> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Sources Management

> Manage Iru Compliance evidence sources: connector setup, authentication, troubleshooting, and enabling or removing integrations under Compliance Sources.

**Sources** connect Iru Compliance to systems you already use, such as identity, code hosts, monitoring, HR, cloud, and more. After a source is **Active**, Iru can **discover and attach artifacts** to the actions and controls they support, which keeps evidence tied to your frameworks and reduces manual uploads. Connecting or disconnecting a source is recorded on the [Unified Activity](/en/iru/platform-overview/unified-activity).

To see how Compliance fits with Endpoint and Identity, read [Iru Overview](/en/iru/platform-overview/iru-overview).

On the left navigation bar, expand **Compliance** and select **Sources**. Turn on the **toggle** on a source’s card, then complete authentication in the wizard (OAuth, API keys, bearer tokens, or vendor-specific steps). When an action names a system and evidence type, automation can use that mapping to decide what to collect.

<Info>
  Need help with a step? [Contact Iru Support](/en/iru/iru-support/access-to-iru-support).
</Info>

## Sources Page

Once you are on **Sources** (same sidebar path as above), **Refresh all evidence** is at the **top right**. Use it to refresh evidence from your connected sources.

Use **Search by name or description** and the **Category** dropdown to narrow the list. **Amazon Web Services** connectors appear under **Amazon sources** inside each relevant category (**Security**, **Developer tools**, **Databases**, **Monitoring**, or **Storage**). Each **Amazon sources** row scrolls horizontally. Use the **arrow** controls to see every card.

## How It Works

Each connector article covers **authentication**, **in-product steps** (including the Iru connector wizard where applicable), **troubleshooting**, and **vendor documentation** links. Read the article for your system before you turn the source **on** in **Sources**.

## Connector Articles

The sidebar **Compliance → Sources** tree follows the same **Category** labels as Iru (**Analytics**, **Communications**, **CRM**, **Databases**, **Developer tools**, **HRIS**, **Monitoring**, **Productivity**, **Project management**, **Security**, **Storage**, **Support**), with **Amazon sources** nested where the product groups AWS connectors.

Browse sources by theme below (accordion sections mirror connector families such as **Amazon Web Services** for documentation). Expand a section to see **Integration** links to full guides and **What it covers** summaries. In Iru, expand **Compliance**, open **Sources**, and use each card’s **toggle**; your tenant controls which connectors are listed.

<AccordionGroup>
  <Accordion title="Analytics" icon="chart-line">
    | Integration                                        | What it covers                                                             |
    | -------------------------------------------------- | -------------------------------------------------------------------------- |
    | [Fivetran](/en/compliance/sources/fivetran-source) | Connectors and pipeline metadata for data-movement governance.             |
    | [Segment](/en/compliance/sources/segment-source)   | Sources, destinations, and workspace settings for customer-data pipelines. |
  </Accordion>

  <Accordion title="Communications" icon="comments">
    | Integration                                              | What it covers                                                                   |
    | -------------------------------------------------------- | -------------------------------------------------------------------------------- |
    | [Aircall](/en/compliance/sources/aircall-source)         | Voice and messaging platform metadata for communications controls.               |
    | [RingCentral](/en/compliance/sources/ringcentral-source) | Voice, messaging, and account configuration for communications controls.         |
    | [Slack](/en/compliance/sources/slack-source)             | Workspace membership, channels, and app integrations for collaboration controls. |
  </Accordion>

  <Accordion title="CRM" icon="address-book">
    | Integration                                          | What it covers                                                    |
    | ---------------------------------------------------- | ----------------------------------------------------------------- |
    | [Attio](/en/compliance/sources/attio-source)         | CRM records and workspace structure for customer-data controls.   |
    | [WordPress](/en/compliance/sources/wordpress-source) | Users, roles, and REST-accessible site metadata for CMS controls. |
  </Accordion>

