Skip to content

Supported integrations

Integrations connect Oblique with external systems in your organization. Oblique can both read information from and write access decisions back to integrations.

Oblique syncs access from the following integrations. In read-write integrations, Oblique can also manage access.

IntegrationResourcesRolesEntitlementsMode
BambooHRYESNOYESRead-only
Claude ConsoleYESYESYESRead-only
CloudflareYESYESYESRead-write
GitHubYESYESYESRead-write
GoogleYESYESYESRead-write
LinearYESYESYESRead-only
NotionYESNOYESRead-only
OktaYESNOYESRead-write
PostHogYESYESYESRead-only

Oblique supports signing in with the following identity providers:

Oblique can send notifications with the following integrations:

Attributes help match users from different systems, identify users on their profiles, and create attribute-based groups.

Attributes cannot be edited in Oblique. To update an attribute, update it in the integration it is from.

Oblique syncs users and user attributes from the following integrations. Each integration’s page lists the attributes it syncs.

Oblique also syncs custom profile attributes from Okta with the data type string.

Oblique uses the following user attributes and integrations to identify users:

AttributeRequiredIntegrationIntegration attribute
First nameYESGoogledisplayName or fullName
OktafirstName
BambooHRdisplayName or firstName
Last nameYESGoogledisplayName or fullName
OktalastName
BambooHRdisplayName or lastName
EmailYESGoogleprimaryEmail
Oktaemail
BambooHRworkEmail
Secondary emailNOOktasecondEmail
UUIDYESOktaid
BambooHRemployeeId

Other than UUID, identifying attributes can’t be used for attribute-based groups.

Oblique uses email addresses and user IDs to match users imported from different systems. When a match is found with new email addresses, those emails are added as secondary emails to the existing user profile. If a user ID matches but emails differ, Oblique treats them as the same user and adds the new emails. If neither emails nor ID match any existing user, Oblique creates a new user profile.

A user’s name and primary email come from whichever first creates the user: an integration, or the user’s first sign-in to Oblique. Integrations that later match the user don’t change them, but add any new emails as secondary emails.

User profiles show information about all user attributes. Certain attributes are used are displayed as part of the user profile, including name, email, manager, and title.

Oblique supports the following core attributes and integrations:

Core attributeIntegrationIntegration attribute
TitleGoogletitle
Oktatitle
BambooHRjobTitleName
ManagerGooglemanagerEmail
OktamanagerId or manager
BambooHRreportsToId
Profile photoGooglethumbnailPhotoUrl

By default, Oblique uses the first integration you connect that provides each core attribute. The integration for a core attribute, except profile photo, can be changed.

Oblique syncs both the managerId and manager user attributes from Okta. If the managerId is an Okta userId, it will be used as the core attribute for manager. Otherwise, if the manager attribute is an email, it is used instead.

User profiles include a profile photo. Oblique will use the profile photo from the identity provider from which the user authenticated to Oblique, or an integration that provides a profile photo. It cannot be changed in Oblique, and must be edited in the identity provider.

By default, Oblique uses the identity provider or the first integration you connect that provides a profile photo.

User attributes on profile pages are only visible to the user themselves and to Oblique admins. Other users, including managers, cannot see them.

Attributes can be used to create attribute-based groups. This helps create groups of users that share a common attribute, such as all users in the same department.

Accounts correspond to subjects in integrations. These are matched to users in Oblique, so that the entitlements attached to that account count as access held by that user.

Accounts cannot be edited in Oblique. To update an account, update it in the integration it is from.

Oblique uses email address to uniquely match accounts imported from integrations to users in Oblique. Matching is sticky, so that if the account’s email later changes, the account remains matched to the user.

A user can have more than one account matched to them in an integration, for example someone who is in the organization with both a work and a personal account. Since synced entitlements are account-level, a user can also have multiple entitlements for the same team through different accounts.

Oblique syncs user and group membership changes within minutes. Other changes may sync less frequently due to external API rate limits. For example, in a large Okta instance, external changes to apps assignments may take hours to reflect in Oblique.

An integration could have different information about a resource than what Oblique shows, for example, if syncing gets delayed, or syncing encounters an issue. The status reflects this difference: Synced, Pending, Error, or Paused.

Resources also have a status. Resources are Synced if they’re up to date with the integration, and Pending if they have changes that haven’t yet been synced.

An integration or resource must be syncing to have a sync state. If an integration is Disconnected, or a resource is Paused, then it has no sync state.

  • Synced: the integration is up to date with Oblique in both directions. An integration is Synced if all of its resources are Synced.
  • Pending: changes made in Oblique haven’t yet synced to the integration. An integration is Pending if any of its resources are Pending.
  • Error: the integration can’t sync, because of an error, rate limit, or other issue.
  • Paused: the integration temporarily isn’t syncing in either direction.

To permanently stop syncing and remove the integration from Oblique, you can remove it.