Skip to content

Integrations & evidence setup

Start with the evidence you have. Agree exactly what connects.

Plan one company’s Valty evaluation around its existing security tools, business inputs and approval process. Use this checklist to define source coverage before granting access.

Setup worksheet

Four inputs to a useful evaluation.

Bring a sanitized example of each relevant input. Do not submit credentials, customer data or sensitive findings through the public demo form.

Findings and control exports

BringA scoped export with stable finding or control identifiers, asset references, severity or result, timestamps and owners.

Confirm togetherConfirm the accepted schema, import mapping and duplicate handling. An imported record retains its source date; import time is not evidence freshness.

Cloud and identity evidence

BringThe provider, tenant or account scope, exact control check and a least-privilege collection identity.

Confirm togetherConfirm supported APIs, required read permissions, refresh intervals and behavior when access expires. A listed provider does not imply every service is covered.

Work management

BringThe intended action, target project or queue, approved owner and the fields needed to route work.

Confirm togetherConfirm which workflow creates a proposal or ticket, which tool executes the action, and which source supplies verification. Read access and write authority are separate.

Financial and business inputs

BringLoss scenario, business interruption assumptions, current costs, budget, proposed investment costs and the decision objective.

Confirm togetherReview the input owner, units, time horizon and evidence gaps. Revenue and margin are business context; modeled loss does not adjust reported earnings.

Tools to bring into scope

Different tools contribute different evidence.

Review these source workflows in your demo. Confirm availability for your environment, exact permissions, collection coverage and verification before evaluation access.

AWS Security Hub

Read evidenceBring active cloud security findings, resource references and reported compliance states into the review.

Confirm the boundaryScope the AWS role, external ID, region and finding access. Collection does not change cloud settings; missing findings are not a passed control.

Microsoft Entra ID

Read evidenceReview MFA registration, conditional-access policies, privileged roles and application identity evidence.

Confirm the boundaryAgree tenant scope and approved Graph read permissions. Registration differs from enforced MFA; policy collection does not change access rules.

CrowdStrike Falcon

Read evidenceReview host inventory, detections and Spotlight vulnerability evidence from the enabled collection scope.

Confirm the boundaryCheck API read access, region and licensed data. Reported endpoint state does not prove prevention effectiveness or authorize host isolation.

Jira

Read evidence · route workReview selected issues and projects. A separately authorized workflow can create a remediation issue linked to a Valty finding.

Confirm the boundaryApprove the target project and issue-create permission. Ticket closure returns the work for verification; it does not prove the control changed.

ServiceNow

Read evidence · route workReview CMDB, incident and change evidence. A separately authorized workflow can create an incident for remediation ownership.

Confirm the boundaryAgree instance, table access and assignment scope. Incident creation needs write access; a closed incident still needs appropriate control verification.

Agree refresh requirements and check the latest successful evidence collection. A connected source, a created ticket and a verified control are separate states; each needs its own evidence.

Permission & coverage

Make the connection contract explicit.

Agree which company and assets are included, the source owner, collection identity, fields collected, refresh cadence, retention and removal process. Start with the minimum evidence needed for the decision.

Record unsupported sources and manual steps alongside connected sources. If credentials expire or collection fails, investigate the evidence gap before relying on a current-state claim.

  1. Scope

    Name the system, environment, owner and evidence needed.

  2. Demonstrate

    Review a supported collection or import with a safe sample and the required permissions.

  3. Agree

    Document coverage, onboarding, security review, commercial terms and the next evidence review before evaluation access.

Availability

Evaluate a supported workflow, not a logo wall.

Valty’s public capability pages describe scoped design-partner and integration workflows. This setup guide is not a promise of universal connector availability or instant onboarding. The evaluation identifies what is supported in your environment.

Evaluate the workflow

Bring one control gap and one decision.

See the supported workflow with illustrative data in a 30-minute platform demo. Agree evidence sources, permissions, actions, verification and commercial scope before evaluation access.

Request a platform demo