From bbfe1e56c05c16b6234ba77e190e9d5f4093b9c6 Mon Sep 17 00:00:00 2001 From: Melinda Moreland Date: Wed, 16 Sep 2026 10:05:43 -0700 Subject: [PATCH 1/3] docs: rename C1 to C1.ai in product docs prose Renames "C1" -> "C1.ai" in running prose per the new naming style guide, across all product/*.mdx docs (admin, CLI, how-to, glossary, release notes). Excludes: code fences/inline code, and known live product-UI labels not yet renamed in the app (C1 MCP, C1 Gateway, C1 System) that would get ahead of the actual product. Co-Authored-By: Claude Sonnet 5 --- product/admin/access-conflicts.mdx | 18 +- product/admin/access-requests.mdx | 46 +-- product/admin/account-provisioning.mdx | 30 +- product/admin/agent-classifiers-configure.mdx | 14 +- product/admin/agent-classifiers-reference.mdx | 14 +- product/admin/agent-classifiers.mdx | 8 +- product/admin/ai-assistant.mdx | 34 +-- product/admin/ai-clients.mdx | 22 +- product/admin/aiam-overview.mdx | 46 +-- product/admin/applications.mdx | 34 +-- product/admin/attributes.mdx | 42 +-- product/admin/audit-ai-tool-usage.mdx | 16 +- product/admin/automation-actions.mdx | 18 +- product/admin/automation-circuit-breaker.mdx | 6 +- product/admin/automation-examples.mdx | 4 +- product/admin/automations-steps-reference.mdx | 26 +- .../admin/automations-triggers-reference.mdx | 12 +- product/admin/automations.mdx | 8 +- product/admin/branding.mdx | 46 +-- product/admin/c1-for-c1.mdx | 46 +-- product/admin/c1-mcp.mdx | 68 ++--- .../admin/campaign-scope-by-inheritance.mdx | 14 +- product/admin/campaigns.mdx | 62 ++-- product/admin/cloud-infrastructure-access.mdx | 18 +- product/admin/code-mode.mdx | 20 +- product/admin/customize-requests.mdx | 20 +- product/admin/decoys.mdx | 24 +- product/admin/delegate.mdx | 18 +- product/admin/directory.mdx | 66 ++--- product/admin/dynamic-access-control.mdx | 24 +- product/admin/email-provider-aws-ses.mdx | 36 +-- .../admin/email-provider-google-workspace.mdx | 30 +- .../admin/email-provider-microsoft-365.mdx | 44 +-- product/admin/email-provider-sendgrid.mdx | 30 +- product/admin/email-provider.mdx | 18 +- product/admin/emergency.mdx | 14 +- product/admin/enable-ai-access-management.mdx | 20 +- .../audit.mdx | 28 +- .../enable.mdx | 18 +- .../overview.mdx | 54 ++-- .../resource-servers.mdx | 30 +- .../scopes-and-profiles.mdx | 20 +- .../support-in-your-app.mdx | 48 +-- product/admin/entitlement-config-rules.mdx | 2 +- product/admin/expressions-examples.mdx | 6 +- product/admin/expressions-reference.mdx | 30 +- product/admin/expressions-troubleshooting.mdx | 6 +- product/admin/expressions-workflows.mdx | 4 +- product/admin/expressions.mdx | 22 +- product/admin/external-datasources.mdx | 36 +-- product/admin/external-insights.mdx | 18 +- product/admin/external-ticketing.mdx | 154 +++++----- product/admin/findings.mdx | 14 +- product/admin/functions-api.mdx | 12 +- product/admin/functions-automations.mdx | 4 +- product/admin/functions-create.mdx | 18 +- product/admin/functions-reference.mdx | 12 +- product/admin/functions.mdx | 16 +- product/admin/global-settings.mdx | 34 +-- product/admin/groups.mdx | 46 +-- product/admin/integration-for-Slack.mdx | 50 ++-- product/admin/inventory.mdx | 12 +- product/admin/manage-campaigns.mdx | 6 +- product/admin/managing-accounts.mdx | 24 +- product/admin/managing-entitlements.mdx | 28 +- product/admin/managing-resources.mdx | 28 +- product/admin/mcp-resources.mdx | 28 +- product/admin/mcp-server/apollo.mdx | 30 +- product/admin/mcp-server/auth0.mdx | 28 +- product/admin/mcp-server/azure-devops.mdx | 30 +- product/admin/mcp-server/bitbucket.mdx | 42 +-- product/admin/mcp-server/box.mdx | 28 +- product/admin/mcp-server/buildkite.mdx | 30 +- product/admin/mcp-server/confluence.mdx | 26 +- product/admin/mcp-server/copilot-studio.mdx | 62 ++-- product/admin/mcp-server/crowdstrike.mdx | 30 +- product/admin/mcp-server/datadog.mdx | 36 +-- product/admin/mcp-server/freshdesk.mdx | 30 +- .../admin/mcp-server/gemini-enterprise.mdx | 98 +++--- product/admin/mcp-server/github.mdx | 72 ++--- product/admin/mcp-server/gong.mdx | 32 +- .../mcp-server/google-analytics-admin.mdx | 38 +-- product/admin/mcp-server/google-analytics.mdx | 36 +-- .../mcp-server/google-cloud-project-setup.mdx | 16 +- product/admin/mcp-server/google-drive.mdx | 52 ++-- product/admin/mcp-server/granola.mdx | 52 ++-- product/admin/mcp-server/hubspot.mdx | 30 +- .../mcp-server/jira-service-management.mdx | 26 +- product/admin/mcp-server/jira.mdx | 26 +- product/admin/mcp-server/linear.mdx | 72 ++--- product/admin/mcp-server/linkedin.mdx | 26 +- product/admin/mcp-server/looker.mdx | 32 +- product/admin/mcp-server/lucid.mdx | 64 ++-- product/admin/mcp-server/mcp-bridge.mdx | 52 ++-- product/admin/mcp-server/metabase.mdx | 32 +- product/admin/mcp-server/metronome.mdx | 34 +-- product/admin/mcp-server/monday.mdx | 52 ++-- product/admin/mcp-server/n8n.mdx | 70 ++--- product/admin/mcp-server/notion.mdx | 58 ++-- product/admin/mcp-server/okta.mdx | 36 +-- product/admin/mcp-server/opsgenie.mdx | 30 +- product/admin/mcp-server/pagerduty.mdx | 76 ++--- product/admin/mcp-server/pylon.mdx | 54 ++-- product/admin/mcp-server/ramp.mdx | 28 +- product/admin/mcp-server/rapid7.mdx | 32 +- product/admin/mcp-server/salesforce.mdx | 26 +- product/admin/mcp-server/slack.mdx | 70 ++--- product/admin/mcp-server/snowflake.mdx | 34 +-- product/admin/mcp-server/statuspage.mdx | 30 +- product/admin/mcp-server/tableau.mdx | 44 +-- product/admin/mcp-server/trello.mdx | 30 +- product/admin/mcp-server/vectara.mdx | 38 +-- product/admin/mcp-server/wiz.mdx | 30 +- product/admin/mcp-servers.mdx | 40 +-- product/admin/ms-teams-public.mdx | 66 ++--- product/admin/nhi.mdx | 12 +- .../admin/notifications-tenant-settings.mdx | 12 +- product/admin/notifications-user-settings.mdx | 20 +- product/admin/object-annotations.mdx | 18 +- product/admin/organization-contacts.mdx | 4 +- product/admin/policies.mdx | 40 +-- product/admin/profile-types.mdx | 30 +- product/admin/profiles.mdx | 20 +- product/admin/provisioning.mdx | 36 +-- product/admin/push-rules.mdx | 28 +- product/admin/query.mdx | 8 +- product/admin/relationships.mdx | 32 +- product/admin/requirements.mdx | 16 +- product/admin/role-mining.mdx | 12 +- product/admin/secret-sharing.mdx | 22 +- product/admin/service-principals/aws-iam.mdx | 22 +- .../service-principals/client-credentials.mdx | 4 +- .../admin/service-principals/custom-oidc.mdx | 10 +- .../service-principals/federation-setup.mdx | 6 +- .../service-principals/github-actions.mdx | 12 +- .../admin/service-principals/gitlab-ci.mdx | 12 +- .../service-principals/hcp-terraform.mdx | 14 +- product/admin/service-principals/manage.mdx | 6 +- product/admin/service-principals/overview.mdx | 16 +- product/admin/service-principals/security.mdx | 6 +- product/admin/service-principals/spiffe.mdx | 18 +- .../workload-federation.mdx | 18 +- product/admin/shadow-apps.mdx | 22 +- product/admin/step-up-auth.mdx | 62 ++-- product/admin/system-log.mdx | 36 +-- product/admin/tool-call-hooks.mdx | 10 +- product/admin/tools-and-toolsets.mdx | 20 +- product/admin/user-roles.mdx | 30 +- product/admin/vaults.mdx | 12 +- product/admin/webhooks-inbound.mdx | 38 +-- product/admin/webhooks.mdx | 60 ++-- product/cli/c1i-agent-skills.mdx | 12 +- product/cli/c1i-commands.mdx | 42 +-- product/cli/c1i.mdx | 26 +- product/cli/commands.mdx | 26 +- product/cli/install.mdx | 28 +- product/glossary.mdx | 92 +++--- product/how-to/access-change-tasks.mdx | 38 +-- product/how-to/ai-tools.mdx | 44 +-- .../how-to/automate-revocation-tickets.mdx | 16 +- product/how-to/cone-aws-sso-integration.mdx | 20 +- product/how-to/connect-mcp-client.mdx | 68 ++--- product/how-to/create-requests.mdx | 82 +++--- product/how-to/intro.mdx | 20 +- product/how-to/qs-aws-jit-identity-center.mdx | 12 +- product/how-to/qs-entra-app-requests.mdx | 26 +- product/how-to/qs-gcp-jit.mdx | 10 +- product/how-to/qs-okta-app-requests.mdx | 26 +- product/how-to/qs-on-call-access-control.mdx | 8 +- product/how-to/qs-onelogin-app-requests.mdx | 26 +- product/how-to/qs-self-service-requests.mdx | 24 +- product/how-to/qs-set-up-c1.mdx | 142 ++++----- product/how-to/qs-user-access-reviews.mdx | 22 +- product/how-to/request-actions.mdx | 24 +- product/how-to/review-tasks.mdx | 18 +- product/intro.mdx | 20 +- product/release-notes-archive.mdx | 214 +++++++------- product/release-notes.mdx | 278 +++++++++--------- 178 files changed, 2969 insertions(+), 2969 deletions(-) diff --git a/product/admin/access-conflicts.mdx b/product/admin/access-conflicts.mdx index 51cd8c76..474afa24 100644 --- a/product/admin/access-conflicts.mdx +++ b/product/admin/access-conflicts.mdx @@ -1,6 +1,6 @@ --- title: Detect access conflicts -og:title: Detect access conflicts - C1 docs +og:title: Detect access conflicts - C1.ai docs og:description: Set up conflict monitors to automatically track and alert on combinations of access that violate separation of duties policies or regulations such as SOX, FDA 21 CFR Part 11, and ISO 27001. description: Set up conflict monitors to automatically track and alert on combinations of access that violate policies or regulations. --- @@ -10,12 +10,12 @@ description: Set up conflict monitors to automatically track and alert on combin An access conflict is when two entitlements assigned to the same user violate a separation of duties (SoD) policy or other regulation. Ensuring SoD is enforced across your organization is an important part of adhering to standards such as SOX, FDA 21 CFR Part 11, and ISO 27001. -Set up an access conflict monitor by defining groups of mutually exclusive access. C1 automatically identifies existing and new access conflicts so you can take action. Each conflict monitor also creates detailed audit logs and downloadable reports so you can prove your SoD compliance to auditors and certifiers. +Set up an access conflict monitor by defining groups of mutually exclusive access. C1.ai automatically identifies existing and new access conflicts so you can take action. Each conflict monitor also creates detailed audit logs and downloadable reports so you can prove your SoD compliance to auditors and certifiers. ## Create a new conflict monitor -This task requires the **Super Administrator** role in C1. +This task requires the **Super Administrator** role in C1.ai. Follow the steps below to create a conflict monitor. You can set up multiple conflict monitors to adhere to the various regulations and policies your organization must follow. @@ -70,19 +70,19 @@ Edit and refine your selections as necessary. No alerts will be triggered until In the **Settings** area of the page, click **Edit** and go to the **Notifications** area. -If you want C1 to send an email when new alerts are generated by the conflict monitor: +If you want C1.ai to send an email when new alerts are generated by the conflict monitor: * Click to turn on **Direct message**. - * Select one or more C1 users to receive notifications by email when new alerts are generated by your conflict monitor. + * Select one or more C1.ai users to receive notifications by email when new alerts are generated by your conflict monitor. -If you want C1 to send Slack notifications when new alerts are generated by the conflict monitor: +If you want C1.ai to send Slack notifications when new alerts are generated by the conflict monitor: - * Click to turn on **Slack**. You'll see an error with instructions if the C1 app for Slack isn't set up for your organization. + * Click to turn on **Slack**. You'll see an error with instructions if the C1.ai app for Slack isn't set up for your organization. - * Type the name of the channel where you want to receive notifications when new alerts are generated by your conflict monitor. If you enter the name of a channel that does not yet exist, the C1 app for Slack will create it for you. + * Type the name of the channel where you want to receive notifications when new alerts are generated by your conflict monitor. If you enter the name of a channel that does not yet exist, the C1.ai app for Slack will create it for you. Click **Save**. @@ -121,7 +121,7 @@ To learn more about a conflict and see its log of past actions, click **View aud ## Review access conflicts in a campaign -You can use your conflict monitors to scope an [access review campaign](/product/admin/campaigns). When you create a campaign and select the **Access conflicts** review type, C1 generates review tasks for users who have active violations detected by your conflict monitors. This lets you systematically review and remediate separation of duties violations across your organization. +You can use your conflict monitors to scope an [access review campaign](/product/admin/campaigns). When you create a campaign and select the **Access conflicts** review type, C1.ai generates review tasks for users who have active violations detected by your conflict monitors. This lets you systematically review and remediate separation of duties violations across your organization. To set up an access conflict campaign, see [Create an access review campaign](/product/admin/campaigns#step-2-choose-what-to-review). diff --git a/product/admin/access-requests.mdx b/product/admin/access-requests.mdx index 89de58b8..8e9bb6a0 100644 --- a/product/admin/access-requests.mdx +++ b/product/admin/access-requests.mdx @@ -1,6 +1,6 @@ --- title: Configure access requests -og:title: Configure access requests - C1 docs +og:title: Configure access requests - C1.ai docs og:description: Manage access requests by configuring the visibility, policy, and provisioning rules for applications and their entitlements. description: Manage access requests by configuring the visibility, policy, and provisioning rules for applications and their entitlements. --- @@ -8,7 +8,7 @@ description: Manage access requests by configuring the visibility, policy, and p ## Set who can request access -C1 has two methods to help you organize and control which apps and entitlements your colleagues can see and request. +C1.ai has two methods to help you organize and control which apps and entitlements your colleagues can see and request. | Method | Best for | | :--- | :--- | @@ -18,7 +18,7 @@ C1 has two methods to help you organize and control which apps and entitlements ### Set the standard audience for an app and select requestable entitlements -A **Super Admin** or an application owner with the **Application Admin** role in C1 must complete this task. +A **Super Admin** or an application owner with the **Application Admin** role in C1.ai must complete this task. Setting an app's standard audience is the quickest way to make select entitlements in the app available for [access requests](/product/how-to/create-requests). The standard audience for an app can be: @@ -108,7 +108,7 @@ Use the **Request policy** dropdown to locate and select the the [approval polic If a time limit should apply to grants of entitlements of your selected resource types, click to turn on **Max request duration** and select the time limit. - At the end of the time limit, the user's access will be automatically revoked. C1 sends the user reminders before the access expires, at 30 days, 14 days, three days, one day, and one hour out (whichever of these apply to the grant's duration), so that an extension can be requested if needed. + At the end of the time limit, the user's access will be automatically revoked. C1.ai sends the user reminders before the access expires, at 30 days, 14 days, three days, one day, and one hour out (whichever of these apply to the grant's duration), so that an extension can be requested if needed. If the entitlements of your selected resource types should be available for [emergency access requests](/product/admin/emergency), click to turn on **Emergency access** and select the emergency access policy that will apply to these requests. @@ -193,7 +193,7 @@ Select the account [provisioning method](/product/admin/provisioning) this appli - **Connector**: This option uses the connector you select to automatically provision the new account. Not all connectors [support account provisioning](/product/admin/account-provisioning#supported-systems), and the configuration and permissions of the connector must be set up to allow provisioning where it is supported. [Review the setup instructions for automatic account provisioning](/product/admin/account-provisioning). - If you choose this option but automatic provisioning via the connector isn't available, C1 will fall back to manual provisioning and assign the provisioning task to the [application owner](/product/admin/applications). + If you choose this option but automatic provisioning via the connector isn't available, C1.ai will fall back to manual provisioning and assign the provisioning task to the [application owner](/product/admin/applications). - **Manual**: This option prompts you to select a designated human provisioner or provisioners who will manually create the new app account. When account access is granted, a [provisioning task](/product/how-to/access-change-tasks#complete-a-provisioning-task) will be assigned to the provisioner you set here. (If multiple provisioners are set, each will be assigned the same task, each will receive a notification, but just one needs to complete the task.) You also have the option to enter instructions about how to provision the new account. These instructions will be included in the provisioning task. @@ -203,15 +203,15 @@ Select the account [provisioning method](/product/admin/provisioning) this appli - You configure provisioning on Entitlement A, choosing **Delegated** and selecting Entitlement B from the dropdown. - - C1 creates an entitlement binding for you between Entitlement B and Entitlement A. To see the binding's details, navigate to either entitlement's details page and click **Bindings**. + - C1.ai creates an entitlement binding for you between Entitlement B and Entitlement A. To see the binding's details, navigate to either entitlement's details page and click **Bindings**. - Entitlement B has been configured to use its connector for provisioning. When a user requests access to Entitlement B and their request is approved, the connector automatically adds access to both Entitlement B and Entitlement A to the user's application account. - C1 automatically creates the binding for you. You'll see the proposed change to the entitlement's bindings whenever you make a change to delegated provisioning, both when the change is automatically creating a new binding for you, and when a binding will be removed if you change the provisioning strategy from delegated to manual or connector-based. + C1.ai automatically creates the binding for you. You'll see the proposed change to the entitlement's bindings whenever you make a change to delegated provisioning, both when the change is automatically creating a new binding for you, and when a binding will be removed if you change the provisioning strategy from delegated to manual or connector-based. - **Webhook**: This option prompts you to select a webhook. Before you can use this option you must [configure a webhook](/product/admin/webhooks) on the **Webhooks** tab of the **Settings** page. Whenever a user is granted access to the entitlement, the webhook will automatically fire. You can use webhooks to automate provisioning workflows for approved access, such as creating a Jira or ServiceDesk ticket or making an API call. - - **External ticketing**: This option prompts you to select an external ticketing system, which much be configured in order to use this option (see [External ticketing](/product/admin/external-ticketing) for instructions). C1 automatically creates a helpdesk ticket in the integrated system each time account provisioning is required. C1 will track the progress of the helpdesk ticket and update or close the provisioning task accordingly. + - **External ticketing**: This option prompts you to select an external ticketing system, which much be configured in order to use this option (see [External ticketing](/product/admin/external-ticketing) for instructions). C1.ai automatically creates a helpdesk ticket in the integrated system each time account provisioning is required. C1.ai will track the progress of the helpdesk ticket and update or close the provisioning task accordingly. @@ -224,7 +224,7 @@ Click **Save**. **What happens if a user is granted access to an entitlement but does not yet have an account in the app?** -You can instruct C1 to automatically make a new app account for any user who does not yet have an account but has been approved for access to an entitlement in the app. To do so, enable **Auto-request accounts** on the **Entitlement management** card. +You can instruct C1.ai to automatically make a new app account for any user who does not yet have an account but has been approved for access to an entitlement in the app. To do so, enable **Auto-request accounts** on the **Entitlement management** card. ## Automatically revoke inherited access @@ -247,11 +247,11 @@ Scroll to the **Entitlement management** card and toggle on **Revoke inherited a -**Done.** When access to an entitlement in this app is revoked, C1 also revokes the upstream grants it was inherited from. A banner shows the downstream effects before an approver commits to the revocation, so nothing gets revoked as a surprise. +**Done.** When access to an entitlement in this app is revoked, C1.ai also revokes the upstream grants it was inherited from. A banner shows the downstream effects before an approver commits to the revocation, so nothing gets revoked as a surprise. ## Set how app accounts are deprovisioned -By default, C1 will attempt to infer the correct account deprovisioning process based on whatever process you've set up for account provisioning. **You only need to proactively configure account deprovisioning if you want to use a different process from the one you've set up for account provisioning.** +By default, C1.ai will attempt to infer the correct account deprovisioning process based on whatever process you've set up for account provisioning. **You only need to proactively configure account deprovisioning if you want to use a different process from the one you've set up for account provisioning.** To select the [deprovisioning method](/product/admin/provisioning) this application will use for revoked app accounts: @@ -270,7 +270,7 @@ Select the account [deprovisioning method](/product/admin/provisioning) this app - **Connector**: This option uses the connector you select to automatically deprovision the account. Not all connectors [support account deprovisioning](/product/admin/account-provisioning#supported-systems), and the configuration and permissions of the connector must be set up to allow deprovisioning where it is supported. [Review the setup instructions for automatic account provisioning](/product/admin/account-provisioning). - If you choose this option but automatic deprovisioning via the connector isn't available, C1 will fall back to manual deprovisioning and assign the deprovisioning task to the [application owner](/product/admin/applications#customize-an-app). + If you choose this option but automatic deprovisioning via the connector isn't available, C1.ai will fall back to manual deprovisioning and assign the deprovisioning task to the [application owner](/product/admin/applications#customize-an-app). - **Manual**: This option prompts you to select a designated human deprovisioner or deprovisioners who will manually deprovision the app account. When the app account is revoked, a [deprovisioning task](/product/how-to/access-change-tasks#complete-a-deprovisioning-task) will be assigned to the deprovisioner you set here. (If multiple deprovisioners are set, each will be assigned the same task, each will receive a notification, but just one needs to complete the task.) You also have the option to enter instructions about how to deprovision this account. These instructions will be included in the deprovisioning task. @@ -280,15 +280,15 @@ Select the account [deprovisioning method](/product/admin/provisioning) this app - You configure deprovisioning on Entitlement A, choosing **Delegated** and selecting Entitlement B from the dropdown. - - C1 creates an entitlement binding for you between Entitlement B and Entitlement A. To see the binding's details, navigate to either entitlement's details page and click **Bindings**. + - C1.ai creates an entitlement binding for you between Entitlement B and Entitlement A. To see the binding's details, navigate to either entitlement's details page and click **Bindings**. - Entitlement B has been configured to use its connector for deprovisioning. When a user's access to Entitlement B is revoked, the connector automatically removes access to both Entitlement B and Entitlement A from the user. - C1 automatically creates the binding for you. You'll see the proposed change to the entitlement's bindings whenever you make a change to delegated provisioning, both when the change is automatically creating a new binding for you, and when a binding will be removed if you change the provisioning strategy from delegated to manual or connector-based. + C1.ai automatically creates the binding for you. You'll see the proposed change to the entitlement's bindings whenever you make a change to delegated provisioning, both when the change is automatically creating a new binding for you, and when a binding will be removed if you change the provisioning strategy from delegated to manual or connector-based. - **Webhook**: This option prompts you to select a webhook. Before you can use this option you must [configure a webhook](/product/admin/webhooks) on the **Webhooks** tab of the **Settings** page. Whenever a user's app account is revoked, the webhook will automatically fire. You can use webhooks to automate deprovisioning workflows for revoked access, such as creating a Jira or ServiceDesk ticket or making an API call. - - **External ticketing**: This option prompts you to select an external ticketing system, which much be configured in order to use this option (see [External ticketing](/product/admin/external-ticketing) for instructions). C1 automatically creates a helpdesk ticket in the integrated system each time deprovisioning is required. C1 will track the progress of the helpdesk ticket and update or close the deprovisioning task accordingly. + - **External ticketing**: This option prompts you to select an external ticketing system, which much be configured in order to use this option (see [External ticketing](/product/admin/external-ticketing) for instructions). C1.ai automatically creates a helpdesk ticket in the integrated system each time deprovisioning is required. C1.ai will track the progress of the helpdesk ticket and update or close the deprovisioning task accordingly. If necessary, add additional steps to the deprovisioning process by clicking **Add step**. @@ -307,7 +307,7 @@ Configure the approval and revocation policies, max request duration, and emerge ### 📋 Your access request configuration workflow -C1 applies policy, grant duration, and emergency access settings using this order of precedence: +C1.ai applies policy, grant duration, and emergency access settings using this order of precedence: 1. The entitlement's configuration 2. The configuration on specific resource types @@ -375,7 +375,7 @@ Use the **Request policy** dropdown to locate and select the the [approval polic If a time limit should apply to grants of entitlements of your selected resource types, click to turn on **Max request duration** and select the time limit. - At the end of the time limit, the user's access will be automatically revoked. C1 sends the user reminders before the access expires, at 30 days, 14 days, three days, one day, and one hour out (whichever of these apply to the grant's duration), so that an extension can be requested if needed. + At the end of the time limit, the user's access will be automatically revoked. C1.ai sends the user reminders before the access expires, at 30 days, 14 days, three days, one day, and one hour out (whichever of these apply to the grant's duration), so that an extension can be requested if needed. If the entitlements of your selected resource types should be available for [emergency access requests](/product/admin/emergency), click to turn on **Emergency access** and select the emergency access policy that will apply to these requests. @@ -423,7 +423,7 @@ In the configuration drawer, you'll see any settings that are currently applied 4. If a time limit should apply to grants of this entitlement, click to turn on **Max request duration** and select the time limit. - At the end of the time limit, the user's access will be automatically revoked. C1 sends the user reminders before the access expires, at 30 days, 14 days, three days, one day, and one hour out (whichever of these apply to the grant's duration), so that an extension can be requested if needed. + At the end of the time limit, the user's access will be automatically revoked. C1.ai sends the user reminders before the access expires, at 30 days, 14 days, three days, one day, and one hour out (whichever of these apply to the grant's duration), so that an extension can be requested if needed. Finally, if you want to preserve these settings from being overwritten by future updates to the app-level settings, enable **Lock configuration**. @@ -442,7 +442,7 @@ Once access is granted, it must be provisioned. Set the [provisioning method](/p **What happens if I don't set provisioning for an entitlement?** -If you do not make any provisioning selections for an entitlement, C1 will default to attempting to provision using the connector, and falling back to manual provisioning (assigned to the [application owner](/product/admin/managing-resources)) if connector provisioning fails. +If you do not make any provisioning selections for an entitlement, C1.ai will default to attempting to provision using the connector, and falling back to manual provisioning (assigned to the [application owner](/product/admin/managing-resources)) if connector provisioning fails. @@ -460,7 +460,7 @@ Locate the entitlement, and select **Edit provisioning** from the more actions ( Select the provisioning method the selected entitlement or entitlements will use: - - **Connector**: This option uses the connector to automatically provision the access. Not all connectors support provisioning, and the configuration and permissions of the connector must be set up to allow provisioning where it is supported. If you choose this option but automatic provisioning via the connector isn't available, C1 will fall back to manual provisioning and assign the provisioning task to the [application owner](/product/admin/applications#customize-an-app). + - **Connector**: This option uses the connector to automatically provision the access. Not all connectors support provisioning, and the configuration and permissions of the connector must be set up to allow provisioning where it is supported. If you choose this option but automatic provisioning via the connector isn't available, C1.ai will fall back to manual provisioning and assign the provisioning task to the [application owner](/product/admin/applications#customize-an-app). - **Manual**: This option prompts you to select a designated human provisioner or provisioners who will manually update the user's access. When access to the entitlement is granted, a [provisioning task](/product/how-to/access-change-tasks#complete-a-provisioning-task) will be assigned to the provisioner you set here. (If multiple provisioners are set, each will be assigned the same task, each will receive a notification, but just one needs to complete the task.) You also have the option to enter instructions about how to provision this entitlement. These instructions will be included in the provisioning task. @@ -470,15 +470,15 @@ Select the provisioning method the selected entitlement or entitlements will use - You configure provisioning on Entitlement A, choosing **Delegated** and selecting Entitlement B from the dropdown. - - C1 creates an entitlement binding for you between Entitlement B and Entitlement A. To see the binding's details, navigate to either entitlement's details page and click **Bindings**. + - C1.ai creates an entitlement binding for you between Entitlement B and Entitlement A. To see the binding's details, navigate to either entitlement's details page and click **Bindings**. - Entitlement B has been configured to use its connector for provisioning. When a user requests access to Entitlement B and their request is approved, the connector automatically adds access to both Entitlement B and Entitlement A to the user's application account. - C1 automatically creates the binding for you. You'll see the proposed change to the entitlement's bindings whenever you make a change to delegated provisioning, both when the change is automatically creating a new binding for you, and when a binding will be removed if you change the provisioning strategy from delegated to manual or connector-based. + C1.ai automatically creates the binding for you. You'll see the proposed change to the entitlement's bindings whenever you make a change to delegated provisioning, both when the change is automatically creating a new binding for you, and when a binding will be removed if you change the provisioning strategy from delegated to manual or connector-based. - **Webhook**: This option prompts you to select a webhook. Before you can use this option you must [configure a webhook](/product/admin/webhooks) on the **Webhooks** tab of the **Settings** page. Whenever a user is granted access to the entitlement, the webhook will automatically fire. You can use webhooks to automate provisioning workflows for approved access, such as creating a Jira or ServiceDesk ticket or making an API call. - - **External ticketing**: This option prompts you to select an external ticketing system, which much be configured in order to use this option (see [External ticketing](/product/admin/external-ticketing) for instructions). C1 automatically creates a helpdesk ticket in the integrated system each time provisioning is required. C1 will track the progress of the helpdesk ticket and update or close the provisioning task accordingly. + - **External ticketing**: This option prompts you to select an external ticketing system, which much be configured in order to use this option (see [External ticketing](/product/admin/external-ticketing) for instructions). C1.ai automatically creates a helpdesk ticket in the integrated system each time provisioning is required. C1.ai will track the progress of the helpdesk ticket and update or close the provisioning task accordingly. Click **Save**. The **Entitlements** table's **Provisioned by** column updates to show your changes. diff --git a/product/admin/account-provisioning.mdx b/product/admin/account-provisioning.mdx index 9df68f39..0dcbb98f 100644 --- a/product/admin/account-provisioning.mdx +++ b/product/admin/account-provisioning.mdx @@ -1,8 +1,8 @@ --- title: Configure account provisioning -og:title: Configure account provisioning - C1 docs -og:description: Certain C1 connectors can be configured to automatically create new accounts. -description: Certain C1 connectors can be configured to automatically create new accounts. +og:title: Configure account provisioning - C1.ai docs +og:description: Certain C1.ai connectors can be configured to automatically create new accounts. +description: Certain C1.ai connectors can be configured to automatically create new accounts. sidebarTitle: Provisioning new accounts --- {/* Editor Refresh: 2026-02-09 */} @@ -13,15 +13,15 @@ Consult the [Connector capabilities index](/baton/capabilities) to see the list **This list is growing!** We're actively working to add account provisioning and deprovisioning support to more connectors. -## How does C1 create new accounts? +## How does C1.ai create new accounts? -When manually creating a new account in an application, you enter the information the app requires, such as an email address, full name, or location. Once configured using the process below, C1 can automatically look up and provide that information to the application, which creates the new account. Read on to learn how it all works under the hood! +When manually creating a new account in an application, you enter the information the app requires, such as an email address, full name, or location. Once configured using the process below, C1.ai can automatically look up and provide that information to the application, which creates the new account. Read on to learn how it all works under the hood! ### Part 1: Account information is defined in a schema For purposes of this explanation, we'll say that SampleApp requires a first name, last name, and email in order to make a new account. -First, a **schema** is added to the SampleApp connector code that tells C1 what information is required in order to make a new user account. We've written the schemas for you in the supported systems listed above, but you can write your own as part of developing a connector. A schema looks like this: +First, a **schema** is added to the SampleApp connector code that tells C1.ai what information is required in order to make a new user account. We've written the schemas for you in the supported systems listed above, but you can write your own as part of developing a connector. A schema looks like this: ```go expandable AccountCreationSchema: &v2.ConnectorAccountCreationSchema{ @@ -63,7 +63,7 @@ Note that the schema contains three fields, which spell out the information need ### Part 2: CEL expressions pull in the required information -Next, you'll tell C1 how to use the accumulated user data in the system to create new accounts. To do this, you'll set up mappings that use CEL expressions to pull and format the user data to meet the application's requirements for a new account. +Next, you'll tell C1.ai how to use the accumulated user data in the system to create new accounts. To do this, you'll set up mappings that use CEL expressions to pull and format the user data to meet the application's requirements for a new account. That's a little complicated, so let's look at an example. Here's the account provisioning setup screen for an app. As you can see, the three fields set in the schema are shown here: email, given name, and family name. The notations to the right of the screen (`str`) show that the system expects each of these values as strings. @@ -77,17 +77,17 @@ Here's the same form with the source values (in the form of CEL expressions) fil Account provisioning setup drawer with CEL expressions added to the three required mapping fields and a tooltip showing the test information for the email field. -Now that this configuration is set up, C1 can pull the required info in the expected format and send it to SampleApp to create a new account. +Now that this configuration is set up, C1.ai can pull the required info in the expected format and send it to SampleApp to create a new account. ## Writing CEL expressions for mappings -The [CEL expressions](/product/admin/expressions) you enter when setting up mappings pull the relevant account data from the accumulated store of user data in C1. This means that much of the user data you'll want to reference is pulled from your [directory apps](/product/admin/directory). +The [CEL expressions](/product/admin/expressions) you enter when setting up mappings pull the relevant account data from the accumulated store of user data in C1.ai. This means that much of the user data you'll want to reference is pulled from your [directory apps](/product/admin/directory). -The `subject` object expressions (where `subject` refers to the C1 user) are especially helpful here. In particular, you might need to use the CEL expression `subject.attributes.` where `` can be replaced by any profile attributes pulled in from the relevant directory apps. You can see the available profile attributes by navigating to any user's details page. +The `subject` object expressions (where `subject` refers to the C1.ai user) are especially helpful here. In particular, you might need to use the CEL expression `subject.attributes.` where `` can be replaced by any profile attributes pulled in from the relevant directory apps. You can see the available profile attributes by navigating to any user's details page. -### Why can't C1 write these CEL expressions for me? +### Why can't C1.ai write these CEL expressions for me? -Because of the variety of ways that information is labeled and pulled in from the many directory apps C1 supports, there is significant variation in the way the CEL expressions must be formed. Additionally, based on the requirements and best practices of your organization, you might need the data returned in a specific format. One size, unfortunately, does not fit all. +Because of the variety of ways that information is labeled and pulled in from the many directory apps C1.ai supports, there is significant variation in the way the CEL expressions must be formed. Additionally, based on the requirements and best practices of your organization, you might need the data returned in a specific format. One size, unfortunately, does not fit all. Our Customer Success team is happy to lend a hand if you're struggling to set up your CEL expressions. You might also find it useful to work with an AI tool if you're unfamiliar with CEL syntax. @@ -119,7 +119,7 @@ Select **Connector** from the dropdown, then select the connector you set up for The mapping fields are pulled directly from the account provisioning schema in the connector's code. These are the values that the application requires in order to create a new account. -Write [CEL expressions](/product/admin/expressions) to tell C1 how to find the information required by the schema. +Write [CEL expressions](/product/admin/expressions) to tell C1.ai how to find the information required by the schema. If needed, add additional mapping fields by clicking **Add mapping**. @@ -142,9 +142,9 @@ When your mapping fields are complete and have been validated, click **Save**. ## Frequently asked questions about automatic account provisioning - + -If a user's key data (such as their name or location) changes, C1 does not currently have a mechanism to update the information on an automatically created account. The user's account information must be updated in the connected software, and the change will be pulled into C1 on the next connector sync. +If a user's key data (such as their name or location) changes, C1.ai does not currently have a mechanism to update the information on an automatically created account. The user's account information must be updated in the connected software, and the change will be pulled into C1.ai on the next connector sync. diff --git a/product/admin/agent-classifiers-configure.mdx b/product/admin/agent-classifiers-configure.mdx index 059e9db8..16581eeb 100644 --- a/product/admin/agent-classifiers-configure.mdx +++ b/product/admin/agent-classifiers-configure.mdx @@ -1,6 +1,6 @@ --- title: "Configure agent classifiers" -og:title: "Configure agent classifiers - C1 docs" +og:title: "Configure agent classifiers - C1.ai docs" description: "Create a classifier, bind it to a surface, author rules, attach hooks and tool gates, and promote rules from Observe to Enforce." og:description: "Create a classifier, bind it to a surface, author rules, attach hooks and tool gates, and promote rules from Observe to Enforce." sidebarTitle: "Configure agent classifiers" @@ -31,7 +31,7 @@ Enter a **Name** (required, up to 128 characters) and optionally a **Description Set **Applies to** — **Agent** or **Gateway**. Choose deliberately: it determines which risk signals your rules can read, and which selector the classifier appears in when you bind it. -Click **Create classifier**. C1 creates it and opens its detail page. +Click **Create classifier**. C1.ai creates it and opens its detail page. @@ -73,14 +73,14 @@ Only classifiers whose **Applies to** is **Agent** appear in these dropdowns. Th ### Gateway surface -For external AI clients connecting through the C1 Gateway: +For external AI clients connecting through the C1.ai Gateway: -Go to **AI > C1 Gateway > Settings**. +Go to **AI > C1.ai Gateway > Settings**. -Under **Default C1 Gateway Classifier policy**, select your classifier. +Under **Default C1.ai Gateway Classifier policy**, select your classifier. @@ -229,10 +229,10 @@ Because an Observe match falls through to the next rule, you can safely stage a ### Where to find Observe results -Every rule that matches a call — enforcing or observing — writes an event to the [C1 system log](/product/admin/system-log). There is no per-classifier activity view in C1, so the system log is where you read Observe results. +Every rule that matches a call — enforcing or observing — writes an event to the [C1.ai system log](/product/admin/system-log). There is no per-classifier activity view in C1.ai, so the system log is where you read Observe results. -C1 does not surface these events in the admin UI, and nothing notifies you when an Observe rule would have fired. To read them you need a [system log exporter](/product/admin/system-log#sync-c1-system-logs-into-your-siem) configured to your SIEM or data source. Set that up **before** you start an Observe rollout, or the traffic you were staging against passes unrecorded from your point of view. +C1.ai does not surface these events in the admin UI, and nothing notifies you when an Observe rule would have fired. To read them you need a [system log exporter](/product/admin/system-log#sync-c1-system-logs-into-your-siem) configured to your SIEM or data source. Set that up **before** you start an Observe rollout, or the traffic you were staging against passes unrecorded from your point of view. In the exported OCSF events, classifier decisions carry: diff --git a/product/admin/agent-classifiers-reference.mdx b/product/admin/agent-classifiers-reference.mdx index 6b0857f9..43da186e 100644 --- a/product/admin/agent-classifiers-reference.mdx +++ b/product/admin/agent-classifiers-reference.mdx @@ -1,6 +1,6 @@ --- title: "Agent classifiers reference" -og:title: "Agent classifiers reference - C1 docs" +og:title: "Agent classifiers reference - C1.ai docs" description: "Technical reference for agent classifiers: object model, rule and tool gate fields, CEL variables, enforcement surfaces, evaluation order, constraints, and troubleshooting." og:description: "Technical reference for agent classifiers: object model, rule and tool gate fields, CEL variables, enforcement surfaces, evaluation order, constraints, and troubleshooting." sidebarTitle: "Agent classifiers reference" @@ -44,7 +44,7 @@ A binding is the only thing that activates a classifier. Creating a classifier, | Surface | Governs | Bind at | Available CEL variables | | :--- | :--- | :--- | :--- | | **Agent** | C1AI agents | **AI > Classifiers** → **Default C1AI Classifier policy**, or an agent's **Classifiers** tab | `ctx.private_data`, `ctx.untrusted_content`, `ctx.exfiltration`, `ctx.tool_name` | -| **Gateway** | External AI clients through the C1 Gateway | **AI > C1 Gateway > Settings** → **Default C1 Gateway Classifier policy** | `ctx.private_data`, `ctx.exfiltration`, `ctx.tool_name` | +| **Gateway** | External AI clients through the C1.ai Gateway | **AI > C1.ai Gateway > Settings** → **Default C1.ai Gateway Classifier policy** | `ctx.private_data`, `ctx.exfiltration`, `ctx.tool_name` | **Applies to** is a two-way choice — **Agent** or **Gateway**. There is no option to target both. @@ -67,7 +67,7 @@ If no binding resolves for a surface — none configured, or it points at a dele | **Name** | Required. Up to 128 characters. | | **Description** | Optional. Up to 1024 characters. | | **Applies to** | **Agent** or **Gateway**. Determines which variables rules can read, and which binding selector the classifier appears in. | -| **Managed by** | **Tenant** for classifiers you author — freely editable. **System** marks a C1-curated classifier, which is read-only. | +| **Managed by** | **Tenant** for classifiers you author — freely editable. **System** marks a C1.ai-curated classifier, which is read-only. | ## Classifier rule fields @@ -172,7 +172,7 @@ Mode works exactly as it does on the tool-call path: **Disabled** and unset are ### Only two built-in patterns run here -**Block output** and **Link filter**. Every other built-in pattern is restricted to the tool-call events, and C1 rejects an incompatible event when you save the hook. +**Block output** and **Link filter**. Every other built-in pattern is restricted to the tool-call events, and C1.ai rejects an incompatible event when you save the hook. **Custom function hooks cannot run on this stage.** Saving a function hook with the Pre-output event is rejected. The stage is also fail-closed, so a function hook that did reach it would withhold every matching response rather than being ignored. @@ -256,7 +256,7 @@ A tool gate filter is evaluated against a different variable set than a classifi | `ctx.tool_kind` | `builtin`, `connector`, `c1_derived`, `unspecified` | | `ctx.caller_kind` | `c1aw`, `claw_builtin`, `code_mode`, `connector_manager`, `mcp_gateway`, `unspecified` | -Both fall back to `unspecified` for a value C1 doesn't recognize, so a filter written as an equality test against a specific kind won't match an unrecognized one. +Both fall back to `unspecified` for a value C1.ai doesn't recognize, so a filter written as an equality test against a specific kind won't match an unrecognized one. The in-product helper text on the filter field mentions only `ctx.tool_name` and `ctx.tool_input` — the two you'll use most. The rest are available. @@ -271,7 +271,7 @@ The in-product helper text on the filter field mentions only `ctx.tool_name` and | Default | On | | Configuration | A single on/off toggle at **AI > Classifiers > Settings** | | When off | The dimension **always scores as low risk** and the judge never runs | -| When it can't be reached at the start of a run | C1 seeds a cautious **MEDIUM** untrusted-content floor rather than treating the turn as low risk | +| When it can't be reached at the start of a run | C1.ai seeds a cautious **MEDIUM** untrusted-content floor rather than treating the turn as low risk | | When a mid-run rescore fails | The existing floor is kept; no new score is synthesized | There is no model selection, threshold, or per-agent judge configuration. @@ -300,7 +300,7 @@ Disabling the judge does not disable rules that read `ctx.untrusted_content` — Check, in order: -1. **Is it bound?** An unbound classifier is evaluated on zero calls. Check **Default C1AI Classifier policy** (agent) or **Default C1 Gateway Classifier policy** (gateway), and any per-agent override that might be shadowing the default. +1. **Is it bound?** An unbound classifier is evaluated on zero calls. Check **Default C1AI Classifier policy** (agent) or **Default C1.ai Gateway Classifier policy** (gateway), and any per-agent override that might be shadowing the default. 2. **Does the surface match?** An Agent classifier won't appear in the gateway selector, and vice versa. 3. **Are the rules in Observe?** Observe logs and falls through by design. 4. **Are the rules Disabled?** An unset mode behaves as disabled. diff --git a/product/admin/agent-classifiers.mdx b/product/admin/agent-classifiers.mdx index b4fb9dfe..f1634468 100644 --- a/product/admin/agent-classifiers.mdx +++ b/product/admin/agent-classifiers.mdx @@ -1,6 +1,6 @@ --- title: "Agent classifiers" -og:title: "Agent classifiers - C1 docs" +og:title: "Agent classifiers - C1.ai docs" description: "Classifiers are named, reusable rule cascades that decide what an AI agent may do on each tool call, based on how much private data, untrusted content, and exfiltration capability is in play." og:description: "Classifiers are named, reusable rule cascades that decide what an AI agent may do on each tool call, based on how much private data, untrusted content, and exfiltration capability is in play." sidebarTitle: "Agent classifiers" @@ -12,7 +12,7 @@ sidebarTitle: "Agent classifiers" **Early access.** This feature is in early access, which means it's undergoing ongoing testing and development while we gather feedback, validate functionality, and improve outputs. -A **classifier** is a named, reusable cascade of rules that C1 evaluates on every governed tool call. Each rule asks a question about the *risk shape* of the call — how sensitive the data in play is, whether the agent has been exposed to untrusted content, whether the call could exfiltrate — and decides what happens: allow it, run a set of hooks over it, require human approval, or block it outright. +A **classifier** is a named, reusable cascade of rules that C1.ai evaluates on every governed tool call. Each rule asks a question about the *risk shape* of the call — how sensitive the data in play is, whether the agent has been exposed to untrusted content, whether the call could exfiltrate — and decides what happens: allow it, run a set of hooks over it, require human approval, or block it outright. Classifiers exist because the risk of an agent action often isn't a property of the tool. `send_email` is harmless until the agent has just read a support ticket written by a stranger and is holding customer records. Access profiles can't express that; they only know whether the tool is reachable. A classifier can, because it evaluates the combination at call time. @@ -37,7 +37,7 @@ Classifiers exist because the risk of an agent action often isn't a property of ## The three risk signals -Every classifier rule is a CEL expression over the same small set of variables. Three of them are the risk axes C1 scores per call, each `LOW`, `MEDIUM`, or `HIGH`: +Every classifier rule is a CEL expression over the same small set of variables. Three of them are the risk axes C1.ai scores per call, each `LOW`, `MEDIUM`, or `HIGH`: | Variable | What it measures | | :--- | :--- | @@ -81,7 +81,7 @@ A classifier declares which surface it **applies to**, and a binding attaches it | Surface | Governs | Where you bind it | Signals available | | :--- | :--- | :--- | :--- | | **Agent** | C1AI agents acting in your tenant | **AI > Classifiers** → **Default C1AI Classifier policy**, or per-agent on an agent's **Classifiers** tab | All three risk signals | -| **Gateway** | External AI clients connecting through the C1 Gateway | **AI > C1 Gateway > Settings** → **Default C1 Gateway Classifier policy** | `ctx.private_data`, `ctx.exfiltration`, `ctx.tool_name` — no `ctx.untrusted_content` | +| **Gateway** | External AI clients connecting through the C1.ai Gateway | **AI > C1.ai Gateway > Settings** → **Default C1.ai Gateway Classifier policy** | `ctx.private_data`, `ctx.exfiltration`, `ctx.tool_name` — no `ctx.untrusted_content` | A classifier targets one surface or the other — you pick **Agent** or **Gateway** when you create it, and it only appears in that surface's binding selector. To cover both, create one classifier per surface. diff --git a/product/admin/ai-assistant.mdx b/product/admin/ai-assistant.mdx index 5f0e3235..d558e3d0 100644 --- a/product/admin/ai-assistant.mdx +++ b/product/admin/ai-assistant.mdx @@ -1,26 +1,26 @@ --- -title: Use the C1 AI assistant -og:title: Use the C1 AI assistant - C1 docs -og:description: Ask questions about your org's access data and take action directly from anywhere in C1. -description: Ask questions about your org's access data and take action directly from anywhere in C1. +title: Use the C1.ai AI assistant +og:title: Use the C1.ai AI assistant - C1.ai docs +og:description: Ask questions about your org's access data and take action directly from anywhere in C1.ai. +description: Ask questions about your org's access data and take action directly from anywhere in C1.ai. sidebarTitle: "Ask C1AI" --- {/* Editor Refresh: 2026-06-23 */} -The C1 AI assistant is available to all C1 users. Ask C1AI questions or tell it what you want to do, and it responds in the same language you write in. +The C1.ai AI assistant is available to all C1.ai users. Ask C1AI questions or tell it what you want to do, and it responds in the same language you write in. ## Where to use the assistant -You can interact with the C1 AI assistant in two places: +You can interact with the C1.ai AI assistant in two places: -- **In the C1 web app** — Click **Ask C1AI** in the bottom-right corner of any page. -- **In Slack** — Once the [C1 app for Slack](/product/admin/integration-for-Slack) is installed, you can DM the assistant from Slack. +- **In the C1.ai web app** — Click **Ask C1AI** in the bottom-right corner of any page. +- **In Slack** — Once the [C1.ai app for Slack](/product/admin/integration-for-Slack) is installed, you can DM the assistant from Slack. -The assistant does not expose a separate REST API for direct programmatic queries. If you need programmatic access to C1 data, use the [C1 REST API](/conductorone-api/api) or the [C1 MCP integration](/product/admin/c1-mcp), which lets external AI clients (such as Claude Desktop or Cursor) query the same C1 identity data. +The assistant does not expose a separate REST API for direct programmatic queries. If you need programmatic access to C1.ai data, use the [C1.ai REST API](/conductorone-api/api) or the [C1.ai MCP integration](/product/admin/c1-mcp), which lets external AI clients (such as Claude Desktop or Cursor) query the same C1.ai identity data. ## Open the assistant -Click **Ask C1AI** in the bottom-right corner of any page in C1. +Click **Ask C1AI** in the bottom-right corner of any page in C1.ai. @@ -30,9 +30,9 @@ The chat panel opens as a floating window. Use the controls in the panel's title ## Ask questions and take action -Type any question or request in the **Ask C1...** field and press **Enter**. +Type any question or request in the **Ask C1.ai...** field and press **Enter**. -Ask it anything about your org's access data: who has access to what, how your organization is structured, what's in your entitlement catalog, and more. Because the assistant has access to the same C1 data your role permits you to see — including IdP-sourced information about your org — it can reason across that data to answer questions that might otherwise require navigating multiple views. +Ask it anything about your org's access data: who has access to what, how your organization is structured, what's in your entitlement catalog, and more. Because the assistant has access to the same C1.ai data your role permits you to see — including IdP-sourced information about your org — it can reason across that data to answer questions that might otherwise require navigating multiple views. Ask when access changed and why it was granted: @@ -48,7 +48,7 @@ The assistant can also take action on what it finds. On your explicit approval, - Configure campaigns and conflict monitors - Build policies -The assistant always asks for your go-ahead before making any change. It can only act on what your C1 role permits — a user without policy management permissions, for example, won't be able to use the assistant to edit policies. +The assistant always asks for your go-ahead before making any change. It can only act on what your C1.ai role permits — a user without policy management permissions, for example, won't be able to use the assistant to edit policies. The assistant maintains context within a conversation, so you can start broad and follow up to narrow results. To start a fresh session, click **Ask C1AI** again. @@ -56,7 +56,7 @@ The assistant maintains context within a conversation, so you can start broad an Ask a reporting question and C1AI can respond with charts, stat cards, and tables instead of just a file download. Ask for multiple charts side by side — for example, "dashboard: grants trend and users by status side by side" — and they render together as an aligned grid, each with its own export option and list of sources. C1AI can also compose a full report in one response: aggregate stat cards, a trend chart, and a data table together, each showing the sources it was built from. -Trend charts (for example, grants vs. revocations, review decisions, or automation runs over time) are built directly from C1's pre-aggregated metrics, so they return fast and with exact numbers you can trace to their source, rather than being computed from raw records on the fly. +Trend charts (for example, grants vs. revocations, review decisions, or automation runs over time) are built directly from C1.ai's pre-aggregated metrics, so they return fast and with exact numbers you can trace to their source, rather than being computed from raw records on the fly. #### Verify report sources @@ -70,15 +70,15 @@ Click the copy icon next to any source to copy its query, or **Copy as Markdown* ## Get a personalized onboarding plan -When your C1 tenant is created, C1AI opens automatically with a short onboarding conversation. It asks a few questions about your organization — such as your industry, your organization's size, and what you're trying to accomplish first. If you signed up via SSO, C1AI also uses the identity provider it detected during setup to suggest a relevant starting point. +When your C1.ai tenant is created, C1AI opens automatically with a short onboarding conversation. It asks a few questions about your organization — such as your industry, your organization's size, and what you're trying to accomplish first. If you signed up via SSO, C1AI also uses the identity provider it detected during setup to suggest a relevant starting point. Based on your answers, C1AI builds a personalized onboarding plan: a set of categorized next steps. Some steps are agent-assisted, meaning C1AI can carry them out for you directly in the chat panel — for example, connecting an app — rather than you having to navigate to that part of the product yourself. -You can leave the onboarding plan and come back to it later — it's saved as a conversation like any other, so you can reopen it from **Recent chats**. If you'd rather set up C1 on your own, you can dismiss the plan at any time. +You can leave the onboarding plan and come back to it later — it's saved as a conversation like any other, so you can reopen it from **Recent chats**. If you'd rather set up C1.ai on your own, you can dismiss the plan at any time. ## Page context -When you open the assistant from a specific page in C1 — an application, a policy, an entitlement, and so on — the assistant pulls in context about that page and its related objects. A chip at the bottom of the chat panel shows what's in context. Use the toggle next to it to include or exclude that context from the conversation. +When you open the assistant from a specific page in C1.ai — an application, a policy, an entitlement, and so on — the assistant pulls in context about that page and its related objects. A chip at the bottom of the chat panel shows what's in context. Use the toggle next to it to include or exclude that context from the conversation. diff --git a/product/admin/ai-clients.mdx b/product/admin/ai-clients.mdx index d4823dad..f49871dc 100644 --- a/product/admin/ai-clients.mdx +++ b/product/admin/ai-clients.mdx @@ -1,24 +1,24 @@ --- title: Manage AI clients -description: Understand how AI clients register with C1, the lifecycle states they move through, and the controls available to admins. -og:title: Manage AI clients - C1 docs -og:description: Understand how AI clients register with C1, the lifecycle states they move through, and the controls available to admins. +description: Understand how AI clients register with C1.ai, the lifecycle states they move through, and the controls available to admins. +og:title: Manage AI clients - C1.ai docs +og:description: Understand how AI clients register with C1.ai, the lifecycle states they move through, and the controls available to admins. --- {/* Editor Refresh: 2026-09-02 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -An **AI client** is any registered AI agent that talks to C1 MCP — Claude Desktop, Claude Code, Cursor, ChatGPT, Copilot, custom agents, and so on. This page covers how clients are registered, the lifecycle states they move through, the controls you have over them, and the tenant policy that governs which client types are allowed in your tenant. +An **AI client** is any registered AI agent that talks to C1.ai MCP — Claude Desktop, Claude Code, Cursor, ChatGPT, Copilot, custom agents, and so on. This page covers how clients are registered, the lifecycle states they move through, the controls you have over them, and the tenant policy that governs which client types are allowed in your tenant. ## How clients register -C1 supports two registration methods: +C1.ai supports two registration methods: -- **Dynamic Client Registration (DCR)** — the AI client registers itself with C1 by calling the registration endpoint, receives a unique client ID and secret, and then authenticates the user. Each client instance gets its own credentials. -- **Client ID Metadata Document (CIMD)** — the AI client presents a metadata URL as its client ID (for example, `https://claude.ai/oauth/mcp-oauth-client-metadata`). C1 fetches and validates the metadata document on the fly. No per-instance registration step is needed — all instances of the same client share a single published identity. +- **Dynamic Client Registration (DCR)** — the AI client registers itself with C1.ai by calling the registration endpoint, receives a unique client ID and secret, and then authenticates the user. Each client instance gets its own credentials. +- **Client ID Metadata Document (CIMD)** — the AI client presents a metadata URL as its client ID (for example, `https://claude.ai/oauth/mcp-oauth-client-metadata`). C1.ai fetches and validates the metadata document on the fly. No per-instance registration step is needed — all instances of the same client share a single published identity. The registration method is determined by the AI client, not by the admin. Some clients (for example, Claude Desktop and Claude AI) use CIMD; others (for example, Cursor) use DCR. Both methods result in an AI connection bound to the authenticating user. @@ -38,7 +38,7 @@ The list shows every client registered against the tenant, with: | :--- | :--- | | **Name** | Client display name (for example, "Claude Desktop") | | **Type** | Personal / shared / service / ephemeral | -| **Owner** | C1 user the client is bound to | +| **Owner** | C1.ai user the client is bound to | | **State** | Active / hidden / closed / deleted (see lifecycle below) | | **Last used** | Timestamp of the last tool call | | **Toolsets** | Toolsets currently accessible to the client (via the user's access profiles) | @@ -47,7 +47,7 @@ You can filter by any column. Click a client to open its detail panel. ## Client lifecycle states -C1 transitions clients through four states. Thresholds are set at the tenant level (**Hide inactive clients after**: 1 day, **Close credentials after**: 1 month, **Delete closed clients after**: 3 months, each settable to zero to disable) but can be overridden per client. +C1.ai transitions clients through four states. Thresholds are set at the tenant level (**Hide inactive clients after**: 1 day, **Close credentials after**: 1 month, **Delete closed clients after**: 3 months, each settable to zero to disable) but can be overridden per client. | State | What it means | What the user sees | | :--- | :--- | :--- | @@ -73,7 +73,7 @@ To change which types are allowed: -Go to **AI > C1 Gateway > Settings**. +Go to **AI > C1.ai Gateway > Settings**. Edit **Allowed client types**. diff --git a/product/admin/aiam-overview.mdx b/product/admin/aiam-overview.mdx index d96b36ea..5b3f4916 100644 --- a/product/admin/aiam-overview.mdx +++ b/product/admin/aiam-overview.mdx @@ -1,48 +1,48 @@ --- title: AI access management overview -description: How C1 governs AI tool and resource access — MCP servers, tools, toolsets, and AI clients. -og:title: AI access management overview - C1 docs -og:description: How C1 governs AI tool and resource access — MCP servers, tools, toolsets, and AI clients. +description: How C1.ai governs AI tool and resource access — MCP servers, tools, toolsets, and AI clients. +og:title: AI access management overview - C1.ai docs +og:description: How C1.ai governs AI tool and resource access — MCP servers, tools, toolsets, and AI clients. sidebarTitle: How AIAM works --- {/* Editor Refresh: 2026-09-02 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -AI Access Management (AIAM) extends C1's identity governance platform to the AI tool layer. It acts as a control plane between AI clients (Claude Desktop, Cursor, ChatGPT, Copilot, and other MCP-compatible clients) and the downstream MCP servers those clients connect to. +AI Access Management (AIAM) extends C1.ai's identity governance platform to the AI tool layer. It acts as a control plane between AI clients (Claude Desktop, Cursor, ChatGPT, Copilot, and other MCP-compatible clients) and the downstream MCP servers those clients connect to. -When AIAM is enabled, every tool call from an AI client is routed through C1's identity-aware proxy. The proxy authenticates the caller, checks the tool call against the user's granted access profile, enforces any configured policy constraints, forwards the call to the downstream MCP server, and writes an audit log entry with full identity context. +When AIAM is enabled, every tool call from an AI client is routed through C1.ai's identity-aware proxy. The proxy authenticates the caller, checks the tool call against the user's granted access profile, enforces any configured policy constraints, forwards the call to the downstream MCP server, and writes an audit log entry with full identity context. AIAM covers the following capabilities: - Registering and configuring MCP servers (from the 3,000+ hosted catalog) - Discovering and classifying the tools and resources each server exposes - Governing tool access at a granular level — admins review, approve, or disable individual tools and control which tools each user and agent can call -- Governing resource access at a granular level — admins review, approve, or disable each static resource and URI template; C1 checks its linked read entitlement on every read +- Governing resource access at a granular level — admins review, approve, or disable each static resource and URI template; C1.ai checks its linked read entitlement on every read - Bundling approved tools into toolsets and binding them to access profiles -- Provisioning end-user and agent tool access through the standard C1 request and approval workflow +- Provisioning end-user and agent tool access through the standard C1.ai request and approval workflow - Vaulting and rotating downstream credentials so they are never exposed to end users or stored locally - Logging every tool call with identity, tool, parameter, and policy context for audit and compliance -C1's AI Connections feature has two sides. This page covers AI access management (AIAM) — governing outbound AI tool calls to external services like Salesforce and GitHub. If you want AI assistants to query C1's own identity data instead, see [C1 MCP](/product/admin/c1-mcp). +C1.ai's AI Connections feature has two sides. This page covers AI access management (AIAM) — governing outbound AI tool calls to external services like Salesforce and GitHub. If you want AI assistants to query C1.ai's own identity data instead, see [C1.ai MCP](/product/admin/c1-mcp). ## Key concepts | Concept | Description | | :--- | :--- | -| **MCP server** | A downstream service that exposes one or more tools via the Model Context Protocol. C1 hosts a curated catalog. | -| **C1 MCP** | The proxy your AI clients connect to. It accepts connections from AI clients, routes requests to the appropriate downstream servers, and enforces authorization on every tool call. AI clients connect to one URL — C1 MCP — not to each downstream server directly. | -| **Tool** | A single capability exposed by an MCP server (for example, `github_create_issue` or `salesforce_query`). C1 discovers tools automatically when an MCP server is registered. | -| **MCP resource** | A static resource or URI template exposed by an MCP server. C1 discovers it automatically. C1 checks its approval state and linked, resource-specific read entitlement on every read. Resources are not toolsets or catalog items. | -| **Toolset** | A named bundle of approved tools. Two kinds: C1-maintained per connector ("All approved tools" and "Read tools", suffixed with the server name) and custom (admin-curated). | -| **Access profile** | The same mechanism C1 already uses for traditional app access. A toolset is bound to an access profile, which carries the approval policy, expiry, and approvers. | +| **MCP server** | A downstream service that exposes one or more tools via the Model Context Protocol. C1.ai hosts a curated catalog. | +| **C1 MCP** | The proxy your AI clients connect to. It accepts connections from AI clients, routes requests to the appropriate downstream servers, and enforces authorization on every tool call. AI clients connect to one URL — C1.ai MCP — not to each downstream server directly. | +| **Tool** | A single capability exposed by an MCP server (for example, `github_create_issue` or `salesforce_query`). C1.ai discovers tools automatically when an MCP server is registered. | +| **MCP resource** | A static resource or URI template exposed by an MCP server. C1.ai discovers it automatically. C1.ai checks its approval state and linked, resource-specific read entitlement on every read. Resources are not toolsets or catalog items. | +| **Toolset** | A named bundle of approved tools. Two kinds: C1.ai-maintained per connector ("All approved tools" and "Read tools", suffixed with the server name) and custom (admin-curated). | +| **Access profile** | The same mechanism C1.ai already uses for traditional app access. A toolset is bound to an access profile, which carries the approval policy, expiry, and approvers. | | **AI client** | A specific registered AI client instance (for example, "Jess's Claude Desktop" or "the team's shared Cursor agent"). Registered via Dynamic Client Registration (DCR) or Client ID Metadata Document (CIMD). | -| **AI connection** | The authenticated link between a user's AI client and C1. When a user connects an AI client to C1, C1 creates an AI connection record that ties the client instance to the user's identity. Admins can view, manage, and revoke AI connections across the tenant. | +| **AI connection** | The authenticated link between a user's AI client and C1.ai. When a user connects an AI client to C1.ai, C1.ai creates an AI connection record that ties the client instance to the user's identity. Admins can view, manage, and revoke AI connections across the tenant. | | **Auth mode** | How an MCP server authenticates downstream. Supported methods include bearer token, custom header, basic auth, and OAuth2 (client credentials, service mode, per-user passthrough, and JWT bearer). | | **Client type** | A classification on each AI client: personal, shared, service, or ephemeral. Tenant-level policy controls which types are allowed. | @@ -50,15 +50,15 @@ C1's AI Connections feature has two sides. This page covers AI access management A typical end-to-end flow: -1. **Admin registers an MCP server** in C1 (for example, the GitHub MCP server) and configures its auth mode. -2. **C1 discovers the tools and resources** the server exposes. Tools begin as Unset; resources begin as Pending. +1. **Admin registers an MCP server** in C1.ai (for example, the GitHub MCP server) and configures its auth mode. +2. **C1.ai discovers the tools and resources** the server exposes. Tools begin as Unset; resources begin as Pending. 3. **Admin reviews and approves tools**, then bundles approved tools into a toolset. -4. **Admin reviews and approves resources**. C1 links each approved resource to its resource-specific read entitlement; resources remain independent of toolsets. +4. **Admin reviews and approves resources**. C1.ai links each approved resource to its resource-specific read entitlement; resources remain independent of toolsets. 5. **Admin binds the toolset to an access profile** with an approval policy. -6. **End user registers their AI client** with C1. -7. **End user requests the tool access profile** from the C1 catalog (web, Slack, or from their AI client). +6. **End user registers their AI client** with C1.ai. +7. **End user requests the tool access profile** from the C1.ai catalog (web, Slack, or from their AI client). 8. **Approver approves**, and the tool becomes available to the user's AI client. -9. **AI client calls a tool or reads a resource** → request hits C1 MCP → C1 checks the user's current access and the item's approval status → forwards to the downstream MCP server using the configured auth mode → returns the result, logging the operation. +9. **AI client calls a tool or reads a resource** → request hits C1.ai MCP → C1.ai checks the user's current access and the item's approval status → forwards to the downstream MCP server using the configured auth mode → returns the result, logging the operation. ## Where to go from here @@ -67,7 +67,7 @@ A typical end-to-end flow: - Setting up audit and compliance? See [Audit AI tool usage](/product/admin/audit-ai-tool-usage). - Ready to test your setup as an end user? See [Get started with AI tools](/product/how-to/ai-tools). - Need to approve a discovered resource or manage its access? See [Govern MCP resources](/product/admin/mcp-resources). -- Governing an MCP server that supports the standard? The gateway is one of two paths C1 governs. For servers that can verify C1-issued tokens, C1 can issue a scoped token and let the agent call the server directly. See [Enterprise-managed authorization](/product/admin/enterprise-managed-authorization/overview). +- Governing an MCP server that supports the standard? The gateway is one of two paths C1.ai governs. For servers that can verify C1.ai-issued tokens, C1.ai can issue a scoped token and let the agent call the server directly. See [Enterprise-managed authorization](/product/admin/enterprise-managed-authorization/overview). {/* LLM Note: For AI assistants interacting with ConductorOne's MCP gateway or writing diff --git a/product/admin/applications.mdx b/product/admin/applications.mdx index 10992c04..2190f9c6 100644 --- a/product/admin/applications.mdx +++ b/product/admin/applications.mdx @@ -1,6 +1,6 @@ --- title: Add and manage applications -og:title: Add and manage applications - C1 docs +og:title: Add and manage applications - C1.ai docs og:description: Applications provide visibility and management of accounts, entitlements, and permissions. description: Applications allow you to govern access and gain visibility into accounts and permissions. sidebarTitle: Add applications @@ -9,18 +9,18 @@ sidebarTitle: Add applications ## Your application inventory -Applications in C1 mirror the tools and services your organization uses. You'll have an application for each piece of software that you manage in C1. +Applications in C1.ai mirror the tools and services your organization uses. You'll have an application for each piece of software that you manage in C1.ai. On the **Apps** page there are three applications categories: -- **Managed apps:** These are the apps you've set up in C1 so it can provide visibility, governance, and automation. You're actively managing these apps with C1. +- **Managed apps:** These are the apps you've set up in C1.ai so it can provide visibility, governance, and automation. You're actively managing these apps with C1.ai. - **Unmanaged apps:** When you add a connector for an app that is an identity provider (IdP), SSO, or federation provider, the connector discovers the child apps inside of it. These apps are listed as unmanaged. You can move these apps to the **Managed** state (more on that below) or leave them as-is. - **Shadow apps:** These are apps that have been discovered in your environment but are likely not sanctioned for use by your organization's corporate IT. [Learn more about shadow apps](/product/admin/shadow-apps). -All newly created tenants start with a single managed app: the [C1 app](/product/admin/c1-for-c1). +All newly created tenants start with a single managed app: the [C1.ai app](/product/admin/c1-for-c1). ## Customize columns and export to CSV @@ -31,10 +31,10 @@ To export apps data to CSV, click **Generate CSV** above the **Apps** table. The ## Create a new application -Setting up a new application primarily involves telling C1 where the app's access data will be sourced from. +Setting up a new application primarily involves telling C1.ai where the app's access data will be sourced from. -A user with the **Application Admin** or **Super Admin** role in C1 must complete this task. +A user with the **Application Admin** or **Super Admin** role in C1.ai must complete this task. @@ -43,7 +43,7 @@ Navigate to the **Apps** page and click **New application**. The **Create app** -Choose the app's **primary source of data** — this decides how C1 keeps its accounts and entitlements current: +Choose the app's **primary source of data** — this decides how C1.ai keeps its accounts and entitlements current: * **Connector** to sync data automatically through a direct integration with the tool or service. Choose a connector from the catalog, or click **Browse all** to see the full list. You'll add credentials after the app is created. @@ -51,11 +51,11 @@ Choose the app's **primary source of data** — this decides how C1 keeps its ac Also select this option if you want to create a custom app that provisions access using webhooks or helpdesk tickets. - * **External data source** to read from a data source your team already connected to C1. Only data sources already connected to your organization are listed. + * **External data source** to read from a data source your team already connected to C1.ai. Only data sources already connected to your organization are listed. * **SSO application** to create a virtual app sourced from an application discovered in your identity provider. Assignments in your identity provider become the app's grants. - * **This app is empty** to track the app in C1 now and add data later. + * **This app is empty** to track the app in C1.ai now and add data later. If you chose **Connector** as the source, choose **how access is managed**: @@ -90,10 +90,10 @@ Click **Create app**. The new application's details page opens. When you add a connector for an app that is an identity provider (IdP), SSO, or federation provider, the connector discovers the apps that are inside of it. These apps are added to the **Unmanaged** app list. -A user with the **Super Administrator** role in C1 must complete this task. +A user with the **Super Administrator** role in C1.ai must complete this task. -If you want to bring an unmanaged app under C1 management so you can start enforcing access controls on it: +If you want to bring an unmanaged app under C1.ai management so you can start enforcing access controls on it: @@ -118,7 +118,7 @@ Click **Manage**. The unmanaged app becomes a new managed app. ## Customize an app -A **Super Admin** or an application owner with the **Application Admin** role in C1 must complete these tasks. +A **Super Admin** or an application owner with the **Application Admin** role in C1.ai must complete these tasks. ### Manage app owners @@ -127,7 +127,7 @@ Application owners can manage the configuration of the applications they own, ca You can assign app owners in two ways: -- **By user**: Add specific C1 users as direct owners. +- **By user**: Add specific C1.ai users as direct owners. - **By entitlement**: Add any entitlement from a connected app. All users currently assigned that entitlement automatically become owners of the app, and ownership updates as users are granted or removed from the entitlement. You can add up to 32 direct user owners and up to 32 entitlements as owners on each app. @@ -182,7 +182,7 @@ Click **Save icon**. -**Done.** The app's new icon is now shown throughout C1. +**Done.** The app's new icon is now shown throughout C1.ai. ## How connectors relate to apps @@ -190,16 +190,16 @@ Connectors provide data ingestion and orchestration functionality for a managed ### Should an app have multiple connectors? -In most cases, you'll only have a single connector for an application. However, it's not uncommon to need or want to have multiple data sources feeding into one application in C1. +In most cases, you'll only have a single connector for an application. However, it's not uncommon to need or want to have multiple data sources feeding into one application in C1.ai. For example, you might use a complex tool that requires multiple flat file uploads to fully represent the user and access data. In this case, you would add multiple file connectors to the application, one for each of the files. -You can also set up more than one connector of the same type in C1. For example, if your organization has two Okta orgs, add a second Okta connector by repeating the connector's standard setup flow. During setup, choose whether to add the new connector to an existing app or create a new app for it — optionally linking the new app to an application discovered in your identity provider. +You can also set up more than one connector of the same type in C1.ai. For example, if your organization has two Okta orgs, add a second Okta connector by repeating the connector's standard setup flow. During setup, choose whether to add the new connector to an existing app or create a new app for it — optionally linking the new app to an application discovered in your identity provider. ## Important notes about managing applications ### Delete applications with great caution! -If you delete an IdP, federation, or SSO provider application from C1, all of the applications that have been discovered within it, both those that are unmanaged and those you've moved to managed and added connectors to, will also be deleted. You'll have to manually recreate these apps and re-add connectors to them to continue managing them with C1. +If you delete an IdP, federation, or SSO provider application from C1.ai, all of the applications that have been discovered within it, both those that are unmanaged and those you've moved to managed and added connectors to, will also be deleted. You'll have to manually recreate these apps and re-add connectors to them to continue managing them with C1.ai. diff --git a/product/admin/attributes.mdx b/product/admin/attributes.mdx index 1e868d9f..68274746 100644 --- a/product/admin/attributes.mdx +++ b/product/admin/attributes.mdx @@ -1,33 +1,33 @@ --- title: Map user attributes -og:title: Map user attributes - C1 docs -og:description: Pull key user data from the apps you integrate with C1 into the platform with user attribute mapping. -description: Pull key user data from the apps you integrate with C1 into the platform with user attribute mapping. +og:title: Map user attributes - C1.ai docs +og:description: Pull key user data from the apps you integrate with C1.ai into the platform with user attribute mapping. +description: Pull key user data from the apps you integrate with C1.ai into the platform with user attribute mapping. sidebarTitle: Map user data --- {/* Editor Refresh: 2026-01-07 */} -Creating and managing user attributes requires the **Super Administrator** role in C1. +Creating and managing user attributes requires the **Super Administrator** role in C1.ai. ## Why are user attributes useful? If your company is like most, you have employee info stored in several different apps. For instance, your human resources (HR) app might hold the data on who everyone's manager is, while your identity provider (IdP) app has the details on job titles and departments. -To make sure all this critical employee data is imported and organized correctly, tell C1 which app to pull what data from, and how that data is labeled in the source app. This lets C1 build a single complete and accurate index of your company's employees using the data from one or multiple apps. +To make sure all this critical employee data is imported and organized correctly, tell C1.ai which app to pull what data from, and how that data is labeled in the source app. This lets C1.ai build a single complete and accurate index of your company's employees using the data from one or multiple apps. -Once mapped, user attributes can also be used across C1, such as when refining the scope of access reviews, defining C1 groups, and forming policies. +Once mapped, user attributes can also be used across C1.ai, such as when refining the scope of access reviews, defining C1.ai groups, and forming policies. ## What's the difference between standard and custom user attributes? -**Standard** user attributes are pre-defined by C1 (the list of these is shown below). This data is shown in the **User details** section of the user's page. +**Standard** user attributes are pre-defined by C1.ai (the list of these is shown below). This data is shown in the **User details** section of the user's page. Standard attribute data is displayed on each user's details page and on the summary tooltip that's shown when you hover over a user's name. It's useful for giving reviewers, admins, and managers a complete picture of who a user is when making decisions about access. **Custom** user attributes are defined by your organization. This data is shown in the **Profile attributes** section of the user's page. -Custom user attributes can be used across C1, including in access review scopes, C1 groups, policies, and profile types. +Custom user attributes can be used across C1.ai, including in access review scopes, C1.ai groups, policies, and profile types. ## Map standard user attributes @@ -35,7 +35,7 @@ Custom user attributes can be used across C1, including in access review scopes, If needed, you can [configure which attributes are pulled in by connectors](/baton/configure) and available for use in mapping. -Tell C1 where to find key pieces of employee data, which will be associated with every user account in C1. This is where you can specify that (for instance) an employee's ID should be pulled from the HR app, but job title and department should be read from the IdP. You'll then map the info types C1 looks for to the way that information is labeled in the source app. +Tell C1.ai where to find key pieces of employee data, which will be associated with every user account in C1.ai. This is where you can specify that (for instance) an employee's ID should be pulled from the HR app, but job title and department should be read from the IdP. You'll then map the info types C1.ai looks for to the way that information is labeled in the source app. @@ -66,15 +66,15 @@ Select one of the pre-loaded standard user attributes from the **Attribute name* If you select an attribute that has already been mapped, you'll see an error. -If **Directory Status** shows as **Unknown** for a user, C1 could not resolve a status value from the mapped source. Common causes: the user has no account in the mapped app, the mapped app hasn't synced successfully, or the source attribute is empty. Check the mapping under **Identities** > **Directory sources** > **Attribute manager** and verify the source app's sync status. For how `GetAppUserStatus` behaves in these cases when writing CEL expressions, see [user library functions](/product/admin/expressions-reference#user-library-functions). +If **Directory Status** shows as **Unknown** for a user, C1.ai could not resolve a status value from the mapped source. Common causes: the user has no account in the mapped app, the mapped app hasn't synced successfully, or the source attribute is empty. Check the mapping under **Identities** > **Directory sources** > **Attribute manager** and verify the source app's sync status. For how `GetAppUserStatus` behaves in these cases when writing CEL expressions, see [user library functions](/product/admin/expressions-reference#user-library-functions). -Select how you'll tell C1 where to find the source (or sources) of data for this attribute. Your options are **direct mapping** or using a **CEL expression**. You can use a combination of direct mapping and CEL expressions to set up fallback logic, or for attributes that accept multiple values, such as Additional Usernames. +Select how you'll tell C1.ai where to find the source (or sources) of data for this attribute. Your options are **direct mapping** or using a **CEL expression**. You can use a combination of direct mapping and CEL expressions to set up fallback logic, or for attributes that accept multiple values, such as Additional Usernames. * If you choose **Direct mapping**: - 1. In the **Application** box, select the app from which C1 should source the selected user attribute data. All the apps you have integrated with C1 are shown as options; you're not limited to only reading user attribute data from your directory. + 1. In the **Application** box, select the app from which C1.ai should source the selected user attribute data. All the apps you have integrated with C1.ai are shown as options; you're not limited to only reading user attribute data from your directory. 2. In the **Application attribute** box, select the label used in your selected app for the user attribute. @@ -82,15 +82,15 @@ Select how you'll tell C1 where to find the source (or sources) of data for this 3. **Optional.** Click **Add fallback source** or **Add another source** (for manager email, additional username, and additional email) and add additional mappings as fallback or additional sources of the user attribute data. - In the case of fallback sources, C1 will iterate through the list you create here until it finds a source with the data it's looking for. + In the case of fallback sources, C1.ai will iterate through the list you create here until it finds a source with the data it's looking for. - In the case of additional sources, multiple values are accepted, and C1 will attempt to capture the data from each source you list. + In the case of additional sources, multiple values are accepted, and C1.ai will attempt to capture the data from each source you list. 4. Click **Preview data** to see a preview of the info pulled by your attribute mapping. * If you choose **CEL expression**: - 1. Enter a CEL expression that tells C1 how to locate the data for this attribute mapping. See the [CEL expressions reference](/product/admin/expressions-reference) for help on forming CEL expressions. + 1. Enter a CEL expression that tells C1.ai how to locate the data for this attribute mapping. See the [CEL expressions reference](/product/admin/expressions-reference) for help on forming CEL expressions. 2. Click **Preview data** to see a preview of the info pulled by your attribute mapping. @@ -117,7 +117,7 @@ If a CEL-based attribute mapping runs into errors, you'll see an orange triangle Custom attributes are used to construct [profile types](/product/admin/profile-types). While most standard attributes are available in CEL expressions, only custom attributes can be bound to profile types. -Creating a custom attribute mapping is just the first step. For the attribute to appear on a C1 user's profile, you also need to bind it to a profile type and assign users to that profile type. See [How do custom attributes reach user profiles?](/product/admin/profile-types#how-do-custom-attributes-reach-user-profiles) for the full lifecycle. +Creating a custom attribute mapping is just the first step. For the attribute to appear on a C1.ai user's profile, you also need to bind it to a profile type and assign users to that profile type. See [How do custom attributes reach user profiles?](/product/admin/profile-types#how-do-custom-attributes-reach-user-profiles) for the full lifecycle. To create a custom user attribute: @@ -133,27 +133,27 @@ Click **Add attribute**. Select the **Custom** attribute type. -In the **Attribute name** box, type the name of the custom user attribute you're creating. This is the name that will be used to reference this attribute across C1. Attribute names must be globally unique. +In the **Attribute name** box, type the name of the custom user attribute you're creating. This is the name that will be used to reference this attribute across C1.ai. Attribute names must be globally unique. -Select how you'll tell C1 where to find the source of data for this attribute. Your options are **direct mapping** or using a **CEL expression**. +Select how you'll tell C1.ai where to find the source of data for this attribute. Your options are **direct mapping** or using a **CEL expression**. * If you choose **Direct mapping**: - 1. In the **Application** box, select the app from which C1 should source the selected user attribute data. All the apps you have integrated with C1 are shown as options; you're not limited to only reading user attribute data from your directory. + 1. In the **Application** box, select the app from which C1.ai should source the selected user attribute data. All the apps you have integrated with C1.ai are shown as options; you're not limited to only reading user attribute data from your directory. 2. In the **Application attribute** box, select the label used in your selected app for the user attribute. **Don't see the attribute you need?** Check to make sure that the application you've selected is connected and syncing data correctly. A sync error might be the cause of missing attributes. - 3. **Optional.** Click **Add fallback source** and add additional mappings as fallback sources of the user attribute data. C1 will iterate through the list you create here until it finds a source with the data it's looking for. + 3. **Optional.** Click **Add fallback source** and add additional mappings as fallback sources of the user attribute data. C1.ai will iterate through the list you create here until it finds a source with the data it's looking for. 4. Click **Preview data** to see a preview of the info pulled by your attribute mapping. * If you choose **CEL expression**: - 1. Enter a CEL expression that tells C1 how to locate the data for this attribute mapping. See the [CEL expressions reference](/product/admin/expressions-reference) for help on forming CEL expressions. + 1. Enter a CEL expression that tells C1.ai how to locate the data for this attribute mapping. See the [CEL expressions reference](/product/admin/expressions-reference) for help on forming CEL expressions. 2. Click **Preview data** to see a preview of the info pulled by your attribute mapping. diff --git a/product/admin/audit-ai-tool-usage.mdx b/product/admin/audit-ai-tool-usage.mdx index ec426796..843d7058 100644 --- a/product/admin/audit-ai-tool-usage.mdx +++ b/product/admin/audit-ai-tool-usage.mdx @@ -1,17 +1,17 @@ --- title: Audit AI tool usage -description: What C1 logs for AI tool calls, MCP resource reads, and AI system events, and where to find audit export options. -og:title: Audit AI tool usage - C1 docs -og:description: What C1 logs for AI tool calls, MCP resource reads, and AI system events, and where to find audit export options. +description: What C1.ai logs for AI tool calls, MCP resource reads, and AI system events, and where to find audit export options. +og:title: Audit AI tool usage - C1.ai docs +og:description: What C1.ai logs for AI tool calls, MCP resource reads, and AI system events, and where to find audit export options. --- {/* Editor Refresh: 2026-05-08 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -Every tool call and resource read that flows through C1 MCP is logged. This page covers what's captured and how to export it for long-term retention, SIEM ingestion, or compliance reviews. +Every tool call and resource read that flows through C1.ai MCP is logged. This page covers what's captured and how to export it for long-term retention, SIEM ingestion, or compliance reviews. ## What gets logged @@ -20,7 +20,7 @@ Each tool call produces one audit log entry with: | Field | Example | | :--- | :--- | | **Timestamp** | `2026-05-07T14:23:11Z` | -| **End user** | The C1 user the AI client is bound to | +| **End user** | The C1.ai user the AI client is bound to | | **AI client** | Client ID and display name | | **MCP server** | Registered server name | | **Tool** | Tool name (for example, `github_create_issue`) | @@ -28,7 +28,7 @@ Each tool call produces one audit log entry with: | **Denial reason** | Populated when result = denied (for example, "tool not in user's access profile", "kill switch active", "client closed") | | **Latency** | Round-trip time for the call | -Each MCP resource read also produces an audit log entry. It includes the end user, AI client, MCP server, resource URI or URI template, result, denial reason when applicable, latency, and response byte count. C1 does not store resource content in the audit event. +Each MCP resource read also produces an audit log entry. It includes the end user, AI client, MCP server, resource URI or URI template, result, denial reason when applicable, latency, and response byte count. C1.ai does not store resource content in the audit event. In addition to tool call events, the following non-call events are also captured: @@ -51,4 +51,4 @@ When an approval policy step is assigned to an agent, each evaluation is attribu ## Export the audit log -AI tool usage events are included in the C1 system log. To set up export to S3 or another data source for SIEM ingestion, see [System logs](/product/admin/system-log). +AI tool usage events are included in the C1.ai system log. To set up export to S3 or another data source for SIEM ingestion, see [System logs](/product/admin/system-log). diff --git a/product/admin/automation-actions.mdx b/product/admin/automation-actions.mdx index a3265b74..d8f4fb5c 100644 --- a/product/admin/automation-actions.mdx +++ b/product/admin/automation-actions.mdx @@ -1,6 +1,6 @@ --- title: Configure requestable automations -og:title: Configure requestable automations - C1 docs +og:title: Configure requestable automations - C1.ai docs og:description: Requestable automations let you safely expose powerful automations to business users and agents without giving them standing admin access. description: Requestable automations let you safely expose powerful automations to business users and agents without giving them standing admin access. sidebarTitle: Requestable automations @@ -9,7 +9,7 @@ sidebarTitle: Requestable automations ## What are requestable automations? -A requestable automation is a [C1 automation](/product/admin/automations) that you make requestable to end users. Unlike standard automations that are triggered by schedules or events, requestable automations are user-driven workflows, such as creating a new GitHub repo or requesting replacement hardware. Requestable automations maintain strict governance while removing IT as a manual bottleneck for repetitive workflows. +A requestable automation is a [C1.ai automation](/product/admin/automations) that you make requestable to end users. Unlike standard automations that are triggered by schedules or events, requestable automations are user-driven workflows, such as creating a new GitHub repo or requesting replacement hardware. Requestable automations maintain strict governance while removing IT as a manual bottleneck for repetitive workflows. ### How do requestable automations work? @@ -21,12 +21,12 @@ The lifecycle of a requestable automation connects automated workflows with huma 3. **Governance gate:** Every request is governed by a policy-driven approval. The automation pauses for human review or auto-approves based on your risk logic, providing a consistent control layer across systems. -4. **Execution and logging:** Once approved, C1 runs the steps using the requester's form inputs. Every action, from the request to the final step, is captured in an end-to-end audit log. +4. **Execution and logging:** Once approved, C1.ai runs the steps using the requester's form inputs. Every action, from the request to the final step, is captured in an end-to-end audit log. ## Create a requestable automation -A user with the **Super Admin** role in C1 must complete this task. +A user with the **Super Admin** role in C1.ai must complete this task. ### Plan the use case @@ -89,7 +89,7 @@ In the **Request form** section, use the dropdown to select **Create new form**. Give the new form a name and description. - Remember that this form will be available as an option across your C1 installation, so choose a name that will help your colleagues understand the form's purpose. + Remember that this form will be available as an option across your C1.ai installation, so choose a name that will help your colleagues understand the form's purpose. Select the data type for your first field. The current options are: @@ -98,7 +98,7 @@ Select the data type for your first field. The current options are: * Text area (a multi-line text field) * Dropdown * Date (a date picker) -* User (a searchable dropdown of C1 users) +* User (a searchable dropdown of C1.ai users) Fill in the field label and provide dropdown options, helper text, a default value, and a placeholder, as needed. The required and available elements vary by field type. Here's an overview of where these elements are shown in the form: @@ -117,7 +117,7 @@ For text and text area fields, choose whether the field is required. A user cann As needed, click **Add field** and repeat the steps above to add additional fields. - Avoid collecting data C1 already has. Requester identity (ID, email, name) is always available and does not need to be requested again. + Avoid collecting data C1.ai already has. Requester identity (ID, email, name) is always available and does not need to be requested again. @@ -182,7 +182,7 @@ Once you have configured your requestable automation, perform a dry run to ensur **Validate the form and policy:** Ensure the field labels are clear for requesters and that the approval policy correctly gates or auto-approves the request based on your logic. -**Audit the execution:** After approval, verify that the automation steps completed successfully in the downstream system and that the C1 task log accurately captures the inputs and outcomes. +**Audit the execution:** After approval, verify that the automation steps completed successfully in the downstream system and that the C1.ai task log accurately captures the inputs and outcomes. **Check error handling:** Intentionally trigger an error (such as a missing required field or a connector timeout) to ensure the resulting task status and notifications provide enough context for troubleshooting. @@ -216,7 +216,7 @@ All app-specific automations are also listed on the **Automations** page. Only u ## Best practices and examples -Requestable automations are most effective for operations that are currently managed via manual tickets, shared credentials, or ad-hoc scripts. By moving these into C1, you gain reliable audit evidence and empower non-IT staff to perform controlled changes. +Requestable automations are most effective for operations that are currently managed via manual tickets, shared credentials, or ad-hoc scripts. By moving these into C1.ai, you gain reliable audit evidence and empower non-IT staff to perform controlled changes. ### Common patterns diff --git a/product/admin/automation-circuit-breaker.mdx b/product/admin/automation-circuit-breaker.mdx index 12d54d06..5e4bad1e 100644 --- a/product/admin/automation-circuit-breaker.mdx +++ b/product/admin/automation-circuit-breaker.mdx @@ -1,6 +1,6 @@ --- title: "Automation circuit breaker" -og:title: "Automation circuit breaker - C1 docs" +og:title: "Automation circuit breaker - C1.ai docs" description: "Set a rate limit on an automation to pause it automatically if it runs too many times within a set period." og:description: "Set a rate limit on an automation to pause it automatically if it runs too many times within a set period." sidebarTitle: "Circuit breaker" @@ -8,7 +8,7 @@ sidebarTitle: "Circuit breaker" {/* Editor Refresh: 2026-05-15 */} -The circuit breaker lets you set a rate limit on an individual automation. If the automation runs more than a configured number of times within a set period, C1 automatically pauses it — queuing new trigger events for review rather than running them immediately. +The circuit breaker lets you set a rate limit on an individual automation. If the automation runs more than a configured number of times within a set period, C1.ai automatically pauses it — queuing new trigger events for review rather than running them immediately. Automations triggered by directory or connector sync events — such as account status changes or group membership changes — are good candidates. These automations can fire at unexpectedly high volume during bulk imports, misconfigured rules, or data quality issues. @@ -34,7 +34,7 @@ Click **Save**. ## When the circuit breaker trips -When the automation exceeds its configured rate within the set period, C1 pauses it. An **Automation paused: too many executions** warning banner appears at the top of the automation's page. New trigger events continue to create paused executions that queue for review without running. +When the automation exceeds its configured rate within the set period, C1.ai pauses it. An **Automation paused: too many executions** warning banner appears at the top of the automation's page. New trigger events continue to create paused executions that queue for review without running. ## Resolve a tripped circuit breaker diff --git a/product/admin/automation-examples.mdx b/product/admin/automation-examples.mdx index 3b309eb5..be997f36 100644 --- a/product/admin/automation-examples.mdx +++ b/product/admin/automation-examples.mdx @@ -39,7 +39,7 @@ subject.employmentType == "FULL_TIME" && subject.status == "ENABLED" 3. Add a **Grant Entitlements** step. Select the entitlements every new employee should receive (for example, email, Slack, HRIS). Set the target user to the trigger's subject user. -4. Add a **Create Account** step. Select the connector for a department-specific tool (for example, Jira for Engineering, Salesforce for Sales). Use the "From C1 user data" creation method to map the user's profile fields automatically. +4. Add a **Create Account** step. Select the connector for a department-specific tool (for example, Jira for Engineering, Salesforce for Sales). Use the "From C1.ai user data" creation method to map the user's profile fields automatically. 5. Add a **Send Slack Message** step. Set the channel to `#new-hires` and the message to: ``` @@ -62,7 +62,7 @@ Create a copy of this automation with an **On Demand** trigger. Run it manually, ## Employee offboarding -**Use case:** When a user's status changes to disabled, revoke their access, update their C1 status, and notify the security team. +**Use case:** When a user's status changes to disabled, revoke their access, update their C1.ai status, and notify the security team. ### What you'll build diff --git a/product/admin/automations-steps-reference.mdx b/product/admin/automations-steps-reference.mdx index dcefc155..3fcc5af5 100644 --- a/product/admin/automations-steps-reference.mdx +++ b/product/admin/automations-steps-reference.mdx @@ -1,6 +1,6 @@ --- title: "Automation steps reference" -description: "A reference guide to all available automation steps in C1, including how to configure fields, handle errors, and reference step output in downstream steps." +description: "A reference guide to all available automation steps in C1.ai, including how to configure fields, handle errors, and reference step output in downstream steps." sidebarTitle: "Automation steps" --- @@ -40,7 +40,7 @@ Posts a notification to a Slack channel or as a direct message to one or more us | Field | Required | CEL | Notes | |---|---|---|---| | Send to | Yes | No | Select **Channel** | -| Slack channel name | Yes | Yes | Must match an existing channel the C1 app for Slack can access | +| Slack channel name | Yes | Yes | Must match an existing channel the C1.ai app for Slack can access | | Message | Yes | Yes | Plain text. Supports template variables | **Direct message** @@ -51,7 +51,7 @@ Posts a notification to a Slack channel or as a direct message to one or more us | Recipients | Yes | Yes | **Subject user** sends to the automation's subject user. **Specific users** lets you select recipients by name. You can also write a CEL expression to identify recipients dynamically. | | Message | Yes | Yes | Plain text. Supports template variables | -**Error behavior:** Fails if the channel doesn't exist or the C1 app for Slack doesn't have access, or if a recipient doesn't have a linked Slack account. Requires the [C1 app for Slack](/product/admin/integration-for-Slack) to be configured. +**Error behavior:** Fails if the channel doesn't exist or the C1.ai app for Slack doesn't have access, or if a recipient doesn't have a linked Slack account. Requires the [C1.ai app for Slack](/product/admin/integration-for-Slack) to be configured. --- @@ -147,7 +147,7 @@ Unenrolls a user from one or more access profiles, stopping automatic access pro ## Modify user status -Changes a user's account status in C1. +Changes a user's account status in C1.ai. | Field | Required | CEL | Notes | |---|---|---|---| @@ -193,7 +193,7 @@ When debugging chained automations, check execution history on both the parent a ## Perform task action -Manages existing C1 tasks by taking actions like reassigning, completing, or canceling them. +Manages existing C1.ai tasks by taking actions like reassigning, completing, or canceling them. | Field | Required | CEL | Notes | |---|---|---|---| @@ -248,7 +248,7 @@ Not every connector supports this step. Check the connector's page under [suppor **Error behavior:** Fails if the target account can't be resolved, or if the connector is offline. -This step is different from **Modify user status**, which only changes the user's status inside C1 and does not reach the connector. It's also different from **Perform connector action** — for connectors that support account lifecycle actions, enabling and disabling always goes through this step instead. +This step is different from **Modify user status**, which only changes the user's status inside C1.ai and does not reach the connector. It's also different from **Perform connector action** — for connectors that support account lifecycle actions, enabling and disabling always goes through this step instead. --- @@ -289,12 +289,12 @@ Provisions a new account in a connected application. | Field | Required | CEL | Notes | |---|---|---|---| | Connector name | Yes | No | The target connector | -| Creation method | Yes | No | "Custom" or "From C1 user data" | +| Creation method | Yes | No | "Custom" or "From C1.ai user data" | | Additional values | Varies | Yes | Fields depend on the connector schema and creation method | ### Creation methods -- **From C1 user data**: Automatically maps the C1 user's profile fields (name, email, department, and so on) to the target app's account schema. Use this when the target app's fields align with standard user attributes. +- **From C1.ai user data**: Automatically maps the C1.ai user's profile fields (name, email, department, and so on) to the target app's account schema. Use this when the target app's fields align with standard user attributes. - **Custom**: Manually specify each field value. Use this when the target app requires fields that don't map directly from the user profile, or when you need to compute values (for example, generating a username from the email prefix using CEL). **Error behavior:** Fails if the connector doesn't support account creation, required fields are missing, or an account already exists for the user in the target app (behavior depends on the connector). @@ -303,7 +303,7 @@ Provisions a new account in a connected application. ## Call function -Executes a [C1 Function](/product/admin/functions) with specified input parameters, enabling custom logic and transformations within your automation. +Executes a [C1.ai Function](/product/admin/functions) with specified input parameters, enabling custom logic and transformations within your automation. | Field | Required | CEL | Notes | |---|---|---|---| @@ -356,7 +356,7 @@ Generates a random password using either a preset 32-character random password o ## Set credential -This step is in early access. If you're interested in using it, please contact the C1 Support team to request access. +This step is in early access. If you're interested in using it, please contact the C1.ai Support team to request access. Apply a credential to a user's account in a connected application. @@ -368,7 +368,7 @@ Apply a credential to a user's account in a connected application. | Field | Required | CEL | Notes | |---|---|---|---| | Connector | Yes | No | Only connectors that support credential actions appear in the picker. | -| Target account | Yes | Yes | The account to set the credential on. Accepts `ctx.trigger.app_user_id` or a CEL expression resolving to a C1 app user ID. For new accounts, pass the output of the Create account step. | +| Target account | Yes | Yes | The account to set the credential on. Accepts `ctx.trigger.app_user_id` or a CEL expression resolving to a C1.ai app user ID. For new accounts, pass the output of the Create account step. | | Credential | Yes | No | Reference to the Generate password step output: `ctx.