Integrations
Listed with the most widely used first, so the ones you actually run are near the top. An app makes this list on one test: can a plain admin API remove a member on the plan you already pay for?
25 more are reachable only if you already pay for a particular plan of theirs — mostly apps where SCIM is the only way to remove a member and SCIM sits above the cheapest paid tier. Expensify needs Control, 1Password and LastPass need Business, Intercom needs Expert, and a long tail of them need Enterprise. Every one is excluded from the count above and carries the plan it needs on its own card, because for these the upgrade is the mechanism and we will not quote you a saving against it. athenahealth, DrChrono and HealthStream need a partner programme rather than a plan.
Microsoft Graph — included with Microsoft 365
Admin SDK — any Business plan
IAM users, groups and access keys
SCIM Users API
Needs your Enterprise
Users API on any standard paid plan
Atlassian org admin API — no Guard subscription needed
Admin API — no enterprise upgrade
REST org members — no plan gate
Admin API closeMemberships — the add-on is included with IAM plans
Needs your DocuSign Admin add-on
Table API — create, then set active=false
Team member management API
Users API — included with any Okta plan
SCIM Users API
Needs your Enterprise
SCIM Users API — role assignment included
Needs your Enterprise
SCIM Users API
Needs your Enterprise
Workspace membership API
Users API
Atlassian org admin API
SCIM Users API
Needs your Enterprise
SCIM Users API
Needs your Enterprise
SCIM Users API
Needs your Enterprise
SCIM Users API — automation is Enterprise-only
Needs your Enterprise
SCIM Users API
Needs your Enterprise
User Provisioning API via a private app — removes by user ID or email
SCIM Users API
Needs your Expert
SCIM Users API
Needs your Plus
SCIM on any Tableau Cloud plan — SAML or OIDC must be configured first
SCIM Users API
Needs your Enterprise Scale
Members API, all tiers
Atlassian org admin API
Users API
SCIM Users API
Needs your Pro or Enterprise
SQL user and role management
SCIM Users API — account-level user management is SCIM-only
Needs your Premium
Org and project users API
Org members API
Users API
Organization members API
Account members API
Org members API
GraphQL userSuspend — deactivates and invalidates their sessions
Team members API
Org users API
Tailnet users API
SCIM Users API
Needs your Falcon Enterprise
Duo Directory sync — included from Essentials, their cheapest paid plan
SCIM — core to the platform, free tier included
SCIM bridge — there is no REST member listing outside it
Needs your Business
SCIM Users API
Needs your Business
SCIM Users API
Needs your Enterprise
Organization members API
SCIM Users API
Needs your Enterprise
SCIM Users API
Needs your Pro
SCIM 2.0 — supported on every paid tier
SCIM Users API
Needs your Control
SCIM — included on every tier, Free included
SCIM — included with every product, no SSO tax
SCIM — there is no general members API
Needs your Enterprise
Organization memberships API
SCIM — also needs SAML SSO configured first
Needs your Enterprise
Users API — disables the user
Needs your Business
Already have SCIM on something? Karmoto speaks it, so those apps work too. We won't claim a five-hundred-app integration count off the back of that — SCIM only reaches apps that already support it, and your directory likely covers most of those today.
The ones people ask about that aren't here. Slack and Notion. Both are listed above as tracked rather than as targets, because the write path each one publishes is gated above the plan most customers hold — Slack's SCIM starts at Business+, and Notion has no removal endpoint we can find at any price. Notion's SCIM surface may still tell a different story; that recheck is queued. Neither moves off tracked on anything less than a call to the endpoint. Everything else people ask for is now on the list, carrying the plan it needs: where you already pay for that tier we orchestrate it, and where you assign the app through a directory group the section below reaches it anyway. What we won't do is bill you for a connector that needs you to buy something first.
Beyond the list
Most companies hand out access to far more apps than any integrations page could list — by putting people in a Microsoft Entra or Google security group and letting the app follow. Karmoto manages that group, so it reaches those apps without needing their API at all.
