For mid-market

At 300 people, integrations stop being nice-to-have.

Your IdP, your SIEM, your MDM, your ITSM — they're already chosen, deployed, and load-bearing. A credential platform that doesn't slot into that stack isn't a platform; it's a project. Clavitor ships the integrations a 100-to-500-user org actually has.

Identity — full Microsoft Entra ID support

Most mid-market orgs run on Microsoft 365 + Entra ID (formerly Azure AD). Clavitor doesn't stop at "we support SAML." The Entra ID surface Clavitor uses end-to-end:

Enterprise SSO from the app gallery

Configure Clavitor as an Entra Enterprise Application via SAML 2.0 or OpenID Connect. Assign users or groups directly in Entra. No app proxy, no on-prem connector — your tenant already has everything required.

Group claims → vault scopes

The same Entra security groups that gate your Microsoft 365 apps gate Clavitor vault scopes. Move a user into the "Engineering" group and their vault access updates on next sign-in. No parallel directory.

Conditional Access compatible

Clavitor's SSO honors MFA assertions, device-state claims, and risk signals from your Entra Conditional Access policies. A user denied by your access rule is denied at Clavitor too — your existing access logic stays the single source of truth.

Microsoft Authenticator + FIDO2 at the IdP layer

The same hardware key or Authenticator push your users already have for Microsoft accounts gates Clavitor sign-in. No separate enrollment, no "Clavitor MFA token" to roll out.

Other supported IdPs: Google Workspace, Okta, JumpCloud, OneLogin, and any standard SAML 2.0 or OIDC provider.

Audit logs into the SIEM you've standardized on

Every credential access, admin action, webhook receipt, and lockout decision is audit-logged with a stable JSON schema and stable error codes. Events are available via an authenticated pull endpoint as JSON or NDJSON; your SIEM ingests them the same way it ingests anything else.

Microsoft Sentinel

Natural fit alongside Entra ID. Pull via Azure Monitor or a custom Data Connector. The event includes the Entra principal alongside the agent ID, so KQL detection rules join cleanly against your existing user signals.

Splunk

HTTP Event Collector (HEC) intake or universal forwarder against an exported log file. Field names are stable across releases so dashboards and saved searches survive Clavitor upgrades.

Datadog

HTTP Logs API intake or the Datadog Agent's HTTP source. Fields map cleanly to Datadog facets — env, service, team, user — so events show up in the same service-ownership views as the rest of your stack.

Elastic / OpenSearch

Filebeat module or direct ingest pipeline. Kibana and OpenSearch Dashboards work against the default field shape; ECS-compatible naming where it makes sense.

Sumo Logic, Graylog, Devo, Wazuh

Same JSON / NDJSON pull endpoint, same field shape. If your SIEM speaks HTTP, it speaks Clavitor audit.

Webhook out (SOAR, Slack, Teams)

HMAC-signed payloads for security-critical events (lockout, agent revoke, scope change). Wire into Slack, Microsoft Teams, PagerDuty, Tines, Torq, or your SOAR — same secret-rotation flow as any modern webhook integration.

The rest of the stack a mid-market org runs

MDM

Intune, Jamf, Kandji — push the Clavitor browser extension and CLI installer via your existing MDM profile. Hardware-key requirements are enforced at sign-in, not negotiated at install time.

ITSM / ticketing

Jira Service Management, ServiceNow, Freshservice — credential requests, scope changes, and recovery flows can post to your ticketing system via webhook for audit and approval workflows.

Multi-region by default

22 Points of Presence (POPs) across every continent. Your London team reads from gb1, San Francisco reads from use1, Singapore from sg1 — same vault, <60ms reads from any continent. Fail-over copy on the opposite side of the world is automatic.

Compliance documents on the public site

DPA and subprocessor list are linked publicly — no NDA gate, no redlining of standard terms. We do not hold a SOC 2 Type II attestation today; controls are self-assessed and aligned with that framework. Regulated buyers can run a private POP or virtual appliance inside their own perimeter.

Slots into the stack you already run.

Mid-Market plan, $6 per seat per month. SCIM from Entra ID / Okta / Google Workspace, SIEM pull endpoint, HMAC webhooks, group-based rotation, MDM-pushable clients, multi-region — included.