{generate_step_name}.credential_ref`. | **Error behavior:** Fails if the target account can't be resolved, the account isn't connected to the selected connector, or the connector is offline. Check the connector's sync status on the application page if this step fails. @@ -377,13 +377,13 @@ Apply a credential to a user's account in a connected application. ## Store credential -Store a generated credential in a C1 vault and optionally deliver it to a recipient. +Store a generated credential in a C1.ai vault and optionally deliver it to a recipient. | Field | Required | CEL | Notes | |---|---|---|---| | Credential | Yes | No | Reference to the Generate password step output: `ctx.{generate_step_name}.credential_ref`. | | Vault type | Yes | No | **Paper Vault**: one-time secret link, self-destructs after N views or a time window. **App Vault**: persistent, entitlement-bound storage accessible via VaultOpenerService. | -| Recipient | Yes | Yes | One or more recipients. For Paper Vault, specify multiple SSO users or multiple email addresses. For App Vault, specify a single C1 user ID. Accepts a CEL expression — use `ctx.trigger.user.manager_id` to deliver to the subject user's manager. | +| Recipient | Yes | Yes | One or more recipients. For Paper Vault, specify multiple SSO users or multiple email addresses. For App Vault, specify a single C1.ai user ID. Accepts a CEL expression — use `ctx.trigger.user.manager_id` to deliver to the subject user's manager. | | Auth type | Yes (Paper Vault) | No | How recipients authenticate to retrieve the secret. Options: SSO Internal, Email verified. | | Expiry | No (Paper Vault) | No | How long the secret is available before auto-expiration. Default: 72 hours. | | Max views | No (Paper Vault) | No | Number of times the secret can be viewed before it self-destructs. Default: 1. | diff --git a/product/admin/automations-triggers-reference.mdx b/product/admin/automations-triggers-reference.mdx index a7a962c4..d117e9c8 100644 --- a/product/admin/automations-triggers-reference.mdx +++ b/product/admin/automations-triggers-reference.mdx @@ -1,10 +1,10 @@ --- title: "Automation triggers reference" -description: "A comprehensive guide to all available automation triggers in C1, including event-based, scheduled, and on-demand options." +description: "A comprehensive guide to all available automation triggers in C1.ai, including event-based, scheduled, and on-demand options." sidebarTitle: "Automation triggers" --- -This page describes the trigger types available for C1 automations. Each trigger determines what event causes an automation to run. +This page describes the trigger types available for C1.ai automations. Each trigger determines what event causes an automation to run. For CEL expression syntax in trigger conditions, see [workflow expressions](/product/admin/expressions-workflows). For the full `ctx.trigger` object schema, see the [expressions reference](/product/admin/expressions-reference). @@ -26,7 +26,7 @@ See [workflow expressions](/product/admin/expressions-workflows). ### User updated -Use this trigger to respond when a user attribute changes in C1. You can monitor changes to employment status, department, manager, or any other user attribute. Add conditional expressions to narrow the trigger to specific changes, such as when a user's status changes from "Active" to "Terminated." +Use this trigger to respond when a user attribute changes in C1.ai. You can monitor changes to employment status, department, manager, or any other user attribute. Add conditional expressions to narrow the trigger to specific changes, such as when a user's status changes from "Active" to "Terminated." **Required fields:** User attribute @@ -74,7 +74,7 @@ Use this trigger to identify when a user hasn't logged into their app account fo ### User created -Use this trigger to respond when a new user is created in C1, typically through directory synchronization. This is ideal for initiating onboarding automations that grant initial access, send welcome communications, or create accounts in various systems. You can add conditional expressions to target specific types of new users based on their attributes. +Use this trigger to respond when a new user is created in C1.ai, typically through directory synchronization. This is ideal for initiating onboarding automations that grant initial access, send welcome communications, or create accounts in various systems. You can add conditional expressions to target specific types of new users based on their attributes. **Required fields:** None @@ -98,7 +98,7 @@ Use this trigger to respond when a new access grant is discovered in your enviro - **Grant type**: Whether the grant is permanent or temporary (has an expiration date). -- **Grant origin**: Whether the grant was created through a C1 ticket workflow or assigned directly in the external system without going through C1. +- **Grant origin**: Whether the grant was created through a C1.ai ticket workflow or assigned directly in the external system without going through C1.ai. **Example:** Trigger when a user is granted access to the OpsGenie on-call rotation @@ -118,7 +118,7 @@ Use this trigger to respond when an access grant is removed from a user's accoun ### Incoming webhook -Use this trigger to let external systems initiate C1 automations by sending webhook requests. This lets you integrate C1 with your broader technology ecosystem, allowing events in other systems (such as HRIS platforms, ticketing systems, or custom applications) to trigger access management workflows. You must configure authentication to ensure only authorized systems can trigger the automation. +Use this trigger to let external systems initiate C1.ai automations by sending webhook requests. This lets you integrate C1.ai with your broader technology ecosystem, allowing events in other systems (such as HRIS platforms, ticketing systems, or custom applications) to trigger access management workflows. You must configure authentication to ensure only authorized systems can trigger the automation. **Required fields:** Authentication method (HMAC or JWT) diff --git a/product/admin/automations.mdx b/product/admin/automations.mdx index ef3e6377..94a667e7 100644 --- a/product/admin/automations.mdx +++ b/product/admin/automations.mdx @@ -1,6 +1,6 @@ --- title: "Create automations" -og:title: "Create automations - C1 docs" +og:title: "Create automations - C1.ai docs" og:description: "Automations are custom workflows that can streamline repetitive tasks like onboarding and offboarding, ensuring consistency and reducing manual effort." description: "Automations are custom workflows that can streamline repetitive tasks like onboarding and offboarding, ensuring consistency and reducing manual effort." sidebarTitle: "Automate custom workflows" @@ -8,7 +8,7 @@ sidebarTitle: "Automate custom workflows" {/* Editor Refresh: 2026-02-05 */} -Automations in C1 empower you to build custom workflows for repetitive tasks, significantly streamlining your operational processes. Automations are ideal for kicking off critical processes when an employee's status changes, providing seamless onboarding, secure offboarding, efficient role transfers, and timely access reviews. Automations ensure consistency, reduce manual effort, and improve compliance. +Automations in C1.ai empower you to build custom workflows for repetitive tasks, significantly streamlining your operational processes. Automations are ideal for kicking off critical processes when an employee's status changes, providing seamless onboarding, secure offboarding, efficient role transfers, and timely access reviews. Automations ensure consistency, reduce manual effort, and improve compliance. Find and manage all your automations on the **Automations** page. @@ -30,7 +30,7 @@ Let's break down the structure: ## Create a new automation - A user with the **Super Admin** role in C1 must complete this task. + A user with the **Super Admin** role in C1.ai must complete this task. @@ -103,7 +103,7 @@ You can filter the list by automation, status, and app. Click any execution to s To view execution history for a single automation, click the **...** (more actions) menu on the automation and select **Show execution history**. -To protect against automations that run unexpectedly at high volume, you can set a rate limit using the [circuit breaker](/product/admin/automation-circuit-breaker). When the limit is exceeded, C1 pauses the automation and queues new trigger events for review rather than running them. +To protect against automations that run unexpectedly at high volume, you can set a rate limit using the [circuit breaker](/product/admin/automation-circuit-breaker). When the limit is exceeded, C1.ai pauses the automation and queues new trigger events for review rather than running them. ## Get agent help building automations diff --git a/product/admin/branding.mdx b/product/admin/branding.mdx index 9924fa1b..dabbe19f 100644 --- a/product/admin/branding.mdx +++ b/product/admin/branding.mdx @@ -1,17 +1,17 @@ --- -title: Add your own brand to C1 -og:title: Add your own brand to C1 - C1 docs -og:description: Apply your organization's logo, favicon, and display name across the C1 product and email notifications. -description: Apply your organization's logo, favicon, and display name across the C1 product and email notifications. -sidebarTitle: "Customize C1's appearance" +title: Add your own brand to C1.ai +og:title: Add your own brand to C1.ai - C1.ai docs +og:description: Apply your organization's logo, favicon, and display name across the C1.ai product and email notifications. +description: Apply your organization's logo, favicon, and display name across the C1.ai product and email notifications. +sidebarTitle: "Customize C1.ai's appearance" --- {/* Editor Refresh: 2026-04-15 */} -This task requires the **Super Administrator** role in C1. +This task requires the **Super Administrator** role in C1.ai. -Use branding settings to replace the default C1 logo, favicon, and display name with your own. +Use branding settings to replace the default C1.ai logo, favicon, and display name with your own. ## What you can customize @@ -24,23 +24,23 @@ Branding settings let you configure the following: - **White favicon / mobile logo.** An inverted favicon used on dark backgrounds. -We recommend uploading both a color and a white version of your logo and favicon so your branding looks right everywhere it appears. However, if you skip the white versions, C1 will use your color assets on both light and dark backgrounds. +We recommend uploading both a color and a white version of your logo and favicon so your branding looks right everywhere it appears. However, if you skip the white versions, C1.ai will use your color assets on both light and dark backgrounds. ## Where your branding appears After you turn branding on and upload assets, your branding is applied in the following places: -- **App header.** Your logo and display name replace the default C1 logo in the top navigation. -- **Sign-in page.** Your logo appears on the C1 sign-in page for your tenant. -- **Browser tab and bookmarks.** Your favicon replaces the default C1 favicon. -- **Email notifications.** Your logo and display name appear in transactional emails, digest emails, and other notifications sent from C1. +- **App header.** Your logo and display name replace the default C1.ai logo in the top navigation. +- **Sign-in page.** Your logo appears on the C1.ai sign-in page for your tenant. +- **Browser tab and bookmarks.** Your favicon replaces the default C1.ai favicon. +- **Email notifications.** Your logo and display name appear in transactional emails, digest emails, and other notifications sent from C1.ai. Asset updates may take a few moments to propagate to all surfaces. Cached browser tabs may continue to show the previous favicon until the tab is refreshed. ## Turn on branding and set a display name -Set your display name and turn on branding to start applying your custom brand across the C1 product and in email notifications. +Set your display name and turn on branding to start applying your custom brand across the C1.ai product and in email notifications. @@ -50,7 +50,7 @@ Navigate to **Settings** > **Branding**. In the **Branding settings** area of the page, click **Edit**. -Turn on the **Enable branding** toggle. When branding is off, C1 shows the default C1 logo, favicon, and name in the product and in emails. +Turn on the **Enable branding** toggle. When branding is off, C1.ai shows the default C1.ai logo, favicon, and name in the product and in emails. In the **Display name** field, enter the name you want to appear alongside your logo. This name is used in the app header and in email notifications. Maximum 128 characters. @@ -62,7 +62,7 @@ Click **Save**. ## Upload a logo -Your logo appears in the C1 app header and in email notifications sent to your users. +Your logo appears in the C1.ai app header and in email notifications sent to your users. **Logo image requirements:** @@ -78,7 +78,7 @@ Navigate to **Settings** > **Branding**. In the **Branding settings** area of the page, click **Edit**. -If necessary, turn on the **Enable branding** toggle. When branding is off, C1 shows the default C1 logo, favicon, and name in the product and in emails. +If necessary, turn on the **Enable branding** toggle. When branding is off, C1.ai shows the default C1.ai logo, favicon, and name in the product and in emails. In the **Logo** section, click **Upload** (or **Replace** if a logo is already set). @@ -87,13 +87,13 @@ In the **Logo** section, click **Upload** (or **Replace** if a logo is already s Drag an image into the upload area, or click to select a file from your computer. -Click **Save**. C1 automatically generates the resized versions needed for different screens and devices. +Click **Save**. C1.ai automatically generates the resized versions needed for different screens and devices. ### Upload a white logo -We recommend uploading a white logo in addition to your primary logo so your branding looks right on dark backgrounds. If you skip this step, C1 uses your primary logo everywhere. +We recommend uploading a white logo in addition to your primary logo so your branding looks right on dark backgrounds. If you skip this step, C1.ai uses your primary logo everywhere. @@ -103,7 +103,7 @@ In the **White logo (optional)** section, click **Upload** (or **Replace** if a Select a file that meets the logo image requirements listed above. -Click **Save**. C1 automatically generates the resized versions needed for different screens and devices. +Click **Save**. C1.ai automatically generates the resized versions needed for different screens and devices. @@ -125,7 +125,7 @@ Navigate to **Settings** > **Branding**. In the **Branding settings** area of the page, click **Edit**. -If necessary, turn on the **Enable branding** toggle. When branding is off, C1 shows the default C1 logo, favicon, and name in the product and in emails. +If necessary, turn on the **Enable branding** toggle. When branding is off, C1.ai shows the default C1.ai logo, favicon, and name in the product and in emails. In the **Favicon / mobile logo** section, click **Upload** (or **Replace** if a favicon is already set). @@ -137,13 +137,13 @@ Drag an image into the upload area, or click to select a file from your computer Use the **Zoom** slider and drag the image inside the crop frame to position it. The image is cropped to a square. -Click **Save**. C1 automatically generates the resized versions needed for browsers and devices. +Click **Save**. C1.ai automatically generates the resized versions needed for browsers and devices. ### Upload a white favicon -We recommend uploading a white favicon in addition to your primary favicon so your branding looks right on dark backgrounds. If you skip this step, C1 uses your primary favicon everywhere. +We recommend uploading a white favicon in addition to your primary favicon so your branding looks right on dark backgrounds. If you skip this step, C1.ai uses your primary favicon everywhere. @@ -161,6 +161,6 @@ Click **Save**. To swap an uploaded logo or favicon, click **Replace** on the asset and upload a new file. The new asset replaces the old one immediately after you save. -To stop using your custom branding without deleting your uploaded assets, turn off the **Enable branding** toggle. C1 reverts to default branding in the product and in emails, but keeps your uploaded files available to turn back on later. +To stop using your custom branding without deleting your uploaded assets, turn off the **Enable branding** toggle. C1.ai reverts to default branding in the product and in emails, but keeps your uploaded files available to turn back on later. diff --git a/product/admin/c1-for-c1.mdx b/product/admin/c1-for-c1.mdx index c77ad40a..70240ecd 100644 --- a/product/admin/c1-for-c1.mdx +++ b/product/admin/c1-for-c1.mdx @@ -1,51 +1,51 @@ --- -title: Work with the C1 app -og:title: Work with the C1 app - C1 docs -og:description: The C1 app is a special application where you can see and manage C1 access within C1. Yes, it's very meta. -description: The C1 app is a special application where you can see and manage C1 access within C1. Yes, it's very meta. -sidebarTitle: The C1 app +title: Work with the C1.ai app +og:title: Work with the C1.ai app - C1.ai docs +og:description: The C1.ai app is a special application where you can see and manage C1.ai access within C1.ai. Yes, it's very meta. +description: The C1.ai app is a special application where you can see and manage C1.ai access within C1.ai. Yes, it's very meta. +sidebarTitle: The C1.ai app --- {/* Editor Refresh: 2026-01-07 */} -## The C1 application +## The C1.ai application -The C1 application contains current data on user access to C1 and user permissions within C1. It lets you review and manage access to C1 ... with C1. It's more than a bit self-referential, true, but we promise it's useful. +The C1.ai application contains current data on user access to C1.ai and user permissions within C1.ai. It lets you review and manage access to C1.ai ... with C1.ai. It's more than a bit self-referential, true, but we promise it's useful. -You'll find the C1 app on the **Apps** page's **Managed apps** tab. Note that it's the one with the **purple** icon. +You'll find the C1.ai app on the **Apps** page's **Managed apps** tab. Note that it's the one with the **purple** icon. -![A screenshot of the C1 app showing the Roles tab.](/images/product/assets/c1-app.png) +![A screenshot of the C1.ai app showing the Roles tab.](/images/product/assets/c1-app.png) -If you create another application named "C1", this is given a white icon. +If you create another application named "C1.ai", this is given a white icon. -### What can I do with the C1 app? +### What can I do with the C1.ai app? -Key uses for the C1 app include: +Key uses for the C1.ai app include: -* **Review C1 user roles in an access review campaign.** C1 [user roles](/product/admin/user-roles) are shown as roles in the C1 app. You can add these roles to an [access review campaign](/product/admin/campaigns) to audit whether C1 users have the appropriate level of permissions in the app. +* **Review C1.ai user roles in an access review campaign.** C1.ai [user roles](/product/admin/user-roles) are shown as roles in the C1.ai app. You can add these roles to an [access review campaign](/product/admin/campaigns) to audit whether C1.ai users have the appropriate level of permissions in the app. -* **Allow users to request new C1 roles.** You can add C1 user roles to access profiles, allowing users to request new permissions in C1. +* **Allow users to request new C1.ai roles.** You can add C1.ai user roles to access profiles, allowing users to request new permissions in C1.ai. - You cannot set app-level access configuration rules on the C1 app, but you can [configure access request settings on an individual entitlement](/product/admin/access-requests#configure-access-request-settings-on-an-individual-entitlement). + You cannot set app-level access configuration rules on the C1.ai app, but you can [configure access request settings on an individual entitlement](/product/admin/access-requests#configure-access-request-settings-on-an-individual-entitlement). -* **Manage users' enrollment in access profiles.** [Access profiles](/product/admin/profiles) are a resource type in the C1 app. Grant users the **enrollment** entitlement to give them access to the access profile and all its associated access. +* **Manage users' enrollment in access profiles.** [Access profiles](/product/admin/profiles) are a resource type in the C1.ai app. Grant users the **enrollment** entitlement to give them access to the access profile and all its associated access. * **Review enrollment in access profiles in an access review campaign.** Use an [access review campaign](/product/admin/campaigns) to periodically review which users are enrolled in an access profile. -### What are the limitations of the C1 app? +### What are the limitations of the C1.ai app? -Because of the special, self-referential nature of the C1 app, it lacks some functionality that's present on all other apps: +Because of the special, self-referential nature of the C1.ai app, it lacks some functionality that's present on all other apps: -* You cannot rename the C1 app or its roles. You can rename [C1 groups](/product/admin/groups) and access profiles. +* You cannot rename the C1.ai app or its roles. You can rename [C1.ai groups](/product/admin/groups) and access profiles. -* You cannot change C1 app's icon. +* You cannot change C1.ai app's icon. -* The C1 app does not support [linked entitlements](/product/admin/relationships#set-up-a-linked-entitlement). +* The C1.ai app does not support [linked entitlements](/product/admin/relationships#set-up-a-linked-entitlement). -* You cannot [bind entitlements](/product/admin/relationships#add-a-manual-binding) in the C1 app to entitlements in other apps. +* You cannot [bind entitlements](/product/admin/relationships#add-a-manual-binding) in the C1.ai app to entitlements in other apps. -* There are no provisioning settings for the C1 app's entitlements, as provisioning and deprovisioning is completed by C1 itself. +* There are no provisioning settings for the C1.ai app's entitlements, as provisioning and deprovisioning is completed by C1.ai itself. diff --git a/product/admin/c1-mcp.mdx b/product/admin/c1-mcp.mdx index 3a482063..6dc6ac8e 100644 --- a/product/admin/c1-mcp.mdx +++ b/product/admin/c1-mcp.mdx @@ -1,21 +1,21 @@ --- -title: C1 MCP -description: Connect AI assistants like Claude Desktop, Codex, Cursor, and VS Code to query your C1 data using the Model Context Protocol (MCP). -og:title: C1 MCP - C1 docs -og:description: Connect AI assistants like Claude Desktop, Codex, Cursor, and VS Code to query your C1 data using the Model Context Protocol (MCP). -sidebarTitle: Connect to the C1 MCP +title: C1.ai MCP +description: Connect AI assistants like Claude Desktop, Codex, Cursor, and VS Code to query your C1.ai data using the Model Context Protocol (MCP). +og:title: C1.ai MCP - C1.ai docs +og:description: Connect AI assistants like Claude Desktop, Codex, Cursor, and VS Code to query your C1.ai data using the Model Context Protocol (MCP). +sidebarTitle: Connect to the C1.ai MCP --- {/* Editor Refresh: 2026-04-28 */} -Connect AI assistants like Claude Desktop, Codex, Cursor, and VS Code to query your C1 data using the Model Context Protocol (MCP). +Connect AI assistants like Claude Desktop, Codex, Cursor, and VS Code to query your C1.ai data using the Model Context Protocol (MCP). -This page covers querying C1's own identity governance data from your AI client. If you're looking to govern AI access to external tools like Salesforce or GitHub, see [AI access management](/product/admin/aiam-overview). +This page covers querying C1.ai's own identity governance data from your AI client. If you're looking to govern AI access to external tools like Salesforce or GitHub, see [AI access management](/product/admin/aiam-overview). -AI Connections are read-only. Connected AI assistants can view your C1 data but cannot create, modify, or delete any configuration. +AI Connections are read-only. Connected AI assistants can view your C1.ai data but cannot create, modify, or delete any configuration. ## Security considerations @@ -30,7 +30,7 @@ AI Connections is designed with security as a priority: ## Prerequisites -Before users can connect AI assistants, a C1 administrator must complete the following setup. +Before users can connect AI assistants, a C1.ai administrator must complete the following setup. ### Turn on AI connections @@ -38,10 +38,10 @@ A Super Admin must enable AI connections in your tenant settings: -Navigate to **AI > C1 Gateway** and click **Settings**. +Navigate to **AI > C1.ai Gateway** and click **Settings**. -Find **C1 Gateway**, click **Edit**, and toggle **Enable the C1 gateway** to on. +Find **C1 Gateway**, click **Edit**, and toggle **Enable the C1.ai gateway** to on. Click **Save**. @@ -85,13 +85,13 @@ If you configure IP restrictions, AI assistants will only work from the specifie ## Connect an AI assistant -Follow these steps to connect your AI assistant to C1 via MCP. +Follow these steps to connect your AI assistant to C1.ai via MCP. **Get the MCP server URL** -In C1, navigate to your user profile menu and click **AI & API** > **AI connections**. Copy the MCP server URL displayed at the top of the page: +In C1.ai, navigate to your user profile menu and click **AI & API** > **AI connections**. Copy the MCP server URL displayed at the top of the page: ```text https://-mcp.conductor.one/v1 @@ -106,19 +106,19 @@ Add the MCP server URL to your AI assistant's configuration: 1. Open Claude Desktop settings. 2. Navigate to the MCP servers section. - 3. Add a new server with the C1 MCP URL. + 3. Add a new server with the C1.ai MCP URL. 4. Save and restart Claude Desktop. - 1. From your terminal, add the C1 MCP server using the `claude mcp add` command: + 1. From your terminal, add the C1.ai MCP server using the `claude mcp add` command: ```bash claude mcp add --transport http c1 https://-mcp.conductor.one/v1 ``` - Replace `` with your C1 tenant subdomain. + Replace `` with your C1.ai tenant subdomain. 2. Start Claude Code and run the `/mcp` slash command. - 3. Select the **c1** server and choose **Authenticate**. Your browser opens to C1 to complete the authorization step described below. + 3. Select the **c1** server and choose **Authenticate**. Your browser opens to C1.ai to complete the authorization step described below. 4. Once authenticated, the server status appears as connected in the `/mcp` view. @@ -126,19 +126,19 @@ Add the MCP server URL to your AI assistant's configuration: - 1. From your terminal, add the C1 MCP server using the `codex mcp add` command: + 1. From your terminal, add the C1.ai MCP server using the `codex mcp add` command: ```bash codex mcp add c1 --url https://-mcp.conductor.one/v1 ``` - Replace `` with your C1 tenant subdomain. + Replace `` with your C1.ai tenant subdomain. 2. Verify the server is configured: ```bash codex mcp list ``` - 3. Start Codex in the CLI or IDE extension and connect to the **c1** MCP server. Your browser opens to C1 to complete the authorization step described below. + 3. Start Codex in the CLI or IDE extension and connect to the **c1** MCP server. Your browser opens to C1.ai to complete the authorization step described below. Codex shares MCP configuration between the CLI and IDE extension. You can also add the server directly in `~/.codex/config.toml`: @@ -152,7 +152,7 @@ Add the MCP server URL to your AI assistant's configuration: 1. Open Cursor settings. 2. Navigate to the **Tools and MCP** configuration. - 3. Add the C1 MCP server URL in the JSON editor. + 3. Add the C1.ai MCP server URL in the JSON editor. 4. Save your configuration. @@ -160,7 +160,7 @@ Add the MCP server URL to your AI assistant's configuration: **Authorize the connection** -When your AI assistant first connects, you'll be redirected to C1 to authorize the connection: +When your AI assistant first connects, you'll be redirected to C1.ai to authorize the connection: 1. Review the connection details. 2. **Optional.** Customize the connection name. @@ -170,7 +170,7 @@ When your AI assistant first connects, you'll be redirected to C1 to authorize t **Start querying** -Once authorized, your AI assistant can query C1 data. The connection appears in your user profile under **AI & API** > **AI connections**. +Once authorized, your AI assistant can query C1.ai data. The connection appears in your user profile under **AI & API** > **AI connections**. @@ -188,14 +188,14 @@ Connected AI assistants have access to the following query tools: ## Queryable objects -AI assistants can query 20 different object types across your C1 tenant. +AI assistants can query 20 different object types across your C1.ai tenant. ### Identity and applications | Object | Description | | :--- | :--- | | `User` | Identity accounts in your directory | -| `App` | Applications and directories connected to C1 | +| `App` | Applications and directories connected to C1.ai | | `Connector` | Data sync connectors for applications | | `Task` | Access requests, reviews, and other tickets | | `Policy` | Approval workflows and access policies | @@ -233,7 +233,7 @@ AI assistants can query 20 different object types across your C1 tenant. | `Webhook` | Event notification configurations | | `Directory` | Account sync configurations | | `ProfileType` | Attribute mapping configurations | -| `RoleBinding` | C1 role assignments | +| `RoleBinding` | C1.ai role assignments | ## Example queries @@ -299,7 +299,7 @@ Click **Confirm**. -Revoking a connection immediately prevents the AI assistant from accessing your C1 data. You can re-authorize the connection later if needed. +Revoking a connection immediately prevents the AI assistant from accessing your C1.ai data. You can re-authorize the connection later if needed. ### Admin management @@ -308,7 +308,7 @@ Super Admins can navigate to **AI** > **C1 Gateway** > **Connected clients** to ## System log events -All MCP activity is recorded in the C1 system log. You can use these event types to monitor and alert on AI connection activity: +All MCP activity is recorded in the C1.ai system log. You can use these event types to monitor and alert on AI connection activity: | Event | Activity Name | Description | | :--- | :--- | :--- | @@ -352,7 +352,7 @@ Each MCP session event includes: | Field | Description | | :--- | :--- | | Session ID | Unique identifier for the connection | -| User | The C1 user who authorized the connection | +| User | The C1.ai user who authorized the connection | | Source IP | IP address of the AI assistant | | User Agent | Client identifier (for example, Claude Desktop, Codex, or Cursor) | | Duration | Session length (in session end events) | @@ -373,7 +373,7 @@ Each tool call event includes: ## Frequently asked questions about AI connections - + No. AI Connections are granted **Read-Only Admin** access. Connected AI assistants can view and query your data, but they cannot create, update, or delete any configuration, users, or access assignments. @@ -382,7 +382,7 @@ Each tool call event includes: - Any tool that supports the Model Context Protocol (MCP) can connect to C1, including: + Any tool that supports the Model Context Protocol (MCP) can connect to C1.ai, including: - Claude Desktop - Claude Code @@ -399,15 +399,15 @@ Each tool call event includes: - Yes. AI connection activity is logged in your C1 system log. See [System log events](#system-log-events) for details. + Yes. AI connection activity is logged in your C1.ai system log. See [System log events](#system-log-events) for details. - The AI assistant immediately loses access to your C1 data. Any ongoing queries will fail. You can re-authorize the same AI assistant later by going through the connection flow again. + The AI assistant immediately loses access to your C1.ai data. Any ongoing queries will fail. You can re-authorize the same AI assistant later by going through the connection flow again. - When you query data through an AI assistant, the query results are sent to the AI provider (for example, Anthropic for Claude) to generate responses. Only the data specifically requested by your queries is transmitted. C1 does not send your data to any AI providers in the MCP flow — it is sent by clients under your control. + When you query data through an AI assistant, the query results are sent to the AI provider (for example, Anthropic for Claude) to generate responses. Only the data specifically requested by your queries is transmitted. C1.ai does not send your data to any AI providers in the MCP flow — it is sent by clients under your control. diff --git a/product/admin/campaign-scope-by-inheritance.mdx b/product/admin/campaign-scope-by-inheritance.mdx index d02c2f52..5746b7a2 100644 --- a/product/admin/campaign-scope-by-inheritance.mdx +++ b/product/admin/campaign-scope-by-inheritance.mdx @@ -1,15 +1,15 @@ --- title: Scope an access review campaign by inheritance -og:title: Scope an access review campaign by inheritance - C1 docs +og:title: Scope an access review campaign by inheritance - C1.ai docs og:description: Use the By inheritance scope type to review cloud infrastructure access that flows through a resource hierarchy, including access inherited from parent resources and group membership. description: Use the By inheritance scope type to review cloud infrastructure access that flows through a resource hierarchy, including access inherited from parent resources and group membership. sidebarTitle: Scope by inheritance --- {/* Editor Refresh: 2026-06-10 */} -The **By inheritance** scope type lets you build an access review campaign around the resources and role assignments you care about, rather than listing every individual entitlement. C1 automatically resolves all the access that flows into your selections—including access inherited from parent resources and from group membership—so reviewers see the full picture of who can reach each resource and why. +The **By inheritance** scope type lets you build an access review campaign around the resources and role assignments you care about, rather than listing every individual entitlement. C1.ai automatically resolves all the access that flows into your selections—including access inherited from parent resources and from group membership—so reviewers see the full picture of who can reach each resource and why. -Resource-based selections work for any app in C1. Scope and role pair selections — where you review who holds a role at a specific level of a resource hierarchy — are only available for cloud infrastructure apps like Azure. +Resource-based selections work for any app in C1.ai. Scope and role pair selections — where you review who holds a role at a specific level of a resource hierarchy — are only available for cloud infrastructure apps like Azure. ## When to use scope by inheritance @@ -18,7 +18,7 @@ Use **By inheritance** when: - You're reviewing access to cloud infrastructure where permissions cascade through a hierarchy—for example, a role assigned at the subscription level that applies to every resource beneath it. - You want to see everyone who can reach a resource, not just everyone who holds a specific entitlement on it. - Users get their access indirectly—through group membership or a role assigned higher up the resource tree—and you want those indirect paths surfaced in the review. -- You'd rather scope by resource than by individual entitlement. Selecting the resources you care about can be faster and clearer than listing entitlements, and C1 resolves each resource to the entitlements that apply to it. +- You'd rather scope by resource than by individual entitlement. Selecting the resources you care about can be faster and clearer than listing entitlements, and C1.ai resolves each resource to the entitlements that apply to it. If you'd rather scope by explicitly naming entitlements, use the standard **By entitlements** scope type instead. @@ -26,8 +26,8 @@ If you'd rather scope by explicitly naming entitlements, use the standard **By e In a cloud environment, a person can have access to a resource without any permission being assigned to that resource directly. **By inheritance** accounts for two paths: -- **Resource hierarchy.** A role assigned high in the resource tree—for example, Contributor on a subscription—grants access to every resource beneath it. When you scope a campaign to a child resource, C1 walks up the parent chain and includes any roles that grant access from above. -- **Group membership.** A user may hold access only because they belong to a group that was granted a role. C1 follows group membership chains so that underlying group access shows up in the review. +- **Resource hierarchy.** A role assigned high in the resource tree—for example, Contributor on a subscription—grants access to every resource beneath it. When you scope a campaign to a child resource, C1.ai walks up the parent chain and includes any roles that grant access from above. +- **Group membership.** A user may hold access only because they belong to a group that was granted a role. C1.ai follows group membership chains so that underlying group access shows up in the review. These two paths combine. If a group is assigned a role on a parent resource and a user belongs to that group, the review captures both the role assignment and the group membership that leads to it—giving reviewers the full picture of why someone has access. @@ -44,7 +44,7 @@ Fill out the campaign details. Under **Review scope type**, select **By inherita Configure your scope selections. You can use one or both: - **Scope and role pairs** *(cloud infrastructure apps only).* Select a combination of a scope resource (such as a subscription) and a role (such as Owner) to review who holds that role within that part of the resource hierarchy. -- **Resources** *(any app).* Select specific resources to review. C1 expands each selection to include access inherited from parent resources. For cloud infrastructure apps, the resource list shows the hierarchy so you can see parent and child relationships. +- **Resources** *(any app).* Select specific resources to review. C1.ai expands each selection to include access inherited from parent resources. For cloud infrastructure apps, the resource list shows the hierarchy so you can see parent and child relationships. **Optional.** Apply additional filters to narrow the campaign: diff --git a/product/admin/campaigns.mdx b/product/admin/campaigns.mdx index d74f4106..9b414f8d 100644 --- a/product/admin/campaigns.mdx +++ b/product/admin/campaigns.mdx @@ -1,6 +1,6 @@ --- title: Create an access review campaign -og:title: Create an access review campaign - C1 docs +og:title: Create an access review campaign - C1.ai docs og:description: Create one-time user access review (UAR) campaigns or reusable campaign templates that can be run on a schedule. Scope campaigns by entitlements, by access conflicts, or by inheritance across a cloud infrastructure resource hierarchy. description: Create one-time user access review (UAR) campaigns or reusable campaign templates. Scope campaigns by entitlements, by access conflicts, or by inheritance across a cloud infrastructure resource hierarchy. sidebarTitle: Create a campaign @@ -30,10 +30,10 @@ On the **Campaigns** page, campaigns are sorted by state and type: If there's a campaign pattern you use repeatedly, create a reusable campaign template instead of configuring the same campaign from scratch every time. -![A screenshot of the Campaigns page in C1, showing the Campaign templates tab with a campaign template for a weekly access review campaign.](/images/product/assets/campaigns-template.png) +![A screenshot of the Campaigns page in C1.ai, showing the Campaign templates tab with a campaign template for a weekly access review campaign.](/images/product/assets/campaigns-template.png) -Once a campaign template is set up, use it to create single campaigns whenever you need them or set a schedule for automated campaign creation. When a schedule is running, C1 automatically creates new instances of the campaign for you and adds them to the **Drafts** tab. You can review, fine-tune, and start these campaigns when you're ready. +Once a campaign template is set up, use it to create single campaigns whenever you need them or set a schedule for automated campaign creation. When a schedule is running, C1.ai automatically creates new instances of the campaign for you and adds them to the **Drafts** tab. You can review, fine-tune, and start these campaigns when you're ready. **Need to reuse a campaign just once?** @@ -46,14 +46,14 @@ Duplicate any existing campaign from the **...** (more actions) menu on the **Ru Follow this process to create a single campaign. Jump to [Create a campaign template](/product/admin/campaigns#create-a-campaign-template) to set up a template that can be used to create many similar campaigns. -C1 offers three ways to define what a campaign covers: +C1.ai offers three ways to define what a campaign covers: -- **By entitlements** — Select specific entitlements, apps, or entitlement types to review. This is the standard approach and works for any app in C1. +- **By entitlements** — Select specific entitlements, apps, or entitlement types to review. This is the standard approach and works for any app in C1.ai. - **By access conflicts** — Review access that has triggered violations in your conflict monitors. Choose **Access conflicts** as the review type in Step 1 below. -- **By inheritance** — Scope the campaign to resources and role assignments in a cloud infrastructure app, and let C1 resolve all access that flows into them through the resource hierarchy. See [Scope an access review campaign by inheritance](/product/admin/campaign-scope-by-inheritance) for details. +- **By inheritance** — Scope the campaign to resources and role assignments in a cloud infrastructure app, and let C1.ai resolve all access that flows into them through the resource hierarchy. See [Scope an access review campaign by inheritance](/product/admin/campaign-scope-by-inheritance) for details. -Only users with the **Campaign Administrator** or **Super Administrator** [user roles](/product/admin/user-roles) in C1 can create and manage campaigns. Campaign admins can only manage the campaigns that they also own. +Only users with the **Campaign Administrator** or **Super Administrator** [user roles](/product/admin/user-roles) in C1.ai can create and manage campaigns. Campaign admins can only manage the campaigns that they also own. ### Step 1: Set up the campaign @@ -82,9 +82,9 @@ Fill out the form, providing the following information: - **By access conflicts**: Review user access that has triggered a violation in one of your enabled conflict monitors. This is a great option for quickly remediating high-risk access issues identified by your conflict monitors. - - **By inheritance**: Review access to cloud infrastructure apps by selecting resources and role assignments. C1 resolves all access that flows into your selections through the resource hierarchy, including inherited and group-based access. See [Scope an access review campaign by inheritance](/product/admin/campaign-scope-by-inheritance) for details. + - **By inheritance**: Review access to cloud infrastructure apps by selecting resources and role assignments. C1.ai resolves all access that flows into your selections through the resource hierarchy, including inherited and group-based access. See [Scope an access review campaign by inheritance](/product/admin/campaign-scope-by-inheritance) for details. - - **Owner**: The campaign's owner, who will manage the campaign while it is in progress. You can set more than one campaign owner. Each owner must have the Campaign Administrator or Super Administrator user role in C1. + - **Owner**: The campaign's owner, who will manage the campaign while it is in progress. You can set more than one campaign owner. Each owner must have the Campaign Administrator or Super Administrator user role in C1.ai. - **Review policy**: The campaign's default [review policy](/product/admin/policies). If needed, you'll be able to adjust the policy to be used for the review of individual entitlements later in the campaign creation process. @@ -119,7 +119,7 @@ If you want all reviewers to receive their campaign tasks in the same format, se By default, all campaign tasks will be created using the review policy you chose. If instead you want campaign tasks to use the review policies set on the entitlements or apps in the campaign, click **Edit** and click to turn on **Use preferred review policies**. - If this option is enabled, C1 will apply policies using this order of precedence: entitlement, application, campaign. + If this option is enabled, C1.ai will apply policies using this order of precedence: entitlement, application, campaign. By default, campaigns are started and ended manually. If you want to automatically start or end the campaign, find the **Schedule** section of the page and click **Edit**. @@ -149,13 +149,13 @@ If you want to use a Slack channel for communication about this campaign, click All campaign owners and users assigned access reviews will be automatically added to this channel when the campaign starts. - **Sending campaign notifications to a private Slack channel?** Make sure the [C1 app for Slack](/product/admin/integration-for-Slack) is added to the channel before you configure it here, or the notifications won't be delivered. + **Sending campaign notifications to a private Slack channel?** Make sure the [C1.ai app for Slack](/product/admin/integration-for-Slack) is added to the channel before you configure it here, or the notifications won't be delivered. **Optional.** To surface app user profile attributes to reviewers during access reviews, find the **Attribute visibility** section and click **Add attribute**. For each attribute you want to show, select an app and the attribute key — for example, **department** on AWS PROD. Each app-attribute combination is configured as a separate entry. Reviewers see no attributes by default; only those you configure here will be visible. -See [Map user attributes](/product/admin/attributes) to learn how attributes are defined in C1. +See [Map user attributes](/product/admin/attributes) to learn how attributes are defined in C1.ai. **Optional.** If you selected a **Default access review view** above (anything other than **None**), you can choose which columns show in the reviewer task list. Find the **Show these review columns** section below the view selector and click **Edit default columns**. @@ -213,7 +213,7 @@ On the **Scope** tab of your campaign, find the **Apps and entitlements** sectio If you're building a UAR reviewing specific resources, click the pencil icon to update the policy used to review specific entitlements, or the trashcan icon to remove an entitlement from the review. -![A screenshot of the Scope tab of a campaign in C1, showing the Edit scope button and the Apply changes button.](/images/product/assets/campaign-scope.png) +![A screenshot of the Scope tab of a campaign in C1.ai, showing the Edit scope button and the Apply changes button.](/images/product/assets/campaign-scope.png) @@ -229,7 +229,7 @@ If you're building a UAR reviewing specific resources, click the pencil icon to You can mix and match these options: - - User status in C1 + - User status in C1.ai - Direct reports of a manager @@ -257,7 +257,7 @@ If you're building a UAR reviewing specific resources, click the pencil icon to - Account type - - Account domain (specifically, whether the email address associated with the account has been [marked trusted](/product/admin/global-settings#set-trusted-domains) by a C1 admin at your organization) + - Account domain (specifically, whether the email address associated with the account has been [marked trusted](/product/admin/global-settings#set-trusted-domains) by a C1.ai admin at your organization) **OR** @@ -293,10 +293,10 @@ Once you're satisfied with your selections, move on to the next step. If any of your selections are sourced from connectors or file uploads that have not been updated recently, you'll see an indicator and a **Your campaign might have data accuracy issues** banner on the **Accuracy** tab. -![A screenshot of the Accuracy tab of a campaign in C1, showing the Your campaign might have data accuracy issues banner and the Data sources table.](/images/product/assets/campaign-data.png) +![A screenshot of the Accuracy tab of a campaign in C1.ai, showing the Your campaign might have data accuracy issues banner and the Data sources table.](/images/product/assets/campaign-data.png) -All data sources for your campaign are shown in the **Data sources** table. C1 flags data sources when: +All data sources for your campaign are shown in the **Data sources** table. C1.ai flags data sources when: * A connector hasn't synced for more than two days * A file source hasn't been updated in more than seven days @@ -333,7 +333,7 @@ If you've set up the campaign to automatically start, it will launch on the sche -When you're ready, click **Start campaign**. Select whether C1 should email campaign kickoff notifications to the users who are assigned the access reviews in the campaign. +When you're ready, click **Start campaign**. Select whether C1.ai should email campaign kickoff notifications to the users who are assigned the access reviews in the campaign. Click **Start campaign**. Again, depending on the size of the campaign, starting it might take several minutes. @@ -351,7 +351,7 @@ Instead of working through each step yourself, click **Create with Campaign assi {/* header name used in links, change with caution */} -Only users with the **Campaign Administrator** or **Super Administrator** [user roles](/product/admin/user-roles) in C1 can create and manage campaigns. +Only users with the **Campaign Administrator** or **Super Administrator** [user roles](/product/admin/user-roles) in C1.ai can create and manage campaigns. Instead of creating a campaign from scratch, you can save time and effort by duplicating a past campaign and tailoring it to your current needs. Duplicating a campaign is a quick way to reuse a past campaign's settings for a one-off review. If you need to run similar campaigns on a regular schedule, [create a campaign template](/product/admin/campaigns#create-a-campaign-template) instead. @@ -379,7 +379,7 @@ Follow the instructions above to validate, stage, and start the duplicate campai ## Create a campaign template -Only users with the **Campaign Administrator** or **Super Administrator** [user roles](/product/admin/user-roles) in C1 can create and manage campaign templates. +Only users with the **Campaign Administrator** or **Super Administrator** [user roles](/product/admin/user-roles) in C1.ai can create and manage campaign templates. ### Step 1: Set up the template @@ -408,9 +408,9 @@ Fill out the form, providing the following information: - **By access conflicts**: Review user access that has triggered a violation in one of your enabled conflict monitors. This is a great option for quickly remediating high-risk access issues identified by your conflict monitors. - - **By inheritance**: Review access to cloud infrastructure apps by selecting resources and role assignments. C1 resolves all access that flows into your selections through the resource hierarchy, including inherited and group-based access. See [Scope an access review campaign by inheritance](/product/admin/campaign-scope-by-inheritance) for details. + - **By inheritance**: Review access to cloud infrastructure apps by selecting resources and role assignments. C1.ai resolves all access that flows into your selections through the resource hierarchy, including inherited and group-based access. See [Scope an access review campaign by inheritance](/product/admin/campaign-scope-by-inheritance) for details. - - **Owner**: The campaign's owner, who will manage the campaign while it is in progress. You can set more than one campaign owner, just be sure anyone you add has the Campaign Administrator or Super Administrator user role in C1. + - **Owner**: The campaign's owner, who will manage the campaign while it is in progress. You can set more than one campaign owner, just be sure anyone you add has the Campaign Administrator or Super Administrator user role in C1.ai. - **Review policy**: The campaign's default [review policy](/product/admin/policies). If needed, you'll be able to adjust the policy to be used for the review of individual entitlements later in the campaign creation process. @@ -454,7 +454,7 @@ If you want all reviewers to receive their campaign tasks in the same format, se By default, all campaign tasks will be created using the review policy you chose. If instead you want campaign tasks to use the review policies set on the entitlements or apps in the campaign, click **Edit** and click to turn on **Use preferred review policies**. - If this option is enabled, C1 will apply policies using this order of precedence: entitlement, application, campaign. + If this option is enabled, C1.ai will apply policies using this order of precedence: entitlement, application, campaign. **Optional.** If you'd like to automatically create draft instances of this campaign, either once on a date in the future or regularly on a set schedule, go to the template's **Settings** tab, find the **Automated scheduling** section, and click **Edit**. @@ -504,13 +504,13 @@ If you want to use a Slack channel for communication about this campaign, click When new campaign instances are created from this template, you'll have a chance to change the Slack channel before starting the campaign. - **Sending campaign notifications to a private Slack channel?** Make sure the [C1 app for Slack](/product/admin/integration-for-Slack) is added to the channel before you configure it here, or the notifications won't be delivered. + **Sending campaign notifications to a private Slack channel?** Make sure the [C1.ai app for Slack](/product/admin/integration-for-Slack) is added to the channel before you configure it here, or the notifications won't be delivered. **Optional.** To surface app user profile attributes to reviewers during access reviews, find the **Attribute visibility** section and click **Add attribute**. For each attribute you want to show, select an app and the attribute key — for example, **department** on AWS PROD. Each app-attribute combination is configured as a separate entry. Reviewers see no attributes by default; only those you configure here will be visible. -See [Map user attributes](/product/admin/attributes) to learn how attributes are defined in C1. +See [Map user attributes](/product/admin/attributes) to learn how attributes are defined in C1.ai. **Optional.** If you selected a **Default access review view** above (anything other than **None**), you can choose which columns show in the reviewer task list. Find the **Show these review columns** section below the view selector and click **Edit default columns**. @@ -568,7 +568,7 @@ On the **Scope** tab of your template, find the **Apps and entitlements** sectio If you're building a UAR reviewing specific resources, click the pencil icon to update the policy used to review specific entitlements, or the trashcan icon to remove an entitlement from the review. -![A screenshot of the Scope tab of a campaign in C1, showing the Edit scope button and the Apply changes button.](/images/product/assets/campaign-scope.png) +![A screenshot of the Scope tab of a campaign in C1.ai, showing the Edit scope button and the Apply changes button.](/images/product/assets/campaign-scope.png) @@ -584,7 +584,7 @@ If you're building a UAR reviewing specific resources, click the pencil icon to You can mix and match these options: - - User status in C1 + - User status in C1.ai - Direct reports of a manager @@ -605,7 +605,7 @@ If you're building a UAR reviewing specific resources, click the pencil icon to - Account type - - Account domain (specifically, whether the email address associated with the account has been [marked trusted](/product/admin/global-settings#set-trusted-domains) by a C1 admin at your organization) + - Account domain (specifically, whether the email address associated with the account has been [marked trusted](/product/admin/global-settings#set-trusted-domains) by a C1.ai admin at your organization) @@ -634,7 +634,7 @@ Once you're satisfied with your selections, move on to the next step. #### Dynamic scope re-evaluation for tag-filtered templates -When you use risk level or compliance framework filters to select entitlements for a campaign template, C1 saves the **filter criteria** rather than a fixed list of entitlements. Each time a campaign is created from the template and prepared, the system re-evaluates the tag criteria against the current state of your entitlements. This means: +When you use risk level or compliance framework filters to select entitlements for a campaign template, C1.ai saves the **filter criteria** rather than a fixed list of entitlements. Each time a campaign is created from the template and prepared, the system re-evaluates the tag criteria against the current state of your entitlements. This means: - Entitlements that have been tagged since the template was last configured are **automatically included** in the next campaign. - Entitlements that have had tags removed are **automatically excluded**. @@ -664,13 +664,13 @@ In short, nothing. If you select a resource for your campaign that does not have Yes, you can! Go to the running campaign's **Configuration** tab and add or edit the campaign instructions. Reviewers will see the new version of the instructions as soon as you click **Save**. -If your campaign template scope is filtered by risk level or compliance framework, newly tagged entitlements are automatically included the next time a campaign is created from the template and prepared. C1 saves the tag criteria, not a static list, so the scope is re-evaluated against current entitlement tags at each campaign preparation. +If your campaign template scope is filtered by risk level or compliance framework, newly tagged entitlements are automatically included the next time a campaign is created from the template and prepared. C1.ai saves the tag criteria, not a static list, so the scope is re-evaluated against current entitlement tags at each campaign preparation. Tag-based filtering is used to narrow the list of entitlements shown when selecting specific resources. You select entitlements from the filtered results, and for campaign templates, the filter criteria are saved for dynamic re-evaluation. You cannot mix manually selected individual entitlements with a purely tag-driven dynamic scope in the same campaign. -You can filter entitlements by **risk level** and **compliance framework** — these are the built-in entitlement attribute types in C1. To use these filters, first create attribute values in **Settings** > **Tags** and assign them to your entitlements. See [Setting entitlement attributes](/product/admin/managing-entitlements#setting-entitlement-attributes) for setup instructions. +You can filter entitlements by **risk level** and **compliance framework** — these are the built-in entitlement attribute types in C1.ai. To use these filters, first create attribute values in **Settings** > **Tags** and assign them to your entitlements. See [Setting entitlement attributes](/product/admin/managing-entitlements#setting-entitlement-attributes) for setup instructions. No. The scope type you choose when creating a campaign cannot be changed afterward. If you need a different scope type, create a new campaign. diff --git a/product/admin/cloud-infrastructure-access.mdx b/product/admin/cloud-infrastructure-access.mdx index 7f5de12f..9c7796b7 100644 --- a/product/admin/cloud-infrastructure-access.mdx +++ b/product/admin/cloud-infrastructure-access.mdx @@ -1,13 +1,13 @@ --- title: Cloud infrastructure governance -og:title: Cloud infrastructure governance - C1 docs -og:description: Govern cloud infrastructure access at enterprise scale. C1 stores Azure access as role-scope bindings and computes effective access on demand, so access requests, access reviews, and lifecycle automation all work with the hierarchy natively. -description: Govern cloud infrastructure access at enterprise scale. C1 stores Azure access as role-scope bindings and computes effective access on demand, so access requests, access reviews, and lifecycle automation all work with the hierarchy natively. +og:title: Cloud infrastructure governance - C1.ai docs +og:description: Govern cloud infrastructure access at enterprise scale. C1.ai stores Azure access as role-scope bindings and computes effective access on demand, so access requests, access reviews, and lifecycle automation all work with the hierarchy natively. +description: Govern cloud infrastructure access at enterprise scale. C1.ai stores Azure access as role-scope bindings and computes effective access on demand, so access requests, access reviews, and lifecycle automation all work with the hierarchy natively. sidebarTitle: Govern cloud infrastructure access --- {/* Editor Refresh: 2026-06-10 */} -Cloud Infrastructure Access is C1's approach to governing access in hierarchical cloud environments like Azure. It introduces a new data model and set of governance workflows designed for the way cloud platforms actually define access — as a role assigned at a scope, with inheritance flowing through the resource hierarchy beneath it. +Cloud Infrastructure Access is C1.ai's approach to governing access in hierarchical cloud environments like Azure. It introduces a new data model and set of governance workflows designed for the way cloud platforms actually define access — as a role assigned at a scope, with inheritance flowing through the resource hierarchy beneath it. ## The problem with flat access models in cloud environments @@ -26,21 +26,21 @@ Representing this as a flat list causes real problems: ## How cloud infrastructure access works -Instead of pre-materializing every role-scope combination, C1 now stores access as **bindings** — one record per role assignment, at the scope it was granted. The resource hierarchy (management groups → subscriptions → resource groups → resources) is stored with parent-child relationships intact. Effective access is computed on demand rather than enumerated upfront. +Instead of pre-materializing every role-scope combination, C1.ai now stores access as **bindings** — one record per role assignment, at the scope it was granted. The resource hierarchy (management groups → subscriptions → resource groups → resources) is stored with parent-child relationships intact. Effective access is computed on demand rather than enumerated upfront. This means: -- A role assigned at a subscription scope covers every resource beneath it, and C1 knows this — without creating millions of pre-materialized rows +- A role assigned at a subscription scope covers every resource beneath it, and C1.ai knows this — without creating millions of pre-materialized rows - End users navigate a resource tree to select the scope and role they need, with breadcrumb navigation showing where they are in the hierarchy - Reviewers evaluate the bindings that actually exist, not an explosion of inherited copies — a review that might have produced tens of thousands of identical line items now shows the handful of bindings that matter, each with its scope and inherited reach visible -## How cloud infrastructure access works across C1 +## How cloud infrastructure access works across C1.ai Cloud Infrastructure Access is launching on [**Microsoft Azure**](/baton/azure), with support for GCP, AWS, and other hierarchical platforms on the roadmap. The following governance capabilities all work on the hierarchical model: -**Access requests** — End users navigate the Azure resource hierarchy to select the scope (for example, a specific resource group or subscription) and role they're requesting. C1 constructs the request at the right level and routes it through your normal request and approval workflow. +**Access requests** — End users navigate the Azure resource hierarchy to select the scope (for example, a specific resource group or subscription) and role they're requesting. C1.ai constructs the request at the right level and routes it through your normal request and approval workflow. **Access reviews** — The new [By inheritance](/product/admin/campaign-scope-by-inheritance) campaign scope type lets reviewers work through role bindings with full hierarchy context, rather than reviewing every inherited downstream grant individually. @@ -48,6 +48,6 @@ The following governance capabilities all work on the hierarchical model: **Lifecycle automation** — JML rules apply to cloud infrastructure access. When someone joins, changes roles, or leaves, their Azure permissions update automatically across the resource tree. -**Provisioning** — C1 grants and revokes access at the specific scope it was requested or assigned, not at a flat entitlement level. +**Provisioning** — C1.ai grants and revokes access at the specific scope it was requested or assigned, not at a flat entitlement level. diff --git a/product/admin/code-mode.mdx b/product/admin/code-mode.mdx index 5c5cd9bf..3c4eb165 100644 --- a/product/admin/code-mode.mdx +++ b/product/admin/code-mode.mdx @@ -1,27 +1,27 @@ --- title: Code mode -description: How C1's MCP gateway exposes governed tools through describe and execute, and how AI agents discover and call those tools by writing short programs. -og:title: Code mode - C1 docs -og:description: How C1's MCP gateway exposes governed tools through describe and execute, and how AI agents discover and call those tools by writing short programs. +description: How C1.ai's MCP gateway exposes governed tools through describe and execute, and how AI agents discover and call those tools by writing short programs. +og:title: Code mode - C1.ai docs +og:description: How C1.ai's MCP gateway exposes governed tools through describe and execute, and how AI agents discover and call those tools by writing short programs. --- {/* Editor Refresh: 2026-08-21 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -Read this page to understand what your users' AI agents are doing when they call tools through C1 — and, if you build agents yourself, to write code-mode programs against the gateway. +Read this page to understand what your users' AI agents are doing when they call tools through C1.ai — and, if you build agents yourself, to write code-mode programs against the gateway. ## How the gateway fits in -C1 is an MCP gateway. AI clients connect to one C1 MCP endpoint, and C1 sits in front of every MCP server and integration your organization has approved. Agents never connect to those servers directly. +C1.ai is an MCP gateway. AI clients connect to one C1.ai MCP endpoint, and C1.ai sits in front of every MCP server and integration your organization has approved. Agents never connect to those servers directly. -On each call, C1 authenticates the human or workload behind the agent, applies per-tool governance, and routes the call to the right upstream server — a hosted server from the catalog, a vendor MCP server, or a private server reached over an [MCP bridge](/product/admin/mcp-server/mcp-bridge). One MCP connection, many governed systems behind it. +On each call, C1.ai authenticates the human or workload behind the agent, applies per-tool governance, and routes the call to the right upstream server — a hosted server from the catalog, a vendor MCP server, or a private server reached over an [MCP bridge](/product/admin/mcp-server/mcp-bridge). One MCP connection, many governed systems behind it. ## What code mode changes -Code mode changes how the gateway presents those governed tools to the client. Instead of advertising every enabled tool as its own named tool, C1 exposes two entrypoints: +Code mode changes how the gateway presents those governed tools to the client. Instead of advertising every enabled tool as its own named tool, C1.ai exposes two entrypoints: | Entrypoint | What the agent uses it for | | :--- | :--- | @@ -119,7 +119,7 @@ When the caller doesn't hold a grant for a tool, the call doesn't fail opaquely. } ``` -The tool is requestable but not yet granted, so C1 opened an access request on the caller's behalf. **The upstream API was not called.** Approval runs through the tool's normal policy — manager approval and the rest — and once the grant lands, the same call executes. +The tool is requestable but not yet granted, so C1.ai opened an access request on the caller's behalf. **The upstream API was not called.** Approval runs through the tool's normal policy — manager approval and the rest — and once the grant lands, the same call executes. ```json { @@ -150,7 +150,7 @@ Executions are capped at 15 minutes total; the polling response reports elapsed - Governing which tools are callable? See [Govern tools and toolsets](/product/admin/tools-and-toolsets). - Constraining calls at runtime? See [Tool call hooks](/product/admin/tool-call-hooks). - Reviewing what agents actually called? See [Audit AI tool usage](/product/admin/audit-ai-tool-usage). -- Connecting a client as an end user? See [Connect your MCP client to C1](/product/how-to/connect-mcp-client). +- Connecting a client as an end user? See [Connect your MCP client to C1.ai](/product/how-to/connect-mcp-client). {/* LLM Note: For AI assistants interacting with ConductorOne's MCP gateway or writing diff --git a/product/admin/customize-requests.mdx b/product/admin/customize-requests.mdx index be39d09f..2bf80cc7 100644 --- a/product/admin/customize-requests.mdx +++ b/product/admin/customize-requests.mdx @@ -1,6 +1,6 @@ --- title: Add instructions and request forms to access requests -og:title: Add instructions and request forms to access requests - C1 docs +og:title: Add instructions and request forms to access requests - C1.ai docs og:description: Use these tools to provide instructions on how to request access, and to collect needed information from requestors. description: Use these tools to provide instructions on how to request access, and to collect needed information from requestors. sidebarTitle: Add instructions and custom forms @@ -16,7 +16,7 @@ You can set instructions on each application that will be shown to users when th -A **Super Admin** or an application owner with the **Application Admin** role in C1 must complete this task. +A **Super Admin** or an application owner with the **Application Admin** role in C1.ai must complete this task. @@ -67,7 +67,7 @@ If [external ticketing](/product/admin/external-ticketing) is configured, inform ### View and manage all forms -The **Platform > Forms** page lists all request forms in your C1 tenant in one place. From here you can create new forms, open any existing form to review or edit its fields, and see which entitlements each form is assigned to — without navigating through individual apps and entitlements. +The **Platform > Forms** page lists all request forms in your C1.ai tenant in one place. From here you can create new forms, open any existing form to review or edit its fields, and see which entitlements each form is assigned to — without navigating through individual apps and entitlements. ### Configure tenant-wide request settings @@ -79,10 +79,10 @@ Click the settings (gear) icon on the **Platform > Forms** page to open a drawer ### Add a request form to an entitlement -A **Super Admin** or an application owner with the **Application Admin** role in C1 must complete this task. +A **Super Admin** or an application owner with the **Application Admin** role in C1.ai must complete this task. -Request forms are set on individual entitlements, so users are asked for information specific to the access they're requesting. Request forms can be reused across apps and entitlements in C1, so you don't have to create them from scratch each time. +Request forms are set on individual entitlements, so users are asked for information specific to the access they're requesting. Request forms can be reused across apps and entitlements in C1.ai, so you don't have to create them from scratch each time. To add an existing request form to an entitlement: @@ -136,7 +136,7 @@ Click **Submit**. ### Create a new request form -A **Super Admin** in C1 must complete this task. +A **Super Admin** in C1.ai must complete this task. When designing and setting up request forms, remember that each entitlement can use only one request form at a time. @@ -151,7 +151,7 @@ Click **New form**. The form creation drawer opens. Give the new form a name and description. - Remember that this form will be available as an option across your C1 installation, so choose a name that will help your colleagues understand the form's purpose. + Remember that this form will be available as an option across your C1.ai installation, so choose a name that will help your colleagues understand the form's purpose. **Optional.** If you want to hide the default **Justification** field when this request form is in use, click to enable **Hide justification field**. If you leave this disabled, the **Justification** field will be included in the request form. @@ -163,7 +163,7 @@ Select the data type for your first field. The current options are: * Text area (a multi-line text field) * Dropdown * Date (a date picker) -* User (a searchable dropdown of C1 users) +* User (a searchable dropdown of C1.ai users) Fill in the field label and provide dropdown options, helper text, a default value, and a placeholder, as needed. Helper text supports markdown — use it to add links, bold text, or lists to guide requesters. The required and available elements vary by field type. Here's an overview of how and where these elements are shown in the access request: @@ -180,7 +180,7 @@ Fill in the field label and provide dropdown options, helper text, a default val Choose whether the field is required. A user cannot submit a request if a required field has not been filled out. -**C1 will always gather required information.** If a request is created without collecting the required information, the request task will be assigned to the user so they can provide the required information before the request approval process begins. This can happen when a request is created in Slack (which does not currently support request forms), or when multiple entitlements are requested at once. +**C1.ai will always gather required information.** If a request is created without collecting the required information, the request task will be assigned to the user so they can provide the required information before the request approval process begins. This can happen when a request is created in Slack (which does not currently support request forms), or when multiple entitlements are requested at once. @@ -200,7 +200,7 @@ You can also open the form creation drawer from within an entitlement: navigate ### Modify a request form -A **Super Admin** in C1 must complete this task. +A **Super Admin** in C1.ai must complete this task. diff --git a/product/admin/decoys.mdx b/product/admin/decoys.mdx index 6f80667c..2c4b50c8 100644 --- a/product/admin/decoys.mdx +++ b/product/admin/decoys.mdx @@ -12,23 +12,23 @@ description: "Plant tripwire credentials that look real but grant no access, and Plant a credential that looks real but grants no access. Any attempt to use it is a high-confidence signal that someone has stolen access. Decoys are tripwire credentials. Plant them where an attacker would look — env files, CI variables, secret managers. -You can configure C1 so that use of a decoy triggers a [Critical finding](/product/admin/findings). +You can configure C1.ai so that use of a decoy triggers a [Critical finding](/product/admin/findings). -Managing decoys requires the **Super Administrator** role in C1. +Managing decoys requires the **Super Administrator** role in C1.ai. ## Plant a decoy -C1 supports five decoy types, each shaped to sit alongside a different kind of real credential: +C1.ai supports five decoy types, each shaped to sit alongside a different kind of real credential: | Decoy type | What it plants | | :--- | :--- | | Human user credential | Client ID + secret planted under an existing human user. | | Service principal credential | Client ID + secret planted under an existing service principal. | -| Connector client credential | Client ID + secret shaped like a connector credential. C1 places it under your tenant's C1 app — there's no app or connector to choose. | +| Connector client credential | Client ID + secret shaped like a connector credential. C1.ai places it under your tenant's C1.ai app — there's no app or connector to choose. | | Workload federation trust | A trust under an existing workload federation provider. Any signature-valid JWT matching its condition triggers a finding. | | Access token | A long-lived API access token issued for an existing user. | -Every decoy type except a connector client credential plants under an existing object — a human user, a service principal, or a registered workload federation provider. C1 places connector client credentials automatically, with nothing to choose. For every other type, make sure the object you need already exists before you start. +Every decoy type except a connector client credential plants under an existing object — a human user, a service principal, or a registered workload federation provider. C1.ai places connector client credentials automatically, with nothing to choose. For every other type, make sure the object you need already exists before you start. @@ -57,10 +57,10 @@ Click **Plant decoy**. -C1 shows the decoy's credential material — a client ID and secret, an access token, or a workload federation trust ID, depending on the type. It also shows a fingerprint. +C1.ai shows the decoy's credential material — a client ID and secret, an access token, or a workload federation trust ID, depending on the type. It also shows a fingerprint. -This is the only time C1 shows this credential material. Save it now: copy each value or download the `.env` file. You'll need to confirm you've saved it before this screen closes. If you lose it, rotate the decoy to get a new one. +This is the only time C1.ai shows this credential material. Save it now: copy each value or download the `.env` file. You'll need to confirm you've saved it before this screen closes. If you lose it, rotate the decoy to get a new one. Save the fingerprint alongside wherever you place the secret. It's how you'll recognize which planted copy fired when you see the resulting finding. @@ -70,21 +70,21 @@ Save the fingerprint alongside wherever you place the secret. It's how you'll re Open a decoy from the list to edit its display name, description, or annotations, or to take one of the following actions from the **...** (more actions) menu: - **Disable** — stops the decoy from triggering findings without deleting it. Past findings stay in history. You can re-enable it at any time. -- **Rotate** — mints a new secret for the decoy and invalidates the old one. C1 shows the new credential material once, the same as when you first planted it. +- **Rotate** — mints a new secret for the decoy and invalidates the old one. C1.ai shows the new credential material once, the same as when you first planted it. - **Delete** — removes the decoy from the list and stops it from triggering findings. Past findings stay in history. ## What happens when a decoy is used -Any attempt to authenticate with a planted decoy credential triggers two things. Whoever presented it gets an ordinary authentication failure — there's no way to tell a decoy apart from a real bad credential. C1 also records the attempt. +Any attempt to authenticate with a planted decoy credential triggers two things. Whoever presented it gets an ordinary authentication failure — there's no way to tell a decoy apart from a real bad credential. C1.ai also records the attempt. -If the **Decoy credential used** [finding type](/product/admin/findings#turn-on-finding-types) is turned on, C1 raises a Critical finding when the decoy is used. Repeated use of the same decoy doesn't create duplicate findings — it's tracked as recurrences of the same finding. If the finding had been resolved, it reopens. +If the **Decoy credential used** [finding type](/product/admin/findings#turn-on-finding-types) is turned on, C1.ai raises a Critical finding when the decoy is used. Repeated use of the same decoy doesn't create duplicate findings — it's tracked as recurrences of the same finding. If the finding had been resolved, it reopens. -Turning off the **Decoy credential used** finding type stops the finding from being created. C1 still records every use to your audit log regardless. Quieting the finding doesn't cost you the trail. +Turning off the **Decoy credential used** finding type stops the finding from being created. C1.ai still records every use to your audit log regardless. Quieting the finding doesn't cost you the trail. The resulting finding includes an **Attempts** table with the forensic detail you need for incident response — timestamp, source IP, user agent, and endpoint for every attempt. Each row also includes the raw event detail behind it. -If a decoy's secret turns up published somewhere public — a paste site, a public repository — C1 can raise a separate **Decoy publicly exposed** finding. The finding includes the scanner that found it, where it was found, and when. +If a decoy's secret turns up published somewhere public — a paste site, a public repository — C1.ai can raise a separate **Decoy publicly exposed** finding. The finding includes the scanner that found it, where it was found, and when. See [Findings](/product/admin/findings) for how to turn on these finding types and build rules around them. diff --git a/product/admin/delegate.mdx b/product/admin/delegate.mdx index b276255e..bb00a6d4 100644 --- a/product/admin/delegate.mdx +++ b/product/admin/delegate.mdx @@ -1,19 +1,19 @@ --- title: Delegate a user's tasks -og:title: Delegate a user's tasks - C1 docs -og:description: Set a delegate for a user who should not or cannot be assigned C1 tasks. Tasks will be automatically reassigned to the delegated user unless the task's policy doesn't allow delegation. -description: Set a delegate for a user who should not or cannot be assigned C1 tasks. Tasks will be automatically reassigned to the delegated user unless the task's policy doesn't allow delegation. +og:title: Delegate a user's tasks - C1.ai docs +og:description: Set a delegate for a user who should not or cannot be assigned C1.ai tasks. Tasks will be automatically reassigned to the delegated user unless the task's policy doesn't allow delegation. +description: Set a delegate for a user who should not or cannot be assigned C1.ai tasks. Tasks will be automatically reassigned to the delegated user unless the task's policy doesn't allow delegation. sidebarTitle: Delegate a user's tasks --- {/* Editor Refresh: 2026-01-07 */} ## When should I set a delegate? -In some cases, you might not want to assign C1 tasks or send the corresponding notifications to certain users. For example, if a policy assigns access review or access request tasks to an executive, you might want to automatically redirect those tasks to a lower-level employee. If an employee is on extended leave, you might need to delegate their tasks to a colleague or manager until they return. In cases like these, you can set a delegate for the user. Users can also set their own delegate from their profile menu. +In some cases, you might not want to assign C1.ai tasks or send the corresponding notifications to certain users. For example, if a policy assigns access review or access request tasks to an executive, you might want to automatically redirect those tasks to a lower-level employee. If an employee is on extended leave, you might need to delegate their tasks to a colleague or manager until they return. In cases like these, you can set a delegate for the user. Users can also set their own delegate from their profile menu. ## Set your own delegate -For times when you'll be out of the office and unable to complete C1 tasks, you can set a delegate on your own account. +For times when you'll be out of the office and unable to complete C1.ai tasks, you can set a delegate on your own account. @@ -31,7 +31,7 @@ Select the user to whom you want to delegate tasks. Only one delegate per user i If you chose to set a **Temporary** delegate, set the delegation period's start and end dates. - C1 cannot retroactively reassign tasks to your delegate if you set a start date in the past. If you set today's date as the start date, C1 will begin enforcing your delegation rule when you save your changes. + C1.ai cannot retroactively reassign tasks to your delegate if you set a start date in the past. If you set today's date as the start date, C1.ai will begin enforcing your delegation rule when you save your changes. Click **Save**. @@ -41,13 +41,13 @@ Click **Save**. New tasks will now be automatically reassigned to your chosen delegate, except when prevented by policy rules. Each task's audit log will contain an entry showing the delegation reassignment. All email and Slack notifications for the task will also be sent to the delegate. -Delegation applies only to tasks created **after** the delegate is set. C1 does not reassign tasks that were already open when you added the delegate — they remain assigned to the original user. To move an existing task, reassign it manually from the task's details page (subject to the governing policy's reassignment rules). +Delegation applies only to tasks created **after** the delegate is set. C1.ai does not reassign tasks that were already open when you added the delegate — they remain assigned to the original user. To move an existing task, reassign it manually from the task's details page (subject to the governing policy's reassignment rules). ## Set a delegate for another user -This task requires the **Super Administrator** role in C1. +This task requires the **Super Administrator** role in C1.ai. @@ -77,7 +77,7 @@ Click **Save**. New tasks will now be automatically reassigned to the user's delegate, except when prevented by policy rules. Each task's audit log will contain an entry showing the delegation reassignment. All email and Slack notifications for the task will also be sent to the delegate, and not to the original user. -Delegation applies only to tasks created **after** the delegate is set. C1 does not reassign tasks that were already open when the delegate was added. To move an existing task, reassign it manually from the task's details page (subject to the governing policy's reassignment rules). +Delegation applies only to tasks created **after** the delegate is set. C1.ai does not reassign tasks that were already open when the delegate was added. To move an existing task, reassign it manually from the task's details page (subject to the governing policy's reassignment rules). ## Delegation in policies diff --git a/product/admin/directory.mdx b/product/admin/directory.mdx index a962b324..5c0ee836 100644 --- a/product/admin/directory.mdx +++ b/product/admin/directory.mdx @@ -1,6 +1,6 @@ --- title: Connect a directory -og:title: Connect a directory - C1 docs +og:title: Connect a directory - C1.ai docs og:description: Integrate your directory and designate sources of truth for employee information. description: Integrate your directory and designate sources of truth for employee information. --- @@ -8,7 +8,7 @@ description: Integrate your directory and designate sources of truth for employe ## What is a directory? -An application that holds a record for every person in your organization should be designated as your directory in C1. +An application that holds a record for every person in your organization should be designated as your directory in C1.ai. This single source of truth is typically one of these: @@ -18,19 +18,19 @@ This single source of truth is typically one of these: * [A custom app](/product/admin/applications#create-a-new-application) using a spreadsheet or CSV of employee data. -Once the directory is designated, C1 uses its data to automatically create C1 user accounts for everyone in your company. +Once the directory is designated, C1.ai uses its data to automatically create C1.ai user accounts for everyone in your company. ## Account to user flow -Every account from every connector takes one of two paths before it becomes — or attaches to — a C1 user, depending on whether the connector is on your directory app. Directory apps drive identity creation; accounts from non-directory apps attach to users that already exist. +Every account from every connector takes one of two paths before it becomes — or attaches to — a C1.ai user, depending on whether the connector is on your directory app. Directory apps drive identity creation; accounts from non-directory apps attach to users that already exist. ### Key terms - **[Account](/product/glossary#account)** — A unique record for an actor (a human, a service account, or a system account) inside an application. -- **[User](/product/glossary#user)** — A human at your organization whose access data is synced to C1 and who can be assigned tasks in C1. -- **[Directory filter](/product/admin/directory#optional-limit-which-accounts-will-be-pulled-into-c1)** — A CEL expression that decides whether an account from your directory should create (or match) a C1 user. -- **[User identification rules](/product/admin/directory#configure-merge-matching)** — The merge-matching rules that determine whether an incoming directory account links to an existing C1 user instead of creating a new one. -- **[Account ownership rules](/product/admin/managing-accounts#auto-match-accounts-with-users)** — The matching strategy (Narrow, Broad, or Custom) used to assign an account from a non-directory app to a C1 user as its owner. +- **[User](/product/glossary#user)** — A human at your organization whose access data is synced to C1.ai and who can be assigned tasks in C1.ai. +- **[Directory filter](/product/admin/directory#optional-limit-which-accounts-will-be-pulled-into-c1)** — A CEL expression that decides whether an account from your directory should create (or match) a C1.ai user. +- **[User identification rules](/product/admin/directory#configure-merge-matching)** — The merge-matching rules that determine whether an incoming directory account links to an existing C1.ai user instead of creating a new one. +- **[Account ownership rules](/product/admin/managing-accounts#auto-match-accounts-with-users)** — The matching strategy (Narrow, Broad, or Custom) used to assign an account from a non-directory app to a C1.ai user as its owner. ```mermaid flowchart LR @@ -60,27 +60,27 @@ Directory apps that pass the filter with `CREATE` either link to an existing use #### One person, many apps -A user has accounts in Okta, GitHub, Workday, and Slack. All four accounts link to one C1 user via primary-email match, and profile attributes are aggregated from each app according to the configured [attribute mapping priorities](/product/admin/attributes). +A user has accounts in Okta, GitHub, Workday, and Slack. All four accounts link to one C1.ai user via primary-email match, and profile attributes are aggregated from each app according to the configured [attribute mapping priorities](/product/admin/attributes). #### Identity provider plus apps -When an IdP connector (Okta, Entra ID) is configured, it typically syncs the largest set of identities and serves as the de-facto source of truth — most other apps' accounts find a C1 user to link to via the IdP's primary emails. The IdP also produces an IdP record per user, which keeps the C1 user retained for audit even after every other account is removed. +When an IdP connector (Okta, Entra ID) is configured, it typically syncs the largest set of identities and serves as the de-facto source of truth — most other apps' accounts find a C1.ai user to link to via the IdP's primary emails. The IdP also produces an IdP record per user, which keeps the C1.ai user retained for audit even after every other account is removed. #### Service account aliased to a human -A human's secondary email is also listed as a service-account address in your directory app. Without intervention, the alias-email match path can link the service-account to the human's C1 user. Resolve this by unlinking the service account in the C1 UI, or by filtering service accounts out at the [directory level](/product/admin/directory#optional-limit-which-accounts-will-be-pulled-into-c1) using `IGNORE`. For service accounts in non-directory apps, only the UI unlink applies. +A human's secondary email is also listed as a service-account address in your directory app. Without intervention, the alias-email match path can link the service-account to the human's C1.ai user. Resolve this by unlinking the service account in the C1.ai UI, or by filtering service accounts out at the [directory level](/product/admin/directory#optional-limit-which-accounts-will-be-pulled-into-c1) using `IGNORE`. For service accounts in non-directory apps, only the UI unlink applies. #### MATCH_ONLY directory for shadow imports -A secondary HR system is configured in `MATCH_ONLY` mode so its accounts can enrich C1 users with HR attributes (employee ID, manager, and so on) without inflating the user count. Accounts from that directory that don't match an existing C1 user are left unmerged until a primary-directory account creates the identity. +A secondary HR system is configured in `MATCH_ONLY` mode so its accounts can enrich C1.ai users with HR attributes (employee ID, manager, and so on) without inflating the user count. Accounts from that directory that don't match an existing C1.ai user are left unmerged until a primary-directory account creates the identity. ## Connect a directory and create user accounts -As part of setting up C1 for your organization, designate a key app as your directory, which will serve as the source of truth for creating C1 user accounts. +As part of setting up C1.ai for your organization, designate a key app as your directory, which will serve as the source of truth for creating C1.ai user accounts. ### Step 1: Integrate an app that holds employee records -First, [set up an application in C1](/product/admin/applications#create-a-new-application) that holds a record for each employee, such as your HR system or your identity provider (IdP). +First, [set up an application in C1.ai](/product/admin/applications#create-a-new-application) that holds a record for each employee, such as your HR system or your identity provider (IdP). Browse the [connectors library](/baton/intro) for a list of available direct integrations, and [let us know](mailto:support@c1.ai) if you don't find what you're looking for. @@ -88,7 +88,7 @@ You can also [create a new app](/product/admin/applications#create-a-new-applica ### Step 2: Set the app as the directory -Next, tell C1 that the app you've integrated is your directory. +Next, tell C1.ai that the app you've integrated is your directory. @@ -102,16 +102,16 @@ On the **Directories** tab, click **Add directory data source**. Select an application in the dropdown. Only apps that have been set up and synced at least once are available to select. -**Optional.** Follow the docs if you want to [limit which accounts will be pulled into C1](/product/admin/directory#optional-limit-which-accounts-will-be-pulled-into-c1) or [specify a custom merge matching strategy](/product/admin/directory#configure-merge-matching). You can also edit these settings later if you're not ready to configure them now. +**Optional.** Follow the docs if you want to [limit which accounts will be pulled into C1.ai](/product/admin/directory#optional-limit-which-accounts-will-be-pulled-into-c1) or [specify a custom merge matching strategy](/product/admin/directory#configure-merge-matching). You can also edit these settings later if you're not ready to configure them now. Click **Create directory**. -### Optional: Limit which accounts will be pulled into C1 +### Optional: Limit which accounts will be pulled into C1.ai -By default, C1 imports all accounts from a designated directory. To import only a subset, set an account import condition. +By default, C1.ai imports all accounts from a designated directory. To import only a subset, set an account import condition. @@ -123,7 +123,7 @@ Click the **...** (more actions) menu to the right of the directory and select * Under **Which accounts should be imported from this directory?**, select an option: -- **All accounts** — imports every account as a C1 user. This is the default. +- **All accounts** — imports every account as a C1.ai user. This is the default. - **Condition** — imports only accounts that match a rule you build from entitlements and account attributes using the visual condition builder. - **Custom CEL** — write a raw CEL expression for filters the condition builder doesn't support. @@ -131,8 +131,8 @@ Under **Which accounts should be imported from this directory?**, select an opti **Working with custom CEL return values:** A **Custom CEL** expression can return a Boolean for simple include/exclude, or a string for finer control: -- `"CREATE"` (or `true`) — match to an existing C1 user, or create a new user if no match exists. -- `"MATCH_ONLY"` — link to an existing C1 user only; never create a new user from it. +- `"CREATE"` (or `true`) — match to an existing C1.ai user, or create a new user if no match exists. +- `"MATCH_ONLY"` — link to an existing C1.ai user only; never create a new user from it. - `"IGNORE"` (or `false`) — skip this account entirely. @@ -144,17 +144,17 @@ Click **Next**, then **Save**. -Your condition is shown in the directory's **Account import condition** column. Any existing C1 users who no longer match the condition will be removed on the next directory sync. +Your condition is shown in the directory's **Account import condition** column. Any existing C1.ai users who no longer match the condition will be removed on the next directory sync. -### Step 3: C1 creates user accounts from your directory app +### Step 3: C1.ai creates user accounts from your directory app -When an app is set as a directory, C1 automatically uses the info in the directory's accounts to create C1 user accounts. Each user's email address is the key data point. +When an app is set as a directory, C1.ai automatically uses the info in the directory's accounts to create C1.ai user accounts. Each user's email address is the key data point. -Accounts from various apps integrated with C1 are all tied to the same human user because they all share an email address. +Accounts from various apps integrated with C1.ai are all tied to the same human user because they all share an email address. ## Configure merge matching -By default, C1 matches directory accounts to C1 users by comparing email address and employee ID. Custom merge matching lets you replace those rules with your own ordered set — useful when your directory uses different identifiers or when you need finer control over how accounts are linked. +By default, C1.ai matches directory accounts to C1.ai users by comparing email address and employee ID. Custom merge matching lets you replace those rules with your own ordered set — useful when your directory uses different identifiers or when you need finer control over how accounts are linked. These settings are available both when adding a new directory and when editing an existing one. @@ -174,33 +174,33 @@ In the **Custom merge matching** section, select **Custom**. The rules list pre-populates with the default rules as a starting point. -Configure your rules. Each rule pairs a **Directory source account field** with a **C1 user field**. Available fields are: **Primary email**, **All emails**, **Username**, **Display name**, and **Employee ID**. +Configure your rules. Each rule pairs a **Directory source account field** with a **C1.ai user field**. Available fields are: **Primary email**, **All emails**, **Username**, **Display name**, and **Employee ID**. For email fields, check **Remove + suffix** to normalize addresses before comparing — for example, `user+tag@example.com` is treated as `user@example.com`. To write a custom [CEL expression](/product/admin/expressions) instead of using a preset field, click the **Switch to CEL expression** icon. -Add, remove, or reorder rules as needed. Rules are evaluated in order — C1 uses the first rule that produces a match. +Add, remove, or reorder rules as needed. Rules are evaluated in order — C1.ai uses the first rule that produces a match. Click **Update**. -**Done.** C1 will use your custom merge rules on the next directory sync. +**Done.** C1.ai will use your custom merge rules on the next directory sync. To revert to default matching at any time, select **Default** and click **Update**. ## Edit user details -C1 does not edit core user details (such as email, name, or employee ID) in place. These fields are sourced from your directory app and refresh from that source on every sync. +C1.ai does not edit core user details (such as email, name, or employee ID) in place. These fields are sourced from your directory app and refresh from that source on every sync. -- **To change core details** (email, name, employee ID, department, job title, and other synced fields): edit the value in the source app that supplies the attribute (for example, your IdP or HRIS). The change propagates to C1 on the next directory sync. Which app supplies each field is configured under **Identities** > **Directory sources** > **Attribute manager** — see [Map user attributes](/product/admin/attributes). -- **To change a user's role in C1**: go to **Identities** > **Users**, click the **...** (more actions) menu next to the user, then select **Change role**. See [User roles](/product/admin/user-roles). +- **To change core details** (email, name, employee ID, department, job title, and other synced fields): edit the value in the source app that supplies the attribute (for example, your IdP or HRIS). The change propagates to C1.ai on the next directory sync. Which app supplies each field is configured under **Identities** > **Directory sources** > **Attribute manager** — see [Map user attributes](/product/admin/attributes). +- **To change a user's role in C1.ai**: go to **Identities** > **Users**, click the **...