Skip to content

Integration Catalogue

Where to find it: Integrations, then Integration Catalogue (/integrations/catalogue).

The Integration Catalogue is the authoritative, named directory that answers the question: "Does OrviQ integrate with X, and how?"

It provides a transparent, read-only disclosure of exactly 22 catalogued integrations:

  • 20 available (backed by active native adapters, collectors, or file parsers in the build)
  • 2 planned (splunk and microsoft_sentinel — catalogue-only in current release, method: push)

Requires the integrations_catalogue entitlement and integration.read permission.


Read-Only Catalogue Behavior

The Integration Catalogue is designed as an honest disclosure interface:

  • Statuses cannot be inflated: Availability is computed dynamically at runtime from the adapter modules compiled into the application build. If an adapter module is missing or marked planned, the platform refuses to display it as operational, regardless of tenant configuration.
  • Read-only disclosure: The catalogue displays integration methods, telemetry types, supported formats, and active connection counts across your tenant without requiring credentials to be entered in the catalogue itself.
  • Direct navigation to connection workflows: Each entry links to its operational configuration area:
    • Vulnerability scanners and ITSM tools link to Security Tool Integrations (/integrations/security-tools?tab=connections).
    • Cloud platforms and identity providers link to Cloud & Identity Discovery (/integrations/discovery?tab=connections).
    • Webhooks and programmatic access link to Administration Settings (/settings/integrations).

Complete Integration Inventory

The catalogue covers 22 named integrations across seven functional categories:

Vendor KeyVendor LabelCategoryIntegration MethodStatusInbound / Outbound Mechanism
entra_idMicrosoft Entra IDIdentity & accessNative connectorAvailableMicrosoft Graph API (users, MFA registration, privileged roles, apps)
active_directoryActive Directory (on-premises)Identity & accessWebhook / push evidenceAvailableCustomer-hosted PowerShell collector pushing over HTTPS; or manual JSON file import
oktaOktaIdentity & accessNative connectorAvailableOkta Management API (users, groups, admin roles, MFA factors)
azureMicrosoft AzureCloud & infrastructureNative connectorAvailableAzure Resource Graph inventory across subscriptions
microsoft_365Microsoft 365Cloud & infrastructureNative connectorAvailableMicrosoft Secure Score controls converted to configuration evidence
awsAmazon Web ServicesCloud & infrastructureNative connectorAvailableResource Explorer inventory; AWS Config for configuration state
gcpGoogle CloudCloud & infrastructureNative connectorAvailableCloud Asset Inventory searchAllResources across org, folders, or projects
vmwareVMware vSphereCloud & infrastructureNative connectorAvailablevCenter REST API inventory (ESXi hosts, virtual machines, datastores)
tenable_scTenable Security CenterVulnerability managementNative connectorAvailableDocumented REST API (x-apikey); plus governed .nessus and CSV file import
nessusTenable NessusVulnerability managementNative connectorAvailableGoverned .nessus file import; REST API export pull where network reachable
tenable_ioTenable Vulnerability ManagementVulnerability managementNative connectorAvailableCloud Vulnerability Export API
qualysQualys VMDRVulnerability managementNative connectorAvailableHost List Detection API; plus governed XML and CSV report import
rapid7Rapid7 InsightVM / NexposeVulnerability managementNative connectorAvailableSecurity Console API v3 (assets and vulnerabilities); plus CSV report import
microsoft_defenderMicrosoft DefenderVulnerability managementNative connectorAvailableDefender for Endpoint API (devices and machine vulnerabilities)
crowdstrikeCrowdStrike Falcon SpotlightVulnerability managementNative connectorAvailableFalcon Spotlight combined vulnerabilities API grouped per sensor host
nipperTitania NipperConfiguration & benchmarksNative connectorAvailableGoverned report import (Nipper Studio XML/CSV/JSON); REST pull for Nipper Enterprise
prowlerProwlerConfiguration & benchmarksCSV / file importAvailableOCSF / CSV report import — cloud security checks mapped to evidence and findings
splunkSplunkSIEMWebhook / push evidencePlannedCatalogue-only in current release (status: planned, method: push)
microsoft_sentinelMicrosoft SentinelSIEMWebhook / push evidencePlannedCatalogue-only in current release (status: planned, method: push)
servicenowServiceNowITSM / ticketingNative connectorAvailableTable API ticket write-back (incidents / vulnerable items) from findings; signed webhooks
jiraJiraITSM / ticketingNative connectorAvailableJira Cloud REST / Data Center API issue write-back from findings; signed webhooks
githubGitHub / GitLabDevOpsNative connectorAvailableRepositories as application assets; branch protection, secret alerts as config evidence

Planned integrations are catalogue-only and not operational

Splunk and Microsoft Sentinel are catalogued with status Planned and method push. In the current release, they are catalogue-only entries without operational adapters and must not be documented, configured, or treated as operational.


Semantic Doctrine

Semantic Doctrine: Integrations & Compliance

Enterprise compliance in OrviQ enforces clear distinctions between technical integration and regulatory status:

  • Integration connection != compliance: Establishing a connection to an external tool demonstrates telemetry flow; it does not satisfy a compliance obligation or certify adherence to any framework.
  • Scanner finding != confirmed control failure: Ingested vulnerabilities or configuration deviations are technical observations. They require triage, contextual risk evaluation, and human review before becoming governed findings or control deficiencies.
  • Evidence != effectiveness: Automated evidence collection (via collectors, push API, or scanner sync) yields point-in-time observation records. Operating effectiveness is established only through indicator rules, threshold validation, and formal assessment by control owners and auditors.

Permissions & Access

ActionPermission KeyRequired EntitlementHuman Session Required?
Browse Integration Catalogueintegration.readintegrations_catalogueNo
Configure operational scanner connectionsintegration.manageintegrations_security_toolsYes
Configure cloud/identity discoverydiscovery.managecloud_discoveryYes

OrviQ Enterprise Governance, Risk & Compliance Platform