  <Accordion title="Databases" icon="database">
    #### Amazon Sources

    | Integration                                                                            | What it covers                                                                     |
    | -------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- |
    | [Amazon Redshift Data API](/en/compliance/sources/amazon-redshift-data-api-source)     | Data API usage and SQL-layer inventory for Redshift governance.                    |
    | [Amazon Redshift Serverless](/en/compliance/sources/amazon-redshift-serverless-source) | Serverless workgroups, namespaces, and related configuration.                      |
    | [AWS DynamoDB](/en/compliance/sources/amazon-dynamodb-source)                          | Tables, indexes, and backup settings (configuration and inventory, not item data). |
    | [AWS RDS](/en/compliance/sources/amazon-relational-database-service-rds-source)        | DB instances, Aurora clusters, snapshots, and encryption settings (no query data). |
    | [AWS Redshift](/en/compliance/sources/amazon-redshift-source)                          | Provisioned clusters, subnet groups, snapshots, and encryption posture.            |

    #### Other Integrations

    | Integration                                          | What it covers                                                                    |
    | ---------------------------------------------------- | --------------------------------------------------------------------------------- |
    | [Snowflake](/en/compliance/sources/snowflake-source) | ACCOUNT\_USAGE metadata, roles, and warehouses via read APIs (not arbitrary SQL). |
  </Accordion>

  <Accordion title="Developer tools" icon="code-branch">
    #### Amazon Sources

    | Integration                                                                                                 | What it covers                                                               |
    | ----------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------- |
    | [AWS CodeCommit](/en/compliance/sources/aws-codecommit-source)                                              | Git repositories, branches, and pull-request settings for change management. |
    | [AWS Elastic Kubernetes Service (EKS)](/en/compliance/sources/amazon-elastic-kubernetes-service-eks-source) | Clusters, node groups, and Kubernetes inventory for container security.      |
    | [AWS Elastic Compute Cloud (EC2)](/en/compliance/sources/amazon-elastic-compute-cloud-ec2-source)           | Instances, security groups, VPC layout, and AMI metadata.                    |
    | [AWS Elastic Container Service (ECS)](/en/compliance/sources/amazon-elastic-container-service-ecs-source)   | Services, tasks, and cluster configuration for container compliance.         |
    | [AWS Elastic Load Balancing (ELB)](/en/compliance/sources/elastic-load-balancing-elb-source)                | Listeners, rules, target groups, and health checks for ingress controls.     |
    | [AWS Lambda](/en/compliance/sources/aws-lambda-source)                                                      | Functions, triggers, and IAM attachments for serverless governance.          |
    | [AWS Organizations](/en/compliance/sources/aws-organizations-source)                                        | Accounts, OUs, roots, and SCP evidence for landing-zone controls.            |
    | [AWS Auto Scaling](/en/compliance/sources/aws-auto-scaling-source)                                          | Scaling groups, policies, and capacity evidence across compute.              |

    #### Microsoft Azure

    | Integration                                                                                  | What it covers                                                                                                           |
    | -------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------ |
    | [Microsoft Azure Authorization](/en/compliance/sources/microsoft-azure-authorization-source) | Role assignments and RBAC policy administration for resources and resource groups.                                       |
    | [Microsoft Azure Key Vault](/en/compliance/sources/microsoft-azure-key-vault-source)         | Key Vault inventory and access policies via the management API (not secret values).                                      |
    | [Microsoft Azure Monitor](/en/compliance/sources/microsoft-azure-monitor-source)             | Diagnostic settings and export of resource logs and metrics to supported destinations.                                   |
    | [Microsoft Azure Network](/en/compliance/sources/microsoft-azure-network-source)             | Virtual networks, subnets, interfaces, public IPs, NSGs, load balancers, VPN gateways, and related networking resources. |
    | [Microsoft Azure Storage](/en/compliance/sources/microsoft-azure-storage-source)             | Storage accounts and configuration within an Azure subscription.                                                         |