** (more actions) menu next to the user, then select **Change role**. See [User roles](/product/admin/user-roles). - **To add or override profile attributes on a user**: use **Identities** > **Users** > *user* > **Profile attributes**. These are the custom attributes described in [Map user attributes](/product/admin/attributes#create-and-map-custom-user-attributes). -There is no API endpoint for updating a user's synced details in C1. The `/api/v1/users` endpoints are read-only (list and get). Update the value in the source directory app instead. +There is no API endpoint for updating a user's synced details in C1.ai. The `/api/v1/users` endpoints are read-only (list and get). Update the value in the source directory app instead. diff --git a/product/admin/dynamic-access-control.mdx b/product/admin/dynamic-access-control.mdx index 5b447836..43051239 100644 --- a/product/admin/dynamic-access-control.mdx +++ b/product/admin/dynamic-access-control.mdx @@ -1,6 +1,6 @@ --- title: "Automate onboarding & offboarding access changes" -og:title: "Automate onboarding & offboarding access changes - C1 docs" +og:title: "Automate onboarding & offboarding access changes - C1.ai docs" og:description: "Automatically create access profile enrollment or unenrollment requests for users who match (or no longer match) an enrollment rule. Ideal for onboarding, offboarding, and other cases when users are joining or leaving a team, role, or organization." description: "Automatically create access profile enrollment or unenrollment requests for users who match (or no longer match) an enrollment rule. Ideal for onboarding, offboarding, and other cases when users are joining or leaving a team, role, or organization." sidebarTitle: Automate JML flows @@ -9,7 +9,7 @@ sidebarTitle: Automate JML flows ## How do enrollment and unenrollment work? -An [access profile](/product/admin/profiles) is a resource in the [C1 app](/product/admin/c1-for-c1). When a user matches the membership condition on the access profile, a request task for the access profile's **enrollment** entitlement is automatically created. When this request is approved, the user is _enrolled_ in the access profile and automatically requests all of its access, all without the user, their manager, or the IT team manually creating a single access request. +An [access profile](/product/admin/profiles) is a resource in the [C1.ai app](/product/admin/c1-for-c1). When a user matches the membership condition on the access profile, a request task for the access profile's **enrollment** entitlement is automatically created. When this request is approved, the user is _enrolled_ in the access profile and automatically requests all of its access, all without the user, their manager, or the IT team manually creating a single access request. When the user no longer matches the membership condition on the access profile, a revocation task for the **enrollment** entitlement is automatically created. When this revocation is confirmed, the user is _unenrolled_ from the access profile. You can configure the access profile to determine to what happens to the user's access in this case (more on this below). @@ -17,7 +17,7 @@ When the user no longer matches the membership condition on the access profile, It depends. When a user is assigned the enrollment entitlement for the access profile, a request task is created. Based on the request policy set on the access profile, the request for enrollment might be auto-approved, or it might need one or more human reviewers to sign off. -Once the user's request for access to the enrollment entitlement is granted, C1 will automatically create access request tasks for each item in the access profile. Based on the request policies on each individual entitlement, this access might be automatically approved, or it might require human intervention to approve and provision. +Once the user's request for access to the enrollment entitlement is granted, C1.ai will automatically create access request tasks for each item in the access profile. Based on the request policies on each individual entitlement, this access might be automatically approved, or it might require human intervention to approve and provision. If an access profile contains only low-risk access, you can set the policies on the access profile itself and the entitlements within it to automatically approve these requests, essentially granting users who are enrolled in the access profile all of its access immediately. @@ -27,7 +27,7 @@ Here too, it depends. When setting up the access profile, you have the option to When a user is unenrolled from the access profile, a revocation task for the enrollment entitlement is created. Based on the revoke policy set on the access profile, the revocation might be auto-approved, or it might need one or more human reviewers to sign off. -Once revocation has been confirmed, C1 will follow the rules set up in the access profile to determine what to do with the user's access. The options here are: +Once revocation has been confirmed, C1.ai will follow the rules set up in the access profile to determine what to do with the user's access. The options here are: * Do nothing, and leave the access granted by the access profile as-is @@ -64,9 +64,9 @@ In the **Joiner** section of the page, click **Edit** and set the following: Select the approval policy that will be used for this access profile's **enrollment** entitlement. -When a user is added to the access profile via membership automation, C1 creates a request task for their access to the access profile's **enrollment** entitlement. The user will not be added to the list of enrolled users until this request is approved. +When a user is added to the access profile via membership automation, C1.ai creates a request task for their access to the access profile's **enrollment** entitlement. The user will not be added to the list of enrolled users until this request is approved. -If you don't set an approval policy here, the access profile will use the default policy set on the [C1 app](/product/admin/c1-for-c1). +If you don't set an approval policy here, the access profile will use the default policy set on the [C1.ai app](/product/admin/c1-for-c1). Once the user's enrollment in the access profile has been approved, access request tasks are created for each entitlement in the access profile. Select whether these request tasks should apply the approval policy on their respective entitlements, or whether they can bypass the individual entitlements' policies. @@ -89,9 +89,9 @@ In the **Leaver** section of the page, click **Edit** and set the following: Select the revocation policy that will be used for this access profile's **enrollment** entitlement. -When a user is removed from the access profile via membership automation, C1 creates a revoke task for their access to the access profile's **enrollment** entitlement. The user will not be removed from the list of enrolled users until this revocation is confirmed. +When a user is removed from the access profile via membership automation, C1.ai creates a revoke task for their access to the access profile's **enrollment** entitlement. The user will not be removed from the list of enrolled users until this revocation is confirmed. -If you don't set a revocation policy here, the access profile will use the default policy set on the [C1 app](/product/admin/c1-for-c1). +If you don't set a revocation policy here, the access profile will use the default policy set on the [C1.ai app](/product/admin/c1-for-c1). Set what to do with the access that has been granted by the access profile when a user is unenrolled. You can: @@ -153,11 +153,11 @@ While request tasks await approval, you'll see a count of **pending members** on The Members page. -As request tasks are approved, users will be added to the **Members** list, and C1 will create access requests for the full contents of the access profile. +As request tasks are approved, users will be added to the **Members** list, and C1.ai will create access requests for the full contents of the access profile. ## Safeguards for automated access changes -By default, C1 pauses any membership automation sync that would remove more than 20% of a profile's members within a single hour. This safeguard applies to access profiles with 100 or more members. The threshold is configurable — open the automation's edit drawer and adjust **Removed members threshold (%)** in the **Anomaly detection** section to set a different cutoff. +By default, C1.ai pauses any membership automation sync that would remove more than 20% of a profile's members within a single hour. This safeguard applies to access profiles with 100 or more members. The threshold is configurable — open the automation's edit drawer and adjust **Removed members threshold (%)** in the **Anomaly detection** section to set a different cutoff. The Anomaly detection section of the membership automation edit drawer, showing the Pause automation when anomalies are detected toggle and the Removed members threshold (%) field set to 20. @@ -183,7 +183,7 @@ Click **Save**. ### Review a paused membership automation sync -When a membership automation sync triggers a safeguard and is paused, you'll see alerts on the main **Access profile** page and the impacted access profile's details page alerting you to the fact. If your organization uses Slack, C1 admins will also receive a Slack message about the pause. +When a membership automation sync triggers a safeguard and is paused, you'll see alerts on the main **Access profile** page and the impacted access profile's details page alerting you to the fact. If your organization uses Slack, C1.ai admins will also receive a Slack message about the pause. @@ -193,7 +193,7 @@ Navigate to the impacted access profile and click **Review** in the banner at th Review the list of access profile members staged for review. - If the list of members looks correct, click **Resume sync** to tell C1 to proceed. + If the list of members looks correct, click **Resume sync** to tell C1.ai to proceed. If the list of members doesn't look correct, click **Go back** and make changes as necessary in the **Membership automation** section of the page. diff --git a/product/admin/email-provider-aws-ses.mdx b/product/admin/email-provider-aws-ses.mdx index f33667d4..c7ad297f 100644 --- a/product/admin/email-provider-aws-ses.mdx +++ b/product/admin/email-provider-aws-ses.mdx @@ -1,17 +1,17 @@ --- -title: Send C1 notifications from AWS SES -og:title: Send C1 notifications from AWS SES - C1 docs -og:description: Configure C1 to send notification emails through your own AWS Simple Email Service account so recipients see your company's domain as the sender. -description: Configure C1 to send notification emails through your own AWS Simple Email Service account so recipients see your company's domain as the sender. +title: Send C1.ai notifications from AWS SES +og:title: Send C1.ai notifications from AWS SES - C1.ai docs +og:description: Configure C1.ai to send notification emails through your own AWS Simple Email Service account so recipients see your company's domain as the sender. +description: Configure C1.ai to send notification emails through your own AWS Simple Email Service account so recipients see your company's domain as the sender. sidebarTitle: AWS SES --- {/* Editor Refresh: 2026-04-27 */} -By default, C1 sends notifications from `no-reply@conductorone.com`. You can instead send through your own AWS Simple Email Service (SES) account so recipients see your company's domain as the sender. +By default, C1.ai sends notifications from `no-reply@conductorone.com`. You can instead send through your own AWS Simple Email Service (SES) account so recipients see your company's domain as the sender. -This task requires the **Super Admin** role in C1 and permission to create IAM roles and verify identities in your AWS account. +This task requires the **Super Admin** role in C1.ai and permission to create IAM roles and verify identities in your AWS account. -C1 authenticates to your AWS account via IAM role assumption with an External ID — no access keys or secrets are shared with C1. You keep full control of the role and can revoke access at any time by deleting it. +C1.ai authenticates to your AWS account via IAM role assumption with an External ID — no access keys or secrets are shared with C1.ai. You keep full control of the role and can revoke access at any time by deleting it. ## Before you begin @@ -47,13 +47,13 @@ If your account is still in the SES sandbox (the default for new accounts), you -## Step 2: Open C1 and copy your tenant's External ID +## Step 2: Open C1.ai and copy your tenant's External ID -C1 generates a unique External ID per tenant. This value is used in your IAM role's trust policy so that only your C1 tenant can assume the role. +C1.ai generates a unique External ID per tenant. This value is used in your IAM role's trust policy so that only your C1.ai tenant can assume the role. -In C1, navigate to **Settings** > **Email provider**. +In C1.ai, navigate to **Settings** > **Email provider**. Click **Edit**. @@ -70,17 +70,17 @@ In the **AWS SES configuration** section, click the copy icon next to the **Exte -The External ID is tenant-specific. Do not reuse External IDs across tenants. If you manage multiple C1 tenants, each needs its own IAM role with its own External ID. +The External ID is tenant-specific. Do not reuse External IDs across tenants. If you manage multiple C1.ai tenants, each needs its own IAM role with its own External ID. -Leave the C1 edit form open — you'll return to it in Step 4 to finish configuration. +Leave the C1.ai edit form open — you'll return to it in Step 4 to finish configuration. ## Step 3: Create the IAM role -Create a role in your AWS account that C1 can assume to send mail. +Create a role in your AWS account that C1.ai can assume to send mail. -C1 uses a dedicated, isolated AWS account for customer integrations. The only principal that can assume your role is `arn:aws:iam::765656841499:role/ConductorOneService`. The External ID condition ensures only your tenant's assume-role calls succeed. +C1.ai uses a dedicated, isolated AWS account for customer integrations. The only principal that can assume your role is `arn:aws:iam::765656841499:role/ConductorOneService`. The External ID condition ensures only your tenant's assume-role calls succeed. @@ -139,11 +139,11 @@ On the role's detail page, open the **Permissions** tab and click **Add permissi Name the policy (for example, `c1-ses-send`) and save. -Copy the role's ARN (for example, `arn:aws:iam::123456789012:role/c1-ses-sender`). You'll paste this into C1 in the next step. +Copy the role's ARN (for example, `arn:aws:iam::123456789012:role/c1-ses-sender`). You'll paste this into C1.ai in the next step. -## Step 4: Finish configuring the email provider in C1 +## Step 4: Finish configuring the email provider in C1.ai Return to the **Settings** > **Email provider** edit form you left open in Step 2. @@ -163,7 +163,7 @@ Click **Save**. -When you save, C1 validates the full assume-role chain by calling `sts:GetCallerIdentity` against your role. If the role ARN, trust policy, or External ID is wrong, save fails with a clear error and your previous configuration is preserved. +When you save, C1.ai validates the full assume-role chain by calling `sts:GetCallerIdentity` against your role. If the role ARN, trust policy, or External ID is wrong, save fails with a clear error and your previous configuration is preserved. **Sender must be a verified SES identity** @@ -173,7 +173,7 @@ The address in **Sender email address** must be verified in SES — either direc ## Step 5: Verify -Send a test message to confirm C1 can send through SES and that your email authentication records are passing. +Send a test message to confirm C1.ai can send through SES and that your email authentication records are passing. diff --git a/product/admin/email-provider-google-workspace.mdx b/product/admin/email-provider-google-workspace.mdx index 62695a11..8af51f42 100644 --- a/product/admin/email-provider-google-workspace.mdx +++ b/product/admin/email-provider-google-workspace.mdx @@ -1,15 +1,15 @@ --- -title: Send C1 notifications from Google Workspace -og:title: Send C1 notifications from Google Workspace - C1 docs -og:description: Configure C1 to send notification emails through your own Google Workspace mailbox so recipients see your company's domain as the sender. -description: Configure C1 to send notification emails through your own Google Workspace mailbox so recipients see your company's domain as the sender. +title: Send C1.ai notifications from Google Workspace +og:title: Send C1.ai notifications from Google Workspace - C1.ai docs +og:description: Configure C1.ai to send notification emails through your own Google Workspace mailbox so recipients see your company's domain as the sender. +description: Configure C1.ai to send notification emails through your own Google Workspace mailbox so recipients see your company's domain as the sender. sidebarTitle: Google Workspace --- {/* Editor Refresh: 2026-04-27 */} -By default, C1 sends notifications from `no-reply@conductorone.com`. You can instead send from your own Google Workspace mailbox so recipients see your company's domain as the sender. +By default, C1.ai sends notifications from `no-reply@conductorone.com`. You can instead send from your own Google Workspace mailbox so recipients see your company's domain as the sender. -This task requires the **Super Admin** role in C1 and the **Super Admin** role in Google Workspace. +This task requires the **Super Admin** role in C1.ai and the **Super Admin** role in Google Workspace. ## Before you begin @@ -25,7 +25,7 @@ You'll need: ## Step 1: Create a dedicated sender mailbox -The address that C1 sends mail as must be a real, licensed user in Google Workspace — not an alias, group, or forwarding address. +The address that C1.ai sends mail as must be a real, licensed user in Google Workspace — not an alias, group, or forwarding address. @@ -51,14 +51,14 @@ Gmail API calls fail for users who have never completed first login. ## Step 2: Create a GCP service account -C1 uses a GCP service account to call the Gmail API on behalf of your sender mailbox. Create the service account in the same GCP organization as your Workspace tenant. +C1.ai uses a GCP service account to call the Gmail API on behalf of your sender mailbox. Create the service account in the same GCP organization as your Workspace tenant. Sign in to the [Google Cloud console](https://console.cloud.google.com) as a super admin. -Create a new project or select an existing one for the C1 email integration. +Create a new project or select an existing one for the C1.ai email integration. In the navigation menu, go to **APIs & Services** > **Library**. @@ -73,13 +73,13 @@ Navigate to **APIs & Services** > **Credentials**. Click **Create credentials** > **Service account**. -Set a name (for example, C1 Email Sender) and click **Create and continue**. No project roles are required — click **Continue**, then **Done**. +Set a name (for example, C1.ai Email Sender) and click **Create and continue**. No project roles are required — click **Continue**, then **Done**. In the service account list, click the service account you just created. -Open the **Keys** tab. Click **Add key** > **Create new key**, choose **JSON** format, and click **Create**. Save the downloaded JSON file securely — you'll upload it to C1 in Step 4. +Open the **Keys** tab. Click **Add key** > **Create new key**, choose **JSON** format, and click **Create**. Save the downloaded JSON file securely — you'll upload it to C1.ai in Step 4. On the service account's **Details** tab, copy the **OAuth 2 Client ID** (a numeric string like `108123456789012345678`). You'll need it for Step 3. @@ -123,13 +123,13 @@ Click **Authorize**. This is a one-time, domain-wide grant. Adding new sender mailboxes later does not require repeating this step. -## Step 4: Configure the email provider in C1 +## Step 4: Configure the email provider in C1.ai -Enter the sender mailbox and service account credentials from the previous steps in C1 to activate the integration. +Enter the sender mailbox and service account credentials from the previous steps in C1.ai to activate the integration. -In C1, navigate to **Settings** > **Email provider**. +In C1.ai, navigate to **Settings** > **Email provider**. Click **Edit**. @@ -162,7 +162,7 @@ Gmail only allows sending with a From: address that matches the authenticated us ## Step 5: Verify -Send a test message to confirm C1 can send through your Workspace mailbox and that your email authentication records are passing. +Send a test message to confirm C1.ai can send through your Workspace mailbox and that your email authentication records are passing. diff --git a/product/admin/email-provider-microsoft-365.mdx b/product/admin/email-provider-microsoft-365.mdx index 59478461..902f6b12 100644 --- a/product/admin/email-provider-microsoft-365.mdx +++ b/product/admin/email-provider-microsoft-365.mdx @@ -1,17 +1,17 @@ --- -title: Send C1 notifications from Microsoft 365 -og:title: Send C1 notifications from Microsoft 365 - C1 docs -og:description: Configure C1 to send notification emails through your Microsoft 365 tenant using the Microsoft Graph sendMail API so recipients see your company's domain as the sender. -description: Configure C1 to send notification emails through your Microsoft 365 tenant using the Microsoft Graph sendMail API so recipients see your company's domain as the sender. +title: Send C1.ai notifications from Microsoft 365 +og:title: Send C1.ai notifications from Microsoft 365 - C1.ai docs +og:description: Configure C1.ai to send notification emails through your Microsoft 365 tenant using the Microsoft Graph sendMail API so recipients see your company's domain as the sender. +description: Configure C1.ai to send notification emails through your Microsoft 365 tenant using the Microsoft Graph sendMail API so recipients see your company's domain as the sender. sidebarTitle: Microsoft 365 --- {/* Editor Refresh: 2026-04-27 */} -By default, C1 sends notifications from `no-reply@conductorone.com`. You can instead send through your own Microsoft 365 tenant using the Microsoft Graph `sendMail` API, so recipients see your company's domain as the sender. +By default, C1.ai sends notifications from `no-reply@conductorone.com`. You can instead send through your own Microsoft 365 tenant using the Microsoft Graph `sendMail` API, so recipients see your company's domain as the sender. -This task requires the **Super Admin** role in C1 and the **Application Administrator** (or **Global Administrator**) role in Entra ID, plus an Exchange Online administrator who can configure mailbox access policies. +This task requires the **Super Admin** role in C1.ai and the **Application Administrator** (or **Global Administrator**) role in Entra ID, plus an Exchange Online administrator who can configure mailbox access policies. -C1 authenticates to your tenant via an Entra ID app registration with the `Mail.Send` application permission. No user passwords are shared with C1, and you can revoke access at any time by removing the client secret or deleting the app. +C1.ai authenticates to your tenant via an Entra ID app registration with the `Mail.Send` application permission. No user passwords are shared with C1.ai, and you can revoke access at any time by removing the client secret or deleting the app. ## Before you begin @@ -28,7 +28,7 @@ You'll need: ## Step 1: Register an app in Entra ID -Create an Entra ID app registration that C1 will authenticate as to call the Microsoft Graph `sendMail` API. +Create an Entra ID app registration that C1.ai will authenticate as to call the Microsoft Graph `sendMail` API. @@ -40,7 +40,7 @@ Navigate to **Identity** > **Applications** > **App registrations** > **New regi Fill in: -- **Name**: C1 Email Sender (or similar). +- **Name**: C1.ai Email Sender (or similar). - **Supported account types**: Accounts in this organizational directory only (single tenant). - **Redirect URI**: leave blank. @@ -50,8 +50,8 @@ Click **Register**. On the app's **Overview** page, copy and save: -- **Application (client) ID** — you'll paste this into C1. -- **Directory (tenant) ID** — you'll paste this into C1. +- **Application (client) ID** — you'll paste this into C1.ai. +- **Directory (tenant) ID** — you'll paste this into C1.ai. @@ -78,30 +78,30 @@ Click **Grant admin consent for your tenant** and confirm. The **Status** column -**Application permission is required, not Delegated.** Delegated permissions require an interactive user sign-in, which doesn't fit a service-to-service email sender. Application permissions allow C1 to send mail without a user present, but also grant the app the ability to send as any mailbox in the tenant by default. Step 4 below restricts that scope. +**Application permission is required, not Delegated.** Delegated permissions require an interactive user sign-in, which doesn't fit a service-to-service email sender. Application permissions allow C1.ai to send mail without a user present, but also grant the app the ability to send as any mailbox in the tenant by default. Step 4 below restricts that scope. ## Step 3: Create a client secret -Create the credential C1 will use to authenticate as the app. +Create the credential C1.ai will use to authenticate as the app. On the app's page, navigate to **Certificates & secrets** > **Client secrets** > **New client secret**. -Enter a description (for example, C1 Email Sender) and choose an expiration. 24 months is the maximum; a shorter expiration is better practice. +Enter a description (for example, C1.ai Email Sender) and choose an expiration. 24 months is the maximum; a shorter expiration is better practice. Click **Add**. -Immediately copy the secret's **Value** — Azure will not show it again after you leave the page. You'll paste this into C1 in Step 5. +Immediately copy the secret's **Value** — Azure will not show it again after you leave the page. You'll paste this into C1.ai in Step 5. -Set a calendar reminder before this secret expires. Once it expires, C1 will fail to send email and there is no automatic renewal. Best practice: rotate the secret 30 days before expiry. +Set a calendar reminder before this secret expires. Once it expires, C1.ai will fail to send email and there is no automatic renewal. Best practice: rotate the secret 30 days before expiry. ## Step 4: Restrict the app to a specific mailbox (highly recommended) @@ -147,13 +147,13 @@ Test-ApplicationAccessPolicy -Identity "" -AppId " -## Step 5: Configure the email provider in C1 +## Step 5: Configure the email provider in C1.ai -Enter the app credentials and sender mailbox from the previous steps in C1 to activate the integration. +Enter the app credentials and sender mailbox from the previous steps in C1.ai to activate the integration. -In C1, navigate to **Settings** > **Email provider**. +In C1.ai, navigate to **Settings** > **Email provider**. Click **Edit**. @@ -179,7 +179,7 @@ Click **Save**. -When you save, C1 validates the credentials by acquiring an OAuth token from Azure AD. If the tenant ID, client ID, or secret is wrong, save fails with a clear error and your previous configuration is preserved. +When you save, C1.ai validates the credentials by acquiring an OAuth token from Azure AD. If the tenant ID, client ID, or secret is wrong, save fails with a clear error and your previous configuration is preserved. **Sender mailbox must be allowed by the access policy** @@ -189,7 +189,7 @@ If you applied an Application Access Policy in Step 4, the **Sender email addres ## Step 6: Verify -Send a test message to confirm C1 can send through your Microsoft 365 tenant and that your email authentication records are passing. +Send a test message to confirm C1.ai can send through your Microsoft 365 tenant and that your email authentication records are passing. @@ -207,5 +207,5 @@ If the message does not arrive, check the spam folder and Microsoft 365 message -**Sent items**: C1 sends mail with `saveToSentItems=false`, so emails sent via this provider do not appear in the sender mailbox's Sent folder. For an audit trail, use C1's email activity log (**Settings** > **Email provider** > **View activity**) or Microsoft 365 message trace. +**Sent items**: C1.ai sends mail with `saveToSentItems=false`, so emails sent via this provider do not appear in the sender mailbox's Sent folder. For an audit trail, use C1.ai's email activity log (**Settings** > **Email provider** > **View activity**) or Microsoft 365 message trace. diff --git a/product/admin/email-provider-sendgrid.mdx b/product/admin/email-provider-sendgrid.mdx index 65e21d55..9624ada6 100644 --- a/product/admin/email-provider-sendgrid.mdx +++ b/product/admin/email-provider-sendgrid.mdx @@ -1,17 +1,17 @@ --- -title: Send C1 notifications from SendGrid -og:title: Send C1 notifications from SendGrid - C1 docs -og:description: Configure C1 to send notification emails through your own Twilio SendGrid account so recipients see your company's domain as the sender. -description: Configure C1 to send notification emails through your own Twilio SendGrid account so recipients see your company's domain as the sender. +title: Send C1.ai notifications from SendGrid +og:title: Send C1.ai notifications from SendGrid - C1.ai docs +og:description: Configure C1.ai to send notification emails through your own Twilio SendGrid account so recipients see your company's domain as the sender. +description: Configure C1.ai to send notification emails through your own Twilio SendGrid account so recipients see your company's domain as the sender. sidebarTitle: SendGrid --- {/* Editor Refresh: 2026-04-27 */} -By default, C1 sends notifications from `no-reply@conductorone.com`. You can instead send through your own Twilio SendGrid account so recipients see your company's domain as the sender. +By default, C1.ai sends notifications from `no-reply@conductorone.com`. You can instead send through your own Twilio SendGrid account so recipients see your company's domain as the sender. -This task requires the **Super Admin** role in C1 and an **Admin**-level account in SendGrid. +This task requires the **Super Admin** role in C1.ai and an **Admin**-level account in SendGrid. -C1 authenticates to SendGrid via a scoped API key with the **Mail Send** permission. No SMTP credentials or user passwords are shared, and you can revoke access at any time by deleting the API key. +C1.ai authenticates to SendGrid via a scoped API key with the **Mail Send** permission. No SMTP credentials or user passwords are shared, and you can revoke access at any time by deleting the API key. ## Before you begin @@ -79,7 +79,7 @@ Once the domain is authenticated, you can send from any address on it without pe ## Step 2: Create a scoped API key -Create a restricted API key that grants C1 only the Mail Send permission. This limits exposure if the key is ever compromised. +Create a restricted API key that grants C1.ai only the Mail Send permission. This limits exposure if the key is ever compromised. @@ -88,7 +88,7 @@ In SendGrid, navigate to **Settings** > **API Keys** > **Create API Key**. Fill in: -- **API Key Name**: C1 Email Sender (or similar). +- **API Key Name**: C1.ai Email Sender (or similar). - **API Key Permissions**: select **Restricted Access**. @@ -98,7 +98,7 @@ In the permissions list, set every scope to **No Access** except **Mail Send**, Click **Create & View**. -Immediately copy the API key — SendGrid will not show it again after you leave the page. You'll paste it into C1 in Step 3. +Immediately copy the API key — SendGrid will not show it again after you leave the page. You'll paste it into C1.ai in Step 3. @@ -106,13 +106,13 @@ Immediately copy the API key — SendGrid will not show it again after you leave **Why Restricted Access?** A Full Access API key can also read mail activity, manage templates, edit senders, and modify billing. If the key leaks, Restricted Access limits the exposure to mail sending only, rather than full SendGrid tenant access. -## Step 3: Configure the email provider in C1 +## Step 3: Configure the email provider in C1.ai -Enter your verified sender and API key in C1 to activate the integration. +Enter your verified sender and API key in C1.ai to activate the integration. -In C1, navigate to **Settings** > **Email provider**. +In C1.ai, navigate to **Settings** > **Email provider**. Click **Edit**. @@ -136,7 +136,7 @@ Click **Save**. -When you save, C1 validates the API key by calling SendGrid's `GET /v3/scopes` endpoint. If the key is missing, wrong, or lacks the Mail Send permission, save fails with a clear error and your previous configuration is preserved. +When you save, C1.ai validates the API key by calling SendGrid's `GET /v3/scopes` endpoint. If the key is missing, wrong, or lacks the Mail Send permission, save fails with a clear error and your previous configuration is preserved. **Sender must match a SendGrid-verified identity** @@ -146,7 +146,7 @@ The **Sender email address** must be either a verified Single Sender (exact matc ## Step 4: Verify -Send a test message to confirm C1 can send through SendGrid and that your email authentication records are passing. +Send a test message to confirm C1.ai can send through SendGrid and that your email authentication records are passing. diff --git a/product/admin/email-provider.mdx b/product/admin/email-provider.mdx index fb536968..ea19f230 100644 --- a/product/admin/email-provider.mdx +++ b/product/admin/email-provider.mdx @@ -1,22 +1,22 @@ --- title: Custom email provider -og:title: Custom email provider - C1 docs -og:description: Send C1 notifications from your own domain by connecting a custom email provider, so recipients see your company's address as the sender. -description: Send C1 notifications from your own domain by connecting a custom email provider, so recipients see your company's address as the sender. +og:title: Custom email provider - C1.ai docs +og:description: Send C1.ai notifications from your own domain by connecting a custom email provider, so recipients see your company's address as the sender. +description: Send C1.ai notifications from your own domain by connecting a custom email provider, so recipients see your company's address as the sender. sidebarTitle: Send email from your domain --- {/* Editor Refresh: 2026-04-27 */} -By default, C1 sends notification emails from `no-reply@conductorone.com`. With a custom email provider, you can send those same notifications from an address on your own domain (for example, `governance@yourcompany.com`), so recipients see a familiar sender and your email authentication records govern deliverability. +By default, C1.ai sends notification emails from `no-reply@conductorone.com`. With a custom email provider, you can send those same notifications from an address on your own domain (for example, `governance@yourcompany.com`), so recipients see a familiar sender and your email authentication records govern deliverability. -Configuring a custom email provider requires the **Super Admin** role in C1, plus administrative access to the email service you choose. +Configuring a custom email provider requires the **Super Admin** role in C1.ai, plus administrative access to the email service you choose. ## Supported providers -| Provider | What C1 uses | +| Provider | What C1.ai uses | |---|---| | [Google Workspace](/product/admin/email-provider-google-workspace) | Gmail API with a GCP service account and domain-wide delegation | -| [AWS SES](/product/admin/email-provider-aws-ses) | IAM role assumption with an External ID — no access keys shared with C1 | +| [AWS SES](/product/admin/email-provider-aws-ses) | IAM role assumption with an External ID — no access keys shared with C1.ai | | [Microsoft 365](/product/admin/email-provider-microsoft-365) | Microsoft Graph `sendMail` API with an Entra ID app registration | | [SendGrid](/product/admin/email-provider-sendgrid) | SendGrid API with a scoped API key | @@ -26,9 +26,9 @@ Regardless of which provider you choose, emails sent from your domain will land ## What happens after you save -When you save a custom email provider configuration, C1 validates the credentials immediately. If validation fails, your previous configuration is preserved and C1 continues sending from `no-reply@conductorone.com` until the issue is resolved. +When you save a custom email provider configuration, C1.ai validates the credentials immediately. If validation fails, your previous configuration is preserved and C1.ai continues sending from `no-reply@conductorone.com` until the issue is resolved. -To switch back to the default sender at any time, navigate to **Settings** > **Email provider**, click **Edit**, and select **C1 Email Delivery Service**. +To switch back to the default sender at any time, navigate to **Settings** > **Email provider**, click **Edit**, and select **C1.ai Email Delivery Service**. ## Test your configuration diff --git a/product/admin/emergency.mdx b/product/admin/emergency.mdx index 21f08edb..6368f980 100644 --- a/product/admin/emergency.mdx +++ b/product/admin/emergency.mdx @@ -1,6 +1,6 @@ --- title: Enable emergency access requests -og:title: Enable emergency access requests - C1 docs +og:title: Enable emergency access requests - C1.ai docs og:description: Emergency access (also known as "break glass" access) is a system for granting expedited access approval in the event of an emergency or incident when access is urgently needed. description: Emergency access (also known as "break glass" access) is a system for granting expedited access approval in the event of an emergency or incident when access is urgently needed. sidebarTitle: Emergency access @@ -11,7 +11,7 @@ sidebarTitle: Emergency access In emergency situations, some employees might need immediate access to resources and systems that they don't normally have access to. In order to get these employees the access they need, companies create expedited access review procedures (sometimes called "break glass" procedures in reference to the "break glass in case of fire" signs on alarms and fire safety equipment). -C1's emergency access request process works like this: +C1.ai's emergency access request process works like this: @@ -21,21 +21,21 @@ Admins enable select entitlements to accept emergency access requests. Each entitlement that supports emergency access is assigned an emergency access policy. -When an emergency arises, a user requests access through C1 and selects **Emergency access** on the request in the web app or Slack. If you prefer to use the CLI, you can [request emergency access through Cone](/product/cli/commands#get). +When an emergency arises, a user requests access through C1.ai and selects **Emergency access** on the request in the web app or Slack. If you prefer to use the CLI, you can [request emergency access through Cone](/product/cli/commands#get). -C1 routes the request through the emergency access review process. +C1.ai routes the request through the emergency access review process. The user is granted emergency access. -## How are emergency access requests shown in the C1 app? +## How are emergency access requests shown in the C1.ai app? -When requesting access in C1, the **Emergency access** toggle is shown when a user has selected an entitlement with emergency access enabled. +When requesting access in C1.ai, the **Emergency access** toggle is shown when a user has selected an entitlement with emergency access enabled. -A completed request access form in C1 for 1 hour of access to an AWS admin role, showing the emergency access toggle present and enabled. +A completed request access form in C1.ai for 1 hour of access to an AWS admin role, showing the emergency access toggle present and enabled. Emergency access requests are shown with a thunderbolt icon in all task lists, including on the **Task log** and **Requests** pages. diff --git a/product/admin/enable-ai-access-management.mdx b/product/admin/enable-ai-access-management.mdx index ca20301e..59a94184 100644 --- a/product/admin/enable-ai-access-management.mdx +++ b/product/admin/enable-ai-access-management.mdx @@ -1,14 +1,14 @@ --- title: Enable AI access management description: Turn on AIAM for your tenant and configure tenant-wide defaults for MCP servers, tools, and AI clients. -og:title: Enable AI access management - C1 docs +og:title: Enable AI access management - C1.ai docs og:description: Turn on AIAM for your tenant and configure tenant-wide defaults for MCP servers, tools, and AI clients. --- {/* Editor Refresh: 2026-09-02 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. AIAM lets you govern which AI clients can call which tools on your behalf, and which end users are allowed to use them. Enabling AIAM for your tenant is a one-time task that requires the **Super Administrator** role. Configuring tenant defaults, registering MCP servers, governing tools, managing AI clients, and using kill switches can be performed by either a Super Administrator or a user with the [AI Governance Administrator](/product/admin/user-roles#ai-governance-administrator) role. @@ -21,16 +21,16 @@ Enabling AIAM exposes the AIAM surfaces (MCP servers, tools, AI clients, AIAM au -Log in to your C1 tenant as a Super Admin. +Log in to your C1.ai tenant as a Super Admin. -Navigate to **AI > C1 Gateway** and click **Settings**. +Navigate to **AI > C1.ai Gateway** and click **Settings**. Find **C1 Gateway** and click **Edit**. -Toggle **Enable the C1 Gateway** to on. +Toggle **Enable the C1.ai Gateway** to on. Click **Save** to confirm. @@ -60,7 +60,7 @@ To change which types are allowed: -In **AI > C1 Gateway > Settings**, find **Allowed client types**. +In **AI > C1.ai Gateway > Settings**, find **Allowed client types**. Check the boxes for the types you want to permit. @@ -76,7 +76,7 @@ Any in-flight client of a now-disallowed type continues to function until its ex ### Default tool classification -When C1 discovers a new tool on a registered MCP server, it assigns the tool this initial state. Until an admin reviews and approves the tool, it cannot be added to a toolset and end users cannot request it. +When C1.ai discovers a new tool on a registered MCP server, it assigns the tool this initial state. Until an admin reviews and approves the tool, it cannot be added to a toolset and end users cannot request it. - **State**: Pending Review / Unset (recommended — keeps every newly-discovered tool out of end-user reach until you've reviewed it) - **Classification**: Sensitive (default) @@ -108,7 +108,7 @@ Turning this off does not bypass access profile approval — end users still go ### Client lifecycle policy -C1 tracks how long it's been since each registered AI client made a tool call, and how long it's been since a client's credentials were closed. Three thresholds control what happens to an inactive client: +C1.ai tracks how long it's been since each registered AI client made a tool call, and how long it's been since a client's credentials were closed. Three thresholds control what happens to an inactive client: | Field label | Helper text | Default | | :--- | :--- | :--- | @@ -122,7 +122,7 @@ To change the thresholds: -In **AI > C1 Gateway > Settings**, find **Client governance**. +In **AI > C1.ai Gateway > Settings**, find **Client governance**. Set each threshold. @@ -168,5 +168,5 @@ Click **Save**. -Combined with the per-tool kill switch ([Govern tools and toolsets](/product/admin/tools-and-toolsets)) and the per-client kill switch ([Manage AI clients](/product/admin/ai-clients)), C1 offers kill switches at four scopes: tenant, server, tool, and client. +Combined with the per-tool kill switch ([Govern tools and toolsets](/product/admin/tools-and-toolsets)) and the per-client kill switch ([Manage AI clients](/product/admin/ai-clients)), C1.ai offers kill switches at four scopes: tenant, server, tool, and client. diff --git a/product/admin/enterprise-managed-authorization/audit.mdx b/product/admin/enterprise-managed-authorization/audit.mdx index a402a816..285cb625 100644 --- a/product/admin/enterprise-managed-authorization/audit.mdx +++ b/product/admin/enterprise-managed-authorization/audit.mdx @@ -1,36 +1,36 @@ --- title: Audit MCP access -description: What C1 records for every token request, how to read a denial, and how to debug a signature rejection at the MCP server. -og:title: Audit MCP access - C1 docs -og:description: What C1 records for every token request, how to read a denial, and how to debug a signature rejection at the MCP server. +description: What C1.ai records for every token request, how to read a denial, and how to debug a signature rejection at the MCP server. +og:title: Audit MCP access - C1.ai docs +og:description: What C1.ai records for every token request, how to read a denial, and how to debug a signature rejection at the MCP server. sidebarTitle: Audit MCP access --- {/* Editor Refresh: 2026-06-13 */} -C1 records every enterprise-managed authorization token request, granted or denied. This page covers what each record holds, how to read a denial, and how to debug a token an MCP server rejects. +C1.ai records every enterprise-managed authorization token request, granted or denied. This page covers what each record holds, how to read a denial, and how to debug a token an MCP server rejects. ## Audit MCP access in your SIEM -The recommended way to audit MCP access is to stream C1's events into your SIEM. C1 emits every enterprise-managed authorization and MCP access event to the system log, and the **System log exporter** forwards them to the SIEM or log store you already use for the rest of your security data. +The recommended way to audit MCP access is to stream C1.ai's events into your SIEM. C1.ai emits every enterprise-managed authorization and MCP access event to the system log, and the **System log exporter** forwards them to the SIEM or log store you already use for the rest of your security data. -To set it up, go to **Settings > Security > System log > Add exporter** and point the exporter at your destination. From then on, every token request C1 records — the fields and status details described below — lands in your SIEM, where you can search, alert, and retain it alongside everything else. See [System logs](/product/admin/system-log). +To set it up, go to **Settings > Security > System log > Add exporter** and point the exporter at your destination. From then on, every token request C1.ai records — the fields and status details described below — lands in your SIEM, where you can search, alert, and retain it alongside everything else. See [System logs](/product/admin/system-log). -C1 recommends this approach for every customer auditing MCP access, not just enterprise tenants. You can also use **Read and download system logs** to read the same events directly in C1. +C1.ai recommends this approach for every customer auditing MCP access, not just enterprise tenants. You can also use **Read and download system logs** to read the same events directly in C1.ai. ## What's recorded -C1 writes one audit event for every token request, whether it's granted or denied. Each event records who asked, what they asked for, and what C1 decided. +C1.ai writes one audit event for every token request, whether it's granted or denied. Each event records who asked, what they asked for, and what C1.ai decided. | Field | What it records | | :--- | :--- | -| **User** | The C1 identity the token was requested for | +| **User** | The C1.ai identity the token was requested for | | **Client** | The agent's client that made the request | | **System** | The MCP server the token is for (the token's audience) | | **Scopes** | The scopes requested and the per-scope outcome (granted or denied) | | **Token ID** | The identifier of the issued token | -| **Signing key** | The key C1 signed the token with | -| **Algorithm** | The signing algorithm C1 used (ES256 by default) | +| **Signing key** | The key C1.ai signed the token with | +| **Algorithm** | The signing algorithm C1.ai used (ES256 by default) | | **Lifetime** | How long the token is valid | | **Status detail** | On a denial, the reason the request was denied | @@ -48,10 +48,10 @@ When a request is denied, the status detail names the cause. Use this table to m ## Debug a signature rejection -A token that C1 issued successfully can still be rejected by the MCP server. When that happens, the audit record for the issuance points to the cause. Check the **signing key ID** and **algorithm** columns first: C1 signs with ES256 by default, and if the server's authorization server expects a different algorithm, it rejects an otherwise valid token. The fix is to set the server's signing algorithm to one its authorization server verifies. +A token that C1.ai issued successfully can still be rejected by the MCP server. When that happens, the audit record for the issuance points to the cause. Check the **signing key ID** and **algorithm** columns first: C1.ai signs with ES256 by default, and if the server's authorization server expects a different algorithm, it rejects an otherwise valid token. The fix is to set the server's signing algorithm to one its authorization server verifies. -## What C1 sees, and what it doesn't +## What C1.ai sees, and what it doesn't -C1 records the issuance decision: every token request, granted or denied. It does not see the agent's later API calls, because those run directly against the MCP server and never pass through C1. +C1.ai records the issuance decision: every token request, granted or denied. It does not see the agent's later API calls, because those run directly against the MCP server and never pass through C1.ai. To retain these events long-term and search them alongside the rest of your security data, stream them to your SIEM with the [System log exporter](#audit-mcp-access-in-your-siem). diff --git a/product/admin/enterprise-managed-authorization/enable.mdx b/product/admin/enterprise-managed-authorization/enable.mdx index 40a41638..9395f348 100644 --- a/product/admin/enterprise-managed-authorization/enable.mdx +++ b/product/admin/enterprise-managed-authorization/enable.mdx @@ -1,8 +1,8 @@ --- title: Enable enterprise-managed authorization -description: Turn enterprise-managed authorization on for your tenant and choose the signing algorithm C1 uses. -og:title: Enable enterprise-managed authorization - C1 docs -og:description: Turn enterprise-managed authorization on for your tenant and choose the signing algorithm C1 uses. +description: Turn enterprise-managed authorization on for your tenant and choose the signing algorithm C1.ai uses. +og:title: Enable enterprise-managed authorization - C1.ai docs +og:description: Turn enterprise-managed authorization on for your tenant and choose the signing algorithm C1.ai uses. sidebarTitle: Enable EMA --- @@ -12,7 +12,7 @@ Enabling enterprise-managed authorization exposes the admin surfaces for registe ## Before you begin -- Enterprise-managed authorization is in early access. [Contact the C1 Support team](mailto:support@c1.ai) to have it enabled for your tenant. The toggle below is live only once C1 has enabled the operator rollout for your tenant. +- Enterprise-managed authorization is in early access. [Contact the C1.ai Support team](mailto:support@c1.ai) to have it enabled for your tenant. The toggle below is live only once C1.ai has enabled the operator rollout for your tenant. - You need an admin role to change tenant settings. ## Enable enterprise-managed authorization for your tenant @@ -27,23 +27,23 @@ Click **Edit** in the top right of the **Cross-App Access** section. Turn on the **Enable cross-app access** toggle. -As the page notes, the issuer is live only when this is on *and* C1 has enabled the operator rollout for your tenant. +As the page notes, the issuer is live only when this is on *and* C1.ai has enabled the operator rollout for your tenant. Set the **Default signing algorithm**. -This is the algorithm C1 uses to sign tokens for any MCP server that doesn't override it at the resource server level. The options are **ES256 (default)**, **EdDSA**, and **RS256**. The MCP server you issue tokens for verifies C1's signature at its own authorization server, so choose an algorithm that server can verify. ES256 is the default and the safest choice for broad compatibility; RS256 is also widely supported. EdDSA is available, but verification support is uneven across servers, so confirm the target server supports it before relying on it. +This is the algorithm C1.ai uses to sign tokens for any MCP server that doesn't override it at the resource server level. The options are **ES256 (default)**, **EdDSA**, and **RS256**. The MCP server you issue tokens for verifies C1.ai's signature at its own authorization server, so choose an algorithm that server can verify. ES256 is the default and the safest choice for broad compatibility; RS256 is also widely supported. EdDSA is available, but verification support is uneven across servers, so confirm the target server supports it before relying on it. {/* -Choose which algorithms C1 maintains keys for. +Choose which algorithms C1.ai maintains keys for. -The **Maintained signing algorithms** controls show the set of algorithms C1 keeps signing keys for. **EdDSA** is always maintained (shown checked and locked); **RS256** and **ES256** are checkboxes you can turn on. Make sure the algorithm you chose as your default is maintained — if no signing key exists for the chosen algorithm, every token request is denied. +The **Maintained signing algorithms** controls show the set of algorithms C1.ai keeps signing keys for. **EdDSA** is always maintained (shown checked and locked); **RS256** and **ES256** are checkboxes you can turn on. Make sure the algorithm you chose as your default is maintained — if no signing key exists for the chosen algorithm, every token request is denied. Set the **Default grant lifetime**. -This is a duration picker. Leave it on **Indefinite** to inherit C1's built-in default, or choose a preset (**1 hour**, 12 hours, 1 day, 1 week, 2 weeks, 1 month) or a **Custom** value. Custom durations are expressed in hours, days, weeks, or months. Here **Indefinite** means "inherit C1's built-in default," which is **300 seconds (5 minutes)** — it does *not* mean tokens never expire. This default applies to any resource server that doesn't set its own **Maximum grant lifetime**. A token keeps working until it expires, so a shorter lifetime tightens the window in which a revoked grant still has effect. +This is a duration picker. Leave it on **Indefinite** to inherit C1.ai's built-in default, or choose a preset (**1 hour**, 12 hours, 1 day, 1 week, 2 weeks, 1 month) or a **Custom** value. Custom durations are expressed in hours, days, weeks, or months. Here **Indefinite** means "inherit C1.ai's built-in default," which is **300 seconds (5 minutes)** — it does *not* mean tokens never expire. This default applies to any resource server that doesn't set its own **Maximum grant lifetime**. A token keeps working until it expires, so a shorter lifetime tightens the window in which a revoked grant still has effect. */} diff --git a/product/admin/enterprise-managed-authorization/overview.mdx b/product/admin/enterprise-managed-authorization/overview.mdx index 91673f0d..29f9ae94 100644 --- a/product/admin/enterprise-managed-authorization/overview.mdx +++ b/product/admin/enterprise-managed-authorization/overview.mdx @@ -1,56 +1,56 @@ --- title: Enterprise-managed authorization for MCP description: Govern how AI agents reach your MCP servers — people authenticate once, and their agents get scoped, short-lived access to the servers they're entitled to. -og:title: Enterprise-managed authorization for MCP - C1 docs +og:title: Enterprise-managed authorization for MCP - C1.ai docs og:description: Govern how AI agents reach your MCP servers — people authenticate once, and their agents get scoped, short-lived access to the servers they're entitled to. sidebarTitle: How EMA works --- {/* Editor Refresh: 2026-06-13 */} -Enterprise-managed authorization (EMA) governs how AI agents — Claude, VS Code, and others — reach the MCP servers your organization runs. Your people authenticate once to C1, and from then on their agents get short-lived, scoped access to the MCP servers they're entitled to. It's single sign-on for agents: the same identity governance you already apply to people, applied to the agents acting on their behalf. +Enterprise-managed authorization (EMA) governs how AI agents — Claude, VS Code, and others — reach the MCP servers your organization runs. Your people authenticate once to C1.ai, and from then on their agents get short-lived, scoped access to the MCP servers they're entitled to. It's single sign-on for agents: the same identity governance you already apply to people, applied to the agents acting on their behalf. -Instead of handing an agent a long-lived API key, C1 exchanges the signed-in user's identity for a short-lived, scoped token addressed to one specific MCP server. C1 checks your access policy before it issues the token and records the decision. +Instead of handing an agent a long-lived API key, C1.ai exchanges the signed-in user's identity for a short-lived, scoped token addressed to one specific MCP server. C1.ai checks your access policy before it issues the token and records the decision. ## What your users see -The capability shows up in each AI client under the client's own name. When a user turns it on there, what they're enabling is the same thing you configure in C1: +The capability shows up in each AI client under the client's own name. When a user turns it on there, what they're enabling is the same thing you configure in C1.ai: - **In Claude** — "enterprise-managed auth," surfaced through connectors. - **In VS Code** — "enterprise-managed MCP authentication." -## The two paths C1 governs +## The two paths C1.ai governs -An AI agent can reach one of your MCP servers in two ways, and C1 governs both under one set of entitlements, one policy engine, and one audit trail. +An AI agent can reach one of your MCP servers in two ways, and C1.ai governs both under one set of entitlements, one policy engine, and one audit trail. | | Enterprise-managed authorization (this page) | AI access management gateway | | :--- | :--- | :--- | | **When to use it** | The MCP server supports enterprise-managed authorization (the Cross-App Access standard) | The MCP server does not support the standard | -| **How the agent connects** | C1 issues a scoped token; the agent calls the server directly | The agent routes its calls through C1's MCP gateway | -| **Is C1 in the data path?** | No. C1 issues the token and is not in the call path | Yes. C1 proxies each call and enforces policy on it | +| **How the agent connects** | C1.ai issues a scoped token; the agent calls the server directly | The agent routes its calls through C1.ai's MCP gateway | +| **Is C1.ai in the data path?** | No. C1.ai issues the token and is not in the call path | Yes. C1.ai proxies each call and enforces policy on it | | **Where enforcement happens** | At token issuance; the server enforces the scope after that | On every tool call, in real time | -Use enterprise-managed authorization for MCP servers that can verify C1-issued tokens. For everything else, use the [AI access management gateway](/product/admin/aiam-overview), which proxies and enforces each call. Many tenants run both. +Use enterprise-managed authorization for MCP servers that can verify C1.ai-issued tokens. For everything else, use the [AI access management gateway](/product/admin/aiam-overview), which proxies and enforces each call. Many tenants run both. ## Why enterprise-managed authorization An AI agent that holds a static API key has broad, standing access with no named owner and no clean way to turn it off. Enterprise-managed authorization applies the same identity governance you already use for people to every agent: - **Short-lived and scoped.** Tokens expire in minutes and carry only the scopes the user was granted, instead of a standing key with broad access. -- **Owned and revocable.** Each agent's access is requested, approved, reviewed, and revoked through the standard C1 workflow. Revoke the grant and the next token request is denied. -- **Standards-based.** It builds on established OAuth standards (token exchange and JWT bearer grants), so any MCP server that implements the standard can verify C1's tokens. -- **Not in the data path.** Because the agent calls the server directly, C1 isn't in the runtime path between the agent and the server. C1 remains the policy and audit point. +- **Owned and revocable.** Each agent's access is requested, approved, reviewed, and revoked through the standard C1.ai workflow. Revoke the grant and the next token request is denied. +- **Standards-based.** It builds on established OAuth standards (token exchange and JWT bearer grants), so any MCP server that implements the standard can verify C1.ai's tokens. +- **Not in the data path.** Because the agent calls the server directly, C1.ai isn't in the runtime path between the agent and the server. C1.ai remains the policy and audit point. -**Under the hood.** Enterprise-managed authorization is built on the open Cross-App Access (XAA) standard — an OAuth-based protocol no single vendor owns; any provider can implement it, and C1 does. The token C1 issues is an [ID-JAG](#key-concepts): a short-lived JWT whose audience is the MCP server's authorization server. You don't need any of this to set EMA up — it's here for the protocol-curious. +**Under the hood.** Enterprise-managed authorization is built on the open Cross-App Access (XAA) standard — an OAuth-based protocol no single vendor owns; any provider can implement it, and C1.ai does. The token C1.ai issues is an [ID-JAG](#key-concepts): a short-lived JWT whose audience is the MCP server's authorization server. You don't need any of this to set EMA up — it's here for the protocol-curious. ## How it works -A user signs in to C1 once. From then on, their agent obtains tokens on their behalf: +A user signs in to C1.ai once. From then on, their agent obtains tokens on their behalf: -1. **Sign in.** The agent signs the user in to C1 and receives an ID token. -2. **Exchange.** The agent sends that ID token to C1 and asks for access to a specific MCP server. C1 checks the user's entitlements and, if they hold the requested scopes, returns a short-lived token scoped to that server. +1. **Sign in.** The agent signs the user in to C1.ai and receives an ID token. +2. **Exchange.** The agent sends that ID token to C1.ai and asks for access to a specific MCP server. C1.ai checks the user's entitlements and, if they hold the requested scopes, returns a short-lived token scoped to that server. 3. **Call.** The agent presents the token to the server's authorization server, receives an access token, and calls the server's API. ```mermaid @@ -70,12 +70,12 @@ sequenceDiagram ## What it governs, and what it doesn't -C1 evaluates your policy when it **issues** the token. After that, the MCP server holds the token until it expires and enforces the scope on each call. C1 is not in the call path, so it does not enforce or see individual API calls the way the AI access management gateway does. +C1.ai evaluates your policy when it **issues** the token. After that, the MCP server holds the token until it expires and enforces the scope on each call. C1.ai is not in the call path, so it does not enforce or see individual API calls the way the AI access management gateway does. This shapes two things to understand up front: -- **Revocation takes effect at the next token request.** When you revoke a grant, C1 denies the next exchange. A token already issued keeps working until it expires, which is a few minutes by default. For an immediate stop on an in-flight token, you depend on the MCP server's own controls. -- **Governance, not per-call enforcement.** Modeling each scope as its own entitlement lets you request, review, certify, and audit access at the scope level. It does not put C1 between the agent and the server on every call. +- **Revocation takes effect at the next token request.** When you revoke a grant, C1.ai denies the next exchange. A token already issued keeps working until it expires, which is a few minutes by default. For an immediate stop on an in-flight token, you depend on the MCP server's own controls. +- **Governance, not per-call enforcement.** Modeling each scope as its own entitlement lets you request, review, certify, and audit access at the scope level. It does not put C1.ai between the agent and the server on every call. ## Onboard your first MCP server @@ -84,9 +84,9 @@ The full path, end to end: 1. [Enable enterprise-managed authorization](/product/admin/enterprise-managed-authorization/enable) for your tenant and choose a signing algorithm. 2. [Register the MCP server](/product/admin/enterprise-managed-authorization/resource-servers). 3. [Discover or declare the server's scopes, enable the ones you want to expose, and bundle them into access profiles](/product/admin/enterprise-managed-authorization/scopes-and-profiles) so users can request them. -4. Users [request access](/product/admin/access-requests) through the standard C1 catalog, and approvers grant it. +4. Users [request access](/product/admin/access-requests) through the standard C1.ai catalog, and approvers grant it. -Before you start, the MCP server's authorization server must be configured to trust C1 as an issuer. That work is done by the server's owner — see [Support enterprise-managed authorization in your MCP server](/product/admin/enterprise-managed-authorization/support-in-your-app). +Before you start, the MCP server's authorization server must be configured to trust C1.ai as an issuer. That work is done by the server's owner — see [Support enterprise-managed authorization in your MCP server](/product/admin/enterprise-managed-authorization/support-in-your-app). These examples use `conductor.one`. If your organization is on the EU data residency instance, substitute `c1eu.ai` in URLs, client IDs, and hostnames. @@ -94,12 +94,12 @@ Before you start, the MCP server's authorization server must be configured to tr | Concept | Description | | :--- | :--- | -| **MCP server (resource server)** | A server C1 issues tokens for. In the protocol it's the "resource server." You register one per server, keyed to that server's authorization server. | -| **Scope** | A single permission an MCP server exposes (for example, `repo.read`). In C1, each scope is its own entitlement, so it can be requested, reviewed, and audited individually. | +| **MCP server (resource server)** | A server C1.ai issues tokens for. In the protocol it's the "resource server." You register one per server, keyed to that server's authorization server. | +| **Scope** | A single permission an MCP server exposes (for example, `repo.read`). In C1.ai, each scope is its own entitlement, so it can be requested, reviewed, and audited individually. | | **Access profile** | A named bundle of scopes you curate so users request one item instead of many. | | **Cross-App Access (XAA)** | The open, OAuth-based protocol enterprise-managed authorization is built on. No single vendor owns it; any provider can implement it. | -| **ID-JAG** | The short-lived token C1 issues. Its audience is the MCP server's authorization server, which verifies C1's signature and exchanges it for an access token. | -| **Issuer and JWKS** | C1's tenant URL is the token issuer (for example, `https://your-tenant.conductor.one`). The server's authorization server verifies C1's signatures against the public keys C1 publishes at the tenant's JWKS endpoint, `https://your-tenant.conductor.one/auth/v1/jwks`. | +| **ID-JAG** | The short-lived token C1.ai issues. Its audience is the MCP server's authorization server, which verifies C1.ai's signature and exchanges it for an access token. | +| **Issuer and JWKS** | C1.ai's tenant URL is the token issuer (for example, `https://your-tenant.conductor.one`). The server's authorization server verifies C1.ai's signatures against the public keys C1.ai publishes at the tenant's JWKS endpoint, `https://your-tenant.conductor.one/auth/v1/jwks`. | ## Where to go from here @@ -107,6 +107,6 @@ Before you start, the MCP server's authorization server must be configured to tr - Ready to connect an MCP server? See [Register an MCP server](/product/admin/enterprise-managed-authorization/resource-servers). - Governing who gets which scopes? See [Govern access: scopes & access profiles](/product/admin/enterprise-managed-authorization/scopes-and-profiles). - Setting up audit and compliance? See [Audit MCP access](/product/admin/enterprise-managed-authorization/audit). -- Are you an end user setting this up in your client? See [Connect your MCP client to C1](/product/how-to/connect-mcp-client). -- Do you own an MCP server that should accept C1 tokens? See [Support enterprise-managed authorization in your MCP server](/product/admin/enterprise-managed-authorization/support-in-your-app). +- Are you an end user setting this up in your client? See [Connect your MCP client to C1.ai](/product/how-to/connect-mcp-client). +- Do you own an MCP server that should accept C1.ai tokens? See [Support enterprise-managed authorization in your MCP server](/product/admin/enterprise-managed-authorization/support-in-your-app). diff --git a/product/admin/enterprise-managed-authorization/resource-servers.mdx b/product/admin/enterprise-managed-authorization/resource-servers.mdx index 7782e640..e3b56da0 100644 --- a/product/admin/enterprise-managed-authorization/resource-servers.mdx +++ b/product/admin/enterprise-managed-authorization/resource-servers.mdx @@ -1,29 +1,29 @@ --- title: Register an MCP server -description: Register an MCP server (the protocol's "resource server") so C1 can issue scoped, short-lived tokens for it. -og:title: Register an MCP server - C1 docs -og:description: Register an MCP server (the protocol's "resource server") so C1 can issue scoped, short-lived tokens for it. +description: Register an MCP server (the protocol's "resource server") so C1.ai can issue scoped, short-lived tokens for it. +og:title: Register an MCP server - C1.ai docs +og:description: Register an MCP server (the protocol's "resource server") so C1.ai can issue scoped, short-lived tokens for it. sidebarTitle: Register an MCP server --- {/* Editor Refresh: 2026-06-13 */} -Register an MCP server to tell C1 which server to issue tokens for and how those tokens are addressed. +Register an MCP server to tell C1.ai which server to issue tokens for and how those tokens are addressed. This is step 2 of the enterprise-managed authorization setup. If you haven't enabled enterprise-managed authorization for your tenant yet, start with [Enable enterprise-managed authorization](/product/admin/enterprise-managed-authorization/enable). ## What's a resource server? -In the protocol, the MCP server you register is the **resource server** — the system C1 issues tokens for. You register one per server, keyed to that server's authorization server. The token C1 mints is addressed to that authorization server, which verifies C1's signature and exchanges the token for an access token the agent uses to call the server. +In the protocol, the MCP server you register is the **resource server** — the system C1.ai issues tokens for. You register one per server, keyed to that server's authorization server. The token C1.ai mints is addressed to that authorization server, which verifies C1.ai's signature and exchanges the token for an access token the agent uses to call the server. ## Before you begin -- The [application for this server](/product/admin/applications) already exists in C1. -- The MCP server's authorization server already trusts C1 as an issuer. The server's owner does this, not you, and not in C1. See [Support enterprise-managed authorization in your MCP server](/product/admin/enterprise-managed-authorization/support-in-your-app). +- The [application for this server](/product/admin/applications) already exists in C1.ai. +- The MCP server's authorization server already trusts C1.ai as an issuer. The server's owner does this, not you, and not in C1.ai. See [Support enterprise-managed authorization in your MCP server](/product/admin/enterprise-managed-authorization/support-in-your-app). ## Register an MCP server -The MCP server is registered on the C1 application that represents it. The **Cross-App Access** tab only appears once enterprise-managed authorization is enabled for your tenant. +The MCP server is registered on the C1.ai application that represents it. The **Cross-App Access** tab only appears once enterprise-managed authorization is enabled for your tenant. @@ -40,7 +40,7 @@ Enter a **Display name** (required), and optionally a **Description**. Set the **Audience** (required). -The audience is the issuer URL of the MCP server's authorization server. It is fixed once the resource server is created, so set it correctly the first time. The audience must not be your own C1 tenant URL. C1 is the token issuer, not the audience. +The audience is the issuer URL of the MCP server's authorization server. It is fixed once the resource server is created, so set it correctly the first time. The audience must not be your own C1.ai tenant URL. C1.ai is the token issuer, not the audience. Add the **Resource URIs**. @@ -63,10 +63,10 @@ The drawer also exposes two advanced switches: **Require proof of possession**, ## Modify-claims hook (not yet available) -The resource server drawer shows a **Modify-claims hook** field, intended for attaching a [Function](/product/admin/functions) that would run when C1 mints a token for this server. This capability is **not yet functional** — the field is reserved for a future release. +The resource server drawer shows a **Modify-claims hook** field, intended for attaching a [Function](/product/admin/functions) that would run when C1.ai mints a token for this server. This capability is **not yet functional** — the field is reserved for a future release. -**Don't configure a modify-claims hook.** It is not implemented yet, and setting one causes C1 to deny every token request for this server. Leave the field unset. +**Don't configure a modify-claims hook.** It is not implemented yet, and setting one causes C1.ai to deny every token request for this server. Leave the field unset. ## Pause an MCP server @@ -79,22 +79,22 @@ Disabling a server does not stop a token that has already been minted. An issued ## Troubleshoot resource server errors -If a token request is denied, or a server rejects a token C1 issued, find your issue below. +If a token request is denied, or a server rejects a token C1.ai issued, find your issue below. The token's audience does not match a registered resource server. Confirm the resource server's audience is the issuer URL of the MCP server's authorization server, and that it matches what the agent's client is asking for. The audience is fixed after creation, so a mismatch means re-registering the server with the correct audience. -The token request names a target that isn't in the resource server's configured resource URLs, so C1 denies it. Add the URL the agent is calling to the resource URLs for this server. +The token request names a target that isn't in the resource server's configured resource URLs, so C1.ai denies it. Add the URL the agent is calling to the resource URLs for this server. -C1 minted the token, but the server's authorization server rejected its signature. The server verifies a different algorithm than the one this resource server is signing with. Set this server's signing algorithm to one its authorization server verifies. ES256 is the broadest choice. +C1.ai minted the token, but the server's authorization server rejected its signature. The server verifies a different algorithm than the one this resource server is signing with. Set this server's signing algorithm to one its authorization server verifies. ES256 is the broadest choice. ## Where to go from here - Enable and govern this server's scopes. See [Govern access: scopes & access profiles](/product/admin/enterprise-managed-authorization/scopes-and-profiles). -- Set up the server to accept C1 tokens. See [Support enterprise-managed authorization in your MCP server](/product/admin/enterprise-managed-authorization/support-in-your-app). +- Set up the server to accept C1.ai tokens. See [Support enterprise-managed authorization in your MCP server](/product/admin/enterprise-managed-authorization/support-in-your-app). - Want the full picture? See the [enterprise-managed authorization overview](/product/admin/enterprise-managed-authorization/overview). diff --git a/product/admin/enterprise-managed-authorization/scopes-and-profiles.mdx b/product/admin/enterprise-managed-authorization/scopes-and-profiles.mdx index 824cefae..5631ba8c 100644 --- a/product/admin/enterprise-managed-authorization/scopes-and-profiles.mdx +++ b/product/admin/enterprise-managed-authorization/scopes-and-profiles.mdx @@ -1,28 +1,28 @@ --- title: "Govern access: scopes & access profiles" -description: Turn an MCP server's scopes into governable, requestable C1 entitlements, bundle them into access profiles, and control how access is granted and revoked. -og:title: "Govern access: scopes & access profiles - C1 docs" -og:description: Turn an MCP server's scopes into governable, requestable C1 entitlements, bundle them into access profiles, and control how access is granted and revoked. +description: Turn an MCP server's scopes into governable, requestable C1.ai entitlements, bundle them into access profiles, and control how access is granted and revoked. +og:title: "Govern access: scopes & access profiles - C1.ai docs" +og:description: Turn an MCP server's scopes into governable, requestable C1.ai entitlements, bundle them into access profiles, and control how access is granted and revoked. sidebarTitle: Govern access --- {/* Editor Refresh: 2026-06-13 */} -Scopes are how you control what an agent's token can do at an MCP server. This page covers turning a server's scopes into C1 entitlements, bundling them into access profiles, and the levers you use to grant and revoke access. +Scopes are how you control what an agent's token can do at an MCP server. This page covers turning a server's scopes into C1.ai entitlements, bundling them into access profiles, and the levers you use to grant and revoke access. ## Scopes are individual entitlements -Each scope an MCP server exposes becomes its own C1 entitlement. Because a scope is an entitlement, you can request, review, certify, and audit it on its own, the same way you govern any other access in C1. A server can expose many scopes. +Each scope an MCP server exposes becomes its own C1.ai entitlement. Because a scope is an entitlement, you can request, review, certify, and audit it on its own, the same way you govern any other access in C1.ai. A server can expose many scopes. -Modeling each scope as its own entitlement gives you per-scope governance. It does not put C1 between the agent and the system on each call. C1 evaluates your policy when it issues a token, not on every API call the agent makes afterward. +Modeling each scope as its own entitlement gives you per-scope governance. It does not put C1.ai between the agent and the system on each call. C1.ai evaluates your policy when it issues a token, not on every API call the agent makes afterward. ## Add and enable scopes -You bring an MCP server's scopes into C1, classify each one, and enable the scopes you want to expose. This happens on the resource server's **Scopes** tab (open the resource server from the application's **Cross-App Access** tab). The tab lists each scope with its **State**, **Classification**, and **Source**, offers a **Pending review** quick filter, and has a **Declare scope** button for adding one by hand. +You bring an MCP server's scopes into C1.ai, classify each one, and enable the scopes you want to expose. This happens on the resource server's **Scopes** tab (open the resource server from the application's **Cross-App Access** tab). The tab lists each scope with its **State**, **Classification**, and **Source**, offers a **Pending review** quick filter, and has a **Declare scope** button for adding one by hand. -Get the scopes into C1. +Get the scopes into C1.ai. Scopes are **discovered** automatically in the background — imported from the server and listed with source **Discovered** in a **Pending review** state so you can confirm them before use. To add one by hand, click **Declare scope** and fill in the drawer: **Scope value** (the literal OAuth scope string, required and immutable after creation), **Display name** (required), **Description**, **Classification**, and **State**. Click **Declare**. @@ -38,7 +38,7 @@ On the Scopes tab, use the row's **State** toggle, or the **⋯** menu's **Appro -Only enabled scopes can be issued in a token. Scopes are never enabled automatically. Enabling a scope is the ceiling on what C1 will ever put in a token for that server. +Only enabled scopes can be issued in a token. Scopes are never enabled automatically. Enabling a scope is the ceiling on what C1.ai will ever put in a token for that server. ## Bundle scopes into access profiles @@ -75,7 +75,7 @@ No lever cancels a token that's already been issued before it expires. A revoked ## Where to go from here -Once a profile exists and your access request settings are configured, users can request it from the standard C1 catalog — there's no further setup step here. +Once a profile exists and your access request settings are configured, users can request it from the standard C1.ai catalog — there's no further setup step here. - Configure how access is requested and approved: [Access requests](/product/admin/access-requests) - Certify access over time: [Campaigns](/product/admin/campaigns) diff --git a/product/admin/enterprise-managed-authorization/support-in-your-app.mdx b/product/admin/enterprise-managed-authorization/support-in-your-app.mdx index 55e24a8a..e4b53e07 100644 --- a/product/admin/enterprise-managed-authorization/support-in-your-app.mdx +++ b/product/admin/enterprise-managed-authorization/support-in-your-app.mdx @@ -1,35 +1,35 @@ --- title: Support enterprise-managed authorization in your MCP server -description: Make your MCP server accept C1-issued tokens by trusting C1 as an issuer and exchanging its ID-JAGs for your own access tokens. -og:title: Support enterprise-managed authorization in your MCP server - C1 docs -og:description: Make your MCP server accept C1-issued tokens by trusting C1 as an issuer and exchanging its ID-JAGs for your own access tokens. +description: Make your MCP server accept C1.ai-issued tokens by trusting C1.ai as an issuer and exchanging its ID-JAGs for your own access tokens. +og:title: Support enterprise-managed authorization in your MCP server - C1.ai docs +og:description: Make your MCP server accept C1.ai-issued tokens by trusting C1.ai as an issuer and exchanging its ID-JAGs for your own access tokens. sidebarTitle: Support in your MCP server --- {/* Editor Refresh: 2026-06-13 */} -This page is for a developer making an MCP server accept C1-issued tokens, whether that server is an internal application your organization builds or a SaaS your organization runs. The C1 admin registers your server inside C1; the work described here is the other side, done at your authorization server. +This page is for a developer making an MCP server accept C1.ai-issued tokens, whether that server is an internal application your organization builds or a SaaS your organization runs. The C1.ai admin registers your server inside C1.ai; the work described here is the other side, done at your authorization server. -Enterprise-managed authorization is built on the open Cross-App Access (XAA) standard, and the token C1 issues is an ID-JAG; both are used directly below because they're what you implement against. +Enterprise-managed authorization is built on the open Cross-App Access (XAA) standard, and the token C1.ai issues is an ID-JAG; both are used directly below because they're what you implement against. ## What your MCP server needs to do To support enterprise-managed authorization, your server does two things: -- Accept C1 as a trusted token issuer. -- Exchange the tokens C1 issues for your own access tokens, using the JWT bearer grant. +- Accept C1.ai as a trusted token issuer. +- Exchange the tokens C1.ai issues for your own access tokens, using the JWT bearer grant. -C1 issues an ID-JAG, a short-lived JWT whose audience is your authorization server's issuer. Your authorization server verifies C1's signature, confirms the token is meant for it, and returns one of your own access tokens that the agent then uses to call your API. +C1.ai issues an ID-JAG, a short-lived JWT whose audience is your authorization server's issuer. Your authorization server verifies C1.ai's signature, confirms the token is meant for it, and returns one of your own access tokens that the agent then uses to call your API. These examples use `conductor.one`. If your organization is on the EU data residency instance, substitute `c1eu.ai` in URLs, client IDs, and hostnames. -## Trust C1 as an issuer +## Trust C1.ai as an issuer -Configure your authorization server to recognize C1 as a token issuer and to advertise the grant C1 relies on. +Configure your authorization server to recognize C1.ai as a token issuer and to advertise the grant C1.ai relies on. -Add C1's issuer URL and its JWKS URL to your authorization server's trusted-issuer configuration. The issuer is the tenant URL, and the keys are published at the tenant's JWKS endpoint: +Add C1.ai's issuer URL and its JWKS URL to your authorization server's trusted-issuer configuration. The issuer is the tenant URL, and the keys are published at the tenant's JWKS endpoint: ```text Issuer: https://.conductor.one @@ -42,10 +42,10 @@ Your authorization server verifies the ID-JAG signature against the keys at the Register the agent's client at your authorization server. The `client_id` claim in the ID-JAG names the agent's client; the client ID you assign at your authorization server must match it so the same client is recognized on both sides. The client authenticates to your authorization server with its own credentials on the JWT bearer request; you choose which client authentication method to require. -Advertise the JWT bearer grant (`urn:ietf:params:oauth:grant-type:jwt-bearer`) in your authorization-server metadata, as defined by [RFC 8414](https://www.rfc-editor.org/rfc/rfc8414.html). C1 discovers this metadata to confirm your authorization server can redeem an ID-JAG. +Advertise the JWT bearer grant (`urn:ietf:params:oauth:grant-type:jwt-bearer`) in your authorization-server metadata, as defined by [RFC 8414](https://www.rfc-editor.org/rfc/rfc8414.html). C1.ai discovers this metadata to confirm your authorization server can redeem an ID-JAG. -Serve protected-resource metadata from your system, as defined by [RFC 9728](https://www.rfc-editor.org/rfc/rfc9728.html). This is how C1 discovers which authorization server protects your system. +Serve protected-resource metadata from your system, as defined by [RFC 9728](https://www.rfc-editor.org/rfc/rfc9728.html). This is how C1.ai discovers which authorization server protects your system. @@ -58,14 +58,14 @@ When your authorization server receives an ID-JAG on a JWT bearer grant, verify | Token type header (`typ`) | `oauth-id-jag+jwt` | | Audience (`aud`) | Exactly your authorization server's issuer, and only that value | | Client | Matches the client authenticating the JWT bearer request | -| Signature | Verifies against C1's published keys at the JWKS URL | +| Signature | Verifies against C1.ai's published keys at the JWKS URL | | Scope (`scope`) | Issue an access token carrying only the scopes in the ID-JAG. You may narrow them, but don't add any. | ### Requesting scopes (and omitting `scope`) The ID-JAG token-exchange `scope` parameter is **optional** ([RFC 8693 §2.1](https://www.rfc-editor.org/rfc/rfc8693.html#section-2.1)). -- **`scope` omitted (or blank):** C1 grants the subject's **default full set** at the resource server — every *enabled* scope the subject is actually entitled to (`enabled-at-RS ∩ subject-held`). This is the path most silent clients use (for example, Claude Code's silent exchange sends no `scope`). +- **`scope` omitted (or blank):** C1.ai grants the subject's **default full set** at the resource server — every *enabled* scope the subject is actually entitled to (`enabled-at-RS ∩ subject-held`). This is the path most silent clients use (for example, Claude Code's silent exchange sends no `scope`). - **`scope` provided:** the grant is narrowed to `requested ∩ enabled ∩ held`. A request can drop scopes but never widen beyond what the subject holds; un-held or not-enabled scopes are silently dropped. - If the subject holds **no** scopes at the resource server, the exchange is **denied** (`invalid_grant`) whether or not `scope` was sent — an omitted `scope` is never a free pass. @@ -73,27 +73,27 @@ The issued ID-JAG's `scope` claim always reflects exactly the granted set. ## Identify the user -The ID-JAG identifies the C1 user the agent is acting for. Use these claims to resolve the token to an account in your system. +The ID-JAG identifies the C1.ai user the agent is acting for. Use these claims to resolve the token to an account in your system. | Claim | What it carries | | :--- | :--- | -| `sub` | An opaque, C1-minted subject pseudonym — a bare random URL-safe identifier with no internal structure, never the user's raw C1 ID and with no `user:` prefix. By default it is **pairwise**: stable for your system, but a different value at every other system, so the same user can't be correlated across systems. (A C1 admin can opt your system into a global pseudonym instead — the same value for that user everywhere.) For your system it is **consistent across token types**: the same value appears whether it's in a C1 ID token issued to your system or in an ID-JAG for your system, so if you also do direct C1 SSO the subjects match. It is not the user's email address. | -| `email` | The user's email address. C1 includes it by default so you can link the token to an existing account or provision one just in time. | +| `sub` | An opaque, C1.ai-minted subject pseudonym — a bare random URL-safe identifier with no internal structure, never the user's raw C1.ai ID and with no `user:` prefix. By default it is **pairwise**: stable for your system, but a different value at every other system, so the same user can't be correlated across systems. (A C1.ai admin can opt your system into a global pseudonym instead — the same value for that user everywhere.) For your system it is **consistent across token types**: the same value appears whether it's in a C1.ai ID token issued to your system or in an ID-JAG for your system, so if you also do direct C1.ai SSO the subjects match. It is not the user's email address. | +| `email` | The user's email address. C1.ai includes it by default so you can link the token to an existing account or provision one just in time. | | `auth_time` | When the user last authenticated, when that information is available. | -Key your local account on the full opaque `sub` — at one system, `iss` + `sub` is a stable, durable account key. Store it verbatim; never parse it or expect a raw C1 user ID inside it. Because the `sub` is pairwise by default, it isn't a cross-system identifier, so use `email` to link accounts across systems or to provision one just in time when you don't already have a mapping. +Key your local account on the full opaque `sub` — at one system, `iss` + `sub` is a stable, durable account key. Store it verbatim; never parse it or expect a raw C1.ai user ID inside it. Because the `sub` is pairwise by default, it isn't a cross-system identifier, so use `email` to link accounts across systems or to provision one just in time when you don't already have a mapping. -C1 does not send a SAML `NameID` (`sub_id`) or a resource-server-specific user identifier (`aud_sub`) in this release. If your system resolves users by one of those, contact the C1 Support team. +C1.ai does not send a SAML `NameID` (`sub_id`) or a resource-server-specific user identifier (`aud_sub`) in this release. If your system resolves users by one of those, contact the C1.ai Support team. -## Signing algorithms C1 can use +## Signing algorithms C1.ai can use -C1 can sign ID-JAGs with ES256 (the default), RS256, or EdDSA. Pick the algorithm your authorization server verifies, and tell your C1 admin which one to use for your system. C1 uses the chosen algorithm with no silent fallback, so the algorithm your admin configures must be one your authorization server accepts. +C1.ai can sign ID-JAGs with ES256 (the default), RS256, or EdDSA. Pick the algorithm your authorization server verifies, and tell your C1.ai admin which one to use for your system. C1.ai uses the chosen algorithm with no silent fallback, so the algorithm your admin configures must be one your authorization server accepts. These examples use `conductor.one`. If your organization is on the EU data residency instance, substitute `c1eu.ai` in URLs, client IDs, and hostnames. ## Example -The following are taken from a verified end-to-end exchange against a live C1 tenant. The protected-resource metadata document shows the fields C1 reads during discovery, and the decoded ID-JAG shows the claims your authorization server verifies. +The following are taken from a verified end-to-end exchange against a live C1.ai tenant. The protected-resource metadata document shows the fields C1.ai reads during discovery, and the decoded ID-JAG shows the claims your authorization server verifies. **The `resource` in your protected-resource metadata must equal the exact URL the agent calls, including any path** — not just the origin. If your MCP server is at `https://api.example.com/mcp`, serve the metadata at `https://api.example.com/.well-known/oauth-protected-resource/mcp` with `"resource": "https://api.example.com/mcp"`. A bare-origin `resource` (e.g. `https://api.example.com`) causes the client's discovery to fail with a resource mismatch. @@ -150,7 +150,7 @@ grant_type=urn:ietf:params:oauth:grant-type:jwt-bearer -**`sub` is an opaque pseudonym, not a C1 user ID.** The `sub` above (`3FFshhPuwk7lbS1M0nESX4KUIxs`) is a bare, C1-minted identifier with no internal structure — by default it's unique to your system, so don't parse it and don't expect to see a raw C1 user ID. Store it verbatim as your account key. (`email` is included when available; the `auth_time` claim is present when C1 has that information.) +**`sub` is an opaque pseudonym, not a C1.ai user ID.** The `sub` above (`3FFshhPuwk7lbS1M0nESX4KUIxs`) is a bare, C1.ai-minted identifier with no internal structure — by default it's unique to your system, so don't parse it and don't expect to see a raw C1.ai user ID. Store it verbatim as your account key. (`email` is included when available; the `auth_time` claim is present when C1.ai has that information.) diff --git a/product/admin/entitlement-config-rules.mdx b/product/admin/entitlement-config-rules.mdx index 57c69731..feac65bb 100644 --- a/product/admin/entitlement-config-rules.mdx +++ b/product/admin/entitlement-config-rules.mdx @@ -1,6 +1,6 @@ --- title: Apply request settings automatically with entitlement configuration rules -og:title: Apply request settings automatically with entitlement configuration rules - C1 docs +og:title: Apply request settings automatically with entitlement configuration rules - C1.ai docs og:description: Use entitlement configuration rules to resolve the request policy and access request settings for many entitlements at once, based on conditions you define—including conditions that match the role and scope of cloud infrastructure apps. description: Use entitlement configuration rules to resolve the request policy and access request settings for many entitlements at once, based on conditions you define—including conditions that match the role and scope of cloud infrastructure apps. sidebarTitle: Entitlement configuration rules diff --git a/product/admin/expressions-examples.mdx b/product/admin/expressions-examples.mdx index d711b11d..4711d604 100644 --- a/product/admin/expressions-examples.mdx +++ b/product/admin/expressions-examples.mdx @@ -1,8 +1,8 @@ --- title: CEL expressions examples -og:title: CEL expressions examples - C1 docs -og:description: Practical examples, common patterns, and real-world use cases for CEL expressions in C1. -description: Practical examples, common patterns, and real-world use cases for CEL expressions in C1. +og:title: CEL expressions examples - C1.ai docs +og:description: Practical examples, common patterns, and real-world use cases for CEL expressions in C1.ai. +description: Practical examples, common patterns, and real-world use cases for CEL expressions in C1.ai. --- {/* Editor Refresh: 2026-02-06 */} diff --git a/product/admin/expressions-reference.mdx b/product/admin/expressions-reference.mdx index 93b22cba..9179352f 100644 --- a/product/admin/expressions-reference.mdx +++ b/product/admin/expressions-reference.mdx @@ -1,8 +1,8 @@ --- title: CEL expressions reference -og:title: CEL expressions reference - C1 docs -og:description: Complete reference for CEL expression objects, functions, and usage contexts in C1. -description: Complete reference for CEL expression objects, functions, and usage contexts in C1. +og:title: CEL expressions reference - C1.ai docs +og:description: Complete reference for CEL expression objects, functions, and usage contexts in C1.ai. +description: Complete reference for CEL expression objects, functions, and usage contexts in C1.ai. --- {/* Editor Refresh: 2026-02-13 */} @@ -80,7 +80,7 @@ Enums are predefined constants. Always use the full enum name (e.g., `UserStatus | Value | Meaning | |:------|:--------| -| `TaskOrigin.WEBAPP` | Created in C1 web interface | +| `TaskOrigin.WEBAPP` | Created in C1.ai web interface | | `TaskOrigin.SLACK` | Created via Slack integration | | `TaskOrigin.API` | Created via API | | `TaskOrigin.JIRA` | Created via Jira integration | @@ -120,12 +120,12 @@ Used in `ctx.trigger.oldAccount.status.status` and `ctx.trigger.newAccount.statu These are complex types returned by functions or available as variables. -**User vs AppUser:** These are different types. A `User` is a person in the C1 directory (your identity provider sync). An `AppUser` is that person's account within a specific application (their GitHub account, Okta account, etc.). One User can have many AppUsers across different apps. +**User vs AppUser:** These are different types. A `User` is a person in the C1.ai directory (your identity provider sync). An `AppUser` is that person's account within a specific application (their GitHub account, Okta account, etc.). One User can have many AppUsers across different apps. #### User -Represents a person in the C1 directory. This is your organization's user record, typically synced from an identity provider. +Represents a person in the C1.ai directory. This is your organization's user record, typically synced from an identity provider. **Returned by:** `FindByEmail`, `GetByID`, `GetManagers`, `DirectReports`, `GetEntitlementMembers` @@ -153,7 +153,7 @@ Represents a person in the C1 directory. This is your organization's user record #### Group -Represents a C1 group. Returned by `FindByName`. +Represents a C1.ai group. Returned by `FindByName`. | Field | Type | Description | |:------|:-----|:------------| @@ -187,7 +187,7 @@ Represents a user's account within a specific connected application (e.g., their #### Task -Represents an access request or task in C1. See [Task object](#task-object) for all fields. +Represents an access request or task in C1.ai. See [Task object](#task-object) for all fields. **Available as:** `task` (in policy expressions) @@ -239,7 +239,7 @@ These variables are automatically available in specific contexts. ## Functions -These library functions let you interact with the C1 system to look up whether a user has access to a certain application or entitlement, or to find the user or list of users who should review a task. +These library functions let you interact with the C1.ai system to look up whether a user has access to a certain application or entitlement, or to find the user or list of users who should review a task. ### User library functions @@ -305,7 +305,7 @@ Note that automation triggers do NOT have access to directory or user library fu ### Time functions -C1 provides comprehensive time functions for working with dates and times in CEL expressions. These functions are available in **all CEL contexts** (Policies, Groups, Automations, Account provisioning). +C1.ai provides comprehensive time functions for working with dates and times in CEL expressions. These functions are available in **all CEL contexts** (Policies, Groups, Automations, Account provisioning). #### Core time functions @@ -426,7 +426,7 @@ For full examples and best practices, see [Use external insights in CEL policy c ### Subject object -The "subject" variable refers to the C1 user. +The "subject" variable refers to the C1.ai user. #### Most common fields @@ -472,7 +472,7 @@ Both `subject.manager` (email) and `subject.manager_id` (ID) are available. Use **Use custom user attributes.** -You can write condition expressions that leverage the custom user attributes you've set up in C1. Any [custom user attribute](/product/admin/attributes) can be passed in to the `subject.attributes.` property and used in your condition expressions. +You can write condition expressions that leverage the custom user attributes you've set up in C1.ai. Any [custom user attribute](/product/admin/attributes) can be passed in to the `subject.attributes.` property and used in your condition expressions. ### User object @@ -524,7 +524,7 @@ The task analysis object provides information about potential access conflicts a ### Entitlement object -The `entitlement` object can only be used in CEL expressions in policies. It does not work when writing CEL expressions to form C1 groups. +The `entitlement` object can only be used in CEL expressions in policies. It does not work when writing CEL expressions to form C1.ai groups. | Field | Data type | Description | Example usage | Common use cases | | :--- | :--- | :--- | :--- | :--- | @@ -560,7 +560,7 @@ The IP CIDR object is used for network range-based access control and filtering. ## Object usage reference -Understanding where each object can be used helps you write effective CEL expressions for different C1 features. +Understanding where each object can be used helps you write effective CEL expressions for different C1.ai features. ### Quick object reference table @@ -806,7 +806,7 @@ Automation triggers have limited function access. They do NOT have access to dir ## Important notes ### Use camelCase -CEL expressions should be written in camelCase. C1 is moving away from snake_case for consistency and readability. Existing expressions in snake_case will still work, but new ones should follow the camelCase convention. +CEL expressions should be written in camelCase. C1.ai is moving away from snake_case for consistency and readability. Existing expressions in snake_case will still work, but new ones should follow the camelCase convention. ### Null safety with has() Use the `has()` macro to check for existence of optional fields, especially in profile maps: diff --git a/product/admin/expressions-troubleshooting.mdx b/product/admin/expressions-troubleshooting.mdx index 8f7ff19a..033987e3 100644 --- a/product/admin/expressions-troubleshooting.mdx +++ b/product/admin/expressions-troubleshooting.mdx @@ -1,8 +1,8 @@ --- title: Troubleshoot CEL expressions -og:title: Troubleshoot CEL expressions - C1 docs -og:description: Debug common errors, understand failure modes, and fix CEL expressions in C1. -description: Debug common errors, understand failure modes, and fix CEL expressions in C1. +og:title: Troubleshoot CEL expressions - C1.ai docs +og:description: Debug common errors, understand failure modes, and fix CEL expressions in C1.ai. +description: Debug common errors, understand failure modes, and fix CEL expressions in C1.ai. --- When your CEL expression doesn't work, this guide helps you figure out why. Most problems fall into two categories: errors caught when you save (easy to fix) and silent failures at runtime (harder to debug). diff --git a/product/admin/expressions-workflows.mdx b/product/admin/expressions-workflows.mdx index 17648219..d2a39d6b 100644 --- a/product/admin/expressions-workflows.mdx +++ b/product/admin/expressions-workflows.mdx @@ -1,11 +1,11 @@ --- title: Workflow expressions -og:title: Workflow expressions - C1 docs +og:title: Workflow expressions - C1.ai docs og:description: Use CEL expressions in workflows to pass data between steps, access trigger context, and build dynamic automations. description: Use CEL expressions in workflows to pass data between steps, access trigger context, and build dynamic automations. --- -Workflow expressions let you pass data between steps in C1 automations - like threading a user's email from a trigger into a lookup step, then into a notification. This is the most powerful CEL context because data flows through multiple steps, and each step can access outputs from all previous steps. +Workflow expressions let you pass data between steps in C1.ai automations - like threading a user's email from a trigger into a lookup step, then into a notification. This is the most powerful CEL context because data flows through multiple steps, and each step can access outputs from all previous steps. ## Core concept: The ctx object diff --git a/product/admin/expressions.mdx b/product/admin/expressions.mdx index e9acf162..201cbe4a 100644 --- a/product/admin/expressions.mdx +++ b/product/admin/expressions.mdx @@ -1,16 +1,16 @@ --- title: Write condition expressions -og:title: Write condition expressions - C1 docs -og:description: Write Common Expression Language (CEL) expressions to define rules for C1 policies and groups. -description: Write Common Expression Language (CEL) expressions to define rules for C1 policies and groups. +og:title: Write condition expressions - C1.ai docs +og:description: Write Common Expression Language (CEL) expressions to define rules for C1.ai policies and groups. +description: Write Common Expression Language (CEL) expressions to define rules for C1.ai policies and groups. --- {/* Editor Refresh: 2026-01-21 */} ## What are CEL expressions and why use them? -CEL (Common Expression Language) expressions are powerful, flexible rules that let you automate decision-making across C1. Instead of manually configuring each policy, group, or automation, you can write expressions that automatically adapt to your organization's unique needs. +CEL (Common Expression Language) expressions are powerful, flexible rules that let you automate decision-making across C1.ai. Instead of manually configuring each policy, group, or automation, you can write expressions that automatically adapt to your organization's unique needs. -CEL is an open-source expression language created by Google. It's the same technology behind Firebase Rules, Google Cloud IAM conditions, and Kubernetes admission webhooks. C1 extends standard CEL with custom functions for directory lookups, user queries, and access management. +CEL is an open-source expression language created by Google. It's the same technology behind Firebase Rules, Google Cloud IAM conditions, and Kubernetes admission webhooks. C1.ai extends standard CEL with custom functions for directory lookups, user queries, and access management. ### Why use CEL expressions? @@ -28,7 +28,7 @@ CEL is an open-source expression language created by Google. It's the same techn ## Where CEL expressions are used -C1 uses CEL expressions in many contexts. Each context provides different variables and expects a specific return type. +C1.ai uses CEL expressions in many contexts. Each context provides different variables and expects a specific return type. ### Primary contexts @@ -58,7 +58,7 @@ Each context provides different variables. For example, `subject` is available i ## How expressions work -When you save an expression, C1 validates it immediately. This catches most errors before they can cause problems: +When you save an expression, C1.ai validates it immediately. This catches most errors before they can cause problems: **Caught when you save:** - Syntax errors (missing quotes, parentheses) @@ -77,9 +77,9 @@ Runtime issues are subtle. For example, if an approver expression returns an emp ## Generate an expression with AI -Instead of writing CEL by hand, you can describe the condition you need in plain English and let C1 generate it for you. In the CEL expression field, click **Generate**, describe the condition — for example, "approve automatically for employees in the Engineering department" — and the generated expression is dropped directly into the field for you to review and save. +Instead of writing CEL by hand, you can describe the condition you need in plain English and let C1.ai generate it for you. In the CEL expression field, click **Generate**, describe the condition — for example, "approve automatically for employees in the Engineering department" — and the generated expression is dropped directly into the field for you to review and save. -If C1 can't generate a valid expression from your description, it explains why instead of guessing, and leaves the field untouched so you can adjust your description and try again. +If C1.ai can't generate a valid expression from your description, it explains why instead of guessing, and leaves the field untouched so you can adjust your description and try again. --- @@ -99,7 +99,7 @@ CEL expressions power two critical parts of [policies](/product/admin/policies): ### Groups - Create dynamic user collections -Use CEL expressions to define membership for [C1 groups](/product/admin/groups): +Use CEL expressions to define membership for [C1.ai groups](/product/admin/groups): **Group expressions** automatically determine group membership based on user attributes and conditions. These expressions must return true or false - true means the user is included in the group. @@ -144,7 +144,7 @@ When [configuring account provisioning](/product/admin/account-provisioning), CE - **[Troubleshooting](/product/admin/expressions-troubleshooting)** - Debug common errors and understand failure modes {/* -LLM Note: For AI assistants answering questions about CEL expressions in C1, +LLM Note: For AI assistants answering questions about CEL expressions in C1.ai, a structured knowledge base is available at rap/cel-expressions/index.md with focused, retrievable documentation chunks. The index describes available files and when to use each. */} diff --git a/product/admin/external-datasources.mdx b/product/admin/external-datasources.mdx index 23192e80..46012212 100644 --- a/product/admin/external-datasources.mdx +++ b/product/admin/external-datasources.mdx @@ -1,7 +1,7 @@ --- title: Manage external data sources og:title: Manage external data sources such as S3 and Azure Blob Storage for IGA -og:description: Use external data sources such as S3 buckets and Azure Blob Storage for modern identity governance in C1 +og:description: Use external data sources such as S3 buckets and Azure Blob Storage for modern identity governance in C1.ai description: Leverage external data sources in S3 or Azure Blob Storage for ingesting app data or pushing SIEM logs sidebarTitle: External data sources --- @@ -9,7 +9,7 @@ sidebarTitle: External data sources ## What are external data sources? -External data sources are S3 buckets and Azure Blob containers that C1 has the permissions to read and write. External data sources can be used for: +External data sources are S3 buckets and Azure Blob containers that C1.ai has the permissions to read and write. External data sources can be used for: - Pushing audit logs for offline storage - Pushing audit logs for consumption into your SIEM @@ -18,18 +18,18 @@ External data sources are S3 buckets and Azure Blob containers that C1 has the p ## Set up an S3 data source -This task requires the **Super Administrator** role in C1 and the **ability to create an IAM Role** in AWS. +This task requires the **Super Administrator** role in C1.ai and the **ability to create an IAM Role** in AWS. -C1 uses an IAM Trust relationship between your AWS Account and C1's Service AWS Account for integrating to S3. This is the [AWS-recommended method of sharing access to AWS Accounts](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_common-scenarios_third-party.html). C1 has a specially created and isolated AWS Account dedicated to the AWS integration. +C1.ai uses an IAM Trust relationship between your AWS Account and C1.ai's Service AWS Account for integrating to S3. This is the [AWS-recommended method of sharing access to AWS Accounts](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_common-scenarios_third-party.html). C1.ai has a specially created and isolated AWS Account dedicated to the AWS integration. -### Step 1: Get a C1-provided External ID for the AWS IAM Role +### Step 1: Get a C1.ai-provided External ID for the AWS IAM Role -Log into C1. +Log into C1.ai. Navigate to **Platform** > **External data sources**. @@ -41,11 +41,11 @@ Click **Add data source**. Choose who will own and manage this integration, then click **Create and add details**. -The S3 bucket integration form opens. Copy and save the External ID generated for you by C1. You'll use this value in Step 2. +The S3 bucket integration form opens. Copy and save the External ID generated for you by C1.ai. You'll use this value in Step 2. -### Step 2: Create an AWS IAM Role for C1 +### Step 2: Create an AWS IAM Role for C1.ai @@ -211,20 +211,20 @@ Click **Save changes**. -### Step 4: Configure the external data source in C1 +### Step 4: Configure the external data source in C1.ai -Return to the C1 **Platform** > **External data sources** page if necessary and navigate to your newly created external data source. +Return to the C1.ai **Platform** > **External data sources** page if necessary and navigate to your newly created external data source. Paste the Role ARN you copied in Step 3 into the **Role ARN** field. -Enter the name of the S3 bucket that contains the files you want to use in C1 in the **S3 bucket** field. +Enter the name of the S3 bucket that contains the files you want to use in C1.ai in the **S3 bucket** field. -**Optional.** Enter the AWS region of the S3 bucket in the **S3 bucket region** field (for example, `us-east-1`). If left blank, C1 auto-detects the bucket's region. +**Optional.** Enter the AWS region of the S3 bucket in the **S3 bucket region** field (for example, `us-east-1`). If left blank, C1.ai auto-detects the bucket's region. Click **Save**. @@ -234,10 +234,10 @@ Click **Save**. ## Set up an Azure Blob Storage data source -This task requires the **Super Administrator** role in C1 and the ability to create a service principal and assign roles in Azure. +This task requires the **Super Administrator** role in C1.ai and the ability to create a service principal and assign roles in Azure. -C1 authenticates to Azure Blob Storage using an Azure Active Directory (Entra ID) service principal. The service principal must have the **Storage Blob Data Contributor** role on the target container. +C1.ai authenticates to Azure Blob Storage using an Azure Active Directory (Entra ID) service principal. The service principal must have the **Storage Blob Data Contributor** role on the target container. ### Step 1: Create a service principal in Azure @@ -246,7 +246,7 @@ C1 authenticates to Azure Blob Storage using an Azure Active Directory (Entra ID In the [Azure portal](https://portal.azure.com), navigate to **Microsoft Entra ID** > **App registrations** and click **New registration**. -Give the app registration a name, such as "C1 external data source", then click **Register**. +Give the app registration a name, such as "C1.ai external data source", then click **Register**. On the app registration overview page, copy and save the **Directory (tenant) ID** and the **Application (client) ID**. You'll use these in Step 3. @@ -285,11 +285,11 @@ Click **Review + assign** to complete the role assignment. -### Step 3: Configure the external data source in C1 +### Step 3: Configure the external data source in C1.ai -In C1, navigate to **Platform** > **External data sources**. +In C1.ai, navigate to **Platform** > **External data sources**. Click **Add data source** and select **Azure Blob Storage** as the data source type. @@ -311,6 +311,6 @@ Click **Save**. -**Done.** C1 can now read from and write to your Azure Blob container. +**Done.** C1.ai can now read from and write to your Azure Blob container. diff --git a/product/admin/external-insights.mdx b/product/admin/external-insights.mdx index efeba730..71108f30 100644 --- a/product/admin/external-insights.mdx +++ b/product/admin/external-insights.mdx @@ -1,30 +1,30 @@ --- title: "External insights" -description: "Bring identity risk scores from your security tools into C1 to inform access reviews and approval decisions." +description: "Bring identity risk scores from your security tools into C1.ai to inform access reviews and approval decisions." og:title: "External insights" -og:description: "Bring identity risk scores from your security tools into C1 to inform access reviews and approval decisions." +og:description: "Bring identity risk scores from your security tools into C1.ai to inform access reviews and approval decisions." sidebarTitle: "Leverage risk scores" --- {/* Editor Refresh: 2026-03-03 */} -External insights brings identity risk data from your security tools into C1, where it appears alongside the identities it describes. Reviewers and approvers see risk scores in context, such as during access reviews and at the moment of approval, so they can make more informed decisions without switching tools. +External insights brings identity risk data from your security tools into C1.ai, where it appears alongside the identities it describes. Reviewers and approvers see risk scores in context, such as during access reviews and at the moment of approval, so they can make more informed decisions without switching tools. ## How external insights work -When you configure an external insights source, C1 syncs risk data from that tool through its connector. C1 matches each risk score to an identity in your directory by email address and attaches it to that identity's profile and any accounts they hold in other connected apps. +When you configure an external insights source, C1.ai syncs risk data from that tool through its connector. C1.ai matches each risk score to an identity in your directory by email address and attaches it to that identity's profile and any accounts they hold in other connected apps. -Once synced, risk scores appear in the C1 UI wherever that identity appears in an access decision. +Once synced, risk scores appear in the C1.ai UI wherever that identity appears in an access decision. ## Enable or disable external insights -This task requires the **Super Administrator** or **Connector Administrator** role in C1. +This task requires the **Super Administrator** or **Connector Administrator** role in C1.ai. External insights are enabled automatically when a connector that is a supported external insight source is configured and syncing. No additional setup is required. -If needed, you can manually turn risk score syncing on or off from the connector's settings page in C1: +If needed, you can manually turn risk score syncing on or off from the connector's settings page in C1.ai: @@ -179,10 +179,10 @@ Require a clean posture from both sources for sensitive access: - Ingest Falcon identity risk scores and password risk (compromised or weak passwords) into C1. + Ingest Falcon identity risk scores and password risk (compromised or weak passwords) into C1.ai. - Ingest Wiz identity risk scores into C1. + Ingest Wiz identity risk scores into C1.ai. diff --git a/product/admin/external-ticketing.mdx b/product/admin/external-ticketing.mdx index e12e7d0d..10f7629e 100644 --- a/product/admin/external-ticketing.mdx +++ b/product/admin/external-ticketing.mdx @@ -1,20 +1,20 @@ --- title: Integrate an external ticketing system -og:title: Integrate an external ticketing system - C1 docs -og:description: Integrate your external ticketing system with C1 to automatically create, track, and update helpdesk tickets for provisioning tasks. -description: Integrate your external ticketing system with C1 to automatically create, track, and update helpdesk tickets for provisioning tasks. +og:title: Integrate an external ticketing system - C1.ai docs +og:description: Integrate your external ticketing system with C1.ai to automatically create, track, and update helpdesk tickets for provisioning tasks. +description: Integrate your external ticketing system with C1.ai to automatically create, track, and update helpdesk tickets for provisioning tasks. sidebarTitle: External ticketing --- {/* Editor Refresh: 2026-01-09 */} ## Configure Jira Cloud as an external ticketing provider -This process walks you through configuring an external ticketing integration with Jira Cloud. Once set up, C1 automatically creates Jira tickets to track provisioning assignments on the entitlements you choose. C1 will track the status of the Jira ticket, and will update the status of the access request in C1 accordingly. +This process walks you through configuring an external ticketing integration with Jira Cloud. Once set up, C1.ai automatically creates Jira tickets to track provisioning assignments on the entitlements you choose. C1.ai will track the status of the Jira ticket, and will update the status of the access request in C1.ai accordingly. ### Step 1: Set up the Jira Cloud connector -The Jira Cloud service account used for external ticketing must have the following project-level permissions on any project where C1 will create issues: +The Jira Cloud service account used for external ticketing must have the following project-level permissions on any project where C1.ai will create issues: - **Browse Projects** — required to verify created issues - **Create Issues** — required to create new issues @@ -34,7 +34,7 @@ During configuration, check the box to **Enable external ticket provisioning**. -In C1, click **Platform** > **External ticketing**. +In C1.ai, click **Platform** > **External ticketing**. Click **Add ticket provisioner**. @@ -52,24 +52,24 @@ Find the **Settings** section of the page and click **Edit**. In the **Schema** field, select the Jira issue type that you want new issues to be created in. -**Optional.** Add a ticket title and description that will be applied to all Jira issues created by C1. +**Optional.** Add a ticket title and description that will be applied to all Jira issues created by C1.ai. To customize your ticket titles and descriptions so they include specific information about the request, see [Customizing ticket templates](/product/admin/external-ticketing#customizing-ticket-templates). -Add a ticket label. This label (tag) will be added to Jira issues created by C1. +Add a ticket label. This label (tag) will be added to Jira issues created by C1.ai. Based on the Jira issue type you specified above, a list of custom fields is shown. Map these fields to the fields in a Jira issue. Except where noted, all fields are required. -Add provision state mappings. C1 will monitor the status of the Jira issue and update the access request task in C1 accordingly. +Add provision state mappings. C1.ai will monitor the status of the Jira issue and update the access request task in C1.ai accordingly. - - **Mark complete**: When a Jira issue transitions to this status, C1 will complete the provisioning step on the task. + - **Mark complete**: When a Jira issue transitions to this status, C1.ai will complete the provisioning step on the task. - - **Mark errored**: When a Jira issue transitions to this status, C1 will mark the provisioning step as errored and fall back to manual provisioning. + - **Mark errored**: When a Jira issue transitions to this status, C1.ai will mark the provisioning step as errored and fall back to manual provisioning. Click **Save**. @@ -80,7 +80,7 @@ Click **Save**. -In C1, click **Apps**. +In C1.ai, click **Apps**. Select an application and click **Entitlements**. @@ -95,7 +95,7 @@ In the **Configure provisioning** drawer, select the **External ticketing** prov Select the Jira Cloud external ticket provisioner configuration you created. -**Optional.** Add any instructions you want to include in the Jira tickets C1 will create about how to provision this access. +**Optional.** Add any instructions you want to include in the Jira tickets C1.ai will create about how to provision this access. Click **Save**. @@ -104,11 +104,11 @@ Click **Save**. Repeat this process for other entitlements as needed. -**Done.** Now, when a user requests access to the entitlement, C1 will automatically create a Jira issue. C1 will monitor the status of the Jira issue, and once the Jira issue transitions to its completed status, the provisioning step will be marked complete in C1 as well. +**Done.