Skip to main content

Capabilities

Team membership can be granted and revoked. Grafana RBAC roles that a team holds (IRM and OnCall plugin roles such as Schedules Editor) are synced as read-only assignments and require Grafana Cloud or Enterprise. Service accounts are synced with their organization role; they are read-only. This connector syncs non-human identities and displays them on the Identities overview dashboard.
Roles are optionalIRM / OnCall RBAC roles are available only on Grafana Cloud and Enterprise. Role sync is disabled by default — enable the Role resource type in the connector’s settings in C1 when your instance has access-control.
The Grafana connector supports both self-hosted Grafana instances and Grafana Cloud. The required credentials and provisioning behavior differ between the two — see Gather Grafana credentials below. The Grafana connector supports automatic account provisioning and deprovisioning. For self-hosted Grafana, when a new account is created by C1, the account’s password is sent to a vault. For Grafana Cloud, account creation is invite-based and no connector-generated password is returned.
Grafana Cloud: enabling the basic login form is a prerequisite for creating brand-new usersGrafana Cloud instances ship with the basic login form disabled by default (users authenticate through grafana.com / SSO). While it is disabled, Grafana rejects instance-level invites for users who do not yet exist in the instance, and account creation fails with:
With the service-account token the connector uses, this means:
  • Users who already exist in the instance (provisioned earlier via SSO, SCIM, or grafana.com) are added to the organization normally — account provisioning works for them without any change.
  • Brand-new users cannot be created until you either:
    • enable SCIM provisioning (Grafana’s recommended path for automatic user lifecycle in Cloud), so users are provisioned by your identity provider before C1 assigns organization roles; or
    • enable the basic login form on the instance (set disable_login_form = false), which permits instance-level invites for external users.
Managing membership directly through the grafana.com portal is a separate API and credential (a Grafana Cloud Access Policy token) that the connector’s instance service-account token cannot use.
Grafana Cloud: provisioning organization roles for externally synced usersIn Grafana Cloud, users who sign in through an external identity provider (such as Grafana.com SSO, Okta, Azure AD, or any OAuth/SAML provider) have their organization roles controlled by that provider. By default, Grafana blocks API-level role changes for these users, which prevents C1 from provisioning organization entitlements for them.To allow C1 to manage organization roles for these users, enable Skip org role sync for the relevant SSO provider in your Grafana instance:
  1. In Grafana, go to Administration → Authentication.
  2. Select the SSO provider your users log in with.
  3. Enable Skip org role sync (equivalent to setting skip_org_role_sync = true).
Once this is enabled, Grafana stops overriding org roles on login and C1 becomes the authoritative source for role assignments. This is a global setting that applies to all users under that provider.This step is not required for self-hosted Grafana instances using basic (username/password) authentication.

Account access origin

Starting with connector version 0.2.3, each synced account’s profile includes attributes that identify how the user’s access originated. They appear in the account’s Profile attributes in C1 and support access reviews where the origin of access matters: is_externally_synced surfaces Grafana’s native isExternallySynced flag verbatim and only when Grafana actually returns it. Whether the flag is returned depends on the endpoint the connector reads, which differs by mode:
  • Grafana Cloud reads the organization users endpoint (/api/org/users), which always returns the flag, so is_externally_synced is present and mirrors Grafana’s value exactly. It reflects only whether the user’s organization role is managed by an external identity provider (role sync) — it is not derived from auth_labels, which is a different concept (how the user authenticated). In Grafana Cloud every user authenticates through grafana.com, so auth_labels is effectively always grafana.com; an admin whose role is managed locally therefore reports is_externally_synced: false even though their auth_labels show grafana.com.
  • Self-hosted Grafana reads the global users endpoint (/api/users), which does not return the flag. Rather than derive a value from a different concept, the connector omits is_externally_synced from the profile entirely. Use auth_labels to reason about authentication provenance in this mode.