    #### Other Integrations

    | Integration                                                | What it covers                                                                 |
    | ---------------------------------------------------------- | ------------------------------------------------------------------------------ |
    | [Bitbucket](/en/compliance/sources/bitbucket-cloud-source) | Repositories, branch policies, and workspace access for code governance.       |
    | [Contentful](/en/compliance/sources/contentful-source)     | Content models, entries, and roles for CMS access controls.                    |
    | [DigitalOcean](/en/compliance/sources/digitalocean-source) | Droplets, Kubernetes, databases, and networking inventory where enabled.       |
    | [Doppler](/en/compliance/sources/doppler-source)           | Projects and sync metadata for secrets governance (not secret values).         |
    | [Drupal](/en/compliance/sources/drupal-source)             | JSON:API users, roles, and content metadata for web CMS controls.              |
    | [Figma](/en/compliance/sources/figma-source)               | Projects, files, org membership, and OAuth-scoped design-system evidence.      |
    | [GitHub](/en/compliance/sources/github-source)             | Orgs, repos, branch protection, teams, and audit-oriented settings.            |
    | [GitLab](/en/compliance/sources/gitlab-source)             | Groups, projects, CI/CD configuration, and membership for DevOps controls.     |
    | [Heroku](/en/compliance/sources/heroku-source)             | Apps, pipelines, collaborators, and add-ons for PaaS evidence.                 |
    | [Jenkins](/en/compliance/sources/jenkins-source)           | Jobs, plugins, and CI configuration for build and deployment controls.         |
    | [OpenAI](/en/compliance/sources/openai-source)             | Org and project metadata for AI usage and access governance.                   |
    | [PagerDuty](/en/compliance/sources/pagerduty-source)       | Services, incidents, schedules, and escalation evidence for incident response. |
    | [Postman](/en/compliance/sources/postman-source)           | Workspaces, collections, and API governance surfaces exposed by API.           |
  </Accordion>

  <Accordion title="HRIS" icon="id-badge">
    | Integration                                                    | What it covers                                                             |
    | -------------------------------------------------------------- | -------------------------------------------------------------------------- |
    | [BambooHR](/en/compliance/sources/bamboohr-source)             | Employee records and HR workflows for workforce compliance evidence.       |
    | [Checkr](/en/compliance/sources/checkr-source)                 | Background screening status and employment verification records.           |
    | [Lattice](/en/compliance/sources/lattice-source)               | Reviews, goals, and HR program metadata tied to people compliance.         |
    | [Sage HR](/en/compliance/sources/sage-hr-source)               | HR employee and absence metadata available via API for workforce evidence. |
    | [Workable](/en/compliance/sources/workable-source)             | Jobs, candidates, and recruiting pipeline metadata for HR compliance.      |
    | [Workday Report](/en/compliance/sources/workday-report-source) | Custom HR reports via Workday RaaS for payroll and workforce evidence.     |
  </Accordion>

  <Accordion title="Monitoring" icon="eye">
    #### Amazon Sources

    | Integration                                                       | What it covers                                                          |
    | ----------------------------------------------------------------- | ----------------------------------------------------------------------- |
    | [AWS CloudWatch](/en/compliance/sources/amazon-cloudwatch-source) | Metrics, alarms, and monitoring configuration for operational controls. |

    #### Other Integrations

    | Integration                                      | What it covers                                                                 |
    | ------------------------------------------------ | ------------------------------------------------------------------------------ |
    | [Datadog](/en/compliance/sources/datadog-source) | Monitors, users, integrations, and security-related configuration via API.     |
    | [Sentry](/en/compliance/sources/sentry-source)   | Projects, releases, and error-tracking configuration for application security. |
  </Accordion>

  <Accordion title="Productivity" icon="briefcase">
    | Integration                                                  | What it covers                                                                    |
    | ------------------------------------------------------------ | --------------------------------------------------------------------------------- |
    | [Confluence](/en/compliance/sources/confluence-cloud-source) | Spaces, pages, and Atlassian access for documentation governance.                 |
    | [Docusign](/en/compliance/sources/docusign-source)           | Envelopes, recipients, and audit metadata for e-signature controls.               |
    | [Envoy](/en/compliance/sources/envoy-source)                 | Workplace visitors and location settings where applicable to physical security.   |
    | [Notion](/en/compliance/sources/notion-source)               | Pages, databases, users, and workspace structure for knowledge governance.        |
    | [Reach 360](/en/compliance/sources/reach-360-source)         | Training enrollments, completions, content, and groups from Articulate Reach 360. |
  </Accordion>