** Now, when a user requests access to the entitlement, C1.ai will automatically create a Jira issue. C1.ai will monitor the status of the Jira issue, and once the Jira issue transitions to its completed status, the provisioning step will be marked complete in C1.ai as well. ## Configure Jira Data Center as an external ticketing provider -This process walks you through configuring an external ticketing integration with Jira Data Center. Once set up, C1 automatically creates Jira tickets to track provisioning assignments on the entitlements you choose. C1 will track the status of the Jira ticket, and will update the status of the access request in C1 accordingly. +This process walks you through configuring an external ticketing integration with Jira Data Center. Once set up, C1.ai automatically creates Jira tickets to track provisioning assignments on the entitlements you choose. C1.ai will track the status of the Jira ticket, and will update the status of the access request in C1.ai accordingly. ### Step 1: Generate a personal access token in Jira Data Center @@ -123,7 +123,7 @@ Navigate to the **Personal Access Tokens** section. Click **Create token**. -Give your token a name, such as "C1". +Give your token a name, such as "C1.ai". Click **Create**. The new personal access token is generated. @@ -135,12 +135,12 @@ Carefully copy and save the new token. You'll use it in Step 3. ### Step 2: Set up the Baton connector -This task requires the **Connector Administrator** or **Super Administrator** role in C1. +This task requires the **Connector Administrator** or **Super Administrator** role in C1.ai. -In C1, navigate to **Apps** > **Connectors** and click **Add connector**. +In C1.ai, navigate to **Apps** > **Connectors** and click **Add connector**. Search for **Baton** and click **Add**. @@ -209,7 +209,7 @@ public.ecr.aws/conductorone/baton-jira-datacenter:latest -f "/out/sync.c1z" -In C1, click **Platform** > **External ticketing**. +In C1.ai, click **Platform** > **External ticketing**. Click **Add ticket provisioner**. @@ -227,24 +227,24 @@ Find the **Settings** section of the page and click **Edit**. In the **Schema** field, select the Jira issue type that you want new issues to be created in. -**Optional.** Add a ticket title and description that will be applied to all Jira issues created by C1. +**Optional.** Add a ticket title and description that will be applied to all Jira issues created by C1.ai. To customize your ticket titles and descriptions so they include specific information about the request, see [Customizing ticket templates](/product/admin/external-ticketing#customizing-ticket-templates). -Add a ticket label. This label (tag) will be added to Jira issues created by C1. +Add a ticket label. This label (tag) will be added to Jira issues created by C1.ai. Based on the Jira issue type you specified above, a list of custom fields is shown. Map these fields to the fields in a Jira issue. Except where noted, all fields are required. -Add provision state mappings. C1 will monitor the status of the Jira issue and update the access request task in C1 accordingly. +Add provision state mappings. C1.ai will monitor the status of the Jira issue and update the access request task in C1.ai accordingly. - - **Mark complete**: When a Jira issue transitions to this status, C1 will complete the provisioning step on the task. + - **Mark complete**: When a Jira issue transitions to this status, C1.ai will complete the provisioning step on the task. - - **Mark errored**: When a Jira issue transitions to this status, C1 will mark the provisioning step as errored and fall back to manual provisioning. + - **Mark errored**: When a Jira issue transitions to this status, C1.ai will mark the provisioning step as errored and fall back to manual provisioning. Click **Save**. @@ -255,7 +255,7 @@ Click **Save**. -In C1, click **Apps**. +In C1.ai, click **Apps**. Select an application and click **Entitlements**. @@ -270,7 +270,7 @@ In the **Configure provisioning** drawer, select the **External ticketing** prov Select the Jira Data Center external ticket provisioner configuration you created. -**Optional.** Add any instructions you want to include in the Jira tickets C1 will create about how to provision this access. +**Optional.** Add any instructions you want to include in the Jira tickets C1.ai will create about how to provision this access. Click **Save**. @@ -279,11 +279,11 @@ Click **Save**. Repeat this process for other entitlements as needed. -**Done.** Now, when a user requests access to the entitlement, C1 will automatically create a Jira issue. C1 will monitor the status of the Jira issue, and once the Jira issue transitions to the “Done” status, the provisioning step will be marked complete in C1 as well. +**Done.** Now, when a user requests access to the entitlement, C1.ai will automatically create a Jira issue. C1.ai will monitor the status of the Jira issue, and once the Jira issue transitions to the “Done” status, the provisioning step will be marked complete in C1.ai as well. ## Configure ServiceNow as an external ticketing provider -This process walks you through configuring an external ticketing integration with ServiceNow. Once set up, C1 will automatically create ServiceNow items to track provisioning assignments on the entitlements you choose. C1 will track the status of the ServiceNow item, and will update the status of the access request in C1 accordingly. +This process walks you through configuring an external ticketing integration with ServiceNow. Once set up, C1.ai will automatically create ServiceNow items to track provisioning assignments on the entitlements you choose. C1.ai will track the status of the ServiceNow item, and will update the status of the access request in C1.ai accordingly. ### Step 1: Set up the ServiceNow connector @@ -295,14 +295,14 @@ Follow the documentation to [set up the ServiceNow connector](/baton/servicenow) During configuration, check the box to **Enable external ticket provisioning**. -**Optional.** Add a catalog ID and/or category ID to filter down catalog items. These fields are optional, but C1 only syncs 100 catalog items, so filtering is recommended. +**Optional.** Add a catalog ID and/or category ID to filter down catalog items. These fields are optional, but C1.ai only syncs 100 catalog items, so filtering is recommended. ### Step 2: Configure the external ticket provisioner integration -In C1, click **Platform** > **External ticketing**. +In C1.ai, click **Platform** > **External ticketing**. Click **Add ticket provisioner**. @@ -320,14 +320,14 @@ Find the **Settings** section of the page and click **Edit**. In the **Schema** field, select the catalog item that you want requests to be created for. -**Optional.** Add a ticket title and description. If added, the title and description will be added to all ServiceNow requested items created by C1. +**Optional.** Add a ticket title and description. If added, the title and description will be added to all ServiceNow requested items created by C1.ai. To customize your ticket titles and descriptions so they include specific information about the request, see [Customizing ticket templates](/product/admin/external-ticketing#customizing-ticket-templates). -Add a ticket label. This label (tag) will be added to ServiceNow requested items created by C1. +Add a ticket label. This label (tag) will be added to ServiceNow requested items created by C1.ai. Based on the schema you specified above, a list of custom fields is shown. Map these fields to the fields in a ServiceNow requested item. Except where noted, all fields are required. @@ -335,11 +335,11 @@ Based on the schema you specified above, a list of custom fields is shown. Map t You can also use ServiceNow's `ref` variables here, but the `sys_id` must be used to populate the value. -Add provision state mappings. C1 will monitor the status of the ServiceNow requested item and update the access request task in C1. +Add provision state mappings. C1.ai will monitor the status of the ServiceNow requested item and update the access request task in C1.ai. - - **Mark complete**: When a ServiceNow requested item transitions to this status, C1 will mark the provisioning step on the task complete. + - **Mark complete**: When a ServiceNow requested item transitions to this status, C1.ai will mark the provisioning step on the task complete. - - **Mark errored**: When a ServiceNow requested item transitions to this status, C1 will mark the provisioning step as errored and fall back to manual provisioning. + - **Mark errored**: When a ServiceNow requested item transitions to this status, C1.ai will mark the provisioning step as errored and fall back to manual provisioning. Click **Save**. @@ -350,7 +350,7 @@ Click **Save**. -In C1, click **Apps**. +In C1.ai, click **Apps**. Select an application and click **Entitlements**. @@ -374,11 +374,11 @@ Click **Save**. Repeat this process for other entitlements as needed. -**Done.** Now, when a user requests access to the entitlement, C1 will automatically create a ServiceNow requested item. C1 will monitor the status of the ServiceNow requested item, and once the ServiceNow requested item transitions to the “Done” status, the provisioning step will be marked complete in C1 as well. +**Done.** Now, when a user requests access to the entitlement, C1.ai will automatically create a ServiceNow requested item. C1.ai will monitor the status of the ServiceNow requested item, and once the ServiceNow requested item transitions to the “Done” status, the provisioning step will be marked complete in C1.ai as well. ## Configure Freshservice as an external ticketing provider -This process walks you through configuring an external ticketing integration with Freshservice. Once set up, C1 will automatically create Freshservice tickets to track provisioning assignments on the entitlements you choose. C1 will track the status of the Freshservice ticket, and will update the status of the access request in C1 accordingly. +This process walks you through configuring an external ticketing integration with Freshservice. Once set up, C1.ai will automatically create Freshservice tickets to track provisioning assignments on the entitlements you choose. C1.ai will track the status of the Freshservice ticket, and will update the status of the access request in C1.ai accordingly. ### Step 1: Set up the Freshservice connector @@ -392,7 +392,7 @@ During configuration, check the box to **Enable external ticket provisioning**. **Optional.** Add a service category ID to filter down category items. - This field is optional, but C1 only syncs 100 category items, so filtering is recommended. You can find the full list of categories by navigating to `https://.freshservice.com/api/v2/service_catalog/categories`. + This field is optional, but C1.ai only syncs 100 category items, so filtering is recommended. You can find the full list of categories by navigating to `https://.freshservice.com/api/v2/service_catalog/categories`. @@ -400,7 +400,7 @@ During configuration, check the box to **Enable external ticket provisioning**. -In C1, click **Platform** > **External ticketing**. +In C1.ai, click **Platform** > **External ticketing**. Click **Add ticket provisioner**. @@ -418,14 +418,14 @@ Find the **Settings** section of the page and click **Edit**. In the **Schema** field, select the catalog item that you want requests to be created for. -**Optional.** Add a ticket title and description. If added, the title and description will be added to all Freshservice tickets created by C1. +**Optional.** Add a ticket title and description. If added, the title and description will be added to all Freshservice tickets created by C1.ai. To customize your ticket titles and descriptions so they include specific information about the request, see [Customizing ticket templates](/product/admin/external-ticketing#customizing-ticket-templates). -Add a ticket label. This label (tag) will be added to Freshservice tickets created by C1. +Add a ticket label. This label (tag) will be added to Freshservice tickets created by C1.ai. Based on the schema you chose above, a list of custom fields is shown. Map these fields to the fields in a Freshservice ticket. Except where noted, all fields are required. @@ -433,11 +433,11 @@ Based on the schema you chose above, a list of custom fields is shown. Map these You can use the variables listed in the [Customizing ticket templates](/product/admin/external-ticketing#customizing-ticket-templates) section below to configure fields that pull a Freshservice data source. -Add provision state mappings. C1 will monitor the status of the Freshservice ticket and update the access request task in C1. +Add provision state mappings. C1.ai will monitor the status of the Freshservice ticket and update the access request task in C1.ai. -- **Mark complete**: When a Freshservice ticket transitions to this status, C1 will mark the provisioning step on the task complete. +- **Mark complete**: When a Freshservice ticket transitions to this status, C1.ai will mark the provisioning step on the task complete. -- **Mark errored**: When a Freshservice ticket transitions to this status, C1 will mark the provisioning step as errored and fall back to manual provisioning. +- **Mark errored**: When a Freshservice ticket transitions to this status, C1.ai will mark the provisioning step as errored and fall back to manual provisioning. Click **Save**. @@ -449,7 +449,7 @@ Click **Save**. -In C1, click **Apps**. +In C1.ai, click **Apps**. Select an application and click **Entitlements**. @@ -473,11 +473,11 @@ Click **Save**. Repeat this process for other entitlements as needed. -**Done.** Now, when a user requests access to the entitlement, C1 will automatically create a Freshservice ticket. C1 will monitor the status of the Freshservice ticket, and it transitions to the “Done” status, the provisioning step will be marked complete in C1 as well. +**Done.** Now, when a user requests access to the entitlement, C1.ai will automatically create a Freshservice ticket. C1.ai will monitor the status of the Freshservice ticket, and it transitions to the “Done” status, the provisioning step will be marked complete in C1.ai as well. ## Configure Linear as an external ticketing provider -This process walks you through configuring an external ticketing integration with Linear. Once set up, C1 will automatically create Linear tickets to track provisioning assignments on the entitlements you choose. C1 will track the status of the Linear ticket, and will update the status of the access request in C1 accordingly. +This process walks you through configuring an external ticketing integration with Linear. Once set up, C1.ai will automatically create Linear tickets to track provisioning assignments on the entitlements you choose. C1.ai will track the status of the Linear ticket, and will update the status of the access request in C1.ai accordingly. ### Step 1: Set up the Linear connector @@ -498,7 +498,7 @@ If needed, you can set up multiple ticket provisioning integrations scoped to di -In C1, click **Platform** > **External ticketing**. +In C1.ai, click **Platform** > **External ticketing**. Click **Add ticket provisioner**. @@ -516,13 +516,13 @@ Find the **Settings** section of the page and click **Edit**. In the **Schema** field, select the catalog item that you want requests to be created for. -**Optional.** Add a ticket title and description. If added, the title and description will be added to all Linear tickets created by C1. +**Optional.** Add a ticket title and description. If added, the title and description will be added to all Linear tickets created by C1.ai. To customize your ticket titles and descriptions so they include specific information about the request, see [Customizing ticket templates](/product/admin/external-ticketing#customizing-ticket-templates). -**Optional.** Add a ticket label. This label will be added to Linear tickets created by C1. If this label does not already exist in Linear, it will be created. +**Optional.** Add a ticket label. This label will be added to Linear tickets created by C1.ai. If this label does not already exist in Linear, it will be created. @@ -551,11 +551,11 @@ Based on the schema you chose above, a list of custom fields is shown. Map these -Add provision state mappings. C1 will monitor the status of the Linear ticket and update the access request task in C1 accordingly. The list of states is based on the Linear team selected above. +Add provision state mappings. C1.ai will monitor the status of the Linear ticket and update the access request task in C1.ai accordingly. The list of states is based on the Linear team selected above. - - **Mark complete**: When a Linear ticket transitions to this status, C1 will mark the provisioning step on the task complete. + - **Mark complete**: When a Linear ticket transitions to this status, C1.ai will mark the provisioning step on the task complete. - - **Mark errored**: When a Linear ticket transitions to this status, C1 will mark the provisioning step as errored and fall back to manual provisioning. + - **Mark errored**: When a Linear ticket transitions to this status, C1.ai will mark the provisioning step as errored and fall back to manual provisioning. Click **Save**. @@ -566,7 +566,7 @@ Click **Save**. -In C1, click **Apps**. +In C1.ai, click **Apps**. Select an application and click **Entitlements**. @@ -591,11 +591,11 @@ Click **Save**. Repeat this process for other entitlements as needed. -**Done.** Now, when a user requests access to the entitlement, C1 will automatically create a Linear ticket. C1 will monitor the status of the Linear ticket, and it transitions to the “Done” status, the provisioning step will be marked complete in C1 as well. +**Done.** Now, when a user requests access to the entitlement, C1.ai will automatically create a Linear ticket. C1.ai will monitor the status of the Linear ticket, and it transitions to the “Done” status, the provisioning step will be marked complete in C1.ai as well. ## Configure HaloITSM as an external ticketing provider -This process walks you through configuring an external ticketing integration with HaloITSM. Once set up, C1 will automatically create HaloITSM tickets to track provisioning assignments on the entitlements you choose. C1 will track the status of the HaloITSM ticket, and will update the status of the access request in C1 accordingly. +This process walks you through configuring an external ticketing integration with HaloITSM. Once set up, C1.ai will automatically create HaloITSM tickets to track provisioning assignments on the entitlements you choose. C1.ai will track the status of the HaloITSM ticket, and will update the status of the access request in C1.ai accordingly. ### Step 1: Set up the HaloITSM connector @@ -612,7 +612,7 @@ During configuration, check the box to **Enable external ticket provisioning**. -In C1, click **Platform** > **External ticketing**. +In C1.ai, click **Platform** > **External ticketing**. Click **Add ticket provisioner**. @@ -630,7 +630,7 @@ Find the **Settings** section of the page and click **Edit**. In the **Schema** field, select the catalog item that you want requests to be created for. -**Optional.** Add a ticket title and description. If added, the title and description will be added to all HaloITSM tickets created by C1. +**Optional.** Add a ticket title and description. If added, the title and description will be added to all HaloITSM tickets created by C1.ai. To customize your ticket titles and descriptions so they include specific information about the request, see [Customizing ticket templates](/product/admin/external-ticketing#customizing-ticket-templates). @@ -642,11 +642,11 @@ Based on the schema you chose above, a list of custom fields is shown. Map these You can use the variables listed in the [Customizing ticket templates](/product/admin/external-ticketing#customizing-ticket-templates) section below to configure fields that pull a HaloITSM data source. -Add provision state mappings. C1 will monitor the status of the HaloITSM ticket and update the access request task in C1. +Add provision state mappings. C1.ai will monitor the status of the HaloITSM ticket and update the access request task in C1.ai. - - **Mark complete**: When a HaloITSM ticket transitions to this status, C1 will mark the provisioning step on the task complete. + - **Mark complete**: When a HaloITSM ticket transitions to this status, C1.ai will mark the provisioning step on the task complete. - - **Mark errored**: When a HaloITSM ticket transitions to this status, C1 will mark the provisioning step as errored and fall back to manual provisioning. + - **Mark errored**: When a HaloITSM ticket transitions to this status, C1.ai will mark the provisioning step as errored and fall back to manual provisioning. Click **Save**. @@ -658,7 +658,7 @@ Click **Save**. -In C1, click **Apps**. +In C1.ai, click **Apps**. Select an application and click **Entitlements**. @@ -682,12 +682,12 @@ Click **Save**. Repeat this process for other entitlements as needed. -**Done.** Now, when a user requests access to the entitlement, C1 will automatically create a HaloITSM ticket. C1 will monitor the status of the HaloITSM ticket, and it transitions to the “Done” status, the provisioning step will be marked complete in C1 as well. +**Done.** Now, when a user requests access to the entitlement, C1.ai will automatically create a HaloITSM ticket. C1.ai will monitor the status of the HaloITSM ticket, and it transitions to the “Done” status, the provisioning step will be marked complete in C1.ai as well. ## Customizing ticket templates {/* header name used in links, change with caution */} -You can pull data from C1 into your external ticketing system so that each ticket shows specific details about the access request, user, application, and entitlement. The variables listed below can be used when setting up the ticket template fields in C1 to generate a unique, customized title and description for each external ticket. +You can pull data from C1.ai into your external ticketing system so that each ticket shows specific details about the access request, user, application, and entitlement. The variables listed below can be used when setting up the ticket template fields in C1.ai to generate a unique, customized title and description for each external ticket. **Routing access review revocations to your ITSM?** Use `{{ .IsRevokeTicket }}` and `{{ .TicketType }}` to write templates that read correctly for both grants and revokes. See [Route campaign revocations to your ITSM](/product/how-to/automate-revocation-tickets) for the full setup. @@ -726,22 +726,22 @@ Fields - `{{ .TicketType }}` Returns the type of the ticket (possible values: Revoke, Grant). Subject -- `{{ .Subject.Id }}`: The unique ID of the C1 user. -- `{{ .Subject.DisplayName }}`: The display name of the C1 user. -- `{{ .Subject.Email }}`: The email address of the C1 user. -- `{{ .Subject.JobTitle }}`: The job title of the C1 user. -- `{{ .Subject.Department }}`: The department of the C1 user. -- `{{ .Subject.Attributes.< CUSTOM USER ATTRIBUTE > }}`: Any [custom user attribute](/product/admin/attributes) that you’ve set up in C1. +- `{{ .Subject.Id }}`: The unique ID of the C1.ai user. +- `{{ .Subject.DisplayName }}`: The display name of the C1.ai user. +- `{{ .Subject.Email }}`: The email address of the C1.ai user. +- `{{ .Subject.JobTitle }}`: The job title of the C1.ai user. +- `{{ .Subject.Department }}`: The department of the C1.ai user. +- `{{ .Subject.Attributes.< CUSTOM USER ATTRIBUTE > }}`: Any [custom user attribute](/product/admin/attributes) that you’ve set up in C1.ai. RequestedBy -The `RequestedBy` field represents the C1 user who **initiated** the access request, which is distinct from `Subject` (the user the request is **for**). For example, if a manager submits a request on behalf of a team member, `RequestedBy` is the manager and `Subject` is the team member. When a ticket is system-generated and no requester is available, these variables render as empty. +The `RequestedBy` field represents the C1.ai user who **initiated** the access request, which is distinct from `Subject` (the user the request is **for**). For example, if a manager submits a request on behalf of a team member, `RequestedBy` is the manager and `Subject` is the team member. When a ticket is system-generated and no requester is available, these variables render as empty. -- `{{ .RequestedBy.DisplayName }}`: The display name of the C1 user who initiated the request. -- `{{ .RequestedBy.Email }}`: The email address of the C1 user who initiated the request. -- `{{ .RequestedBy.JobTitle }}`: The job title of the C1 user who initiated the request. -- `{{ .RequestedBy.Department }}`: The department of the C1 user who initiated the request. -- `{{ .RequestedBy.Profile.< CUSTOM USER ATTRIBUTE > }}`: Any [custom user attribute](/product/admin/attributes) for the C1 user who initiated the request. Note that `RequestedBy` uses `.Profile` for custom attributes, not `.Attributes` as `Subject` does — using `.RequestedBy.Attributes.` will always render empty. +- `{{ .RequestedBy.DisplayName }}`: The display name of the C1.ai user who initiated the request. +- `{{ .RequestedBy.Email }}`: The email address of the C1.ai user who initiated the request. +- `{{ .RequestedBy.JobTitle }}`: The job title of the C1.ai user who initiated the request. +- `{{ .RequestedBy.Department }}`: The department of the C1.ai user who initiated the request. +- `{{ .RequestedBy.Profile.< CUSTOM USER ATTRIBUTE > }}`: Any [custom user attribute](/product/admin/attributes) for the C1.ai user who initiated the request. Note that `RequestedBy` uses `.Profile` for custom attributes, not `.Attributes` as `Subject` does — using `.RequestedBy.Attributes.` will always render empty. User - `{{ .User.Id }}`: The unique ID of the user. diff --git a/product/admin/findings.mdx b/product/admin/findings.mdx index f5cb2f7f..b7d3787e 100644 --- a/product/admin/findings.mdx +++ b/product/admin/findings.mdx @@ -10,13 +10,13 @@ description: "Detect and act on the things you care about in your organization's **Early access.** This feature is in early access, which means it's undergoing ongoing testing and development while we gather feedback, validate functionality, and improve outputs. -Stop hunting for risk by hand. Point C1 at the conditions you care about — unowned service accounts, exposed credentials, misclassified identities, and more. These are surfaced as findings when they occur. Rules let you triage, escalate, or resolve findings automatically. C1 checks for these conditions every time a connector syncs, and reports back the moment it detects a match. +Stop hunting for risk by hand. Point C1.ai at the conditions you care about — unowned service accounts, exposed credentials, misclassified identities, and more. These are surfaced as findings when they occur. Rules let you triage, escalate, or resolve findings automatically. C1.ai checks for these conditions every time a connector syncs, and reports back the moment it detects a match. Navigate to **Security** > **Findings** to get started. ## Turn on finding types -C1 comes with a catalog of built-in finding types, grouped by category. Most are opt-in — you choose which conditions matter to your organization — but a handful are on by default, so C1 starts surfacing them without any setup. +C1.ai comes with a catalog of built-in finding types, grouped by category. Most are opt-in — you choose which conditions matter to your organization — but a handful are on by default, so C1.ai starts surfacing them without any setup. The finding types on by default are the ones built on unambiguous evidence: a decoy was touched, a credential is confirmed public, a connector's anomaly detection is confirmed off, or a non-human identity has no owner. Finding types that instead rely on inference over synced data are off by default, so you can look at the results before turning them loose. @@ -29,17 +29,17 @@ You can turn any finding type on or off at any time from the settings menu — t From any tab in **Findings**, click the **settings** (gear) icon at the top right of the page. -In **Findings settings**, toggle on the finding types you want C1 to detect. Each type shows a short description of what it looks for. +In **Findings settings**, toggle on the finding types you want C1.ai to detect. Each type shows a short description of what it looks for. Click **Save changes**. -C1 starts creating findings of the types you turned on the next time each connector syncs. +C1.ai starts creating findings of the types you turned on the next time each connector syncs. -Turning off a finding type stops C1 from creating new findings of that type. Findings of that type that are already open stay open — nothing re-checks them, so they won't resolve automatically. +Turning off a finding type stops C1.ai from creating new findings of that type. Findings of that type that are already open stay open — nothing re-checks them, so they won't resolve automatically. ### Finding catalog reference @@ -65,7 +65,7 @@ The following finding types are available today. Types marked **On by default** Click a finding from the **Overview** or **All findings** tab to open its detail view, which includes: -- **Evidence** — why C1 flagged this finding, including any confidence score. +- **Evidence** — why C1.ai flagged this finding, including any confidence score. - **Activity** — an audit trail of everything that's happened to the finding, including when it was created, when routing rules evaluated against it, and any evidence updates. - **Assignee** — the person responsible for triaging the finding. Appears as its own column and filter on the findings list, and as a detail field on the finding itself. @@ -111,7 +111,7 @@ Go to **Findings** > **Routing rules** to create or manage them. Each rule has: For example, suppress low-severity noise automatically with a rule matching `finding.severity == FINDING_SEVERITY_LOW` and action Suppress. Escalate anything Critical with a rule matching `finding.severity == FINDING_SEVERITY_CRITICAL` that triggers an [automation](/product/admin/automations) to notify your team or open a ticket. -Unlike transformation rules, routing rules stop at the first match. C1 evaluates rules in ascending order by **Order** and applies only the first one that matches. +Unlike transformation rules, routing rules stop at the first match. C1.ai evaluates rules in ascending order by **Order** and applies only the first one that matches. ### Order rules effectively diff --git a/product/admin/functions-api.mdx b/product/admin/functions-api.mdx index 22662d81..79fc4eb5 100644 --- a/product/admin/functions-api.mdx +++ b/product/admin/functions-api.mdx @@ -1,18 +1,18 @@ --- title: "Manage functions via the API" og:title: "Manage functions via the API" -description: "Use the C1 REST API to create, edit, and publish functions programmatically without the web UI." -og:description: "Use the C1 REST API to create, edit, and publish functions programmatically without the web UI." +description: "Use the C1.ai REST API to create, edit, and publish functions programmatically without the web UI." +og:description: "Use the C1.ai REST API to create, edit, and publish functions programmatically without the web UI." sidebarTitle: "Manage via the API" --- -Manage functions programmatically through the C1 REST API to automate deployments or work outside the web UI. For the web UI workflow, see [Create and test functions](/product/admin/functions-create). +Manage functions programmatically through the C1.ai REST API to automate deployments or work outside the web UI. For the web UI workflow, see [Create and test functions](/product/admin/functions-create). These examples use `conductor.one`. If your organization is on the EU data residency instance, substitute `c1eu.ai` in URLs, client IDs, and hostnames. ## Authentication -All API calls require a bearer token from a personal API key or service principal credential. See [C1 API and keys](/conductorone-api/api) for setup. +All API calls require a bearer token from a personal API key or service principal credential. See [C1.ai API and keys](/conductorone-api/api) for setup. ```bash export C1_TENANT="https://your-tenant.conductor.one" @@ -252,7 +252,7 @@ curl -X POST "$C1_TENANT/api/v1/functions/$FUNCTION_ID/invoke" \ }' ``` -If you omit `commitId`, C1 uses the published commit. +If you omit `commitId`, C1.ai uses the published commit. ### Run tests @@ -263,4 +263,4 @@ curl -X POST "$C1_TENANT/api/v1/functions/$FUNCTION_ID/test" \ -d '{}' ``` -If you omit `commitId`, C1 uses the published commit. +If you omit `commitId`, C1.ai uses the published commit. diff --git a/product/admin/functions-automations.mdx b/product/admin/functions-automations.mdx index 84a0679a..11a00680 100644 --- a/product/admin/functions-automations.mdx +++ b/product/admin/functions-automations.mdx @@ -1,8 +1,8 @@ --- title: "Use functions in automations" og:title: "Use functions in automations" -description: "Add custom function steps to C1 automations to implement complex business logic, integrate with external systems, and make dynamic decisions in your workflows." -og:description: "Add custom function steps to C1 automations to implement complex business logic, integrate with external systems, and make dynamic decisions in your workflows." +description: "Add custom function steps to C1.ai automations to implement complex business logic, integrate with external systems, and make dynamic decisions in your workflows." +og:description: "Add custom function steps to C1.ai automations to implement complex business logic, integrate with external systems, and make dynamic decisions in your workflows." sidebarTitle: "Use functions in automations" --- diff --git a/product/admin/functions-create.mdx b/product/admin/functions-create.mdx index 385d1b91..e83db523 100644 --- a/product/admin/functions-create.mdx +++ b/product/admin/functions-create.mdx @@ -1,18 +1,18 @@ --- title: "Create and test functions" og:title: "Create and test functions" -description: "Learn how to create, write, test, and publish C1 functions using the built-in code editor." -og:description: "Learn how to create, write, test, and publish C1 functions using the built-in code editor." +description: "Learn how to create, write, test, and publish C1.ai functions using the built-in code editor." +og:description: "Learn how to create, write, test, and publish C1.ai functions using the built-in code editor." sidebarTitle: "Create and test functions" --- {/* Editor Refresh: 2026-04-30 */} -This guide walks you through creating your first function, from a simple "hello world" to accessing C1 data and calling external APIs. +This guide walks you through creating your first function, from a simple "hello world" to accessing C1.ai data and calling external APIs. ## Use C1AI to write function code -Not sure where to start with TypeScript or the C1 API? [C1AI](/product/admin/ai-assistant) can generate a working function from a plain-language description of what you want it to do — no TypeScript expertise required. Since functions start as drafts, you can try out the generated code, run it, and iterate safely before publishing. +Not sure where to start with TypeScript or the C1.ai API? [C1AI](/product/admin/ai-assistant) can generate a working function from a plain-language description of what you want it to do — no TypeScript expertise required. Since functions start as drafts, you can try out the generated code, run it, and iterate safely before publishing. To get started, click **Create with Functions assistant** when creating a new function, or click **Edit with Functions assistant** in the code editor of an existing function draft. Describe what you want your function to do, and C1AI will generate code to get you started. You can then edit the code as needed, run it with test inputs, and publish when you're ready. @@ -86,12 +86,12 @@ Output: } ``` -### Access C1 data +### Access C1.ai data -Use the pre-authenticated `sdk` object to query data from your C1 tenant. +Use the pre-authenticated `sdk` object to query data from your C1.ai tenant. -Functions authenticate to the C1 API as a service principal. Before publishing, link a service principal whose roles match what your function needs to do. See [Step 5: Link a service principal for API access](#step-5-link-a-service-principal-for-api-access) below. +Functions authenticate to the C1.ai API as a service principal. Before publishing, link a service principal whose roles match what your function needs to do. See [Step 5: Link a service principal for API access](#step-5-link-a-service-principal-for-api-access) below. ### List users @@ -315,7 +315,7 @@ For the full assertion API and more examples, see [Testing with @c1/test](/produ ## Step 5: Link a service principal for API access -Functions authenticate to the C1 API as a linked service principal. Its role bindings determine what your function can do — read-only, write, or anything in between. +Functions authenticate to the C1.ai API as a linked service principal. Its role bindings determine what your function can do — read-only, write, or anything in between. @@ -342,7 +342,7 @@ The function authenticates as that service principal on its next invocation. To Click **Save draft** to commit your changes. -Click **Publish** to make your function available for use across C1. +Click **Publish** to make your function available for use across C1.ai. diff --git a/product/admin/functions-reference.mdx b/product/admin/functions-reference.mdx index aa07a22e..97331b03 100644 --- a/product/admin/functions-reference.mdx +++ b/product/admin/functions-reference.mdx @@ -1,8 +1,8 @@ --- title: "Functions reference" og:title: "Functions reference" -description: "Technical reference for C1 functions, including SDK namespaces, runtime constraints, configuration options, and troubleshooting." -og:description: "Technical reference for C1 functions, including SDK namespaces, runtime constraints, configuration options, and troubleshooting." +description: "Technical reference for C1.ai functions, including SDK namespaces, runtime constraints, configuration options, and troubleshooting." +og:description: "Technical reference for C1.ai functions, including SDK namespaces, runtime constraints, configuration options, and troubleshooting." sidebarTitle: "Functions reference" --- @@ -10,7 +10,7 @@ sidebarTitle: "Functions reference" ## SDK namespaces -The pre-authenticated `sdk` object provides type-safe access to the C1 API through 60+ namespaces organized by resource type. +The pre-authenticated `sdk` object provides type-safe access to the C1.ai API through 60+ namespaces organized by resource type. | Category | Namespaces | |----------|------------| @@ -87,7 +87,7 @@ Packages are resolved at deploy time. No `package.json` or `node_modules` needed ## Configuration options -Configure secrets and network access in the C1 UI: +Configure secrets and network access in the C1.ai UI: @@ -155,7 +155,7 @@ export default async function main(input: JSONObject): Promise { ### API access -Functions authenticate to the C1 API as a linked [service principal](/product/admin/service-principals/overview). The service principal's role bindings determine what the function can do — every SDK call is authorized against those roles, and calls outside the granted permissions are denied. +Functions authenticate to the C1.ai API as a linked [service principal](/product/admin/service-principals/overview). The service principal's role bindings determine what the function can do — every SDK call is authorized against those roles, and calls outside the granted permissions are denied. To link or change a function's service principal, open the function and click **...** > **Link service principal**. To change what the function can do, edit the service principal's roles in **Identities** > **Service principals** — no function redeploy needed. @@ -221,7 +221,7 @@ Click **Test draft** when viewing a draft, or **Run tests** when viewing publish |------------|--------| | Runtime | Deno (V8-based). Native TS, ES modules, web standard APIs (`fetch`, `URL`, etc.) | | Filesystem | None. Functions are stateless. | -| Network | Egress allowlist only. C1 API subdomains pre-approved. | +| Network | Egress allowlist only. C1.ai API subdomains pre-approved. | | State | No persistence between invocations. Each call starts fresh. | | Auth | OAuth2 + DPoP auto-injected. Never handle tokens. | | Dependencies | `@c1/functions-sdk` auto-available. Other npm packages resolved at publish time. | diff --git a/product/admin/functions.mdx b/product/admin/functions.mdx index 69100877..6aa57498 100644 --- a/product/admin/functions.mdx +++ b/product/admin/functions.mdx @@ -1,21 +1,21 @@ --- title: "Extend with custom code" og:title: "Extend with custom code" -description: "Extend C1's identity governance capabilities with custom serverless TypeScript functions that integrate with external systems and implement organization-specific workflows." -og:description: "Extend C1's identity governance capabilities with custom serverless TypeScript functions that integrate with external systems and implement organization-specific workflows." +description: "Extend C1.ai's identity governance capabilities with custom serverless TypeScript functions that integrate with external systems and implement organization-specific workflows." +og:description: "Extend C1.ai's identity governance capabilities with custom serverless TypeScript functions that integrate with external systems and implement organization-specific workflows." sidebarTitle: "Extend with custom code" --- {/* Editor Refresh: 2026-04-30 */} -Functions are serverless TypeScript functions that extend C1's identity governance capabilities. Write custom automation logic, integrate with external systems, and implement organization-specific workflows that go beyond out-of-the-box features. +Functions are serverless TypeScript functions that extend C1.ai's identity governance capabilities. Write custom automation logic, integrate with external systems, and implement organization-specific workflows that go beyond out-of-the-box features. ## What you can do with functions - **Call external systems**: Integrate with approved external APIs using a network allowlist - **Run on events**: Trigger functions from automations using user lifecycle events, access changes, or schedules - **Implement custom business logic**: Write your organization's unique workflows in TypeScript -- **Access C1 data**: Query users, apps, and entitlements through type-safe APIs +- **Access C1.ai data**: Query users, apps, and entitlements through type-safe APIs ## Key features @@ -25,12 +25,12 @@ Functions provide a secure, managed environment for running custom code. - Modern TypeScript with async/await support - Import external npm packages dynamically using `npm:` prefix -- `@c1/functions-sdk` provides pre-authenticated access to C1 APIs +- `@c1/functions-sdk` provides pre-authenticated access to C1.ai APIs ### Security and isolation - Each function runs in isolation in a sandboxed environment -- Functions authenticate to the C1 API as a [service principal](/product/admin/service-principals/overview) — its role bindings determine what the function can do at runtime +- Functions authenticate to the C1.ai API as a [service principal](/product/admin/service-principals/overview) — its role bindings determine what the function can do at runtime - Network allowlist controls which external domains functions can access - Secrets management stores API keys securely, accessible via `functions.getConfig()` - Execution logs capture `console.log` statements and stream back to the UI @@ -50,7 +50,7 @@ Functions can run as steps in [automation workflows](/product/admin/functions-au ### Manual invocation -You can run functions on-demand from the C1 web UI: +You can run functions on-demand from the C1.ai web UI: @@ -69,7 +69,7 @@ Click **Run**. The function executes and returns output JSON. ### API invocation -You can also call functions programmatically via the C1 API for administrative tasks, batch processing, or integration with other systems. +You can also call functions programmatically via the C1.ai API for administrative tasks, batch processing, or integration with other systems. ## Key use cases for functions diff --git a/product/admin/global-settings.mdx b/product/admin/global-settings.mdx index 5a006092..0fb9ffd0 100644 --- a/product/admin/global-settings.mdx +++ b/product/admin/global-settings.mdx @@ -1,13 +1,13 @@ --- title: Global settings -og:title: Global settings - C1 docs -og:description: Configure global settings such as attribute values, the length of C1 sessions, and trusted IPs. -description: Configure global settings such as attribute values, the length of C1 sessions, and trusted IPs. +og:title: Global settings - C1.ai docs +og:description: Configure global settings such as attribute values, the length of C1.ai sessions, and trusted IPs. +description: Configure global settings such as attribute values, the length of C1.ai sessions, and trusted IPs. --- {/* Editor Refresh: 2026-01-14 */} -These tasks all require the **Super Administrator** role in C1. +These tasks all require the **Super Administrator** role in C1.ai. ## Set attribute values @@ -33,7 +33,7 @@ In either the **Compliance framework** or **Risk level** field, type the name of Repeat the process, adding additional attribute values as needed. Click the **x** next to any value to delete it from the list. - If you delete a value that is currently in use in C1, that value will not be removed from any entitlements it is assigned to. + If you delete a value that is currently in use in C1.ai, that value will not be removed from any entitlements it is assigned to. When you're finished, click **Save** and confirm your action. @@ -42,7 +42,7 @@ When you're finished, click **Save** and confirm your action. ### Step 2: Add attributes to an app's entitlements -You can set attributes on individual entitlements or in bulk. C1 does not apply a default risk level to entitlements automatically. Every entitlement's risk level is unset until you assign one using the steps below. +You can set attributes on individual entitlements or in bulk. C1.ai does not apply a default risk level to entitlements automatically. Every entitlement's risk level is unset until you assign one using the steps below. #### Set attributes in bulk @@ -82,7 +82,7 @@ Click **Save**. ## Set trusted domains -If needed, you can set a list of domains trusted by your organization. Any accounts associated with a domain not on the trusted domain list will be marked **External** in C1. +If needed, you can set a list of domains trusted by your organization. Any accounts associated with a domain not on the trusted domain list will be marked **External** in C1.ai. @@ -100,11 +100,11 @@ Add a trusted domain (such as `example.com`) and press **Enter**. Repeat this pr Click **Save**. -**Done.** Accounts associated with a domain not explicitly marked as trusted will be tagged **External** when the connectors complete their next sync or when you refresh account data uploaded to C1 in a spreadsheet or CSV file. +**Done.** Accounts associated with a domain not explicitly marked as trusted will be tagged **External** when the connectors complete their next sync or when you refresh account data uploaded to C1.ai in a spreadsheet or CSV file. ## Configure session length -By default, C1 sessions are set to **20 hours**. Customize your organization's session length to adhere to your internal security policies and best practices. +By default, C1.ai sessions are set to **20 hours**. Customize your organization's session length to adhere to your internal security policies and best practices. @@ -121,11 +121,11 @@ Click **Save**. -**Done.** Your session length has been updated. C1 will require all users in your organization to start new sessions every time the maximum length you selected elapses. +**Done.** Your session length has been updated. C1.ai will require all users in your organization to start new sessions every time the maximum length you selected elapses. ## Configure global IP allow lists -To enhance security and ensure that C1 is only accessed over trusted networks, configure the global IP allow list. You can fine-tune the allowed IP ranges by category to adhere to your organization's best practices for network and API key security. +To enhance security and ensure that C1.ai is only accessed over trusted networks, configure the global IP allow list. You can fine-tune the allowed IP ranges by category to adhere to your organization's best practices for network and API key security. @@ -148,10 +148,10 @@ Enable the toggles for each allow list you want to configure: For each category you've enabled, enter the allowed IP ranges (CIDRs). Up to 32 CIDRs are accepted. - As a safeguard against locking yourself out of the system, C1 displays a banner showing whether your current IP address is allowed or denied access. + As a safeguard against locking yourself out of the system, C1.ai displays a banner showing whether your current IP address is allowed or denied access. -**If you accidentally lock yourself out, contact the C1 support team.** +**If you accidentally lock yourself out, contact the C1.ai support team.** @@ -172,7 +172,7 @@ API keys that have a source IP allow list are evaluated first, followed by other ## Temporarily disable system features -The controls on the **System management** page allow you to temporarily disable automations and all notifications with a single click. Using these controls helps C1 admins to perform system maintenance, large-scale data changes, and crisis management without generating an overwhelming number of alerts or triggering unintended access changes. +The controls on the **System management** page allow you to temporarily disable automations and all notifications with a single click. Using these controls helps C1.ai admins to perform system maintenance, large-scale data changes, and crisis management without generating an overwhelming number of alerts or triggering unintended access changes. @@ -187,17 +187,17 @@ Click **Edit** and enable one or more of the available options: * **Disable automations**: Automation executions are not processed. Executions are created, but will terminate immediately. A log will be generated each time an automation attempts to execute. - * **Disable connector anomaly pauses**: Connector anomaly detection is disabled across all connectors. By default, C1 automatically pauses a connector sync when it detects an unusually large or unexpected change in the data, to prevent unintended bulk changes. Enable this setting to turn off that behavior tenant-wide. + * **Disable connector anomaly pauses**: Connector anomaly detection is disabled across all connectors. By default, C1.ai automatically pauses a connector sync when it detects an unusually large or unexpected change in the data, to prevent unintended bulk changes. Enable this setting to turn off that behavior tenant-wide. Click **Save**. -If any system management control is enabled, a banner is shown across C1 alerting other users that normal operations of that function have been temporarily suspended. +If any system management control is enabled, a banner is shown across C1.ai alerting other users that normal operations of that function have been temporarily suspended. -A screenshot showing C1 with a banner stating that access profile membership automations are disabled. +A screenshot showing C1.ai with a banner stating that access profile membership automations are disabled. diff --git a/product/admin/groups.mdx b/product/admin/groups.mdx index 1fcba28d..ce745d81 100644 --- a/product/admin/groups.mdx +++ b/product/admin/groups.mdx @@ -1,33 +1,33 @@ --- -title: C1 groups -og:title: Groups in the C1 app - C1 docs -og:description: Create custom groups in the C1 app that dynamically adjust their membership based on adherence to a membership rule. -description: Create custom groups in the C1 app that dynamically adjust their membership based on adherence to a membership rule. +title: C1.ai groups +og:title: Groups in the C1.ai app - C1.ai docs +og:description: Create custom groups in the C1.ai app that dynamically adjust their membership based on adherence to a membership rule. +description: Create custom groups in the C1.ai app that dynamically adjust their membership based on adherence to a membership rule. sidebarTitle: Create custom groups --- {/* Editor Refresh: 2026-01-07 */} -## What are C1 groups? +## What are C1.ai groups? -A screenshot of the C1 app showing a sample C1 group. +A screenshot of the C1.ai app showing a sample C1.ai group. -C1 groups are collections of C1 users that you create and use within C1. These groups are resources in [the C1 app](/product/admin/c1-for-c1). +C1.ai groups are collections of C1.ai users that you create and use within C1.ai. These groups are resources in [the C1.ai app](/product/admin/c1-for-c1). -## What can I do with a C1 group? +## What can I do with a C1.ai group? Key uses for these special groups include: -* **Organizing employees without creating custom IdP groups.** C1 groups make it easy to create groups of employees who share key profile attributes or combinations of access. +* **Organizing employees without creating custom IdP groups.** C1.ai groups make it easy to create groups of employees who share key profile attributes or combinations of access. -* **Specifying who is granted an access profile.** An access profile can be requestable by, or automatically assigned to, a C1 group. +* **Specifying who is granted an access profile.** An access profile can be requestable by, or automatically assigned to, a C1.ai group. -* **Assigning a group as reviewer on a policy step.** A C1 group can be set as a policy step reviewer. +* **Assigning a group as reviewer on a policy step.** A C1.ai group can be set as a policy step reviewer. ## What kind of groups should I make? When considering what groups to make, think about how you want to organize your employees for access management, access profile, and policy reviews. Groups provide a flexible way to do so without needing to manage complex groups in your identity provider. -Here are some ideas for groups you might create in C1: +Here are some ideas for groups you might create in C1.ai: * **Department or team-based groups:** For example, "Marketing Team", "Engineering Department", "Sales". This helps organize employees and manage access relevant to those teams. @@ -39,9 +39,9 @@ Here are some ideas for groups you might create in C1: * **Reviewer groups:** Groups specifically created to be used as reviewers in policies. For example, "Security Reviewers", "Legal Reviewers". -## Create a new C1 group +## Create a new C1.ai group -Create a C1 group by setting a rule for membership. C1 will dynamically add or remove members from the group based on their adherence to the rule. +Create a C1.ai group by setting a rule for membership. C1.ai will dynamically add or remove members from the group based on their adherence to the rule. @@ -82,14 +82,14 @@ Note that not all users who match the membership rule will be shown immediately When you're satisfied, click **Save**. The **Membership rule** section syncs and updates the list of matching users. -Depending on the number of users in your C1 installation, syncing might take some time. When syncing is complete, the **Syncing** label will be replaced by a **Last sync** timestamp. +Depending on the number of users in your C1.ai installation, syncing might take some time. When syncing is complete, the **Syncing** label will be replaced by a **Last sync** timestamp. -**Done.** Your C1 group is now ready for use elsewhere in the app. The group will re-sync every hour to check which C1 users match the rule you set, and will add or remove group members accordingly. +**Done.** Your C1.ai group is now ready for use elsewhere in the app. The group will re-sync every hour to check which C1.ai users match the rule you set, and will add or remove group members accordingly. -## Duplicate a C1 group +## Duplicate a C1.ai group Need a group that's similar to one that already exists? To save time, you can duplicate an existing group and then make adjustments as needed. @@ -110,7 +110,7 @@ If you need to manually add users to the access profile who do not match the mem The users you add will be shown in the list of members, with a notation that they were added manually, rather than by membership automation. -## Frequently asked questions about C1 groups +## Frequently asked questions about C1.ai groups @@ -118,22 +118,22 @@ The users you add will be shown in the list of members, with a notation that the A new sync is kicked off each hour. - + Yes. Add the group's entitlement to an app's [requestable entitlements](/product/admin/access-requests#set-the-standard-audience-for-an-app-and-select-requestable-entitlements) or to an [access profile](/product/admin/profiles) like any other entitlement, and users can request group membership with the same approvals, durations, and revocation as other requestable access. Members added through a request aren't removed by the group's membership automation rule — the same protection that already applies to users you add manually. - + -There is no dedicated groups endpoint in the C1 API. C1 groups are resources of the group resource type in the C1 app, so you fetch them with the app resource endpoints: +There is no dedicated groups endpoint in the C1.ai API. C1.ai groups are resources of the group resource type in the C1.ai app, so you fetch them with the app resource endpoints: -1. Find the group resource type for the C1 app: `GET /api/v1/apps/{app_id}/resource_types` +1. Find the group resource type for the C1.ai app: `GET /api/v1/apps/{app_id}/resource_types` 2. List the group resources of that type: `GET /api/v1/apps/{app_id}/resource_types/{app_resource_type_id}/resources` 3. To get a group's entitlements (such as its member entitlement), list the entitlements associated with that resource: `GET /api/v1/apps/{app_id}/entitlements/resource_types/{app_resource_type_id}/resources/{app_resource_id}` -In each request, `app_id` is the ID of the built-in C1 app. +In each request, `app_id` is the ID of the built-in C1.ai app. diff --git a/product/admin/integration-for-Slack.mdx b/product/admin/integration-for-Slack.mdx index 15f0ba76..7340e4ee 100644 --- a/product/admin/integration-for-Slack.mdx +++ b/product/admin/integration-for-Slack.mdx @@ -1,15 +1,15 @@ --- -title: Interact with C1 via Slack -og:title: Interact with C1 via Slack - C1 docs -og:description: Use the C1 app for Slack to request access, review access requests, and get notifications when there are tasks that need your attention in C1. -description: Use the C1 app for Slack to request access, review access requests, and get notifications when there are tasks that need your attention in C1. +title: Interact with C1.ai via Slack +og:title: Interact with C1.ai via Slack - C1.ai docs +og:description: Use the C1.ai app for Slack to request access, review access requests, and get notifications when there are tasks that need your attention in C1.ai. +description: Use the C1.ai app for Slack to request access, review access requests, and get notifications when there are tasks that need your attention in C1.ai. sidebarTitle: "Slack" --- {/* Editor Refresh: 2026-01-29 */} -## What can I do with the C1 app for Slack? +## What can I do with the C1.ai app for Slack? -Use the C1 app for Slack to interact directly with C1 without leaving Slack. Once the C1 app for Slack is installed for your workspace, you and your colleagues can: +Use the C1.ai app for Slack to interact directly with C1.ai without leaving Slack. Once the C1.ai app for Slack is installed for your workspace, you and your colleagues can: - Request access from anywhere in Slack using the `/c1 request` command: @@ -41,23 +41,23 @@ Use the C1 app for Slack to interact directly with C1 without leaving Slack. Onc -- Ask questions about your org's access data and take action using the C1 AI assistant +- Ask questions about your org's access data and take action using the C1.ai AI assistant -### Ask questions and take action with the C1 AI assistant +### Ask questions and take action with the C1.ai AI assistant -The C1 AI assistant is available to all C1 users and is enabled by default when the C1 app for Slack is installed. It works like a standard conversational AI — you ask it questions or tell it what you want to do, and it responds in the same language you write in. When a task calls for it, the assistant presents rich interactive responses directly in Slack — buttons, forms, and pickers — so you can complete actions without leaving the conversation. +The C1.ai AI assistant is available to all C1.ai users and is enabled by default when the C1.ai app for Slack is installed. It works like a standard conversational AI — you ask it questions or tell it what you want to do, and it responds in the same language you write in. When a task calls for it, the assistant presents rich interactive responses directly in Slack — buttons, forms, and pickers — so you can complete actions without leaving the conversation. -Open the C1 app in Slack to find a **Chat** tab where the assistant lives, a **History** tab to review past conversations, and a **New Chat** button. For quick access from anywhere in Slack, type `@C1` in any channel the app has been added to — the assistant replies in a thread, and each thread is its own conversation. Or add the C1 app as a participant in a direct message to start a private conversation. +Open the C1.ai app in Slack to find a **Chat** tab where the assistant lives, a **History** tab to review past conversations, and a **New Chat** button. For quick access from anywhere in Slack, type `@C1` in any channel the app has been added to — the assistant replies in a thread, and each thread is its own conversation. Or add the C1.ai app as a participant in a direct message to start a private conversation. -When you `@C1` in a channel, the assistant's response is visible to everyone in that channel. Use a direct message with the C1 app for conversations you want to keep private. To start a DM with the assistant, add C1 as a participant in a new or existing direct message — in a DM, every message you send is answered without needing to @-mention it. +When you `@C1` in a channel, the assistant's response is visible to everyone in that channel. Use a direct message with the C1.ai app for conversations you want to keep private. To start a DM with the assistant, add C1.ai as a participant in a new or existing direct message — in a DM, every message you send is answered without needing to @-mention it. -Ask it anything about your org's access data: who has access to what, how your organization is structured, what's in your entitlement catalog, and more. Because the assistant has access to the same C1 data your role permits you to see — including IdP-sourced information about your org — it can reason across that data to answer questions that might otherwise require navigating multiple views. +Ask it anything about your org's access data: who has access to what, how your organization is structured, what's in your entitlement catalog, and more. Because the assistant has access to the same C1.ai data your role permits you to see — including IdP-sourced information about your org — it can reason across that data to answer questions that might otherwise require navigating multiple views. You can also ask for data in a specific format — for example, "give me a CSV of everyone with admin access" — and the assistant generates a downloadable file (CSV, JSON, PDF, or plain text) with the link appearing directly in your Slack thread. @@ -68,48 +68,48 @@ The assistant can also take action on what it finds. On your explicit approval, - Configure campaigns and conflict monitors - Build automations and policies -The assistant always asks for your go-ahead before making any change. It can only see and act on what your C1 role permits — a user without policy management permissions, for example, won't be able to use the assistant to edit policies. The assistant maintains context within a conversation — whether a direct message or a reply thread — so you can start broad and follow up to narrow results. Starting a **New Chat** begins a fresh session. +The assistant always asks for your go-ahead before making any change. It can only see and act on what your C1.ai role permits — a user without policy management permissions, for example, won't be able to use the assistant to edit policies. The assistant maintains context within a conversation — whether a direct message or a reply thread — so you can start broad and follow up to narrow results. Starting a **New Chat** begins a fresh session. -Your Slack account must be linked to your C1 user account for the assistant to work. If it isn't linked yet, the assistant will let you know and direct you to your C1 administrator to get set up. +Your Slack account must be linked to your C1.ai user account for the assistant to work. If it isn't linked yet, the assistant will let you know and direct you to your C1.ai administrator to get set up. -## Install the C1 app for Slack for your organization +## Install the C1.ai app for Slack for your organization -Approve the C1 app for use in your organization's Slack workspace. +Approve the C1.ai app for use in your organization's Slack workspace. -In C1, navigate to **Settings** > **Notifications**. +In C1.ai, navigate to **Settings** > **Notifications**. In the **Slack** section of the page, click **Connect**. -Click **Add to Slack** and select a channel where the C1 app can post messages. +Click **Add to Slack** and select a channel where the C1.ai app can post messages. Click **Allow**. -**Done.** You'll be directed back to the C1 **Settings** page, where you'll see that your Slack workspace is now connected. +**Done.** You'll be directed back to the C1.ai **Settings** page, where you'll see that your Slack workspace is now connected. -## Add the C1 app for Slack to an individual workspace +## Add the C1.ai app for Slack to an individual workspace In Slack, navigate to the **Apps** section of the navigation bar. -Click **Add apps** and search for C1. +Click **Add apps** and search for C1.ai. -Click the C1 app and follow the prompts to add it to your Slack workspace. +Click the C1.ai app and follow the prompts to add it to your Slack workspace. -**Done.** You can now interact with C1 directly from Slack. +**Done.** You can now interact with C1.ai directly from Slack. ## Create a campaign Slack channel @@ -138,7 +138,7 @@ Click **Add to channel**. -**Need to send campaign messages to a private Slack channel?** Make sure to install the C1 app for Slack in the private channel first, then follow the steps above to add campaign notifications to that channel. +**Need to send campaign messages to a private Slack channel?** Make sure to install the C1.ai app for Slack in the private channel first, then follow the steps above to add campaign notifications to that channel. All campaign owners and users assigned access reviews will be automatically added to this channel. If a new user is assigned an access review during the campaign, they will also be automatically added to the channel. @@ -147,7 +147,7 @@ Click **Deactivate** to stop sending campaign updates to the channel. Click **Remove** to remove this channel entirely from the campaign. You can then add a new channel, if necessary. -When the campaign ends, the status in the channel will read **Completed** and no further notifications will be sent by C1. The channel will remain open until archived by your organization. +When the campaign ends, the status in the channel will read **Completed** and no further notifications will be sent by C1.ai. The channel will remain open until archived by your organization. diff --git a/product/admin/inventory.mdx b/product/admin/inventory.mdx index 64005a22..ae5062f5 100644 --- a/product/admin/inventory.mdx +++ b/product/admin/inventory.mdx @@ -1,6 +1,6 @@ --- title: Gain visibility into your access data -og:title: Gain visibility into your access data - C1 Docs +og:title: Gain visibility into your access data - C1.ai Docs og:description: The Inventory page provides a unified view of identities, resources, and sensitive secrets. description: The Inventory page provides a unified view of identities, resources, and sensitive secrets. sidebarTitle: View your inventory @@ -12,7 +12,7 @@ sidebarTitle: View your inventory ## View all resources, identities, and select secrets -The **Inventory** page gives you a single-pane-of-glass view of all the identities and resources synced to C1, as well as insight into key sensitive credentials generated in select integrations. Use the sort and filter tools on each tab to quickly zero in on the info you need. +The **Inventory** page gives you a single-pane-of-glass view of all the identities and resources synced to C1.ai, as well as insight into key sensitive credentials generated in select integrations. Use the sort and filter tools on each tab to quickly zero in on the info you need. A screenshot of the Inventory page, showing the Identities tab with the service accounts filter engaged. @@ -65,7 +65,7 @@ Click the checkbox to **Sync secrets**, then click **Save**. -**Done.** The next time the connector syncs, it will begin publishing information about secrets on the **Secrets** tab. You can wait for the connector's next scheduled sync, or navigate to the connector's page in C1 and click **Sync now**. +**Done.** The next time the connector syncs, it will begin publishing information about secrets on the **Secrets** tab. You can wait for the connector's next scheduled sync, or navigate to the connector's page in C1.ai and click **Sync now**. ### Configure Google Cloud Platform to sync secrets {/* header name used in links, change with caution */} @@ -74,11 +74,11 @@ If your Google Cloud Platform with Google Workspace connector is already set up, -In the C1 project in Google Cloud Platform, search for "API keys" and enable it. +In the C1.ai project in Google Cloud Platform, search for "API keys" and enable it. -Next, grant the API Keys Viewer Role to the service account you created for C1. Navigate to **IAM & Admin** > **IAM**. +Next, grant the API Keys Viewer Role to the service account you created for C1.ai. Navigate to **IAM & Admin** > **IAM**. On the IAM page, find your Service Account in the list on the Principals tab. @@ -94,7 +94,7 @@ Click **Save**. -**Done.** The next time the Google Cloud Platform connector syncs, it will begin publishing information about API tokens and service account keys on the **Secrets** tab. You can wait for the connector's next scheduled sync, or navigate to the connector's page in C1 and click **Sync now**. +**Done.** The next time the Google Cloud Platform connector syncs, it will begin publishing information about API tokens and service account keys on the **Secrets** tab. You can wait for the connector's next scheduled sync, or navigate to the connector's page in C1.ai and click **Sync now**. ## Track unused secrets diff --git a/product/admin/manage-campaigns.mdx b/product/admin/manage-campaigns.mdx index 94c7e676..82f88149 100644 --- a/product/admin/manage-campaigns.mdx +++ b/product/admin/manage-campaigns.mdx @@ -1,6 +1,6 @@ --- title: Administer an active campaign -og:title: Administer an active campaign - C1 docs +og:title: Administer an active campaign - C1.ai docs og:description: Campaign Owners have several tools at their disposal to help guide an access review campaign through the process of gathering reviews. description: Campaign Owners have several tools at their disposal to help guide an access review campaign through the process of gathering reviews. sidebarTitle: Manage active campaigns @@ -49,7 +49,7 @@ Click the **Generate CSV** icon above the log to generate a downloadable report ## Send notifications -C1 automates the process of notifying users about their open access reviews, reassignments, and impending deadlines. +C1.ai automates the process of notifying users about their open access reviews, reassignments, and impending deadlines. **Make sure that notification emails reach you:** @@ -115,7 +115,7 @@ Click the **...** (more actions) menu for the task and select **Revoke access**. -Depending on the revocation policy set on the entitlement, the task might require review and approval before the access is removed by either an automatic or manual process. C1 will create and assign the tasks as appropriate. +Depending on the revocation policy set on the entitlement, the task might require review and approval before the access is removed by either an automatic or manual process. C1.ai will create and assign the tasks as appropriate. A campaign-driven revocation is deprovisioned the same way as any other revocation: using whichever [deprovisioning method](/product/admin/access-requests#set-how-app-accounts-are-deprovisioned) is set on the entitlement. If that method is **External ticketing**, the revocation automatically opens a ticket in your connected ITSM. See [Route campaign revocations to your ITSM](/product/how-to/automate-revocation-tickets) for the full setup, including revoke-specific ticket template variables. diff --git a/product/admin/managing-accounts.mdx b/product/admin/managing-accounts.mdx index 59e025d6..2092afd6 100644 --- a/product/admin/managing-accounts.mdx +++ b/product/admin/managing-accounts.mdx @@ -1,6 +1,6 @@ --- title: Manage application accounts -og:title: Manage application accounts - C1 docs +og:title: Manage application accounts - C1.ai docs og:description: The accounts in an application are shown on the application's Accounts tab, where you can set service accounts, map users to accounts, and view each account's details. description: The accounts in an application are shown on the Accounts tab, where you can set service accounts, map users to accounts, and view each account's details. sidebarTitle: Manage accounts @@ -12,16 +12,16 @@ sidebarTitle: Manage accounts An application's **Accounts** tab shows you a list of all the accounts inside the application, the status of each account, its type (user, service, or system), the account owner, and the roles the account has in the app. -![A screenshot of a Slack application's Accounts tab in C1.](/images/product/assets/apps-accounts-1.png) +![A screenshot of a Slack application's Accounts tab in C1.ai.](/images/product/assets/apps-accounts-1.png) ## Account owners -When app accounts are ingested, C1 automatically attempts to match them to C1 users (the humans in your organization). These mappings are shown in the **Account owner** column. +When app accounts are ingested, C1.ai automatically attempts to match them to C1.ai users (the humans in your organization). These mappings are shown in the **Account owner** column. ### Auto-match accounts with users -By default, C1 uses email accounts and usernames to match accounts to users. This is called **Narrow** mapping. If users and accounts aren't matching automatically when using narrow mappings, you can switch to **Broad** mapping (which also attempts to match first and last names) or **Custom** mapping (which lets you define your own ordered match rules). +By default, C1.ai uses email accounts and usernames to match accounts to users. This is called **Narrow** mapping. If users and accounts aren't matching automatically when using narrow mappings, you can switch to **Broad** mapping (which also attempts to match first and last names) or **Custom** mapping (which lets you define your own ordered match rules). To change the mapping level: @@ -37,14 +37,14 @@ Select the type of mapping you want to use: * **Narrow**: (Default) Accounts are mapped using email addresses and usernames. * **Broad**: Accounts are first mapped using email addresses and usernames, but if these cannot be found or matched, accounts are then mapped using the user's first and last name. - * **Custom**: Accounts are mapped using an ordered list of rules that you define. Each rule defines a pair of key expressions to extract matching keys from application accounts and C1 users. Rules are evaluated in order, and C1 uses the first rule that produces a match. The default rules match the narrow mapping behavior, which you can then add to, reorder, or replace. + * **Custom**: Accounts are mapped using an ordered list of rules that you define. Each rule defines a pair of key expressions to extract matching keys from application accounts and C1.ai users. Rules are evaluated in order, and C1.ai uses the first rule that produces a match. The default rules match the narrow mapping behavior, which you can then add to, reorder, or replace. Click **Save**. -C1 will immediately begin remapping the app's accounts. +C1.ai will immediately begin remapping the app's accounts. ### Manually set account owners @@ -61,7 +61,7 @@ Find the account that needs an account owner change and click the **...** (more Select **Set account owner**. -Choose the correct C1 user from the dropdown and click **Set account owner**. +Choose the correct C1.ai user from the dropdown and click **Set account owner**. @@ -80,7 +80,7 @@ Use the checkboxes to select the accounts that need an account owner change. From the bulk actions menu at the bottom of the screen, select **Set account owner**. -Choose the correct C1 user from the dropdown and click **Set account owner**. +Choose the correct C1.ai user from the dropdown and click **Set account owner**. @@ -95,7 +95,7 @@ Choose the correct C1 user from the dropdown and click **Set account owner**. Accounts are set to **User** by default. Use the **Account type** control to designate service accounts and system accounts, which can then be included in or excluded from your access review campaigns as needed. -The account type you set here is the source of the `account.app_user_type` value (`AppUserType.USER`, `AppUserType.SERVICE_ACCOUNT`, or `AppUserType.SYSTEM_ACCOUNT`) used in [CEL expressions](/product/admin/expressions-reference#appusertype). C1 does not infer account type from the source app — you (or an automation) must tag the account in C1 for those expressions to match. The related `subject.type` value on a C1 user (such as `UserType.HUMAN`, `UserType.SERVICE`, or `UserType.SYSTEM`) is derived from the account types of the accounts linked to the user. +The account type you set here is the source of the `account.app_user_type` value (`AppUserType.USER`, `AppUserType.SERVICE_ACCOUNT`, or `AppUserType.SYSTEM_ACCOUNT`) used in [CEL expressions](/product/admin/expressions-reference#appusertype). C1.ai does not infer account type from the source app — you (or an automation) must tag the account in C1.ai for those expressions to match. The related `subject.type` value on a C1.ai user (such as `UserType.HUMAN`, `UserType.SERVICE`, or `UserType.SYSTEM`) is derived from the account types of the accounts linked to the user. To set an account type: @@ -123,7 +123,7 @@ Use **Configure columns** in the **Accounts** table header to adjust which colum To export accounts data to CSV, click **Generate CSV** above the **Accounts** table. The **Download as CSV** drawer opens where you can choose which columns to include before generating the file. -![A screenshot of a Slack application's Accounts tab in C1.](/images/product/assets/apps-accounts-3.png) +![A screenshot of a Slack application's Accounts tab in C1.ai.](/images/product/assets/apps-accounts-3.png) If you use the search and filter tools to narrow what's shown, the export reflects only the filtered list of accounts. @@ -141,13 +141,13 @@ Click any account name on the **Accounts** tab to view that account's details pa * **Past grants**: The entitlements in this application that this account formerly had access to -![A screenshot of a Slack application account's details page in C1.](/images/product/assets/apps-accounts-2.png) +![A screenshot of a Slack application account's details page in C1.ai.](/images/product/assets/apps-accounts-2.png) ## Manually revoke an account's access to an entitlement -A user with the **Super Administrator** role in C1, the application owner, the entitlement owner, or the direct manager of the account owner can perform this task. Anyone who does not have the **Super Administrator** role or one of these relationships with the account will see an error if they attempt to revoke access this way. +A user with the **Super Administrator** role in C1.ai, the application owner, the entitlement owner, or the direct manager of the account owner can perform this task. Anyone who does not have the **Super Administrator** role or one of these relationships with the account will see an error if they attempt to revoke access this way. diff --git a/product/admin/managing-entitlements.mdx b/product/admin/managing-entitlements.mdx index 2152fd77..259c32af 100644 --- a/product/admin/managing-entitlements.mdx +++ b/product/admin/managing-entitlements.mdx @@ -1,7 +1,7 @@ --- title: Managing entitlements -og:title: Manage application entitlements - C1 docs -og:description: Manage entitlements on resources in C1 +og:title: Manage application entitlements - C1.ai docs +og:description: Manage entitlements on resources in C1.ai description: Entitlements are access rights, permissions, or privileges on resources. --- {/* Editor Refresh: 2026-05-21 */} @@ -16,25 +16,25 @@ For example, entitlements can include: - **Read** access to a data table - **Assignment** of a role -Entitlements allow C1 to provide fine-grained visibility into access rights and privileges for users and accounts. +Entitlements allow C1.ai to provide fine-grained visibility into access rights and privileges for users and accounts. -When application data is ingested into C1 via connector, file, or other data feed, C1 identifies and creates [resources](/product/admin/managing-resources) and entitlements for those resources in the application. These resources are the basis of permission management. +When application data is ingested into C1.ai via connector, file, or other data feed, C1.ai identifies and creates [resources](/product/admin/managing-resources) and entitlements for those resources in the application. These resources are the basis of permission management. To navigate to the entitlements in an application, go to the application's page and click the **Entitlements** tab. ### A special entitlement: Access -Every managed application in C1 comes with a built-in resource and entitlement: the **Credential** resource and the **Access** entitlement. The Access entitlement references all [accounts](/product/admin/managing-accounts) in the application, which lets C1 treat account membership like any other entitlement. +Every managed application in C1.ai comes with a built-in resource and entitlement: the **Credential** resource and the **Access** entitlement. The Access entitlement references all [accounts](/product/admin/managing-accounts) in the application, which lets C1.ai treat account membership like any other entitlement. For example: -- If you want to make new accounts requestable in C1, set the corresponding access controls on the **Access** entitlement. +- If you want to make new accounts requestable in C1.ai, set the corresponding access controls on the **Access** entitlement. - If you want to run an access review on anyone who has any account in an application, select the **Credential** for the application. Because of its special nature, the Access entitlement cannot be renamed or deleted. However, you can set its attributes and manage its grants just like any other entitlement. ## Creating entitlements -Entitlements are created automatically when connector or file data is ingested into C1. Connectors identify resources inside the application — roles, groups, and similar objects — and sync them along with their corresponding entitlements to C1. +Entitlements are created automatically when connector or file data is ingested into C1.ai. Connectors identify resources inside the application — roles, groups, and similar objects — and sync them along with their corresponding entitlements to C1.ai. If you need to manually create an entitlement for a resource, you can create a virtual entitlement: @@ -52,12 +52,12 @@ Click **Create**. ### Requesting access to entitlements created ahead of sync -If you provision groups, roles, or other entitlements using infrastructure as code — for example, Terraform with a `match_baton_id` — the entitlement can exist in your source of truth before C1's next connector sync merges it in. If a user requests access to one of these entitlements before that merge completes, the task now waits instead of failing. +If you provision groups, roles, or other entitlements using infrastructure as code — for example, Terraform with a `match_baton_id` — the entitlement can exist in your source of truth before C1.ai's next connector sync merges it in. If a user requests access to one of these entitlements before that merge completes, the task now waits instead of failing. The task's status shows **Waiting**, and its details include a callout explaining that it's waiting on the connector sync. Once the entitlement merges, the task resumes automatically and provisioning continues. If the merge doesn't complete within 24 hours, the task falls back to manual provisioning. -This behavior isn't on by default. Contact the [C1 Support team](mailto:support@c1.ai) to enable it for your tenant. +This behavior isn't on by default. Contact the [C1.ai Support team](mailto:support@c1.ai) to enable it for your tenant. ## Customize columns and export to CSV @@ -73,7 +73,7 @@ To manage an entitlement, navigate to the application, click the **Entitlements* ### Rename the entitlement {/* header name used in links, change with caution */} -In C1, entitlements are displayed next to their resource as a short label called a _slug_. The slug describes the access right or permission the entitlement grants. +In C1.ai, entitlements are displayed next to their resource as a short label called a _slug_. The slug describes the access right or permission the entitlement grants. Entitlement slugs are set automatically by connectors, but you can edit most of them. The exception is the credential resource, which has a single **Access** entitlement that cannot be renamed. @@ -111,7 +111,7 @@ Entitlement owners can be the target of policy approval steps — for example, y You can assign entitlement owners in two ways: -- **By user**: Add specific C1 users as direct owners. +- **By user**: Add specific C1.ai users as direct owners. - **By entitlement**: Add any entitlement from a connected app. All users currently assigned that entitlement automatically become owners, and ownership updates as users are granted or removed from the entitlement. You can add up to 32 direct user owners and up to 32 entitlements as owners on each entitlement. @@ -162,7 +162,7 @@ When you're finished, click **Save** and confirm your action. -If you remove an attribute that is currently in use in C1, that attribute will not be removed from any entitlements it is assigned to. +If you remove an attribute that is currently in use in C1.ai, that attribute will not be removed from any entitlements it is assigned to. To apply an attribute to an entitlement: @@ -185,7 +185,7 @@ You can now filter entitlements by attribute when creating an access review camp ### Set an entitlement alias -Aliases are shortcuts you can add to entitlements. They let you reference an entitlement by a short, memorable name — for example, when using the [C1 CLI tool](/product/cli/commands) to request access. +Aliases are shortcuts you can add to entitlements. They let you reference an entitlement by a short, memorable name — for example, when using the [C1.ai CLI tool](/product/cli/commands) to request access. For example, in the command `cone get aws-prod`, `aws-prod` is the alias mapped to a production AWS role. @@ -215,7 +215,7 @@ You can also change, extend, or even remove a grant's expiration date on this pa Entitlement visibility is inherited from the resource the entitlement belongs to. When a resource's visibility is restricted, all entitlements on that resource are also restricted in the same way. -For example, if a resource's visibility is set to **Members**, only users who have been granted an entitlement on that resource (along with the resource's owners, entitlement owners, the app's owners, and Super Admins) can see the resource and any of its entitlements. Users who don't meet the visibility criteria will not see the entitlements in search results or other areas of the C1 interface. +For example, if a resource's visibility is set to **Members**, only users who have been granted an entitlement on that resource (along with the resource's owners, entitlement owners, the app's owners, and Super Admins) can see the resource and any of its entitlements. Users who don't meet the visibility criteria will not see the entitlements in search results or other areas of the C1.ai interface. To change the visibility of an entitlement, update the [visibility setting on its parent resource](/product/admin/managing-resources#resource-visibility-controls). diff --git a/product/admin/managing-resources.mdx b/product/admin/managing-resources.mdx index 81978aa4..f13b240a 100644 --- a/product/admin/managing-resources.mdx +++ b/product/admin/managing-resources.mdx @@ -1,6 +1,6 @@ --- title: Manage resources -og:title: Manage resources - C1 docs +og:title: Manage resources - C1.ai docs og:description: Resources are objects within an application. description: Resources are objects within an application. --- @@ -8,7 +8,7 @@ description: Resources are objects within an application. ## What are resources? -In C1, a resource represents any object within an application. Think of resources as the specific items you want to manage access for. +In C1.ai, a resource represents any object within an application. Think of resources as the specific items you want to manage access for. Common examples of resources include: @@ -19,21 +19,21 @@ Common examples of resources include: * Licenses * S3 buckets -Resources are always specific to a particular application. C1's flexible data model allows you to easily model and manage these resources, along with the entitlements (the specific access rights) associated with each resource. +Resources are always specific to a particular application. C1.ai's flexible data model allows you to easily model and manage these resources, along with the entitlements (the specific access rights) associated with each resource. -C1 automatically identifies and creates resources when application data is ingested through connectors or file uploads. These resources form the foundation for all permission management activities within C1. +C1.ai automatically identifies and creates resources when application data is ingested through connectors or file uploads. These resources form the foundation for all permission management activities within C1.ai. You can view all an application's resources on the **Resources** tab. To view just the groups for an application, use the **Groups** tab on the application's page. ## What is the Credential resource? -Every application managed within C1 includes a unique default resource known as the **Credential** resource. This resource always contains exactly one entitlement, called **Access**. +Every application managed within C1.ai includes a unique default resource known as the **Credential** resource. This resource always contains exactly one entitlement, called **Access**. The **Credential** resource represents the fundamental ability to have an account within that specific application. The **Access** entitlement is used to reference and manage accounts associated with the application. -This design allows C1 to uniformly manage both accounts and general application access as if they were standard resources and entitlements. +This design allows C1.ai to uniformly manage both accounts and general application access as if they were standard resources and entitlements. Example use cases: @@ -43,9 +43,9 @@ Example use cases: ## Creating resources -Most resources in C1 are created automatically when application data is ingested. Our connectors are designed to identify and synchronize essential resources (such as roles, groups, and permissions) from your connected applications directly into C1. This automated process ensures that your resource inventory is always up to date. +Most resources in C1.ai are created automatically when application data is ingested. Our connectors are designed to identify and synchronize essential resources (such as roles, groups, and permissions) from your connected applications directly into C1.ai. This automated process ensures that your resource inventory is always up to date. -In specific scenarios where a resource cannot be automatically ingested (such as for custom or non-standard objects), resources can be created manually. You can do this via the C1 API or by [creating a virtual entitlement](/product/admin/managing-entitlements#creating-entitlements). +In specific scenarios where a resource cannot be automatically ingested (such as for custom or non-standard objects), resources can be created manually. You can do this via the C1.ai API or by [creating a virtual entitlement](/product/admin/managing-entitlements#creating-entitlements). ## Customize columns and export to CSV @@ -55,7 +55,7 @@ To export resources data to CSV, click **Generate CSV** above the **Resources** ## Managing resources -Once resources are in C1, you can manage their associated metadata, even if they were automatically ingested by a connector. +Once resources are in C1.ai, you can manage their associated metadata, even if they were automatically ingested by a connector. To manage a resource, navigate to the resource's details page: @@ -71,7 +71,7 @@ From the resource detail page, you can rename the resource, update its owners, a ### Rename the resource -If you change the name of the resource, C1 will remember and persist this change through future connector syncs, but the new name will not be written back to the connected application. +If you change the name of the resource, C1.ai will remember and persist this change through future connector syncs, but the new name will not be written back to the connected application. To change the resource name: @@ -146,7 +146,7 @@ This tab displays a comprehensive list of all accounts that have been assigned e ## Resource visibility controls -Resource visibility controls let you determine which C1 users can see a resource and its entitlements in the admin interface — for example, on the **Apps > Resources** page and in search results. By default, resources are visible to all C1 users in your organization. +Resource visibility controls let you determine which C1.ai users can see a resource and its entitlements in the admin interface — for example, on the **Apps > Resources** page and in search results. By default, resources are visible to all C1.ai users in your organization. A common use case is hiding sensitive resources from lower-privileged admin users. For example, you might restrict visibility on resources related to production infrastructure, privileged roles, or restricted data so that only designated owners or Super Admins are aware they exist. @@ -190,7 +190,7 @@ Click **Save** to apply your changes. -When you restrict a resource's visibility, users who are not permitted to view the resource will not see it or its entitlements in search results, directory listings, or other areas of the C1 interface. +When you restrict a resource's visibility, users who are not permitted to view the resource will not see it or its entitlements in search results, directory listings, or other areas of the C1.ai interface. @@ -199,12 +199,12 @@ When you restrict a resource's visibility, users who are not permitted to view t ## Delete a resource -You can delete manually created resources from C1. +You can delete manually created resources from C1.ai. **Important:** -Resources that have been synchronized from a connector cannot be deleted directly within C1. These resources represent the authoritative "truth" as defined in your connected software tool. To remove such a resource from C1, you must first delete it within the source tool itself, and the resource will be removed from C1 on the next data sync. +Resources that have been synchronized from a connector cannot be deleted directly within C1.ai. These resources represent the authoritative "truth" as defined in your connected software tool. To remove such a resource from C1.ai, you must first delete it within the source tool itself, and the resource will be removed from C1.ai on the next data sync. To delete a manually created resources: diff --git a/product/admin/mcp-resources.mdx b/product/admin/mcp-resources.mdx index c4d6cf46..030194b5 100644 --- a/product/admin/mcp-resources.mdx +++ b/product/admin/mcp-resources.mdx @@ -1,17 +1,17 @@ --- title: Govern MCP resources -description: Review MCP resources and URI templates discovered by C1, approve them, and inspect the access state that controls who can read them. -og:title: Govern MCP resources - C1 docs -og:description: Review MCP resources and URI templates discovered by C1, approve them, and inspect the access state that controls who can read them. +description: Review MCP resources and URI templates discovered by C1.ai, approve them, and inspect the access state that controls who can read them. +og:title: Govern MCP resources - C1.ai docs +og:description: Review MCP resources and URI templates discovered by C1.ai, approve them, and inspect the access state that controls who can read them. --- {/* Editor Refresh: 2026-08-25 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -An MCP server can expose more than tools. It can also expose static resources, such as a named document, and URI templates, which resolve a resource from a URI supplied by the client. C1 discovers these items when it discovers the MCP server and governs them independently from tools. +An MCP server can expose more than tools. It can also expose static resources, such as a named document, and URI templates, which resolve a resource from a URI supplied by the client. C1.ai discovers these items when it discovers the MCP server and governs them independently from tools. This page describes how to review and manage discovered MCP resources. For tool governance, see [Govern tools and toolsets](/product/admin/tools-and-toolsets). @@ -24,13 +24,13 @@ Each approved MCP resource has its own read entitlement. A user can read a resou - The user has a grant for that entitlement. - The MCP server and tenant controls allow the request. -A tool grant does not grant access to a resource. Resources are not added to toolsets or exposed as catalog items. C1 does not provide an end-user resource request flow. +A tool grant does not grant access to a resource. Resources are not added to toolsets or exposed as catalog items. C1.ai does not provide an end-user resource request flow. -Resource content is returned only when the AI client explicitly reads the resource. C1 does not automatically add resource content to a tool call or an AI prompt. Resource access is the same whether the client uses Code Mode or direct tools. +Resource content is returned only when the AI client explicitly reads the resource. C1.ai does not automatically add resource content to a tool call or an AI prompt. Resource access is the same whether the client uses Code Mode or direct tools. ## View discovered resources -To see the resources C1 discovered from a server, open the server's resource inventory. +To see the resources C1.ai discovered from a server, open the server's resource inventory. @@ -44,7 +44,7 @@ Click the **Resources** tab. -The table lists static resources and URI templates that C1 discovered from the server. It includes each item's name, kind, URI or template, MIME type, state, access status, and last-discovered time. +The table lists static resources and URI templates that C1.ai discovered from the server. It includes each item's name, kind, URI or template, MIME type, state, access status, and last-discovered time. Use the search field to find a name, description, URI, or template. Filter by kind or state when you need to focus on a subset of the inventory. Open a resource to view its complete URI or template, metadata, linked entitlement, grant count, and discovery history. @@ -70,7 +70,7 @@ Click **Approve** or **Disable**. -Only the lifecycle state is editable. C1 preserves the URI or URI template exactly as the MCP server advertised it. Changes to discovered metadata retain the resource's state. A changed URI or template is a new pending resource; the old resource is marked Removed. +Only the lifecycle state is editable. C1.ai preserves the URI or URI template exactly as the MCP server advertised it. Changes to discovered metadata retain the resource's state. A changed URI or template is a new pending resource; the old resource is marked Removed. ## Inspect resource access @@ -80,7 +80,7 @@ The **Access** column identifies resources that are not ready for users: | Access status | What it means | | :--- | :--- | -| **Entitlement missing** | C1 cannot use the resource until its linked entitlement is available. | +| **Entitlement missing** | C1.ai cannot use the resource until its linked entitlement is available. | | **Entitlement inactive** | The resource's linked entitlement is not active. | | **No grants** | The resource is approved, but no users can read it. | | **Grant count** | The number of grants for the resource's linked entitlement. | @@ -89,10 +89,10 @@ Revoking a grant takes effect on the next resource read, including for an existi ## Track discovery changes -C1 repeats discovery on a schedule. Open **View history** from a resource's **...** (more actions) menu, or click the resource's name to open its details panel and select **View history** there. The history shows changes to the resource's metadata, lifecycle state, URI or template, entitlement, and discovery times. +C1.ai repeats discovery on a schedule. Open **View history** from a resource's **...** (more actions) menu, or click the resource's name to open its details panel and select **View history** there. The history shows changes to the resource's metadata, lifecycle state, URI or template, entitlement, and discovery times. -If an upstream server stops advertising a resource, C1 marks it **Removed**. If the server later advertises the same resource identity again, review its current state before it becomes available to users. +If an upstream server stops advertising a resource, C1.ai marks it **Removed**. If the server later advertises the same resource identity again, review its current state before it becomes available to users. ## Audit resource reads -C1 logs each allowed and denied resource read. The audit record identifies the caller, MCP server, resource, result, reason for a denial when applicable, latency, and response size. It does not store resource content. For audit-log details and export options, see [Audit AI tool usage](/product/admin/audit-ai-tool-usage). +C1.ai logs each allowed and denied resource read. The audit record identifies the caller, MCP server, resource, result, reason for a denial when applicable, latency, and response size. It does not store resource content. For audit-log details and export options, see [Audit AI tool usage](/product/admin/audit-ai-tool-usage). diff --git a/product/admin/mcp-server/apollo.mdx b/product/admin/mcp-server/apollo.mdx index 89a0b42e..074dd9cd 100644 --- a/product/admin/mcp-server/apollo.mdx +++ b/product/admin/mcp-server/apollo.mdx @@ -1,26 +1,26 @@ --- title: Set up the Apollo MCP server -description: Create an Apollo API key and register the Apollo MCP server in C1 so AI clients can call governed Apollo tools. +description: Create an Apollo API key and register the Apollo MCP server in C1.ai so AI clients can call governed Apollo tools. og:title: Set up the Apollo MCP server -og:description: Create an Apollo API key and register the Apollo MCP server in C1 so AI clients can call governed Apollo tools. +og:description: Create an Apollo API key and register the Apollo MCP server in C1.ai so AI clients can call governed Apollo tools. sidebarTitle: Apollo --- {/* Editor Refresh: 2026-06-11 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -The Apollo MCP server lets you govern access to Apollo — contacts, accounts, and other sales data — as tools your AI clients can call through C1. +The Apollo MCP server lets you govern access to Apollo — contacts, accounts, and other sales data — as tools your AI clients can call through C1.ai. -Apollo authenticates with an API key sent in a request header. A single key authenticates everyone, so all tool calls reach Apollo as one shared identity. Create the key from a dedicated service-account user so activity is attributable to C1 rather than a person. +Apollo authenticates with an API key sent in a request header. A single key authenticates everyone, so all tool calls reach Apollo as one shared identity. Create the key from a dedicated service-account user so activity is attributable to C1.ai rather than a person. -## How C1 connects to Apollo +## How C1.ai connects to Apollo -C1 hosts the Apollo MCP server, so your users' AI clients only ever see MCP tools — they never call Apollo directly. When an AI client calls one of these tools, C1 makes the matching request to the Apollo API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Apollo MCP server, so your users' AI clients only ever see MCP tools — they never call Apollo directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Apollo API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call Apollo on your users' behalf. +The credentials you set up below are what C1.ai uses to call Apollo on your users' behalf. ## Before you begin @@ -28,12 +28,12 @@ The credentials you set up below are what C1 uses to call Apollo on your users' - An Apollo account with permission to create API keys, which typically requires an admin role. -If you don't see **Apollo** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **Apollo** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Create an Apollo API key -Create an API key in Apollo so C1 can authenticate to the Apollo API. +Create an API key in Apollo so C1.ai can authenticate to the Apollo API. @@ -49,11 +49,11 @@ Limit the key to only the endpoints you need, then copy the key. Treat the key l ## How Apollo credentials are shared -Every user's tool calls use the one API key you provided, so Apollo sees a single shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared production setup, create the key from a dedicated service-account user so activity is attributable to C1 rather than a person. +Every user's tool calls use the one API key you provided, so Apollo sees a single shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared production setup, create the key from a dedicated service-account user so activity is attributable to C1.ai rather than a person. For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## Register the Apollo MCP server in C1 +## Register the Apollo MCP server in C1.ai With your API key ready, register the server and provide your credentials. @@ -65,13 +65,13 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Custom header**, enter the header name `X-Api-Key`, and paste your API key as the value. -Save your changes. C1 starts a sync that discovers the tools the Apollo server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Apollo server exposes. ## Discover and govern tools -After you register the server, C1 runs tool discovery against Apollo. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Apollo. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -83,5 +83,5 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Apollo credentials -- **Rotate the API key** by creating a new key in Apollo and updating it on the server's authentication settings in C1, then revoking the old key. +- **Rotate the API key** by creating a new key in Apollo and updating it on the server's authentication settings in C1.ai, then revoking the old key. - **Adjust access** by limiting the key's endpoints in Apollo. diff --git a/product/admin/mcp-server/auth0.mdx b/product/admin/mcp-server/auth0.mdx index 376cde5e..06570c50 100644 --- a/product/admin/mcp-server/auth0.mdx +++ b/product/admin/mcp-server/auth0.mdx @@ -1,26 +1,26 @@ --- title: Set up the Auth0 MCP server -description: Create an Auth0 Management API token, then register the Auth0 MCP server in C1 and govern the tools your AI clients can call. +description: Create an Auth0 Management API token, then register the Auth0 MCP server in C1.ai and govern the tools your AI clients can call. og:title: Set up the Auth0 MCP server -og:description: Create an Auth0 Management API token, then register the Auth0 MCP server in C1 and govern the tools your AI clients can call. +og:description: Create an Auth0 Management API token, then register the Auth0 MCP server in C1.ai and govern the tools your AI clients can call. sidebarTitle: Auth0 --- {/* Editor Refresh: 2026-06-11 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -The Auth0 MCP server lets you govern access to Auth0 — users, connections, applications, roles, and other tenant data managed through the Auth0 Management API — as tools your AI clients can call through C1. +The Auth0 MCP server lets you govern access to Auth0 — users, connections, applications, roles, and other tenant data managed through the Auth0 Management API — as tools your AI clients can call through C1.ai. Auth0 authenticates with a Management API token. A single token authenticates every user, so all tool calls reach Auth0 as one shared identity. -## How C1 connects to Auth0 +## How C1.ai connects to Auth0 -C1 hosts the Auth0 MCP server, so your users' AI clients only ever see MCP tools — they never call Auth0 directly. When an AI client calls one of these tools, C1 makes the matching request to the Auth0 API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Auth0 MCP server, so your users' AI clients only ever see MCP tools — they never call Auth0 directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Auth0 API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call Auth0 on your users' behalf. +The credentials you set up below are what C1.ai uses to call Auth0 on your users' behalf. ## Before you begin @@ -28,7 +28,7 @@ The credentials you set up below are what C1 uses to call Auth0 on your users' b - An Auth0 account with permission to create a machine-to-machine application authorized for the Auth0 Management API. -If you don't see **Auth0** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **Auth0** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Create an Auth0 Management API token @@ -47,15 +47,15 @@ From the application's **Settings**, note your tenant **Domain**, **Client ID**, -For a shared production setup, use a dedicated machine-to-machine application so activity is attributable to C1 rather than a person. +For a shared production setup, use a dedicated machine-to-machine application so activity is attributable to C1.ai rather than a person. ## How Auth0 credentials are shared -The Management API token authenticates every user as one shared Auth0 identity, so Auth0 sees a single identity for all tool calls. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared setup, create the credential from a dedicated machine-to-machine application so activity is attributable to C1 rather than a person. +The Management API token authenticates every user as one shared Auth0 identity, so Auth0 sees a single identity for all tool calls. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared setup, create the credential from a dedicated machine-to-machine application so activity is attributable to C1.ai rather than a person. For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## Register the Auth0 MCP server in C1 +## Register the Auth0 MCP server in C1.ai With your Management API token ready, register the server and provide your credentials. @@ -70,13 +70,13 @@ Enter your Auth0 tenant URL, such as `https://your-tenant.us.auth0.com`. When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Bearer token** and paste your Auth0 Management API token. -Save your changes. C1 starts a sync that discovers the tools the Auth0 server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Auth0 server exposes. ## Discover and govern tools -After you register the server, C1 runs tool discovery against Auth0. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Auth0. