Skip to content

Changelog

Claude Console integration

Oblique’s Claude Console integration syncs members and their access in your Claude Console organization and its workspaces to Oblique. This includes each member’s organization and workspace roles.

Oblique’s Claude Console integration is currently read-only.

To connect a Claude Console organization, create an admin API key in Claude Console, then navigate to the Integrations page, select Add integration, and select Claude Console.

Cloudflare integration

Oblique’s Cloudflare integration syncs members and their access to the resource groups and user groups in your Cloudflare account to Oblique. When connected as a read-write integration, Oblique can also manage that access by updating user group membership and policies.

To connect a Cloudflare account, navigate to the Integrations page, select Add integration, and select Cloudflare.

Notion integration

Oblique’s Notion integration syncs members and their access in your Notion workspace to Oblique.

Oblique’s Notion integration is currently read-only.

To connect a Notion workspace, navigate to the Integrations page, select Add integration, and select Notion.

Linear integration

Oblique’s Linear integration syncs members and their access in your Linear workspace and its teams to Oblique.

Oblique’s Linear integration is currently read-only.

To connect a Linear workspace, navigate to the Integrations page, select Add integration, and select Linear.

PostHog integration

Oblique’s PostHog integration syncs members and their access in your PostHog organization and its projects to Oblique.

Oblique’s PostHog integration is currently read-only.

To connect a PostHog organization, navigate to the Integrations page, select Add integration, and select PostHog.

BambooHR integration

Oblique’s BambooHR integration lets you use your HR data in BambooHR as the source of truth for users and user attributes. Sync information about your employees to Oblique, including information on their role and manager to populate their user profile, and their attributes to use in attribute-based groups.

Oblique also imports the accounts that have access to your BambooHR instance, so you can read who has access to BambooHR, as with other integrations you have set up with Oblique. Oblique’s BambooHR integration is read-only.

User access reviews

Use Oblique to conduct user access reviews, to regularly review who has access to what in your environment based on your compliance obligations. For each review, capture accounts from integrations like your identity providers, directly from an app, or manually via a screenshot or pasting in accounts. Then, make a decision to approve, remove, or change access, and complete any remediation needed based on those decisions.

Oblique lets you define the scope of your review, and keeps track of the accounts, the decisions you made for each, and any remediation items needed. Oblique also generates a PDF report you can share with your auditor of your completed review.

Start a review from the Reviews tab.

GitHub integration

Oblique’s GitHub integration lets you understand the access your users have in GitHub, by syncing your GitHub organization’s members, teams, and team membership to Oblique. The integration is currently at the organization-level and read-only.

When you connect an integration like GitHub or Slack, Oblique imports the accounts in it and matches each one to a user by email address. Imported entitlements are attached to those accounts, so Oblique can tell you which users have access to which resources using those accounts.

Terraform provider

Oblique’s Terraform provider oblique-security/oblique lets you objects in Oblique via Terraform and as code workflows, including integrations, listings, groups, and admins. Once objects are managed by Terraform, they can no longer be modified from the Oblique app, and when you run terraform plan, Terraform will generate a preview of changes in Oblique for your review.

You can copy the Terraform config for objects individually, or for all objects by going to Manage, the to the Terraform page. Once you terraform apply this configuration, the Oblique app will show that they are managed by Terraform and cannot be modified.

MCP server

Oblique’s remote MCP server lets you connect to Oblique from the MCP client of your choice. The server is authorized as your user, so both admins and end users can use it to take actions like reading current group membership, making access requests, or configuring policies.

The MCP server supports two scopes: standard, for reading all information available to you and making requests; and privileged, for reading and writing changes directly.

To connect a client, click on your profile picture in the upper right corner, select Account settings, then navigate to the MCP page.

Recommendations

Recommendations are suggestions from Oblique to simplify entitlements without changing access.

Oblique suggests changes to deduplicate redundant access, where a user has access both directly and indirectly, and to consolidate access, to migrate direct access common to multiple users to a group they all belong to. Recommendations only suggest changes that won’t alter the resulting access in any way.

You can find recommendations for your tenant in the Recommendations tab under Manage. Create a request from a recommendation to apply it.

Approve requests in Slack

With the Oblique Slack app, reviewers can receive request notifications and approve them without leaving Slack.

Approving from Slack is disabled by default. An admin can enable approvals from Slack from the Slack integration details, selecting the Settings tab, and under Slack settings by toggling on Approvals from Slack.

From a message in Slack, a reviewer can select Approve or Close to respond to the request.

Auto-approval policies

Auto-approval policies allow members of a group to claim access to a listing role without requiring a human approval. An auto-approval policy also specifies a duration for the access, and whether or not a justification is required when claiming access.

Admins can add auto-approval policies to a listing from the listing detail page, by selecting Manage listing, and then under Auto-approved groups, selecting Add auto-approved group.

Reporting groups

Reporting groups define users who have the same manager, or are part of the same organization. These can then be granted access to resources or role assignments in Oblique.

There are two types of reporting groups: a user’s direct reports only, and a user’s organization, including their direct and indirect reports. The manager themselves is not included in the reporting group.

You can create a reporting group from the Groups tab, by selecting Add group, then Reporting group.

Slack DMs for request notifications

The Oblique Slack app sends request notifications to individuals who are requestors or reviewers as direct messages. Reviewers are notified when they need to approve a request, and requestors are notified when the status of their request changes. Users can disable DMs in their notification settings.

The Oblique Slack app still sends notifications about all requests to a public Slack channel.

Listings

Listings are groups of related resources, typically used to present multiple access levels for the same application. These listings are presented to users in the access catalog, where they can request access. Resources are no longer visible to end users. Instead, listings are the primary way that users see, understand, and request access in Oblique.

Each listing has one or many roles, which represent a set of permissions. This often maps to an application role, like Admin or Editor.

Instead of requesting access to resources, users request access to roles in listings. When a user is assigned a role, they are automatically granted access to all resources mapped to that role.

Timeline of access changes

View a timeline of access changes affecting a user, group, or resource on the user profile or attribute-based group, team group, or resource’s detail page.

Each item is an event that affected access, by adding or removing an entitlement. Access changes only include granted or revoked access, and do not include changes that edit entitlements, such as extending an entitlement.

Slack app

The Oblique Slack app lets Oblique notify users about pending requests directly in Slack.

The Slack app sends notifications for all requests made in Oblique to a public channel. Requestors and reviewers are automatically tagged, with updates threaded and status changes reflected in real-time.

Requests

Creating an entitlement now uses the request workflow. Users can request access for themselves, another user, or an attribute-based group or team to any resource. The request can be approved by the resource owner or an Oblique Admin.

Google Workspace integration

Connect Oblique with Google Workspace to pull users from Google and manage Google Groups. Pull and push membership of Google groups from within Oblique.

Preview access changes

Preview the impact of an access change as part of adding entitlements or changing team membership:

  • Which users and resources are affected, and which users remain unaffected
  • Which users gain or lose access per resource

Dark mode

Oblique is available in Light, Dark, and System modes. By default, Oblique respects System settings.