Black Hat 2026: Book a meeting and enter to win $1k for a Kid's Team, Club, or Program.

Identity Context Everywhere.
Zero Custom Connectors.

Synqly connects your product to the leading identity providers through a single API so you can read user and group data, search audit logs, disable accounts, and expire sessions, regardless of which IdP a customer runs.

Bi-Directional Integrations with Leading Identity Solutions

Identity is the thread that connects every security incident to a human or a system account. Knowing that an alert fired is far less useful than knowing which user triggered it, what groups they belong to, what their access history looks like, and whether their session is still active.

Synqly’s Identity connector gives your product normalized, bi-directional access to the identity providers your customers use. Read user records, group memberships, and audit logs with a consistent query model. Disable accounts and expire sessions through a unified action API. Attach raw provider events for compliance when customers need the original data, without building separate integrations for each IdP.

Incident investigation

Run a single audit log search across Okta, Microsoft Entra ID, Google Workspace, and other connected IdPs to reconstruct what a user did and when, without switching between provider consoles.

Account compromise response

When your product detects a compromised account, immediately disable it and expire active sessions across connected identity providers through a single action, regardless of which IdP the customer uses.

Just-in-time access reviews

Pull current user and group membership data from IdPs on demand to support access review workflows, privilege audits, and least-privilege enforcement.

Identity enrichment for alerts

Overlay user and entitlement context onto security alerts so analysts see who triggered a detection, their role, their group memberships, and their recent activity, all in one place.

Synqly Trusted
Identity Partners

Greenhouse logo in teal with a stylized plant forming the letter g on the left side of the wordmarkAshby logo in bold purple serif font in a wordmark style.

Identity Integration Technical Capabilities

account_circle_off

Disable User

Disables a user in the identity system based on user ID.

person_add

Enable User

Reenables a disabled user in the identity system based on user ID.

logout

Expire All User Sessions

Logs a user out of all current sessions so they must log in again.

lock_reset

Force User Password Reset

Forces a user to reset their password before they can log in again.

group

Get Group

Returns a `Group` object wrapped in an OCSF Entity Management event of type Read from the token-linked identity provider. Depending on the providers offerings, this may include additional group information, such as the roles assigned.

group_search

Get Group Members

Returns list of `User` objects wrapped in an OCSF Entity Management event of type Read from the token-linked identity provider that are members in the group referenced by ID.

account_circle

Get User

Returns a `User` object wrapped in an OCSF Entity Management event of type Read from the token-linked identity provider. Depending
on the providers offerings, this may include additional user information, such as the user\\\\\\\'s current groups and roles.

account_circle

Get User Picture

Returns the profile picture for a user as binary image data. The Content-Type header indicates the image format (e.g., image/jpeg, image/png).

document_search

Query Audit Log

Returns a list of `Event` objects from the token-linked audit log.

groups

Query Groups

Returns a list of `Group` objects wrapped in the OCSF Entity Management event of type Read from the token-linked identity provider.

crisis_alert

Query Risk Events

Returns identity threat / risk events (for example Microsoft Entra Identity Protection risk detections for users), normalized to OCSF.

person_alert

Query Risky Users

Returns rolled-up risky user records (for example Microsoft Entra Identity Protection riskyUsers), each normalized to an OCSF Entity Management Read event.

group

Query Users

Returns a list of `User` objects wrapped in the OCSF Entity Management event of type Read from the token-linked identity provider.

  • Platform
  • Integrations
  • Resources
  • About
  • Blog