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -88,5 +88,5 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Auth0 credentials -- **Rotate the Management API token** by rotating the client secret on the machine-to-machine application in the Auth0 Dashboard, then update the token on the server's authentication settings in C1. +- **Rotate the Management API token** by rotating the client secret on the machine-to-machine application in the Auth0 Dashboard, then update the token on the server's authentication settings in C1.ai. - **Adjust access** by editing the Management API permissions granted to the application in Auth0. diff --git a/product/admin/mcp-server/azure-devops.mdx b/product/admin/mcp-server/azure-devops.mdx index 5c40ad91..a81214d5 100644 --- a/product/admin/mcp-server/azure-devops.mdx +++ b/product/admin/mcp-server/azure-devops.mdx @@ -1,18 +1,18 @@ --- title: Set up the Azure DevOps MCP server -description: Connect Azure DevOps to C1 with a personal access token or a Microsoft Entra token, then register the MCP server and govern its tools. +description: Connect Azure DevOps to C1.ai with a personal access token or a Microsoft Entra token, then register the MCP server and govern its tools. og:title: Set up the Azure DevOps MCP server -og:description: Connect Azure DevOps to C1 with a personal access token or a Microsoft Entra token, then register the MCP server and govern its tools. +og:description: Connect Azure DevOps to C1.ai with a personal access token or a Microsoft Entra token, then register the MCP server and govern its tools. sidebarTitle: Azure DevOps --- {/* Editor Refresh: 2026-06-11 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -The Azure DevOps MCP server lets you govern access to Azure DevOps — projects, Git repositories, pull requests, builds, pipelines, teams, and work item queries — as tools your AI clients can call through C1. +The Azure DevOps MCP server lets you govern access to Azure DevOps — projects, Git repositories, pull requests, builds, pipelines, teams, and work item queries — as tools your AI clients can call through C1.ai. Azure DevOps is organization-scoped: every API call is rooted at your organization URL. You provide your organization slug — the segment after `https://dev.azure.com/` in your organization URL (for example, `https://dev.azure.com/acme` becomes `acme`) — when you register the server. @@ -23,11 +23,11 @@ Azure DevOps supports two ways to authenticate, and you choose one when you regi For a deeper comparison of shared versus per-user credentials, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## How C1 connects to Azure DevOps +## How C1.ai connects to Azure DevOps -C1 hosts the Azure DevOps MCP server, so your users' AI clients only ever see MCP tools — they never call Azure DevOps directly. When an AI client calls one of these tools, C1 makes the matching request to the Azure DevOps API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Azure DevOps MCP server, so your users' AI clients only ever see MCP tools — they never call Azure DevOps directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Azure DevOps API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call Azure DevOps on your users' behalf. +The credentials you set up below are what C1.ai uses to call Azure DevOps on your users' behalf. ## Before you begin @@ -37,7 +37,7 @@ The credentials you set up below are what C1 uses to call Azure DevOps on your u - For a Microsoft Entra token, permission to [register an application in Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/identity-platform/quickstart-register-app) and obtain a token for the Azure DevOps resource. -If you don't see **Azure DevOps** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **Azure DevOps** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Option 1: Use a personal access token @@ -66,7 +66,7 @@ Select **Create** and copy the token. Azure DevOps shows the token only once. -For a shared production setup, create the token from a dedicated service account so activity is attributable to C1 rather than a person. +For a shared production setup, create the token from a dedicated service account so activity is attributable to C1.ai rather than a person. ### Register the server with a token @@ -83,7 +83,7 @@ Enter your **organization** slug when prompted. When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Basic auth**. Azure DevOps personal access tokens use basic authentication: enter any value for the username and paste your personal access token as the password. -Save your changes. C1 starts a sync that discovers the tools the Azure DevOps server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Azure DevOps server exposes. @@ -120,19 +120,19 @@ Enter your **organization** slug when prompted. When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Bearer token** and paste your Microsoft Entra access token. -Save your changes. C1 starts a sync that discovers the tools the Azure DevOps server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Azure DevOps server exposes. ## How Azure DevOps credentials are shared -Both authentication methods are shared: every user's tool calls use the one credential you provided, so Azure DevOps sees a single shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared setup, use a dedicated service account so activity is attributable to C1 rather than a person. +Both authentication methods are shared: every user's tool calls use the one credential you provided, so Azure DevOps sees a single shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared setup, use a dedicated service account so activity is attributable to C1.ai rather than a person. For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). ## Discover and govern tools -After you register the server, C1 runs tool discovery against Azure DevOps. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Azure DevOps. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -144,6 +144,6 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Azure DevOps credentials -- **Rotate a personal access token** by creating a new token in Azure DevOps under **User settings** > **Personal access tokens** and updating it in C1, then revoking the old token. Set an expiration so it rotates on a schedule. -- **Refresh a Microsoft Entra token** before it expires by obtaining a new access token for the Azure DevOps resource and updating it in C1. +- **Rotate a personal access token** by creating a new token in Azure DevOps under **User settings** > **Personal access tokens** and updating it in C1.ai, then revoking the old token. Set an expiration so it rotates on a schedule. +- **Refresh a Microsoft Entra token** before it expires by obtaining a new access token for the Azure DevOps resource and updating it in C1.ai. - **Adjust access** by editing the token's scopes in Azure DevOps or the application's permissions in Microsoft Entra ID. diff --git a/product/admin/mcp-server/bitbucket.mdx b/product/admin/mcp-server/bitbucket.mdx index 15fd8293..1b7fce76 100644 --- a/product/admin/mcp-server/bitbucket.mdx +++ b/product/admin/mcp-server/bitbucket.mdx @@ -1,18 +1,18 @@ --- title: Set up the Bitbucket MCP server -description: Connect Bitbucket to C1 with per-user OAuth, an app password, or an API token, then register the MCP server and govern its tools. +description: Connect Bitbucket to C1.ai with per-user OAuth, an app password, or an API token, then register the MCP server and govern its tools. og:title: Set up the Bitbucket MCP server -og:description: Connect Bitbucket to C1 with per-user OAuth, an app password, or an API token, then register the MCP server and govern its tools. +og:description: Connect Bitbucket to C1.ai with per-user OAuth, an app password, or an API token, then register the MCP server and govern its tools. sidebarTitle: Bitbucket --- {/* Editor Refresh: 2026-06-11 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -The Bitbucket MCP server lets you govern access to Bitbucket Cloud — repositories, pull requests, issues, pipelines, projects, and workspace data — as tools your AI clients can call through C1. +The Bitbucket MCP server lets you govern access to Bitbucket Cloud — repositories, pull requests, issues, pipelines, projects, and workspace data — as tools your AI clients can call through C1.ai. Bitbucket supports three ways to authenticate, and you choose one when you register the server: @@ -22,11 +22,11 @@ Bitbucket supports three ways to authenticate, and you choose one when you regis For a deeper comparison of shared versus per-user credentials, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## How C1 connects to Bitbucket +## How C1.ai connects to Bitbucket -C1 hosts the Bitbucket MCP server, so your users' AI clients only ever see MCP tools — they never call Bitbucket directly. When an AI client calls one of these tools, C1 makes the matching request to the Bitbucket API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Bitbucket MCP server, so your users' AI clients only ever see MCP tools — they never call Bitbucket directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Bitbucket API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call Bitbucket on your users' behalf. +The credentials you set up below are what C1.ai uses to call Bitbucket on your users' behalf. ## Before you begin @@ -35,7 +35,7 @@ The credentials you set up below are what C1 uses to call Bitbucket on your user - For an app password or API token, a Bitbucket account whose access the credential should carry. -If you don't see **Bitbucket** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **Bitbucket** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Option 1: Set up per-user OAuth @@ -44,7 +44,7 @@ With per-user OAuth, you register one Bitbucket OAuth consumer and each user aut ### Create a Bitbucket OAuth consumer -Create an OAuth consumer in your Bitbucket workspace so C1 can prompt each user to authorize their own account. +Create an OAuth consumer in your Bitbucket workspace so C1.ai can prompt each user to authorize their own account. @@ -54,7 +54,7 @@ In Bitbucket, go to your **Workspace settings** > **OAuth consumers** and select Fill in the registration form: - **Name** — a recognizable name such as `C1`. -- **Callback URL** — set this exactly to whichever matches your C1 tenant's domain: +- **Callback URL** — set this exactly to whichever matches your C1.ai tenant's domain: - Default instance: `https://accounts.conductor.one/auth/callback` - EU data residency instance: `https://accounts.c1eu.ai/auth/callback` @@ -88,7 +88,7 @@ An app password authenticates every user as one shared Bitbucket identity. Use t ### Create an app password -Create an app password in Bitbucket so C1 can authenticate to the Bitbucket API. +Create an app password in Bitbucket so C1.ai can authenticate to the Bitbucket API. @@ -102,7 +102,7 @@ Create the app password and copy it. Bitbucket shows it only once. -For a shared production setup, create the app password from a dedicated service account so activity is attributable to C1 rather than a person. +For a shared production setup, create the app password from a dedicated service account so activity is attributable to C1.ai rather than a person. ### Register the server with an app password @@ -116,7 +116,7 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Basic auth**. Enter your Bitbucket **username** and paste the **app password** as the password. -Save your changes. C1 starts a sync that discovers the tools the Bitbucket server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Bitbucket server exposes. @@ -126,7 +126,7 @@ An API token authenticates every user as one shared identity. Use this when you ### Create an API token -Create an API token in your Atlassian account so C1 can authenticate to the Bitbucket API. +Create an API token in your Atlassian account so C1.ai can authenticate to the Bitbucket API. @@ -137,7 +137,7 @@ Copy the generated token. Treat it as a high-value credential. -For a shared production setup, create the API token from a dedicated service account so activity is attributable to C1 rather than a person. +For a shared production setup, create the API token from a dedicated service account so activity is attributable to C1.ai rather than a person. ### Register the server with an API token @@ -151,7 +151,7 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Custom header**. Set the header name to `Authorization` and the value to `Bearer ` followed by your API token (for example, `Bearer abc123`). -Save your changes. C1 starts a sync that discovers the tools the Bitbucket server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Bitbucket server exposes. @@ -160,13 +160,13 @@ Save your changes. C1 starts a sync that discovers the tools the Bitbucket serve How Bitbucket sees your users' activity depends on the method you chose: - **Per-user OAuth.** Each user authorizes with their own Bitbucket account, so tool calls run under that user's Bitbucket identity and inherit only the access they already have. Bitbucket attributes each action to the individual user. -- **App password or API token.** Every user's tool calls use the one credential you provided, so Bitbucket sees a single shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). +- **App password or API token.** Every user's tool calls use the one credential you provided, so Bitbucket sees a single shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). ## Discover and govern tools -After you register the server, C1 runs tool discovery against Bitbucket. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Bitbucket. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -178,7 +178,7 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Bitbucket credentials -- **Rotate the OAuth client secret** by regenerating the secret on your Bitbucket OAuth consumer under **Workspace settings** > **OAuth consumers**, then update it on the server's authentication settings in C1. -- **Rotate an app password** by creating a new app password in Bitbucket and updating it in C1, then deleting the old one. -- **Rotate an API token** by generating a new token and updating it in C1, then revoking the old one. +- **Rotate the OAuth client secret** by regenerating the secret on your Bitbucket OAuth consumer under **Workspace settings** > **OAuth consumers**, then update it on the server's authentication settings in C1.ai. +- **Rotate an app password** by creating a new app password in Bitbucket and updating it in C1.ai, then deleting the old one. +- **Rotate an API token** by generating a new token and updating it in C1.ai, then revoking the old one. - **Adjust access** by editing the consumer's permissions, the app password's permissions, or the token's scope in Bitbucket. diff --git a/product/admin/mcp-server/box.mdx b/product/admin/mcp-server/box.mdx index dfb14e4f..15f5566e 100644 --- a/product/admin/mcp-server/box.mdx +++ b/product/admin/mcp-server/box.mdx @@ -1,18 +1,18 @@ --- title: Set up the Box MCP server -description: Connect Box to C1 with per-user OAuth or a shared OAuth2 service app, then register the Box MCP server and govern its tools. +description: Connect Box to C1.ai with per-user OAuth or a shared OAuth2 service app, then register the Box MCP server and govern its tools. og:title: Set up the Box MCP server -og:description: Connect Box to C1 with per-user OAuth or a shared OAuth2 service app, then register the Box MCP server and govern its tools. +og:description: Connect Box to C1.ai with per-user OAuth or a shared OAuth2 service app, then register the Box MCP server and govern its tools. sidebarTitle: Box --- {/* Editor Refresh: 2026-06-11 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -The Box MCP server lets you govern access to Box — files, folders, users, groups, and other content data — as tools your AI clients can call through C1. +The Box MCP server lets you govern access to Box — files, folders, users, groups, and other content data — as tools your AI clients can call through C1.ai. Box authenticates with OAuth. You create a Box app, then choose how users connect when you register the server: @@ -21,11 +21,11 @@ Box authenticates with OAuth. You create a Box app, then choose how users connec For a deeper comparison of shared versus per-user credentials, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## How C1 connects to Box +## How C1.ai connects to Box -C1 hosts the Box MCP server, so your users' AI clients only ever see MCP tools — they never call Box directly. When an AI client calls one of these tools, C1 makes the matching request to the Box API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Box MCP server, so your users' AI clients only ever see MCP tools — they never call Box directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Box API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call Box on your users' behalf. +The credentials you set up below are what C1.ai uses to call Box on your users' behalf. ## Before you begin @@ -33,12 +33,12 @@ The credentials you set up below are what C1 uses to call Box on your users' beh - A Box account with permission to create and manage apps in the Box Developer Console, which typically requires an admin role. -If you don't see **Box** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **Box** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Create a Box app -Create a Box app in the Developer Console to hold the OAuth credentials C1 uses, whichever connection method you choose below. +Create a Box app in the Developer Console to hold the OAuth credentials C1.ai uses, whichever connection method you choose below. @@ -48,7 +48,7 @@ In the Box Developer Console, create a new custom app that uses standard OAuth 2 Give the app a recognizable name such as `C1`. -In the app's configuration, set the **redirect URI** exactly to whichever matches your C1 tenant's domain: +In the app's configuration, set the **redirect URI** exactly to whichever matches your C1.ai tenant's domain: - Default instance: `https://accounts.conductor.one/auth/callback` - EU data residency instance: `https://accounts.c1eu.ai/auth/callback` @@ -86,7 +86,7 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **OAuth2 — service mode** and enter your app's **client ID** and **client secret**. -Save your changes. C1 starts a sync that discovers the tools the Box server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Box server exposes. @@ -95,13 +95,13 @@ Save your changes. C1 starts a sync that discovers the tools the Box server expo How Box sees your users' activity depends on the method you chose: - **Per-user OAuth.** Each user authorizes with their own Box account, so tool calls run under that user's Box identity and inherit only the access they already have. Box attributes each action to the individual user. -- **OAuth2 service mode.** Every user's tool calls use the one shared app you provided, so Box sees a single shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). +- **OAuth2 service mode.** Every user's tool calls use the one shared app you provided, so Box sees a single shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). ## Discover and govern tools -After you register the server, C1 runs tool discovery against Box. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Box. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -113,5 +113,5 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Box credentials -- **Rotate the client secret** in your Box app in the Developer Console, then update the secret on the server's authentication settings in C1. +- **Rotate the client secret** in your Box app in the Developer Console, then update the secret on the server's authentication settings in C1.ai. - **Adjust access** by editing the app's scopes in Box. diff --git a/product/admin/mcp-server/buildkite.mdx b/product/admin/mcp-server/buildkite.mdx index d5c9ec21..9655daab 100644 --- a/product/admin/mcp-server/buildkite.mdx +++ b/product/admin/mcp-server/buildkite.mdx @@ -1,26 +1,26 @@ --- title: Set up the Buildkite MCP server -description: Create a Buildkite API access token, then register the Buildkite MCP server in C1 and govern the tools it exposes. +description: Create a Buildkite API access token, then register the Buildkite MCP server in C1.ai and govern the tools it exposes. og:title: Set up the Buildkite MCP server -og:description: Create a Buildkite API access token, then register the Buildkite MCP server in C1 and govern the tools it exposes. +og:description: Create a Buildkite API access token, then register the Buildkite MCP server in C1.ai and govern the tools it exposes. sidebarTitle: Buildkite --- {/* Editor Refresh: 2026-06-11 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -The Buildkite MCP server lets you govern access to Buildkite — organizations, pipelines, builds, jobs, agents, and clusters — as tools your AI clients can call through C1. +The Buildkite MCP server lets you govern access to Buildkite — organizations, pipelines, builds, jobs, agents, and clusters — as tools your AI clients can call through C1.ai. Buildkite authenticates with an API access token. A single token authenticates everyone, so all tool calls reach Buildkite as one shared identity. -## How C1 connects to Buildkite +## How C1.ai connects to Buildkite -C1 hosts the Buildkite MCP server, so your users' AI clients only ever see MCP tools — they never call Buildkite directly. When an AI client calls one of these tools, C1 makes the matching request to the Buildkite API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Buildkite MCP server, so your users' AI clients only ever see MCP tools — they never call Buildkite directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Buildkite API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call Buildkite on your users' behalf. +The credentials you set up below are what C1.ai uses to call Buildkite on your users' behalf. ## Before you begin @@ -28,12 +28,12 @@ The credentials you set up below are what C1 uses to call Buildkite on your user - A Buildkite account that can create an API access token with access to the organizations you want to govern. -If you don't see **Buildkite** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **Buildkite** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Create a Buildkite API access token -Create an API access token in Buildkite so C1 can authenticate to the Buildkite API. +Create an API access token in Buildkite so C1.ai can authenticate to the Buildkite API. @@ -53,15 +53,15 @@ Create the token and copy it. Buildkite shows the token only once. -For a shared production setup, create the token from a dedicated service account so activity is attributable to C1 rather than a person. +For a shared production setup, create the token from a dedicated service account so activity is attributable to C1.ai rather than a person. ## How Buildkite credentials are shared -Every user's tool calls use the one API access token you provided, so Buildkite sees a single shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared setup, use a dedicated service account so activity is attributable to C1 rather than a person. +Every user's tool calls use the one API access token you provided, so Buildkite sees a single shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared setup, use a dedicated service account so activity is attributable to C1.ai rather than a person. For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## Register the Buildkite MCP server in C1 +## Register the Buildkite MCP server in C1.ai With your API access token ready, register the server and provide your credentials. @@ -73,13 +73,13 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Bearer token** and paste your API access token. -Save your changes. C1 starts a sync that discovers the tools the Buildkite server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Buildkite server exposes. ## Discover and govern tools -After you register the server, C1 runs tool discovery against Buildkite. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Buildkite. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -91,5 +91,5 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Buildkite credentials -- **Rotate the API access token** by creating a new token on your Buildkite **API access tokens** page and updating it in C1, then revoking the old token. +- **Rotate the API access token** by creating a new token on your Buildkite **API access tokens** page and updating it in C1.ai, then revoking the old token. - **Adjust access** by editing the token's organizations and REST API scopes in Buildkite. diff --git a/product/admin/mcp-server/confluence.mdx b/product/admin/mcp-server/confluence.mdx index 0c45c649..0a29fa51 100644 --- a/product/admin/mcp-server/confluence.mdx +++ b/product/admin/mcp-server/confluence.mdx @@ -1,26 +1,26 @@ --- title: Set up the Confluence MCP server -description: Connect Confluence to C1 with per-user OAuth, then register the Confluence MCP server and govern the tools it exposes. +description: Connect Confluence to C1.ai with per-user OAuth, then register the Confluence MCP server and govern the tools it exposes. og:title: Set up the Confluence MCP server -og:description: Connect Confluence to C1 with per-user OAuth, then register the Confluence MCP server and govern the tools it exposes. +og:description: Connect Confluence to C1.ai with per-user OAuth, then register the Confluence MCP server and govern the tools it exposes. sidebarTitle: Confluence --- {/* Editor Refresh: 2026-06-11 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -The Confluence MCP server lets you govern access to Confluence Cloud — pages, blog posts, spaces, comments, attachments, whiteboards, groups, and users — as tools your AI clients can call through C1. +The Confluence MCP server lets you govern access to Confluence Cloud — pages, blog posts, spaces, comments, attachments, whiteboards, groups, and users — as tools your AI clients can call through C1.ai. Confluence uses per-user OAuth, which is recommended: each person authorizes with their own Atlassian account, so every tool call runs under that user's identity and permissions. -## How C1 connects to Confluence +## How C1.ai connects to Confluence -C1 hosts the Confluence MCP server, so your users' AI clients only ever see MCP tools — they never call Confluence directly. When an AI client calls one of these tools, C1 makes the matching request to the Confluence API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Confluence MCP server, so your users' AI clients only ever see MCP tools — they never call Confluence directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Confluence API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call Confluence on your users' behalf. +The credentials you set up below are what C1.ai uses to call Confluence on your users' behalf. ## Before you begin @@ -28,7 +28,7 @@ The credentials you set up below are what C1 uses to call Confluence on your use - An Atlassian account that can create an OAuth 2.0 integration. See Atlassian's [OAuth 2.0 (3LO) apps guide](https://developer.atlassian.com/cloud/confluence/oauth-2-3lo-apps/). -If you don't see **Confluence** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **Confluence** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Create an Atlassian OAuth 2.0 integration @@ -46,7 +46,7 @@ Select **Create** > **OAuth 2.0 integration**, enter a recognizable name such as Open the **Permissions** tab. Next to **Confluence API**, select **Add**, then **Configure**, and add the scopes from [Confluence scopes](#confluence-scopes) below — the default read scopes, plus any optional write or delete scopes you need. -Open the **Authorization** tab. Next to **OAuth 2.0 (3LO)**, select **Configure** and set the **Callback URL** exactly to whichever matches your C1 tenant's domain: +Open the **Authorization** tab. Next to **OAuth 2.0 (3LO)**, select **Configure** and set the **Callback URL** exactly to whichever matches your C1.ai tenant's domain: - Default instance: `https://accounts.conductor.one/auth/callback` - EU data residency instance: `https://accounts.c1eu.ai/auth/callback` @@ -60,7 +60,7 @@ Open the **Settings** tab. Under **Authentication details**, copy the **Client I ## Confluence scopes -C1 requests the default read scopes automatically. The default is read-only; to enable write or delete tools, add the optional scopes below in the Developer Console (**Permissions** > **Confluence API** > **Configure**) and in C1's scopes field when configuring authentication. Grant only what you need. These are Confluence's **granular** scopes — the connector targets the Confluence v2 API, which the classic scopes (`write:confluence-content`, and so on) do not authorize. +C1.ai requests the default read scopes automatically. The default is read-only; to enable write or delete tools, add the optional scopes below in the Developer Console (**Permissions** > **Confluence API** > **Configure**) and in C1.ai's scopes field when configuring authentication. Grant only what you need. These are Confluence's **granular** scopes — the connector targets the Confluence v2 API, which the classic scopes (`write:confluence-content`, and so on) do not authorize. **Default scopes** read pages, spaces, attachments, comments, and related content (plus `offline_access` for token refresh): @@ -82,7 +82,7 @@ With per-user OAuth, each user authorizes with their own Atlassian account, so t For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## Register the Confluence MCP server in C1 +## Register the Confluence MCP server in C1.ai With your OAuth 2.0 integration ready, register the server and provide its credentials. @@ -100,7 +100,7 @@ Save your changes. The first time a user calls a Confluence tool from their AI c ## Discover and govern tools -After you register the server, C1 runs tool discovery against Confluence. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Confluence. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -112,5 +112,5 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Confluence credentials -- **Rotate the OAuth client secret** in the Atlassian Developer Console under your integration's **Settings** tab, then update the secret on the server's authentication settings in C1. +- **Rotate the OAuth client secret** in the Atlassian Developer Console under your integration's **Settings** tab, then update the secret on the server's authentication settings in C1.ai. - **Adjust access** by editing the integration's Confluence scopes on the **Permissions** tab in the Atlassian Developer Console. diff --git a/product/admin/mcp-server/copilot-studio.mdx b/product/admin/mcp-server/copilot-studio.mdx index 3d6365c1..73f08ea6 100644 --- a/product/admin/mcp-server/copilot-studio.mdx +++ b/product/admin/mcp-server/copilot-studio.mdx @@ -1,39 +1,39 @@ --- -title: Connect Copilot Studio to C1 -description: Build a Copilot Studio agent that calls governed tools through C1, then publish it to Microsoft 365 Copilot for your whole organization. -og:title: Connect Copilot Studio to C1 -og:description: Build a Copilot Studio agent that calls governed tools through C1, then publish it to Microsoft 365 Copilot for your whole organization. +title: Connect Copilot Studio to C1.ai +description: Build a Copilot Studio agent that calls governed tools through C1.ai, then publish it to Microsoft 365 Copilot for your whole organization. +og:title: Connect Copilot Studio to C1.ai +og:description: Build a Copilot Studio agent that calls governed tools through C1.ai, then publish it to Microsoft 365 Copilot for your whole organization. sidebarTitle: Connect Copilot Studio --- {/* Editor Refresh: 2026-08-07 */} -Build an agent in Copilot Studio that calls the tools your IT team approved for you, using your own identity, with every call authorized and logged by C1. Then publish the agent so your colleagues use it from Microsoft 365 Copilot and Teams. +Build an agent in Copilot Studio that calls the tools your IT team approved for you, using your own identity, with every call authorized and logged by C1.ai. Then publish the agent so your colleagues use it from Microsoft 365 Copilot and Teams. ## What you'll do The full path from empty agent to an agent your whole organization can use has three stages, and the middle one involves your Teams admin. -1. **Build it.** Create the agent, add C1 as a tool, authorize the connection, and write the agent's instructions. +1. **Build it.** Create the agent, add C1.ai as a tool, authorize the connection, and write the agent's instructions. 2. **Publish it.** Publish the agent, connect the Microsoft 365 Copilot channel, and request admin approval to reach everyone. 3. **Approve and use it.** Your Teams admin approves the app, you confirm it went through, and people add the agent in Microsoft 365 Copilot. -You don't need a C1 admin role for any of this. You do need a Teams admin for stage three if you want the agent available to the whole organization. +You don't need a C1.ai admin role for any of this. You do need a Teams admin for stage three if you want the agent available to the whole organization. ## Before you begin - AI access management must be enabled for your tenant. See [Enable AI access management](/product/admin/enable-ai-access-management). - A Copilot Studio environment you can create agents in, from your Power Platform admin. -- Access in C1 to the tools you want the agent to call. Request it from the C1 catalog and an approver grants it. See [Find and request AI tool access](/product/how-to/ai-tools#find-and-request-ai-tool-access). +- Access in C1.ai to the tools you want the agent to call. Request it from the C1.ai catalog and an approver grants it. See [Find and request AI tool access](/product/how-to/ai-tools#find-and-request-ai-tool-access). - A Teams admin who can approve the app, if you're publishing to everyone in your organization. -## Get your C1 MCP server URL +## Get your C1.ai MCP server URL -Every connection to C1 uses the same URL, scoped to your tenant. Copy it before you open Copilot Studio. +Every connection to C1.ai uses the same URL, scoped to your tenant. Copy it before you open Copilot Studio. -In C1, click your profile menu and click **AI & API**. +In C1.ai, click your profile menu and click **AI & API**. On the **AI connections** tab, copy the **MCP server URL**. @@ -48,7 +48,7 @@ You now have the URL to paste into Copilot Studio's MCP onboarding wizard. ## Create a blank agent -Start from a blank agent so nothing is configured that you didn't choose. If you already have an agent you want to give governed tools to, skip to [Add C1 as a tool](#add-c1-as-a-tool). +Start from a blank agent so nothing is configured that you didn't choose. If you already have an agent you want to give governed tools to, skip to [Add C1.ai as a tool](#add-c1-as-a-tool). @@ -73,9 +73,9 @@ The name has a 42-character limit and can't contain angle brackets. The descript Copilot Studio provisions the agent and opens its **Overview** page. -## Add C1 as a tool +## Add C1.ai as a tool -C1 appears to Copilot Studio as an MCP server. Add it through the MCP onboarding wizard. +C1.ai appears to Copilot Studio as an MCP server. Add it through the MCP onboarding wizard. @@ -88,9 +88,9 @@ Select **Add a tool**, then select **New tool**. Select **Model Context Protocol**. The MCP onboarding wizard appears. -Enter a **Server name** and **Server description**, and paste your C1 MCP server URL into **Server URL**. +Enter a **Server name** and **Server description**, and paste your C1.ai MCP server URL into **Server URL**. -Write a clear description, because the agent's orchestrator uses it to decide when to call C1. For example: "Governed access to approved company tools, authorized per user by C1." +Write a clear description, because the agent's orchestrator uses it to decide when to call C1.ai. For example: "Governed access to approved company tools, authorized per user by C1.ai." For the authentication type, select **OAuth 2.0**, then select **Dynamic discovery** as the type. @@ -103,18 +103,18 @@ On **Add tool**, select **Create a new connection**, then select **Add to agent* -C1 is now added as a tool, and the agent needs an authorized connection before it can call it. +C1.ai is now added as a tool, and the agent needs an authorized connection before it can call it. ## Authorize the connection -The first time the agent calls a C1 tool, C1 asks you to sign in and confirm the connection. +The first time the agent calls a C1.ai tool, C1.ai asks you to sign in and confirm the connection. Test the agent and ask it to list its available tools. -When the sign-in prompt appears, sign in to C1. +When the sign-in prompt appears, sign in to C1.ai. Review the connection details and click **Allow**. @@ -144,7 +144,7 @@ Test the agent and adjust the instructions until it behaves the way you want. -The agent now follows these instructions when deciding when to call C1. +The agent now follows these instructions when deciding when to call C1.ai. ## Publish the agent @@ -263,7 +263,7 @@ The status changes to **Approved**. Confirm **Make agent available in Microsoft 365 Copilot** is still selected in the channel panel. -Open the agent and ask it to list its tools, to confirm the C1 connection still works after publishing. +Open the agent and ask it to list its tools, to confirm the C1.ai connection still works after publishing. @@ -284,11 +284,11 @@ Find the agent in the agent list, or add it from the **Built by your org** secti Enter **@**, select the agent from the list, and ask a question. -When C1 asks you to sign in, sign in and select **Allow**. +When C1.ai asks you to sign in, sign in and select **Allow**. -Everyone authorizes C1 with their own identity, so each person sees only the tools their own access grants them. Sharing the agent doesn't share your access. +Everyone authorizes C1.ai with their own identity, so each person sees only the tools their own access grants them. Sharing the agent doesn't share your access. ### Update the agent later @@ -298,10 +298,10 @@ You can keep improving the agent after it's approved. Changes to the instruction | Symptom | Cause | Fix | | :--- | :--- | :--- | -| **AI & API** isn't in your C1 profile menu | AI access management isn't enabled for your tenant. | Ask your C1 admin to contact the C1 support team. | +| **AI & API** isn't in your C1.ai profile menu | AI access management isn't enabled for your tenant. | Ask your C1.ai admin to contact the C1.ai support team. | | **Model Context Protocol** isn't offered as a tool type | The agent uses classic orchestration. | Turn on generative orchestration on the agent's **Settings** page, under **Generative AI** > **Orchestration**. If the option isn't there, your Power Platform admin turned it off for the environment. | -| The wizard can't reach or register with the C1 URL | A typo in the URL, or a Power Platform data policy blocking connectors. | Check the URL. If it's correct, ask your Power Platform admin whether a data policy applies. | -| The agent connects but lists no tools | Your access hasn't been granted. | Request it from the C1 catalog. See [How to request AI tools](/product/how-to/ai-tools). | +| The wizard can't reach or register with the C1.ai URL | A typo in the URL, or a Power Platform data policy blocking connectors. | Check the URL. If it's correct, ask your Power Platform admin whether a data policy applies. | +| The agent connects but lists no tools | Your access hasn't been granted. | Request it from the C1.ai catalog. See [How to request AI tools](/product/how-to/ai-tools). | | A tool call is denied part way through a working session | Your access was revoked, or a just-in-time grant expired. | Submit a new request to renew. | | Tools from one service fail while others work | That service needs your own credentials. | Authorize it under **AI & API > MCP connections**. | | You don't have permissions to any environments | You have no Copilot Studio environment. | Ask your Power Platform admin for access to one, or to create one. | @@ -312,12 +312,12 @@ You can keep improving the agent after it's approved. Changes to the instruction ## Frequently asked questions about connecting Copilot Studio - -No. Anyone with a C1 account can build an agent and authorize it. Enabling AI access management and granting tool access are C1 admin tasks done separately. Publishing to your whole organization needs a Teams admin. + +No. Anyone with a C1.ai account can build an agent and authorize it. Enabling AI access management and granting tool access are C1.ai admin tasks done separately. Publishing to your whole organization needs a Teams admin. -Only the tools your access profiles grant you. C1 checks every tool call against your granted access, so two people using the same agent can see different tools. +Only the tools your access profiles grant you. C1.ai checks every tool call against your granted access, so two people using the same agent can see different tools. @@ -328,8 +328,8 @@ Yes, with a smaller audience. Use **Copy link** to share an installation link, o The next tool call returns a denied error, and in-flight calls finish. Nothing on your machine is deleted; only new tool calls are affected. See [What happens if your access is revoked or expires](/product/how-to/ai-tools#what-happens-if-your-access-is-revoked-or-expires). - -Yes. When you add C1 to another agent in the same environment, the **Add tool** dialog offers your existing connection instead of making you create a new one. + +Yes. When you add C1.ai to another agent in the same environment, the **Add tool** dialog offers your existing connection instead of making you create a new one. diff --git a/product/admin/mcp-server/crowdstrike.mdx b/product/admin/mcp-server/crowdstrike.mdx index 419d36c2..9ed7f006 100644 --- a/product/admin/mcp-server/crowdstrike.mdx +++ b/product/admin/mcp-server/crowdstrike.mdx @@ -1,26 +1,26 @@ --- title: Set up the CrowdStrike MCP server -description: Create a CrowdStrike Falcon API client, then register the CrowdStrike MCP server in C1 and govern the tools your AI clients can call. +description: Create a CrowdStrike Falcon API client, then register the CrowdStrike MCP server in C1.ai and govern the tools your AI clients can call. og:title: Set up the CrowdStrike MCP server -og:description: Create a CrowdStrike Falcon API client, then register the CrowdStrike MCP server in C1 and govern the tools your AI clients can call. +og:description: Create a CrowdStrike Falcon API client, then register the CrowdStrike MCP server in C1.ai and govern the tools your AI clients can call. sidebarTitle: CrowdStrike --- {/* Editor Refresh: 2026-06-11 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -The CrowdStrike MCP server lets you govern access to CrowdStrike Falcon — detections, incidents, hosts, vulnerabilities, and other data exposed by the Falcon API — as tools your AI clients can call through C1. +The CrowdStrike MCP server lets you govern access to CrowdStrike Falcon — detections, incidents, hosts, vulnerabilities, and other data exposed by the Falcon API — as tools your AI clients can call through C1.ai. CrowdStrike authenticates with a Falcon API client using the OAuth2 client credentials flow. The API client's client ID and client secret authenticate every user, so all tool calls reach Falcon as one shared identity. -## How C1 connects to CrowdStrike +## How C1.ai connects to CrowdStrike -C1 hosts the CrowdStrike MCP server, so your users' AI clients only ever see MCP tools — they never call CrowdStrike directly. When an AI client calls one of these tools, C1 makes the matching request to the CrowdStrike API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the CrowdStrike MCP server, so your users' AI clients only ever see MCP tools — they never call CrowdStrike directly. When an AI client calls one of these tools, C1.ai makes the matching request to the CrowdStrike API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call CrowdStrike on your users' behalf. +The credentials you set up below are what C1.ai uses to call CrowdStrike on your users' behalf. ## Before you begin @@ -28,12 +28,12 @@ The credentials you set up below are what C1 uses to call CrowdStrike on your us - A CrowdStrike Falcon account with the **Falcon Administrator** role, or another role that can create API clients. -If you don't see **CrowdStrike** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **CrowdStrike** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Create a CrowdStrike Falcon API client -CrowdStrike issues a client ID and client secret to an API client, which C1 exchanges for an access token using the client credentials flow. +CrowdStrike issues a client ID and client secret to an API client, which C1.ai exchanges for an access token using the client credentials flow. @@ -54,15 +54,15 @@ Note your Falcon cloud's API base URL, such as `https://api.crowdstrike.com` or -For a shared production setup, use a dedicated API client so activity is attributable to C1 rather than a person. +For a shared production setup, use a dedicated API client so activity is attributable to C1.ai rather than a person. ## How CrowdStrike credentials are shared -The API client authenticates every user as one shared Falcon identity, so CrowdStrike sees a single identity for all tool calls. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared setup, use a dedicated API client so activity is attributable to C1 rather than a person. +The API client authenticates every user as one shared Falcon identity, so CrowdStrike sees a single identity for all tool calls. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared setup, use a dedicated API client so activity is attributable to C1.ai rather than a person. For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## Register the CrowdStrike MCP server in C1 +## Register the CrowdStrike MCP server in C1.ai With your API client ready, register the server and provide your credentials. @@ -77,13 +77,13 @@ Enter your Falcon API base URL, such as `https://api.crowdstrike.com`. When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **OAuth2 — client credentials** and enter the API client's **client ID** and **client secret**. -Save your changes. C1 starts a sync that discovers the tools the CrowdStrike server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the CrowdStrike server exposes. ## Discover and govern tools -After you register the server, C1 runs tool discovery against CrowdStrike. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against CrowdStrike. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -95,5 +95,5 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your CrowdStrike credentials -- **Rotate the client secret** by resetting it on the API client in the Falcon console, then update the secret on the server's authentication settings in C1. +- **Rotate the client secret** by resetting it on the API client in the Falcon console, then update the secret on the server's authentication settings in C1.ai. - **Adjust access** by editing the API scopes granted to the API client in CrowdStrike. diff --git a/product/admin/mcp-server/datadog.mdx b/product/admin/mcp-server/datadog.mdx index 4fe3da1b..ae636aa3 100644 --- a/product/admin/mcp-server/datadog.mdx +++ b/product/admin/mcp-server/datadog.mdx @@ -1,31 +1,31 @@ --- title: Set up the Datadog MCP server -description: Create your Datadog API and application keys, then register the Datadog MCP server with C1 and configure authentication. +description: Create your Datadog API and application keys, then register the Datadog MCP server with C1.ai and configure authentication. og:title: Set up the Datadog MCP server -og:description: Create your Datadog API and application keys, then register the Datadog MCP server with C1 and configure authentication. +og:description: Create your Datadog API and application keys, then register the Datadog MCP server with C1.ai and configure authentication. sidebarTitle: Datadog --- {/* Editor Refresh: 2026-06-11 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -The Datadog MCP server lets you govern access to the Datadog observability platform — metrics, monitors, dashboards, logs, security signals, incidents, and more — as tools your AI clients can call through C1. +The Datadog MCP server lets you govern access to the Datadog observability platform — metrics, monitors, dashboards, logs, security signals, incidents, and more — as tools your AI clients can call through C1.ai. Datadog authenticates with two credentials that work together: - An **API key** identifies your organization to Datadog. - An **application key** authorizes a user or role to read and write data. -Most Datadog endpoints need both, so you'll create each one in Datadog and then provide them to C1 when you register the server. +Most Datadog endpoints need both, so you'll create each one in Datadog and then provide them to C1.ai when you register the server. -## How C1 connects to Datadog +## How C1.ai connects to Datadog -C1 hosts the Datadog MCP server, so your users' AI clients only ever see MCP tools — they never call Datadog directly. When an AI client calls one of these tools, C1 makes the matching request to the Datadog REST API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Datadog MCP server, so your users' AI clients only ever see MCP tools — they never call Datadog directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Datadog REST API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call Datadog on your users' behalf. +The credentials you set up below are what C1.ai uses to call Datadog on your users' behalf. ## Before you begin @@ -35,7 +35,7 @@ The credentials you set up below are what C1 uses to call Datadog on your users' ## Find your Datadog site -Datadog hosts each organization on a regional site with its own API host. You'll select this site when you register the server in C1. To find yours, match the host in your browser's address bar while you're signed in to Datadog. +Datadog hosts each organization on a regional site with its own API host. You'll select this site when you register the server in C1.ai. To find yours, match the host in your browser's address bar while you're signed in to Datadog. | Site | Web host | API host | | :--- | :--- | :--- | @@ -52,7 +52,7 @@ For more detail, see Datadog's [Getting Started with Datadog sites](https://docs ## Create a Datadog API key -Create an API key in your Datadog organization to identify it to C1. +Create an API key in your Datadog organization to identify it to C1.ai. @@ -65,7 +65,7 @@ Go to **Organization Settings** > **API Keys**. Select **New Key**, give it a recognizable name such as `C1`, and select **Create API key**. -Copy the key and store it safely. You'll add it to C1 when you register the server. +Copy the key and store it safely. You'll add it to C1.ai when you register the server. @@ -73,7 +73,7 @@ API keys are organization-level. They don't expire by default and aren't tied to ## Create a Datadog application key -Create an application key to authorize C1 to call the Datadog API. +Create an application key to authorize C1.ai to call the Datadog API. @@ -96,13 +96,13 @@ For more detail on both key types, see Datadog's [API and application keys](http ## How Datadog credentials are shared -The Datadog MCP server uses a single shared credential. The API key and application key you provide are used for every user's tool calls, so Datadog sees all activity as one identity — the user or service account that owns the application key. C1 still attributes each call to the individual user who made it in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). +The Datadog MCP server uses a single shared credential. The API key and application key you provide are used for every user's tool calls, so Datadog sees all activity as one identity — the user or service account that owns the application key. C1.ai still attributes each call to the individual user who made it in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). -To keep that shared identity attributable to C1 rather than a person, create the application key from a dedicated service-account user, as described in [Create a Datadog application key](#create-a-datadog-application-key). +To keep that shared identity attributable to C1.ai rather than a person, create the application key from a dedicated service-account user, as described in [Create a Datadog application key](#create-a-datadog-application-key). For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## Register the Datadog MCP server in C1 +## Register the Datadog MCP server in C1.ai With both keys ready, register the server and provide your credentials. @@ -118,13 +118,13 @@ When you [configure authentication](/product/admin/mcp-servers#configure-authent - Your **application key** -Save your changes. C1 starts a sync that discovers the tools the Datadog server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Datadog server exposes. ## Discover and govern tools -After you register the server, C1 runs tool discovery against Datadog. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Datadog. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification) for details. @@ -138,6 +138,6 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered You can rotate either key or adjust the application key's scopes at any time without re-registering the server. -- **Rotate the API key** in **Organization Settings** > **API Keys** in Datadog, then update the credential on the server's authentication settings in C1. +- **Rotate the API key** in **Organization Settings** > **API Keys** in Datadog, then update the credential on the server's authentication settings in C1.ai. - **Rotate the application key** the same way under **Application Keys**. If you used a service-account user, keep that account active so the key stays valid. - **Adjust scopes** at any time by editing the application key's authorization scopes in Datadog. diff --git a/product/admin/mcp-server/freshdesk.mdx b/product/admin/mcp-server/freshdesk.mdx index e8676827..8011395c 100644 --- a/product/admin/mcp-server/freshdesk.mdx +++ b/product/admin/mcp-server/freshdesk.mdx @@ -1,26 +1,26 @@ --- title: Set up the Freshdesk MCP server -description: Create Freshdesk basic auth credentials and register the Freshdesk MCP server in C1 so AI clients can call governed Freshdesk tools. +description: Create Freshdesk basic auth credentials and register the Freshdesk MCP server in C1.ai so AI clients can call governed Freshdesk tools. og:title: Set up the Freshdesk MCP server -og:description: Create Freshdesk basic auth credentials and register the Freshdesk MCP server in C1 so AI clients can call governed Freshdesk tools. +og:description: Create Freshdesk basic auth credentials and register the Freshdesk MCP server in C1.ai so AI clients can call governed Freshdesk tools. sidebarTitle: Freshdesk --- {/* Editor Refresh: 2026-06-11 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -The Freshdesk MCP server lets you govern access to Freshdesk — tickets, contacts, companies, and other support data — as tools your AI clients can call through C1. +The Freshdesk MCP server lets you govern access to Freshdesk — tickets, contacts, companies, and other support data — as tools your AI clients can call through C1.ai. -Freshdesk authenticates with basic auth, using a Freshdesk API key as the username. A single credential authenticates everyone, so all tool calls reach Freshdesk as one shared identity. Create the API key from a dedicated service-account agent so activity is attributable to C1 rather than a person. +Freshdesk authenticates with basic auth, using a Freshdesk API key as the username. A single credential authenticates everyone, so all tool calls reach Freshdesk as one shared identity. Create the API key from a dedicated service-account agent so activity is attributable to C1.ai rather than a person. -## How C1 connects to Freshdesk +## How C1.ai connects to Freshdesk -C1 hosts the Freshdesk MCP server, so your users' AI clients only ever see MCP tools — they never call Freshdesk directly. When an AI client calls one of these tools, C1 makes the matching request to the Freshdesk API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Freshdesk MCP server, so your users' AI clients only ever see MCP tools — they never call Freshdesk directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Freshdesk API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call Freshdesk on your users' behalf. +The credentials you set up below are what C1.ai uses to call Freshdesk on your users' behalf. ## Before you begin @@ -28,12 +28,12 @@ The credentials you set up below are what C1 uses to call Freshdesk on your user - A Freshdesk agent account with the API access and role needed for the tools you plan to govern. -If you don't see **Freshdesk** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **Freshdesk** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Find your Freshdesk API key -Copy the API key from your Freshdesk agent profile so C1 can authenticate as that agent. +Copy the API key from your Freshdesk agent profile so C1.ai can authenticate as that agent. @@ -48,11 +48,11 @@ Freshdesk basic auth uses your API key as the username. Freshdesk ignores the pa ## How Freshdesk credentials are shared -Every user's tool calls use the one API key you provided, so Freshdesk sees a single shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared production setup, create the API key from a dedicated service-account agent so activity is attributable to C1 rather than a person. +Every user's tool calls use the one API key you provided, so Freshdesk sees a single shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared production setup, create the API key from a dedicated service-account agent so activity is attributable to C1.ai rather than a person. For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## Register the Freshdesk MCP server in C1 +## Register the Freshdesk MCP server in C1.ai With your API key ready, register the server and provide your credentials. @@ -64,13 +64,13 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Basic auth**, enter your Freshdesk API key as the username, and enter any placeholder such as `X` as the password. -Save your changes. C1 starts a sync that discovers the tools the Freshdesk server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Freshdesk server exposes. ## Discover and govern tools -After you register the server, C1 runs tool discovery against Freshdesk. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Freshdesk. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -82,5 +82,5 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Freshdesk credentials -- **Rotate the API key** by resetting it in Freshdesk, then update the username on the server's authentication settings in C1. +- **Rotate the API key** by resetting it in Freshdesk, then update the username on the server's authentication settings in C1.ai. - **Adjust access** by changing the role of the agent whose API key you use. diff --git a/product/admin/mcp-server/gemini-enterprise.mdx b/product/admin/mcp-server/gemini-enterprise.mdx index 069de194..34cbd512 100644 --- a/product/admin/mcp-server/gemini-enterprise.mdx +++ b/product/admin/mcp-server/gemini-enterprise.mdx @@ -1,17 +1,17 @@ --- -title: Connect Gemini Enterprise to C1 -description: Give Gemini Enterprise users access to C1-governed tools, with every tool call attributed to the person who made it. -og:title: Connect Gemini Enterprise to C1 -og:description: Give Gemini Enterprise users access to C1-governed tools, with every tool call attributed to the person who made it. +title: Connect Gemini Enterprise to C1.ai +description: Give Gemini Enterprise users access to C1.ai-governed tools, with every tool call attributed to the person who made it. +og:title: Connect Gemini Enterprise to C1.ai +og:description: Give Gemini Enterprise users access to C1.ai-governed tools, with every tool call attributed to the person who made it. sidebarTitle: Connect Gemini Enterprise --- {/* Editor Refresh: 2026-08-19 */} -Google [Gemini Enterprise](https://cloud.google.com/gemini/enterprise) calls the C1 MCP gateway as a tool source. Your users ask Gemini Enterprise a question, Gemini calls a C1 tool on their behalf, and C1 enforces your access policies against that person's identity. Tool calls are attributed to individual users, not to a shared service account. +Google [Gemini Enterprise](https://cloud.google.com/gemini/enterprise) calls the C1.ai MCP gateway as a tool source. Your users ask Gemini Enterprise a question, Gemini calls a C1.ai tool on their behalf, and C1.ai enforces your access policies against that person's identity. Tool calls are attributed to individual users, not to a shared service account. -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. ## What you'll do @@ -20,22 +20,22 @@ Setup spans two products. Some stages depend on someone other than you, so line | Stage | Where | Depends on | | :--- | :--- | :--- | -| [Collect the values you'll reuse](#collect-the-values-youll-reuse) | C1 and Google Cloud | Nothing | +| [Collect the values you'll reuse](#collect-the-values-youll-reuse) | C1.ai and Google Cloud | Nothing | | [Enable the Google Cloud APIs](#enable-the-google-cloud-apis) | Google Cloud | `roles/serviceusage.serviceUsageAdmin` | | [Allow custom MCP data connectors](#allow-custom-mcp-data-connectors) | Google Cloud | An **organization** policy administrator | | [Prepare Gemini Enterprise](#prepare-gemini-enterprise) | Gemini Enterprise | A Gemini Enterprise subscription | -| [Get the OAuth client ID](#get-the-oauth-client-id) | C1 and Google Cloud | `roles/storage.admin`, if you host the document yourself | +| [Get the OAuth client ID](#get-the-oauth-client-id) | C1.ai and Google Cloud | `roles/storage.admin`, if you host the document yourself | | [Create the data store](#create-the-data-store) | Gemini Enterprise | `roles/discoveryengine.editor` | | [Sign in to the web app](#sign-in-to-the-web-app) | Gemini Enterprise | A licensed user | -| [Enable the actions](#enable-the-actions) | Gemini Enterprise | Tool access already granted in C1 | -| [Verify the connection](#verify-the-gemini-enterprise-connection) | Gemini Enterprise and C1 | A user with C1 tool access | +| [Enable the actions](#enable-the-actions) | Gemini Enterprise | Tool access already granted in C1.ai | +| [Verify the connection](#verify-the-gemini-enterprise-connection) | Gemini Enterprise and C1.ai | A user with C1.ai tool access | ## Before you begin Confirm all of these before you start. The organization policy change in particular can take time to arrange. - AI access management must be enabled for your tenant. See [Enable AI access management](/product/admin/enable-ai-access-management). -- **The users who will use Gemini Enterprise need C1 tool access already.** Their access profiles determine which tools they can call, and a user with no toolset sees no tools at all. See [Tools and toolsets](/product/admin/tools-and-toolsets). +- **The users who will use Gemini Enterprise need C1.ai tool access already.** Their access profiles determine which tools they can call, and a user with no toolset sees no tools at all. See [Tools and toolsets](/product/admin/tools-and-toolsets). - A Google Cloud project with a Gemini Enterprise app already created. In the console, open **Gemini Enterprise** and select **Create app**, or see Google's [Create a Gemini Enterprise app](https://docs.cloud.google.com/gemini/enterprise/docs/create-app) documentation. There is a command-line alternative in [Enable the Google Cloud APIs](#enable-the-google-cloud-apis). - A Gemini Enterprise subscription with licenses available to assign. A new app starts with no users licensed. The identity provider must be set before you create the data store, and licenses must be assigned before tool discovery will work. Both are in [Prepare Gemini Enterprise](#prepare-gemini-enterprise). - Someone who holds `roles/orgpolicy.policyAdmin` at the organization level. Project **Owner** does not include it, and a project-level grant is not sufficient for the policy change below. @@ -49,8 +49,8 @@ The steps below reuse these values. Collect them once. | Value | Where to get it | Example | | :--- | :--- | :--- | -| **Tenant** | The subdomain of your C1 URL. It is also the prefix of your MCP server URL. | `acme` | -| **MCP server URL** | In C1, open your user profile menu and select **AI & API** > **AI connections**. Copy the URL shown at the top of the page. | `https://acme-mcp.conductor.one/v1` | +| **Tenant** | The subdomain of your C1.ai URL. It is also the prefix of your MCP server URL. | `acme` | +| **MCP server URL** | In C1.ai, open your user profile menu and select **AI & API** > **AI connections**. Copy the URL shown at the top of the page. | `https://acme-mcp.conductor.one/v1` | | **Project ID** | The Google Cloud console project picker, or `gcloud config get-value project`. | `acme-gemini` | | **Project number** | `gcloud projects describe YOUR_PROJECT_ID --format="value(projectNumber)"`. This is not the same as the project ID, and a few API calls need it. | `514280176422` | | **Your email** | The Google identity you run these commands as, and the first person to be licensed. | `admin@acme.com` | @@ -355,9 +355,9 @@ curl -s -X POST \ ## Get the OAuth client ID -Gemini Enterprise authenticates each user to C1 with the OAuth 2.0 authorization code flow, and it needs an OAuth client that already exists. It does not register one itself, and it does not publish a client identity you can point at. +Gemini Enterprise authenticates each user to C1.ai with the OAuth 2.0 authorization code flow, and it needs an OAuth client that already exists. It does not register one itself, and it does not publish a client identity you can point at. -C1 does not hand out an opaque client ID from a registration form. Instead, the client ID **is** a URL: it points at a small public JSON file describing the client, called a *Client ID Metadata Document*. C1 fetches that URL to learn who the client is, which means someone has to host the document. +C1.ai does not hand out an opaque client ID from a registration form. Instead, the client ID **is** a URL: it points at a small public JSON file describing the client, called a *Client ID Metadata Document*. C1.ai fetches that URL to learn who the client is, which means someone has to host the document. Google is the party that should host it, since Gemini Enterprise is the client it describes. Today it does not, and Google's own instructions are to register the MCP server as an OAuth client with your identity provider and take a client ID from it. Until Google publishes a document, somebody else has to host one on Google's behalf. @@ -365,10 +365,10 @@ Google is the party that should host it, since Gemini Enterprise is the client i | :--- | :--- | :--- | | Google | A Google-published URL | Not published. The preferred outcome | | You | The URL you publish it at | Works today | -| C1 | `https://.conductor.one/auth/v1/client-metadata/gemini-enterprise` | Not available yet | +| C1.ai | `https://.conductor.one/auth/v1/client-metadata/gemini-enterprise` | Not available yet | -Host the document yourself for now. The C1-hosted document has not shipped, so every tenant returns a `404` from that URL, and it is a stopgap rather than the end state: a client identity carries the most weight when the client's own vendor publishes it. [Contact the C1 support team](mailto:support@c1.ai) for timing. +Host the document yourself for now. The C1.ai-hosted document has not shipped, so every tenant returns a `404` from that URL, and it is a stopgap rather than the end state: a client identity carries the most weight when the client's own vendor publishes it. [Contact the C1.ai support team](mailto:support@c1.ai) for timing. When Google publishes a client metadata document for Gemini Enterprise, use that URL as the client ID and retire whatever you were hosting. @@ -376,7 +376,7 @@ When Google publishes a client metadata document for Gemini Enterprise, use that This client has no secret, so nothing expires and nothing needs rotating. Configure it once and it keeps working. -Do not register a client through C1's dynamic registration endpoint instead. An unapproved dynamic registration's secret expires one hour after it is issued, and rotating it preserves the original expiry rather than extending it, so the connector fails at its first token refresh. +Do not register a client through C1.ai's dynamic registration endpoint instead. An unapproved dynamic registration's secret expires one hour after it is issued, and rotating it preserves the original expiry rather than extending it, so the connector fails at its first token refresh. ### Host the client metadata document yourself @@ -397,7 +397,7 @@ Save the file as `gemini-enterprise-oauth-client.json`. The Cloud Storage comman } ``` -C1 fetches this document over the public internet, so it must be reachable without authentication. A Cloud Storage bucket works. Replace `YOUR_BUCKET` with a bucket name you choose, which must be globally unique across all of Cloud Storage: +C1.ai fetches this document over the public internet, so it must be reachable without authentication. A Cloud Storage bucket works. Replace `YOUR_BUCKET` with a bucket name you choose, which must be globally unique across all of Cloud Storage: ```bash gcloud storage buckets create gs://YOUR_BUCKET \ @@ -473,7 +473,7 @@ Organization policy changes take a minute or two to take effect, in both directi ## Create the data store -Connect the C1 MCP gateway to your Gemini Enterprise app. +Connect the C1.ai MCP gateway to your Gemini Enterprise app. Creating the connector is the one step you cannot script. The public Discovery Engine API refuses it: @@ -523,12 +523,12 @@ Complete the fields. The third column is where this form most often goes wrong. | :--- | :--- | :--- | | **MCP Server URL** | `https://-mcp.conductor.one/v1` | Ends with `/v1`. | | **Authorization URL** | `https://.conductor.one/auth/v1/authorize` | No trailing parameters. | -| **Authorization URL Parameters** | `&resource=https://-mcp.conductor.one/v1` | Required. C1 binds tokens to a resource, so omitting this yields a token your MCP endpoint rejects. | +| **Authorization URL Parameters** | `&resource=https://-mcp.conductor.one/v1` | Required. C1.ai binds tokens to a resource, so omitting this yields a token your MCP endpoint rejects. | | **Token URL** | `https://.conductor.one/auth/v1/token` | No special handling | | **Client ID** | Your client metadata document URL | The full `https://` URL, not a bare identifier. | -| **Client Secret** | `none` | Proof Key for Code Exchange (PKCE) needs no secret, but the console requires a value in this field, and Google's documentation says to enter `none`. C1 never reads it. | +| **Client Secret** | `none` | Proof Key for Code Exchange (PKCE) needs no secret, but the console requires a value in this field, and Google's documentation says to enter `none`. C1.ai never reads it. | | **Scopes** | `openid profile email offline_access` | Space-separated, not comma-separated. | -| **Enable PKCE Support** | Selected | Not selected by default. C1 requires PKCE, so the flow fails without it. | +| **Enable PKCE Support** | Selected | Not selected by default. C1.ai requires PKCE, so the flow fails without it. | | **Use HTTP Basic Authentication** | Cleared | **Selected by default.** Leaving it selected sends credentials in an `Authorization` header, which does not work for a client with no secret. | @@ -657,7 +657,7 @@ Your collection ID is the one shown as **Collection ID** on the data store's **D ### Reach every tool without spending your action budget -The C1 gateway publishes far more tools than the 100 a data store can enable. Rather than choosing a hundred of them, enable the twelve tools above. They let the agent find and run any tool your access profiles allow: +The C1.ai gateway publishes far more tools than the 100 a data store can enable. Rather than choosing a hundred of them, enable the twelve tools above. They let the agent find and run any tool your access profiles allow: | Tool | What it does | | :--- | :--- | @@ -666,10 +666,10 @@ The C1 gateway publishes far more tools than the 100 a data store can enable. Ra | `get_execution` | Collects the result of a program that ran too long to answer inline | | `list_guides`, `load_guide` | Fetch usage guides for the more involved flows | | `create_vfs`, `create_vfs_artifact`, `list_vfs_files`, `get_vfs_download_url` | Give that program a scratch filesystem, and hand results back as files | -| `find_api_objects`, `count_api_objects` | Look up and count C1 objects such as users, apps, and entitlements, without writing a program | +| `find_api_objects`, `count_api_objects` | Look up and count C1.ai objects such as users, apps, and entitlements, without writing a program | | `query_metrics` | Return bucketed time series for reporting questions in one call | -Add whichever named C1 actions your users ask for by name on top of those, and the rest stay reachable through `search_tools`. +Add whichever named C1.ai actions your users ask for by name on top of those, and the rest stay reachable through `search_tools`. Enable `get_execution` alongside `execute`. A program that runs longer than about 25 seconds returns a pending status and an execution ID instead of a result, and `get_execution` is what collects it. Without it those runs cannot be recovered and the agent reports a failure for work that actually succeeded. @@ -693,11 +693,11 @@ A `401` entry on its own is normal: the console retries and a successful reload ## Verify the Gemini Enterprise connection -Seeing actions listed does not confirm your credentials work. You confirm the setup only when a user successfully calls a C1 tool. +Seeing actions listed does not confirm your credentials work. You confirm the setup only when a user successfully calls a C1.ai tool. -Open your Gemini Enterprise web app as an end user who has C1 tool access. +Open your Gemini Enterprise web app as an end user who has C1.ai tool access. In the message box, select the **Connectors** icon. Your connector is listed with an **Authorize** link beside it. @@ -706,30 +706,30 @@ In the message box, select the **Connectors** icon. Your connector is listed wit Select **Authorize**, sign in through your identity provider, and approve. The connector then shows a toggle, switched on. -Every user does this once, for themselves. Enabling actions as an administrator authorizes nobody. Until a user authorizes here, the assistant answers that it has no C1 integration, even though the actions are enabled and the connector is **Active**. +Every user does this once, for themselves. Enabling actions as an administrator authorizes nobody. Until a user authorizes here, the assistant answers that it has no C1.ai integration, even though the actions are enabled and the connector is **Active**. -Ask a question that needs a C1 tool, naming the connector, such as "Using the C1 connector, list the access reviews in C1." +Ask a question that needs a C1.ai tool, naming the connector, such as "Using the C1.ai connector, list the access reviews in C1.ai." The assistant names the action it wants to call and waits. Select **Send** to confirm it. -In C1, go to **AI** > **C1 Gateway** and select the **AI clients** tab. Gemini Enterprise is listed with a registration type of **CIMD**, and **People connected** counts the users who have authorized it. The **AI connections** tab shows one row per user. Users can see their own connections under their profile menu at **AI & API** > **AI connections**. +In C1.ai, go to **AI** > **C1 Gateway** and select the **AI clients** tab. Gemini Enterprise is listed with a registration type of **CIMD**, and **People connected** counts the users who have authorized it. The **AI connections** tab shows one row per user. Users can see their own connections under their profile menu at **AI & API** > **AI connections**. The **Verified** column shows the domain that serves your client metadata document, so a self-hosted document reads `storage.googleapis.com` rather than a Google domain. That is expected while you host the document yourself. -Confirm the tool call was logged. Every call through C1 MCP records the end user, the tool, the result, and a denial reason when refused. See [Audit AI tool usage](/product/admin/audit-ai-tool-usage). +Confirm the tool call was logged. Every call through C1.ai MCP records the end user, the tool, the result, and a denial reason when refused. See [Audit AI tool usage](/product/admin/audit-ai-tool-usage). The connection is working, and every tool call is attributed to the user who made it. -If the agent does not call a tool, returns nothing, or reports a denial, see [Troubleshoot Gemini Enterprise connection errors](#troubleshoot-gemini-enterprise-connection-errors). A denial that names a missing toolset or access profile is C1 working as configured, not a broken integration. +If the agent does not call a tool, returns nothing, or reports a denial, see [Troubleshoot Gemini Enterprise connection errors](#troubleshoot-gemini-enterprise-connection-errors). A denial that names a missing toolset or access profile is C1.ai working as configured, not a broken integration. These examples use `conductor.one`. If your organization is on the EU data residency instance, substitute `c1eu.ai` in URLs, client IDs, and hostnames. @@ -743,20 +743,20 @@ If the agent does not call a tool, returns nothing, or reports a denial, see [Tr | `PERMISSION_DENIED` on `gcloud storage buckets create` or the `allUsers` binding | The caller lacks `roles/storage.admin` on the project. | Grant it. See [Required roles](#required-roles). | | **You must configure your access control settings before you continue**, and **Create** is greyed out | No identity provider is set for the app's location. | Set one, then return to the form. See [Set the identity provider](#set-the-identity-provider). | | **Client ID** and **Client Secret** are blank on the **Re-authenticate** panel | Expected. The console never displays stored credentials, on a working connector or a broken one. | Nothing to fix. To change them, type both in again and select **Verify Auth**. | -| `404` on the client metadata URL | Nothing is hosting a document at that URL, or the file is not publicly readable. | Confirm you are using a URL you host yourself. The C1-hosted URL is not available yet. See [Get the OAuth client ID](#get-the-oauth-client-id). | +| `404` on the client metadata URL | Nothing is hosting a document at that URL, or the file is not publicly readable. | Confirm you are using a URL you host yourself. The C1.ai-hosted URL is not available yet. See [Get the OAuth client ID](#get-the-oauth-client-id). | | **We encountered some problems during authentication** | The client ID is wrong, or the sign-in window was closed or blocked. | Confirm the client ID resolves, allow popups for the console, and retry **Verify Auth**. | -| The form will not accept an empty **Client Secret** | The console treats the field as required. | Enter `none`, as in [Create the data store](#create-the-data-store). C1 never reads it. | +| The form will not accept an empty **Client Secret** | The console treats the field as required. | Enter `none`, as in [Create the data store](#create-the-data-store). C1.ai never reads it. | | **Failed to reload custom actions** on a connector imported from Agent Registry | Registry-imported connectors fail discovery with `FAILED_PRECONDITION`. | Recreate the data store from the **Custom MCP Server** card. See [Create the data store](#create-the-data-store). | | **Failed to reload custom actions** on a connector that is **Active** | The most common cause by far is that the signed-in user has never opened the Gemini Enterprise web app. | Open the web app as that user, then reload again. See [Sign in to the web app](#sign-in-to-the-web-app). | | **Failed to reload custom actions**, and the user has signed in | The connector is still creating, `discoveryengine.googleapis.com` is not enabled, the user holds no license, or no identity provider is set. | Wait for **Active**, then check each in turn. See [Prepare Gemini Enterprise](#prepare-gemini-enterprise). | | **Reload custom actions** shows no error and no actions | Most often the reload is still running. It takes about 30 seconds. | Wait for the **Custom actions reloaded** confirmation, then reload the page. | -| The action list stays empty after the reload finishes | C1 returned an empty tool list for the authorizing user, which happens when that user has no toolset. | Assign the authorizing user an access profile that includes the tools you expect, then reload again. See [Tools and toolsets](/product/admin/tools-and-toolsets). | +| The action list stays empty after the reload finishes | C1.ai returned an empty tool list for the authorizing user, which happens when that user has no toolset. | Assign the authorizing user an access profile that includes the tools you expect, then reload again. See [Tools and toolsets](/product/admin/tools-and-toolsets). | | The assistant answers that it has "no ConductorOne integration" | The user has not authorized the connector in the web app. Enabling actions authorizes nobody. | In the message box, open **Connectors** and select **Authorize** beside your connector. See [Verify the Gemini Enterprise connection](#verify-the-gemini-enterprise-connection). | -| The assistant picks a web search instead of a C1 action | No enabled action matches the request, so nothing is callable. | Enable the actions the request needs, and name the connector in the prompt. | -| A user's tool calls are denied while another user's succeed | C1 is enforcing that user's access profile. This is expected behavior. | Check the denial reason in the audit log. See [Audit AI tool usage](/product/admin/audit-ai-tool-usage). | +| The assistant picks a web search instead of a C1.ai action | No enabled action matches the request, so nothing is callable. | Enable the actions the request needs, and name the connector in the prompt. | +| A user's tool calls are denied while another user's succeed | C1.ai is enforcing that user's access profile. This is expected behavior. | Check the denial reason in the audit log. See [Audit AI tool usage](/product/admin/audit-ai-tool-usage). | | Authorization works, then breaks about an hour later | The connector uses a dynamically registered client whose secret expired. | Host a Client ID Metadata Document and use its URL as the client ID instead of registering dynamically. See [Get the OAuth client ID](#get-the-oauth-client-id). | | Tool calls fail immediately after a working **Verify Auth** | The token is not bound to your MCP endpoint. | Set **Authorization URL Parameters** to `&resource=https://-mcp.conductor.one/v1`. | -| `failed to fetch client metadata` | C1 fetches its own client metadata document over the public internet, and your tenant hostname does not resolve publicly. | This affects self-managed C1 deployments rather than C1 cloud tenants. [Contact the C1 support team](mailto:support@c1.ai). | +| `failed to fetch client metadata` | C1.ai fetches its own client metadata document over the public internet, and your tenant hostname does not resolve publicly. | This affects self-managed C1.ai deployments rather than C1.ai cloud tenants. [Contact the C1.ai support team](mailto:support@c1.ai). | To correct an authentication value, edit the existing connector's settings rather than recreating it. The connector name cannot be changed after creation, as noted in [Create the data store](#create-the-data-store), so changing it means creating a new data store and removing the old one. @@ -770,39 +770,39 @@ These constraints come from Gemini Enterprise and Google Cloud. - Gemini Enterprise supports **egress mode only**. It calls out to your MCP server; your MCP server cannot call in. - A data store supports a maximum of **100 enabled actions**. -C1's gateway already satisfies Google's other requirements for a custom MCP server: it uses StreamableHTTP transport rather than server-sent events, and it presents a certificate from a publicly trusted authority. +C1.ai's gateway already satisfies Google's other requirements for a custom MCP server: it uses StreamableHTTP transport rather than server-sent events, and it presents a certificate from a publicly trusted authority. ## Frequently asked questions about connecting Gemini Enterprise -No. The client ID identifies Gemini Enterprise as an application, not as a user. Every person authorizes individually through your identity provider and receives their own token. C1 evaluates each tool call against that person's access profiles, and their activity is logged under their own identity. +No. The client ID identifies Gemini Enterprise as an application, not as a user. Every person authorizes individually through your identity provider and receives their own token. C1.ai evaluates each tool call against that person's access profiles, and their activity is logged under their own identity. -The client is a public OAuth client with no secret. Client ID Metadata Document clients cannot use shared secrets, so C1 never reads the field. Security comes from the authorization code flow with PKCE, which you turn on with **Enable PKCE Support**. +The client is a public OAuth client with no secret. Client ID Metadata Document clients cannot use shared secrets, so C1.ai never reads the field. Security comes from the authorization code flow with PKCE, which you turn on with **Enable PKCE Support**. -No, and this was tested rather than taken on trust. A working connector reports `use_agent_gateway_egress: false`, so its traffic never passes through Agent Gateway, and a setup built with no gateway and no registry discovers tools and serves live tool calls normally. C1 governs the tool calls. +No, and this was tested rather than taken on trust. A working connector reports `use_agent_gateway_egress: false`, so its traffic never passes through Agent Gateway, and a setup built with no gateway and no registry discovers tools and serves live tool calls normally. C1.ai governs the tool calls. -Agent Registry is a catalog of approved MCP servers. Listing the C1 gateway there is a separate exercise that changes nothing about this integration. If you do list it, still create your data connector from the **Custom MCP Server** card: a connector imported from the registry fails tool discovery. +Agent Registry is a catalog of approved MCP servers. Listing the C1.ai gateway there is a separate exercise that changes nothing about this integration. If you do list it, still create your data connector from the **Custom MCP Server** card: a connector imported from the registry fails tool discovery. -In C1, open **AI** > **C1 Gateway**, select the **AI clients** tab, find the Gemini Enterprise client, and use its **kill switch**. It revokes all tokens for that client immediately, for every user. To cut off one person instead, use **Revoke** on their row in the **AI connections** tab. See [Manage AI clients](/product/admin/ai-clients). +In C1.ai, open **AI** > **C1 Gateway**, select the **AI clients** tab, find the Gemini Enterprise client, and use its **kill switch**. It revokes all tokens for that client immediately, for every user. To cut off one person instead, use **Revoke** on their row in the **AI connections** tab. See [Manage AI clients](/product/admin/ai-clients). -Yes. Every tool call through C1 MCP is logged with the end user, the tool, the result, and a denial reason when refused. See [Audit AI tool usage](/product/admin/audit-ai-tool-usage). +Yes. Every tool call through C1.ai MCP is logged with the end user, the tool, the result, and a denial reason when refused. See [Audit AI tool usage](/product/admin/audit-ai-tool-usage). ## Pages related to governing AI tool access -These pages cover the C1 side of the integration. +These pages cover the C1.ai side of the integration. - [Tools and toolsets](/product/admin/tools-and-toolsets) covers the access profiles that decide which tools each user can call. - [Manage AI clients](/product/admin/ai-clients) covers lifecycle states, the kill switch, and allowed client types. -- [Connect to the C1 MCP](/product/admin/c1-mcp) covers the same gateway from desktop AI assistants. -- [Audit AI tool usage](/product/admin/audit-ai-tool-usage) covers what C1 logs for every tool call. +- [Connect to the C1.ai MCP](/product/admin/c1-mcp) covers the same gateway from desktop AI assistants. +- [Audit AI tool usage](/product/admin/audit-ai-tool-usage) covers what C1.ai logs for every tool call. diff --git a/product/admin/mcp-server/github.mdx b/product/admin/mcp-server/github.mdx index d13b6d16..1a67de1f 100644 --- a/product/admin/mcp-server/github.mdx +++ b/product/admin/mcp-server/github.mdx @@ -1,37 +1,37 @@ --- title: Set up the GitHub MCP server -description: Connect GitHub to C1 through the GitHub API or GitHub's own hosted MCP server, then register the server and govern its tools. +description: Connect GitHub to C1.ai through the GitHub API or GitHub's own hosted MCP server, then register the server and govern its tools. og:title: Set up the GitHub MCP server -og:description: Connect GitHub to C1 through the GitHub API or GitHub's own hosted MCP server, then register the server and govern its tools. +og:description: Connect GitHub to C1.ai through the GitHub API or GitHub's own hosted MCP server, then register the server and govern its tools. sidebarTitle: GitHub --- {/* Editor Refresh: 2026-07-24 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -C1 can govern GitHub access two ways. Both let your AI clients read from and act on GitHub through governed MCP tools, but they come from different places and appear as two separate entries in your MCP server catalog: +C1.ai can govern GitHub access two ways. Both let your AI clients read from and act on GitHub through governed MCP tools, but they come from different places and appear as two separate entries in your MCP server catalog: -- **GitHub MCP** — listed as plain **GitHub** in your catalog. C1 registers GitHub's own hosted MCP server (`api.githubcopilot.com`) as a downstream server C1 governs. GitHub doesn't support dynamic client registration (DCR), so authentication is per-user OAuth through a GitHub OAuth App you register once, or a shared personal access token. Tool calls run with the connected user's granted OAuth scopes (or the token's permissions), against GitHub's own broader tool set — including cross-item search, discussions, and security alerts. -- **GitHub API** — C1 hosts its own MCP server that translates GitHub's REST API into tools. You choose between per-user OAuth or a shared personal access token, and access follows the OAuth app's requested scopes or the token's repository permissions. +- **GitHub MCP** — listed as plain **GitHub** in your catalog. C1.ai registers GitHub's own hosted MCP server (`api.githubcopilot.com`) as a downstream server C1.ai governs. GitHub doesn't support dynamic client registration (DCR), so authentication is per-user OAuth through a GitHub OAuth App you register once, or a shared personal access token. Tool calls run with the connected user's granted OAuth scopes (or the token's permissions), against GitHub's own broader tool set — including cross-item search, discussions, and security alerts. +- **GitHub API** — C1.ai hosts its own MCP server that translates GitHub's REST API into tools. You choose between per-user OAuth or a shared personal access token, and access follows the OAuth app's requested scopes or the token's repository permissions. | | GitHub MCP | GitHub API | | :--- | :--- | :--- | -| **Who hosts the MCP server** | GitHub | C1 | +| **Who hosts the MCP server** | GitHub | C1.ai | | **Authentication** | Per-user OAuth (no dynamic client registration — requires a GitHub OAuth App), or a personal access token | Per-user OAuth (requires a GitHub OAuth App), or a personal access token | | **Access scoping** | The OAuth scopes granted at authorization, or the personal access token's permissions | The OAuth app's requested scopes, or the personal access token's repository permissions | | **Tool surface** | GitHub's own tool set: repositories, issues, pull requests, Actions workflows, discussions, security alerts, and notifications | Repositories, pull requests, issues, Actions, and organization data, mapped to GitHub API endpoints | -| **Setup effort** | Register a GitHub OAuth App (or generate a token), then register in C1 | Register a GitHub OAuth App (or generate a token), then register in C1 | +| **Setup effort** | Register a GitHub OAuth App (or generate a token), then register in C1.ai | Register a GitHub OAuth App (or generate a token), then register in C1.ai | -Use the native **GitHub MCP** option (listed as plain **GitHub** in your catalog) if you want GitHub's own broader, agentic tool set, including cross-item search, discussions, and security alerts. Use **GitHub API** if you want C1's own curated tool surface mapped directly to GitHub API endpoints. +Use the native **GitHub MCP** option (listed as plain **GitHub** in your catalog) if you want GitHub's own broader, agentic tool set, including cross-item search, discussions, and security alerts. Use **GitHub API** if you want C1.ai's own curated tool surface mapped directly to GitHub API endpoints. -C1 registers as a client of GitHub's own hosted MCP server ([GitHub MCP Server](https://github.com/github/github-mcp-server)) rather than translating GitHub's REST API itself. Your users' AI clients still only ever see C1-governed MCP tools, but C1 proxies each tool call straight through to `api.githubcopilot.com` under the connected user's authorized session, then returns the result. The tools available are exactly the ones GitHub's hosted MCP server exposes — C1 doesn't reshape or add to them. +C1.ai registers as a client of GitHub's own hosted MCP server ([GitHub MCP Server](https://github.com/github/github-mcp-server)) rather than translating GitHub's REST API itself. Your users' AI clients still only ever see C1.ai-governed MCP tools, but C1.ai proxies each tool call straight through to `api.githubcopilot.com` under the connected user's authorized session, then returns the result. The tools available are exactly the ones GitHub's hosted MCP server exposes — C1.ai doesn't reshape or add to them. ## Before you begin @@ -40,12 +40,12 @@ C1 registers as a client of GitHub's own hosted MCP server ([GitHub MCP Server]( - If you'd rather not register an OAuth App, this option also accepts a GitHub personal access token as a shared bearer credential. See **Use a personal access token instead** below. -In your MCP server catalog, this option is listed as **GitHub** — distinct from the **GitHub API** entry, which connects through C1's own MCP server. If you don't see either, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +In your MCP server catalog, this option is listed as **GitHub** — distinct from the **GitHub API** entry, which connects through C1.ai's own MCP server. If you don't see either, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Set up per-user OAuth -Per-user OAuth is the recommended way to connect — each user authorizes individually, and every tool call runs under their own GitHub identity and permissions. Unlike C1's other native MCP integrations, GitHub doesn't support dynamic client registration for this server, so you need to register a GitHub OAuth App yourself before C1 can prompt users to connect. +Per-user OAuth is the recommended way to connect — each user authorizes individually, and every tool call runs under their own GitHub identity and permissions. Unlike C1.ai's other native MCP integrations, GitHub doesn't support dynamic client registration for this server, so you need to register a GitHub OAuth App yourself before C1.ai can prompt users to connect. First, create a GitHub OAuth App that users will authorize through: @@ -57,13 +57,13 @@ In GitHub, go to **Settings** > **Developer settings** > **OAuth Apps** and sele Fill in the registration form: - **Application name** — a recognizable name such as `C1`. -- **Homepage URL** — your C1 tenant URL, or `https://www.c1.ai`. -- **Authorization callback URL** — set this exactly to whichever matches your C1 tenant's domain (GitHub OAuth Apps allow only one callback URL, unlike GitHub Apps): +- **Homepage URL** — your C1.ai tenant URL, or `https://www.c1.ai`. +- **Authorization callback URL** — set this exactly to whichever matches your C1.ai tenant's domain (GitHub OAuth Apps allow only one callback URL, unlike GitHub Apps): - Default instance: `https://accounts.conductor.one/auth/callback` - EU data residency instance: `https://accounts.c1eu.ai/auth/callback` -Select **Register application**, then copy the **Client ID**. Select **Generate a new client secret** and copy the secret — GitHub shows it only once. Store it securely, and if it's ever exposed, generate a new one, update C1, then delete the old one ([best practices for creating an OAuth app](https://docs.github.com/en/apps/oauth-apps/building-oauth-apps/best-practices-for-creating-an-oauth-app)). +Select **Register application**, then copy the **Client ID**. Select **Generate a new client secret** and copy the secret — GitHub shows it only once. Store it securely, and if it's ever exposed, generate a new one, update C1.ai, then delete the old one ([best practices for creating an OAuth app](https://docs.github.com/en/apps/oauth-apps/building-oauth-apps/best-practices-for-creating-an-oauth-app)). @@ -77,13 +77,13 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **OAuth2 — per-user passthrough** and enter your OAuth app's **client ID** and **client secret**. -Save your changes. The first time a user calls a GitHub tool from their AI client, they're redirected to GitHub to sign in (if they aren't already) and approve the requested scopes, then returned to C1 ([authorizing OAuth apps](https://docs.github.com/en/apps/oauth-apps/building-oauth-apps/authorizing-oauth-apps)). +Save your changes. The first time a user calls a GitHub tool from their AI client, they're redirected to GitHub to sign in (if they aren't already) and approve the requested scopes, then returned to C1.ai ([authorizing OAuth apps](https://docs.github.com/en/apps/oauth-apps/building-oauth-apps/authorizing-oauth-apps)). ## What access is granted -When a user authorizes, C1 requests these scopes on GitHub's consent screen ([scopes for OAuth apps](https://docs.github.com/en/apps/oauth-apps/building-oauth-apps/scopes-for-oauth-apps)): +When a user authorizes, C1.ai requests these scopes on GitHub's consent screen ([scopes for OAuth apps](https://docs.github.com/en/apps/oauth-apps/building-oauth-apps/scopes-for-oauth-apps)): - `repo` — full read/write access to public and private repositories, including code, commit statuses, invitations, collaborators, deployment statuses, and webhooks. - `read:org` — read-only access to organization membership, organization projects, and team membership. @@ -95,7 +95,7 @@ When a user authorizes, C1 requests these scopes on GitHub's consent screen ([sc - `workflow` — the ability to add and update GitHub Actions workflow files. - `codespace` — the ability to create and manage codespaces. -Tool calls then run with the connected user's own GitHub permissions across whichever of these scopes they hold — for example, a user without `write:packages` can't publish a package through a GitHub tool even though C1 requested that scope. +Tool calls then run with the connected user's own GitHub permissions across whichever of these scopes they hold — for example, a user without `write:packages` can't publish a package through a GitHub tool even though C1.ai requested that scope. ## Use a personal access token instead @@ -112,18 +112,18 @@ Copy the token — GitHub shows it only once. Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-server) and select **GitHub** from the catalog. -When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Bearer token** and paste the token. C1 sends it as `Authorization: Bearer ` on every request. +When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Bearer token** and paste the token. C1.ai sends it as `Authorization: Bearer ` on every request. ## How GitHub MCP credentials are shared - **Per-user OAuth.** Each user authorizes with their own GitHub account, so tool calls run under that user's GitHub identity and inherit only the scopes they granted. GitHub attributes each action to the individual user. -- **Personal access token.** Every user's tool calls use the one token you provided, so GitHub sees a single shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). +- **Personal access token.** Every user's tool calls use the one token you provided, so GitHub sees a single shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). ## Discover and govern tools -After you register the server, C1 runs tool discovery against GitHub's hosted MCP server. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against GitHub's hosted MCP server. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -135,16 +135,16 @@ Tool discovery runs even if authentication isn't complete yet, so seeing discove ## Manage access to GitHub MCP -- **Rotate the OAuth client secret** on your OAuth app's settings page in GitHub (**Settings** > **Developer settings** > **OAuth Apps**), then update the secret on the server's authentication settings in C1. -- **Rotate a personal access token** by generating a new one in GitHub and updating it in C1. Set an expiration on the token so it rotates on a schedule. -- **An individual user can revoke their own authorization at any time.** In GitHub, go to **Settings** > **Applications** > **Authorized OAuth Apps**, then select **Revoke** next to C1 ([reviewing your authorized OAuth apps](https://docs.github.com/en/apps/oauth-apps/using-oauth-apps/reviewing-your-authorized-oauth-apps)). +- **Rotate the OAuth client secret** on your OAuth app's settings page in GitHub (**Settings** > **Developer settings** > **OAuth Apps**), then update the secret on the server's authentication settings in C1.ai. +- **Rotate a personal access token** by generating a new one in GitHub and updating it in C1.ai. Set an expiration on the token so it rotates on a schedule. +- **An individual user can revoke their own authorization at any time.** In GitHub, go to **Settings** > **Applications** > **Authorized OAuth Apps**, then select **Revoke** next to C1.ai ([reviewing your authorized OAuth apps](https://docs.github.com/en/apps/oauth-apps/using-oauth-apps/reviewing-your-authorized-oauth-apps)). - **An organization owner can restrict or revoke OAuth App access org-wide** if the organization has third-party application access restrictions enabled ([about OAuth App access restrictions](https://docs.github.com/en/organizations/managing-oauth-access-to-your-organizations-data/about-oauth-app-access-restrictions)). -C1 hosts the GitHub MCP server, so your users' AI clients only ever see MCP tools — they never call GitHub directly. When an AI client calls one of these tools, C1 makes the matching request to the GitHub API using the credentials you configure here, then returns the result to the AI client. The credentials you set up below are what C1 uses to call GitHub on your users' behalf. +C1.ai hosts the GitHub MCP server, so your users' AI clients only ever see MCP tools — they never call GitHub directly. When an AI client calls one of these tools, C1.ai makes the matching request to the GitHub API using the credentials you configure here, then returns the result to the AI client. The credentials you set up below are what C1.ai uses to call GitHub on your users' behalf. GitHub supports two ways to authenticate, and you choose one when you register the server: @@ -160,7 +160,7 @@ For a deeper comparison of shared versus per-user credentials, see [Configure au - For a personal access token, you need the GitHub account whose access the token should carry. -In your MCP server catalog, this option is listed as **GitHub API** — distinct from the **GitHub** entry, which connects to GitHub's own hosted MCP server. If you don't see either, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +In your MCP server catalog, this option is listed as **GitHub API** — distinct from the **GitHub** entry, which connects to GitHub's own hosted MCP server. If you don't see either, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Option 1: Set up per-user OAuth @@ -169,7 +169,7 @@ With per-user OAuth, you register one GitHub OAuth app and each user authorizes ### Create a GitHub OAuth app -Register an OAuth app in GitHub so C1 can prompt each user to authorize with their own account. For the full walkthrough, see GitHub's [latest guide to creating an OAuth app](https://docs.github.com/en/apps/oauth-apps/building-oauth-apps/creating-an-oauth-app). +Register an OAuth app in GitHub so C1.ai can prompt each user to authorize with their own account. For the full walkthrough, see GitHub's [latest guide to creating an OAuth app](https://docs.github.com/en/apps/oauth-apps/building-oauth-apps/creating-an-oauth-app). @@ -179,8 +179,8 @@ In GitHub, go to **Settings** > **Developer settings** > **OAuth Apps** and sele Fill in the registration form: - **Application name** — a recognizable name such as `C1`. -- **Homepage URL** — your C1 tenant URL, or `https://www.c1.ai`. -- **Authorization callback URL** — set this exactly to whichever matches your C1 tenant's domain (GitHub OAuth apps allow only one callback URL): +- **Homepage URL** — your C1.ai tenant URL, or `https://www.c1.ai`. +- **Authorization callback URL** — set this exactly to whichever matches your C1.ai tenant's domain (GitHub OAuth apps allow only one callback URL): - Default instance: `https://accounts.conductor.one/auth/callback` - EU data residency instance: `https://accounts.c1eu.ai/auth/callback` @@ -214,7 +214,7 @@ A personal access token authenticates every user as one shared GitHub identity. ### Create a personal access token -Generate a fine-grained personal access token in GitHub for C1 to authenticate with. For the full walkthrough, see GitHub's [guide to creating a fine-grained personal access token](https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/managing-your-personal-access-tokens#creating-a-fine-grained-personal-access-token). +Generate a fine-grained personal access token in GitHub for C1.ai to authenticate with. For the full walkthrough, see GitHub's [guide to creating a fine-grained personal access token](https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/managing-your-personal-access-tokens#creating-a-fine-grained-personal-access-token). @@ -231,7 +231,7 @@ Select **Generate token** and copy it. GitHub shows the token only once. -For a shared production setup, create the token from a dedicated service-account user so activity is attributable to C1 rather than a person. +For a shared production setup, create the token from a dedicated service-account user so activity is attributable to C1.ai rather than a person. ### Register the server with a token @@ -245,7 +245,7 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Bearer token** and paste your personal access token. -Save your changes. C1 starts a sync that discovers the tools the GitHub server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the GitHub server exposes. @@ -254,13 +254,13 @@ Save your changes. C1 starts a sync that discovers the tools the GitHub server e How GitHub sees your users' activity depends on the method you chose: - **Per-user OAuth.** Each user authorizes with their own GitHub account, so tool calls run under that user's GitHub identity and inherit only the access they already have. GitHub attributes each action to the individual user. -- **Personal access token.** Every user's tool calls use the one token you provided, so GitHub sees a single shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). +- **Personal access token.** Every user's tool calls use the one token you provided, so GitHub sees a single shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). ## Discover and govern tools -After you register the server, C1 runs tool discovery against GitHub. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against GitHub. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -272,8 +272,8 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your GitHub credentials -- **Rotate the OAuth client secret** in your GitHub OAuth app under **Settings** > **Developer settings** > **OAuth Apps**, then update the secret on the server's authentication settings in C1. -- **Rotate a personal access token** by generating a new one in GitHub and updating it in C1. Set an expiration on the token so it rotates on a schedule. +- **Rotate the OAuth client secret** in your GitHub OAuth app under **Settings** > **Developer settings** > **OAuth Apps**, then update the secret on the server's authentication settings in C1.ai. +- **Rotate a personal access token** by generating a new one in GitHub and updating it in C1.ai. Set an expiration on the token so it rotates on a schedule. - **Adjust access** by editing the OAuth app's scopes or the token's repository permissions in GitHub. diff --git a/product/admin/mcp-server/gong.mdx b/product/admin/mcp-server/gong.mdx index 8916958d..3e205a63 100644 --- a/product/admin/mcp-server/gong.mdx +++ b/product/admin/mcp-server/gong.mdx @@ -1,26 +1,26 @@ --- title: Set up the Gong MCP server -description: Generate Gong API credentials, then register the Gong MCP server in C1 and govern the tools your AI clients can call. +description: Generate Gong API credentials, then register the Gong MCP server in C1.ai and govern the tools your AI clients can call. og:title: Set up the Gong MCP server -og:description: Generate Gong API credentials, then register the Gong MCP server in C1 and govern the tools your AI clients can call. +og:description: Generate Gong API credentials, then register the Gong MCP server in C1.ai and govern the tools your AI clients can call. sidebarTitle: Gong --- {/* Editor Refresh: 2026-06-11 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -The Gong MCP server lets you govern access to Gong — calls, transcripts, users, scorecards, deals, sequences, and permission profiles — as tools your AI clients can call through C1. +The Gong MCP server lets you govern access to Gong — calls, transcripts, users, scorecards, deals, sequences, and permission profiles — as tools your AI clients can call through C1.ai. -Gong authenticates with a generated Access Key and Access Key Secret pair that C1 sends as HTTP basic auth. A single credential pair authenticates everyone, so all tool calls reach Gong as one shared identity. +Gong authenticates with a generated Access Key and Access Key Secret pair that C1.ai sends as HTTP basic auth. A single credential pair authenticates everyone, so all tool calls reach Gong as one shared identity. -## How C1 connects to Gong +## How C1.ai connects to Gong -C1 hosts the Gong MCP server, so your users' AI clients only ever see MCP tools — they never call Gong directly. When an AI client calls one of these tools, C1 makes the matching request to the Gong API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Gong MCP server, so your users' AI clients only ever see MCP tools — they never call Gong directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Gong API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call Gong on your users' behalf. +The credentials you set up below are what C1.ai uses to call Gong on your users' behalf. ## Before you begin @@ -28,12 +28,12 @@ The credentials you set up below are what C1 uses to call Gong on your users' be - A Gong **Technical Administrator** account. Only a Technical Administrator can generate API credentials. If you don't have that role, find your Gong tech admin in Gong's [Find your Technical or Business Admin](https://help.gong.io/v1/docs/find-your-technical-or-business-admin) help article. -If you don't see **Gong** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **Gong** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Generate Gong API credentials -Generate an Access Key and Access Key Secret in Gong so C1 can authenticate to the Gong API. For Gong's own walkthrough, see [Receive access to the API](https://help.gong.io/docs/receive-access-to-the-api). +Generate an Access Key and Access Key Secret in Gong so C1.ai can authenticate to the Gong API. For Gong's own walkthrough, see [Receive access to the API](https://help.gong.io/docs/receive-access-to-the-api). @@ -53,15 +53,15 @@ Note your Gong API base URL. Gong runs each customer's API on a regional subdoma -For a shared production setup, generate the credentials under a dedicated service-account user so activity is attributable to C1 rather than a person. +For a shared production setup, generate the credentials under a dedicated service-account user so activity is attributable to C1.ai rather than a person. ## How Gong credentials are shared -Every user's tool calls use the one Access Key and Access Key Secret pair you provided, so Gong sees a single shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared production setup, generate the credentials from a dedicated service-account user so Gong activity is attributable to C1 rather than a person. +Every user's tool calls use the one Access Key and Access Key Secret pair you provided, so Gong sees a single shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared production setup, generate the credentials from a dedicated service-account user so Gong activity is attributable to C1.ai rather than a person. For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## Register the Gong MCP server in C1 +## Register the Gong MCP server in C1.ai With your credential pair ready, register the server and provide your credentials. @@ -76,13 +76,13 @@ Enter your Gong instance URL, such as `https://acme.api.gong.io`. When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Basic auth** and enter your **Access Key** as the username and your **Access Key Secret** as the password. -Save your changes. C1 starts a sync that discovers the tools the Gong server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Gong server exposes. ## Discover and govern tools -After you register the server, C1 runs tool discovery against Gong. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Gong. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -94,5 +94,5 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Gong credentials -- **Rotate the credential pair** in **Company Settings** > **Ecosystem** > **API**: revoke the existing key, select **Get API Key** to issue a fresh pair, then update the credentials in C1. Gong emails the technical administrator before a key expires so you can rotate proactively. +- **Rotate the credential pair** in **Company Settings** > **Ecosystem** > **API**: revoke the existing key, select **Get API Key** to issue a fresh pair, then update the credentials in C1.ai. Gong emails the technical administrator before a key expires so you can rotate proactively. - **Watch your rate limits.