  <Accordion title="Project management" icon="list-check">
    | Integration                                        | What it covers                                                           |
    | -------------------------------------------------- | ------------------------------------------------------------------------ |
    | [Aha!](/en/compliance/sources/aha-ideas-source)    | Roadmaps, ideas, and workspace metadata for product governance evidence. |
    | [Asana](/en/compliance/sources/asana-source)       | Workspaces, projects, and tasks for access and collaboration reviews.    |
    | [ClickUp](/en/compliance/sources/clickup-source)   | Workspaces, lists, tasks, and members for operational evidence.          |
    | [Jira](/en/compliance/sources/jira-source)         | Projects, issues, workflows, and service-management evidence.            |
    | [Shortcut](/en/compliance/sources/shortcut-source) | Stories, epics, and workflow metadata for engineering governance.        |
    | [Trello](/en/compliance/sources/trello-source)     | Boards, lists, cards, and members for lightweight project evidence.      |
  </Accordion>

  <Accordion title="Security" icon="shield">
    | Integration                                                   | What it covers                                                             |
    | ------------------------------------------------------------- | -------------------------------------------------------------------------- |
    | [Iru Endpoint](/en/compliance/sources/iru-endpoint-source)    | Device enrollment, posture, and endpoint inventory from Iru Endpoint.      |
    | [1Password](/en/compliance/sources/1password-business-source) | Audit and access events from your password manager (Events Reporting API). |

    #### Amazon Sources

    | Integration                                                                                                      | What it covers                                                                 |
    | ---------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------ |
    | [Amazon Inspector](/en/compliance/sources/amazon-inspector-source)                                               | EC2 and container vulnerability and assessment findings.                       |
    | [AWS CloudTrail](/en/compliance/sources/aws-cloudtrail-source)                                                   | Management events and trail configuration for API audit evidence.              |
    | [AWS Config](/en/compliance/sources/aws-config-source)                                                           | Resource inventory, rules, and configuration timeline per Region.              |
    | [AWS GuardDuty](/en/compliance/sources/amazon-guardduty-source)                                                  | Threat-detection findings and detector configuration.                          |
    | [AWS IAM](/en/compliance/sources/aws-identity-and-access-management-iam-source)                                  | Users, roles, policies, MFA, and credential reports for access reviews.        |
    | [AWS IAM Identity Center (Identity Store)](/en/compliance/sources/aws-iam-identity-center-identity-store-source) | Directory users, groups, and memberships (`identitystore:` APIs).              |
    | [AWS IAM Identity Center (SSO)](/en/compliance/sources/aws-iam-identity-center-sso-source)                       | Permission sets, assignments, and SSO applications (`sso:` APIs).              |
    | [AWS Key Management Service (KMS)](/en/compliance/sources/aws-key-management-service-kms-source)                 | CMK metadata, rotation settings, and key policy evidence (not cleartext keys). |
    | [AWS Secrets Manager](/en/compliance/sources/aws-secrets-manager-source)                                         | Secret rotation metadata and inventory (not secret values).                    |
    | [AWS Security Hub](/en/compliance/sources/aws-security-hub-source)                                               | Aggregated controls and findings across integrated AWS security services.      |

    #### Other Integrations

    | Integration                                                      | What it covers                                                                      |
    | ---------------------------------------------------------------- | ----------------------------------------------------------------------------------- |
    | [Cloudflare](/en/compliance/sources/cloudflare-source)           | DNS, WAF, and edge security configuration for perimeter controls.                   |
    | [HashiCorp Vault](/en/compliance/sources/hashicorp-vault-source) | Policies, mounts, and metadata for secrets-engine governance (not secret payloads). |
    | [JumpCloud](/en/compliance/sources/jumpcloud-source)             | Directory, SSO, MDM, and device inventory for unified identity evidence.            |
    | [KnowBe4](/en/compliance/sources/knowbe4-source)                 | Training campaigns and phishing simulation completion records.                      |
    | [Okta](/en/compliance/sources/okta-source)                       | Users, groups, MFA, apps, and SSO policies for identity evidence.                   |
    | [Semgrep](/en/compliance/sources/semgrep-source)                 | Static analysis findings, projects, and policies from Semgrep Cloud.                |
  </Accordion>

