Supported integrations
Integrations connect Oblique with external systems in your organization. Oblique can both read information from and write access decisions back to integrations.
Supported integrations
Section titled “Supported integrations”Access integrations
Section titled “Access integrations”Oblique syncs access from the following integrations. In read-write integrations, Oblique can also manage access.
| Integration | Resources | Roles | Entitlements | Mode |
|---|---|---|---|---|
| BambooHR | YES | NO | YES | Read-only |
| Claude Console | YES | YES | YES | Read-only |
| Cloudflare | YES | YES | YES | Read-write |
| GitHub | YES | YES | YES | Read-write |
| YES | YES | YES | Read-write | |
| Linear | YES | YES | YES | Read-only |
| Notion | YES | NO | YES | Read-only |
| Okta | YES | NO | YES | Read-write |
| PostHog | YES | YES | YES | Read-only |
User and attribute integrations
Section titled “User and attribute integrations”Single sign-on integrations
Section titled “Single sign-on integrations”Oblique supports signing in with the following identity providers:
Notification integrations
Section titled “Notification integrations”Oblique can send notifications with the following integrations:
Supported attributes
Section titled “Supported attributes”Attributes help match users from different systems, identify users on their profiles, and create attribute-based groups.
Attributes cannot be edited in Oblique. To update an attribute, update it in the integration it is from.
User and attribute integrations
Section titled “User and attribute integrations”Oblique syncs users and user attributes from the following integrations. Each integration’s page lists the attributes it syncs.
Oblique also syncs custom profile attributes from Okta with the data type string.
Identifying attributes
Section titled “Identifying attributes”Oblique uses the following user attributes and integrations to identify users:
| Attribute | Required | Integration | Integration attribute |
|---|---|---|---|
| First name | YES | displayName or fullName | |
| Okta | firstName | ||
| BambooHR | displayName or firstName | ||
| Last name | YES | displayName or fullName | |
| Okta | lastName | ||
| BambooHR | displayName or lastName | ||
| YES | primaryEmail | ||
| Okta | email | ||
| BambooHR | workEmail | ||
| Secondary email | NO | Okta | secondEmail |
| UUID | YES | Okta | id |
| BambooHR | employeeId |
Other than UUID, identifying attributes can’t be used for attribute-based groups.
Oblique uses email addresses and user IDs to match users imported from different systems. When a match is found with new email addresses, those emails are added as secondary emails to the existing user profile. If a user ID matches but emails differ, Oblique treats them as the same user and adds the new emails. If neither emails nor ID match any existing user, Oblique creates a new user profile.
A user’s name and primary email come from whichever first creates the user: an integration, or the user’s first sign-in to Oblique. Integrations that later match the user don’t change them, but add any new emails as secondary emails.
Core attributes
Section titled “Core attributes”User profiles show information about all user attributes. Certain attributes are used are displayed as part of the user profile, including name, email, manager, and title.
Oblique supports the following core attributes and integrations:
| Core attribute | Integration | Integration attribute |
|---|---|---|
| Title | title | |
| Okta | title | |
| BambooHR | jobTitleName | |
| Manager | managerEmail | |
| Okta | managerId or manager | |
| BambooHR | reportsToId | |
| Profile photo | thumbnailPhotoUrl |
By default, Oblique uses the first integration you connect that provides each core attribute. The integration for a core attribute, except profile photo, can be changed.
Manager
Section titled “Manager”Oblique syncs both the managerId and manager user attributes from Okta. If the managerId is an Okta userId, it will be used as the core attribute for manager. Otherwise, if the manager attribute is an email, it is used instead.
Profile photo
Section titled “Profile photo”User profiles include a profile photo. Oblique will use the profile photo from the identity provider from which the user authenticated to Oblique, or an integration that provides a profile photo. It cannot be changed in Oblique, and must be edited in the identity provider.
By default, Oblique uses the identity provider or the first integration you connect that provides a profile photo.
Using attributes
Section titled “Using attributes”Attribute visibility on user profiles
Section titled “Attribute visibility on user profiles”User attributes on profile pages are only visible to the user themselves and to Oblique admins. Other users, including managers, cannot see them.
Attribute-based groups
Section titled “Attribute-based groups”Attributes can be used to create attribute-based groups. This helps create groups of users that share a common attribute, such as all users in the same department.
Accounts
Section titled “Accounts”Accounts correspond to subjects in integrations. These are matched to users in Oblique, so that the entitlements attached to that account count as access held by that user.
Accounts cannot be edited in Oblique. To update an account, update it in the integration it is from.
Account matching
Section titled “Account matching”Oblique uses email address to uniquely match accounts imported from integrations to users in Oblique. Matching is sticky, so that if the account’s email later changes, the account remains matched to the user.
A user can have more than one account matched to them in an integration, for example someone who is in the organization with both a work and a personal account. Since synced entitlements are account-level, a user can also have multiple entitlements for the same team through different accounts.
Syncing
Section titled “Syncing”Oblique syncs user and group membership changes within minutes. Other changes may sync less frequently due to external API rate limits. For example, in a large Okta instance, external changes to apps assignments may take hours to reflect in Oblique.
An integration could have different information about a resource than what Oblique shows, for example, if syncing gets delayed, or syncing encounters an issue. The status reflects this difference: Synced, Pending, Error, or Paused.
Resources also have a status. Resources are Synced if they’re up to date with the integration, and Pending if they have changes that haven’t yet been synced.
An integration or resource must be syncing to have a sync state. If an integration is Disconnected, or a resource is Paused, then it has no sync state.
- Synced: the integration is up to date with Oblique in both directions. An integration is Synced if all of its resources are Synced.
- Pending: changes made in Oblique haven’t yet synced to the integration. An integration is Pending if any of its resources are Pending.
- Error: the integration can’t sync, because of an error, rate limit, or other issue.
- Paused: the integration temporarily isn’t syncing in either direction.
To permanently stop syncing and remove the integration from Oblique, you can remove it.