Skip to main content
A is the integration. A connection holds the credentials Klef signs in with, the permissions those credentials carry, and the settings that decide how Klef treats the accounts it finds there. Connections can be configured under the Connections page.
Screenshot placeholder: the connections list

The workspace's connections

Adding One

Choose the system and authorize it one of two ways, depending on what that system offers:
  • Sign in. Klef sends you to the system to approve its access, and keeps the token it gets back.
  • Credentials. You fill in the settings the connector needs, such as a tenant ID and a client secret. Secrets are stored encrypted and never shown again.
Each connector’s page lists the settings it takes and the access it needs. Grant the access first: Klef checks it as soon as the connection is saved.

Checking Permissions

To help ensure the connection has the access it needs, Klef has a Check Access button on each connection’s configuration page. The check verifies that the connection has the required permissions to operate and reports back any missing capabilities. A missing required capability means the connector cannot operate and should be fixed. A missing recommended capability means the connector’s functionality is limited, but otherwise it can still operate.
Screenshot placeholder: an access check result

The result of an access check

One Connection per System

Currently, Klef only support one connection per system. For example, you cannot connect two Microsoft Entra tenants concurrently.

How Often a Source Syncs

Klef syncs from your connected every 15 minutes and re-reads their whole rosters every 6 hours. have no cadence. Klef reads a target when it builds a plan, so what a plan shows is what was there moments before.

Disabling a Connection

To disable syncing to a target, turn on Protect Accounts under the connection’s settings. Once enabled, will still show what would have been changed, but nothing is written to the system.

Deleting a Connection

Deleting a connection removes its credentials and stops its schedules. It changes nothing in the system itself: accounts stay exactly as they are. Policies that target the system are skipped until you connect again, and accounts adopted through the old connection have to be adopted again on the new one. Delete a connection to retire a system, not to re-authorize it: editing the connection keeps everything Klef already knows about its accounts.