
- deprovisioning
- REST
- plus signed webhooks
Identity
People arrive and leave on their own
SCIM and directory sync create, update and disable accounts in step with your identity provider. Someone offboarded at 17:00 cannot sign in at 17:15, and a new joiner is in scope for a baseline before their first week is out.
- SAML 2.0, OIDC, SCIM 2.0 and LDAP/AD sync
- Dynamic audiences on any directory attribute
- Orphaned-account report for the edge cases
Downstream
Every event, wherever you watch
Simulation results, enrolments, certificates, score changes and reported threats are all first-class events. Stream them to a SIEM, post them to Slack or Teams, or pull them over REST into a GRC tool or risk register.
- Signed webhooks with idempotent delivery
- Slack and Teams for nudges and report routing
- Full REST API — the console is one of its clients
Directory
Supported systems
| System | What it does | Notes |
|---|---|---|
| Microsoft Entra ID | SSO and SCIM provisioning | Group and dynamic-group scoping |
| Okta | SAML / OIDC SSO and SCIM | Push groups supported |
| Google Workspace | SSO and directory sync | Org-unit scoping |
| LDAP / Active Directory | On-premises directory sync | Enterprise tier |
| Microsoft 365 / Google | Simulation delivery and allow-listing | See deliverability |
| Mimecast / Proofpoint | Gateway bypass policy | Generated rule sets |
| Slack / Teams | Nudges, reminders and report routing | Per-channel configuration |
| SIEM & SOAR | Event streaming | Splunk, Sentinel, Chronicle and generic webhook |
Questions
Asked on every first call
The ones that decide whether a first call turns into a second one.
3 questions
Is there an agent to install on endpoints?
No. SafeLoop is delivered entirely through your mail platform, your identity provider and an optional mail add-in. Nothing is installed on laptops or phones.
How quickly does deprovisioning take effect?
In the same sync cycle as your identity provider, which runs every fifteen minutes by default. SCIM deletes and disables are applied immediately on receipt.
Can we pull results into our own reporting?
Yes. The REST API exposes campaigns, audiences, results, enrolments, certificates and score history, and signed webhooks push the same events in real time. Several customers report from their own warehouse rather than the console.
Keep reading
Related
Connect a test tenant on the call
SSO and SCIM against your sandbox directory usually takes under twenty minutes.