  <Accordion title="Storage" icon="hard-drive">
    #### Amazon Sources

    | Integration                                                                                          | What it covers                                                                      |
    | ---------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------- |
    | [AWS Elastic File System (Amazon EFS)](/en/compliance/sources/amazon-elastic-file-system-efs-source) | File systems, mounts, and encryption posture for shared storage.                    |
    | [AWS S3](/en/compliance/sources/amazon-simple-storage-service-s3-source)                             | Bucket policies, encryption, logging, and public-access blocks (not object bodies). |

    #### Other Integrations

    | Integration                              | What it covers                                              |
    | ---------------------------------------- | ----------------------------------------------------------- |
    | [Box](/en/compliance/sources/box-source) | Enterprise content, folders, and collaboration permissions. |
  </Accordion>

  <Accordion title="Support" icon="headset">
    | Integration                                        | What it covers                                                             |
    | -------------------------------------------------- | -------------------------------------------------------------------------- |
    | [Intercom](/en/compliance/sources/intercom-source) | Workspace apps, conversations metadata, and admin surfaces exposed by API. |
  </Accordion>
</AccordionGroup>

## Enable a Source

<Steps>
  <Step title="Open Sources">
    On the left navigation bar, expand **Compliance** and select **Sources**.

    <Frame>
      <img src="https://mintcdn.com/iru/tI0HDLDwHj8r9Ile/assets/media/images/iru-navigation-compliance-sources.png?fit=max&auto=format&n=tI0HDLDwHj8r9Ile&q=85&s=87dcef15fc17d2fb9a6e53f454e41710" alt="Left navigation: Compliance expanded, Sources selected" width="410" height="1024" data-path="assets/media/images/iru-navigation-compliance-sources.png" />
    </Frame>
  </Step>

  <Step title="Turn on the integration">
    Find the source card (use **Search by name or description** or **Category** if you need to narrow the list). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard (OAuth, API key, IAM role, or other prompts depending on the integration).
  </Step>

  <Step title="Finish the wizard">
    Complete the wizard until the card shows **Active**. See the connector article for your system if you need field-level detail.
  </Step>
</Steps>

<Note>
  If nothing opens when you turn the **toggle** on, check **pop-up blocker** settings for the Iru site and try again.
</Note>

## Disable or Remove a Source

When a source is already **Active**, click its **toggle** again. Iru prompts you to confirm that you want to **remove** that source. Select **Yes, remove** to disable the integration and turn the source off. Select **Cancel** to dismiss the prompt and leave the source **Active**.

Connecting, updating, or removing a source is one of the signals Iru AI uses for [Adaptive Compliance](/en/compliance/adaptive-compliance). Within about a day, you may see a **Control Update** recommendation on **Home** → **Insights**, on the **Frameworks** list, or on a framework’s detail page so control and action text still match how you collect evidence.

If expected artifacts do not appear after the source is **Active**, confirm your **actions** describe which evidence should come from that system and that the connected account has the **scopes** or permissions the connector needs.

## Related Articles

<CardGroup cols={2}>
  <Card title="Getting Started With Compliance" icon="rocket" href="/en/compliance/getting-started-with-compliance">
    Frameworks, actions, and artifacts.
  </Card>

  <Card title="Adaptive Compliance" icon="sparkles" href="/en/compliance/adaptive-compliance">
    Review control and action updates after source or policy changes.
  </Card>

  <Card title="Policies Management" icon="file-lines" href="/en/compliance/policies-management">
    Create, publish, and track security and compliance policies.
  </Card>

  <Card title="Artifacts Management" icon="folder-open" href="/en/compliance/artifacts-management">
    Uploads, validation, and organizing evidence.
  </Card>
</CardGroup>
