Skip to content

Integrations

Plugs into the stack you already run

Provision people from your directory, deliver through your gateway, and stream every event into the tools your team already watches. No endpoint agent, no rip-and-replace, and no spreadsheet that somebody has to remember to update.

15 min
directory sync interval
Immediate
deprovisioning
REST
plus signed webhooks
15 minsync intervalENTRA · OKTA · GOOGLE · LDAPJoiner createdIn scope for a baselineLeaver disabledCannot sign in at 17:15No CSV. No agent. No manual stepanyone has to remember.

Identity

People arrive and leave on their own

SCIM and directory sync create, update and disable accounts in step with your identity provider. Someone offboarded at 17:00 cannot sign in at 17:15, and a new joiner is in scope for a baseline before their first week is out.

  • SAML 2.0, OIDC, SCIM 2.0 and LDAP/AD sync
  • Dynamic audiences on any directory attribute
  • Orphaned-account report for the edge cases
Request — Authenticated session, org resolved from the subdomainRequestAuthenticated session, org resolved from the subdomainTenant context — orgId bound to the async execution context — not a request argumentTenant contextorgId bound to the async execution context — not a request argumentRepository layer — Every query is scoped before it reaches the driverRepository layerEvery query is scoped before it reaches the driverPostgres row-level security — The database refuses cross-tenant reads even if the app is wrongPostgres row-level securityThe database refuses cross-tenant reads even if the app is wrongYour data — Encrypted at rest, keys in a managed vaultYour dataEncrypted at rest, keys in a managed vault
Two independent enforcement layers. A bug in one does not become a data breach.

Downstream

Every event, wherever you watch

Simulation results, enrolments, certificates, score changes and reported threats are all first-class events. Stream them to a SIEM, post them to Slack or Teams, or pull them over REST into a GRC tool or risk register.

  • Signed webhooks with idempotent delivery
  • Slack and Teams for nudges and report routing
  • Full REST API — the console is one of its clients
0%10%20%30%40%Baseline: 33.2% phish-prone33.2%Baseline90 days: 20.1% phish-prone20.1%90 days12 months: 4.2% phish-prone4.2%12 months−87%
Phish-prone rate over 12 months of continuous simulation and training. Source: KnowBe4 2026 Phishing by Industry benchmark (33.2% → 20.1% → 4.2%).

Directory

Supported systems

SystemWhat it doesNotes
Microsoft Entra IDSSO and SCIM provisioningGroup and dynamic-group scoping
OktaSAML / OIDC SSO and SCIMPush groups supported
Google WorkspaceSSO and directory syncOrg-unit scoping
LDAP / Active DirectoryOn-premises directory syncEnterprise tier
Microsoft 365 / GoogleSimulation delivery and allow-listingSee deliverability
Mimecast / ProofpointGateway bypass policyGenerated rule sets
Slack / TeamsNudges, reminders and report routingPer-channel configuration
SIEM & SOAREvent streamingSplunk, Sentinel, Chronicle and generic webhook

Questions

Asked on every first call

The ones that decide whether a first call turns into a second one.

3 questions

Is there an agent to install on endpoints?

No. SafeLoop is delivered entirely through your mail platform, your identity provider and an optional mail add-in. Nothing is installed on laptops or phones.

How quickly does deprovisioning take effect?

In the same sync cycle as your identity provider, which runs every fifteen minutes by default. SCIM deletes and disables are applied immediately on receipt.

Can we pull results into our own reporting?

Yes. The REST API exposes campaigns, audiences, results, enrolments, certificates and score history, and signed webhooks push the same events in real time. Several customers report from their own warehouse rather than the console.

Connect a test tenant on the call

SSO and SCIM against your sandbox directory usually takes under twenty minutes.

See your human risk in 20 minutes

Book a demo and we’ll run a sample campaign against a test group.