** By default Gong allows 3 requests per second and 10,000 requests per day per company. To request more headroom, contact Gong support. diff --git a/product/admin/mcp-server/google-analytics-admin.mdx b/product/admin/mcp-server/google-analytics-admin.mdx index 8ae6ca0f..ab07f029 100644 --- a/product/admin/mcp-server/google-analytics-admin.mdx +++ b/product/admin/mcp-server/google-analytics-admin.mdx @@ -1,18 +1,18 @@ --- title: Set up the Google Analytics Admin MCP server -description: Connect Google Analytics Admin to C1 with per-user OAuth or a service account, then register the MCP server and govern its tools. +description: Connect Google Analytics Admin to C1.ai with per-user OAuth or a service account, then register the MCP server and govern its tools. og:title: Set up the Google Analytics Admin MCP server -og:description: Connect Google Analytics Admin to C1 with per-user OAuth or a service account, then register the MCP server and govern its tools. +og:description: Connect Google Analytics Admin to C1.ai with per-user OAuth or a service account, then register the MCP server and govern its tools. sidebarTitle: Google Analytics Admin --- {/* Editor Refresh: 2026-06-11 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -The Google Analytics Admin MCP server lets you govern access to Google Analytics 4 configuration — accounts, properties, data streams, custom dimensions, conversions, and account-level user permissions — as tools your AI clients can call through C1. +The Google Analytics Admin MCP server lets you govern access to Google Analytics 4 configuration — accounts, properties, data streams, custom dimensions, conversions, and account-level user permissions — as tools your AI clients can call through C1.ai. Google Analytics Admin supports two ways to authenticate, and you choose one when you register the server: @@ -21,11 +21,11 @@ Google Analytics Admin supports two ways to authenticate, and you choose one whe For a deeper comparison of shared versus per-user credentials, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## How C1 connects to Google Analytics Admin +## How C1.ai connects to Google Analytics Admin -C1 hosts the Google Analytics Admin MCP server, so your users' AI clients only ever see MCP tools — they never call Google Analytics Admin directly. When an AI client calls one of these tools, C1 makes the matching request to the Google Analytics Admin API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Google Analytics Admin MCP server, so your users' AI clients only ever see MCP tools — they never call Google Analytics Admin directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Google Analytics Admin API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call Google Analytics Admin on your users' behalf. +The credentials you set up below are what C1.ai uses to call Google Analytics Admin on your users' behalf. ## Before you begin @@ -34,7 +34,7 @@ The credentials you set up below are what C1 uses to call Google Analytics Admin - The right GA4 role for the operations you need. Reads need at least **Viewer**, edits and creates need **Editor** at the property level or **Administrator** at the account level, and managing GA4 user permissions needs **Administrator** at the account level. -If you don't see **Google Analytics Admin** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **Google Analytics Admin** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. @@ -47,11 +47,11 @@ With per-user OAuth, you register one Google OAuth client and each user authoriz ### Create a Google OAuth client -Create an OAuth client in Google Cloud so C1 can prompt each user to authorize with their own Google account. +Create an OAuth client in Google Cloud so C1.ai can prompt each user to authorize with their own Google account. -Sign in to the Google Cloud console and create or select a project for C1. +Sign in to the Google Cloud console and create or select a project for C1.ai. Go to **APIs & Services** > **Library**, search for **Google Analytics Admin API**, and select **Enable**. @@ -63,7 +63,7 @@ Go to **APIs & Services** > **OAuth consent screen**. Choose **Internal** for a Go to **APIs & Services** > **Credentials** > **Create Client** > **Web application**. For full details, see Google's [Manage OAuth Clients](https://support.google.com/cloud/answer/15549257) documentation. -Under **Authorized redirect URIs**, add exactly whichever matches your C1 tenant's domain: +Under **Authorized redirect URIs**, add exactly whichever matches your C1.ai tenant's domain: - Default instance: `https://accounts.conductor.one/auth/callback` - EU data residency instance: `https://accounts.c1eu.ai/auth/callback` @@ -73,7 +73,7 @@ Select **Create**, then copy the **Client ID** and **Client secret**. Google sho -Confirm that each user who authorizes has the GA4 role needed for the operations C1 should perform, in the GA4 Admin UI under **Account Access Management** or **Property Access Management**. +Confirm that each user who authorizes has the GA4 role needed for the operations C1.ai should perform, in the GA4 Admin UI under **Account Access Management** or **Property Access Management**. ### Register the server with OAuth @@ -93,11 +93,11 @@ Save your changes. The first time a user calls a Google Analytics Admin tool fro ## Option 2: Use a service account -A Google service account authenticates every user as one shared identity. C1 signs a JWT with the service account's key to obtain access tokens. Use this for automated administration where per-user attribution in Analytics isn't required. +A Google service account authenticates every user as one shared identity. C1.ai signs a JWT with the service account's key to obtain access tokens. Use this for automated administration where per-user attribution in Analytics isn't required. ### Create a service account and grant property access -Create a Google service account, download its key, and grant it the GA4 access C1 will use. +Create a Google service account, download its key, and grant it the GA4 access C1.ai will use. @@ -123,7 +123,7 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **JWT Bearer (RFC 7523)** and provide the service account's JSON key and the scopes you need, such as `analytics.readonly` and `analytics.edit`. -Save your changes. C1 starts a sync that discovers the tools the Google Analytics Admin server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Google Analytics Admin server exposes. @@ -132,13 +132,13 @@ Save your changes. C1 starts a sync that discovers the tools the Google Analytic How Google Analytics sees your users' activity depends on the method you chose: - **Per-user OAuth.** Each user authorizes with their own Google account, so tool calls run under that user's Analytics identity and inherit only the access they already have. Google attributes each action to the individual user. -- **Service account.** Every user's tool calls use the one service account you configured, so Analytics sees a single shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). +- **Service account.** Every user's tool calls use the one service account you configured, so Analytics sees a single shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). ## Discover and govern tools -After you register the server, C1 runs tool discovery against Google Analytics Admin. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Google Analytics Admin. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -150,6 +150,6 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Google Analytics Admin credentials -- **Rotate the OAuth client secret** in your Google Cloud project under **APIs & Services** > **Credentials**, then update the secret on the server's authentication settings in C1. -- **Rotate the service account key** by generating a new JSON key in the Cloud Console, updating it in C1, then deleting the old key. +- **Rotate the OAuth client secret** in your Google Cloud project under **APIs & Services** > **Credentials**, then update the secret on the server's authentication settings in C1.ai. +- **Rotate the service account key** by generating a new JSON key in the Cloud Console, updating it in C1.ai, then deleting the old key. - **Adjust access** by editing the OAuth client's scopes, or by changing the service account's role in **Account Access Management** or **Property Access Management**. diff --git a/product/admin/mcp-server/google-analytics.mdx b/product/admin/mcp-server/google-analytics.mdx index 1cef84d2..150950f1 100644 --- a/product/admin/mcp-server/google-analytics.mdx +++ b/product/admin/mcp-server/google-analytics.mdx @@ -1,18 +1,18 @@ --- title: Set up the Google Analytics MCP server -description: Connect Google Analytics to C1 with per-user OAuth or a service account, then register the Google Analytics MCP server and govern its tools. +description: Connect Google Analytics to C1.ai with per-user OAuth or a service account, then register the Google Analytics MCP server and govern its tools. og:title: Set up the Google Analytics MCP server -og:description: Connect Google Analytics to C1 with per-user OAuth or a service account, then register the Google Analytics MCP server and govern its tools. +og:description: Connect Google Analytics to C1.ai with per-user OAuth or a service account, then register the Google Analytics MCP server and govern its tools. sidebarTitle: Google Analytics --- {/* Editor Refresh: 2026-06-11 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -The Google Analytics MCP server lets you govern access to Google Analytics 4 report data — dimensions, metrics, realtime events, pivot reports, and audience exports — as tools your AI clients can call through C1. +The Google Analytics MCP server lets you govern access to Google Analytics 4 report data — dimensions, metrics, realtime events, pivot reports, and audience exports — as tools your AI clients can call through C1.ai. Google Analytics supports two ways to authenticate, and you choose one when you register the server: @@ -21,11 +21,11 @@ Google Analytics supports two ways to authenticate, and you choose one when you For a deeper comparison of shared versus per-user credentials, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## How C1 connects to Google Analytics +## How C1.ai connects to Google Analytics -C1 hosts the Google Analytics MCP server, so your users' AI clients only ever see MCP tools — they never call Google Analytics directly. When an AI client calls one of these tools, C1 makes the matching request to the Google Analytics API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Google Analytics MCP server, so your users' AI clients only ever see MCP tools — they never call Google Analytics directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Google Analytics API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call Google Analytics on your users' behalf. +The credentials you set up below are what C1.ai uses to call Google Analytics on your users' behalf. ## Before you begin @@ -34,7 +34,7 @@ The credentials you set up below are what C1 uses to call Google Analytics on yo - Access to the GA4 properties you want to query. The user or service account must already have at least **Viewer** access on those properties. -If you don't see **Google Analytics** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **Google Analytics** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Option 1: Set up per-user OAuth @@ -43,11 +43,11 @@ With per-user OAuth, you register one Google OAuth client and each user authoriz ### Create a Google OAuth client -Create an OAuth client in Google Cloud so C1 can prompt each user to authorize with their own Google account. +Create an OAuth client in Google Cloud so C1.ai can prompt each user to authorize with their own Google account. -Sign in to the Google Cloud console and create or select a project for C1. +Sign in to the Google Cloud console and create or select a project for C1.ai. Go to **APIs & Services** > **Library**, search for **Google Analytics Data API**, and select **Enable**. @@ -59,7 +59,7 @@ Go to **APIs & Services** > **OAuth consent screen**. Choose **Internal** for a Go to **APIs & Services** > **Credentials** > **Create Client** > **Web application**. For full details, see Google's [Manage OAuth Clients](https://support.google.com/cloud/answer/15549257) documentation. -Under **Authorized redirect URIs**, add exactly whichever matches your C1 tenant's domain: +Under **Authorized redirect URIs**, add exactly whichever matches your C1.ai tenant's domain: - Default instance: `https://accounts.conductor.one/auth/callback` - EU data residency instance: `https://accounts.c1eu.ai/auth/callback` @@ -89,11 +89,11 @@ Save your changes. The first time a user calls a Google Analytics tool from thei ## Option 2: Use a service account -A Google service account authenticates every user as one shared identity. C1 signs a JWT with the service account's key to obtain access tokens. Use this for automated reporting where per-user attribution in Analytics isn't required. +A Google service account authenticates every user as one shared identity. C1.ai signs a JWT with the service account's key to obtain access tokens. Use this for automated reporting where per-user attribution in Analytics isn't required. ### Create a service account and grant property access -Create a Google service account, download its key, and grant it access to the GA4 properties C1 will query. +Create a Google service account, download its key, and grant it access to the GA4 properties C1.ai will query. @@ -119,7 +119,7 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **OAuth2 — JWT bearer** and provide the service account's JSON key and the scopes you need, such as `analytics.readonly`. -Save your changes. C1 starts a sync that discovers the tools the Google Analytics server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Google Analytics server exposes. @@ -128,13 +128,13 @@ Save your changes. C1 starts a sync that discovers the tools the Google Analytic How Google Analytics sees your users' activity depends on the method you chose: - **Per-user OAuth.** Each user authorizes with their own Google account, so tool calls run under that user's Analytics identity and inherit only the access they already have. Google attributes each action to the individual user. -- **Service account.** Every user's tool calls use the one service account you configured, so Analytics sees a single shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). +- **Service account.** Every user's tool calls use the one service account you configured, so Analytics sees a single shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). ## Discover and govern tools -After you register the server, C1 runs tool discovery against Google Analytics. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Google Analytics. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -146,6 +146,6 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Google Analytics credentials -- **Rotate the OAuth client secret** in your Google Cloud project under **APIs & Services** > **Credentials**, then update the secret on the server's authentication settings in C1. -- **Rotate the service account key** by generating a new JSON key in the Cloud Console, updating it in C1, then deleting the old key. +- **Rotate the OAuth client secret** in your Google Cloud project under **APIs & Services** > **Credentials**, then update the secret on the server's authentication settings in C1.ai. +- **Rotate the service account key** by generating a new JSON key in the Cloud Console, updating it in C1.ai, then deleting the old key. - **Adjust access** by editing the OAuth client's scopes, or by changing the service account's role in each GA4 property's **Property Access Management**. diff --git a/product/admin/mcp-server/google-cloud-project-setup.mdx b/product/admin/mcp-server/google-cloud-project-setup.mdx index 67ac9301..ad55fe68 100644 --- a/product/admin/mcp-server/google-cloud-project-setup.mdx +++ b/product/admin/mcp-server/google-cloud-project-setup.mdx @@ -18,12 +18,12 @@ Set up one Google Cloud project and reuse it for every Google MCP server — Goo ## What the project provides -When a user's AI client calls a Google tool, C1 makes the matching request to the Google API. Your Google Cloud project supplies three things that request depends on: +When a user's AI client calls a Google tool, C1.ai makes the matching request to the Google API. Your Google Cloud project supplies three things that request depends on: | What | Why it matters | | :--- | :--- | | **Enabled APIs** | Each connector calls a specific Google API (for example, the Gmail API). That API must be enabled in your project. | -| **OAuth client** | The client ID and secret C1 uses to let each user authorize with their own Google account. | +| **OAuth client** | The client ID and secret C1.ai uses to let each user authorize with their own Google account. | | **Quota project** | The project that Google attributes each request's quota and billing to. You enter this as the **Google Cloud Quota Project ID** when you register the server, and every caller must be allowed to use it. | The third item is the one most often missed — see [Grant users permission to use the project](#grant-users-permission-to-use-the-project). Skipping it is the most common cause of a failed Google connection. @@ -37,7 +37,7 @@ Pick the project that will own your OAuth credentials and receive API quota. It Sign in to the [Google Cloud console](https://console.cloud.google.com/). -Create a new project for C1, or select an existing one. Note its **Project ID** (for example, `acme-c1-mcp`) — you'll enter this exact value when you register each Google server. +Create a new project for C1.ai, or select an existing one. Note its **Project ID** (for example, `acme-c1-mcp`) — you'll enter this exact value when you register each Google server. **Optional.** The Workspace APIs in this guide don't require a billing account. If you plan to use a billing-gated Google API or need higher quota limits, link a billing account to the project. @@ -130,14 +130,14 @@ gcloud projects add-iam-policy-binding YOUR_PROJECT_ID \ ``` -IAM changes usually take effect within a minute but can take a few. If a user still sees `PERMISSION_DENIED` right after you grant access, have them retry shortly and reconnect their Google account so C1 mints a fresh token. +IAM changes usually take effect within a minute but can take a few. If a user still sees `PERMISSION_DENIED` right after you grant access, have them retry shortly and reconnect their Google account so C1.ai mints a fresh token. For the service-account option (see [Use a service account instead](#optional-use-a-service-account-instead)), the caller is the service account rather than each user — grant the Service Usage Consumer role to the service account instead of a user group. ## Create an OAuth client -Per-user OAuth needs one OAuth client in your project. Its client ID and secret let each user authorize C1 with their own Google account. +Per-user OAuth needs one OAuth client in your project. Its client ID and secret let each user authorize C1.ai with their own Google account. ### Configure the OAuth consent screen @@ -170,7 +170,7 @@ Create the OAuth client, then capture its ID and secret. Go to **APIs & Services** > **Credentials** > **Create Client** > **Web application**. For details, see Google's [Manage OAuth Clients](https://support.google.com/cloud/answer/15549257) documentation. -Under **Authorized redirect URIs**, add exactly whichever matches your C1 tenant's domain: +Under **Authorized redirect URIs**, add exactly whichever matches your C1.ai tenant's domain: - Default instance: `https://accounts.conductor.one/auth/callback` - EU data residency instance: `https://accounts.c1eu.ai/auth/callback` @@ -407,7 +407,7 @@ Then follow the connector-specific page for anything unique to that server: - [Google Analytics Admin](/product/admin/mcp-server/google-analytics-admin) -Connectors without a dedicated page above use the same [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-server) flow. If a Google connector you want isn't in your catalog yet, [contact the C1 support team](mailto:support@c1.ai). +Connectors without a dedicated page above use the same [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-server) flow. If a Google connector you want isn't in your catalog yet, [contact the C1.ai support team](mailto:support@c1.ai). ## Troubleshoot Google Cloud project errors @@ -416,7 +416,7 @@ Connectors without a dedicated page above use the same [Register an MCP server]( | :--- | :--- | :--- | | `PERMISSION_DENIED: Caller does not have required permission to use project ...` | The caller lacks `serviceusage.services.use` on the quota project. | Grant the **Service Usage Consumer** role — see [Grant users permission to use the project](#grant-users-permission-to-use-the-project). | | `SERVICE_DISABLED` / "API has not been used in project ... before or it is disabled" | The connector's API isn't enabled in the quota project. | Enable it — see [Enable the APIs for your connectors](#enable-the-apis-for-your-connectors). | -| Authorization flow fails after the user consents | The redirect URI doesn't match. | Set it to exactly whichever matches your C1 tenant's domain (default instance: `https://accounts.conductor.one/auth/callback`; EU data residency instance: `https://accounts.c1eu.ai/auth/callback`) — see [Create the client credentials](#create-the-client-credentials). | +| Authorization flow fails after the user consents | The redirect URI doesn't match. | Set it to exactly whichever matches your C1.ai tenant's domain (default instance: `https://accounts.conductor.one/auth/callback`; EU data residency instance: `https://accounts.c1eu.ai/auth/callback`) — see [Create the client credentials](#create-the-client-credentials). | | A restricted-scope warning blocks External users | The app needs Google verification for restricted scopes. | Use an **Internal** consent screen for Workspace-only use, or complete Google's verification for External use. | | "Google hasn't verified this app" blocks sign-in | The External app isn't verified and the user isn't a test user. | Add the user as a **test user** on the consent screen, or complete Google's verification. | diff --git a/product/admin/mcp-server/google-drive.mdx b/product/admin/mcp-server/google-drive.mdx index 55f91344..ac0718c1 100644 --- a/product/admin/mcp-server/google-drive.mdx +++ b/product/admin/mcp-server/google-drive.mdx @@ -1,37 +1,37 @@ --- title: Set up the Google Drive MCP server -description: Connect Google Drive to C1 through the Google Drive API or Google's own hosted MCP server, then register the server and govern its tools. +description: Connect Google Drive to C1.ai through the Google Drive API or Google's own hosted MCP server, then register the server and govern its tools. og:title: Set up the Google Drive MCP server -og:description: Connect Google Drive to C1 through the Google Drive API or Google's own hosted MCP server, then register the server and govern its tools. +og:description: Connect Google Drive to C1.ai through the Google Drive API or Google's own hosted MCP server, then register the server and govern its tools. sidebarTitle: Google Drive --- {/* Editor Refresh: 2026-07-24 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -C1 can govern Google Drive access two ways. Both let your AI clients read from and act on Drive through governed MCP tools, but they come from different places and appear as two separate entries in your MCP server catalog: +C1.ai can govern Google Drive access two ways. Both let your AI clients read from and act on Drive through governed MCP tools, but they come from different places and appear as two separate entries in your MCP server catalog: -- **Google Drive MCP** — listed as plain **Google Drive** in your catalog. C1 registers Google's own hosted Drive MCP server (`drivemcp.googleapis.com`) as a downstream server C1 governs. Authentication is per-user OAuth using a Google Cloud OAuth client you create — Google doesn't support dynamic client registration (DCR) for this server, so there's no bearer token or API key fallback either. Tool calls run with the connected user's own Drive permissions, scoped to whichever OAuth scopes you grant. -- **Google Drive API** — C1 hosts its own MCP server that translates the Google Drive REST API into tools. You choose between per-user OAuth or a service account with domain-wide delegation (Workspace only), and you scope access with the OAuth or delegated scopes you configure. +- **Google Drive MCP** — listed as plain **Google Drive** in your catalog. C1.ai registers Google's own hosted Drive MCP server (`drivemcp.googleapis.com`) as a downstream server C1.ai governs. Authentication is per-user OAuth using a Google Cloud OAuth client you create — Google doesn't support dynamic client registration (DCR) for this server, so there's no bearer token or API key fallback either. Tool calls run with the connected user's own Drive permissions, scoped to whichever OAuth scopes you grant. +- **Google Drive API** — C1.ai hosts its own MCP server that translates the Google Drive REST API into tools. You choose between per-user OAuth or a service account with domain-wide delegation (Workspace only), and you scope access with the OAuth or delegated scopes you configure. | | Google Drive MCP | Google Drive API | | :--- | :--- | :--- | -| **Who hosts the MCP server** | Google | C1 | +| **Who hosts the MCP server** | Google | C1.ai | | **Authentication** | Per-user OAuth with a Google Cloud OAuth client you create — no dynamic client registration, bearer token, or API key option | Per-user OAuth, or a service account with domain-wide delegation (Workspace only) | | **Access scoping** | The connected user's Drive permissions, within the OAuth scopes you grant (`drive`, `drive.readonly`, or `drive.file`) | The OAuth scopes you configure, or the scopes you delegate to the service account | | **Tool surface** | Google's own fixed tool set: search, read and download content, file metadata, permissions, recent files, plus file creation and copying | Files, folders, shared drives, permissions, comments, and revisions, mapped to Drive API endpoints | -| **Setup effort** | Create a Google Cloud OAuth client and enable the Drive MCP API, then register in C1 | Create an OAuth client or service account first, then register in C1 | +| **Setup effort** | Create a Google Cloud OAuth client and enable the Drive MCP API, then register in C1.ai | Create an OAuth client or service account first, then register in C1.ai | -Use the native **Google Drive MCP** option (listed as plain **Google Drive** in your catalog) if Google's own tool set covers what you need and per-user OAuth is acceptable for your tenant. Use **Google Drive API** if you need a shared service-account credential, or you want the broader tool surface — including permissions, comments, and revisions — that C1's own translation provides. +Use the native **Google Drive MCP** option (listed as plain **Google Drive** in your catalog) if Google's own tool set covers what you need and per-user OAuth is acceptable for your tenant. Use **Google Drive API** if you need a shared service-account credential, or you want the broader tool surface — including permissions, comments, and revisions — that C1.ai's own translation provides. -C1 registers as a client of Google's own hosted Drive MCP server ([Configure the Drive MCP server](https://developers.google.com/workspace/drive/api/guides/configure-mcp-server)) rather than translating the Google Drive REST API itself. Your users' AI clients still only ever see C1-governed MCP tools, but C1 proxies each tool call straight through to `drivemcp.googleapis.com` under the connected user's authorized session, then returns the result. The tools available are exactly the ones Google's own MCP server exposes — C1 doesn't reshape or add to them. +C1.ai registers as a client of Google's own hosted Drive MCP server ([Configure the Drive MCP server](https://developers.google.com/workspace/drive/api/guides/configure-mcp-server)) rather than translating the Google Drive REST API itself. Your users' AI clients still only ever see C1.ai-governed MCP tools, but C1.ai proxies each tool call straight through to `drivemcp.googleapis.com` under the connected user's authorized session, then returns the result. The tools available are exactly the ones Google's own MCP server exposes — C1.ai doesn't reshape or add to them. ## Before you begin @@ -40,7 +40,7 @@ C1 registers as a client of Google's own hosted Drive MCP server ([Configure the - Each user needs a Google account with access to the Drive content you want their AI client to reach. -In your MCP server catalog, this option is listed as **Google Drive** — distinct from the **Google Drive API** entry, which connects through C1's own MCP server. If you don't see either, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +In your MCP server catalog, this option is listed as **Google Drive** — distinct from the **Google Drive API** entry, which connects through C1.ai's own MCP server. If you don't see either, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Set up per-user OAuth @@ -53,7 +53,7 @@ If you already completed [Set up a Google Cloud project for MCP servers](/produc -Follow [Set up a Google Cloud project for MCP servers](/product/admin/mcp-server/google-cloud-project-setup) to create or select a project, grant your users the **Service Usage Consumer** role, and create an OAuth client with the redirect URI set to whichever matches your C1 tenant's domain — default instance: `https://accounts.conductor.one/auth/callback`, EU data residency instance: `https://accounts.c1eu.ai/auth/callback`. +Follow [Set up a Google Cloud project for MCP servers](/product/admin/mcp-server/google-cloud-project-setup) to create or select a project, grant your users the **Service Usage Consumer** role, and create an OAuth client with the redirect URI set to whichever matches your C1.ai tenant's domain — default instance: `https://accounts.conductor.one/auth/callback`, EU data residency instance: `https://accounts.c1eu.ai/auth/callback`. In the same project, also enable the **Google Drive MCP API** (`drivemcp.googleapis.com`): go to **APIs & Services** > **Library**, search for **Google Drive MCP API**, and select **Enable**. Google's hosted Drive MCP server requires this API alongside the Google Drive API. See Google's [Enable the MCP services](https://developers.google.com/workspace/drive/api/guides/configure-mcp-server#enable-mcp-services) documentation. @@ -85,11 +85,11 @@ Once a user authorizes, tool calls run with that user's own Drive permissions, l ## How Google Drive MCP credentials are shared -This option only supports per-user OAuth — there's no shared, service-account, or bearer-token mode. Every tool call runs under the calling user's own Google identity, and Google attributes each action to that individual. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). +This option only supports per-user OAuth — there's no shared, service-account, or bearer-token mode. Every tool call runs under the calling user's own Google identity, and Google attributes each action to that individual. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). ## Discover and govern tools -After you register the server, C1 runs tool discovery against Google's Drive MCP server. Discovered tools appear on the server's **Tools** tab and include Google's own search, file content, metadata, permissions, and file creation and copying tools. +After you register the server, C1.ai runs tool discovery against Google's Drive MCP server. Discovered tools appear on the server's **Tools** tab and include Google's own search, file content, metadata, permissions, and file creation and copying tools. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -101,7 +101,7 @@ Tool discovery runs even if authentication isn't complete yet, so seeing discove ## Manage access to Google Drive MCP -- **Rotate the OAuth client secret** in your Google Cloud project under **APIs & Services** > **Credentials**, then update the secret on the server's authentication settings in C1. +- **Rotate the OAuth client secret** in your Google Cloud project under **APIs & Services** > **Credentials**, then update the secret on the server's authentication settings in C1.ai. - **Adjust scopes** by editing them on the OAuth consent screen's **Data Access** page; users must reconnect their Google account to grant any newly added scopes. - **An individual user can revoke access at any time** from their Google Account's linked apps page. See Google's [Manage third-party apps & services with access to your account](https://support.google.com/accounts/answer/3466521) documentation. @@ -109,7 +109,7 @@ Tool discovery runs even if authentication isn't complete yet, so seeing discove -C1 hosts the Google Drive MCP server, so your users' AI clients only ever see MCP tools — they never call Google Drive directly. When an AI client calls one of these tools, C1 makes the matching request to the Google Drive API using the credentials you configure here, then returns the result to the AI client. The credentials you set up below are what C1 uses to call Google Drive on your users' behalf. +C1.ai hosts the Google Drive MCP server, so your users' AI clients only ever see MCP tools — they never call Google Drive directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Google Drive API using the credentials you configure here, then returns the result to the AI client. The credentials you set up below are what C1.ai uses to call Google Drive on your users' behalf. Google Drive supports two ways to authenticate, and you choose one when you register the server: @@ -125,7 +125,7 @@ For a deeper comparison of shared versus per-user credentials, see [Configure au - For the service-account option, a Google Workspace administrator to set up [domain-wide delegation](https://knowledge.workspace.google.com/admin/apps/control-api-access-with-domain-wide-delegation). -In your MCP server catalog, this option is listed as **Google Drive API** — distinct from the **Google Drive** entry, which connects to Google's own hosted MCP server. If you don't see either, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +In your MCP server catalog, this option is listed as **Google Drive API** — distinct from the **Google Drive** entry, which connects to Google's own hosted MCP server. If you don't see either, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Option 1: Set up per-user OAuth @@ -134,11 +134,11 @@ With per-user OAuth, you register one Google OAuth client and each user authoriz ### Create a Google OAuth client -Create an OAuth client in your Google Cloud project so users can authorize C1 with their own Google accounts. +Create an OAuth client in your Google Cloud project so users can authorize C1.ai with their own Google accounts. -Sign in to the Google Cloud console and create or select a project for C1. +Sign in to the Google Cloud console and create or select a project for C1.ai. Go to **APIs & Services** > **Library**, search for **Google Drive API**, and select **Enable**. @@ -150,7 +150,7 @@ Go to **APIs & Services** > **OAuth consent screen**. Choose **Internal** for a Go to **APIs & Services** > **Credentials** > **Create Client** > **Web application**. For full details, see Google's [Manage OAuth Clients](https://support.google.com/cloud/answer/15549257) documentation. -Under **Authorized redirect URIs**, add exactly whichever matches your C1 tenant's domain: +Under **Authorized redirect URIs**, add exactly whichever matches your C1.ai tenant's domain: - Default instance: `https://accounts.conductor.one/auth/callback` - EU data residency instance: `https://accounts.c1eu.ai/auth/callback` @@ -180,7 +180,7 @@ Save your changes. The first time a user calls a Google Drive tool from their AI ## Option 2: Use a service account (Workspace only) -A Google service account with domain-wide delegation authenticates every user as one shared identity. C1 signs a JWT with the service account's key to obtain access tokens. Use this for Workspace tenants that want C1 to reach Drive without per-user consent. +A Google service account with domain-wide delegation authenticates every user as one shared identity. C1.ai signs a JWT with the service account's key to obtain access tokens. Use this for Workspace tenants that want C1.ai to reach Drive without per-user consent. ### Create a service account and grant delegation @@ -213,7 +213,7 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **JWT Bearer (RFC 7523)** and provide the service account's JSON key and the scopes you delegated. -Save your changes. C1 starts a sync that discovers the tools the Google Drive server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Google Drive server exposes. @@ -222,13 +222,13 @@ Save your changes. C1 starts a sync that discovers the tools the Google Drive se How Google Drive sees your users' activity depends on the method you chose: - **Per-user OAuth.** Each user authorizes with their own Google account, so tool calls run under that user's Drive identity and inherit only the access they already have. Google attributes each action to the individual user. -- **Service account.** Every user's tool calls use the one service account you configured, so Drive sees a single shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). +- **Service account.** Every user's tool calls use the one service account you configured, so Drive sees a single shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). ## Discover and govern tools -After you register the server, C1 runs tool discovery against Google Drive. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Google Drive. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -240,8 +240,8 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Google Drive API credentials -- **Rotate the OAuth client secret** in your Google Cloud project under **APIs & Services** > **Credentials**, then update the secret on the server's authentication settings in C1. -- **Rotate the service account key** by generating a new JSON key in the Cloud Console, updating it in C1, then deleting the old key. +- **Rotate the OAuth client secret** in your Google Cloud project under **APIs & Services** > **Credentials**, then update the secret on the server's authentication settings in C1.ai. +- **Rotate the service account key** by generating a new JSON key in the Cloud Console, updating it in C1.ai, then deleting the old key. - **Adjust access** by editing the OAuth client's scopes, or the scopes granted to the service account in domain-wide delegation. diff --git a/product/admin/mcp-server/granola.mdx b/product/admin/mcp-server/granola.mdx index 95eee5ea..6519717d 100644 --- a/product/admin/mcp-server/granola.mdx +++ b/product/admin/mcp-server/granola.mdx @@ -1,29 +1,29 @@ --- title: Set up the Granola MCP server -description: Connect Granola to C1 through Granola's own hosted MCP server or the Granola API, then register the server and govern its tools. +description: Connect Granola to C1.ai through Granola's own hosted MCP server or the Granola API, then register the server and govern its tools. og:title: Set up the Granola MCP server -og:description: Connect Granola to C1 through Granola's own hosted MCP server or the Granola API, then register the server and govern its tools. +og:description: Connect Granola to C1.ai through Granola's own hosted MCP server or the Granola API, then register the server and govern its tools. sidebarTitle: Granola --- {/* Editor Refresh: 2026-07-24 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -C1 can govern [Granola](https://www.granola.ai) — an AI meeting-notes app — access two ways. Both let your AI clients read from Granola through governed MCP tools, but they come from different places and appear as two separate entries in your MCP server catalog: +C1.ai can govern [Granola](https://www.granola.ai) — an AI meeting-notes app — access two ways. Both let your AI clients read from Granola through governed MCP tools, but they come from different places and appear as two separate entries in your MCP server catalog: -- **Granola MCP** — listed as plain **Granola** in your catalog. C1 registers Granola's own hosted MCP server (`mcp.granola.ai`) as a downstream server C1 governs. Authentication is always per-user OAuth using dynamic client registration (DCR) — Granola's hosted MCP server doesn't support a bearer token or API key, so there's no integration to create in Granola first. Tool calls run with the connected user's own Granola access, scoped to their active workspace. -- **Granola API** — C1 hosts its own MCP server that translates Granola's REST API into tools. Authentication is a single shared bearer token (a Granola API key), so every tool call reaches Granola as one identity. +- **Granola MCP** — listed as plain **Granola** in your catalog. C1.ai registers Granola's own hosted MCP server (`mcp.granola.ai`) as a downstream server C1.ai governs. Authentication is always per-user OAuth using dynamic client registration (DCR) — Granola's hosted MCP server doesn't support a bearer token or API key, so there's no integration to create in Granola first. Tool calls run with the connected user's own Granola access, scoped to their active workspace. +- **Granola API** — C1.ai hosts its own MCP server that translates Granola's REST API into tools. Authentication is a single shared bearer token (a Granola API key), so every tool call reaches Granola as one identity. | | Granola MCP | Granola API | | :--- | :--- | :--- | -| **Who hosts the MCP server** | Granola | C1 | +| **Who hosts the MCP server** | Granola | C1.ai | | **Authentication** | Per-user OAuth with dynamic client registration (DCR) only — no bearer token or API key option | Bearer token (a Granola API key) only — no OAuth option | | **Access scoping** | The connected user's own Granola access, for their active workspace | Whatever notes the API key's access scope (personal and/or public notes) covers | | **Tool surface** | Granola's own meeting-notes tools: searching meeting history, browsing folders, listing meetings, and reading full notes | Granola's meeting-data REST endpoints, mapped to tools | -| **Setup effort** | Register in C1 and authorize — nothing to create in Granola first | Generate a Granola API key first, then register it in C1 | +| **Setup effort** | Register in C1.ai and authorize — nothing to create in Granola first | Generate a Granola API key first, then register it in C1.ai | Use the native **Granola MCP** option (listed as plain **Granola** in your catalog) if per-user OAuth is acceptable for your tenant and you want each user's tool calls attributed to them individually. Use **Granola API** if you need a single shared credential instead. @@ -31,7 +31,7 @@ Use the native **Granola MCP** option (listed as plain **Granola** in your catal -C1 registers as a client of Granola's own hosted MCP server ([Granola MCP](https://docs.granola.ai/help-center/sharing/integrations/mcp)) rather than translating Granola's REST API itself. Your users' AI clients still only ever see C1-governed MCP tools, but C1 proxies each tool call straight through to `mcp.granola.ai` under the connected user's authorized session, then returns the result. The tools available are exactly the ones Granola's own MCP server exposes — C1 doesn't reshape or add to them. +C1.ai registers as a client of Granola's own hosted MCP server ([Granola MCP](https://docs.granola.ai/help-center/sharing/integrations/mcp)) rather than translating Granola's REST API itself. Your users' AI clients still only ever see C1.ai-governed MCP tools, but C1.ai proxies each tool call straight through to `mcp.granola.ai` under the connected user's authorized session, then returns the result. The tools available are exactly the ones Granola's own MCP server exposes — C1.ai doesn't reshape or add to them. ## Before you begin @@ -39,12 +39,12 @@ C1 registers as a client of Granola's own hosted MCP server ([Granola MCP](https - Nothing to create in Granola ahead of time. This option only supports per-user OAuth with dynamic client registration — Granola's hosted MCP server doesn't offer a bearer token or API key mode, so there's no client ID, secret, or integration to register. Each user just needs a Granola account with access to the workspace whose notes they want tools to reach. -In your MCP server catalog, this option is listed as **Granola** — distinct from the **Granola API** entry, which connects through C1's own MCP server. If you don't see either, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +In your MCP server catalog, this option is listed as **Granola** — distinct from the **Granola API** entry, which connects through C1.ai's own MCP server. If you don't see either, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Set up per-user OAuth -Per-user OAuth with dynamic client registration (DCR) is the only authentication method this option supports — there's no bearer token or API key fallback. Each user authorizes individually through their browser, signing in with the Granola account tied to their workspace, and C1 registers itself with Granola's authorization server automatically, so there's no app to create in Granola first (see Granola's [Granola MCP](https://docs.granola.ai/help-center/sharing/integrations/mcp#do-i-need-a-client-id-or-client-secret) documentation). +Per-user OAuth with dynamic client registration (DCR) is the only authentication method this option supports — there's no bearer token or API key fallback. Each user authorizes individually through their browser, signing in with the Granola account tied to their workspace, and C1.ai registers itself with Granola's authorization server automatically, so there's no app to create in Granola first (see Granola's [Granola MCP](https://docs.granola.ai/help-center/sharing/integrations/mcp#do-i-need-a-client-id-or-client-secret) documentation). @@ -54,7 +54,7 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **OAuth2 — per-user passthrough** and enable **Use dynamic client registration**. There's no client ID or secret to enter. -Save your changes. The first time a user calls a Granola tool from their AI client, they're redirected to sign in with their Granola account (if they aren't already) and approve the connection, then returned to C1. +Save your changes. The first time a user calls a Granola tool from their AI client, they're redirected to sign in with their Granola account (if they aren't already) and approve the connection, then returned to C1.ai. @@ -64,11 +64,11 @@ Unlike the Granola API option, there are no separate capability toggles to confi ## How Granola MCP credentials are shared -This option only supports per-user OAuth — there's no shared, service-account, or bearer-token mode. Every tool call runs under the calling user's own Granola identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). +This option only supports per-user OAuth — there's no shared, service-account, or bearer-token mode. Every tool call runs under the calling user's own Granola identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). ## Discover and govern tools -After you register the server, C1 runs tool discovery against Granola's MCP server. Discovered tools appear on the server's **Tools** tab and include Granola's meeting-notes search, folder browsing, meeting listing, and note-reading tools. +After you register the server, C1.ai runs tool discovery against Granola's MCP server. Discovered tools appear on the server's **Tools** tab and include Granola's meeting-notes search, folder browsing, meeting listing, and note-reading tools. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -80,13 +80,13 @@ Tool discovery runs even if authentication isn't complete yet, so seeing discove ## Manage access to Granola MCP -Because this option uses per-user OAuth, there's no shared secret in C1 to rotate. Granola's own published documentation ([Granola MCP](https://docs.granola.ai/help-center/sharing/integrations/mcp#claude-shows-no-tools-available)) doesn't describe a centralized, self-service page in Granola for listing or revoking individual MCP connections — the documented way to disconnect is from the connected AI client itself (for example, in Claude, opening the Granola connector's settings and choosing to disconnect it, then reconnecting to re-authorize). If your tenant needs a connection revoked and you can't do it from the AI client side, contact Granola support to confirm the current process, since this is an area where Granola's own controls may change. +Because this option uses per-user OAuth, there's no shared secret in C1.ai to rotate. Granola's own published documentation ([Granola MCP](https://docs.granola.ai/help-center/sharing/integrations/mcp#claude-shows-no-tools-available)) doesn't describe a centralized, self-service page in Granola for listing or revoking individual MCP connections — the documented way to disconnect is from the connected AI client itself (for example, in Claude, opening the Granola connector's settings and choosing to disconnect it, then reconnecting to re-authorize). If your tenant needs a connection revoked and you can't do it from the AI client side, contact Granola support to confirm the current process, since this is an area where Granola's own controls may change. -C1 hosts the Granola MCP server, so your users' AI clients only ever see MCP tools — they never call Granola directly. When an AI client calls one of these tools, C1 makes the matching request to Granola's REST API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Granola MCP server, so your users' AI clients only ever see MCP tools — they never call Granola directly. When an AI client calls one of these tools, C1.ai makes the matching request to Granola's REST API using the credentials you configure here, then returns the result to the AI client. Granola supports one authentication method for its API: a bearer token (a Granola API key). Every tool call reaches Granola as the same identity, so there's no per-user attribution on the Granola side. @@ -96,28 +96,28 @@ Granola supports one authentication method for its API: a bearer token (a Granol - You need access to generate a Granola API key. On Granola's Business plan, any workspace member can create a personal API key; on Granola's Enterprise plan, a workspace admin must first enable API key access for members before a key can be created. See Granola's [API documentation](https://docs.granola.ai/introduction#api-key-access-scopes). -In your MCP server catalog, this option is listed as **Granola API** — distinct from the **Granola** entry, which connects to Granola's own hosted MCP server. If you don't see either, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +In your MCP server catalog, this option is listed as **Granola API** — distinct from the **Granola** entry, which connects to Granola's own hosted MCP server. If you don't see either, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Generate a Granola API key -Generate the key in the Granola app before registering the server in C1. +Generate the key in the Granola app before registering the server in C1.ai. In the Granola app, go to **Settings** > **Connectors** > **API keys**, then select **Create new key**. -Choose the note access scope for the key — **personal notes**, **public notes** (workspace-visible and Team space content), or both — depending on what C1 should be able to read. +Choose the note access scope for the key — **personal notes**, **public notes** (workspace-visible and Team space content), or both — depending on what C1.ai should be able to read. Select **Generate API Key**, then copy the key. Treat it as a high-value credential; Granola API keys are bearer tokens and Granola won't show the full value again after you leave the page. -For a shared production setup, generate the key from a dedicated service-account workspace member so activity is attributable to C1 rather than a person. +For a shared production setup, generate the key from a dedicated service-account workspace member so activity is attributable to C1.ai rather than a person. -With your API key ready, register the server and provide it to C1: +With your API key ready, register the server and provide it to C1.ai: @@ -127,19 +127,19 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Bearer token** and paste your Granola API key. -Save your changes. C1 starts a sync that discovers the tools the Granola API exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Granola API exposes. ## How Granola API credentials are shared -Every user's tool calls use the one API key you provided, so Granola sees a single shared identity for all activity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). +Every user's tool calls use the one API key you provided, so Granola sees a single shared identity for all activity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). ## Discover and govern tools -After you register the server, C1 runs tool discovery against Granola. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Granola. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -151,8 +151,8 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Granola API credentials -- **Rotate the API key** by generating a new key in Granola (**Settings** > **Connectors** > **API keys**) and updating it on the server's authentication settings in C1. -- **Revoke a key** from the same page in Granola. Once revoked, a key is permanently disabled and cannot be restored — generate a new one and update it in C1 to keep the integration working. +- **Rotate the API key** by generating a new key in Granola (**Settings** > **Connectors** > **API keys**) and updating it on the server's authentication settings in C1.ai. +- **Revoke a key** from the same page in Granola. Once revoked, a key is permanently disabled and cannot be restored — generate a new one and update it in C1.ai to keep the integration working. - **Adjust access** by generating a new key with a different note access scope, since a key's scope is set when it's created. diff --git a/product/admin/mcp-server/hubspot.mdx b/product/admin/mcp-server/hubspot.mdx index f641593f..efbe43b6 100644 --- a/product/admin/mcp-server/hubspot.mdx +++ b/product/admin/mcp-server/hubspot.mdx @@ -1,26 +1,26 @@ --- title: Set up the HubSpot MCP server -description: Create a HubSpot private app token and register the HubSpot MCP server in C1 so AI clients can call governed HubSpot tools. +description: Create a HubSpot private app token and register the HubSpot MCP server in C1.ai so AI clients can call governed HubSpot tools. og:title: Set up the HubSpot MCP server -og:description: Create a HubSpot private app token and register the HubSpot MCP server in C1 so AI clients can call governed HubSpot tools. +og:description: Create a HubSpot private app token and register the HubSpot MCP server in C1.ai so AI clients can call governed HubSpot tools. sidebarTitle: HubSpot --- {/* Editor Refresh: 2026-06-11 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -The HubSpot MCP server lets you govern access to HubSpot — contacts, companies, deals, and other CRM records — as tools your AI clients can call through C1. +The HubSpot MCP server lets you govern access to HubSpot — contacts, companies, deals, and other CRM records — as tools your AI clients can call through C1.ai. -HubSpot authenticates with a private app access token. A single token authenticates everyone, so all tool calls reach HubSpot as one shared identity. Create the token from a dedicated service-account user so activity is attributable to C1 rather than a person. +HubSpot authenticates with a private app access token. A single token authenticates everyone, so all tool calls reach HubSpot as one shared identity. Create the token from a dedicated service-account user so activity is attributable to C1.ai rather than a person. -## How C1 connects to HubSpot +## How C1.ai connects to HubSpot -C1 hosts the HubSpot MCP server, so your users' AI clients only ever see MCP tools — they never call HubSpot directly. When an AI client calls one of these tools, C1 makes the matching request to the HubSpot API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the HubSpot MCP server, so your users' AI clients only ever see MCP tools — they never call HubSpot directly. When an AI client calls one of these tools, C1.ai makes the matching request to the HubSpot API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call HubSpot on your users' behalf. +The credentials you set up below are what C1.ai uses to call HubSpot on your users' behalf. ## Before you begin @@ -28,12 +28,12 @@ The credentials you set up below are what C1 uses to call HubSpot on your users' - A HubSpot account with permission to create and manage private apps, which requires super admin access. -If you don't see **HubSpot** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **HubSpot** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Create a HubSpot private app token -Create a private app in HubSpot to generate the access token C1 uses to call HubSpot. +Create a private app in HubSpot to generate the access token C1.ai uses to call HubSpot. @@ -52,11 +52,11 @@ Select **Create app**, then copy the **access token**. Treat the token like a pa ## How HubSpot credentials are shared -Every user's tool calls use the one private app token you provided, so HubSpot sees a single shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared production setup, create the token from a dedicated service-account user so activity is attributable to C1 rather than a person. +Every user's tool calls use the one private app token you provided, so HubSpot sees a single shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared production setup, create the token from a dedicated service-account user so activity is attributable to C1.ai rather than a person. For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## Register the HubSpot MCP server in C1 +## Register the HubSpot MCP server in C1.ai With your token ready, register the server and provide your credentials. @@ -68,13 +68,13 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Bearer token** and paste your private app access token. -Save your changes. C1 starts a sync that discovers the tools the HubSpot server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the HubSpot server exposes. ## Discover and govern tools -After you register the server, C1 runs tool discovery against HubSpot. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against HubSpot. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -86,5 +86,5 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your HubSpot credentials -- **Rotate the access token** by rotating it in the private app's settings in HubSpot, then update the token on the server's authentication settings in C1. +- **Rotate the access token** by rotating it in the private app's settings in HubSpot, then update the token on the server's authentication settings in C1.ai. - **Adjust access** by editing the private app's scopes in HubSpot. diff --git a/product/admin/mcp-server/jira-service-management.mdx b/product/admin/mcp-server/jira-service-management.mdx index 6cb06f83..2f6699a5 100644 --- a/product/admin/mcp-server/jira-service-management.mdx +++ b/product/admin/mcp-server/jira-service-management.mdx @@ -1,26 +1,26 @@ --- title: Set up the Jira Service Management MCP server -description: Connect Jira Service Management to C1 with per-user OAuth, then register the MCP server and govern the tools it exposes. +description: Connect Jira Service Management to C1.ai with per-user OAuth, then register the MCP server and govern the tools it exposes. og:title: Set up the Jira Service Management MCP server -og:description: Connect Jira Service Management to C1 with per-user OAuth, then register the MCP server and govern the tools it exposes. +og:description: Connect Jira Service Management to C1.ai with per-user OAuth, then register the MCP server and govern the tools it exposes. sidebarTitle: Jira Service Management --- {/* Editor Refresh: 2026-06-11 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -The Jira Service Management MCP server lets you govern access to Jira Service Management — service desks, requests, queues, customers, organizations, knowledge base content, and SLAs — as tools your AI clients can call through C1. +The Jira Service Management MCP server lets you govern access to Jira Service Management — service desks, requests, queues, customers, organizations, knowledge base content, and SLAs — as tools your AI clients can call through C1.ai. Jira Service Management uses per-user OAuth, which is recommended: each person authorizes with their own Atlassian account, so every tool call runs under that user's identity and permissions. -## How C1 connects to Jira Service Management +## How C1.ai connects to Jira Service Management -C1 hosts the Jira Service Management MCP server, so your users' AI clients only ever see MCP tools — they never call Jira Service Management directly. When an AI client calls one of these tools, C1 makes the matching request to the Jira Service Management API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Jira Service Management MCP server, so your users' AI clients only ever see MCP tools — they never call Jira Service Management directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Jira Service Management API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call Jira Service Management on your users' behalf. +The credentials you set up below are what C1.ai uses to call Jira Service Management on your users' behalf. ## Before you begin @@ -28,7 +28,7 @@ The credentials you set up below are what C1 uses to call Jira Service Managemen - An Atlassian account that can create an OAuth 2.0 integration. See Atlassian's [OAuth 2.0 (3LO) apps guide](https://developer.atlassian.com/cloud/jira/service-desk/oauth-2-authorization-code-grants-3lo-for-apps/). -If you don't see **Jira Service Management** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **Jira Service Management** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Create an Atlassian OAuth 2.0 integration @@ -43,10 +43,10 @@ Sign in to the Atlassian Developer Console with your Atlassian account. For the Select **Create** > **OAuth 2.0 integration**, enter a recognizable name such as `C1`, then select **Create**. -Open the **Permissions** tab. Next to **Jira Service Management API**, select **Add**, then **Configure**, and add the scopes C1 needs for the operations you plan to govern, such as reading requests, queues, and customers. +Open the **Permissions** tab. Next to **Jira Service Management API**, select **Add**, then **Configure**, and add the scopes C1.ai needs for the operations you plan to govern, such as reading requests, queues, and customers. -Open the **Authorization** tab. Next to **OAuth 2.0 (3LO)**, select **Configure** and set the **Callback URL** exactly to whichever matches your C1 tenant's domain: +Open the **Authorization** tab. Next to **OAuth 2.0 (3LO)**, select **Configure** and set the **Callback URL** exactly to whichever matches your C1.ai tenant's domain: - Default instance: `https://accounts.conductor.one/auth/callback` - EU data residency instance: `https://accounts.c1eu.ai/auth/callback` @@ -64,7 +64,7 @@ With per-user OAuth, each user authorizes with their own Atlassian account, so t For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## Register the Jira Service Management MCP server in C1 +## Register the Jira Service Management MCP server in C1.ai With your integration ready, register the server and provide your credentials. @@ -82,7 +82,7 @@ Save your changes. The first time a user calls a Jira Service Management tool fr ## Discover and govern tools -After you register the server, C1 runs tool discovery against Jira Service Management. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Jira Service Management. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -94,5 +94,5 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Jira Service Management credentials -- **Rotate the OAuth client secret** in the Atlassian Developer Console under your integration's **Settings** tab, then update the secret on the server's authentication settings in C1. +- **Rotate the OAuth client secret** in the Atlassian Developer Console under your integration's **Settings** tab, then update the secret on the server's authentication settings in C1.ai. - **Adjust access** by editing the integration's scopes on the **Permissions** tab in the Atlassian Developer Console. diff --git a/product/admin/mcp-server/jira.mdx b/product/admin/mcp-server/jira.mdx index 86ce34a9..de65ca4b 100644 --- a/product/admin/mcp-server/jira.mdx +++ b/product/admin/mcp-server/jira.mdx @@ -1,26 +1,26 @@ --- title: Set up the Jira MCP server -description: Connect Jira to C1 with per-user OAuth, then register the Jira MCP server and govern the tools it exposes. +description: Connect Jira to C1.ai with per-user OAuth, then register the Jira MCP server and govern the tools it exposes. og:title: Set up the Jira MCP server -og:description: Connect Jira to C1 with per-user OAuth, then register the Jira MCP server and govern the tools it exposes. +og:description: Connect Jira to C1.ai with per-user OAuth, then register the Jira MCP server and govern the tools it exposes. sidebarTitle: Jira --- {/* Editor Refresh: 2026-06-11 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -The Jira MCP server lets you govern access to Jira Cloud — issues, projects, sprints, workflows, dashboards, filters, fields, and configuration — as tools your AI clients can call through C1. +The Jira MCP server lets you govern access to Jira Cloud — issues, projects, sprints, workflows, dashboards, filters, fields, and configuration — as tools your AI clients can call through C1.ai. Jira uses per-user OAuth, which is recommended: each person authorizes with their own Atlassian account, so every tool call runs under that user's identity and permissions. -## How C1 connects to Jira +## How C1.ai connects to Jira -C1 hosts the Jira MCP server, so your users' AI clients only ever see MCP tools — they never call Jira directly. When an AI client calls one of these tools, C1 makes the matching request to the Jira API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Jira MCP server, so your users' AI clients only ever see MCP tools — they never call Jira directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Jira API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call Jira on your users' behalf. +The credentials you set up below are what C1.ai uses to call Jira on your users' behalf. ## Before you begin @@ -28,7 +28,7 @@ The credentials you set up below are what C1 uses to call Jira on your users' be - An Atlassian account that can create an OAuth 2.0 integration. See Atlassian's [OAuth 2.0 (3LO) apps guide](https://developer.atlassian.com/cloud/jira/platform/oauth-2-3lo-apps/). -If you don't see **Jira** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **Jira** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Create an Atlassian OAuth 2.0 integration @@ -46,7 +46,7 @@ Select **Create** > **OAuth 2.0 integration**, enter a recognizable name such as Open the **Permissions** tab. Next to **Jira API**, select **Add**, then **Configure**, and add the scopes from [Jira scopes](#jira-scopes) below — the default read scopes, plus any optional write or admin scopes you need. -Open the **Authorization** tab. Next to **OAuth 2.0 (3LO)**, select **Configure** and set the **Callback URL** exactly to whichever matches your C1 tenant's domain: +Open the **Authorization** tab. Next to **OAuth 2.0 (3LO)**, select **Configure** and set the **Callback URL** exactly to whichever matches your C1.ai tenant's domain: - Default instance: `https://accounts.conductor.one/auth/callback` - EU data residency instance: `https://accounts.c1eu.ai/auth/callback` @@ -60,7 +60,7 @@ Open the **Settings** tab. Under **Authentication details**, copy the **Client I ## Jira scopes -C1 requests the default read scopes automatically. The default is read-only; to enable write or admin tools, add the optional scopes below in the Developer Console (**Permissions** > **Jira API** > **Configure**) and in C1's scopes field when configuring authentication. Grant only what you need. +C1.ai requests the default read scopes automatically. The default is read-only; to enable write or admin tools, add the optional scopes below in the Developer Console (**Permissions** > **Jira API** > **Configure**) and in C1.ai's scopes field when configuring authentication. Grant only what you need. **Default scopes** read issues, projects, and users (plus `offline_access` for token refresh): @@ -85,7 +85,7 @@ With per-user OAuth, each user authorizes with their own Atlassian account, so t For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## Register the Jira MCP server in C1 +## Register the Jira MCP server in C1.ai With your integration ready, register the server and provide your credentials. @@ -103,7 +103,7 @@ Save your changes. The first time a user calls a Jira tool from their AI client, ## Discover and govern tools -After you register the server, C1 runs tool discovery against Jira. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Jira. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -115,5 +115,5 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Jira credentials -- **Rotate the OAuth client secret** in the Atlassian Developer Console under your integration's **Settings** tab, then update the secret on the server's authentication settings in C1. +- **Rotate the OAuth client secret** in the Atlassian Developer Console under your integration's **Settings** tab, then update the secret on the server's authentication settings in C1.ai. - **Adjust access** by editing the integration's Jira scopes on the **Permissions** tab in the Atlassian Developer Console. diff --git a/product/admin/mcp-server/linear.mdx b/product/admin/mcp-server/linear.mdx index 95367088..45df0970 100644 --- a/product/admin/mcp-server/linear.mdx +++ b/product/admin/mcp-server/linear.mdx @@ -1,29 +1,29 @@ --- title: Set up the Linear MCP server -description: Connect Linear to C1 through Linear's own hosted MCP server or the Linear API, then register the server and govern its tools. +description: Connect Linear to C1.ai through Linear's own hosted MCP server or the Linear API, then register the server and govern its tools. og:title: Set up the Linear MCP server -og:description: Connect Linear to C1 through Linear's own hosted MCP server or the Linear API, then register the server and govern its tools. +og:description: Connect Linear to C1.ai through Linear's own hosted MCP server or the Linear API, then register the server and govern its tools. sidebarTitle: Linear --- {/* Editor Refresh: 2026-07-24 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -C1 can govern Linear access two ways. Both let your AI clients read from and act on Linear through governed MCP tools, but they come from different places and appear as two separate entries in your MCP server catalog: +C1.ai can govern Linear access two ways. Both let your AI clients read from and act on Linear through governed MCP tools, but they come from different places and appear as two separate entries in your MCP server catalog: -- **Linear MCP** — listed as plain **Linear** in your catalog. C1 registers Linear's own hosted MCP server (`mcp.linear.app`) as a downstream server C1 governs. The recommended authentication method is per-user OAuth with dynamic client registration (DCR) — nothing to register in Linear first. Linear's MCP server also accepts a personal API key sent as a bearer token, if you'd rather use a single shared credential. -- **Linear API** — C1 hosts its own MCP server that translates the Linear API into tools. You choose between per-user OAuth (which requires creating a Linear OAuth application) or a personal API key, and scope access with the OAuth scopes or API key permissions you grant. +- **Linear MCP** — listed as plain **Linear** in your catalog. C1.ai registers Linear's own hosted MCP server (`mcp.linear.app`) as a downstream server C1.ai governs. The recommended authentication method is per-user OAuth with dynamic client registration (DCR) — nothing to register in Linear first. Linear's MCP server also accepts a personal API key sent as a bearer token, if you'd rather use a single shared credential. +- **Linear API** — C1.ai hosts its own MCP server that translates the Linear API into tools. You choose between per-user OAuth (which requires creating a Linear OAuth application) or a personal API key, and scope access with the OAuth scopes or API key permissions you grant. | | Linear MCP | Linear API | | :--- | :--- | :--- | -| **Who hosts the MCP server** | Linear | C1 | +| **Who hosts the MCP server** | Linear | C1.ai | | **Authentication** | Per-user OAuth with dynamic client registration (DCR), or a personal API key (bearer token) | Per-user OAuth (requires a Linear OAuth application), or a personal API key (bearer token) | | **Access scoping** | The connected user's full Linear permissions with OAuth; a personal API key can be restricted to Read, Write, Admin, Create issues, Create comments, and specific teams | The OAuth scopes or API key permissions you configure | | **Tool surface** | Linear's own tool set: finding, creating, and updating issues, projects, and comments, with more functionality on the way | Issues, projects, cycles, teams, users, and comments, mapped to Linear API endpoints | -| **Setup effort** | Register in C1 and authorize — nothing to create in Linear first for OAuth | Create a Linear OAuth application first (for per-user OAuth), then register it in C1 | +| **Setup effort** | Register in C1.ai and authorize — nothing to create in Linear first for OAuth | Create a Linear OAuth application first (for per-user OAuth), then register it in C1.ai | Use the native **Linear MCP** option (listed as plain **Linear** in your catalog) if you want Linear's own hosted tool set and dynamic client registration is acceptable for your tenant. Use **Linear API** if you need to create a dedicated OAuth application, or you want to scope access with the Linear API's own permission model. @@ -31,21 +31,21 @@ Use the native **Linear MCP** option (listed as plain **Linear** in your catalog -C1 registers as a client of Linear's own hosted MCP server ([MCP server](https://linear.app/docs/mcp)) rather than translating the Linear API itself. Your users' AI clients still only ever see C1-governed MCP tools, but C1 proxies each tool call straight through to `mcp.linear.app` under the connected user's authorized session (or a shared bearer credential, if you choose that method instead), then returns the result. The tools available are exactly the ones Linear's own MCP server exposes — C1 doesn't reshape or add to them. +C1.ai registers as a client of Linear's own hosted MCP server ([MCP server](https://linear.app/docs/mcp)) rather than translating the Linear API itself. Your users' AI clients still only ever see C1.ai-governed MCP tools, but C1.ai proxies each tool call straight through to `mcp.linear.app` under the connected user's authorized session (or a shared bearer credential, if you choose that method instead), then returns the result. The tools available are exactly the ones Linear's own MCP server exposes — C1.ai doesn't reshape or add to them. ## Before you begin - AI access management must be enabled for your tenant. See [Enable AI access management](/product/admin/enable-ai-access-management). -- For per-user OAuth with dynamic client registration, nothing to create in Linear ahead of time — C1 registers itself with Linear's authorization server automatically. Each user just needs a Linear account with access to the workspace. +- For per-user OAuth with dynamic client registration, nothing to create in Linear ahead of time — C1.ai registers itself with Linear's authorization server automatically. Each user just needs a Linear account with access to the workspace. - For a personal API key, you need the Linear account whose access the key should carry. -In your MCP server catalog, this option is listed as **Linear** — distinct from the **Linear API** entry, which connects through C1's own MCP server. If you don't see either, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +In your MCP server catalog, this option is listed as **Linear** — distinct from the **Linear API** entry, which connects through C1.ai's own MCP server. If you don't see either, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. Linear's MCP server (`https://mcp.linear.app/mcp`) supports two ways to authenticate: -- **Per-user OAuth with dynamic client registration** (recommended). Each person authorizes with their own Linear account, and C1 registers itself with Linear's authorization server automatically — there's no OAuth application to create in Linear first ([MCP server](https://linear.app/docs/mcp)). +- **Per-user OAuth with dynamic client registration** (recommended). Each person authorizes with their own Linear account, and C1.ai registers itself with Linear's authorization server automatically — there's no OAuth application to create in Linear first ([MCP server](https://linear.app/docs/mcp)). - **Personal API key**. A single key authenticates everyone, sent as a bearer token, so all tool calls reach Linear's MCP server as one shared identity. ## Option 1: Set up per-user OAuth with dynamic client registration @@ -60,7 +60,7 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **OAuth2 — per-user passthrough** and enable **Use dynamic client registration**. There's no client ID or secret to enter. -Save your changes. The first time a user calls a Linear tool from their AI client, they're redirected to Linear to sign in (if they aren't already) and approve the connection, then returned to C1. +Save your changes. The first time a user calls a Linear tool from their AI client, they're redirected to Linear to sign in (if they aren't already) and approve the connection, then returned to C1.ai. @@ -70,11 +70,11 @@ Linear's MCP server also accepts a personal API key sent as a bearer credential ### Create a personal API key -Create the key in Linear before registering the server in C1. +Create the key in Linear before registering the server in C1.ai. -Sign in to Linear as the account C1 should run as, then open **Settings** > **Security & access**. +Sign in to Linear as the account C1.ai should run as, then open **Settings** > **Security & access**. Under **Personal API keys**, select **Create key**. @@ -87,7 +87,7 @@ Copy the generated key. -For a read-only connection, restrict the key to the **Read** permission only. For a shared production setup, create the key from a dedicated service-account user so activity is attributable to C1 rather than a person. +For a read-only connection, restrict the key to the **Read** permission only. For a shared production setup, create the key from a dedicated service-account user so activity is attributable to C1.ai rather than a person. ### Register the server with a key @@ -101,7 +101,7 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Bearer token** and paste your personal API key. -Save your changes. C1 starts a sync that discovers the tools Linear's MCP server exposes. +Save your changes. C1.ai starts a sync that discovers the tools Linear's MCP server exposes. @@ -112,11 +112,11 @@ With per-user OAuth, tool calls run with the connected user's own Linear permiss ## How Linear MCP credentials are shared - **Per-user OAuth.** Every tool call runs under the calling user's own Linear identity, and Linear attributes each action to that individual. -- **Personal API key.** Every user's tool calls use the one key you provided, so Linear sees a single shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). +- **Personal API key.** Every user's tool calls use the one key you provided, so Linear sees a single shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). ## Discover and govern tools -After you register the server, C1 runs tool discovery against Linear's MCP server. Discovered tools appear on the server's **Tools** tab and include Linear's own tools for finding, creating, and updating issues, projects, and comments. +After you register the server, C1.ai runs tool discovery against Linear's MCP server. Discovered tools appear on the server's **Tools** tab and include Linear's own tools for finding, creating, and updating issues, projects, and comments. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -129,13 +129,13 @@ Tool discovery runs even if authentication isn't complete yet, so seeing discove ## Manage access to Linear MCP - **Rotate or revoke a personal API key** in Linear under **Settings** > **Security & access** > **Personal API keys** ([Security & access](https://linear.app/docs/security-and-access)). Adjust a key's scope by revoking it and creating a new one with different permissions — existing keys can't be re-scoped after creation. -- **An individual user can revoke their own OAuth authorization at any time.** In Linear, go to **Settings** > **Security & access**, find the C1 entry under **Authorized applications**, hover over it, and select **Revoke access** ([Security & access](https://linear.app/docs/security-and-access)). +- **An individual user can revoke their own OAuth authorization at any time.** In Linear, go to **Settings** > **Security & access**, find the C1.ai entry under **Authorized applications**, hover over it, and select **Revoke access** ([Security & access](https://linear.app/docs/security-and-access)). -The Linear MCP server lets you govern access to Linear — issues, projects, cycles, teams, users, and comments — as tools your AI clients can call through C1. +The Linear MCP server lets you govern access to Linear — issues, projects, cycles, teams, users, and comments — as tools your AI clients can call through C1.ai. Linear supports two ways to authenticate, and you choose one when you register the server: @@ -144,11 +144,11 @@ Linear supports two ways to authenticate, and you choose one when you register t For a deeper comparison of shared versus per-user credentials, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## How C1 connects to Linear +## How C1.ai connects to Linear -C1 hosts the Linear MCP server, so your users' AI clients only ever see MCP tools — they never call Linear directly. When an AI client calls one of these tools, C1 makes the matching request to the Linear API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Linear MCP server, so your users' AI clients only ever see MCP tools — they never call Linear directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Linear API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call Linear on your users' behalf. +The credentials you set up below are what C1.ai uses to call Linear on your users' behalf. ## Before you begin @@ -157,7 +157,7 @@ The credentials you set up below are what C1 uses to call Linear on your users' - For a personal API key, you need the Linear account whose access the key should carry. -If you don't see **Linear API** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **Linear API** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Option 1: Set up per-user OAuth @@ -166,20 +166,20 @@ With per-user OAuth, you register one Linear OAuth application and each user aut ### Create a Linear OAuth application -Create an OAuth application in Linear so users can authorize C1 with their own Linear accounts. For Linear's own walkthrough, see [OAuth 2.0 authentication](https://linear.app/developers/oauth-2-0-authentication). +Create an OAuth application in Linear so users can authorize C1.ai with their own Linear accounts. For Linear's own walkthrough, see [OAuth 2.0 authentication](https://linear.app/developers/oauth-2-0-authentication). As a Linear workspace admin, open **Settings** > **API** > **OAuth applications** and select **Create new**. -Set the **Redirect URI** exactly to whichever matches your C1 tenant's domain: +Set the **Redirect URI** exactly to whichever matches your C1.ai tenant's domain: - Default instance: `https://accounts.conductor.one/auth/callback` - EU data residency instance: `https://accounts.c1eu.ai/auth/callback` -Select the scopes C1 needs for the operations you plan to govern, such as `read`, `write`, `issues:create`, and `comments:create`. +Select the scopes C1.ai needs for the operations you plan to govern, such as `read`, `write`, `issues:create`, and `comments:create`. Save the application, then copy its **Client ID** and **Client Secret**. @@ -208,11 +208,11 @@ A personal API key authenticates every user as one shared Linear identity. The k ### Create a personal API key -Create a personal API key in Linear for the account C1 should run as. For Linear's own walkthrough, see [API and webhooks](https://linear.app/docs/api-and-webhooks). +Create a personal API key in Linear for the account C1.ai should run as. For Linear's own walkthrough, see [API and webhooks](https://linear.app/docs/api-and-webhooks). -Sign in to Linear as the account C1 should run as, then open **Settings** > **Security & access**. +Sign in to Linear as the account C1.ai should run as, then open **Settings** > **Security & access**. Under **Personal API keys**, select **New API key**. @@ -225,7 +225,7 @@ Copy the key immediately. Linear shows it only once. -For a shared production setup, create the key from a dedicated service-account user with only the workspace memberships C1 needs, so activity is attributable to C1 rather than a person. +For a shared production setup, create the key from a dedicated service-account user with only the workspace memberships C1.ai needs, so activity is attributable to C1.ai rather than a person. ### Register the server with a key @@ -239,7 +239,7 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Bearer token** and paste your personal API key. -Save your changes. C1 starts a sync that discovers the tools the Linear server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Linear server exposes. @@ -248,13 +248,13 @@ Save your changes. C1 starts a sync that discovers the tools the Linear server e How Linear sees your users' activity depends on the method you chose: - **Per-user OAuth.** Each user authorizes with their own Linear account, so tool calls run under that user's Linear identity and inherit only the access they already have. Linear attributes each action to the individual user. -- **Personal API key.** Every user's tool calls use the one key you provided, so Linear sees a single shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). +- **Personal API key.** Every user's tool calls use the one key you provided, so Linear sees a single shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). ## Discover and govern tools -After you register the server, C1 runs tool discovery against Linear. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Linear. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -266,8 +266,8 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Linear API credentials -- **Rotate the OAuth client secret** in your Linear OAuth application under **Settings** > **API** > **OAuth applications**, then update the secret on the server's authentication settings in C1. -- **Rotate a personal API key** in **Settings** > **Security & access** by deleting the existing key, creating a new one, and updating it in C1. Linear personal API keys don't expire on their own, so rotate them on a schedule. +- **Rotate the OAuth client secret** in your Linear OAuth application under **Settings** > **API** > **OAuth applications**, then update the secret on the server's authentication settings in C1.ai. +- **Rotate a personal API key** in **Settings** > **Security & access** by deleting the existing key, creating a new one, and updating it in C1.ai. Linear personal API keys don't expire on their own, so rotate them on a schedule. - **Adjust access** by editing the OAuth application's scopes, or by changing the workspace memberships of the account that owns the personal API key. diff --git a/product/admin/mcp-server/linkedin.mdx b/product/admin/mcp-server/linkedin.mdx index 53eb4b6b..48461d14 100644 --- a/product/admin/mcp-server/linkedin.mdx +++ b/product/admin/mcp-server/linkedin.mdx @@ -1,26 +1,26 @@ --- title: Set up the LinkedIn MCP server -description: Connect LinkedIn to C1 with per-user OAuth, then register the LinkedIn MCP server and govern its tools. +description: Connect LinkedIn to C1.ai with per-user OAuth, then register the LinkedIn MCP server and govern its tools. og:title: Set up the LinkedIn MCP server -og:description: Connect LinkedIn to C1 with per-user OAuth, then register the LinkedIn MCP server and govern its tools. +og:description: Connect LinkedIn to C1.ai with per-user OAuth, then register the LinkedIn MCP server and govern its tools. sidebarTitle: LinkedIn --- {/* Editor Refresh: 2026-06-11 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -The LinkedIn MCP server lets you govern access to LinkedIn — member profiles, organization pages, social posts, and ads data — as tools your AI clients can call through C1. +The LinkedIn MCP server lets you govern access to LinkedIn — member profiles, organization pages, social posts, and ads data — as tools your AI clients can call through C1.ai. LinkedIn authenticates with per-user OAuth. Each person authorizes with their own LinkedIn account, so every tool call runs under that user's LinkedIn identity and permissions. For a deeper comparison of shared versus per-user credentials, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## How C1 connects to LinkedIn +## How C1.ai connects to LinkedIn -C1 hosts the LinkedIn MCP server, so your users' AI clients only ever see MCP tools — they never call LinkedIn directly. When an AI client calls one of these tools, C1 makes the matching request to the LinkedIn API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the LinkedIn MCP server, so your users' AI clients only ever see MCP tools — they never call LinkedIn directly. When an AI client calls one of these tools, C1.ai makes the matching request to the LinkedIn API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call LinkedIn on your users' behalf. +The credentials you set up below are what C1.ai uses to call LinkedIn on your users' behalf. ## Before you begin @@ -28,12 +28,12 @@ The credentials you set up below are what C1 uses to call LinkedIn on your users - A LinkedIn account with permission to create an app in the LinkedIn Developer Portal, linked to a LinkedIn Page you administer. -If you don't see **LinkedIn** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **LinkedIn** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Create a LinkedIn app -Create an app in the LinkedIn Developer Portal to generate the OAuth credentials C1 uses to connect. +Create an app in the LinkedIn Developer Portal to generate the OAuth credentials C1.ai uses to connect. @@ -43,7 +43,7 @@ In the LinkedIn Developer Portal, select **Create app**. For details, see Linked Give the app a recognizable name such as `C1` and associate it with a LinkedIn Page you administer. -On the **Auth** tab, set the **authorized redirect URL** exactly to whichever matches your C1 tenant's domain: +On the **Auth** tab, set the **authorized redirect URL** exactly to whichever matches your C1.ai tenant's domain: - Default instance: `https://accounts.conductor.one/auth/callback` - EU data residency instance: `https://accounts.c1eu.ai/auth/callback` @@ -62,7 +62,7 @@ Each user authorizes with their own LinkedIn account, so tool calls run under th For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## Register the LinkedIn MCP server in C1 +## Register the LinkedIn MCP server in C1.ai With your app ready, register the server and provide your credentials. @@ -80,7 +80,7 @@ Save your changes. The first time a user calls a LinkedIn tool from their AI cli ## Discover and govern tools -After you register the server, C1 runs tool discovery against LinkedIn. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against LinkedIn. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -92,5 +92,5 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your LinkedIn credentials -- **Rotate the client secret** in your LinkedIn app under the **Auth** tab, then update the secret on the server's authentication settings in C1. +- **Rotate the client secret** in your LinkedIn app under the **Auth** tab, then update the secret on the server's authentication settings in C1.ai. - **Adjust access** by requesting or removing products on the app's **Products** tab in LinkedIn. diff --git a/product/admin/mcp-server/looker.mdx b/product/admin/mcp-server/looker.mdx index 8f51a46c..5519111d 100644 --- a/product/admin/mcp-server/looker.mdx +++ b/product/admin/mcp-server/looker.mdx @@ -1,26 +1,26 @@ --- title: Set up the Looker MCP server -description: Create Looker API credentials, then register the Looker MCP server in C1 and govern the tools it exposes. +description: Create Looker API credentials, then register the Looker MCP server in C1.ai and govern the tools it exposes. og:title: Set up the Looker MCP server -og:description: Create Looker API credentials, then register the Looker MCP server in C1 and govern the tools it exposes. +og:description: Create Looker API credentials, then register the Looker MCP server in C1.ai and govern the tools it exposes. sidebarTitle: Looker --- {/* Editor Refresh: 2026-06-11 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -The Looker MCP server lets you govern access to Looker — dashboards, looks, queries, explores, content, and users — as tools your AI clients can call through C1. +The Looker MCP server lets you govern access to Looker — dashboards, looks, queries, explores, content, and users — as tools your AI clients can call through C1.ai. -Looker authenticates with API credentials: a client ID and client secret that C1 exchanges for a short-lived access token. A single set of credentials authenticates everyone, so all tool calls reach Looker as one shared identity. +Looker authenticates with API credentials: a client ID and client secret that C1.ai exchanges for a short-lived access token. A single set of credentials authenticates everyone, so all tool calls reach Looker as one shared identity. -## How C1 connects to Looker +## How C1.ai connects to Looker -C1 hosts the Looker MCP server, so your users' AI clients only ever see MCP tools — they never call Looker directly. When an AI client calls one of these tools, C1 makes the matching request to the Looker API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Looker MCP server, so your users' AI clients only ever see MCP tools — they never call Looker directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Looker API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call Looker on your users' behalf. +The credentials you set up below are what C1.ai uses to call Looker on your users' behalf. ## Before you begin @@ -28,7 +28,7 @@ The credentials you set up below are what C1 uses to call Looker on your users' - A Looker account with API credentials. API credentials inherit the permissions and content access of the user they belong to, so use a user that has the access you want this integration to have. -If you don't see **Looker** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **Looker** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Create Looker API credentials @@ -47,17 +47,17 @@ Copy both the **Client ID** and the **Client Secret**. Looker shows the client s -For a shared production setup, create the credentials under a dedicated service-account user so activity is attributable to C1 rather than a person, and grant that user only the roles and content access you want to govern. +For a shared production setup, create the credentials under a dedicated service-account user so activity is attributable to C1.ai rather than a person, and grant that user only the roles and content access you want to govern. ## How Looker credentials are shared -Every user's tool calls use the one set of API credentials you provided, so Looker sees a single shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared setup, create the credentials under a dedicated service-account user so activity is attributable to C1 rather than a person. +Every user's tool calls use the one set of API credentials you provided, so Looker sees a single shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared setup, create the credentials under a dedicated service-account user so activity is attributable to C1.ai rather than a person. For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## Register the Looker MCP server in C1 +## Register the Looker MCP server in C1.ai -With your credentials ready, register the server and provide them to C1. +With your credentials ready, register the server and provide them to C1.ai. @@ -70,13 +70,13 @@ Enter your Looker instance URL when prompted. When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Client credentials** and enter your Looker **client ID** and **client secret**. -Save your changes. C1 starts a sync that discovers the tools the Looker server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Looker server exposes. ## Discover and govern tools -After you register the server, C1 runs tool discovery against Looker. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Looker. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -88,5 +88,5 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Looker credentials -- **Rotate the API credentials** by generating a new key for the user in Looker, updating the client ID and client secret in C1, then deleting the old key. +- **Rotate the API credentials** by generating a new key for the user in Looker, updating the client ID and client secret in C1.ai, then deleting the old key. - **Adjust access** by editing the roles and content access of the user the credentials belong to in Looker. diff --git a/product/admin/mcp-server/lucid.mdx b/product/admin/mcp-server/lucid.mdx index c4bdff86..3f610cc8 100644 --- a/product/admin/mcp-server/lucid.mdx +++ b/product/admin/mcp-server/lucid.mdx @@ -1,29 +1,29 @@ --- title: Set up the Lucid MCP server -description: Connect Lucid to C1 through the Lucid API or Lucid's own hosted MCP server, then register the server and govern its tools. +description: Connect Lucid to C1.ai through the Lucid API or Lucid's own hosted MCP server, then register the server and govern its tools. og:title: Set up the Lucid MCP server -og:description: Connect Lucid to C1 through the Lucid API or Lucid's own hosted MCP server, then register the server and govern its tools. +og:description: Connect Lucid to C1.ai through the Lucid API or Lucid's own hosted MCP server, then register the server and govern its tools. sidebarTitle: Lucid --- {/* Editor Refresh: 2026-07-24 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -C1 can govern Lucid access two ways. Both let your AI clients read from and act on Lucid through governed MCP tools, but they come from different places and appear as two separate entries in your MCP server catalog: +C1.ai can govern Lucid access two ways. Both let your AI clients read from and act on Lucid through governed MCP tools, but they come from different places and appear as two separate entries in your MCP server catalog: -- **Lucid MCP** — listed as plain **Lucid** in your catalog. C1 registers Lucid's own hosted MCP server (`mcp.lucid.app`) as a downstream server C1 governs. Authentication is always per-user OAuth using dynamic client registration (DCR) — Lucid's hosted MCP server doesn't support a bearer token or API key, so there's no application to create in Lucid first. Before anyone can connect, a Lucid account admin must enable MCP access for the account from the Lucid Admin Panel. Tool calls run with the connected user's full Lucid permissions. -- **Lucid API** — C1 hosts its own MCP server that translates Lucid's REST API into tools. You choose between per-user OAuth or a shared API token, and you scope access with the **scopes** you grant the Lucid OAuth application (or token). +- **Lucid MCP** — listed as plain **Lucid** in your catalog. C1.ai registers Lucid's own hosted MCP server (`mcp.lucid.app`) as a downstream server C1.ai governs. Authentication is always per-user OAuth using dynamic client registration (DCR) — Lucid's hosted MCP server doesn't support a bearer token or API key, so there's no application to create in Lucid first. Before anyone can connect, a Lucid account admin must enable MCP access for the account from the Lucid Admin Panel. Tool calls run with the connected user's full Lucid permissions. +- **Lucid API** — C1.ai hosts its own MCP server that translates Lucid's REST API into tools. You choose between per-user OAuth or a shared API token, and you scope access with the **scopes** you grant the Lucid OAuth application (or token). | | Lucid MCP | Lucid API | | :--- | :--- | :--- | -| **Who hosts the MCP server** | Lucid | C1 | +| **Who hosts the MCP server** | Lucid | C1.ai | | **Authentication** | Per-user OAuth with dynamic client registration (DCR) only — no bearer token or API key option | Per-user OAuth, or a shared API token | | **Access scoping** | The connected user's full Lucid permissions — not independently scoped | The OAuth **scopes** you configure on the application, or the token | | **Tool surface** | Lucid's own tool set: document search, content retrieval, diagram creation (including org charts, mind maps, and UML sequence diagrams), image export, and sharing | Documents, folders, teams, and users, mapped to Lucid API endpoints | -| **Setup effort** | An account admin enables MCP access in Lucid, then register and authorize in C1 — nothing else to create in Lucid first | Create a Lucid OAuth application or API token first, then register it in C1 | +| **Setup effort** | An account admin enables MCP access in Lucid, then register and authorize in C1.ai — nothing else to create in Lucid first | Create a Lucid OAuth application or API token first, then register it in C1.ai | Use the native **Lucid MCP** option (listed as plain **Lucid** in your catalog) if you want Lucid's own broader, agentic tool set and per-user OAuth is acceptable for your tenant. Use **Lucid API** if you need a shared service-account credential (API token), or you want to scope access with OAuth scopes. @@ -31,7 +31,7 @@ Use the native **Lucid MCP** option (listed as plain **Lucid** in your catalog) -C1 registers as a client of Lucid's own hosted MCP server ([Integrate Lucid with AI tools using the Lucid MCP server](https://help.lucid.co/hc/en-us/articles/42578801807508-Integrate-Lucid-with-AI-tools-using-the-Lucid-MCP-server)) rather than translating Lucid's REST API itself. Your users' AI clients still only ever see C1-governed MCP tools, but C1 proxies each tool call straight through to `mcp.lucid.app` under the connected user's authorized session, then returns the result. The tools available are exactly the ones Lucid's own MCP server exposes — C1 doesn't reshape or add to them. +C1.ai registers as a client of Lucid's own hosted MCP server ([Integrate Lucid with AI tools using the Lucid MCP server](https://help.lucid.co/hc/en-us/articles/42578801807508-Integrate-Lucid-with-AI-tools-using-the-Lucid-MCP-server)) rather than translating Lucid's REST API itself. Your users' AI clients still only ever see C1.ai-governed MCP tools, but C1.ai proxies each tool call straight through to `mcp.lucid.app` under the connected user's authorized session, then returns the result. The tools available are exactly the ones Lucid's own MCP server exposes — C1.ai doesn't reshape or add to them. ## Before you begin @@ -40,16 +40,16 @@ C1 registers as a client of Lucid's own hosted MCP server ([Integrate Lucid with - Nothing else to create in Lucid ahead of time. This option only supports per-user OAuth with dynamic client registration — Lucid's hosted MCP server doesn't offer a bearer token or API key mode, so there's no client ID, secret, or application to register. Each user just needs a Lucid account with access to the workspace. -In your MCP server catalog, this option is listed as **Lucid** — distinct from the **Lucid API** entry, which connects through C1's own MCP server. If you don't see either, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +In your MCP server catalog, this option is listed as **Lucid** — distinct from the **Lucid API** entry, which connects through C1.ai's own MCP server. If you don't see either, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Set up per-user OAuth -Per-user OAuth with dynamic client registration (DCR) is the only authentication method this option supports — there's no bearer token or API key fallback. Each user authorizes individually, and C1 registers itself with Lucid's authorization server automatically, so there's no application to create in Lucid first (see Lucid's [Integrate Lucid with AI tools using the Lucid MCP server](https://help.lucid.co/hc/en-us/articles/42578801807508-Integrate-Lucid-with-AI-tools-using-the-Lucid-MCP-server#faq) documentation). +Per-user OAuth with dynamic client registration (DCR) is the only authentication method this option supports — there's no bearer token or API key fallback. Each user authorizes individually, and C1.ai registers itself with Lucid's authorization server automatically, so there's no application to create in Lucid first (see Lucid's [Integrate Lucid with AI tools using the Lucid MCP server](https://help.lucid.co/hc/en-us/articles/42578801807508-Integrate-Lucid-with-AI-tools-using-the-Lucid-MCP-server#faq) documentation). -In Lucid, have an account admin go to the Lucid Admin Panel and enable MCP access for the account. This is a prerequisite — until it's enabled, users can't connect regardless of how the server is configured in C1. +In Lucid, have an account admin go to the Lucid Admin Panel and enable MCP access for the account. This is a prerequisite — until it's enabled, users can't connect regardless of how the server is configured in C1.ai. Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-server) and select **Lucid** from the catalog. @@ -58,21 +58,21 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **OAuth2 — per-user passthrough** and enable **Use dynamic client registration**. There's no client ID or secret to enter. -Save your changes. The first time a user calls a Lucid tool from their AI client, they're redirected to Lucid to sign in (if they aren't already) and approve the connection, then returned to C1. +Save your changes. The first time a user calls a Lucid tool from their AI client, they're redirected to Lucid to sign in (if they aren't already) and approve the connection, then returned to C1.ai. ## What access is granted -Unlike the Lucid API option, there are no separate scope toggles to configure in C1. Once a user authorizes, tool calls run with that user's full Lucid permissions — they can access everything the user can already access in Lucid, including documents and folders across Lucidchart, Lucidspark, and Lucidscale. This integration's tools can search for and open documents, read their contents and metadata, create and edit diagrams (including org charts, mind maps, and UML sequence diagrams), export documents as images, and manage sharing — creating share links and granting collaborators view, comment, edit, or edit-and-share access ([Integrate Lucid with AI tools using the Lucid MCP server](https://help.lucid.co/hc/en-us/articles/42578801807508-Integrate-Lucid-with-AI-tools-using-the-Lucid-MCP-server#available-actions); [Lucid MCP Server — Supported Operations](https://learn.microsoft.com/en-us/connectors/lucidmcpserver/)). Access follows your normal Lucid permissions — the integration can only reach documents and folders you can already see. +Unlike the Lucid API option, there are no separate scope toggles to configure in C1.ai. Once a user authorizes, tool calls run with that user's full Lucid permissions — they can access everything the user can already access in Lucid, including documents and folders across Lucidchart, Lucidspark, and Lucidscale. This integration's tools can search for and open documents, read their contents and metadata, create and edit diagrams (including org charts, mind maps, and UML sequence diagrams), export documents as images, and manage sharing — creating share links and granting collaborators view, comment, edit, or edit-and-share access ([Integrate Lucid with AI tools using the Lucid MCP server](https://help.lucid.co/hc/en-us/articles/42578801807508-Integrate-Lucid-with-AI-tools-using-the-Lucid-MCP-server#available-actions); [Lucid MCP Server — Supported Operations](https://learn.microsoft.com/en-us/connectors/lucidmcpserver/)). Access follows your normal Lucid permissions — the integration can only reach documents and folders you can already see. ## How Lucid MCP credentials are shared -This option only supports per-user OAuth — there's no shared, service-account, or bearer-token mode. Every tool call runs under the calling user's own Lucid identity, and Lucid attributes each action to that individual. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). +This option only supports per-user OAuth — there's no shared, service-account, or bearer-token mode. Every tool call runs under the calling user's own Lucid identity, and Lucid attributes each action to that individual. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). ## Discover and govern tools -After you register the server, C1 runs tool discovery against Lucid's MCP server. Discovered tools appear on the server's **Tools** tab and include Lucid's own document search and fetch tools, diagram creation (including org charts, mind maps, and UML sequence diagrams), image export, and sharing. +After you register the server, C1.ai runs tool discovery against Lucid's MCP server. Discovered tools appear on the server's **Tools** tab and include Lucid's own document search and fetch tools, diagram creation (including org charts, mind maps, and UML sequence diagrams), image export, and sharing. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -84,7 +84,7 @@ Tool discovery runs even if authentication isn't complete yet, so seeing discove ## Manage access to Lucid MCP -Because this option uses per-user OAuth, there's no shared secret in C1 to rotate. Users and admins manage access from Lucid itself: +Because this option uses per-user OAuth, there's no shared secret in C1.ai to rotate. Users and admins manage access from Lucid itself: - **An individual user can disconnect at any time.** In Lucid, open account settings and go to the **Authorized Websites and Applications** list, then select the app and choose the remove option to revoke it ([Access and update account settings](https://help.lucid.co/hc/en-us/articles/360049864551-Access-and-update-account-settings#apps-and-integrations-settings)). - **An account admin can turn off MCP access for everyone.** In the Lucid Admin Panel, disable MCP access for the account. This revokes every AI tool and MCP client connected through Lucid MCP at once; users must re-authenticate if it's re-enabled later. @@ -93,7 +93,7 @@ Because this option uses per-user OAuth, there's no shared secret in C1 to rotat -The Lucid MCP server lets you govern access to Lucid — documents, folders, teams, users, and account data — as tools your AI clients can call through C1. +The Lucid MCP server lets you govern access to Lucid — documents, folders, teams, users, and account data — as tools your AI clients can call through C1.ai. Lucid supports two ways to authenticate, and you choose one when you register the server: @@ -102,11 +102,11 @@ Lucid supports two ways to authenticate, and you choose one when you register th For a deeper comparison of shared versus per-user credentials, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## How C1 connects to Lucid +## How C1.ai connects to Lucid -C1 hosts the Lucid MCP server, so your users' AI clients only ever see MCP tools — they never call Lucid directly. When an AI client calls one of these tools, C1 makes the matching request to the Lucid API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Lucid MCP server, so your users' AI clients only ever see MCP tools — they never call Lucid directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Lucid API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call Lucid on your users' behalf. +The credentials you set up below are what C1.ai uses to call Lucid on your users' behalf. ## Before you begin @@ -115,7 +115,7 @@ The credentials you set up below are what C1 uses to call Lucid on your users' b - For an API token, the Lucid account whose access the token should carry. -In your MCP server catalog, this option is listed as **Lucid API** — distinct from the **Lucid** entry, which connects to Lucid's own hosted MCP server. If you don't see either, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +In your MCP server catalog, this option is listed as **Lucid API** — distinct from the **Lucid** entry, which connects to Lucid's own hosted MCP server. If you don't see either, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Option 1: Set up per-user OAuth @@ -131,7 +131,7 @@ Register an OAuth 2.0 application in Lucid that users will authorize through. Fo In Lucid, go to **Account settings** > **Developer** and create a new OAuth 2.0 application. -Set the **redirect URI** exactly to whichever matches your C1 tenant's domain: +Set the **redirect URI** exactly to whichever matches your C1.ai tenant's domain: - Default instance: `https://accounts.conductor.one/auth/callback` - EU data residency instance: `https://accounts.c1eu.ai/auth/callback` @@ -146,7 +146,7 @@ Save the application, then copy the **Client ID** and **Client Secret**. Lucid s ### Register the server with OAuth -With your OAuth application ready, register the server and provide its credentials to C1. +With your OAuth application ready, register the server and provide its credentials to C1.ai. @@ -166,7 +166,7 @@ A Lucid API token authenticates every user as one shared Lucid identity. Use thi ### Create a Lucid API token -Generate an API token in Lucid for C1 to authenticate with. For more information, see Lucid's [API keys](https://developer.lucid.co/docs/api-keys) documentation. +Generate an API token in Lucid for C1.ai to authenticate with. For more information, see Lucid's [API keys](https://developer.lucid.co/docs/api-keys) documentation. @@ -180,11 +180,11 @@ Copy the token. Lucid shows the token only once. -For a shared production setup, create the token from a dedicated service-account user so activity is attributable to C1 rather than a person. +For a shared production setup, create the token from a dedicated service-account user so activity is attributable to C1.ai rather than a person. ### Register the server with a token -With your API token ready, register the server and provide it to C1. +With your API token ready, register the server and provide it to C1.ai. @@ -194,7 +194,7 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Bearer token** and paste your API token. -Save your changes. C1 starts a sync that discovers the tools the Lucid server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Lucid server exposes. @@ -203,13 +203,13 @@ Save your changes. C1 starts a sync that discovers the tools the Lucid server ex How Lucid sees your users' activity depends on the method you chose: - **Per-user OAuth.** Each user authorizes with their own Lucid account, so tool calls run under that user's Lucid identity and inherit only the access they already have. Lucid attributes each action to the individual user. -- **API token.** Every user's tool calls use the one token you provided, so Lucid sees a single shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). +- **API token.** Every user's tool calls use the one token you provided, so Lucid sees a single shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). ## Discover and govern tools -After you register the server, C1 runs tool discovery against Lucid. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Lucid. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -221,8 +221,8 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Lucid credentials -- **Rotate the OAuth client secret** in your Lucid OAuth application under **Account settings** > **Developer**, then update the secret on the server's authentication settings in C1. -- **Rotate an API token** by generating a new one in Lucid and updating it in C1, then revoking the old token. +- **Rotate the OAuth client secret** in your Lucid OAuth application under **Account settings** > **Developer**, then update the secret on the server's authentication settings in C1.ai. +- **Rotate an API token** by generating a new one in Lucid and updating it in C1.ai, then revoking the old token. - **Adjust access** by editing the application's scopes in Lucid. diff --git a/product/admin/mcp-server/mcp-bridge.mdx b/product/admin/mcp-server/mcp-bridge.mdx index 6eea7018..5be18033 100644 --- a/product/admin/mcp-server/mcp-bridge.mdx +++ b/product/admin/mcp-server/mcp-bridge.mdx @@ -1,7 +1,7 @@ --- title: Connect a private MCP server through a bridge description: Route AI tool calls to an MCP server running in your private network — no inbound firewall rules needed. -og:title: Connect a private MCP server through a bridge - C1 docs +og:title: Connect a private MCP server through a bridge - C1.ai docs og:description: Route AI tool calls to an MCP server running in your private network — no inbound firewall rules needed. sidebarTitle: Private bridge --- @@ -9,33 +9,33 @@ sidebarTitle: Private bridge {/* Editor Refresh: 2026-06-25 */} -**Activation required.