Assign a role in Karmoto, the person lands in the right groups, and every app behind them opens up on their first day.
The group membership is the entitlement, so quarterly reviews and the evidence pack cover these apps exactly as completely as a direct connector does.
Removing the group blocks sign-in. It does not delete the account inside the app, and may not end a live session — so Karmoto records it as access blocked, never as a clean revoke.
Group-based app assignment needs Entra ID P1, which is included with Microsoft 365 Business Premium and E3 — so most companies this size already have it and no upgrade is involved. Entra supports security groups only, and not nested ones, for app assignment.
Files and shared drives
Losing a departing employee's documents is the offboarding failure people notice first — usually weeks later, when someone needs the file and it's locked in a deleted account.
Google Shared Drives and SharePoint sites are membership, not ownership. Removing someone doesn't touch a single file — the documents stay exactly where the team expects them.
My Drive and OneDrive belong to the person. On termination Karmoto hands ownership to their manager before the account closes, so nothing is stranded.
The old \\server\share drives are governed by Active Directory groups and NTFS permissions, and reaching them needs an agent inside your network. We don't do this, and we'd tell you before you asked.
Ownership transfer runs on Google's own Data Transfer API and Microsoft Graph, so the move happens inside your tenant and never passes through us. Google won't transfer files to or from an account outside your domain, which is their rule rather than ours.
Healthcare
Your EHR is usually the one system where offboarding already works — HIPAA forces an audited access review on it. What actually goes unrevoked is everything around it: the shared drive, the scheduling tool, the video visits, the billing portal. Those are in the list above. These are the healthcare-specific ones we'll reach too.
SCIM user lifecycle — near-universal for HIPAA training
hStream APIs — access runs through their partner programme
athenaOne API — requires their Marketplace partner programme
REST API — production access starts with an email to api@drchrono.com
SOAP API — customer key from Admin, Settings, API Keys
REST API, key issued per office through their Developer Portal
Epic, Oracle Health and MEDITECH aren't here. They're hospital-scale systems that administer access inside their own tooling rather than through a public API, and they sit outside the size of company we build for. We'd rather say that than imply otherwise.
Where the API stops
Both let us read who has an account, and neither lets us remove one on the plan most teams hold — Notion has no removal endpoint on any plan, and Slack's is SCIM, which starts at Business+. So Karmoto flags the account during offboarding, gives your admin the exact step, and records who marked it done. The next sync re-reads the member list. If they're still there, the task reopens.
That check is the difference between a record and a tick box. Your audit trail separates the two: revoked means an API call returned success, attested means a named person said they did it, and verified means we went back and confirmed it. An auditor treats those differently, so we don't merge them.
We read the member list; no removal endpoint exists on any plan
We read users.list on any plan; the write path is SCIM, which starts at Business+
One gap we'd rather state than have you find: Notion's API doesn't return guests, so a departing contractor on a guest seat can be attested but not automatically re-checked. Those stay marked attested, never verified, and the guest list is reviewed from an export instead. Slack has no such gap — its member list includes guests and still shows the account after removal, so the confirmation is positive rather than an absence.
Only apps with a readable member list qualify, because without one there is nothing to check the attestation against. Loom, Figma, Miro, Airtable and 1Password were all considered and none of them expose one on a plan you'd already be paying for, so they aren't here.
Where your people come from
These aren't apps we provision into — they're where the hire and the termination originate. Payroll and benefits stay exactly where they are.
A nightly CSV over SFTP works with every HRIS ever built, including the PEOs that have no API at all — Insperity, TriNet, Justworks. Your HR admin configures it once in about ten minutes, and no partner approval is involved. This is the path we build first, because it covers everyone.
Requires ADP's partner programme
RaaS reports or SOAP — built against a signed contract
Requires partner approval
Direct REST API — no partner programme
Requires partner approval
Requires partner approval
Production keys need Gusto's pre-approval and a security review
Direct REST API
This order isn't fixed. If enough people name the same app it moves to the front — a better signal than anything we can work out from a spreadsheet.
Request an app