For mid-market
At 300 people, integrations stop being nice-to-have.
Your IdP, your SIEM, your MDM, your ITSM — they're already chosen, deployed, and load-bearing. A credential platform that doesn't slot into that stack isn't a platform; it's a project. Clavitor ships the integrations a 100-to-500-user org actually has.
Identity — full Microsoft Entra ID support
Most mid-market orgs run on Microsoft 365 + Entra ID (formerly Azure AD). Clavitor doesn't stop at "we support SAML." The Entra ID surface Clavitor uses end-to-end:
Enterprise SSO from the app gallery
Configure Clavitor as an Entra Enterprise Application via SAML 2.0 or OpenID Connect. Assign users or groups directly in Entra. No app proxy, no on-prem connector — your tenant already has everything required.
Group claims → vault scopes
The same Entra security groups that gate your Microsoft 365 apps gate Clavitor vault scopes. Move a user into the "Engineering" group and their vault access updates on next sign-in. No parallel directory.
Conditional Access compatible
Clavitor's SSO honors MFA assertions, device-state claims, and risk signals from your Entra Conditional Access policies. A user denied by your access rule is denied at Clavitor too — your existing access logic stays the single source of truth.
Microsoft Authenticator + FIDO2 at the IdP layer
The same hardware key or Authenticator push your users already have for Microsoft accounts gates Clavitor sign-in. No separate enrollment, no "Clavitor MFA token" to roll out.
Other supported IdPs: Google Workspace, Okta, JumpCloud, OneLogin, and any standard SAML 2.0 or OIDC provider.
Audit logs into the SIEM you've standardized on
Every credential access, admin action, webhook receipt, and lockout decision is audit-logged with a stable JSON schema and stable error codes. Events are available via an authenticated pull endpoint as JSON or NDJSON; your SIEM ingests them the same way it ingests anything else.
Microsoft Sentinel
Natural fit alongside Entra ID. Pull via Azure Monitor or a custom Data Connector. The event includes the Entra principal alongside the agent ID, so KQL detection rules join cleanly against your existing user signals.
Splunk
HTTP Event Collector (HEC) intake or universal forwarder against an exported log file. Field names are stable across releases so dashboards and saved searches survive Clavitor upgrades.
Datadog
HTTP Logs API intake or the Datadog Agent's HTTP source. Fields map cleanly to Datadog facets — env, service, team, user — so events show up in the same service-ownership views as the rest of your stack.
Elastic / OpenSearch
Filebeat module or direct ingest pipeline. Kibana and OpenSearch Dashboards work against the default field shape; ECS-compatible naming where it makes sense.
Sumo Logic, Graylog, Devo, Wazuh
Same JSON / NDJSON pull endpoint, same field shape. If your SIEM speaks HTTP, it speaks Clavitor audit.
Webhook out (SOAR, Slack, Teams)
HMAC-signed payloads for security-critical events (lockout, agent revoke, scope change). Wire into Slack, Microsoft Teams, PagerDuty, Tines, Torq, or your SOAR — same secret-rotation flow as any modern webhook integration.
The rest of the stack a mid-market org runs
MDM
Intune, Jamf, Kandji — push the Clavitor browser extension and CLI installer via your existing MDM profile. Hardware-key requirements are enforced at sign-in, not negotiated at install time.
ITSM / ticketing
Jira Service Management, ServiceNow, Freshservice — credential requests, scope changes, and recovery flows can post to your ticketing system via webhook for audit and approval workflows.
Multi-region by default
22 Points of Presence (POPs) across every continent. Your London team reads from gb1, San Francisco reads from use1, Singapore from sg1 — same vault, <60ms reads from any continent. Fail-over copy on the opposite side of the world is automatic.
Compliance documents on the public site
DPA and subprocessor list are linked publicly — no NDA gate, no redlining of standard terms. We do not hold a SOC 2 Type II attestation today; controls are self-assessed and aligned with that framework. Regulated buyers can run a private POP or virtual appliance inside their own perimeter.
Slots into the stack you already run.
Mid-Market plan, $6 per seat per month. SCIM from Entra ID / Okta / Google Workspace, SIEM pull endpoint, HMAC webhooks, group-based rotation, MDM-pushable clients, multi-region — included.