> ## Documentation Index
> Fetch the complete documentation index at: https://conductorone-luisinasantos-sync-coupa-v0-1-13-docs.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Set up a Drata connector

> C1 provides identity governance for Drata. Integrate your Drata workspace with C1 for unified visibility and governance over who is on your workforce roster and whether they are still active.

C1 provides identity governance for Drata. Integrate your Drata workspace with
C1 for unified visibility and governance over who is on your workforce roster
and whether they are still active.

## Capabilities

| Resource | Sync | Provision |
| - | - | - |
| Users | <Icon icon="square-check" iconType="solid" color="#c937ae" /> | |

The connector syncs the people in your Drata workspace as user identities. Each
user carries their name, their login email, and whether they are still with the
organization -- personnel Drata marks as a former employee or former contractor,
or whose separation date has already passed, sync as disabled. Someone with a
*future* separation date, such as a scheduled offboard, stays enabled until that
date arrives. Their employment status, start and separation dates, and linked
Drata user ID are included as attributes on the identity.

Roster entries that are not people sync as **service accounts** rather than
human identities: those Drata marks with the `SERVICE_ACCOUNT` employment
status, and those it flags as non-human, which also carry Drata's stated reason
as an attribute.

You can also sync **personnel custom fields** as attributes. Drata custom
fields are defined per workspace, so you choose which ones to bring across by
naming them on the connector; anything you do not name is ignored. Each one
lands on the identity as `custom_<field name>` -- a field named **Cost Center**
becomes `custom_cost_center`.

<Note>
  Drata's personnel API does not return a built-in job title or department. If
  you track those as personnel custom fields in Drata, name them in **Personnel
  Custom Fields** and they will sync as attributes.
</Note>

<Warning>
  Custom fields are matched by name. If a field is renamed in Drata, or the name
  is entered here with a typo, that attribute stops syncing until the connector's
  configuration is updated to match -- and a renamed field also changes the
  attribute key it lands on.
</Warning>

<Note>
  This connector is identities-only: it lists people and surfaces their employment
  metadata as attributes on their identity, but it does not sync entitlements or
  grants and does not change anyone's access.
</Note>

## Gather Drata credentials

<Warning>
  You need a Drata **API key**. The Drata public API is available on the
  **Advanced** plan and above. Treat the API key as a secret.
</Warning>

<Steps>
  <Step>
    Sign in to Drata as an administrator.
  </Step>

  <Step>
    Open **Settings**, then **API Keys**.
  </Step>

  <Step>
    Create a new API key and copy its value. You will enter it when configuring
    the connector.
  </Step>
</Steps>

## Configure the Drata connector

<Tabs>
  <Tab title="Cloud-hosted">
    Follow these instructions to use a built-in, no-code connector hosted by C1.

    <Steps>
      <Step>
        In C1, navigate to **Apps** > **Connectors** and click **Add connector**.
      </Step>

      <Step>
        Search for **Drata** and click **Add**.
      </Step>

      <Step>
        Choose where to add the connector: **Create a new app**, or **Add to an existing app** (then select the app).

        If you're creating a new app, choose whether to link it to an application discovered from your identity provider: select **Yes** and pick the IdP application, or **No** to continue with just the connector.
      </Step>

      <Step>
        Set the connector's **Name** and, optionally, a **Description**.
      </Step>

      <Step>
        Click the pencil icon next to **Owners** to choose who can configure and manage this connector.
      </Step>

      <Step>
        Click **Add**. The connector is created and its configuration page opens.
      </Step>

      <Step>
        Find the **Settings** area of the page and click **Edit**.
      </Step>

      <Step>
        Enter the Drata credentials:

        * **Drata API Key**: The API key you created in Drata.
      </Step>

      <Step>
        Optionally, set **Personnel Custom Fields** to the Drata personnel
        custom fields you want synced as identity attributes, separated by
        commas -- for example `Title, Cost Center`. Names are matched
        case-insensitively against the custom fields defined in Drata under
        **Settings** > **Personnel**. Leave it blank to sync no custom fields.
      </Step>

      <Step>
        Click **Save**.
      </Step>

      <Step>
        The connector's label changes to **Syncing**, followed by **Connected**. You can view the logs to ensure that information is syncing.
      </Step>
    </Steps>

    **Done.** Your Drata connector is now pulling access data into C1.
  </Tab>

  <Tab title="Self-hosted">
    Follow these instructions to run the Drata connector in your own
    environment.

    <Steps>
      <Step>
        Create a secret for the Drata API key.
      </Step>

      <Step>
        Configure the connector environment variables:

        * **BATON\_DRATA\_API\_KEY**: The Drata API key (store this as a secret).
        * **BATON\_DRATA\_CUSTOM\_FIELDS** (optional): Comma-separated Drata
          personnel custom field names to sync as identity attributes, for
          example `Title,Cost Center`.
      </Step>

      <Step>
        Deploy the connector using your standard self-hosted connector process.
      </Step>
    </Steps>

    **Done.** Your Drata connector is now pulling access data into C1.
  </Tab>
</Tabs>
