$ every product image on this site is an unretouched screenshot of the running platform — demo tenant, fictional people, captured live
🔌 Platform · Connect

Any system connected.
Before the coffee's cold.

Vendor templates for Entra ID, Google Workspace, Workday, SuccessFactors, Salesforce, ServiceNow, Box, AFAS, TOPdesk, Atlassian and GitHub — plus generic REST, SCIM 2.0, LDAP, SQL and SFTP-CSV engines for everything else. Guided, live-tested, and gated until you trust it.

The wizard

Configuration you confirm, not author.

Pick the system, drop in credentials, and the wizard auto-discovers the schema, pre-fills the mappings and tests every step against live records from your own system.

  • Live endpoint test at every gate — you never configure blind
  • Attribute selection decides, per field, what gets imported at all
  • Account types & ownership rules classify what you'll find
  • You choose where the secret lives: EU vault, your vault (BYOV), or on the agent
app.rapidvalue.eu/onboarding
the guided wizard — live test at every gate
the guided wizard — live test at every gate

Shareable templates

A working connector becomes a portable artifact.

Export any working connector as a secret-free, versioned template — import it into another tenant, or publish it to the community registry with provenance. This is how the connector long-tail solves itself: a new vendor template is days of work on the generic engines, not a roadmap quarter.

  • Secret-free by construction — credentials never travel with the template
  • Versioned, with provenance and trust-tiers in the registry
  • New vendor templates built alongside onboarding customers, at no extra cost
…/settings · connector templates
the template registry — secret-free, versioned connector templates with provenance
secret-free templates with provenance — export, import, install

Gated go-live

Provisioning from day one — writes gated until you release them.

Every new connector provisions from the start, but every write queues for your batch approval until you remove the gate, per system. You watch the platform make the right calls before you let it act.

  • Batch approval queue per system — see exactly what would change
  • Per-object visibility-only mode: observe before you govern
  • Blast-radius safety limits cap runaway writes at the threshold
…/safety-limits
blast-radius caps on writes, per system
blast-radius caps on writes, per system

Unstructured data

Your riskiest access isn't in an app — it's in a folder.

The scan family reads Google Drive, Box and on-prem SMB/NTFS file shares and turns folders into governed objects: sensitivity classification, who-can-access per folder, and risk flags for the shares nobody owns, the ones shared outside the organisation, and the ones living entirely outside IGA scope.

  • Folder inventory with sensitivity + risk flags: external · over-shared · no owner · outside IGA
  • Who-can-access resolved to people — external collaborators marked per person
  • Assign an owner or bring a share into scope, one click each
…/unstructured
folder inventory with sensitivity, risk flags and who-can-access
file shares as governed objects — flags on the ones nobody owns

Related

See a system connected on your own data.

A 30-minute kickoff connects your HR feed and one system — working POC the same day.