Capabilities
Team membership can be granted and revoked. Grafana RBAC roles that a team holds (IRM and OnCall plugin roles such as Schedules Editor) are synced as read-only assignments and require Grafana Cloud or Enterprise. Service accounts are synced with their organization role; they are read-only.
This connector syncs non-human identities and displays them on the Identities overview dashboard.
Roles are optionalIRM / OnCall RBAC roles are available only on Grafana Cloud and Enterprise. Role sync is disabled by default — enable the Role resource type in the connector’s settings in C1 when your instance has access-control.
Grafana Cloud: provisioning organization roles for externally synced usersIn Grafana Cloud, users who sign in through an external identity provider (such as Grafana.com SSO, Okta, Azure AD, or any OAuth/SAML provider) have their organization roles controlled by that provider. By default, Grafana blocks API-level role changes for these users, which prevents C1 from provisioning organization entitlements for them.To allow C1 to manage organization roles for these users, enable Skip org role sync for the relevant SSO provider in your Grafana instance:
- In Grafana, go to Administration → Authentication.
- Select the SSO provider your users log in with.
- Enable Skip org role sync (equivalent to setting
skip_org_role_sync = true).
Account access origin
Starting with connector version 0.2.3, each synced account’s profile includes attributes that identify how the user’s access originated. They appear in the account’s Profile attributes in C1 and support access reviews where the origin of access matters:is_externally_synced surfaces Grafana’s native isExternallySynced flag verbatim and only when Grafana actually returns it. Whether the flag is returned depends on the endpoint the connector reads, which differs by mode:
- Grafana Cloud reads the organization users endpoint (
/api/org/users), which always returns the flag, sois_externally_syncedis present and mirrors Grafana’s value exactly. It reflects only whether the user’s organization role is managed by an external identity provider (role sync) — it is not derived fromauth_labels, which is a different concept (how the user authenticated). In Grafana Cloud every user authenticates through grafana.com, soauth_labelsis effectively alwaysgrafana.com; an admin whose role is managed locally therefore reportsis_externally_synced: falseeven though theirauth_labelsshowgrafana.com. - Self-hosted Grafana reads the global users endpoint (
/api/users), which does not return the flag. Rather than derive a value from a different concept, the connector omitsis_externally_syncedfrom the profile entirely. Useauth_labelsto reason about authentication provenance in this mode.
Gather Grafana credentials
Configuring the connector requires credentials obtained in your Grafana instance. The credentials you need depend on whether you are connecting to Grafana Cloud or a self-hosted Grafana instance.- Grafana Cloud
- Self-hosted Grafana
For Grafana Cloud, the connector authenticates using a service account token. Basic username/password authentication is not supported in Cloud mode.To create a service account token:You will need:
- In your Grafana Cloud instance, go to Administration → Users and access → Service accounts.
- Click Add service account, give it a name, and assign it the Admin role.
- Make sure the service account’s basic role is set to at least Viewer — not No basic role. See the callout below; this must be done in the Grafana UI.
- Open the new service account and click Add service account token.
- Copy and save the generated token — it will not be shown again.
These six actions cover sync only. When provisioning is enabled (
BATON_PROVISIONING), granting and revoking access calls separate write endpoints that need additional RBAC actions. The actions you need depend on which provisioning capability is enabled — account provisioning (creating brand-new users) and entitlement provisioning (granting/revoking org roles and team membership) call different endpoints and do not require the same permissions.Account provisioning (CreateAccount, Delete):Entitlement provisioning (Grant/Revoke on the Organizations and Teams resource types):
org.users:add is reached only by CreateAccount’s invite path. A customer who enables entitlement provisioning without account provisioning does not need it: in Cloud mode, Grant only ever updates the role of a user who is already an org member (via PATCH /api/org/users/{id}), or fails outright if the user isn’t already a member — it never calls the invite endpoint.org.users:remove, by contrast, is needed independently by both capabilities: account provisioning’s Delete and entitlement provisioning’s Revoke both call the same DELETE /api/org/users/{id} endpoint. A customer who enables only one of the two capabilities still needs this permission for that capability alone.Team sync always reads team membership, so teams.permissions:read is required unconditionally. teams.roles:read is only needed when Role sync is enabled — the connector only fetches each team’s RBAC roles in that case — same as roles:read. A narrower token that previously synced only users/orgs may still fail List after this upgrade, since teams:read and teams.permissions:read are newly required for team sync regardless of Role sync.With Role sync enabled,
roles:read and teams.roles:read come as a packageNo built-in Grafana role grants one of these actions without the other: fixed:roles:reader and fixed:roles:writer each grant both together, and the basic roles that grant roles:read (basic:admin and basic:grafana_admin) also grant teams.roles:read. basic:viewer and basic:editor grant neither. This is expected — when Role sync is disabled, the connector needs neither action, so there is nothing to isolate; when Role sync is enabled, plan on granting both together (or use a custom role if you need to diverge from Grafana’s built-in roles for some other reason).- Your Grafana Cloud instance URL (e.g.,
https://your-org.grafana.net) - The service account token generated above
Configure the Grafana connector
- Cloud-hosted
- Self-hosted
Follow these instructions to use a built-in, no-code connector hosted by C1.Done. Your Grafana connector is now pulling access data into C1.
1
In C1, navigate to Apps > Connectors and click Add connector.
2
Search for Grafana and click Add.
3
Choose where to add the connector: Create a new app, or Add to an existing app (then select the app).If you’re creating a new app, choose whether to link it to an application discovered from your identity provider: select Yes and pick the IdP application, or No to continue with just the connector.
4
Set the connector’s Name and, optionally, a Description.
5
Click the pencil icon next to Owners to choose who can configure and manage this connector.
6
Click Add. The connector is created and its configuration page opens.
7
Find the Settings area of the page and click Edit.
8
Paste your Grafana instance URL into the Instance URL field.
9
Enter your credentials based on your Grafana deployment type:
- Grafana Cloud: Select “API Key” as the auth method and paste your service account token into the API Token field.
- Self-hosted Grafana: Select “Basic Authentication” as the auth method and paste the admin account’s username and password into the Username and Password fields.
10
Click Save.
11
The connector’s label changes to Syncing, followed by Connected. You can view the logs to ensure that information is syncing.