> ## Documentation Index
> Fetch the complete documentation index at: https://www.c1.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Set up a BeyondTrust Password Safe connector

> C1 provides identity governance for BeyondTrust BeyondInsight + Password Safe. Integrate your Password Safe instance with C1 for unified visibility and governance over user access.

C1 provides identity governance for BeyondTrust BeyondInsight + Password Safe (BIPS). Integrate your BIPS instance with C1 for unified visibility and governance over user access.

## Capabilities

| Resource | Sync | Provision |
| - | - | - |
| Users | <Icon icon="square-check" iconType="solid" color="#c937ae" /> | <Icon icon="square-check" iconType="solid" color="#c937ae" /> |
| User Groups | <Icon icon="square-check" iconType="solid" color="#c937ae" /> | <Icon icon="square-check" iconType="solid" color="#c937ae" /> |
| Smart Rules | <Icon icon="square-check" iconType="solid" color="#c937ae" /> | |
| Managed Systems | <Icon icon="square-check" iconType="solid" color="#c937ae" /> | |
| Managed Accounts | <Icon icon="square-check" iconType="solid" color="#c937ae" /> | |

The connector reads BeyondInsight users, user groups, Smart Rules, managed systems, and managed accounts through the Password Safe v3 REST API. It provisions BeyondInsight user accounts (create / delete) and user-group memberships (grant / revoke). On create, the connector always supplies an initial random password (required by the BIPS API) and returns it to the administrator for rotation; SSO is the intended post-create login path. Two actions, **Disable User** and **Enable User**, quarantine and reactivate a user without removing them. Smart Rule role assignments and managed-account write-back are not exposed today.

## Prerequisites

<Warning>
  Managed accounts are **not API-accessible by default**. A BeyondInsight administrator must enable **API Enabled** per account or via a Smart Rule before the connector can read them. Without this, the first sync returns no managed accounts. A missing Password Safe **Requestor**, **Requestor/Approver**, or **ISA** role fails the same way: the connector syncs zero managed accounts with no error. If managed accounts are empty, check both the role assignment and the API Enabled flag before assuming the environment is empty.
</Warning>

<Steps>
  <Step>
    In BeyondInsight, create an **Application** user dedicated to C1.
  </Step>

  <Step>
    Generate an **API Registration** (API key) for that user. The key is a long string the connector sends in the `Authorization: PS-Auth` header on the BIPS sign-in call (`Auth/SignAppin`).
  </Step>

  <Step>
    Attach an **API Access Policy** to the registration that allows access from the IP range C1 will connect from. If the policy requires a run-as user password, capture it as well.
  </Step>

  <Step>
    Grant the C1 application user the BeyondInsight permissions **User Accounts Management (Read/Write)** (users and groups), **Password Safe System Management (Read)** (managed systems), and **Password Safe API Global Quarantine (Read/Write)** (the Disable User action). Managed accounts have no feature permission: assign the user a Password Safe **Requestor**, **Requestor/Approver**, or **ISA** role instead. Grant Read access to the Smart Rules that scope the managed accounts and Smart Rules you want synced.
  </Step>

  <Step>
    For each managed account (or for the Smart Rule that owns them), flip **API Enabled** to **Yes**.
  </Step>
</Steps>

## Gather BeyondTrust credentials

<Steps>
  <Step>
    Note your BIPS API base URL. For cloud tenants it is `https://<tenant>.ps.beyondtrustcloud.com/BeyondTrust/api/public/v3`; for self-hosted deployments it is `https://<your-host>/BeyondTrust/api/public/v3`.
  </Step>

  <Step>
    Build the full PS-Auth Authorization value, including the leading `PS-Auth `, in the format `PS-Auth key=<api-key>; runas=<application-user-name>;`. Append `pwd=<password>;` if your API Access Policy requires the run-as user's password.
  </Step>

  <Step>
    Copy both values somewhere safe. The key is shown once at creation time.
  </Step>
</Steps>

## Configure the BeyondTrust Password Safe connector

<Tabs>
  <Tab title="Cloud-hosted">
    Follow these instructions to use a built-in, no-code connector hosted by C1.

    <Steps>
      <Step>
        In C1, navigate to **Apps** > **Connectors** and click **Add connector**.
      </Step>

      <Step>
        Search for **BeyondTrust Password Safe** and click **Add**.
      </Step>

      <Step>
        Choose where to add the connector: **Create a new app**, or **Add to an existing app** (then select the app).

        If you're creating a new app, choose whether to link it to an application discovered from your identity provider: select **Yes** and pick the IdP application, or **No** to continue with just the connector.
      </Step>

      <Step>
        Set the connector's **Name** and, optionally, a **Description**.
      </Step>

      <Step>
        Click the pencil icon next to **Owners** to choose who can configure and manage this connector.
      </Step>

      <Step>
        Click **Add**. The connector is created and its configuration page opens.
      </Step>

      <Step>
        Find the **Settings** area of the page and click **Edit**.
      </Step>

      <Step>
        Enter the BIPS credentials:

        * **Base URL**: your BIPS v3 endpoint, e.g. `https://tenant.ps.beyondtrustcloud.com/BeyondTrust/api/public/v3`.
        * **PS-Auth credentials**: the full Authorization value, e.g. `PS-Auth key=<api-key>; runas=<application-user>;`.
      </Step>

      <Step>
        Click **Save**.
      </Step>

      <Step>
        The connector's label changes to **Syncing**, followed by **Connected**. You can view the logs to ensure that information is syncing.
      </Step>
    </Steps>

    **Done.** Your BeyondTrust Password Safe connector is now pulling access data into C1.
  </Tab>

  <Tab title="Self-hosted">
    Follow these instructions to run the BeyondTrust Password Safe connector in your own environment.

    <Steps>
      <Step>
        Create a secret for the PS-Auth credentials.
      </Step>

      <Step>
        Configure the connector environment variables:

        * **BATON\_BASE\_URL**: your BIPS v3 endpoint, e.g. `https://tenant.ps.beyondtrustcloud.com/BeyondTrust/api/public/v3`.
        * **BATON\_PS\_AUTH\_CREDENTIALS**: the full Authorization value, e.g. `PS-Auth key=<api-key>; runas=<application-user>;`.
      </Step>

      <Step>
        Deploy the connector using your standard self-hosted connector process.
      </Step>
    </Steps>

    **Done.** Your BeyondTrust Password Safe connector is now pulling access data into C1.
  </Tab>
</Tabs>