** AI access management must be enabled for your tenant, and private bridge connectivity must be turned on separately. To get started, [contact the C1 support team](mailto:support@c1.ai). +**Activation required.** AI access management must be enabled for your tenant, and private bridge connectivity must be turned on separately. To get started, [contact the C1.ai support team](mailto:support@c1.ai). -If your MCP server runs in a private network — a laptop, a VM, or a cluster — and you can't or don't want to open inbound firewall rules, you can reach it through a **bridge**. You run a small agent (`bridge-client`) next to your server; it dials out to C1 and holds a tunnel open. C1 sends incoming tool calls back down that tunnel, so nothing in your network needs to listen for inbound connections. A single bridge isn't limited to one server: it can expose multiple MCP servers at once, each as its own named service (see [Expose multiple MCP servers on one bridge](#expose-multiple-mcp-servers-on-one-bridge)). Note the distinction: multiple *services* run through one `bridge-client`, not through multiple copies of it — a credential holds only one session, so run exactly one `bridge-client` instance per credential. Multiple instances sharing a credential evict each other continuously (see [Troubleshooting](#troubleshooting-bridge-connection-issues)). +If your MCP server runs in a private network — a laptop, a VM, or a cluster — and you can't or don't want to open inbound firewall rules, you can reach it through a **bridge**. You run a small agent (`bridge-client`) next to your server; it dials out to C1.ai and holds a tunnel open. C1.ai sends incoming tool calls back down that tunnel, so nothing in your network needs to listen for inbound connections. A single bridge isn't limited to one server: it can expose multiple MCP servers at once, each as its own named service (see [Expose multiple MCP servers on one bridge](#expose-multiple-mcp-servers-on-one-bridge)). Note the distinction: multiple *services* run through one `bridge-client`, not through multiple copies of it — a credential holds only one session, so run exactly one `bridge-client` instance per credential. Multiple instances sharing a credential evict each other continuously (see [Troubleshooting](#troubleshooting-bridge-connection-issues)). Setup has two halves that must match each other: -1. A **bridge config** (YAML) that tells `bridge-client` where your MCP servers are and what to advertise to C1. -2. An **MCP server registration** in C1, one per advertised service, that points C1 at that service over the bridge. +1. A **bridge config** (YAML) that tells `bridge-client` where your MCP servers are and what to advertise to C1.ai. +2. An **MCP server registration** in C1.ai, one per advertised service, that points C1.ai at that service over the bridge. ## Before you begin - Your MCP server must be running and reachable from wherever you'll run `bridge-client`. Have its `host:port`, endpoint path (typically `/mcp`), and transport (`streamable-http` or `sse`) ready. -- Download `bridge-client` from the [C1 download center](https://dist.conductorone.com/ConductorOne/bridge-client). Linux and macOS binaries and container images are available there. +- Download `bridge-client` from the [C1.ai download center](https://dist.conductorone.com/ConductorOne/bridge-client). Linux and macOS binaries and container images are available there. - **Creating a bridge** requires the **Connector Administrator** or **Super Administrator** role. - **Registering the MCP server** requires the **Editor** role on the destination app. -## Step 1: Create a bridge in C1 +## Step 1: Create a bridge in C1.ai -Creating a bridge issues the credentials that `bridge-client` uses to authenticate to C1. +Creating a bridge issues the credentials that `bridge-client` uses to authenticate to C1.ai. -In C1, go to **Settings** > **Bridges**. +In C1.ai, go to **Settings** > **Bridges**. -Give it a display name (for example, `my-laptop` or `prod-vpc-east`) and optionally a description, then click **Create bridge**. C1 navigates to the bridge's detail page. +Give it a display name (for example, `my-laptop` or `prod-vpc-east`) and optionally a description, then click **Create bridge**. C1.ai navigates to the bridge's detail page. On the bridge detail page, find the **Credentials** card and click **Create credential**. (On a bridge that already has an active credential, this button is labeled **Rotate credential** instead.) @@ -45,7 +45,7 @@ Copy the **Client ID** and **Client secret** from the dialog. -The bridge is created in C1. You'll add the credentials to your config in the next step. +The bridge is created in C1.ai. You'll add the credentials to your config in the next step. The client secret is shown only once. Copy it now — you'll paste it into the bridge config in the next step. @@ -75,13 +75,13 @@ bridge: | :--- | :--- | :--- | | `listen_port` | Yes | Port advertised on the bridge (1–65535). Must be unique within the config. | | `backend` | Yes | Local `host:port` that `bridge-client` dials — where your MCP server listens. | -| `name` | Recommended | Service name shown in C1. You select this name when registering the MCP server. Must be unique within the config. | +| `name` | Recommended | Service name shown in C1.ai. You select this name when registering the MCP server. Must be unique within the config. | | `service_type` | No | `MCP_NATIVE` (native MCP server), `HOSTED` (hosted HTTP MCP), or `RAW` (opaque TCP). | | `service_path` | No | The MCP endpoint path, for example `/mcp`. | | `transport_type` | No | `streamable-http` or `sse` for an MCP server, or `http` for a hosted HTTP service. | -The `service_path` and `transport_type` you set here are what C1 uses when routing tool calls. The registration wizard in Step 4 doesn't let you override them, so set them correctly now. +The `service_path` and `transport_type` you set here are what C1.ai uses when routing tool calls. The registration wizard in Step 4 doesn't let you override them, so set them correctly now. ### Expose multiple MCP servers on one bridge @@ -108,7 +108,7 @@ bridge: transport_type: streamable-http ``` -Each service appears separately on the bridge detail page, and you register each one as its own MCP server in C1 (Step 4), selecting it by its `name`. +Each service appears separately on the bridge detail page, and you register each one as its own MCP server in C1.ai (Step 4), selecting it by its `name`. ### Other ways to supply config @@ -243,9 +243,9 @@ kubectl apply -f bridge-deployment.yaml After a few seconds, the bridge status changes to **Connected** in **Settings** > **Bridges**, and the service you configured appears on the bridge detail page. -## Step 4: Register the MCP server in C1 +## Step 4: Register the MCP server in C1.ai -With the bridge running, register the server in C1 so its tools are available for governance. +With the bridge running, register the server in C1.ai so its tools are available for governance. @@ -257,7 +257,7 @@ If you're starting from the tenant-wide MCP servers page (**AI** > **MCPs**) ins Under **Choose a server**, select **External MCP server** — "Connect to an external MCP server by URL." -Under **Connectivity**, select **Private bridge** — "Route through a C1 Bridge running in your network." Then set: +Under **Connectivity**, select **Private bridge** — "Route through a C1.ai Bridge running in your network." Then set: - **Bridge** — the bridge you created in Step 1. - **Service** — the service your bridge advertised, which is the `name` field from `bridge.yaml` (`my-mcp` in the example). @@ -265,11 +265,11 @@ Under **Connectivity**, select **Private bridge** — "Route through a C1 Bridge Under **Configure**, enter a display name for the server. The **Server URL** field is read-only — it's resolved automatically from the bridge service you selected. -In the **Authentication** section, pick the **Authentication method** C1 uses to reach your server — **Bearer token**, **Custom header**, **Basic auth**, or **OAuth2** — and enter the credentials it requires. Then click **Add server**. +In the **Authentication** section, pick the **Authentication method** C1.ai uses to reach your server — **Bearer token**, **Custom header**, **Basic auth**, or **OAuth2** — and enter the credentials it requires. Then click **Add server**. -C1 connects to your server over the bridge and begins tool discovery. +C1.ai connects to your server over the bridge and begins tool discovery. A user can only call a tool once they're an **app user** of the app the server is registered under. New external apps start with no app users. When you register from an existing app that has none, the wizard inserts a **Link users** step to populate them by linking an entitlement from another app. When you start from the tenant-wide MCP servers page instead, you get the **Choose app** step (not **Link users**) — populate app users afterward from the app's settings. See [Calling the tools from an AI client](#calling-the-tools-from-an-ai-client) for the full set of ways to do this. @@ -277,13 +277,13 @@ A user can only call a tool once they're an **app user** of the app the server i ## Step 5: Review discovered tools -After you click **Add server**, C1 connects to your MCP server over the bridge and pulls its tool list. The wizard's final step shows these discovered tools. +After you click **Add server**, C1.ai connects to your MCP server over the bridge and pulls its tool list. The wizard's final step shows these discovered tools. -C1 records each tool's name, description, and input schema exactly as your MCP server advertises them, and surfaces that text to AI clients during discovery. The agent relies on it to decide which tool fits a request — so clear, accurate tool descriptions and schemas on your server directly affect how reliably the right tool gets found and called. +C1.ai records each tool's name, description, and input schema exactly as your MCP server advertises them, and surfaces that text to AI clients during discovery. The agent relies on it to decide which tool fits a request — so clear, accurate tool descriptions and schemas on your server directly affect how reliably the right tool gets found and called. Each tool: -- Becomes its own **entitlement** in C1 — access is requested, granted, and reviewed like any other entitlement. +- Becomes its own **entitlement** in C1.ai — access is requested, granted, and reviewed like any other entitlement. - Is **auto-classified** in the **Classification** column; you can change the classification. - Starts with **State** set to **Unset**. Flip the toggle to **Enabled** to allow calls to that tool, or **Disabled** to block it for everyone. @@ -296,7 +296,7 @@ Setting a tool's state to **Enabled** makes it callable only by users who hold a ## Step 6: Verify the connection - In **Settings** > **Bridges**, the bridge shows **Connected**, with your service listed. -- On the server's **Tools** tab in C1, the discovered tools appear. +- On the server's **Tools** tab in C1.ai, the discovered tools appear. - On the server's **Details** tab, **Test credentials** succeeds and reports the number of tools discovered over the bridge. If something looks off, check the `bridge-client` logs. For a binary deployment, logs go to stdout/stderr. For Kubernetes: @@ -307,15 +307,15 @@ kubectl logs -l app=bridge-client -f ## Calling the tools from an AI client -Once the bridge is running and tools are approved, your users reach them from their AI clients (Claude Code, Claude Desktop, Cursor, VS Code) through C1's MCP gateway — not through the bridge directly. C1 authenticates the user, enforces tool governance, and routes each call through the bridge to your local server. +Once the bridge is running and tools are approved, your users reach them from their AI clients (Claude Code, Claude Desktop, Cursor, VS Code) through C1.ai's MCP gateway — not through the bridge directly. C1.ai authenticates the user, enforces tool governance, and routes each call through the bridge to your local server. -By default, these clients use **code mode**: instead of listing each tool as its own named tool, C1 exposes discovery and execution entrypoints (`describe` and `execute`), and the agent finds the tools it needs and invokes them by writing short code. Your bridged tools won't appear one by one in the client's tool list — that's expected, not a discovery failure. Governance is unchanged: every underlying call still runs the same per-tool checks — the tool must be **Enabled** and the caller must hold a grant. Code mode is a tenant-level AI governance setting (on by default); with it off — or for **Service** and **Ephemeral** client types — C1 instead exposes each enabled tool as a directly named tool. See [Code mode](/product/admin/code-mode) for how agents discover and call tools through these entrypoints. +By default, these clients use **code mode**: instead of listing each tool as its own named tool, C1.ai exposes discovery and execution entrypoints (`describe` and `execute`), and the agent finds the tools it needs and invokes them by writing short code. Your bridged tools won't appear one by one in the client's tool list — that's expected, not a discovery failure. Governance is unchanged: every underlying call still runs the same per-tool checks — the tool must be **Enabled** and the caller must hold a grant. Code mode is a tenant-level AI governance setting (on by default); with it off — or for **Service** and **Ephemeral** client types — C1.ai instead exposes each enabled tool as a directly named tool. See [Code mode](/product/admin/code-mode) for how agents discover and call tools through these entrypoints. A call only executes when the requesting user is an **app user** of the server's app and holds a grant for the tool. If the caller isn't yet an app user, the call opens an access request instead of running. App users come from the destination app's account sources. Populate them by linking an entitlement from another app (the **Link users** step during registration, or linked entitlements later in the app's settings), by importing a CSV of app users, or — if the app is backed by a connector — by syncing them from the connector. -For end-user setup instructions, see [Connect your MCP client to C1](/product/how-to/connect-mcp-client). +For end-user setup instructions, see [Connect your MCP client to C1.ai](/product/how-to/connect-mcp-client). ## Troubleshooting bridge connection issues diff --git a/product/admin/mcp-server/metabase.mdx b/product/admin/mcp-server/metabase.mdx index 3dd9bbd0..e5ed4a77 100644 --- a/product/admin/mcp-server/metabase.mdx +++ b/product/admin/mcp-server/metabase.mdx @@ -1,26 +1,26 @@ --- title: Set up the Metabase MCP server -description: Create a Metabase API key, then register the Metabase MCP server in C1 and govern the tools it exposes. +description: Create a Metabase API key, then register the Metabase MCP server in C1.ai and govern the tools it exposes. og:title: Set up the Metabase MCP server -og:description: Create a Metabase API key, then register the Metabase MCP server in C1 and govern the tools it exposes. +og:description: Create a Metabase API key, then register the Metabase MCP server in C1.ai and govern the tools it exposes. sidebarTitle: Metabase --- {/* Editor Refresh: 2026-06-11 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -The Metabase MCP server lets you govern access to Metabase — dashboards, questions, collections, databases, and users — as tools your AI clients can call through C1. +The Metabase MCP server lets you govern access to Metabase — dashboards, questions, collections, databases, and users — as tools your AI clients can call through C1.ai. -Metabase authenticates with an API key that C1 sends in a request header. A single key authenticates everyone, so all tool calls reach Metabase as one shared identity. +Metabase authenticates with an API key that C1.ai sends in a request header. A single key authenticates everyone, so all tool calls reach Metabase as one shared identity. -## How C1 connects to Metabase +## How C1.ai connects to Metabase -C1 hosts the Metabase MCP server, so your users' AI clients only ever see MCP tools — they never call Metabase directly. When an AI client calls one of these tools, C1 makes the matching request to the Metabase API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Metabase MCP server, so your users' AI clients only ever see MCP tools — they never call Metabase directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Metabase API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call Metabase on your users' behalf. +The credentials you set up below are what C1.ai uses to call Metabase on your users' behalf. ## Before you begin @@ -28,7 +28,7 @@ The credentials you set up below are what C1 uses to call Metabase on your users - A Metabase admin account that can create API keys. An API key inherits the permissions of the group you assign it to, so assign a group that has the access you want this integration to have. -If you don't see **Metabase** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **Metabase** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Create a Metabase API key @@ -50,17 +50,17 @@ Create the key and copy it. Metabase shows the key only once. -For a shared production setup, assign the key to a dedicated group so activity is attributable to C1 rather than a person, and scope that group to only the data you want to govern. +For a shared production setup, assign the key to a dedicated group so activity is attributable to C1.ai rather than a person, and scope that group to only the data you want to govern. ## How Metabase credentials are shared -Every user's tool calls use the one API key you provided, so Metabase sees a single shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared setup, assign the key to a dedicated group so activity is attributable to C1 rather than a person. +Every user's tool calls use the one API key you provided, so Metabase sees a single shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared setup, assign the key to a dedicated group so activity is attributable to C1.ai rather than a person. For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## Register the Metabase MCP server in C1 +## Register the Metabase MCP server in C1.ai -With your API key ready, register the server and provide it to C1. +With your API key ready, register the server and provide it to C1.ai. @@ -70,13 +70,13 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Custom header**. Set the header name to `X-Api-Key` and the value to your Metabase API key. Enter your Metabase instance URL when prompted. -Save your changes. C1 starts a sync that discovers the tools the Metabase server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Metabase server exposes. ## Discover and govern tools -After you register the server, C1 runs tool discovery against Metabase. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Metabase. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -88,5 +88,5 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Metabase credentials -- **Rotate the API key** by creating a new key under **Admin settings** > **Authentication** > **API Keys**, updating it in C1, then deleting the old key. +- **Rotate the API key** by creating a new key under **Admin settings** > **Authentication** > **API Keys**, updating it in C1.ai, then deleting the old key. - **Adjust access** by changing the group the key belongs to, or by editing that group's permissions in Metabase. diff --git a/product/admin/mcp-server/metronome.mdx b/product/admin/mcp-server/metronome.mdx index cce770a4..d78071f3 100644 --- a/product/admin/mcp-server/metronome.mdx +++ b/product/admin/mcp-server/metronome.mdx @@ -1,26 +1,26 @@ --- title: Set up the Metronome MCP server -description: Create a Metronome API token, then register the Metronome MCP server in C1 and govern the tools your AI clients can call. +description: Create a Metronome API token, then register the Metronome MCP server in C1.ai and govern the tools your AI clients can call. og:title: Set up the Metronome MCP server -og:description: Create a Metronome API token, then register the Metronome MCP server in C1 and govern the tools your AI clients can call. +og:description: Create a Metronome API token, then register the Metronome MCP server in C1.ai and govern the tools your AI clients can call. sidebarTitle: Metronome --- {/* Editor Refresh: 2026-06-11 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -The Metronome MCP server lets you govern access to Metronome — customers, contracts, invoices, billable metrics, products, rate cards, and usage data — as tools your AI clients can call through C1. +The Metronome MCP server lets you govern access to Metronome — customers, contracts, invoices, billable metrics, products, rate cards, and usage data — as tools your AI clients can call through C1.ai. -Metronome authenticates with an API token that C1 sends as a bearer token. A single token authenticates everyone, so all tool calls reach Metronome as one shared identity. +Metronome authenticates with an API token that C1.ai sends as a bearer token. A single token authenticates everyone, so all tool calls reach Metronome as one shared identity. -## How C1 connects to Metronome +## How C1.ai connects to Metronome -C1 hosts the Metronome MCP server, so your users' AI clients only ever see MCP tools — they never call Metronome directly. When an AI client calls one of these tools, C1 makes the matching request to the Metronome API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Metronome MCP server, so your users' AI clients only ever see MCP tools — they never call Metronome directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Metronome API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call Metronome on your users' behalf. +The credentials you set up below are what C1.ai uses to call Metronome on your users' behalf. ## Before you begin @@ -28,12 +28,12 @@ The credentials you set up below are what C1 uses to call Metronome on your user - A Metronome account that can create API tokens. New tokens inherit the permissions of the user that created them, so create the token under an account that has the access you want this integration to have. -If you don't see **Metronome** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **Metronome** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Create a Metronome API token -Create an API token in the Metronome app for C1 to authenticate with. +Create an API token in the Metronome app for C1.ai to authenticate with. @@ -50,17 +50,17 @@ Copy the token immediately. Metronome shows the full token only once and you can -For a shared production setup, create the token under a dedicated service-account user so activity is attributable to C1 rather than a person. If your Metronome account enforces an inbound IP allowlist, add C1's egress IPs to it. See [Network requirements](/product/admin/requirements). +For a shared production setup, create the token under a dedicated service-account user so activity is attributable to C1.ai rather than a person. If your Metronome account enforces an inbound IP allowlist, add C1.ai's egress IPs to it. See [Network requirements](/product/admin/requirements). ## How Metronome credentials are shared -Every user's tool calls use the one API token you provided, so Metronome sees a single shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared production setup, create the token from a dedicated service-account user so Metronome activity is attributable to C1 rather than a person. +Every user's tool calls use the one API token you provided, so Metronome sees a single shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared production setup, create the token from a dedicated service-account user so Metronome activity is attributable to C1.ai rather than a person. For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## Register the Metronome MCP server in C1 +## Register the Metronome MCP server in C1.ai -With your API token ready, register the server and provide it to C1. +With your API token ready, register the server and provide it to C1.ai. @@ -70,13 +70,13 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Bearer token** and paste your Metronome API token. -Save your changes. C1 starts a sync that discovers the tools the Metronome server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Metronome server exposes. ## Discover and govern tools -After you register the server, C1 runs tool discovery against Metronome. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Metronome. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -88,5 +88,5 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Metronome credentials -- **Rotate the API token** by creating a new one in Metronome under **Connections** > **API tokens & webhooks**, updating it in C1, then archiving the old token with the trash icon. Metronome recommends removing unused tokens and rotating tokens in use regularly. Archival is permanent, so confirm the new token works before you archive the old one. +- **Rotate the API token** by creating a new one in Metronome under **Connections** > **API tokens & webhooks**, updating it in C1.ai, then archiving the old token with the trash icon. Metronome recommends removing unused tokens and rotating tokens in use regularly. Archival is permanent, so confirm the new token works before you archive the old one. - **Adjust access** by creating the token under a user whose permissions match the access you want, since a token inherits its creator's permissions. To scope a token further by access level, environment, or endpoint, contact your Metronome representative. diff --git a/product/admin/mcp-server/monday.mdx b/product/admin/mcp-server/monday.mdx index de3e9264..443965f5 100644 --- a/product/admin/mcp-server/monday.mdx +++ b/product/admin/mcp-server/monday.mdx @@ -1,31 +1,31 @@ --- title: Set up the monday.com MCP server -description: Connect monday.com to C1 through monday.com's own hosted MCP server or the monday.com API, then register the server and govern its tools. +description: Connect monday.com to C1.ai through monday.com's own hosted MCP server or the monday.com API, then register the server and govern its tools. og:title: Set up the monday.com MCP server -og:description: Connect monday.com to C1 through monday.com's own hosted MCP server or the monday.com API, then register the server and govern its tools. +og:description: Connect monday.com to C1.ai through monday.com's own hosted MCP server or the monday.com API, then register the server and govern its tools. sidebarTitle: monday.com --- {/* Editor Refresh: 2026-07-24 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -C1 can govern monday.com access two ways. Both let your AI clients read from and act on monday.com through governed MCP tools, but they come from different places and appear as two separate entries in your MCP server catalog — and the two catalog names are easy to mix up: +C1.ai can govern monday.com access two ways. Both let your AI clients read from and act on monday.com through governed MCP tools, but they come from different places and appear as two separate entries in your MCP server catalog — and the two catalog names are easy to mix up: -- **Monday** — the native MCP option. C1 registers monday.com's own hosted MCP server (`mcp.monday.com`) as a downstream server C1 governs. Authentication is always per-user OAuth using dynamic client registration (DCR) — monday.com's hosted MCP server doesn't support a bearer token or API key, so there's no integration to create in monday.com first. Tool calls run with the connected user's full monday.com permissions. -- **monday.com** — the API option. C1 hosts its own MCP server that translates monday.com's REST/GraphQL API into tools. Authentication is a single personal API token sent as a bearer token, so all tool calls reach monday.com as one shared identity. +- **Monday** — the native MCP option. C1.ai registers monday.com's own hosted MCP server (`mcp.monday.com`) as a downstream server C1.ai governs. Authentication is always per-user OAuth using dynamic client registration (DCR) — monday.com's hosted MCP server doesn't support a bearer token or API key, so there's no integration to create in monday.com first. Tool calls run with the connected user's full monday.com permissions. +- **monday.com** — the API option. C1.ai hosts its own MCP server that translates monday.com's REST/GraphQL API into tools. Authentication is a single personal API token sent as a bearer token, so all tool calls reach monday.com as one shared identity. In your catalog, the bare name **Monday** always means the native hosted-MCP option, and **monday.com** always means the API option below — the two entries are distinct servers with different authentication models, not two names for the same thing. | | Monday | monday.com | | :--- | :--- | :--- | -| **Who hosts the MCP server** | monday.com | C1 | +| **Who hosts the MCP server** | monday.com | C1.ai | | **Authentication** | Per-user OAuth with dynamic client registration (DCR) only — no bearer token or API key option | A single personal API token, sent as a bearer token | | **Access scoping** | The connected user's full monday.com permissions — not independently scoped, though an account admin can still limit hosted MCP to specific workspaces | Whatever workspace, board, column, and item access the token's creator has — not independently scoped | | **Tool surface** | monday.com's own tool set: search, boards, items and subitems, updates, docs, dashboards, workflows, and automations | Boards, items, columns, groups, workspaces, and users, mapped to monday.com API endpoints | -| **Setup effort** | An account admin must first turn on hosted MCP access in monday.com, then register in C1 and authorize | Create a personal API token in monday.com, then register it in C1 | +| **Setup effort** | An account admin must first turn on hosted MCP access in monday.com, then register in C1.ai and authorize | Create a personal API token in monday.com, then register it in C1.ai | Use the native **Monday** option if you want monday.com's own broader, agentic tool set and per-user OAuth is acceptable for your tenant. Use **monday.com** if you need a shared service-account credential instead of per-user login. @@ -33,7 +33,7 @@ Use the native **Monday** option if you want monday.com's own broader, agentic t -C1 registers as a client of monday.com's own hosted MCP server ([monday MCP: Connect AI assistants to your account](https://monday.com/w/mcp)) rather than translating monday.com's REST API itself. Your users' AI clients still only ever see C1-governed MCP tools, but C1 proxies each tool call straight through to `mcp.monday.com` under the connected user's authorized session, then returns the result. +C1.ai registers as a client of monday.com's own hosted MCP server ([monday MCP: Connect AI assistants to your account](https://monday.com/w/mcp)) rather than translating monday.com's REST API itself. Your users' AI clients still only ever see C1.ai-governed MCP tools, but C1.ai proxies each tool call straight through to `mcp.monday.com` under the connected user's authorized session, then returns the result. ## Before you begin @@ -42,12 +42,12 @@ C1 registers as a client of monday.com's own hosted MCP server ([monday MCP: Con - Nothing to create in monday.com ahead of time. This option only supports per-user OAuth with dynamic client registration — there's no client ID, secret, bearer token, or API key mode, so there's no integration to register in monday.com first. Each user just needs a monday.com account with access to the workspace you want to govern. -In your MCP server catalog, this option is listed as **Monday** — distinct from the **monday.com** entry, which connects through C1's own MCP server. If you don't see either, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +In your MCP server catalog, this option is listed as **Monday** — distinct from the **monday.com** entry, which connects through C1.ai's own MCP server. If you don't see either, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Set up per-user OAuth with dynamic client registration -Per-user OAuth with dynamic client registration (DCR) is the only authentication method this option supports — there's no bearer token or API key fallback. Each user authorizes individually, and C1 registers itself with monday.com's authorization server automatically, so there's no app to create in monday.com first ([Platform MCP security](https://developer.monday.com/api-reference/docs/monday-mcp-security-overview)). +Per-user OAuth with dynamic client registration (DCR) is the only authentication method this option supports — there's no bearer token or API key fallback. Each user authorizes individually, and C1.ai registers itself with monday.com's authorization server automatically, so there's no app to create in monday.com first ([Platform MCP security](https://developer.monday.com/api-reference/docs/monday-mcp-security-overview)). @@ -57,7 +57,7 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **OAuth2 — per-user passthrough** and enable **Use dynamic client registration**. There's no client ID or secret to enter. -Save your changes. The first time a user calls a Monday tool from their AI client, they're redirected to monday.com to sign in (if they aren't already) and approve the connection, then returned to C1. +Save your changes. The first time a user calls a Monday tool from their AI client, they're redirected to monday.com to sign in (if they aren't already) and approve the connection, then returned to C1.ai. @@ -67,11 +67,11 @@ Unlike the monday.com API option, there are no separate capability toggles to co ## How Monday credentials are shared -This option only supports per-user OAuth — there's no shared, service-account, or bearer-token mode. Every tool call runs under the calling user's own monday.com identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). +This option only supports per-user OAuth — there's no shared, service-account, or bearer-token mode. Every tool call runs under the calling user's own monday.com identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). ## Discover and govern tools -After you register the server, C1 runs tool discovery against monday.com's MCP server. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against monday.com's MCP server. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -83,15 +83,15 @@ Tool discovery runs even if authentication isn't complete yet, so seeing discove ## Manage access to Monday -Because this option uses per-user OAuth, there's no shared secret in C1 to rotate. An account admin manages access from monday.com itself: under **Admin** > **Permissions** > **AI Connectors**, uncheck **Public Hosted MCP** to cut off this integration along with every other AI tool using monday.com's hosted MCP server, or turn off the whole **"Allow external AI agents to access your monday.com account data"** toggle to block all external AI access outright. Admins can also narrow access to specific workspaces from the same panel instead of revoking entirely ([Managing AI Connectors and MCP Access](https://support.monday.com/hc/en-us/articles/35696101067154-Managing-AI-Connectors-and-MCP-Access)). +Because this option uses per-user OAuth, there's no shared secret in C1.ai to rotate. An account admin manages access from monday.com itself: under **Admin** > **Permissions** > **AI Connectors**, uncheck **Public Hosted MCP** to cut off this integration along with every other AI tool using monday.com's hosted MCP server, or turn off the whole **"Allow external AI agents to access your monday.com account data"** toggle to block all external AI access outright. Admins can also narrow access to specific workspaces from the same panel instead of revoking entirely ([Managing AI Connectors and MCP Access](https://support.monday.com/hc/en-us/articles/35696101067154-Managing-AI-Connectors-and-MCP-Access)). -C1 hosts the monday.com MCP server, so your users' AI clients only ever see MCP tools — they never call monday.com directly. When an AI client calls one of these tools, C1 makes the matching request to monday.com's API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the monday.com MCP server, so your users' AI clients only ever see MCP tools — they never call monday.com directly. When an AI client calls one of these tools, C1.ai makes the matching request to monday.com's API using the credentials you configure here, then returns the result to the AI client. -monday.com authenticates with a personal API token that C1 sends as a bearer token. A single token authenticates everyone, so all tool calls reach monday.com as one shared identity. +monday.com authenticates with a personal API token that C1.ai sends as a bearer token. A single token authenticates everyone, so all tool calls reach monday.com as one shared identity. ## Before you begin @@ -99,12 +99,12 @@ monday.com authenticates with a personal API token that C1 sends as a bearer tok - A monday.com account that can generate a personal API token, with access to the boards and workspaces you want this integration to have. -In your MCP server catalog, this option is listed as **monday.com** — distinct from the **Monday** entry, which connects to monday.com's own hosted MCP server. If you don't see either, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +In your MCP server catalog, this option is listed as **monday.com** — distinct from the **Monday** entry, which connects to monday.com's own hosted MCP server. If you don't see either, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Create a monday.com personal API token -Create a personal API token in monday.com for C1 to authenticate with. See monday.com's [Authentication](https://developer.monday.com/api-reference/docs/authentication) documentation. +Create a personal API token in monday.com for C1.ai to authenticate with. See monday.com's [Authentication](https://developer.monday.com/api-reference/docs/authentication) documentation. @@ -118,17 +118,17 @@ Select **Show** and copy the token. -A personal token inherits whatever workspace, board, column, and item permissions the creating user already has in monday.com — there's no separate scope to configure. For a shared production setup, create the token under a dedicated service-account user so activity is attributable to C1 rather than a person. +A personal token inherits whatever workspace, board, column, and item permissions the creating user already has in monday.com — there's no separate scope to configure. For a shared production setup, create the token under a dedicated service-account user so activity is attributable to C1.ai rather than a person. ## How monday.com credentials are shared -Every user's tool calls use the one API token you provided, so monday.com sees a single shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). +Every user's tool calls use the one API token you provided, so monday.com sees a single shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## Register the monday.com MCP server in C1 +## Register the monday.com MCP server in C1.ai -With your API token ready, register the server and provide it to C1. +With your API token ready, register the server and provide it to C1.ai. @@ -138,13 +138,13 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Bearer token** and paste your personal API token. -Save your changes. C1 starts a sync that discovers the tools the monday.com server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the monday.com server exposes. ## Discover and govern tools -After you register the server, C1 runs tool discovery against monday.com. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against monday.com. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -156,7 +156,7 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your monday.com credentials -- **Rotate the personal API token** by regenerating it from the same **My access tokens** (or **Administration** > **Connections**) page in monday.com, then updating it in C1. Regenerating immediately invalidates the previous token, so confirm the new one works in C1 before considering the old one retired. +- **Rotate the personal API token** by regenerating it from the same **My access tokens** (or **Administration** > **Connections**) page in monday.com, then updating it in C1.ai. Regenerating immediately invalidates the previous token, so confirm the new one works in C1.ai before considering the old one retired. - **Adjust access** by changing the permissions of the user the token belongs to in monday.com, since the token mirrors whatever access that user already has. diff --git a/product/admin/mcp-server/n8n.mdx b/product/admin/mcp-server/n8n.mdx index 8a567481..20d4d1c9 100644 --- a/product/admin/mcp-server/n8n.mdx +++ b/product/admin/mcp-server/n8n.mdx @@ -1,32 +1,32 @@ --- title: Set up the n8n MCP server -description: Connect n8n to C1 through n8n's own hosted MCP server (n8n Cloud only) or the n8n API, then register the server and govern its tools. +description: Connect n8n to C1.ai through n8n's own hosted MCP server (n8n Cloud only) or the n8n API, then register the server and govern its tools. og:title: Set up the n8n MCP server -og:description: Connect n8n to C1 through n8n's own hosted MCP server (n8n Cloud only) or the n8n API, then register the server and govern its tools. +og:description: Connect n8n to C1.ai through n8n's own hosted MCP server (n8n Cloud only) or the n8n API, then register the server and govern its tools. sidebarTitle: n8n --- {/* Editor Refresh: 2026-07-24 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -C1 can govern n8n access two ways. Both let your AI clients read from and act on n8n through governed MCP tools, but they support different n8n deployments and appear as two separate entries in your MCP server catalog: +C1.ai can govern n8n access two ways. Both let your AI clients read from and act on n8n through governed MCP tools, but they support different n8n deployments and appear as two separate entries in your MCP server catalog: -- **n8n MCP** — listed as plain **n8n** in your catalog. C1 registers n8n's own hosted MCP server as a downstream server C1 governs. **This option works with n8n Cloud only.** Authentication is per-user OAuth 2.1 (dynamic client registration recommended), or a personal access token as a bearer credential fallback. -- **n8n API** — C1 hosts its own MCP server that translates n8n's REST API into tools. A single API key authenticates every user as one shared identity. This works with **either n8n Cloud or a self-hosted n8n instance**. +- **n8n MCP** — listed as plain **n8n** in your catalog. C1.ai registers n8n's own hosted MCP server as a downstream server C1.ai governs. **This option works with n8n Cloud only.** Authentication is per-user OAuth 2.1 (dynamic client registration recommended), or a personal access token as a bearer credential fallback. +- **n8n API** — C1.ai hosts its own MCP server that translates n8n's REST API into tools. A single API key authenticates every user as one shared identity. This works with **either n8n Cloud or a self-hosted n8n instance**. -**Use n8n MCP only if you're on n8n Cloud.** Self-hosted n8n instances can't use this option — use **n8n API** instead, or, if your self-hosted instance exposes its own MCP server, connect it to C1 as an external MCP server. +**Use n8n MCP only if you're on n8n Cloud.** Self-hosted n8n instances can't use this option — use **n8n API** instead, or, if your self-hosted instance exposes its own MCP server, connect it to C1.ai as an external MCP server. | | n8n MCP | n8n API | | :--- | :--- | :--- | | **n8n deployment supported** | n8n Cloud only | n8n Cloud or self-hosted | -| **Who hosts the MCP server** | n8n | C1 | +| **Who hosts the MCP server** | n8n | C1.ai | | **Authentication** | Per-user OAuth 2.1 with dynamic client registration (recommended), or a personal access token (bearer) | A single shared API key (custom header) | | **Access scoping** | The connected user's own n8n permissions in that workspace, or the token owner's permissions if using a personal access token | Whatever the API key's owning n8n user account can access | | **Tool surface** | n8n's own instance-level MCP tools: workflow search, execution, testing, and publishing; execution history; credential listing; workflow building and validation; data tables | Workflows, executions, credentials, tags, and users, mapped to n8n API endpoints | -| **Setup effort** | Register in C1 and authorize — nothing to create in n8n first (unless you choose a personal access token) | Create an n8n API key first, then register it in C1 | +| **Setup effort** | Register in C1.ai and authorize — nothing to create in n8n first (unless you choose a personal access token) | Create an n8n API key first, then register it in C1.ai | Use the native **n8n MCP** option (listed as plain **n8n** in your catalog) if you're on n8n Cloud and want n8n's own broader tool set with per-user OAuth. Use **n8n API** if you're on a self-hosted instance, or you need a shared service-account credential. @@ -34,22 +34,22 @@ Use the native **n8n MCP** option (listed as plain **n8n** in your catalog) if y -C1 registers as a client of n8n's own hosted MCP server rather than translating n8n's REST API itself. Your users' AI clients still only ever see C1-governed MCP tools, but C1 proxies each tool call straight through to your n8n Cloud workspace under the connected user's (or token's) authorized session, then returns the result. The tools available are exactly the ones n8n's own MCP server exposes — C1 doesn't reshape or add to them. See n8n's [MCP server tools reference](https://docs.n8n.io/connect/connect-to-n8n-mcp-server/mcp-server-tools-reference) for the full list. +C1.ai registers as a client of n8n's own hosted MCP server rather than translating n8n's REST API itself. Your users' AI clients still only ever see C1.ai-governed MCP tools, but C1.ai proxies each tool call straight through to your n8n Cloud workspace under the connected user's (or token's) authorized session, then returns the result. The tools available are exactly the ones n8n's own MCP server exposes — C1.ai doesn't reshape or add to them. See n8n's [MCP server tools reference](https://docs.n8n.io/connect/connect-to-n8n-mcp-server/mcp-server-tools-reference) for the full list. ## Before you begin - AI access management must be enabled for your tenant. See [Enable AI access management](/product/admin/enable-ai-access-management). -- **This option is n8n Cloud only.** If you run a self-hosted n8n instance, use the **n8n API** option instead, or, if your instance has its own MCP server enabled, register it in C1 as an external MCP server. +- **This option is n8n Cloud only.** If you run a self-hosted n8n instance, use the **n8n API** option instead, or, if your instance has its own MCP server enabled, register it in C1.ai as an external MCP server. - Your n8n Cloud workspace name — the subdomain in `.app.n8n.cloud` (for example, enter `c1-mcp` for a workspace at `https://c1-mcp.app.n8n.cloud`). You'll enter this when you register the server. - A user account on the n8n Cloud workspace (for per-user OAuth), or a personal access token (for the bearer fallback). -In your MCP server catalog, this option is listed as **n8n** — distinct from the **n8n API** entry, which connects through C1's own MCP server. If you don't see either, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +In your MCP server catalog, this option is listed as **n8n** — distinct from the **n8n API** entry, which connects through C1.ai's own MCP server. If you don't see either, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Set up per-user OAuth (recommended) -Per-user OAuth 2.1 with dynamic client registration (DCR) is the recommended way to connect n8n MCP. Each user authorizes individually, and C1 registers itself with your workspace's authorization server automatically, so there's nothing to create in n8n first. See n8n's [Connect to n8n MCP server](https://docs.n8n.io/connect/connect-to-n8n-mcp-server#setting-up-mcp-authentication) documentation for background on n8n's MCP authentication options. +Per-user OAuth 2.1 with dynamic client registration (DCR) is the recommended way to connect n8n MCP. Each user authorizes individually, and C1.ai registers itself with your workspace's authorization server automatically, so there's nothing to create in n8n first. See n8n's [Connect to n8n MCP server](https://docs.n8n.io/connect/connect-to-n8n-mcp-server#setting-up-mcp-authentication) documentation for background on n8n's MCP authentication options. @@ -59,10 +59,10 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve Enter your n8n Cloud workspace name when prompted. -When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **OAuth2 — per-user passthrough** and enable **Use dynamic client registration**. Leave the authorize and token URL fields blank — C1 auto-discovers them from your workspace. +When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **OAuth2 — per-user passthrough** and enable **Use dynamic client registration**. Leave the authorize and token URL fields blank — C1.ai auto-discovers them from your workspace. -Save your changes. The first time a user calls an n8n tool from their AI client, they're redirected to n8n to sign in (if they aren't already) and approve the connection, then returned to C1. +Save your changes. The first time a user calls an n8n tool from their AI client, they're redirected to n8n to sign in (if they aren't already) and approve the connection, then returned to C1.ai. @@ -81,7 +81,7 @@ Open **Connection details**, then switch to the **Access Token** tab. n8n genera -For a shared production setup, generate the token from a dedicated service-account user so activity is attributable to C1 rather than a person. +For a shared production setup, generate the token from a dedicated service-account user so activity is attributable to C1.ai rather than a person. Then register the server with that token: @@ -105,16 +105,16 @@ Save your changes. Access depends on the authentication method you chose: - **Per-user OAuth.** Tool calls run with the connected user's own n8n permissions in that workspace — they can access what that user can already access in n8n. -- **Personal access token.** Every tool call runs with the token owner's n8n permissions, regardless of which C1 user made the request. +- **Personal access token.** Every tool call runs with the token owner's n8n permissions, regardless of which C1.ai user made the request. ## How n8n MCP credentials are shared - **Per-user OAuth.** Every tool call runs under the calling user's own n8n identity, and n8n attributes each action to that individual. -- **Personal access token.** Every user's tool calls use the one token you provided, so n8n sees a single shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). +- **Personal access token.** Every user's tool calls use the one token you provided, so n8n sees a single shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). ## Discover and govern tools -After you register the server, C1 runs tool discovery against n8n's MCP server. Discovered tools appear on the server's **Tools** tab and include n8n's own workflow search, execution, testing, and publishing tools; execution history lookups; credential listing; workflow building and validation; and data table management. +After you register the server, C1.ai runs tool discovery against n8n's MCP server. Discovered tools appear on the server's **Tools** tab and include n8n's own workflow search, execution, testing, and publishing tools; execution history lookups; credential listing; workflow building and validation; and data table management. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -126,36 +126,36 @@ Tool discovery runs even if authentication isn't complete yet, so seeing discove ## Manage access to n8n MCP -- **Rotate or revoke a personal access token.** Go to **Settings** > **Instance-level MCP** in n8n, open **Connection details**, switch to the **Access Token** tab, and generate a new token. n8n automatically revokes the previous one. Update the new token in C1's authentication settings. +- **Rotate or revoke a personal access token.** Go to **Settings** > **Instance-level MCP** in n8n, open **Connection details**, switch to the **Access Token** tab, and generate a new token. n8n automatically revokes the previous one. Update the new token in C1.ai's authentication settings. - **Revoke an individual user's OAuth authorization.** In n8n, go to **Settings** > **Instance-level MCP**, open the **Connected clients** tab, and use the action menu next to the client to revoke its access. See n8n's [Connect to n8n MCP server](https://docs.n8n.io/connect/connect-to-n8n-mcp-server#revoking-client-access) documentation for current steps, since exact menu locations can change. -The n8n MCP server lets you govern access to n8n — workflows, executions, credentials, tags, and users — as tools your AI clients can call through C1. This option connects to a self-hosted n8n instance, or to an n8n Cloud workspace, through n8n's REST API. +The n8n MCP server lets you govern access to n8n — workflows, executions, credentials, tags, and users — as tools your AI clients can call through C1.ai. This option connects to a self-hosted n8n instance, or to an n8n Cloud workspace, through n8n's REST API. -n8n authenticates with an API key that C1 sends in a request header. A single key authenticates everyone, so all tool calls reach n8n as one shared identity. +n8n authenticates with an API key that C1.ai sends in a request header. A single key authenticates everyone, so all tool calls reach n8n as one shared identity. -## How C1 connects to n8n +## How C1.ai connects to n8n -C1 hosts the n8n MCP server, so your users' AI clients only ever see MCP tools — they never call n8n directly. When an AI client calls one of these tools, C1 makes the matching request to the n8n API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the n8n MCP server, so your users' AI clients only ever see MCP tools — they never call n8n directly. When an AI client calls one of these tools, C1.ai makes the matching request to the n8n API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call n8n on your users' behalf. +The credentials you set up below are what C1.ai uses to call n8n on your users' behalf. ## Before you begin - AI access management must be enabled for your tenant. See [Enable AI access management](/product/admin/enable-ai-access-management). - An account on your n8n instance that can create API keys, with access to the resources you want to govern. -- The base URL of your n8n instance, reachable from C1. +- The base URL of your n8n instance, reachable from C1.ai. -If you don't see **n8n API** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **n8n API** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Create an n8n API key -Create an API key on your n8n instance for C1 to authenticate with. For more information, see n8n's [API authentication](https://docs.n8n.io/api/authentication/) documentation. +Create an API key on your n8n instance for C1.ai to authenticate with. For more information, see n8n's [API authentication](https://docs.n8n.io/api/authentication/) documentation. @@ -169,17 +169,17 @@ Copy the key. n8n shows the key only once. -For a shared production setup, create the key from a dedicated service-account user so activity is attributable to C1 rather than a person. +For a shared production setup, create the key from a dedicated service-account user so activity is attributable to C1.ai rather than a person. ## How n8n credentials are shared -Every user's tool calls use the one API key you provided, so n8n sees a single shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared setup, create the key from a dedicated service-account user so activity is attributable to C1 rather than a person. +Every user's tool calls use the one API key you provided, so n8n sees a single shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared setup, create the key from a dedicated service-account user so activity is attributable to C1.ai rather than a person. For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## Register the n8n MCP server in C1 +## Register the n8n MCP server in C1.ai -With your API key ready, register the server and provide it to C1. +With your API key ready, register the server and provide it to C1.ai. @@ -192,13 +192,13 @@ Enter the base URL of your n8n instance when prompted. When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Custom header**. Set the header name to `X-N8N-API-KEY` and the value to your n8n API key. -Save your changes. C1 starts a sync that discovers the tools the n8n server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the n8n server exposes. ## Discover and govern tools -After you register the server, C1 runs tool discovery against n8n. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against n8n. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -210,7 +210,7 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your n8n credentials -- **Rotate the API key** by creating a new key under **Settings** > **n8n API**, updating it in C1, then deleting the old key. +- **Rotate the API key** by creating a new key under **Settings** > **n8n API**, updating it in C1.ai, then deleting the old key. - **Adjust access** by changing the permissions of the user the key belongs to on your n8n instance. diff --git a/product/admin/mcp-server/notion.mdx b/product/admin/mcp-server/notion.mdx index d6365d39..044bbf59 100644 --- a/product/admin/mcp-server/notion.mdx +++ b/product/admin/mcp-server/notion.mdx @@ -1,29 +1,29 @@ --- title: Set up the Notion MCP server -description: Connect Notion to C1 through the Notion API or Notion's own hosted MCP server, then register the server and govern its tools. +description: Connect Notion to C1.ai through the Notion API or Notion's own hosted MCP server, then register the server and govern its tools. og:title: Set up the Notion MCP server -og:description: Connect Notion to C1 through the Notion API or Notion's own hosted MCP server, then register the server and govern its tools. +og:description: Connect Notion to C1.ai through the Notion API or Notion's own hosted MCP server, then register the server and govern its tools. sidebarTitle: Notion --- {/* Editor Refresh: 2026-07-16 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -C1 can govern Notion access two ways. Both let your AI clients read from and act on Notion through governed MCP tools, but they come from different places and appear as two separate entries in your MCP server catalog: +C1.ai can govern Notion access two ways. Both let your AI clients read from and act on Notion through governed MCP tools, but they come from different places and appear as two separate entries in your MCP server catalog: -- **Notion MCP** — listed as plain **Notion** in your catalog. C1 registers Notion's own hosted MCP server (`mcp.notion.com`) as a downstream server C1 governs. Authentication is always per-user OAuth using dynamic client registration (DCR) — Notion's hosted MCP server doesn't support a bearer token or API key, so there's no integration to create in Notion first. Tool calls run with the connected user's full Notion permissions, plus whatever connected sources (Slack, Google Drive, GitHub, Jira, Microsoft Teams, SharePoint, OneDrive, Linear) their Notion AI connectors expose. -- **Notion API** — C1 hosts its own MCP server that translates Notion's REST API into tools. You choose between per-user OAuth or a shared internal integration secret (a bearer token), and you scope access with the **capabilities** you grant the Notion integration (read/update/insert content, comments, user information). +- **Notion MCP** — listed as plain **Notion** in your catalog. C1.ai registers Notion's own hosted MCP server (`mcp.notion.com`) as a downstream server C1.ai governs. Authentication is always per-user OAuth using dynamic client registration (DCR) — Notion's hosted MCP server doesn't support a bearer token or API key, so there's no integration to create in Notion first. Tool calls run with the connected user's full Notion permissions, plus whatever connected sources (Slack, Google Drive, GitHub, Jira, Microsoft Teams, SharePoint, OneDrive, Linear) their Notion AI connectors expose. +- **Notion API** — C1.ai hosts its own MCP server that translates Notion's REST API into tools. You choose between per-user OAuth or a shared internal integration secret (a bearer token), and you scope access with the **capabilities** you grant the Notion integration (read/update/insert content, comments, user information). | | Notion MCP | Notion API | | :--- | :--- | :--- | -| **Who hosts the MCP server** | Notion | C1 | +| **Who hosts the MCP server** | Notion | C1.ai | | **Authentication** | Per-user OAuth with dynamic client registration (DCR) only — no bearer token or API key option | Per-user OAuth, or a shared internal integration secret (bearer token) | | **Access scoping** | The connected user's full Notion permissions — not independently scoped | The Notion **capabilities** you configure on the integration | | **Tool surface** | Notion's own tool set: cross-source search, page and database creation/editing, page duplication, database views, comments, teamspaces, and users | Pages, databases, blocks, comments, users, and search, mapped to Notion API endpoints | -| **Setup effort** | Register in C1 and authorize — nothing to create in Notion first | Create a Notion integration (public or internal) first, then register it in C1 | +| **Setup effort** | Register in C1.ai and authorize — nothing to create in Notion first | Create a Notion integration (public or internal) first, then register it in C1.ai | Use the native **Notion MCP** option (listed as plain **Notion** in your catalog) if you want Notion's own broader, agentic tool set — including cross-source search — and per-user OAuth is acceptable for your tenant. Use **Notion API** if you need a shared service-account credential (bearer token), or you want to scope access with Notion's capability toggles. @@ -31,7 +31,7 @@ Use the native **Notion MCP** option (listed as plain **Notion** in your catalog -C1 registers as a client of Notion's own hosted MCP server ([Notion MCP](https://www.notion.com/help/notion-mcp)) rather than translating Notion's REST API itself. Your users' AI clients still only ever see C1-governed MCP tools, but C1 proxies each tool call straight through to `mcp.notion.com` under the connected user's authorized session, then returns the result. The tools available are exactly the ones Notion's own MCP server exposes — C1 doesn't reshape or add to them. +C1.ai registers as a client of Notion's own hosted MCP server ([Notion MCP](https://www.notion.com/help/notion-mcp)) rather than translating Notion's REST API itself. Your users' AI clients still only ever see C1.ai-governed MCP tools, but C1.ai proxies each tool call straight through to `mcp.notion.com` under the connected user's authorized session, then returns the result. The tools available are exactly the ones Notion's own MCP server exposes — C1.ai doesn't reshape or add to them. ## Before you begin @@ -40,12 +40,12 @@ C1 registers as a client of Notion's own hosted MCP server ([Notion MCP](https:/ - To search and read from connected sources (Slack, Google Drive, GitHub, Jira, Microsoft Teams, SharePoint, OneDrive, Linear) through Notion MCP, users need those connectors set up on the Notion side. See Notion's [Notion MCP](https://www.notion.com/help/notion-mcp) documentation. -In your MCP server catalog, this option is listed as **Notion** — distinct from the **Notion API** entry, which connects through C1's own MCP server. If you don't see either, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +In your MCP server catalog, this option is listed as **Notion** — distinct from the **Notion API** entry, which connects through C1.ai's own MCP server. If you don't see either, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Set up per-user OAuth -Per-user OAuth with dynamic client registration (DCR) is the only authentication method this option supports — there's no bearer token or API key fallback. Each user authorizes individually, and C1 registers itself with Notion's authorization server automatically, so there's no app to create in Notion first (see Notion's [Connecting to Notion MCP](https://developers.notion.com/guides/mcp/get-started-with-mcp) documentation). +Per-user OAuth with dynamic client registration (DCR) is the only authentication method this option supports — there's no bearer token or API key fallback. Each user authorizes individually, and C1.ai registers itself with Notion's authorization server automatically, so there's no app to create in Notion first (see Notion's [Connecting to Notion MCP](https://developers.notion.com/guides/mcp/get-started-with-mcp) documentation). @@ -55,7 +55,7 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **OAuth2 — per-user passthrough** and enable **Use dynamic client registration**. There's no client ID or secret to enter. -Save your changes. The first time a user calls a Notion tool from their AI client, they're redirected to Notion to sign in (if they aren't already) and approve the connection, then returned to C1. +Save your changes. The first time a user calls a Notion tool from their AI client, they're redirected to Notion to sign in (if they aren't already) and approve the connection, then returned to C1.ai. @@ -65,11 +65,11 @@ Unlike the Notion API option, there are no separate capability toggles to config ## How Notion MCP credentials are shared -This option only supports per-user OAuth — there's no shared, service-account, or bearer-token mode. Every tool call runs under the calling user's own Notion identity, and Notion attributes each action to that individual. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). +This option only supports per-user OAuth — there's no shared, service-account, or bearer-token mode. Every tool call runs under the calling user's own Notion identity, and Notion attributes each action to that individual. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). ## Discover and govern tools -After you register the server, C1 runs tool discovery against Notion's MCP server. Discovered tools appear on the server's **Tools** tab and include Notion's own search and fetch tools, page and database creation and editing, page duplication, comments, teamspaces, users, and database views. +After you register the server, C1.ai runs tool discovery against Notion's MCP server. Discovered tools appear on the server's **Tools** tab and include Notion's own search and fetch tools, page and database creation and editing, page duplication, comments, teamspaces, users, and database views. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -81,7 +81,7 @@ Tool discovery runs even if authentication isn't complete yet, so seeing discove ## Manage access to Notion MCP -Because this option uses per-user OAuth, there's no shared secret in C1 to rotate. Users and admins manage access from Notion itself: +Because this option uses per-user OAuth, there's no shared secret in C1.ai to rotate. Users and admins manage access from Notion itself: - **An individual user can disconnect at any time.** In Notion, go to **Settings** > **Connections**, select the connection, open the **•••** menu, and choose **Disconnect the connection** ([Add and manage connections](https://www.notion.com/help/add-and-manage-connections-with-the-api)). - **An Enterprise workspace owner can revoke access for one user or everyone.** In Notion, go to **Settings** > **Connections** > **Manage**, open the **•••** menu next to the connection, then choose **Revoke specific users' access to a connection** or **Disconnect all users** ([Enterprise connection settings](https://www.notion.com/help/enterprise-connection-settings)). Disconnecting all users revokes every external AI tool and MCP client connected through Notion MCP at once; affected users must re-authenticate to reconnect. @@ -90,7 +90,7 @@ Because this option uses per-user OAuth, there's no shared secret in C1 to rotat -C1 hosts the Notion MCP server, so your users' AI clients only ever see MCP tools — they never call Notion directly. When an AI client calls one of these tools, C1 makes the matching request to the Notion API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Notion MCP server, so your users' AI clients only ever see MCP tools — they never call Notion directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Notion API using the credentials you configure here, then returns the result to the AI client. Notion supports two ways to authenticate, and you choose one when you register the server: @@ -106,7 +106,7 @@ For a deeper comparison of shared versus per-user credentials, see [Configure au - For an internal integration secret, you need to be a **Workspace Owner** of the Notion workspace. -In your MCP server catalog, this option is listed as **Notion API** — distinct from the **Notion** entry, which connects to Notion's own hosted MCP server. If you don't see either, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +In your MCP server catalog, this option is listed as **Notion API** — distinct from the **Notion** entry, which connects to Notion's own hosted MCP server. If you don't see either, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Option 1: Set up per-user OAuth @@ -123,20 +123,20 @@ In Notion's developer portal, select **New integration**. See Notion's [Create i Enter a recognizable name such as `C1`, select the associated workspace, and set **Type** to **Public**. -Set the **Redirect URI** exactly to whichever matches your C1 tenant's domain: +Set the **Redirect URI** exactly to whichever matches your C1.ai tenant's domain: - Default instance: `https://accounts.conductor.one/auth/callback` - EU data residency instance: `https://accounts.c1eu.ai/auth/callback` -On the **Capabilities** tab, enable only what C1 needs: **Read content** for read operations, plus **Update content** or **Insert content** if C1 should edit or create pages, and the comment and user-information capabilities you need. +On the **Capabilities** tab, enable only what C1.ai needs: **Read content** for read operations, plus **Update content** or **Insert content** if C1.ai should edit or create pages, and the comment and user-information capabilities you need. Copy the integration's **Client ID** and **Client Secret**. -With your public integration ready, register the server and provide its credentials to C1: +With your public integration ready, register the server and provide its credentials to C1.ai: @@ -154,7 +154,7 @@ Save your changes. The first time a user calls a Notion tool from their AI clien An internal integration secret authenticates every user as one shared Notion identity. Use this when per-user attribution in Notion isn't required. -First, create an internal integration in Notion and connect it to the pages C1 should reach: +First, create an internal integration in Notion and connect it to the pages C1.ai should reach: @@ -164,7 +164,7 @@ In Notion's developer portal, select **New integration**. See Notion's [Create i Enter a recognizable name such as `C1`, select the associated workspace, and set **Type** to **Internal**, then select **Save**. -On the **Capabilities** tab, enable only what C1 needs: **Read content** for read operations, plus **Update content** or **Insert content** if C1 should edit or create pages, and the comment and user-information capabilities you need. +On the **Capabilities** tab, enable only what C1.ai needs: **Read content** for read operations, plus **Update content** or **Insert content** if C1.ai should edit or create pages, and the comment and user-information capabilities you need. On the **Configuration** tab, under **Internal Integration Secret**, select **Show** and copy the token. Treat it as a high-value credential. @@ -174,9 +174,9 @@ Connect the integration to the pages it should reach. An internal integration se -For a shared production setup, create the integration from a dedicated service-account user so activity is attributable to C1 rather than a person. +For a shared production setup, create the integration from a dedicated service-account user so activity is attributable to C1.ai rather than a person. -With your internal integration secret ready, register the server and provide it to C1: +With your internal integration secret ready, register the server and provide it to C1.ai: @@ -186,7 +186,7 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Bearer token** and paste your internal integration secret. -Save your changes. C1 starts a sync that discovers the tools the Notion server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Notion server exposes. @@ -195,13 +195,13 @@ Save your changes. C1 starts a sync that discovers the tools the Notion server e How Notion sees your users' activity depends on the method you chose: - **Per-user OAuth.** Each user authorizes with their own Notion account, so tool calls run under that user's Notion identity and inherit only the access they already have. Notion attributes each action to the individual user. -- **Internal integration secret.** Every user's tool calls use the one secret you provided, so Notion sees a single shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). +- **Internal integration secret.** Every user's tool calls use the one secret you provided, so Notion sees a single shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). ## Discover and govern tools -After you register the server, C1 runs tool discovery against Notion. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Notion. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -213,8 +213,8 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Notion API credentials -- **Rotate the OAuth client secret** on your public integration's **Configuration** tab in Notion, then update the secret on the server's authentication settings in C1. -- **Rotate the internal integration secret** by regenerating it on the integration's **Configuration** tab in Notion and updating it in C1. +- **Rotate the OAuth client secret** on your public integration's **Configuration** tab in Notion, then update the secret on the server's authentication settings in C1.ai. +- **Rotate the internal integration secret** by regenerating it on the integration's **Configuration** tab in Notion and updating it in C1.ai. - **Adjust access** by editing the integration's capabilities, and for an internal integration, the set of pages it's connected to. diff --git a/product/admin/mcp-server/okta.mdx b/product/admin/mcp-server/okta.mdx index 64bc8ba9..df5cc7a0 100644 --- a/product/admin/mcp-server/okta.mdx +++ b/product/admin/mcp-server/okta.mdx @@ -1,18 +1,18 @@ --- title: Set up the Okta MCP server -description: Create an Okta OIDC app, grant the Okta API scopes C1 needs, and register the Okta MCP server so your AI clients read Okta directory data through governed tools. +description: Create an Okta OIDC app, grant the Okta API scopes C1.ai needs, and register the Okta MCP server so your AI clients read Okta directory data through governed tools. og:title: Set up the Okta MCP server -og:description: Create an Okta OIDC app, grant the Okta API scopes C1 needs, and register the Okta MCP server so your AI clients read Okta directory data through governed tools. +og:description: Create an Okta OIDC app, grant the Okta API scopes C1.ai needs, and register the Okta MCP server so your AI clients read Okta directory data through governed tools. sidebarTitle: Okta --- {/* Editor Refresh: 2026-07-30 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -The Okta MCP server lets you govern access to Okta directory data — users, groups, applications, devices, and organization configuration exposed by the Okta management APIs — as tools your AI clients call through C1. +The Okta MCP server lets you govern access to Okta directory data — users, groups, applications, devices, and organization configuration exposed by the Okta management APIs — as tools your AI clients call through C1.ai. The server is read-only by default: it requests read scopes and exposes read tools. To enable tools that modify Okta, you grant the matching management scopes — see [Okta API scopes](#okta-api-scopes). @@ -29,9 +29,9 @@ Choose per-user OAuth when the people using the server are themselves Okta admin For a deeper comparison of shared versus per-user credentials, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## How C1 connects to Okta +## How C1.ai connects to Okta -C1 hosts the Okta MCP server, so your users' AI clients only ever see MCP tools — they never call Okta directly. When an AI client calls one of these tools, C1 makes the matching request to the Okta API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Okta MCP server, so your users' AI clients only ever see MCP tools — they never call Okta directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Okta API using the credentials you configure here, then returns the result to the AI client. ## Before you begin @@ -40,12 +40,12 @@ C1 hosts the Okta MCP server, so your users' AI clients only ever see MCP tools - Your Okta organization URL, such as `https://acme.okta.com`. -If you don't see **Okta** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **Okta** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Create an Okta OIDC app -Register one Okta OIDC app that C1 uses to authorize with Okta. For full details, see Okta's [Create OpenID Connect app integrations](https://help.okta.com/en-us/content/topics/apps/apps_app_integration_wizard_oidc.htm) and [OAuth for Okta](https://developer.okta.com/docs/guides/implement-oauth-for-okta/main/) documentation. +Register one Okta OIDC app that C1.ai uses to authorize with Okta. For full details, see Okta's [Create OpenID Connect app integrations](https://help.okta.com/en-us/content/topics/apps/apps_app_integration_wizard_oidc.htm) and [OAuth for Okta](https://developer.okta.com/docs/guides/implement-oauth-for-okta/main/) documentation. @@ -58,7 +58,7 @@ Select **OIDC - OpenID Connect** as the sign-in method and **Web Application** a Give the app a recognizable name, such as `C1`. -Set the **Sign-in redirect URI** to exactly whichever matches your C1 tenant's domain — the value must match exactly, even a trailing-slash difference fails the authorization flow: +Set the **Sign-in redirect URI** to exactly whichever matches your C1.ai tenant's domain — the value must match exactly, even a trailing-slash difference fails the authorization flow: - Default instance: `https://accounts.conductor.one/auth/callback` - EU data residency instance: `https://accounts.c1eu.ai/auth/callback` @@ -67,18 +67,18 @@ Set the **Sign-in redirect URI** to exactly whichever matches your C1 tenant's d Under **Assignments**, limit who can authorize the app to the administrators who will connect it, then select **Save**. -Open the app's **Okta API Scopes** tab and select **Grant** for each scope the server needs. See [Okta API scopes](#okta-api-scopes) for the recommended set. A scope must be granted here before C1 can request it. +Open the app's **Okta API Scopes** tab and select **Grant** for each scope the server needs. See [Okta API scopes](#okta-api-scopes) for the recommended set. A scope must be granted here before C1.ai can request it. On the app's **General** tab, copy the **Client ID** and **Client secret**. Okta shows the secret only once. -Your Okta OIDC app is ready to connect. Keep the client ID and secret for [Register the Okta MCP server in C1](#register-the-okta-mcp-server-in-c1). +Your Okta OIDC app is ready to connect. Keep the client ID and secret for [Register the Okta MCP server in C1.ai](#register-the-okta-mcp-server-in-c1). ## Okta API scopes -C1 requests these read scopes by default. Together they let the server read the Okta directory and configuration that the tools surface, without granting any write access. +C1.ai requests these read scopes by default. Together they let the server read the Okta directory and configuration that the tools surface, without granting any write access. | Scope | Grants read access to | | :--- | :--- | @@ -102,7 +102,7 @@ C1 requests these read scopes by default. Together they let the server read the These are Okta **administrator** scopes. Okta limits each token to what the authorizing account's admin role permits, so grant read scopes to an account with a read-capable admin role — for example, a read-only administrator. A token can hold a scope but still return nothing if the account lacks the matching admin permission. -To enable tools that **modify** Okta, grant the matching management scope — for example `okta.users.manage` for user writes or `okta.groups.manage` for group writes — on the app's **Okta API Scopes** tab, then add it to the server's scopes in C1. Grant management scopes only where you need write access, and only to an account whose admin role allows those changes. +To enable tools that **modify** Okta, grant the matching management scope — for example `okta.users.manage` for user writes or `okta.groups.manage` for group writes — on the app's **Okta API Scopes** tab, then add it to the server's scopes in C1.ai. Grant management scopes only where you need write access, and only to an account whose admin role allows those changes. Scope changes take effect the next time a user authorizes. If you add scopes after someone has already connected, they keep their existing grants until they reconnect their Okta account, and tools that need the new scopes return an authorization error until they do. @@ -113,11 +113,11 @@ Scope changes take effect the next time a user authorizes. If you add scopes aft How Okta sees your users' activity depends on the method you chose: - **Per-user OAuth.** Each user authorizes with their own Okta account, so tool calls run under that user's Okta identity and inherit only the admin permissions they already have. Okta attributes each action to the individual user. -- **Service mode.** An administrator authorizes once, so every user's tool calls reach Okta as one shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). Authorize from a dedicated service-account user so activity is attributable to C1 rather than a person. +- **Service mode.** An administrator authorizes once, so every user's tool calls reach Okta as one shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). Authorize from a dedicated service-account user so activity is attributable to C1.ai rather than a person. For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## Register the Okta MCP server in C1 +## Register the Okta MCP server in C1.ai With your OAuth app ready, register the server and provide your credentials. @@ -138,7 +138,7 @@ Save your changes. With per-user OAuth, the first time a user calls an Okta tool ## Discover and govern tools -After you register the server, C1 runs tool discovery against Okta. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Okta. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -150,5 +150,5 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Okta credentials -- **Rotate the OAuth client secret** in your Okta app under **Applications** > **Applications**, then update the secret in the server's authentication settings in C1. -- **Adjust access** by granting or revoking Okta API scopes on the app's **Okta API Scopes** tab, then updating the scopes in C1 to match. Users reconnect their Okta account for scope changes to take effect. +- **Rotate the OAuth client secret** in your Okta app under **Applications** > **Applications**, then update the secret in the server's authentication settings in C1.ai. +- **Adjust access** by granting or revoking Okta API scopes on the app's **Okta API Scopes** tab, then updating the scopes in C1.ai to match. Users reconnect their Okta account for scope changes to take effect. diff --git a/product/admin/mcp-server/opsgenie.mdx b/product/admin/mcp-server/opsgenie.mdx index 33f9d915..65a96a37 100644 --- a/product/admin/mcp-server/opsgenie.mdx +++ b/product/admin/mcp-server/opsgenie.mdx @@ -1,26 +1,26 @@ --- title: Set up the Opsgenie MCP server -description: Create an Opsgenie API key, then register the Opsgenie MCP server in C1 and govern the tools it exposes. +description: Create an Opsgenie API key, then register the Opsgenie MCP server in C1.ai and govern the tools it exposes. og:title: Set up the Opsgenie MCP server -og:description: Create an Opsgenie API key, then register the Opsgenie MCP server in C1 and govern the tools it exposes. +og:description: Create an Opsgenie API key, then register the Opsgenie MCP server in C1.ai and govern the tools it exposes. sidebarTitle: Opsgenie --- {/* Editor Refresh: 2026-06-11 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -The Opsgenie MCP server lets you govern access to Opsgenie — alerts, escalations, schedules, on-call data, teams, and users — as tools your AI clients can call through C1. +The Opsgenie MCP server lets you govern access to Opsgenie — alerts, escalations, schedules, on-call data, teams, and users — as tools your AI clients can call through C1.ai. Opsgenie authenticates with an API key. A single key authenticates everyone, so all tool calls reach Opsgenie as one shared identity. -## How C1 connects to Opsgenie +## How C1.ai connects to Opsgenie -C1 hosts the Opsgenie MCP server, so your users' AI clients only ever see MCP tools — they never call Opsgenie directly. When an AI client calls one of these tools, C1 makes the matching request to the Opsgenie API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Opsgenie MCP server, so your users' AI clients only ever see MCP tools — they never call Opsgenie directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Opsgenie API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call Opsgenie on your users' behalf. +The credentials you set up below are what C1.ai uses to call Opsgenie on your users' behalf. ## Before you begin @@ -28,12 +28,12 @@ The credentials you set up below are what C1 uses to call Opsgenie on your users - An Opsgenie account with permission to create an API integration or API key for the operations you plan to govern. -If you don't see **Opsgenie** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **Opsgenie** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Create an Opsgenie API key -Create an API integration in Opsgenie to authenticate C1 to the Opsgenie API. +Create an API integration in Opsgenie to authenticate C1.ai to the Opsgenie API. @@ -47,15 +47,15 @@ Copy the generated **API key**. Treat it as a high-value credential. -For a shared production setup, create the API key from a dedicated service account so activity is attributable to C1 rather than a person. +For a shared production setup, create the API key from a dedicated service account so activity is attributable to C1.ai rather than a person. ## How Opsgenie credentials are shared -Every user's tool calls use the one API key you provided, so Opsgenie sees a single shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared setup, use a dedicated service account so activity is attributable to C1 rather than a person. +Every user's tool calls use the one API key you provided, so Opsgenie sees a single shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared setup, use a dedicated service account so activity is attributable to C1.ai rather than a person. For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## Register the Opsgenie MCP server in C1 +## Register the Opsgenie MCP server in C1.ai With your API key ready, register the server and provide your credentials. @@ -67,13 +67,13 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Custom header**. Set the header name to `Authorization` and the value to `GenieKey ` followed by your API key (for example, `GenieKey abc123`). -Save your changes. C1 starts a sync that discovers the tools the Opsgenie server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Opsgenie server exposes. ## Discover and govern tools -After you register the server, C1 runs tool discovery against Opsgenie. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Opsgenie. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -85,5 +85,5 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Opsgenie credentials -- **Rotate the API key** by creating a new API integration or key in Opsgenie and updating it in C1, then removing the old one. +- **Rotate the API key** by creating a new API integration or key in Opsgenie and updating it in C1.ai, then removing the old one. - **Adjust access** by editing the integration's permissions in Opsgenie. diff --git a/product/admin/mcp-server/pagerduty.mdx b/product/admin/mcp-server/pagerduty.mdx index af64fee1..17207f1e 100644 --- a/product/admin/mcp-server/pagerduty.mdx +++ b/product/admin/mcp-server/pagerduty.mdx @@ -1,29 +1,29 @@ --- title: Set up the PagerDuty MCP server -description: Connect PagerDuty to C1 through the PagerDuty REST API or PagerDuty's own hosted MCP server, then register the server and govern its tools. +description: Connect PagerDuty to C1.ai through the PagerDuty REST API or PagerDuty's own hosted MCP server, then register the server and govern its tools. og:title: Set up the PagerDuty MCP server -og:description: Connect PagerDuty to C1 through the PagerDuty REST API or PagerDuty's own hosted MCP server, then register the server and govern its tools. +og:description: Connect PagerDuty to C1.ai through the PagerDuty REST API or PagerDuty's own hosted MCP server, then register the server and govern its tools. sidebarTitle: PagerDuty --- {/* Editor Refresh: 2026-07-24 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -C1 can govern PagerDuty access two ways. Both let your AI clients read from and act on PagerDuty through governed MCP tools, but they come from different places and appear as two separate entries in your MCP server catalog: +C1.ai can govern PagerDuty access two ways. Both let your AI clients read from and act on PagerDuty through governed MCP tools, but they come from different places and appear as two separate entries in your MCP server catalog: -- **PagerDuty MCP** — listed as plain **PagerDuty** in your catalog. C1 registers PagerDuty's own hosted MCP server (`mcp.pagerduty.com`) as a downstream server C1 governs. Authenticate with per-user OAuth — using a Scoped OAuth application you register manually in PagerDuty, since PagerDuty's hosted MCP server doesn't support dynamic client registration (DCR) — or with a shared API key or user token. Tool calls run with whichever identity you authenticated. -- **PagerDuty API** — C1 hosts its own MCP server that translates PagerDuty's REST API into tools. You choose between per-user OAuth or a shared REST API key, and access is scoped to the OAuth app's granted scopes or the REST API key's permissions. +- **PagerDuty MCP** — listed as plain **PagerDuty** in your catalog. C1.ai registers PagerDuty's own hosted MCP server (`mcp.pagerduty.com`) as a downstream server C1.ai governs. Authenticate with per-user OAuth — using a Scoped OAuth application you register manually in PagerDuty, since PagerDuty's hosted MCP server doesn't support dynamic client registration (DCR) — or with a shared API key or user token. Tool calls run with whichever identity you authenticated. +- **PagerDuty API** — C1.ai hosts its own MCP server that translates PagerDuty's REST API into tools. You choose between per-user OAuth or a shared REST API key, and access is scoped to the OAuth app's granted scopes or the REST API key's permissions. | | PagerDuty MCP | PagerDuty API | | :--- | :--- | :--- | -| **Who hosts the MCP server** | PagerDuty | C1 | +| **Who hosts the MCP server** | PagerDuty | C1.ai | | **Authentication** | Per-user OAuth with a manually registered Scoped OAuth application (no DCR), or a shared API key / user token (bearer) | Per-user OAuth, or a shared REST API key (bearer token) | -| **Access scoping** | The connected identity's own PagerDuty permissions, within whatever scopes the OAuth app was granted — not independently scoped by C1 | The scopes you grant the OAuth app, or the permissions of the REST API key you provide | +| **Access scoping** | The connected identity's own PagerDuty permissions, within whatever scopes the OAuth app was granted — not independently scoped by C1.ai | The scopes you grant the OAuth app, or the permissions of the REST API key you provide | | **Tool surface** | PagerDuty's own tool set: incidents, services, on-call schedules, escalation policies, teams, event orchestrations, status pages, and more | Incidents, services, schedules, escalation policies, and users, mapped to PagerDuty REST API endpoints | -| **Setup effort** | Register a Scoped OAuth application in PagerDuty (or create an API key), then register it in C1 — no automatic registration | Register an OAuth app or create a REST API key in PagerDuty, then register it in C1 | +| **Setup effort** | Register a Scoped OAuth application in PagerDuty (or create an API key), then register it in C1.ai — no automatic registration | Register an OAuth app or create a REST API key in PagerDuty, then register it in C1.ai | Use the native **PagerDuty MCP** option (listed as plain **PagerDuty** in your catalog) if you want PagerDuty's own broader, agentic tool set and you're prepared to manually register a Scoped OAuth application (or use an API key). Use **PagerDuty API** if you'd rather scope access purely through PagerDuty's REST API scopes with either credential type. @@ -31,17 +31,17 @@ Use the native **PagerDuty MCP** option (listed as plain **PagerDuty** in your c -C1 registers as a client of PagerDuty's own hosted MCP server ([PagerDuty MCP Server](https://support.pagerduty.com/main/docs/pagerduty-mcp-server)) rather than translating PagerDuty's REST API itself. Your users' AI clients still only ever see C1-governed MCP tools, but C1 proxies each tool call straight through to `mcp.pagerduty.com/mcp` under the connected identity, then returns the result. The tools available are exactly the ones PagerDuty's own MCP server exposes — C1 doesn't reshape or add to them. +C1.ai registers as a client of PagerDuty's own hosted MCP server ([PagerDuty MCP Server](https://support.pagerduty.com/main/docs/pagerduty-mcp-server)) rather than translating PagerDuty's REST API itself. Your users' AI clients still only ever see C1.ai-governed MCP tools, but C1.ai proxies each tool call straight through to `mcp.pagerduty.com/mcp` under the connected identity, then returns the result. The tools available are exactly the ones PagerDuty's own MCP server exposes — C1.ai doesn't reshape or add to them. ## Before you begin - AI access management must be enabled for your tenant. See [Enable AI access management](/product/admin/enable-ai-access-management). -- For per-user OAuth, you need permission to register a Scoped OAuth application in PagerDuty — this requires an account admin or owner role. Regular users are limited to **Classic User OAuth**, which C1 doesn't use here, since it only supports coarse and unreliable access. +- For per-user OAuth, you need permission to register a Scoped OAuth application in PagerDuty — this requires an account admin or owner role. Regular users are limited to **Classic User OAuth**, which C1.ai doesn't use here, since it only supports coarse and unreliable access. - For an API key or user token, you need a PagerDuty account that can create a REST API key, or your own user account to create a personal token. - PagerDuty's hosted MCP server doesn't support OAuth dynamic client registration (DCR). Unlike some other native MCP integrations, per-user OAuth here always starts with an application you register yourself — there's no automatic client registration to skip. -In your MCP server catalog, this option is listed as **PagerDuty** — distinct from the **PagerDuty API** entry, which connects through C1's own MCP server. If you don't see either, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +In your MCP server catalog, this option is listed as **PagerDuty** — distinct from the **PagerDuty API** entry, which connects through C1.ai's own MCP server. If you don't see either, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Option 1: Set up per-user OAuth @@ -50,23 +50,23 @@ With per-user OAuth, you register one Scoped OAuth application in PagerDuty and ### Register a Scoped OAuth application -Register the application in PagerDuty before configuring authentication in C1. +Register the application in PagerDuty before configuring authentication in C1.ai. -In PagerDuty, go to **Integrations** > **App Registration** and select **New App**. Give it a name that identifies C1 for your team, such as `C1`. See PagerDuty's [Register an App](https://developer.pagerduty.com/docs/register-an-app) documentation. +In PagerDuty, go to **Integrations** > **App Registration** and select **New App**. Give it a name that identifies C1.ai for your team, such as `C1`. See PagerDuty's [Register an App](https://developer.pagerduty.com/docs/register-an-app) documentation. -Select **OAuth 2.0** as the app's functionality, then leave **Scoped OAuth** selected on the next screen — it's the default and the only mode with the granular, per-object scopes below. The other option, **Classic User OAuth**, only supports coarse read (and unreliable write) access, so C1 doesn't use it. +Select **OAuth 2.0** as the app's functionality, then leave **Scoped OAuth** selected on the next screen — it's the default and the only mode with the granular, per-object scopes below. The other option, **Classic User OAuth**, only supports coarse read (and unreliable write) access, so C1.ai doesn't use it. -Set the **Redirect URL** exactly to whichever matches your C1 tenant's domain: +Set the **Redirect URL** exactly to whichever matches your C1.ai tenant's domain: - Default instance: `https://accounts.conductor.one/auth/callback` - EU data residency instance: `https://accounts.c1eu.ai/auth/callback` -Select the scopes C1 needs. For full functionality, grant: +Select the scopes C1.ai needs. For full functionality, grant: - `incidents.read`, `incidents.write` — view, create, acknowledge, resolve, and update incidents - `services.read`, `services.write` — view, create, and update services @@ -102,7 +102,7 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **OAuth2 — per-user passthrough** and enter your application's **client ID** and **client secret**. -Save your changes. The first time a user calls a PagerDuty tool from their AI client, they're redirected to PagerDuty to sign in (if they aren't already) and approve the connection, then returned to C1. +Save your changes. The first time a user calls a PagerDuty tool from their AI client, they're redirected to PagerDuty to sign in (if they aren't already) and approve the connection, then returned to C1.ai. @@ -124,12 +124,12 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Bearer token** and paste your API key or user token. -Save your changes. C1 starts a sync that discovers the tools the PagerDuty MCP server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the PagerDuty MCP server exposes. -PagerDuty doesn't use the standard `Bearer` prefix for this credential — it expects the `Authorization` header formatted as `Token token=` ([source](https://community.pagerduty.com/ask-a-product-question-2/can-t-use-api-user-tokens-702)). C1 sends it in this format automatically; you don't need to enter the prefix yourself. +PagerDuty doesn't use the standard `Bearer` prefix for this credential — it expects the `Authorization` header formatted as `Token token=` ([source](https://community.pagerduty.com/ask-a-product-question-2/can-t-use-api-user-tokens-702)). C1.ai sends it in this format automatically; you don't need to enter the prefix yourself. ## What access is granted @@ -141,11 +141,11 @@ Tool calls run with whichever identity you authenticated: for per-user OAuth, th How PagerDuty sees your users' activity depends on the method you chose: - **Per-user OAuth.** Each user authorizes with their own PagerDuty account, so tool calls run under that user's PagerDuty identity and inherit only the scopes you granted. PagerDuty attributes each action to the individual user. -- **API key or user token.** Every user's tool calls use the one credential you provided, so PagerDuty sees a single shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). +- **API key or user token.** Every user's tool calls use the one credential you provided, so PagerDuty sees a single shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). ## Discover and govern tools -After you register the server, C1 runs tool discovery against PagerDuty's hosted MCP server. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against PagerDuty's hosted MCP server. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -157,8 +157,8 @@ Tool discovery runs even if authentication isn't complete yet, so seeing discove ## Manage access to PagerDuty MCP -- **Rotate the OAuth client secret** in your PagerDuty app under **Integrations** > **App Registration**, then update the secret on the server's authentication settings in C1. -- **Rotate an API key or user token** by creating a new one in PagerDuty and updating it in C1, then delete the old one. +- **Rotate the OAuth client secret** in your PagerDuty app under **Integrations** > **App Registration**, then update the secret on the server's authentication settings in C1.ai. +- **Rotate an API key or user token** by creating a new one in PagerDuty and updating it in C1.ai, then delete the old one. - **Revoke access** from the app's page in **App Registration** — revoke its tokens to invalidate every session at once, or delete the app entirely. - **Adjust scopes** by editing them on the OAuth application in PagerDuty, or by choosing a read-only versus full-access API key. @@ -166,7 +166,7 @@ Tool discovery runs even if authentication isn't complete yet, so seeing discove -The PagerDuty MCP server lets you govern access to PagerDuty — incidents, services, schedules, escalation policies, and users exposed by the PagerDuty REST API — as tools your AI clients can call through C1. +The PagerDuty MCP server lets you govern access to PagerDuty — incidents, services, schedules, escalation policies, and users exposed by the PagerDuty REST API — as tools your AI clients can call through C1.ai. PagerDuty supports two ways to authenticate, and you choose one when you register the server: @@ -175,11 +175,11 @@ PagerDuty supports two ways to authenticate, and you choose one when you registe For a deeper comparison of shared versus per-user credentials, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## How C1 connects to PagerDuty +## How C1.ai connects to PagerDuty -C1 hosts the PagerDuty MCP server, so your users' AI clients only ever see MCP tools — they never call PagerDuty directly. When an AI client calls one of these tools, C1 makes the matching request to the PagerDuty API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the PagerDuty MCP server, so your users' AI clients only ever see MCP tools — they never call PagerDuty directly. When an AI client calls one of these tools, C1.ai makes the matching request to the PagerDuty API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call PagerDuty on your users' behalf. +The credentials you set up below are what C1.ai uses to call PagerDuty on your users' behalf. ## Before you begin @@ -188,7 +188,7 @@ The credentials you set up below are what C1 uses to call PagerDuty on your user - For a REST API key, you need a PagerDuty account that can create a REST API key, and the email address of a valid PagerDuty user to record as the actor on write operations. -In your MCP server catalog, this option is listed as **PagerDuty API** — distinct from the **PagerDuty** entry, which connects to PagerDuty's own hosted MCP server. If you don't see either, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +In your MCP server catalog, this option is listed as **PagerDuty API** — distinct from the **PagerDuty** entry, which connects to PagerDuty's own hosted MCP server. If you don't see either, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Option 1: Set up per-user OAuth @@ -197,7 +197,7 @@ With per-user OAuth, you register one PagerDuty OAuth app and each user authoriz ### Create a PagerDuty OAuth app -Register an OAuth app in PagerDuty so each user can authorize C1 with their own account. +Register an OAuth app in PagerDuty so each user can authorize C1.ai with their own account. @@ -208,7 +208,7 @@ Add an **OAuth 2.0** functionality to the app and choose the authorization code -Set the **Redirect URL** exactly to whichever matches your C1 tenant's domain, then choose the scopes the server needs, such as read access to incidents, services, and users: +Set the **Redirect URL** exactly to whichever matches your C1.ai tenant's domain, then choose the scopes the server needs, such as read access to incidents, services, and users: - Default instance: `https://accounts.conductor.one/auth/callback` - EU data residency instance: `https://accounts.c1eu.ai/auth/callback` @@ -240,7 +240,7 @@ A REST API key authenticates every user as one shared PagerDuty identity. Use th ### Create a REST API key -Create a REST API key in PagerDuty for C1 to authenticate with as a single shared identity. +Create a REST API key in PagerDuty for C1.ai to authenticate with as a single shared identity. @@ -254,7 +254,7 @@ Select **Create Key** and copy the key. PagerDuty shows the key only once. -For a shared production setup, create the key from a dedicated service-account user so activity is attributable to C1 rather than a person. +For a shared production setup, create the key from a dedicated service-account user so activity is attributable to C1.ai rather than a person. ### Register the server with a REST API key @@ -271,7 +271,7 @@ Enter the **actor email** — the email of a valid PagerDuty user to record as t When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Bearer token** and paste your REST API key. -Save your changes. C1 starts a sync that discovers the tools the PagerDuty server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the PagerDuty server exposes. @@ -280,13 +280,13 @@ Save your changes. C1 starts a sync that discovers the tools the PagerDuty serve How PagerDuty sees your users' activity depends on the method you chose: - **Per-user OAuth.** Each user authorizes with their own PagerDuty account, so tool calls run under that user's PagerDuty identity and inherit only the access they already have. PagerDuty attributes each action to the individual user. -- **REST API key.** Every user's tool calls use the one key you provided, so PagerDuty sees a single shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). +- **REST API key.** Every user's tool calls use the one key you provided, so PagerDuty sees a single shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). ## Discover and govern tools -After you register the server, C1 runs tool discovery against PagerDuty. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against PagerDuty. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -298,8 +298,8 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your PagerDuty credentials -- **Rotate the OAuth client secret** in your PagerDuty app under **Integrations** > **Developer Tools** > **App Registration**, then update the secret on the server's authentication settings in C1. -- **Rotate a REST API key** by creating a new key in PagerDuty and updating it in C1, then delete the old key. +- **Rotate the OAuth client secret** in your PagerDuty app under **Integrations** > **Developer Tools** > **App Registration**, then update the secret on the server's authentication settings in C1.ai. +- **Rotate a REST API key** by creating a new key in PagerDuty and updating it in C1.ai, then delete the old key. - **Adjust access** by editing the OAuth app's scopes or by choosing a read-only versus full-access REST API key in PagerDuty. diff --git a/product/admin/mcp-server/pylon.mdx b/product/admin/mcp-server/pylon.mdx index 7efe92e8..efa03a48 100644 --- a/product/admin/mcp-server/pylon.mdx +++ b/product/admin/mcp-server/pylon.mdx @@ -1,29 +1,29 @@ --- title: Set up the Pylon MCP server -description: Connect Pylon to C1 through the Pylon API or Pylon's own hosted MCP server, then register the server and govern its tools. +description: Connect Pylon to C1.ai through the Pylon API or Pylon's own hosted MCP server, then register the server and govern its tools. og:title: Set up the Pylon MCP server -og:description: Connect Pylon to C1 through the Pylon API or Pylon's own hosted MCP server, then register the server and govern its tools. +og:description: Connect Pylon to C1.ai through the Pylon API or Pylon's own hosted MCP server, then register the server and govern its tools. sidebarTitle: Pylon --- {/* Editor Refresh: 2026-07-24 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -C1 can govern [Pylon](https://www.usepylon.com/) access two ways. Both let your AI clients read from and act on Pylon through governed MCP tools, but they come from different places and appear as two separate entries in your MCP server catalog: +C1.ai can govern [Pylon](https://www.usepylon.com/) access two ways. Both let your AI clients read from and act on Pylon through governed MCP tools, but they come from different places and appear as two separate entries in your MCP server catalog: -- **Pylon MCP** — listed as plain **Pylon** in your catalog. C1 registers Pylon's own hosted MCP server (`mcp.usepylon.com`) as a downstream server C1 governs. Authentication is always per-user OAuth using dynamic client registration (DCR) — Pylon's hosted MCP server doesn't support a bearer token or API key, so there's no integration to create in Pylon first. Tool calls run with the connected user's own Pylon seat permissions. -- **Pylon API** — C1 hosts its own MCP server that translates Pylon's REST API into tools. Authentication is a single shared bearer token (an API token generated in Pylon), so every tool call reaches Pylon as one shared identity. +- **Pylon MCP** — listed as plain **Pylon** in your catalog. C1.ai registers Pylon's own hosted MCP server (`mcp.usepylon.com`) as a downstream server C1.ai governs. Authentication is always per-user OAuth using dynamic client registration (DCR) — Pylon's hosted MCP server doesn't support a bearer token or API key, so there's no integration to create in Pylon first. Tool calls run with the connected user's own Pylon seat permissions. +- **Pylon API** — C1.ai hosts its own MCP server that translates Pylon's REST API into tools. Authentication is a single shared bearer token (an API token generated in Pylon), so every tool call reaches Pylon as one shared identity. | | Pylon MCP | Pylon API | | :--- | :--- | :--- | -| **Who hosts the MCP server** | Pylon | C1 | +| **Who hosts the MCP server** | Pylon | C1.ai | | **Authentication** | Per-user OAuth with dynamic client registration (DCR) only — no bearer token or API key option | Bearer token (API token) only — no OAuth option | | **Access scoping** | The connected user's own Pylon seat and role permissions — not independently scoped | Whatever the API token's seat can reach in Pylon | | **Tool surface** | Pylon's own tool set: search, read, create, and update issues, accounts, and contacts | Issues, accounts, contacts, teams, users, knowledge bases, and tags, mapped to Pylon API endpoints | -| **Setup effort** | Register in C1 and authorize — nothing to create in Pylon first | Generate an API token in Pylon, then register it in C1 | +| **Setup effort** | Register in C1.ai and authorize — nothing to create in Pylon first | Generate an API token in Pylon, then register it in C1.ai | Use the native **Pylon MCP** option (listed as plain **Pylon** in your catalog) if per-user OAuth is acceptable for your tenant and Pylon's own agentic tool set is enough. Use **Pylon API** if you need a shared service-account credential (bearer token) instead. @@ -31,7 +31,7 @@ Use the native **Pylon MCP** option (listed as plain **Pylon** in your catalog) -C1 registers as a client of Pylon's own hosted MCP server ([Pylon MCP](https://docs.usepylon.com/pylon-docs/integrations/pylon-mcp)) rather than translating Pylon's REST API itself. Your users' AI clients still only ever see C1-governed MCP tools, but C1 proxies each tool call straight through to `mcp.usepylon.com` under the connected user's authorized session, then returns the result. The tools available are exactly the ones Pylon's own MCP server exposes — C1 doesn't reshape or add to them. +C1.ai registers as a client of Pylon's own hosted MCP server ([Pylon MCP](https://docs.usepylon.com/pylon-docs/integrations/pylon-mcp)) rather than translating Pylon's REST API itself. Your users' AI clients still only ever see C1.ai-governed MCP tools, but C1.ai proxies each tool call straight through to `mcp.usepylon.com` under the connected user's authorized session, then returns the result. The tools available are exactly the ones Pylon's own MCP server exposes — C1.ai doesn't reshape or add to them. ## Before you begin @@ -40,12 +40,12 @@ C1 registers as a client of Pylon's own hosted MCP server ([Pylon MCP](https://d - A Pylon admin must first turn on the MCP server from **Settings → AI Controls → MCP Server** in the Pylon dashboard ([Pylon MCP](https://docs.usepylon.com/pylon-docs/integrations/pylon-mcp#setup-in-pylon)). Each person who will connect needs a **Member** or **Admin** seat with the **MCP Access** role enabled; **Viewer** and **Integration** seats can't authenticate and see an "Authorization failed" error ([Connecting to the Pylon MCP Server](https://support.usepylon.com/articles/2407390554-connecting-to-the-pylon-mcp-server)). -In your MCP server catalog, this option is listed as **Pylon** — distinct from the **Pylon API** entry, which connects through C1's own MCP server. If you don't see either, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +In your MCP server catalog, this option is listed as **Pylon** — distinct from the **Pylon API** entry, which connects through C1.ai's own MCP server. If you don't see either, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Set up per-user OAuth -Per-user OAuth with dynamic client registration (DCR) is the only authentication method this option supports — there's no bearer token or API key fallback. Each user authorizes individually, and C1 registers itself with Pylon's authorization server automatically, so there's no app to create in Pylon first. +Per-user OAuth with dynamic client registration (DCR) is the only authentication method this option supports — there's no bearer token or API key fallback. Each user authorizes individually, and C1.ai registers itself with Pylon's authorization server automatically, so there's no app to create in Pylon first. @@ -55,7 +55,7 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **OAuth2 — per-user passthrough** and enable **Use dynamic client registration**. There's no client ID or secret to enter. -Save your changes. The first time a user calls a Pylon tool from their AI client, they're redirected to Pylon to sign in (if they aren't already) and approve the connection, then returned to C1. +Save your changes. The first time a user calls a Pylon tool from their AI client, they're redirected to Pylon to sign in (if they aren't already) and approve the connection, then returned to C1.ai. @@ -65,11 +65,11 @@ Once a user authorizes, tool calls run with that user's own Pylon seat permissio ## How Pylon MCP credentials are shared -This option only supports per-user OAuth — there's no shared, service-account, or bearer-token mode. Every tool call runs under the calling user's own Pylon identity, and Pylon attributes each action to that individual. