Capabilities
The connector syncs the people in your Drata workspace as user identities. Each
user carries their name, their login email, and whether they are still with the
organization — personnel Drata marks as a former employee or former contractor,
or whose separation date has already passed, sync as disabled. Someone with a
future separation date, such as a scheduled offboard, stays enabled until that
date arrives. Their employment status, start and separation dates, and linked
Drata user ID are included as attributes on the identity.
Roster entries that are not people sync as service accounts rather than
human identities: those Drata marks with the
SERVICE_ACCOUNT employment
status, and those it flags as non-human, which also carry Drata’s stated reason
as an attribute.
You can also sync personnel custom fields as attributes. Drata custom
fields are defined per workspace, so you choose which ones to bring across by
naming them on the connector; anything you do not name is ignored. Each one
lands on the identity as custom_<field name> — a field named Cost Center
becomes custom_cost_center.
Drata’s personnel API does not return a built-in job title or department. If
you track those as personnel custom fields in Drata, name them in Personnel
Custom Fields and they will sync as attributes.
This connector is identities-only: it lists people and surfaces their employment
metadata as attributes on their identity, but it does not sync entitlements or
grants and does not change anyone’s access.
Gather Drata credentials
1
Sign in to Drata as an administrator.
2
Open Settings, then API Keys.
3
Create a new API key and copy its value. You will enter it when configuring
the connector.
Configure the Drata connector
- Cloud-hosted
- Self-hosted
Follow these instructions to use a built-in, no-code connector hosted by C1.Done. Your Drata connector is now pulling access data into C1.
1
In C1, navigate to Apps > Connectors and click Add connector.
2
Search for Drata and click Add.
3
Choose where to add the connector: Create a new app, or Add to an existing app (then select the app).If you’re creating a new app, choose whether to link it to an application discovered from your identity provider: select Yes and pick the IdP application, or No to continue with just the connector.
4
Set the connector’s Name and, optionally, a Description.
5
Click the pencil icon next to Owners to choose who can configure and manage this connector.
6
Click Add. The connector is created and its configuration page opens.
7
Find the Settings area of the page and click Edit.
8
Enter the Drata credentials:
- Drata API Key: The API key you created in Drata.
9
Optionally, set Personnel Custom Fields to the Drata personnel
custom fields you want synced as identity attributes, separated by
commas — for example
Title, Cost Center. Names are matched
case-insensitively against the custom fields defined in Drata under
Settings > Personnel. Leave it blank to sync no custom fields.10
Click Save.
11
The connector’s label changes to Syncing, followed by Connected. You can view the logs to ensure that information is syncing.