> ## Documentation Index
> Fetch the complete documentation index at: https://klef.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Connections

export const Term = ({term, children}) => {
  const terms = {
    "desired-state": "What should be true for a worker: the accounts and access they should have, given who they are and their lifecycle stage.",
    connector: "An integration with one of your systems.",
    source: "An HRIS Klef pulls its workers from.",
    target: "A connector Klef writes to.",
    "worker-model": "Klef's own record of each worker.",
    worker: "Klef's own record of one person.",
    policy: "A rule that sets the desired state for a group of workers at each lifecycle stage.",
    plan: "The set of operations needed to make reality match desired state, shown before it applies.",
    operation: "A single change described in a plan.",
    reconciler: "The engine that compares desired state to your live systems and produces a plan.",
    resource: "A reusable piece a policy uses: a script, a lookup table, or a secret.",
    segment: "A saved group of workers, defined by conditions over their attributes. A policy applies to one segment, or to everyone.",
    "lifecycle-stage": "Where a worker is right now: Pre-start, Active, Leave, Suspended, or Terminated.",
    mastering: "Taking a worker field's value from a connected system instead of your HRIS."
  };
  return <Tooltip tip={terms[term]}>{children}</Tooltip>;
};

A <Term term="connector">connector</Term> is the integration. A connection holds the credentials Klef signs in with, the permissions those credentials carry, and the settings that decide how Klef treats the accounts it finds there.

Connections can be configured under the **Connections** page.

<Frame caption="The workspace's connections">
  <img src="https://mintcdn.com/klef/xJ0kXbcegZOD2G3h/images/placeholder.svg?fit=max&auto=format&n=xJ0kXbcegZOD2G3h&q=85&s=4edf941b8a72c65c8b0a1d9fc3d52b42" alt="Screenshot placeholder: the connections list" noZoom width="1200" height="675" data-path="images/placeholder.svg" />
</Frame>

## Adding One

Choose the system and authorize it one of two ways, depending on what that system offers:

* **Sign in.** Klef sends you to the system to approve its access, and keeps the token it gets back.
* **Credentials.** You fill in the settings the connector needs, such as a tenant ID and a client
  secret. Secrets are stored encrypted and never shown again.

Each connector's page lists the settings it takes and the access it needs. Grant the access first:
Klef checks it as soon as the connection is saved.

## Checking Permissions

To help ensure the connection has the access it needs, Klef has a **Check Access** button on each connection's configuration page. The check verifies that the connection has the required permissions to operate and reports back any missing capabilities.

A missing **required capability** means the connector cannot operate and should be fixed. A missing **recommended capability** means the connector's functionality is limited, but otherwise it can still operate.

<Frame caption="The result of an access check">
  <img src="https://mintcdn.com/klef/xJ0kXbcegZOD2G3h/images/placeholder.svg?fit=max&auto=format&n=xJ0kXbcegZOD2G3h&q=85&s=4edf941b8a72c65c8b0a1d9fc3d52b42" alt="Screenshot placeholder: an access check result" noZoom width="1200" height="675" data-path="images/placeholder.svg" />
</Frame>

## One Connection per System

Currently, Klef only support one connection per system. For example, you cannot connect two Microsoft Entra tenants concurrently.

## How Often a Source Syncs

Klef syncs from your connected <Term term="source">sources</Term> every 15 minutes and re-reads their whole rosters every 6 hours.

<Term term="target">Targets</Term> have no cadence. Klef reads a target when it builds a plan, so what a plan shows is what was there moments before.

## Disabling a Connection

To disable syncing to a target, turn on **Protect Accounts** under the connection's settings. Once enabled, <Term term="plan">plans</Term> will still show what would have been changed, but nothing is written to the system.

## Deleting a Connection

Deleting a connection removes its credentials and stops its schedules. It changes nothing in the system itself: accounts stay exactly as they are.

Policies that target the system are skipped until you connect again, and accounts adopted through the
old connection have to be adopted again on the new one. Delete a connection to retire a system, not to
re-authorize it: editing the connection keeps everything Klef already knows about its accounts.
