Skip to main content

Business Software

Business software integrations cover the SaaS applications the organization actually runs its work in — identity providers, collaboration suites, file sharing, conferencing, code hosting and CRM. These are audit-log sources rather than security products: they record who signed in and from where, what was opened or shared, and what an administrator changed. Because they are what an attacker reaches once credentials are stolen, their audit logs are among the highest-value feeds available, and almost all of them are collected by polling the vendor's audit or events API on a schedule.

In this section

  • Okta — Okta System Log: sign-ins, MFA outcomes, administrator actions and user lifecycle changes, polled with an SSWS API token.
  • Cisco Duo — Duo Admin API: authentication, administrator action and telephony logs for multi-factor access.
  • Google Workspace (OAuth) — the Workspace audit log from the Admin SDK Reports API, authorised by an administrator consenting to Fluency's OAuth client.
  • Google Workspace (Service Account) — the same audit log, reached through a service account in your own Google Cloud project with domain-wide delegation.
  • Zoom Video — meeting, account and user-management activity from the Zoom API.
  • Salesforce Event Monitoring — CRM login, API and data-export telemetry from the EventLogFile object.
  • Box.com — Box enterprise audit events, including Box Shield alerts, pulled from the Events API by a Client Credentials Grant application.
  • GitHub Audit — GitHub organization webhook events for an organization and every repository it owns, pushed to a Webhook URL the install issues.
  • Bitwarden — organization event logs and the member, group, policy and collection roster, from the Bitwarden Public API.
  • Black Kite — outside-in risk findings for the third parties you monitor, polled from the Black Kite API v2.
  • Workday — the Workday user activity log, polled from the Privacy API with a refresh-token credential issued to an integration system user.
  • Varonis SaaS API — DatAlert alerts and, optionally, the file-activity events behind them, polled from the Varonis SaaS API.

Choosing what to collect

Most of these products expose more than one log stream — sign-in versus administrative versus data-access activity. Which streams matter, and what they cost in volume, is worth deciding before the integration is enabled rather than after the first invoice.