Gather Grafana credentials

Configuring the connector requires credentials obtained in your Grafana instance. The credentials you need depend on whether you are connecting to Grafana Cloud or a self-hosted Grafana instance.
For Grafana Cloud, the connector authenticates using a service account token. Basic username/password authentication is not supported in Cloud mode.To create a service account token:
  1. In your Grafana Cloud instance, go to Administration → Users and access → Service accounts.
  2. Click Add service account, give it a name, and assign it the Admin role.
  3. Make sure the service account’s basic role is set to at least Viewer — not No basic role. See the callout below; this must be done in the Grafana UI.
  4. Open the new service account and click Add service account token.
  5. Copy and save the generated token — it will not be shown again.
A basic role is required, and no RBAC action substitutes for itThe connector calls GET /api/org both for the initial credential validation and, in Cloud mode, on every sync as the Organization resource-sync source — so this is not a one-time check, it’s needed for every sync. That endpoint is gated by a Grafana basic role, not by an RBAC action: a service account set to No basic role returns 403 there even when every RBAC action below is granted, and assigning orgs:read does not satisfy it. Setting the basic role to Viewer does.Set this in the Grafana UI (Administration → Users and access → Service accounts → your service account → Basic role). It cannot currently be set through the API — PATCH /api/serviceaccounts/{id} with {"role":"Viewer"} returns HTTP 500 on Grafana Cloud.
Use an Admin service-account role, or a credential with equivalent permissions. The connector requires six RBAC actions:These six actions cover sync only. When provisioning is enabled (BATON_PROVISIONING), granting and revoking access calls separate write endpoints that need additional RBAC actions. The actions you need depend on which provisioning capability is enabled — account provisioning (creating brand-new users) and entitlement provisioning (granting/revoking org roles and team membership) call different endpoints and do not require the same permissions.Account provisioning (CreateAccount, Delete):Entitlement provisioning (Grant/Revoke on the Organizations and Teams resource types):org.users:add is reached only by CreateAccount’s invite path. A customer who enables entitlement provisioning without account provisioning does not need it: in Cloud mode, Grant only ever updates the role of a user who is already an org member (via PATCH /api/org/users/{id}), or fails outright if the user isn’t already a member — it never calls the invite endpoint.org.users:remove, by contrast, is needed independently by both capabilities: account provisioning’s Delete and entitlement provisioning’s Revoke both call the same DELETE /api/org/users/{id} endpoint. A customer who enables only one of the two capabilities still needs this permission for that capability alone.Team sync always reads team membership, so teams.permissions:read is required unconditionally. teams.roles:read is only needed when Role sync is enabled — the connector only fetches each team’s RBAC roles in that case — same as roles:read. A narrower token that previously synced only users/orgs may still fail List after this upgrade, since teams:read and teams.permissions:read are newly required for team sync regardless of Role sync.
With Role sync enabled, roles:read and teams.roles:read come as a packageNo built-in Grafana role grants one of these actions without the other: fixed:roles:reader and fixed:roles:writer each grant both together, and the basic roles that grant roles:read (basic:admin and basic:grafana_admin) also grant teams.roles:read. basic:viewer and basic:editor grant neither. This is expected — when Role sync is disabled, the connector needs neither action, so there is nothing to isolate; when Role sync is enabled, plan on granting both together (or use a custom role if you need to diverge from Grafana’s built-in roles for some other reason).
You will need:
  • Your Grafana Cloud instance URL (e.g., https://your-org.grafana.net)
  • The service account token generated above
Done. Next, move on to the connector configuration instructions.

Configure the Grafana connector

To complete this task, you’ll need:
  • The Connector Administrator or Super Administrator role in C1
  • Access to the set of Grafana credentials gathered by following the instructions above
Follow these instructions to use a built-in, no-code connector hosted by C1.
1
In C1, navigate to Apps > Connectors and click Add connector.
2
Search for Grafana and click Add.
3
Choose where to add the connector: Create a new app, or Add to an existing app (then select the app).If you’re creating a new app, choose whether to link it to an application discovered from your identity provider: select Yes and pick the IdP application, or No to continue with just the connector.
4
Set the connector’s Name and, optionally, a Description.
5
Click the pencil icon next to Owners to choose who can configure and manage this connector.
6
Click Add. The connector is created and its configuration page opens.
7
Find the Settings area of the page and click Edit.
8
Paste your Grafana instance URL into the Instance URL field.
9
Enter your credentials based on your Grafana deployment type:
  • Grafana Cloud: Select “API Key” as the auth method and paste your service account token into the API Token field.
  • Self-hosted Grafana: Select “Basic Authentication” as the auth method and paste the admin account’s username and password into the Username and Password fields.
10
Click Save.
11
The connector’s label changes to Syncing, followed by Connected. You can view the logs to ensure that information is syncing.
Done. Your Grafana connector is now pulling access data into C1.