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). +This option only supports per-user OAuth — there's no shared, service-account, or bearer-token mode. Every tool call runs under the calling user's own Pylon identity, and Pylon attributes each action to that individual. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). ## Discover and govern tools -After you register the server, C1 runs tool discovery against Pylon's MCP server. Discovered tools appear on the server's **Tools** tab and include Pylon's own search, read, create, and update tools for issues, accounts, and contacts. +After you register the server, C1.ai runs tool discovery against Pylon's MCP server. Discovered tools appear on the server's **Tools** tab and include Pylon's own search, read, create, and update tools for issues, accounts, and contacts. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -81,7 +81,7 @@ Tool discovery runs even if authentication isn't complete yet, so seeing discove ## Manage access to Pylon MCP -Because this option uses per-user OAuth, there's no shared secret in C1 to rotate. Users and admins manage access from Pylon itself: +Because this option uses per-user OAuth, there's no shared secret in C1.ai to rotate. Users and admins manage access from Pylon itself: - **An individual user's session expires periodically** — some sessions last a few hours, others several days ([Connecting to the Pylon MCP Server](https://support.usepylon.com/articles/2407390554-connecting-to-the-pylon-mcp-server)). Reconnecting re-runs the same authorization flow. - **A Pylon admin can turn off the integration workspace-wide** from the same **Settings → AI Controls → MCP Server** panel used to enable it, or remove an individual's **MCP Access** role from the Users page under Settings to cut off just that person's connection ([Roles & User Management](https://docs.usepylon.com/pylon-docs/platform/roles-and-user-management)). @@ -90,7 +90,7 @@ Because this option uses per-user OAuth, there's no shared secret in C1 to rotat -C1 hosts the Pylon MCP server, so your users' AI clients only ever see MCP tools — they never call Pylon directly. When an AI client calls one of these tools, C1 makes the matching request to the Pylon API using the bearer token you configure here, then returns the result to the AI client. +C1.ai hosts the Pylon MCP server, so your users' AI clients only ever see MCP tools — they never call Pylon directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Pylon API using the bearer token you configure here, then returns the result to the AI client. Pylon's REST API supports a single authentication method: a bearer token generated in the Pylon dashboard. Every tool call reaches Pylon as that one shared identity. @@ -100,30 +100,30 @@ Pylon's REST API supports a single authentication method: a bearer token generat - You need access to generate an API token in Pylon, at **Settings → API Tokens** in the Pylon dashboard. -In your MCP server catalog, this option is listed as **Pylon API** — distinct from the **Pylon** entry, which connects to Pylon's own hosted MCP server. If you don't see either, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +In your MCP server catalog, this option is listed as **Pylon API** — distinct from the **Pylon** entry, which connects to Pylon's own hosted MCP server. If you don't see either, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Generate a Pylon API token -Generate the token in Pylon before registering the server in C1. +Generate the token in Pylon before registering the server in C1.ai. In Pylon, go to [Settings → API Tokens](https://app.usepylon.com/settings/api-tokens). -Create a new token and give it a recognizable name — actions the token takes in Pylon show up under that name, so use something that identifies C1. +Create a new token and give it a recognizable name — actions the token takes in Pylon show up under that name, so use something that identifies C1.ai. Copy the token. Treat it as a high-value credential; Pylon only shows it once. -For a shared production setup, generate the token from a dedicated service-account user so activity is attributable to C1 rather than a person. +For a shared production setup, generate the token from a dedicated service-account user so activity is attributable to C1.ai rather than a person. -## Register the server in C1 +## Register the server in C1.ai -With your API token ready, register the server and provide it to C1. +With your API token ready, register the server and provide it to C1.ai. @@ -133,17 +133,17 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Bearer token** and paste your Pylon API token. -Save your changes. C1 starts a sync that discovers the tools the Pylon server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Pylon server exposes. ## How Pylon API credentials are shared -Every user's tool calls use the one bearer token you provided, so Pylon sees a single shared identity, attributed to whichever token name you chose. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). +Every user's tool calls use the one bearer token you provided, so Pylon sees a single shared identity, attributed to whichever token name you chose. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). ## Discover and govern tools -After you register the server, C1 runs tool discovery against Pylon. Discovered tools appear on the server's **Tools** tab and include issues, accounts, contacts, teams, users, knowledge bases, and tags. +After you register the server, C1.ai runs tool discovery against Pylon. Discovered tools appear on the server's **Tools** tab and include issues, accounts, contacts, teams, users, knowledge bases, and tags. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -155,8 +155,8 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Pylon API credentials -- **Rotate the token** by generating a new one at **Settings → API Tokens** in Pylon, then updating it on the server's authentication settings in C1. Revoke the old token in Pylon once the new one is in place. -- **Revoke access entirely** by deleting the token in Pylon; C1's calls will start failing until you provide a new one. +- **Rotate the token** by generating a new one at **Settings → API Tokens** in Pylon, then updating it on the server's authentication settings in C1.ai. Revoke the old token in Pylon once the new one is in place. +- **Revoke access entirely** by deleting the token in Pylon; C1.ai's calls will start failing until you provide a new one. diff --git a/product/admin/mcp-server/ramp.mdx b/product/admin/mcp-server/ramp.mdx index 3edea4d4..41954298 100644 --- a/product/admin/mcp-server/ramp.mdx +++ b/product/admin/mcp-server/ramp.mdx @@ -1,18 +1,18 @@ --- title: Set up the Ramp MCP server -description: Connect Ramp to C1 with per-user OAuth or a shared OAuth2 service app, then register the Ramp MCP server and govern its tools. +description: Connect Ramp to C1.ai with per-user OAuth or a shared OAuth2 service app, then register the Ramp MCP server and govern its tools. og:title: Set up the Ramp MCP server -og:description: Connect Ramp to C1 with per-user OAuth or a shared OAuth2 service app, then register the Ramp MCP server and govern its tools. +og:description: Connect Ramp to C1.ai with per-user OAuth or a shared OAuth2 service app, then register the Ramp MCP server and govern its tools. sidebarTitle: Ramp --- {/* Editor Refresh: 2026-06-11 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -The Ramp MCP server lets you govern access to Ramp — users, departments, cards, transactions, reimbursements, bills, and other spend data — as tools your AI clients can call through C1. +The Ramp MCP server lets you govern access to Ramp — users, departments, cards, transactions, reimbursements, bills, and other spend data — as tools your AI clients can call through C1.ai. Ramp authenticates with OAuth. You create a Ramp developer app, then choose how users connect when you register the server: @@ -21,11 +21,11 @@ Ramp authenticates with OAuth. You create a Ramp developer app, then choose how For a deeper comparison of shared versus per-user credentials, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## How C1 connects to Ramp +## How C1.ai connects to Ramp -C1 hosts the Ramp MCP server, so your users' AI clients only ever see MCP tools — they never call Ramp directly. When an AI client calls one of these tools, C1 makes the matching request to the Ramp API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Ramp MCP server, so your users' AI clients only ever see MCP tools — they never call Ramp directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Ramp API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call Ramp on your users' behalf. +The credentials you set up below are what C1.ai uses to call Ramp on your users' behalf. ## Before you begin @@ -33,12 +33,12 @@ The credentials you set up below are what C1 uses to call Ramp on your users' be - A Ramp account with permission to create developer apps, which typically requires an admin role. -If you don't see **Ramp** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **Ramp** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Create a Ramp developer app -Create a developer app in Ramp so C1 can authenticate with the Ramp API. +Create a developer app in Ramp so C1.ai can authenticate with the Ramp API. @@ -48,7 +48,7 @@ In Ramp, open **Settings** > **Developer** and create a new app. See Ramp's [Acc Give the app a recognizable name such as `C1`. -For per-user OAuth, set the **redirect URI** exactly to whichever matches your C1 tenant's domain: +For per-user OAuth, set the **redirect URI** exactly to whichever matches your C1.ai tenant's domain: - Default instance: `https://accounts.conductor.one/auth/callback` - EU data residency instance: `https://accounts.c1eu.ai/auth/callback` @@ -86,7 +86,7 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **OAuth2 — service mode** and enter your app's **client ID** and **client secret**. -Save your changes. C1 starts a sync that discovers the tools the Ramp server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Ramp server exposes. @@ -95,13 +95,13 @@ Save your changes. C1 starts a sync that discovers the tools the Ramp server exp How Ramp sees your users' activity depends on the method you chose: - **Per-user OAuth.** Each user authorizes with their own Ramp account, so tool calls run under that user's Ramp identity and inherit only the access they already have. Ramp attributes each action to the individual user. -- **OAuth2 service mode.** Every user's tool calls use the one shared app you provided, so Ramp sees a single shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). +- **OAuth2 service mode.** Every user's tool calls use the one shared app you provided, so Ramp sees a single shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). ## Discover and govern tools -After you register the server, C1 runs tool discovery against Ramp. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Ramp. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -113,5 +113,5 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Ramp credentials -- **Rotate the client secret** in your Ramp developer app, then update the secret on the server's authentication settings in C1. +- **Rotate the client secret** in your Ramp developer app, then update the secret on the server's authentication settings in C1.ai. - **Adjust access** by editing the app's scopes in Ramp. diff --git a/product/admin/mcp-server/rapid7.mdx b/product/admin/mcp-server/rapid7.mdx index b9ce0bd7..17d64937 100644 --- a/product/admin/mcp-server/rapid7.mdx +++ b/product/admin/mcp-server/rapid7.mdx @@ -1,26 +1,26 @@ --- title: Set up the Rapid7 MCP server -description: Create a Rapid7 InsightVM API account, then register the Rapid7 MCP server in C1 and govern the tools your AI clients can call. +description: Create a Rapid7 InsightVM API account, then register the Rapid7 MCP server in C1.ai and govern the tools your AI clients can call. og:title: Set up the Rapid7 MCP server -og:description: Create a Rapid7 InsightVM API account, then register the Rapid7 MCP server in C1 and govern the tools your AI clients can call. +og:description: Create a Rapid7 InsightVM API account, then register the Rapid7 MCP server in C1.ai and govern the tools your AI clients can call. sidebarTitle: Rapid7 --- {/* Editor Refresh: 2026-06-11 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -The Rapid7 MCP server lets you govern access to Rapid7 InsightVM — assets, vulnerabilities, scans, sites, and reports exposed by the InsightVM Security Console API — as tools your AI clients can call through C1. +The Rapid7 MCP server lets you govern access to Rapid7 InsightVM — assets, vulnerabilities, scans, sites, and reports exposed by the InsightVM Security Console API — as tools your AI clients can call through C1.ai. Rapid7 InsightVM authenticates with a console username and password using HTTP basic auth. A single account authenticates every user, so all tool calls reach InsightVM as one shared identity. -## How C1 connects to Rapid7 +## How C1.ai connects to Rapid7 -C1 hosts the Rapid7 MCP server, so your users' AI clients only ever see MCP tools — they never call Rapid7 directly. When an AI client calls one of these tools, C1 makes the matching request to the Rapid7 InsightVM API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Rapid7 MCP server, so your users' AI clients only ever see MCP tools — they never call Rapid7 directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Rapid7 InsightVM API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call Rapid7 on your users' behalf. +The credentials you set up below are what C1.ai uses to call Rapid7 on your users' behalf. ## Before you begin @@ -28,12 +28,12 @@ The credentials you set up below are what C1 uses to call Rapid7 on your users' - An InsightVM Security Console account with the permissions needed to read the assets and vulnerability data you want to govern, and network access to the console's API port (3780 by default). -If you don't see **Rapid7** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **Rapid7** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Create a Rapid7 InsightVM API account -The InsightVM API uses Security Console credentials. Create a dedicated console user for C1 so the credential is recognizable and easy to rotate. For more information, see Rapid7's [Managing users and authentication](https://docs.rapid7.com/insightvm/managing-users-and-authentication/) documentation. +The InsightVM API uses Security Console credentials. Create a dedicated console user for C1.ai so the credential is recognizable and easy to rotate. For more information, see Rapid7's [Managing users and authentication](https://docs.rapid7.com/insightvm/managing-users-and-authentication/) documentation. @@ -44,19 +44,19 @@ In the InsightVM Security Console, go to **Administration** > **Users** and crea Grant the user only the roles and asset-group access needed to read the data you want to govern, such as read access to sites, assets, and vulnerabilities. -Note the user's **username** and **password**, and confirm the console **host** and **API port** (3780 by default) that C1 will connect to. +Note the user's **username** and **password**, and confirm the console **host** and **API port** (3780 by default) that C1.ai will connect to. -For a shared production setup, use a dedicated service account so activity is attributable to C1 rather than a person. +For a shared production setup, use a dedicated service account so activity is attributable to C1.ai rather than a person. ## How Rapid7 credentials are shared -The console account authenticates every user as one shared InsightVM identity, so InsightVM sees a single identity for all tool calls. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared setup, create the credential from a dedicated service account so activity is attributable to C1 rather than a person. +The console account authenticates every user as one shared InsightVM identity, so InsightVM sees a single identity for all tool calls. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared setup, create the credential from a dedicated service account so activity is attributable to C1.ai rather than a person. For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## Register the Rapid7 MCP server in C1 +## Register the Rapid7 MCP server in C1.ai With your console account ready, register the server and provide your credentials. @@ -71,13 +71,13 @@ Enter your InsightVM Security Console **host** (such as `nexpose.example.com`) a When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Basic auth** and enter the console **username** and **password**. -Save your changes. C1 starts a sync that discovers the tools the Rapid7 server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Rapid7 server exposes. ## Discover and govern tools -After you register the server, C1 runs tool discovery against Rapid7. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Rapid7. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -89,5 +89,5 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Rapid7 credentials -- **Rotate the password** on the InsightVM console user, then update the password on the server's authentication settings in C1. +- **Rotate the password** on the InsightVM console user, then update the password on the server's authentication settings in C1.ai. - **Adjust access** by editing the roles and asset-group access granted to the console user in InsightVM. diff --git a/product/admin/mcp-server/salesforce.mdx b/product/admin/mcp-server/salesforce.mdx index 5b8b7c44..1c17a828 100644 --- a/product/admin/mcp-server/salesforce.mdx +++ b/product/admin/mcp-server/salesforce.mdx @@ -1,26 +1,26 @@ --- title: Set up the Salesforce MCP server -description: Connect Salesforce to C1 with per-user OAuth, then register the Salesforce MCP server and govern the tools it exposes. +description: Connect Salesforce to C1.ai with per-user OAuth, then register the Salesforce MCP server and govern the tools it exposes. og:title: Set up the Salesforce MCP server -og:description: Connect Salesforce to C1 with per-user OAuth, then register the Salesforce MCP server and govern the tools it exposes. +og:description: Connect Salesforce to C1.ai with per-user OAuth, then register the Salesforce MCP server and govern the tools it exposes. sidebarTitle: Salesforce --- {/* Editor Refresh: 2026-06-11 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -The Salesforce MCP server lets you govern access to the Salesforce Customer Platform — accounts, contacts, opportunities, custom objects, and the rest of the Salesforce data model — as tools your AI clients can call through C1. +The Salesforce MCP server lets you govern access to the Salesforce Customer Platform — accounts, contacts, opportunities, custom objects, and the rest of the Salesforce data model — as tools your AI clients can call through C1.ai. Salesforce uses per-user OAuth, which is recommended: each person authorizes with their own Salesforce account, so every tool call runs under that user's identity and permissions. -## How C1 connects to Salesforce +## How C1.ai connects to Salesforce -C1 hosts the Salesforce MCP server, so your users' AI clients only ever see MCP tools — they never call Salesforce directly. When an AI client calls one of these tools, C1 makes the matching request to the Salesforce API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Salesforce MCP server, so your users' AI clients only ever see MCP tools — they never call Salesforce directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Salesforce API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call Salesforce on your users' behalf. +The credentials you set up below are what C1.ai uses to call Salesforce on your users' behalf. ## Before you begin @@ -28,7 +28,7 @@ The credentials you set up below are what C1 uses to call Salesforce on your use - A Salesforce admin account that can create a connected app, typically the **System Administrator** profile or the **Customize Application** and **Modify All Data** permissions. -If you don't see **Salesforce** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **Salesforce** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Create a Salesforce connected app @@ -47,7 +47,7 @@ Fill in **Basic Information**: - **Contact Email** — your team's email. -Under **API (Enable OAuth Settings)**, select **Enable OAuth Settings**, then set the **Callback URL** exactly to whichever matches your C1 tenant's domain: +Under **API (Enable OAuth Settings)**, select **Enable OAuth Settings**, then set the **Callback URL** exactly to whichever matches your C1.ai tenant's domain: - Default instance: `https://accounts.conductor.one/auth/callback` - EU data residency instance: `https://accounts.c1eu.ai/auth/callback` @@ -58,7 +58,7 @@ The URL must match character for character, including any trailing slash. Under **Selected OAuth Scopes**, add: - **Manage user data via APIs (`api`)** — grants Salesforce REST API access on behalf of the user. -- **Perform requests at any time (`refresh_token`, `offline_access`)** — issues a refresh token so C1 can renew access without prompting the user again. +- **Perform requests at any time (`refresh_token`, `offline_access`)** — issues a refresh token so C1.ai can renew access without prompting the user again. Select **Save**. The new connected app can take up to ten minutes to propagate. @@ -78,7 +78,7 @@ With per-user OAuth, each user authorizes with their own Salesforce account, so For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## Register the Salesforce MCP server in C1 +## Register the Salesforce MCP server in C1.ai With your connected app ready, register the server and provide your credentials. @@ -96,7 +96,7 @@ Save your changes. The first time a user calls a Salesforce tool from their AI c ## Discover and govern tools -After you register the server, C1 runs tool discovery against Salesforce. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Salesforce. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -108,5 +108,5 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Salesforce credentials -- **Rotate the consumer secret** in **App Manager** by opening your connected app and re-fetching its consumer details, then update the secret on the server's authentication settings in C1. +- **Rotate the consumer secret** in **App Manager** by opening your connected app and re-fetching its consumer details, then update the secret on the server's authentication settings in C1.ai. - **Adjust access** by editing the connected app's OAuth scopes in Salesforce. diff --git a/product/admin/mcp-server/slack.mdx b/product/admin/mcp-server/slack.mdx index 739c7b45..3fc63a86 100644 --- a/product/admin/mcp-server/slack.mdx +++ b/product/admin/mcp-server/slack.mdx @@ -1,46 +1,46 @@ --- title: Set up the Slack MCP server -description: Connect Slack to C1 through the Slack API or Slack's own hosted MCP server, then register the server and govern its tools. +description: Connect Slack to C1.ai through the Slack API or Slack's own hosted MCP server, then register the server and govern its tools. og:title: Set up the Slack MCP server -og:description: Connect Slack to C1 through the Slack API or Slack's own hosted MCP server, then register the server and govern its tools. +og:description: Connect Slack to C1.ai through the Slack API or Slack's own hosted MCP server, then register the server and govern its tools. sidebarTitle: Slack --- {/* Editor Refresh: 2026-07-24 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -C1 can govern Slack access two ways. Both let your AI clients read from and act on Slack through governed MCP tools, but they come from different places and appear as two separate entries in your MCP server catalog: +C1.ai can govern Slack access two ways. Both let your AI clients read from and act on Slack through governed MCP tools, but they come from different places and appear as two separate entries in your MCP server catalog: -- **Slack MCP** — listed as plain **Slack** in your catalog. C1 registers Slack's own hosted MCP server (`mcp.slack.com`) as a downstream server C1 governs. Authentication uses Slack's dedicated user-token OAuth flow: an admin registers a Slack app and provides its client ID and secret to C1 (there's no dynamic client registration), then each user authorizes individually. A static Slack user token is also supported as a bearer fallback. Tool calls run with the connected user's **User Token Scopes** — never a bot identity. -- **Slack API** — C1 hosts its own MCP server that translates the Slack API into tools. You authorize with per-user OAuth using a Slack app's client ID and secret, and scope access with the **User Token Scopes** you configure. +- **Slack MCP** — listed as plain **Slack** in your catalog. C1.ai registers Slack's own hosted MCP server (`mcp.slack.com`) as a downstream server C1.ai governs. Authentication uses Slack's dedicated user-token OAuth flow: an admin registers a Slack app and provides its client ID and secret to C1.ai (there's no dynamic client registration), then each user authorizes individually. A static Slack user token is also supported as a bearer fallback. Tool calls run with the connected user's **User Token Scopes** — never a bot identity. +- **Slack API** — C1.ai hosts its own MCP server that translates the Slack API into tools. You authorize with per-user OAuth using a Slack app's client ID and secret, and scope access with the **User Token Scopes** you configure. | | Slack MCP | Slack API | | :--- | :--- | :--- | -| **Who hosts the MCP server** | Slack | C1 | +| **Who hosts the MCP server** | Slack | C1.ai | | **Authentication** | Slack's user-token OAuth flow via a Slack app you register (client ID/secret; no dynamic client registration) — or a static user token as a bearer fallback | Per-user OAuth via a Slack app's client ID/secret | | **Access scoping** | The **User Token Scopes** you request on the Slack app | The **User Token Scopes** you configure | | **Tool surface** | Slack's own tool set exposed by its hosted MCP server | Channels, messages, users, files, and search, mapped to Slack API endpoints | -| **Setup effort** | Create a Slack app, turn on its **Slack Model Context Protocol (MCP) Server** toggle, configure the user-token OAuth flow (or a static token), then register in C1 | Create a Slack app, configure user token scopes, then register in C1 | +| **Setup effort** | Create a Slack app, turn on its **Slack Model Context Protocol (MCP) Server** toggle, configure the user-token OAuth flow (or a static token), then register in C1.ai | Create a Slack app, configure user token scopes, then register in C1.ai | -Use the native **Slack MCP** option (listed as plain **Slack** in your catalog) if you want Slack's own hosted tool set and can register a Slack app for its user-token OAuth flow (or a static token). Use **Slack API** if you'd rather use C1's own Slack integration with the scopes-based setup you're already familiar with. +Use the native **Slack MCP** option (listed as plain **Slack** in your catalog) if you want Slack's own hosted tool set and can register a Slack app for its user-token OAuth flow (or a static token). Use **Slack API** if you'd rather use C1.ai's own Slack integration with the scopes-based setup you're already familiar with. -C1 registers as a client of Slack's own hosted MCP server ([Slack MCP server](https://docs.slack.dev/ai/slack-mcp-server)) rather than translating the Slack API itself. Your users' AI clients still only ever see C1-governed MCP tools, but C1 proxies each tool call straight through to `mcp.slack.com` under the connected user's authorized session (or a configured static token), then returns the result. The tools available are exactly the ones Slack's own MCP server exposes — C1 doesn't reshape or add to them. +C1.ai registers as a client of Slack's own hosted MCP server ([Slack MCP server](https://docs.slack.dev/ai/slack-mcp-server)) rather than translating the Slack API itself. Your users' AI clients still only ever see C1.ai-governed MCP tools, but C1.ai proxies each tool call straight through to `mcp.slack.com` under the connected user's authorized session (or a configured static token), then returns the result. The tools available are exactly the ones Slack's own MCP server exposes — C1.ai doesn't reshape or add to them. ## Before you begin - AI access management must be enabled for your tenant. See [Enable AI access management](/product/admin/enable-ai-access-management). -- Permission to create and configure a Slack app. Unlike some MCP servers, Slack's hosted MCP server doesn't support dynamic client registration, so you register an app and provide its client ID and secret to C1 before anyone can authorize. +- Permission to create and configure a Slack app. Unlike some MCP servers, Slack's hosted MCP server doesn't support dynamic client registration, so you register an app and provide its client ID and secret to C1.ai before anyone can authorize. - Only a **directory-published** or **internal** Slack app can use the hosted MCP server — see Step 3 below. -In your MCP server catalog, this option is listed as **Slack** — distinct from the **Slack API** entry, which connects through C1's own MCP server. If you don't see either, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +In your MCP server catalog, this option is listed as **Slack** — distinct from the **Slack API** entry, which connects through C1.ai's own MCP server. If you don't see either, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Create a Slack app for MCP @@ -52,7 +52,7 @@ Before configuring authentication, register a Slack app and turn on its MCP supp Sign in at [api.slack.com/apps](https://api.slack.com/apps) and select **Create New App** > **From an app manifest**. Choose the workspace to develop in, then select **Next**. -Paste the manifest below and select **Next**, then **Create**. It turns on MCP support and sets the redirect URL and C1's default, read-only **User Token Scopes** for you, instead of clicking through Slack's scope picker. Slack ignores YAML comments on import, so the commented-out write scopes stay disabled until you uncomment them and reimport. +Paste the manifest below and select **Next**, then **Create**. It turns on MCP support and sets the redirect URL and C1.ai's default, read-only **User Token Scopes** for you, instead of clicking through Slack's scope picker. Slack ignores YAML comments on import, so the commented-out write scopes stay disabled until you uncomment them and reimport. The manifest below uses the default instance's redirect URL. If your tenant is on the EU data residency instance, change `redirect_urls` to `https://accounts.c1eu.ai/auth/callback` before you paste it in. @@ -114,7 +114,7 @@ In the app settings sidebar, open **Features** > **Agents**. Under **Slack Model Leave the **Agent experience** toggle on the same page off. It's a separate Slack feature for conversational agents, and the MCP server doesn't require it. -Make the app eligible to use the MCP server: either submit it to the Slack Marketplace (directory-published), or have a workspace admin install it as an internal app. Keep the app ID fixed once you've registered it in C1, since C1's connection pins to it. +Make the app eligible to use the MCP server: either submit it to the Slack Marketplace (directory-published), or have a workspace admin install it as an internal app. Keep the app ID fixed once you've registered it in C1.ai, since C1.ai's connection pins to it. @@ -141,11 +141,11 @@ Scope changes take effect the next time a user connects (or the next call using ## Option 1: Set up the user-token OAuth flow (recommended) -With per-user OAuth, each person authorizes individually and tool calls run under that user's own Slack identity. Because the MCP server issues user tokens rather than bot tokens, C1 uses Slack's dedicated user-token OAuth endpoints — authorizing at `slack.com/oauth/v2_user/authorize` and exchanging the code at `slack.com/api/oauth.v2.user.access` — rather than Slack's classic bot-token authorize and token pair. There's no dynamic client registration for this flow: you register the Slack app from the previous step, then provide its client ID and secret to C1. +With per-user OAuth, each person authorizes individually and tool calls run under that user's own Slack identity. Because the MCP server issues user tokens rather than bot tokens, C1.ai uses Slack's dedicated user-token OAuth endpoints — authorizing at `slack.com/oauth/v2_user/authorize` and exchanging the code at `slack.com/api/oauth.v2.user.access` — rather than Slack's classic bot-token authorize and token pair. There's no dynamic client registration for this flow: you register the Slack app from the previous step, then provide its client ID and secret to C1.ai. -In the app settings, open **OAuth & Permissions** and confirm the redirect URL and the **User Token Scopes** match the manifest — see [Slack MCP scopes](#slack-mcp-scopes) above. The redirect URL should be whichever matches your C1 tenant's domain: default instance `https://accounts.conductor.one/auth/callback`, EU data residency instance `https://accounts.c1eu.ai/auth/callback`. +In the app settings, open **OAuth & Permissions** and confirm the redirect URL and the **User Token Scopes** match the manifest — see [Slack MCP scopes](#slack-mcp-scopes) above. The redirect URL should be whichever matches your C1.ai tenant's domain: default instance `https://accounts.conductor.one/auth/callback`, EU data residency instance `https://accounts.c1eu.ai/auth/callback`. If you created the app from scratch, add them now: under **Redirect URLs**, select **Add New Redirect URL**, enter the URL exactly, select **Add**, then **Save URLs**; then add the scopes under **Scopes**. @@ -159,7 +159,7 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **OAuth2 — per-user passthrough** and enter your app's **client ID** and **client secret**, plus the scopes you configured. -Save your changes. The first time a user calls a Slack tool from their AI client, they're redirected to Slack to authorize (if they aren't already), then returned to C1. +Save your changes. The first time a user calls a Slack tool from their AI client, they're redirected to Slack to authorize (if they aren't already), then returned to C1.ai. @@ -181,7 +181,7 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Bearer token** and paste the user token. -Save your changes. C1 sends the token as `Authorization: Bearer ` on every call to Slack's MCP server. +Save your changes. C1.ai sends the token as `Authorization: Bearer ` on every call to Slack's MCP server. @@ -196,13 +196,13 @@ Tool calls run with whichever **User Token Scopes** you granted — either the c How Slack sees your users' activity depends on the method you chose: - **Per-user OAuth (recommended).** Each user authorizes with their own Slack account, so tool calls run under that user's Slack user-token identity, scoped to the User Token Scopes you configured. Slack attributes each action to the individual user. -- **Static user token (Bearer).** Every user's tool calls use the one token you provided, so Slack sees a single shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). +- **Static user token (Bearer).** Every user's tool calls use the one token you provided, so Slack sees a single shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). ## Discover and govern tools -After you register the server, C1 runs tool discovery against Slack's MCP server. Discovered tools appear on the server's **Tools** tab and are exactly the ones Slack's own MCP server exposes. +After you register the server, C1.ai runs tool discovery against Slack's MCP server. Discovered tools appear on the server's **Tools** tab and are exactly the ones Slack's own MCP server exposes. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -214,8 +214,8 @@ Tool discovery runs even if authentication isn't complete yet, so seeing discove ## Manage access to Slack MCP -- **Rotate the client secret** on the app's **Basic Information** page under **App Credentials**, then update the secret on the server's authentication settings in C1. -- **Rotate a static user token** by reinstalling the app in Slack to regenerate the **User OAuth Token**, then update it in C1. +- **Rotate the client secret** on the app's **Basic Information** page under **App Credentials**, then update the secret on the server's authentication settings in C1.ai. +- **Rotate a static user token** by reinstalling the app in Slack to regenerate the **User OAuth Token**, then update it in C1.ai. - **Revoke access** by uninstalling the Slack app from the workspace on **OAuth & Permissions**, or by turning off the app's **Slack Model Context Protocol (MCP) Server** toggle under **Features** > **Agents**. - **Adjust access** by editing the app's **User Token Scopes** on the **OAuth & Permissions** page in Slack. @@ -223,15 +223,15 @@ Tool discovery runs even if authentication isn't complete yet, so seeing discove -The Slack MCP server lets you govern access to Slack — channels, messages, users, files, and search — as tools your AI clients can call through C1. +The Slack MCP server lets you govern access to Slack — channels, messages, users, files, and search — as tools your AI clients can call through C1.ai. Slack uses per-user OAuth, which is recommended: each person authorizes with their own Slack account, so every tool call runs under that user's identity and permissions. -## How C1 connects to Slack +## How C1.ai connects to Slack -C1 hosts the Slack MCP server, so your users' AI clients only ever see MCP tools — they never call Slack directly. When an AI client calls one of these tools, C1 makes the matching request to the Slack API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Slack MCP server, so your users' AI clients only ever see MCP tools — they never call Slack directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Slack API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call Slack on your users' behalf. +The credentials you set up below are what C1.ai uses to call Slack on your users' behalf. ## Before you begin @@ -239,7 +239,7 @@ The credentials you set up below are what C1 uses to call Slack on your users' b - Permission to create and configure a Slack app. See Slack's [guide to installing apps with OAuth](https://docs.slack.dev/authentication/installing-with-oauth/). -In your MCP server catalog, this option is listed as **Slack API** — distinct from the **Slack** entry, which connects to Slack's own hosted MCP server. If you don't see either, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +In your MCP server catalog, this option is listed as **Slack API** — distinct from the **Slack** entry, which connects to Slack's own hosted MCP server. If you don't see either, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Create a Slack app @@ -251,7 +251,7 @@ With per-user OAuth, you register one Slack app and each user authorizes individ Sign in to the Slack apps dashboard and select **Create New App** > **From an app manifest**. Choose the workspace to develop in, then select **Next**. For detail on the OAuth flow, see Slack's [guide to installing apps with OAuth](https://docs.slack.dev/authentication/installing-with-oauth/#how). -Paste the manifest below and select **Next**, then **Create**. It sets the redirect URL and C1's default, read-only **User Token Scopes** for you, instead of clicking through Slack's scope picker. Slack ignores YAML comments on import, so the commented-out scopes stay disabled until you uncomment them and reimport. +Paste the manifest below and select **Next**, then **Create**. It sets the redirect URL and C1.ai's default, read-only **User Token Scopes** for you, instead of clicking through Slack's scope picker. Slack ignores YAML comments on import, so the commented-out scopes stay disabled until you uncomment them and reimport. The manifest below uses the default instance's redirect URL. If your tenant is on the EU data residency instance, change `redirect_urls` to `https://accounts.c1eu.ai/auth/callback` before you paste it in. @@ -294,7 +294,7 @@ settings: -To create the app by hand instead, select **From scratch**, then add whichever redirect URL matches your C1 tenant's domain under **Redirect URLs** on **OAuth & Permissions** (default instance: `https://accounts.conductor.one/auth/callback`, EU data residency instance: `https://accounts.c1eu.ai/auth/callback`), and the scopes under **Scopes**. +To create the app by hand instead, select **From scratch**, then add whichever redirect URL matches your C1.ai tenant's domain under **Redirect URLs** on **OAuth & Permissions** (default instance: `https://accounts.conductor.one/auth/callback`, EU data residency instance: `https://accounts.c1eu.ai/auth/callback`), and the scopes under **Scopes**. In the app's left sidebar, open **OAuth & Permissions** and confirm the redirect URL and **User Token Scopes** match the manifest. Add any optional scopes your write or admin tools need from [Slack scopes](#slack-scopes) below. User token scopes let the app act as each authorizing user. @@ -306,9 +306,9 @@ In the left sidebar, open **Basic Information**. Under **App Credentials**, copy ## Slack scopes -C1 uses **user token scopes** only — every tool call acts as the authorizing user, not as a bot. The [manifest above](#create-a-slack-app) adds the default scopes under **User Token Scopes**; add any optional ones on Slack's **OAuth & Permissions** page. Leave **Bot Token Scopes** empty. +C1.ai uses **user token scopes** only — every tool call acts as the authorizing user, not as a bot. The [manifest above](#create-a-slack-app) adds the default scopes under **User Token Scopes**; add any optional ones on Slack's **OAuth & Permissions** page. Leave **Bot Token Scopes** empty. -C1 requests the default read scopes automatically. The default is read-only; to enable write or admin tools, an admin adds the optional scopes below manually — under **User Token Scopes** in Slack, and in C1's scopes field when configuring authentication. Grant only what you need. +C1.ai requests the default read scopes automatically. The default is read-only; to enable write or admin tools, an admin adds the optional scopes below manually — under **User Token Scopes** in Slack, and in C1.ai's scopes field when configuring authentication. Grant only what you need. **Default scopes** browse channels and messages (public channels, private channels, direct messages, and group direct messages), users, user groups, files, pins, and message search: @@ -337,9 +337,9 @@ With per-user OAuth, each user authorizes with their own Slack account, so tool For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## Register the Slack MCP server in C1 +## Register the Slack MCP server in C1.ai -Register the server in C1 and connect it to the Slack app you created. +Register the server in C1.ai and connect it to the Slack app you created. @@ -355,7 +355,7 @@ Save your changes. The first time a user calls a Slack tool from their AI client ## Discover and govern tools -After you register the server, C1 runs tool discovery against Slack. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Slack. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -367,7 +367,7 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Slack credentials -- **Rotate the client secret** on the app's **Basic Information** page under **App Credentials**, then update the secret on the server's authentication settings in C1. +- **Rotate the client secret** on the app's **Basic Information** page under **App Credentials**, then update the secret on the server's authentication settings in C1.ai. - **Adjust access** by editing the app's **User Token Scopes** on the **OAuth & Permissions** page in Slack. diff --git a/product/admin/mcp-server/snowflake.mdx b/product/admin/mcp-server/snowflake.mdx index 095e1e67..5b066264 100644 --- a/product/admin/mcp-server/snowflake.mdx +++ b/product/admin/mcp-server/snowflake.mdx @@ -9,16 +9,16 @@ sidebarTitle: Snowflake {/* Editor Refresh: 2026-08-31 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -**Early access.** The Snowflake MCP servers are in early access while we gather feedback. If your Snowflake setup differs from what this guide describes, [contact the C1 support team](mailto:support@c1.ai). +**Early access.** The Snowflake MCP servers are in early access while we gather feedback. If your Snowflake setup differs from what this guide describes, [contact the C1.ai support team](mailto:support@c1.ai). -The Snowflake MCP servers let you govern access to your Snowflake account — running SQL statements, inspecting databases, schemas, tables, and warehouses, and using Cortex AI features — as tools your AI clients call through C1. +The Snowflake MCP servers let you govern access to your Snowflake account — running SQL statements, inspecting databases, schemas, tables, and warehouses, and using Cortex AI features — as tools your AI clients call through C1.ai. -C1 publishes several Snowflake servers, and they all connect the same way: +C1.ai publishes several Snowflake servers, and they all connect the same way: - **Snowflake (Data)** — run SQL statements and inspect schemas, tables, databases, and warehouses. - **Snowflake (Admin)** — manage accounts, databases, and warehouses. @@ -27,11 +27,11 @@ C1 publishes several Snowflake servers, and they all connect the same way: Set up the Snowflake side once, then register each server you want to use. -## How C1 connects to Snowflake +## How C1.ai connects to Snowflake -C1 hosts the Snowflake MCP servers, so your users' AI clients only ever see MCP tools — they never call Snowflake directly. When an AI client calls one of these tools, C1 makes the matching request to the Snowflake API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Snowflake MCP servers, so your users' AI clients only ever see MCP tools — they never call Snowflake directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Snowflake API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call Snowflake on your users' behalf. +The credentials you set up below are what C1.ai uses to call Snowflake on your users' behalf. ## Before you begin @@ -39,7 +39,7 @@ The credentials you set up below are what C1 uses to call Snowflake on your user - You need the ACCOUNTADMIN role in Snowflake, or a role with the privileges to create the objects below. Only ACCOUNTADMIN has the `CREATE INTEGRATION` privilege by default. See [CREATE SECURITY INTEGRATION](https://docs.snowflake.com/en/sql-reference/sql/create-security-integration-oauth-snowflake) in the Snowflake documentation. - You need your Snowflake account URL, including the scheme, such as `https://myorg-myaccount.snowflakecomputing.com`. Find it in Snowsight under your account details, or see [Account identifiers](https://docs.snowflake.com/en/user-guide/admin-account-identifier). -## Create a Snowflake role for C1 +## Create a Snowflake role for C1.ai Snowflake OAuth has no per-API or per-resource scopes. There is no read scope or write scope to grant. What a tool can reach is decided entirely by the **Snowflake role** it runs as, and by what that role has been granted. This is true whichever authentication method you choose, so start here. @@ -77,7 +77,7 @@ Run this in Snowsight as ACCOUNTADMIN. -Create the security integration. Set `OAUTH_CLIENT_TYPE` to `'CONFIDENTIAL'`, because C1 holds the client secret in a protected backend. +Create the security integration. Set `OAUTH_CLIENT_TYPE` to `'CONFIDENTIAL'`, because C1.ai holds the client secret in a protected backend. ```sql CREATE SECURITY INTEGRATION c1_mcp_oauth @@ -99,7 +99,7 @@ Retrieve the client ID and secret. Pass the integration name in uppercase. SELECT SYSTEM$SHOW_OAUTH_CLIENT_SECRETS('C1_MCP_OAUTH'); ``` -The result is a JSON object. Copy the `oauth_client_id` and `oauth_client_secret` values — you enter both in C1. Snowflake also returns `oauth_client_secret_2`, a second secret you can use to rotate credentials without downtime. See [SYSTEM$SHOW_OAUTH_CLIENT_SECRETS](https://docs.snowflake.com/en/sql-reference/functions/system_show_oauth_client_secrets). +The result is a JSON object. Copy the `oauth_client_id` and `oauth_client_secret` values — you enter both in C1.ai. Snowflake also returns `oauth_client_secret_2`, a second secret you can use to rotate credentials without downtime. See [SYSTEM$SHOW_OAUTH_CLIENT_SECRETS](https://docs.snowflake.com/en/sql-reference/functions/system_show_oauth_client_secrets). Grant the role to everyone who will use the server. A user can only authorize as a role they already hold, so this step is what makes per-user OAuth work. @@ -143,11 +143,11 @@ Repeat for each Snowflake server you want to use. The same security integration ## How OAuth credentials are shared -Each user authorizes with their own Snowflake account, so tool calls run under that user's Snowflake identity and the role they consented to. Snowflake attributes each query to the individual user, and C1 also attributes each call in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). +Each user authorizes with their own Snowflake account, so tool calls run under that user's Snowflake identity and the role they consented to. Snowflake attributes each query to the individual user, and C1.ai also attributes each call in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). ## Manage your OAuth credentials -- **Rotate the client secret.** `SYSTEM$SHOW_OAUTH_CLIENT_SECRETS` returns two secrets, so you can move C1 to the second one and then rotate the first without interrupting users. +- **Rotate the client secret.** `SYSTEM$SHOW_OAUTH_CLIENT_SECRETS` returns two secrets, so you can move C1.ai to the second one and then rotate the first without interrupting users. - **Change what tools can reach.** Adjust the grants on `c1_mcp_role`. Tools return Snowflake's own permission error when the role lacks a privilege. - **Revoke access for one person.** Revoke the role from that user with `REVOKE ROLE c1_mcp_role FROM USER jsmith`. - **Revoke access for everyone.** Disable the integration with `ALTER SECURITY INTEGRATION c1_mcp_oauth SET ENABLED = FALSE`. @@ -215,7 +215,7 @@ Enter your **Snowflake account URL**, such as `https://myorg-myaccount.snowflake When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose the bearer token method and paste the token. Set **Snowflake token type** to `PROGRAMMATIC_ACCESS_TOKEN`. -Save your changes. C1 starts a sync that discovers the tools the Snowflake server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Snowflake server exposes. @@ -227,14 +227,14 @@ Repeat for each Snowflake server you want to use. The same service user and toke ## How token credentials are shared -Every user's tool calls use the one token you provided, so Snowflake sees a single shared identity and attributes every query to the service user. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). +Every user's tool calls use the one token you provided, so Snowflake sees a single shared identity and attributes every query to the service user. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). ## Manage your token credentials -- **Rotate the token.** Generate a replacement token, update the server's credentials in C1, then remove the old token in Snowflake. +- **Rotate the token.** Generate a replacement token, update the server's credentials in C1.ai, then remove the old token in Snowflake. - **Change what tools can reach.** Adjust the grants on `c1_mcp_role`. Tools return Snowflake's own permission error when the role lacks a privilege. - **Revoke access.** Remove the token from the user in Snowflake, or disable the service user. -- **Plan for expiry.** The token stops working at `DAYS_TO_EXPIRY`. Tool calls fail until you issue a replacement and update the credentials in C1. +- **Plan for expiry.** The token stops working at `DAYS_TO_EXPIRY`. Tool calls fail until you issue a replacement and update the credentials in C1.ai. @@ -242,7 +242,7 @@ Every user's tool calls use the one token you provided, so Snowflake sees a sing ## Discover and govern tools -After you register the server, C1 runs tool discovery against Snowflake. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Snowflake. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). diff --git a/product/admin/mcp-server/statuspage.mdx b/product/admin/mcp-server/statuspage.mdx index 2281cceb..e79d9010 100644 --- a/product/admin/mcp-server/statuspage.mdx +++ b/product/admin/mcp-server/statuspage.mdx @@ -1,26 +1,26 @@ --- title: Set up the Statuspage MCP server -description: Create a Statuspage API key, then register the Statuspage MCP server in C1 and govern the tools it exposes. +description: Create a Statuspage API key, then register the Statuspage MCP server in C1.ai and govern the tools it exposes. og:title: Set up the Statuspage MCP server -og:description: Create a Statuspage API key, then register the Statuspage MCP server in C1 and govern the tools it exposes. +og:description: Create a Statuspage API key, then register the Statuspage MCP server in C1.ai and govern the tools it exposes. sidebarTitle: Statuspage --- {/* Editor Refresh: 2026-06-11 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -The Statuspage MCP server lets you govern access to Statuspage — pages, components, incidents, maintenances, metrics, and subscribers — as tools your AI clients can call through C1. +The Statuspage MCP server lets you govern access to Statuspage — pages, components, incidents, maintenances, metrics, and subscribers — as tools your AI clients can call through C1.ai. Statuspage authenticates with an API key. A single key authenticates everyone, so all tool calls reach Statuspage as one shared identity. -## How C1 connects to Statuspage +## How C1.ai connects to Statuspage -C1 hosts the Statuspage MCP server, so your users' AI clients only ever see MCP tools — they never call Statuspage directly. When an AI client calls one of these tools, C1 makes the matching request to the Statuspage API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Statuspage MCP server, so your users' AI clients only ever see MCP tools — they never call Statuspage directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Statuspage API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call Statuspage on your users' behalf. +The credentials you set up below are what C1.ai uses to call Statuspage on your users' behalf. ## Before you begin @@ -28,12 +28,12 @@ The credentials you set up below are what C1 uses to call Statuspage on your use - A Statuspage account with access to the pages you want to govern and permission to create an API key. -If you don't see **Statuspage** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **Statuspage** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Create a Statuspage API key -Create an API key in your Statuspage account to authenticate C1's requests. +Create an API key in your Statuspage account to authenticate C1.ai's requests. @@ -47,15 +47,15 @@ Copy the generated key. Treat it as a high-value credential. -For a shared production setup, create the API key from a dedicated service account so activity is attributable to C1 rather than a person. +For a shared production setup, create the API key from a dedicated service account so activity is attributable to C1.ai rather than a person. ## How Statuspage credentials are shared -Every user's tool calls use the one API key you provided, so Statuspage sees a single shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared setup, use a dedicated service account so activity is attributable to C1 rather than a person. +Every user's tool calls use the one API key you provided, so Statuspage sees a single shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared setup, use a dedicated service account so activity is attributable to C1.ai rather than a person. For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## Register the Statuspage MCP server in C1 +## Register the Statuspage MCP server in C1.ai With your API key ready, register the server and provide your credentials. @@ -67,13 +67,13 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Custom header**. Set the header name to `Authorization` and the value to `OAuth ` followed by your API key (for example, `OAuth abc123`). -Save your changes. C1 starts a sync that discovers the tools the Statuspage server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Statuspage server exposes. ## Discover and govern tools -After you register the server, C1 runs tool discovery against Statuspage. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Statuspage. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -85,5 +85,5 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Statuspage credentials -- **Rotate the API key** by generating a new key in your Statuspage account settings and updating it in C1, then removing the old one. +- **Rotate the API key** by generating a new key in your Statuspage account settings and updating it in C1.ai, then removing the old one. - **Adjust access** by managing the account the key belongs to in Statuspage. diff --git a/product/admin/mcp-server/tableau.mdx b/product/admin/mcp-server/tableau.mdx index cab4508b..e290d979 100644 --- a/product/admin/mcp-server/tableau.mdx +++ b/product/admin/mcp-server/tableau.mdx @@ -1,43 +1,43 @@ --- title: Set up the Tableau MCP server -description: Create a Tableau session token from a personal access token, then register the Tableau MCP server in C1 and govern its tools. +description: Create a Tableau session token from a personal access token, then register the Tableau MCP server in C1.ai and govern its tools. og:title: Set up the Tableau MCP server -og:description: Create a Tableau session token from a personal access token, then register the Tableau MCP server in C1 and govern its tools. +og:description: Create a Tableau session token from a personal access token, then register the Tableau MCP server in C1.ai and govern its tools. sidebarTitle: Tableau --- {/* Editor Refresh: 2026-06-11 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -The Tableau MCP server lets you govern access to Tableau Cloud and Tableau Server — workbooks, data sources, projects, users, groups, sites, schedules, and subscriptions — as tools your AI clients can call through C1. +The Tableau MCP server lets you govern access to Tableau Cloud and Tableau Server — workbooks, data sources, projects, users, groups, sites, schedules, and subscriptions — as tools your AI clients can call through C1.ai. -Tableau authenticates with a session token that C1 sends in the `X-Tableau-Auth` header. You generate the session token from a Tableau personal access token (PAT). A single token authenticates everyone, so all tool calls reach Tableau as one shared identity. +Tableau authenticates with a session token that C1.ai sends in the `X-Tableau-Auth` header. You generate the session token from a Tableau personal access token (PAT). A single token authenticates everyone, so all tool calls reach Tableau as one shared identity. -## How C1 connects to Tableau +## How C1.ai connects to Tableau -C1 hosts the Tableau MCP server, so your users' AI clients only ever see MCP tools — they never call Tableau directly. When an AI client calls one of these tools, C1 makes the matching request to the Tableau API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Tableau MCP server, so your users' AI clients only ever see MCP tools — they never call Tableau directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Tableau API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call Tableau on your users' behalf. +The credentials you set up below are what C1.ai uses to call Tableau on your users' behalf. ## Before you begin - AI access management must be enabled for your tenant. See [Enable AI access management](/product/admin/enable-ai-access-management). -- A Tableau user with the site role needed for the operations C1 should perform. Use a **Site Administrator Creator** for full admin coverage, or a narrower Explorer or Viewer role for reads only. For a shared production setup, create a dedicated Tableau service-account user and generate the PAT from that account. +- A Tableau user with the site role needed for the operations C1.ai should perform. Use a **Site Administrator Creator** for full admin coverage, or a narrower Explorer or Viewer role for reads only. For a shared production setup, create a dedicated Tableau service-account user and generate the PAT from that account. -If you don't see **Tableau** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **Tableau** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Generate a Tableau personal access token -Create a personal access token for the Tableau user C1 should run as. For Tableau's own walkthrough, see [Manage Your Account Settings](https://help.tableau.com/current/pro/desktop/en-us/useracct.htm) and [Personal Access Tokens](https://help.tableau.com/current/server/en-us/security_personal_access_tokens.htm). +Create a personal access token for the Tableau user C1.ai should run as. For Tableau's own walkthrough, see [Manage Your Account Settings](https://help.tableau.com/current/pro/desktop/en-us/useracct.htm) and [Personal Access Tokens](https://help.tableau.com/current/server/en-us/security_personal_access_tokens.htm). -Sign in to Tableau Cloud or Tableau Server as the user C1 should run as. +Sign in to Tableau Cloud or Tableau Server as the user C1.ai should run as. Select your profile picture, then **My Account Settings**, and scroll to **Personal Access Tokens**. @@ -52,7 +52,7 @@ Copy the **Token Secret** immediately. Tableau shows it only once and you cannot ## Find your instance URL and site -C1 needs your Tableau instance URL and site to scope its requests. Find both while you're signed in to Tableau. +C1.ai needs your Tableau instance URL and site to scope its requests. Find both while you're signed in to Tableau. @@ -65,7 +65,7 @@ Your **site content URL** is the path segment after `/#/site/` in the browser, s ## Create a session token -Tableau's REST API uses a two-step flow: you exchange a personal access token for a short-lived session token, then send that session token on every request. The value C1 stores in the `X-Tableau-Auth` header is the **session token**, not the raw PAT. +Tableau's REST API uses a two-step flow: you exchange a personal access token for a short-lived session token, then send that session token on every request. The value C1.ai stores in the `X-Tableau-Auth` header is the **session token**, not the raw PAT. @@ -75,19 +75,19 @@ Sign in to the Tableau REST API by sending a `POST` request to `https:// -Copy the `credentials.site.id` value from the response. This is your **site LUID**, which C1 needs to scope requests to your site. +Copy the `credentials.site.id` value from the response. This is your **site LUID**, which C1.ai needs to scope requests to your site. -A session token expires after about 4 hours, or 15 days of inactivity. The PAT itself expires after 15 days of inactivity or 1 year of active use, whichever comes first. When the session token expires, sign in again to mint a new one and update it in C1. +A session token expires after about 4 hours, or 15 days of inactivity. The PAT itself expires after 15 days of inactivity or 1 year of active use, whichever comes first. When the session token expires, sign in again to mint a new one and update it in C1.ai. ## How Tableau credentials are shared -Every user's tool calls use the one session token you provided, so Tableau sees a single shared identity, scoped to the site role of the user whose PAT produced the token. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared production setup, generate the PAT from a dedicated service-account user so Tableau activity is attributable to C1 rather than a person. +Every user's tool calls use the one session token you provided, so Tableau sees a single shared identity, scoped to the site role of the user whose PAT produced the token. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared production setup, generate the PAT from a dedicated service-account user so Tableau activity is attributable to C1.ai rather than a person. For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## Register the Tableau MCP server in C1 +## Register the Tableau MCP server in C1.ai With your session token and site details ready, register the server and provide your credentials. @@ -102,13 +102,13 @@ Enter your **instance URL**, such as `https://10ay.online.tableau.com`, and your When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Custom header**, set the header name to `X-Tableau-Auth`, and paste your session token as the value. -Save your changes. C1 starts a sync that discovers the tools the Tableau server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Tableau server exposes. ## Discover and govern tools -After you register the server, C1 runs tool discovery against Tableau. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Tableau. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -120,6 +120,6 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Tableau credentials -- **Refresh the session token** by signing in to the Tableau REST API again before the token expires, then updating the `X-Tableau-Auth` value in C1. Because the session token is short-lived, plan to refresh it on a schedule. -- **Rotate the personal access token** by generating a new PAT in **My Account Settings** before the old one expires, using it to mint a fresh session token, then updating C1. Each user can have up to 10 active PATs. +- **Refresh the session token** by signing in to the Tableau REST API again before the token expires, then updating the `X-Tableau-Auth` value in C1.ai. Because the session token is short-lived, plan to refresh it on a schedule. +- **Rotate the personal access token** by generating a new PAT in **My Account Settings** before the old one expires, using it to mint a fresh session token, then updating C1.ai. Each user can have up to 10 active PATs. - **Adjust access** by changing the site role of the user whose PAT you use, or by switching to a PAT from a user with the role you need. diff --git a/product/admin/mcp-server/trello.mdx b/product/admin/mcp-server/trello.mdx index 31ef0561..69d0050c 100644 --- a/product/admin/mcp-server/trello.mdx +++ b/product/admin/mcp-server/trello.mdx @@ -1,26 +1,26 @@ --- title: Set up the Trello MCP server -description: Create a Trello API key and token, then register the Trello MCP server in C1 and govern the tools it exposes. +description: Create a Trello API key and token, then register the Trello MCP server in C1.ai and govern the tools it exposes. og:title: Set up the Trello MCP server -og:description: Create a Trello API key and token, then register the Trello MCP server in C1 and govern the tools it exposes. +og:description: Create a Trello API key and token, then register the Trello MCP server in C1.ai and govern the tools it exposes. sidebarTitle: Trello --- {/* Editor Refresh: 2026-06-11 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -The Trello MCP server lets you govern access to Trello — boards, lists, cards, members, and organizations — as tools your AI clients call through C1. +The Trello MCP server lets you govern access to Trello — boards, lists, cards, members, and organizations — as tools your AI clients call through C1.ai. Trello authenticates with an API key paired with a token. The token is authorized against a single Trello account, so all tool calls reach Trello as one shared identity. -## How C1 connects to Trello +## How C1.ai connects to Trello -C1 hosts the Trello MCP server, so your users' AI clients only ever see MCP tools — they never call Trello directly. When an AI client calls one of these tools, C1 makes the matching request to the Trello API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Trello MCP server, so your users' AI clients only ever see MCP tools — they never call Trello directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Trello API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call Trello on your users' behalf. +The credentials you set up below are what C1.ai uses to call Trello on your users' behalf. ## Before you begin @@ -28,12 +28,12 @@ The credentials you set up below are what C1 uses to call Trello on your users' - A Trello account that can create a Power-Up to obtain an API key, and that can authorize a token carrying the access you want to govern. -If you don't see **Trello** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **Trello** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Create a Trello API key and token -Create an API key and authorize a token so C1 can call Trello on your account's behalf. +Create an API key and authorize a token so C1.ai can call Trello on your account's behalf. @@ -47,15 +47,15 @@ From the same page, use the **Token** link to authorize a token for your account -For a shared production setup, authorize the token from a dedicated service-account user so activity is attributable to C1 rather than a person. +For a shared production setup, authorize the token from a dedicated service-account user so activity is attributable to C1.ai rather than a person. ## How Trello credentials are shared -Every user's tool calls use the one API key and token you provided, so Trello sees a single shared identity. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared setup, authorize the token from a dedicated service-account user so activity is attributable to C1 rather than a person. +Every user's tool calls use the one API key and token you provided, so Trello sees a single shared identity. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared setup, authorize the token from a dedicated service-account user so activity is attributable to C1.ai rather than a person. For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## Register the Trello MCP server in C1 +## Register the Trello MCP server in C1.ai With your API key and token ready, register the server and provide your credentials. @@ -67,13 +67,13 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Custom header** and enter your Trello **API key** and **token** in the fields provided. -Save your changes. C1 starts a sync that discovers the tools the Trello server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Trello server exposes. ## Discover and govern tools -After you register the server, C1 runs tool discovery against Trello. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Trello. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -85,5 +85,5 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Trello credentials -- **Rotate the token** by authorizing a new token in Trello, updating it in C1, then revoking the old token from the account's connected apps. +- **Rotate the token** by authorizing a new token in Trello, updating it in C1.ai, then revoking the old token from the account's connected apps. - **Adjust access** by authorizing the token under an account that has the boards and organizations you want to govern. diff --git a/product/admin/mcp-server/vectara.mdx b/product/admin/mcp-server/vectara.mdx index 10f6cb40..cc564e00 100644 --- a/product/admin/mcp-server/vectara.mdx +++ b/product/admin/mcp-server/vectara.mdx @@ -1,31 +1,31 @@ --- title: Set up the Vectara MCP server -description: Create a Vectara API key or OAuth app credentials, then register the Vectara MCP server in C1 and govern its tools. +description: Create a Vectara API key or OAuth app credentials, then register the Vectara MCP server in C1.ai and govern its tools. og:title: Set up the Vectara MCP server -og:description: Create a Vectara API key or OAuth app credentials, then register the Vectara MCP server in C1 and govern its tools. +og:description: Create a Vectara API key or OAuth app credentials, then register the Vectara MCP server in C1.ai and govern its tools. sidebarTitle: Vectara --- {/* Editor Refresh: 2026-06-11 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -The Vectara MCP server lets you govern access to Vectara — corpora, documents, queries, and account data — as tools your AI clients can call through C1. +The Vectara MCP server lets you govern access to Vectara — corpora, documents, queries, and account data — as tools your AI clients can call through C1.ai. Vectara supports two ways to authenticate, and you choose one when you register the server: - **API key** (recommended for most setups). A single key authenticates everyone, so all tool calls reach Vectara as one shared identity. -- **OAuth2 client credentials**. C1 exchanges an app client ID and secret for a short-lived access token. A single app authenticates everyone, so all tool calls reach Vectara as one shared identity. +- **OAuth2 client credentials**. C1.ai exchanges an app client ID and secret for a short-lived access token. A single app authenticates everyone, so all tool calls reach Vectara as one shared identity. For a deeper comparison of shared versus per-user credentials, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## How C1 connects to Vectara +## How C1.ai connects to Vectara -C1 hosts the Vectara MCP server, so your users' AI clients only ever see MCP tools — they never call Vectara directly. When an AI client calls one of these tools, C1 makes the matching request to the Vectara API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Vectara MCP server, so your users' AI clients only ever see MCP tools — they never call Vectara directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Vectara API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call Vectara on your users' behalf. +The credentials you set up below are what C1.ai uses to call Vectara on your users' behalf. ## Before you begin @@ -33,7 +33,7 @@ The credentials you set up below are what C1 uses to call Vectara on your users' - A Vectara account that can create API keys or OAuth app credentials, scoped to the corpora you want to govern. -If you don't see **Vectara** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **Vectara** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Option 1: Use an API key @@ -42,7 +42,7 @@ A Vectara API key authenticates every user as one shared identity. Use this for ### Create a Vectara API key -Create an API key in the Vectara Console to authenticate C1's requests. For more information, see Vectara's [API key management](https://docs.vectara.com/docs/security/authentication/api-key-management) documentation. +Create an API key in the Vectara Console to authenticate C1.ai's requests. For more information, see Vectara's [API key management](https://docs.vectara.com/docs/security/authentication/api-key-management) documentation. @@ -56,7 +56,7 @@ Copy the key. Vectara shows the key only once. -For a shared production setup, scope the key to only the corpora and access level you want to govern so activity is attributable to C1 rather than a person. +For a shared production setup, scope the key to only the corpora and access level you want to govern so activity is attributable to C1.ai rather than a person. ### Register the server with an API key @@ -70,7 +70,7 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Custom header**. Set the header name to `x-api-key` and the value to your Vectara API key. -Save your changes. C1 starts a sync that discovers the tools the Vectara server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Vectara server exposes. @@ -80,7 +80,7 @@ OAuth2 client credentials authenticate every user as one shared identity using a ### Create a Vectara OAuth app -Create an app client in the Vectara Console for C1 to authenticate with. For more information, see Vectara's [App Clients for OAuth](https://docs.vectara.com/docs/console-ui/app-clients) documentation. +Create an app client in the Vectara Console for C1.ai to authenticate with. For more information, see Vectara's [App Clients for OAuth](https://docs.vectara.com/docs/console-ui/app-clients) documentation. @@ -94,7 +94,7 @@ Copy the **Client ID** and **Client Secret**. Vectara shows the client secret on -For a shared production setup, scope the app to only the corpora and access level you want to govern so activity is attributable to C1 rather than a person. +For a shared production setup, scope the app to only the corpora and access level you want to govern so activity is attributable to C1.ai rather than a person. ### Register the server with OAuth2 client credentials @@ -108,7 +108,7 @@ Follow [Register an MCP server](/product/admin/mcp-servers#register-an-mcp-serve When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **OAuth2 — client credentials** and enter your app's **client ID** and **client secret**. -Save your changes. C1 starts a sync that discovers the tools the Vectara server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Vectara server exposes. @@ -119,13 +119,13 @@ Both authentication methods use one shared identity: - **API key.** Every user's tool calls use the one API key you provided, so Vectara sees a single shared identity. - **OAuth2 client credentials.** Every user's tool calls use the one app you provided, so Vectara sees a single shared identity. -With either method, C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared setup, scope the credential to a dedicated identity so activity is attributable to C1 rather than a person. +With either method, C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared setup, scope the credential to a dedicated identity so activity is attributable to C1.ai rather than a person. For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). ## Discover and govern tools -After you register the server, C1 runs tool discovery against Vectara. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Vectara. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -137,6 +137,6 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Vectara credentials -- **Rotate the API key** by creating a new key in the Vectara Console, updating it in C1, then deleting the old key. -- **Rotate the OAuth app secret** by generating a new client secret for the app in the Vectara Console and updating it in C1. +- **Rotate the API key** by creating a new key in the Vectara Console, updating it in C1.ai, then deleting the old key. +- **Rotate the OAuth app secret** by generating a new client secret for the app in the Vectara Console and updating it in C1.ai. - **Adjust access** by editing the corpora and access level on the key or app in Vectara. diff --git a/product/admin/mcp-server/wiz.mdx b/product/admin/mcp-server/wiz.mdx index c56642eb..f4eca558 100644 --- a/product/admin/mcp-server/wiz.mdx +++ b/product/admin/mcp-server/wiz.mdx @@ -1,26 +1,26 @@ --- title: Set up the Wiz MCP server -description: Create a Wiz service account, then register the Wiz MCP server in C1 and govern the tools your AI clients can call. +description: Create a Wiz service account, then register the Wiz MCP server in C1.ai and govern the tools your AI clients can call. og:title: Set up the Wiz MCP server -og:description: Create a Wiz service account, then register the Wiz MCP server in C1 and govern the tools your AI clients can call. +og:description: Create a Wiz service account, then register the Wiz MCP server in C1.ai and govern the tools your AI clients can call. sidebarTitle: Wiz --- {/* Editor Refresh: 2026-06-11 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -The Wiz MCP server lets you govern access to the Wiz cloud security platform — issues, vulnerabilities, cloud resources, and other data exposed by the Wiz GraphQL API — as tools your AI clients can call through C1. +The Wiz MCP server lets you govern access to the Wiz cloud security platform — issues, vulnerabilities, cloud resources, and other data exposed by the Wiz GraphQL API — as tools your AI clients can call through C1.ai. Wiz authenticates with a service account using the OAuth2 client credentials flow. The service account's client ID and client secret authenticate every user, so all tool calls reach Wiz as one shared identity. -## How C1 connects to Wiz +## How C1.ai connects to Wiz -C1 hosts the Wiz MCP server, so your users' AI clients only ever see MCP tools — they never call Wiz directly. When an AI client calls one of these tools, C1 makes the matching request to the Wiz API using the credentials you configure here, then returns the result to the AI client. +C1.ai hosts the Wiz MCP server, so your users' AI clients only ever see MCP tools — they never call Wiz directly. When an AI client calls one of these tools, C1.ai makes the matching request to the Wiz API using the credentials you configure here, then returns the result to the AI client. -The credentials you set up below are what C1 uses to call Wiz on your users' behalf. +The credentials you set up below are what C1.ai uses to call Wiz on your users' behalf. ## Before you begin @@ -29,12 +29,12 @@ The credentials you set up below are what C1 uses to call Wiz on your users' beh - Your regional Wiz API endpoint, such as `https://api.us1.app.wiz.io`. -If you don't see **Wiz** in your MCP server catalog, [contact the C1 support team](mailto:support@c1.ai) to enable it for your tenant. +If you don't see **Wiz** in your MCP server catalog, [contact the C1.ai support team](mailto:support@c1.ai) to enable it for your tenant. ## Create a Wiz service account -Wiz issues a client ID and client secret to a service account, which C1 exchanges for an access token using the client credentials flow. +Wiz issues a client ID and client secret to a service account, which C1.ai exchanges for an access token using the client credentials flow. @@ -49,15 +49,15 @@ Copy the **Client ID** and **Client Secret**. Wiz shows the secret only once. -For a shared production setup, use a dedicated service account so activity is attributable to C1 rather than a person. +For a shared production setup, use a dedicated service account so activity is attributable to C1.ai rather than a person. ## How Wiz credentials are shared -The service account authenticates every user as one shared Wiz identity, so Wiz sees a single identity for all tool calls. C1 still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared setup, use a dedicated service account so activity is attributable to C1 rather than a person. +The service account authenticates every user as one shared Wiz identity, so Wiz sees a single identity for all tool calls. C1.ai still attributes each call to the individual user in the [AI tool usage audit log](/product/admin/audit-ai-tool-usage). For a shared setup, use a dedicated service account so activity is attributable to C1.ai rather than a person. For how shared and per-user credentials work across MCP servers, see [Configure authentication](/product/admin/mcp-servers#configure-authentication). -## Register the Wiz MCP server in C1 +## Register the Wiz MCP server in C1.ai With your service account credentials ready, register the server and provide them. @@ -72,13 +72,13 @@ Enter your regional Wiz API endpoint, such as `https://api.us1.app.wiz.io`. When you [configure authentication](/product/admin/mcp-servers#configure-authentication), choose **Client credentials** and enter the service account's **client ID** and **client secret**. -Save your changes. C1 starts a sync that discovers the tools the Wiz server exposes. +Save your changes. C1.ai starts a sync that discovers the tools the Wiz server exposes. ## Discover and govern tools -After you register the server, C1 runs tool discovery against Wiz. Discovered tools appear on the server's **Tools** tab. +After you register the server, C1.ai runs tool discovery against Wiz. Discovered tools appear on the server's **Tools** tab. Each tool starts as either **Pending review** or automatically **Approved**, depending on the option chosen when the server was set up or your tenant's default tool settings in **AI** > **MCPs** > **Settings**. See [Require tool approval](/product/admin/enable-ai-access-management#require-tool-approval) and [Default tool classification](/product/admin/enable-ai-access-management#default-tool-classification). @@ -90,5 +90,5 @@ Tool discovery runs even if your credentials are incorrect, so seeing discovered ## Manage your Wiz credentials -- **Rotate the client secret** by rotating the service account's secret in Wiz, then update the secret on the server's authentication settings in C1. +- **Rotate the client secret** by rotating the service account's secret in Wiz, then update the secret on the server's authentication settings in C1.ai. - **Adjust access** by editing the scopes granted to the service account in Wiz. diff --git a/product/admin/mcp-servers.mdx b/product/admin/mcp-servers.mdx index a0c4ce55..9fd5d608 100644 --- a/product/admin/mcp-servers.mdx +++ b/product/admin/mcp-servers.mdx @@ -1,31 +1,31 @@ --- title: Set up an MCP server -description: Register an MCP server with C1, link it to a C1 application, and configure authentication so C1 can govern access to its tools and resources. -og:title: Set up an MCP server - C1 docs -og:description: Register an MCP server with C1, link it to a C1 application, and configure authentication so C1 can govern access to its tools and resources. +description: Register an MCP server with C1.ai, link it to a C1.ai application, and configure authentication so C1.ai can govern access to its tools and resources. +og:title: Set up an MCP server - C1.ai docs +og:description: Register an MCP server with C1.ai, link it to a C1.ai application, and configure authentication so C1.ai can govern access to its tools and resources. --- {/* Editor Refresh: 2026-05-29 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -This page walks through registering an MCP server with C1, linking it to a C1 application, and configuring authentication. Once registered, C1 discovers the tools and resources the server exposes. See [Govern tools and toolsets](/product/admin/tools-and-toolsets) and [Govern MCP resources](/product/admin/mcp-resources) for what to do next. +This page walks through registering an MCP server with C1.ai, linking it to a C1.ai application, and configuring authentication. Once registered, C1.ai discovers the tools and resources the server exposes. See [Govern tools and toolsets](/product/admin/tools-and-toolsets) and [Govern MCP resources](/product/admin/mcp-resources) for what to do next. ## Before you begin - AIAM must be enabled for the tenant. See [Enable AI access management](/product/admin/enable-ai-access-management). -- For OAuth-based auth, you'll need a client ID and secret from the downstream service — unless the server supports OAuth Dynamic Client Registration (DCR), in which case C1 registers itself automatically and no credentials are required. -- For per-user OAuth, the downstream service must be reachable by C1's hosted callback URL. +- For OAuth-based auth, you'll need a client ID and secret from the downstream service — unless the server supports OAuth Dynamic Client Registration (DCR), in which case C1.ai registers itself automatically and no credentials are required. +- For per-user OAuth, the downstream service must be reachable by C1.ai's hosted callback URL. ## Register an MCP server -C1 walks you through registering an MCP server one question at a time, whether you start from the catalog or from a custom URL: +C1.ai walks you through registering an MCP server one question at a time, whether you start from the catalog or from a custom URL: -In C1, go to **AI > MCPs** and click **Connect MCP server**. +In C1.ai, go to **AI > MCPs** and click **Connect MCP server**. Choose the server from the catalog shortlist (or browse the full catalog grid), or enter a custom URL. @@ -34,10 +34,10 @@ Choose the server from the catalog shortlist (or browse the full catalog grid), Answer the setup questions as they appear: where the server is hosted (public or through a bridge), the server URL, who should be able to use it and when, and what happens to newly discovered tools. -Confirm authentication. C1 probes the server's OAuth configuration automatically — a self-registering (DCR) server asks nothing further here. Otherwise, choose an auth method; see [Configure authentication](#configure-authentication) for what each one needs. +Confirm authentication. C1.ai probes the server's OAuth configuration automatically — a self-registering (DCR) server asks nothing further here. Otherwise, choose an auth method; see [Configure authentication](#configure-authentication) for what each one needs. -Review and submit. C1 registers the server and runs initial discovery. +Review and submit. C1.ai registers the server and runs initial discovery. @@ -53,7 +53,7 @@ The server's URL can't be changed once it completes its first successful sync. T ## Configure authentication -C1 supports multiple auth methods for downstream MCP servers. Admins can select any supported method when configuring a server. +C1.ai supports multiple auth methods for downstream MCP servers. Admins can select any supported method when configuring a server. | Method | Who the downstream sees | When to use | | :--- | :--- | :--- | @@ -65,7 +65,7 @@ C1 supports multiple auth methods for downstream MCP servers. Admins can select | **OAuth2 — per-user passthrough** | Each end user, with their own credentials | When the downstream needs per-user identity (Google Workspace, GitHub, Salesforce, and so on) | | **JWT Bearer (RFC 7523)** | A service identity via signed JWT | Services that support certificate-based or JWT-based auth (for example, Tableau or Google service accounts) | -For per-user OAuth passthrough, C1 vaults each user's downstream tokens and auto-refreshes them so end users don't hit token expiry mid-session. +For per-user OAuth passthrough, C1.ai vaults each user's downstream tokens and auto-refreshes them so end users don't hit token expiry mid-session. To configure auth: @@ -79,7 +79,7 @@ Select the auth method. Enter the required credentials for the selected method: -- **Bearer token** — paste the token. C1 vaults it. +- **Bearer token** — paste the token. C1.ai vaults it. - **Custom header** — enter the header name and value. - **Basic auth** — choose a credential mode: - **Shared (admin authorizes)**: Enter a username and password once. All users connect using the same credentials. @@ -89,12 +89,12 @@ Enter the required credentials for the selected method: - **Per-user passthrough** — enter client ID, client secret, authorization URL, token URL, and scopes. End users see a Connect prompt the first time their AI client calls a tool from this server. - **JWT bearer** — enter the issuer, private key, subject, audience, token URL, and scopes. -If the server supports OAuth Dynamic Client Registration (DCR), you can skip entering a client ID and secret entirely. Toggle on **Use dynamic client registration** — C1 registers itself with the server's authorization server automatically. +If the server supports OAuth Dynamic Client Registration (DCR), you can skip entering a client ID and secret entirely. Toggle on **Use dynamic client registration** — C1.ai registers itself with the server's authorization server automatically. -Before registering, C1 runs a discovery check against the server's authorization server. If discovery finds an issue that can be relaxed — such as an issuer mismatch or an authorization server on a different host — C1 shows you the finding and asks you to acknowledge it before registration continues. Findings that can't be safely relaxed block registration entirely. +Before registering, C1.ai runs a discovery check against the server's authorization server. If discovery finds an issue that can be relaxed — such as an issuer mismatch or an authorization server on a different host — C1.ai shows you the finding and asks you to acknowledge it before registration continues. Findings that can't be safely relaxed block registration entirely. -Click **Save**. C1 makes a test call to validate the credentials. +Click **Save**. C1.ai makes a test call to validate the credentials. @@ -104,13 +104,13 @@ Click **Save**. C1 makes a test call to validate the credentials. | :--- | :--- | :--- | | **Authentication** | Required | See above | | **Data sensitivity** | Optional | Metadata tag on the server (low / medium / high). Surfaces in the catalog and audit log; no enforcement | -| **Tool prefix** | Optional; required if multiple servers under one app | Prepended to tool names so AI clients can disambiguate (for example, `gh_` vs `gl_` for two Git providers). If you don't set one, C1 uses the prefix the server's own implementation declares; if it doesn't declare one, C1 generates a default. | +| **Tool prefix** | Optional; required if multiple servers under one app | Prepended to tool names so AI clients can disambiguate (for example, `gh_` vs `gl_` for two Git providers). If you don't set one, C1.ai uses the prefix the server's own implementation declares; if it doesn't declare one, C1.ai generates a default. | | **Tool enablement** | Optional | Choose **Require enablement** or **Auto-enable** for this server's tools, independent of your tenant's [default tool approval setting](/product/admin/enable-ai-access-management#require-tool-approval). Leave unset to inherit the tenant default. | ## What happens after registration -- C1 runs an initial **tool and resource discovery** sweep against the server. Discovered tools appear under the **Tools** tab with state **Pending Review** by default. Discovered resources and URI templates appear on the **Resources** tab with state **Pending**. -- C1 re-runs discovery on a schedule. New tools and resources need review. Tools that disappear are flagged but not auto-deleted. Resources that disappear are marked **Removed** and cannot be read. +- C1.ai runs an initial **tool and resource discovery** sweep against the server. Discovered tools appear under the **Tools** tab with state **Pending Review** by default. Discovered resources and URI templates appear on the **Resources** tab with state **Pending**. +- C1.ai re-runs discovery on a schedule. New tools and resources need review. Tools that disappear are flagged but not auto-deleted. Resources that disappear are marked **Removed** and cannot be read. - No tool from this server is callable by any end user yet — see [Govern tools and toolsets](/product/admin/tools-and-toolsets) to approve, classify, and bundle them. A resource also needs approval and a user grant before it can be read. See [Govern MCP resources](/product/admin/mcp-resources). {/* diff --git a/product/admin/ms-teams-public.mdx b/product/admin/ms-teams-public.mdx index 54107006..58006325 100644 --- a/product/admin/ms-teams-public.mdx +++ b/product/admin/ms-teams-public.mdx @@ -1,19 +1,19 @@ --- -title: Interact with C1 via Microsoft Teams -og:title: Interact with C1 via Microsoft Teams - C1 docs -og:description: Use the C1 Microsoft Teams app to get notifications and accomplish tasks. -description: Use the C1 Microsoft Teams app to get notifications and accomplish tasks. +title: Interact with C1.ai via Microsoft Teams +og:title: Interact with C1.ai via Microsoft Teams - C1.ai docs +og:description: Use the C1.ai Microsoft Teams app to get notifications and accomplish tasks. +description: Use the C1.ai Microsoft Teams app to get notifications and accomplish tasks. sidebarTitle: "Microsoft Teams" --- {/* Editor Refresh: 2026-01-07 */} -Microsoft Teams as a C1 notification and interaction surface is not yet supported on the EU data residency instance. +Microsoft Teams as a C1.ai notification and interaction surface is not yet supported on the EU data residency instance. -## What can I do with the C1 Microsoft Teams app? +## What can I do with the C1.ai Microsoft Teams app? -Use C1's Microsoft Teams app to interact directly with C1 without leaving Microsoft Teams. Once the C1 Microsoft Teams app is installed for your workspace, you and your colleagues can: +Use C1.ai's Microsoft Teams app to interact directly with C1.ai without leaving Microsoft Teams. Once the C1.ai Microsoft Teams app is installed for your workspace, you and your colleagues can: - Track your open requests for access and get notified about progress - Get notified when an open access request needs your approval @@ -24,33 +24,33 @@ Use C1's Microsoft Teams app to interact directly with C1 without leaving Micros **Have a question? Need a hand?** -[Contact our support team](mailto:support@c1.ai) for assistance with the C1 Teams app. +[Contact our support team](mailto:support@c1.ai) for assistance with the C1.ai Teams app. -## Set up the C1 MS Teams app for your organization +## Set up the C1.ai MS Teams app for your organization -This task requires the **Admin** role in the Microsoft directory you're connecting and the **Super Administrator** role in C1. +This task requires the **Admin** role in the Microsoft directory you're connecting and the **Super Administrator** role in C1.ai. -### Step 1: Install the C1 app +### Step 1: Install the C1.ai app -In the Microsoft Teams app marketplace, navigate to the [C1 app](https://marketplace.microsoft.com/en-us/product/office/WA200009797) or search for "C1" and download the app. +In the Microsoft Teams app marketplace, navigate to the [C1.ai app](https://marketplace.microsoft.com/en-us/product/office/WA200009797) or search for "C1.ai" and download the app. #### Optional: Add the app to a Teams policy -If desired, you can add the C1 app to your organization's Teams interface by adding the app to a policy. +If desired, you can add the C1.ai app to your organization's Teams interface by adding the app to a policy. In the Microsoft Teams admin center, navigate to **Teams apps** > **Manage apps**. -Search for the "C1" app in your app catalog. +Search for the "C1.ai" app in your app catalog. Navigate to **Teams apps** > **Setup policies**. @@ -60,37 +60,37 @@ On the **Manage policies** tab, click the **Global (Org-wide default)** policy.< If desired, you can create and use a custom policy here instead of the global policy. -On the policy's page, click **Add apps** and search for "C1". +On the policy's page, click **Add apps** and search for "C1.ai". -Click **Select**, then click **Add** to add the C1 app to the policy. +Click **Select**, then click **Add** to add the C1.ai app to the policy. -**Optional.** Add the C1 app to the list of apps pinned to your organization's Teams sidebar. +**Optional.** Add the C1.ai app to the list of apps pinned to your organization's Teams sidebar. -### Step 2: Connect the C1 Microsoft Teams app +### Step 2: Connect the C1.ai Microsoft Teams app -Next, connect the C1 app for use in your organization's Microsoft Teams directory. +Next, connect the C1.ai app for use in your organization's Microsoft Teams directory. -In C1, navigate to **Settings** > **Notifications**. +In C1.ai, navigate to **Settings** > **Notifications**. In the **Microsoft Teams** section of the page, click **Connect**. -You'll be directed to Microsoft Teams. Follow the prompts and review the permissions in Microsoft that the C1 app requires: +You'll be directed to Microsoft Teams. Follow the prompts and review the permissions in Microsoft that the C1.ai app requires: - Organization.Read.All - used to fetch the tenant hostname - User.Read.All - used to look up Teams users by email -**Done.** You'll be directed back to the C1 **Settings** page, where you'll see that your Microsoft Teams directory is now connected. +**Done.** You'll be directed back to the C1.ai **Settings** page, where you'll see that your Microsoft Teams directory is now connected. **Need to connect to additional Teams directories?** @@ -98,37 +98,37 @@ You'll be directed to Microsoft Teams. Follow the prompts and review the permiss No problem. Sign in to Microsoft Teams as an admin on the directory you want to connect and repeat the steps above. -## Set up the C1 MS Teams app on an individual workstation +## Set up the C1.ai MS Teams app on an individual workstation -If a Teams admin at your organization has not automatically added the C1 app to your organization's Teams interface, you can set it up on your workstation yourself. Here's what to do: +If a Teams admin at your organization has not automatically added the C1.ai app to your organization's Teams interface, you can set it up on your workstation yourself. Here's what to do: -In the Microsoft Teams app marketplace, navigate to the [C1 app](https://marketplace.microsoft.com/en-us/product/office/WA200009797) or search for "C1" and download the app. +In the Microsoft Teams app marketplace, navigate to the [C1.ai app](https://marketplace.microsoft.com/en-us/product/office/WA200009797) or search for "C1.ai" and download the app. If the app isn't available, check with an admin to ensure that they've completed the installation steps above. If the app is available but you receive an error asking you to contact an admin, ensure they've completed the configuration process above. -**Done.** You're set up and ready to work with C1 from the comfort of your Teams interface. +**Done.** You're set up and ready to work with C1.ai from the comfort of your Teams interface. -## Disconnect the C1 MS Teams app +## Disconnect the C1.ai MS Teams app -Fully disconnecting the C1 integration and removing the app is a two-step process. +Fully disconnecting the C1.ai integration and removing the app is a two-step process. -### Step 1: Disconnect from C1 +### Step 1: Disconnect from C1.ai -In C1, navigate to **Settings** > **Notifications**. +In C1.ai, navigate to **Settings** > **Notifications**. In the **Microsoft Teams** section of the page, find the Teams directory you want to disconnect and click **Remove**. -The integration between your C1 tenant and your Teams directory is now severed. +The integration between your C1.ai tenant and your Teams directory is now severed. ### Step 2: Remove the Enterprise Application from Entra ID @@ -144,14 +144,14 @@ Log into the Entra ID Admin Center. Navigate to **Enterprise Applications** > **All applications**. -Find and select the "C1" app. +Find and select the "C1.ai" app. Click **Properties**, then select **Delete** and confirm your choice. -**Done.** The app is removed from your Entra ID instance, and its Organization.Read.All and User.Read.All permissions have been fully disconnected from your C1 tenant. +**Done.** The app is removed from your Entra ID instance, and its Organization.Read.All and User.Read.All permissions have been fully disconnected from your C1.ai tenant. diff --git a/product/admin/nhi.mdx b/product/admin/nhi.mdx index b1637bdd..497b9c90 100644 --- a/product/admin/nhi.mdx +++ b/product/admin/nhi.mdx @@ -1,14 +1,14 @@ --- title: "Non-human identities (NHI)" og:title: "Non-human identities (NHI)" -og:description: "See how C1 classifies and surfaces non-human identities across your connected sources." -description: "See how C1 classifies and surfaces non-human identities across your connected sources." +og:description: "See how C1.ai classifies and surfaces non-human identities across your connected sources." +description: "See how C1.ai classifies and surfaces non-human identities across your connected sources." sidebarTitle: "Non-human identities" --- {/* Editor Refresh: 2026-09-02 */} -The **Identities overview** dashboard gives you one place to see every identity C1 discovers across your connected sources — human and non-human alike — including a dedicated view for non-human identities (NHIs). +The **Identities overview** dashboard gives you one place to see every identity C1.ai discovers across your connected sources — human and non-human alike — including a dedicated view for non-human identities (NHIs). **NHI capabilities are under active development.** Classification, ownership, and policy support for non-human identities will keep expanding: follow the [release notes](/product/release-notes) for updates. @@ -16,17 +16,17 @@ The **Identities overview** dashboard gives you one place to see every identity ## What counts as an NHI -In C1, a non-human identity (NHI) is a resource classified as one of the following: +In C1.ai, a non-human identity (NHI) is a resource classified as one of the following: - **App registration** — for example, an Entra enterprise app, OAuth app, GitHub App, or Databricks service principal. - **Assumable role** — for example, an AWS IAM role or GCP workload identity. - **Managed identity** -Service accounts, secrets, and agents are related but separate categories that C1 tracks on the same dashboard — see [Find identities across your environment](#find-identities-across-your-environment) below. They aren't classified as NHIs. +Service accounts, secrets, and agents are related but separate categories that C1.ai tracks on the same dashboard — see [Find identities across your environment](#find-identities-across-your-environment) below. They aren't classified as NHIs. ## Find identities across your environment -Navigate to **Identities** > **Overview** to view the dashboard. It has a tab for each identity category C1 tracks — **Human users**, **Service**, **Secrets**, **Agents** — plus a dedicated **NHI** tab scoped to the app registrations, assumable roles, and managed identities described above. +Navigate to **Identities** > **Overview** to view the dashboard. It has a tab for each identity category C1.ai tracks — **Human users**, **Service**, **Secrets**, **Agents** — plus a dedicated **NHI** tab scoped to the app registrations, assumable roles, and managed identities described above. The Identities overview dashboard's NHI tab, listing app registrations and assumable roles grouped by connected app, with columns for owner, type, subtype, and findings. diff --git a/product/admin/notifications-tenant-settings.mdx b/product/admin/notifications-tenant-settings.mdx index 9bccf049..a94b4d89 100644 --- a/product/admin/notifications-tenant-settings.mdx +++ b/product/admin/notifications-tenant-settings.mdx @@ -1,6 +1,6 @@ --- title: Tenant notification settings -og:title: Tenant notification settings - C1 docs +og:title: Tenant notification settings - C1.ai docs og:description: Configure organization-wide notification policies, default preferences, and whether users can customize their own notification settings. description: Configure organization-wide notification policies, default preferences, and whether users can customize their own notification settings. sidebarTitle: Tenant-wide settings @@ -15,7 +15,7 @@ This page covers organization-wide notification settings that can be controlled Once Slack or Microsoft Teams is configured for your organization, that delivery channel's column appears in the notification settings table and as a digest option. You can then use the bulk checkboxes and lock icons to manage those channels the same way as email. -- To set up Slack, see [Set up the C1 app for Slack](/product/admin/integration-for-Slack). +- To set up Slack, see [Set up the C1.ai app for Slack](/product/admin/integration-for-Slack). - To set up Microsoft Teams, see [Set up the Microsoft Teams app](/product/admin/ms-teams-public). ## Update organization-wide notification settings @@ -63,19 +63,19 @@ Click **Save** to apply your changes. -## Update C1 digest defaults +## Update C1.ai digest defaults -Set the default digest delivery preferences for your organization. Digest notifications contain a summary of C1 tasks requiring attention and are only sent when a user has at least one pending task or expiring access item. +Set the default digest delivery preferences for your organization. Digest notifications contain a summary of C1.ai tasks requiring attention and are only sent when a user has at least one pending task or expiring access item. Navigate to **Settings** > **Notifications**. -In the **C1 digest** area of the page, click **Edit**. +In the **C1.ai digest** area of the page, click **Edit**. -If necessary, click the toggle to enable **Send C1 digest**. +If necessary, click the toggle to enable **Send C1.ai digest**. Choose the default digest frequency: diff --git a/product/admin/notifications-user-settings.mdx b/product/admin/notifications-user-settings.mdx index 8a2bb9f0..8a075038 100644 --- a/product/admin/notifications-user-settings.mdx +++ b/product/admin/notifications-user-settings.mdx @@ -1,6 +1,6 @@ --- title: How to configure your notification settings -og:title: Your notification settings - C1 docs +og:title: Your notification settings - C1.ai docs og:description: View and customize your notification preferences for email, Slack, and Microsoft Teams. description: View and customize your notification preferences for email, Slack, and Microsoft Teams. sidebarTitle: How to configure your notifications @@ -17,13 +17,13 @@ To view your current notification settings and make updates: -In C1, click your profile icon at the bottom left of the screen and select **Notification settings**. +In C1.ai, click your profile icon at the bottom left of the screen and select **Notification settings**. In the **Notifications** area of the page, click **Edit**. -Adjust your notification preferences and delivery methods, as needed. If a setting is locked by your organizations' C1 admins and cannot be changed, the checkbox will be disabled. +Adjust your notification preferences and delivery methods, as needed. If a setting is locked by your organizations' C1.ai admins and cannot be changed, the checkbox will be disabled. Click **Save** to apply your changes. @@ -37,23 +37,23 @@ Your available personal notification settings are based on defaults configured b - **Unlocked settings**: You can customize these preferences to match your needs. - **Locked settings** (disabled checkbox): These are set by your admin and cannot be changed. -If a setting you need to adjust is locked, contact your C1 admin to request a change. +If a setting you need to adjust is locked, contact your C1.ai admin to request a change. -## Update your C1 digest delivery preferences +## Update your C1.ai digest delivery preferences -Sign up to receive digest notifications on a daily or weekly cadence. Digests contain a summary of the C1 tasks requiring your attention. +Sign up to receive digest notifications on a daily or weekly cadence. Digests contain a summary of the C1.ai tasks requiring your attention. Digest notifications are only sent if you have at least one pending task or expiring access item. If you have nothing requiring attention, no digest is sent. -In C1, click your profile icon at the bottom left of the screen and select **Notification settings**. +In C1.ai, click your profile icon at the bottom left of the screen and select **Notification settings**. -In the **C1 digest** area of the page, click **Edit**. +In the **C1.ai digest** area of the page, click **Edit**. -If necessary, click the toggle to enable **Send C1 digest**. +If necessary, click the toggle to enable **Send C1.ai digest**. Choose how often you'll receive digests: @@ -71,7 +71,7 @@ Click **Save** to apply your changes. ## Make your notifications work for you -Here are some tips to help you get the most value out of your C1 notifications: +Here are some tips to help you get the most value out of your C1.ai notifications: - **Choose an appropriate frequency**: Select daily digests if you handle time-sensitive approvals. Weekly digests work well for periodic access reviews. - **Enable multiple channels**: Enable Slack or Teams for real-time notifications while keeping email enabled for a permanent record. diff --git a/product/admin/object-annotations.mdx b/product/admin/object-annotations.mdx index b14d9785..e029ec9c 100644 --- a/product/admin/object-annotations.mdx +++ b/product/admin/object-annotations.mdx @@ -1,14 +1,14 @@ --- title: "Object annotations" -og:title: "Object annotations - C1 docs" -description: "Attach custom key/value metadata to C1 objects to track cost centers, compliance scope, ownership, and IaC management state." -og:description: "Attach custom key/value metadata to C1 objects to track cost centers, compliance scope, ownership, and IaC management state." +og:title: "Object annotations - C1.ai docs" +description: "Attach custom key/value metadata to C1.ai objects to track cost centers, compliance scope, ownership, and IaC management state." +og:description: "Attach custom key/value metadata to C1.ai objects to track cost centers, compliance scope, ownership, and IaC management state." sidebarTitle: "Annotations" --- {/* Editor Refresh: 2026-05-15 */} -Annotations let you attach custom key/value metadata to C1 objects. Use them to record cost centers, compliance scope, ownership, or to mark which objects an infrastructure-as-code (IaC) tool — such as Terraform, OpenTofu, or Pulumi — is responsible for managing. +Annotations let you attach custom key/value metadata to C1.ai objects. Use them to record cost centers, compliance scope, ownership, or to mark which objects an infrastructure-as-code (IaC) tool — such as Terraform, OpenTofu, or Pulumi — is responsible for managing. Annotations are stored on the object, returned on every read, and fully tracked in object history. @@ -26,7 +26,7 @@ Annotations are stored on the object, returned on every read, and fully tracked ## Add and edit annotations -### In the C1 UI +### In the C1.ai UI On any supported object's detail page, an **Annotations** row appears in the header with a pencil icon. Click the pencil to open the **Edit annotations** drawer. @@ -84,12 +84,12 @@ acme.com/audit-cycle = quarterly - **Cost reporting** — tag apps and access profiles with a cost center; annotations are returned on every API read, so you can query them or export to an ops dashboard - **Compliance scope** — tag entitlements and access profiles with framework values like `soc2`, `hipaa`, or `pci` -- **Ownership** — record an owner for objects where no C1 user maps cleanly +- **Ownership** — record an owner for objects where no C1.ai user maps cleanly - **Audit cadence** — tag access review templates with `quarterly`, `annual`, or `ad-hoc` ## IaC management labels -A set of reserved keys mark an object as managed by an IaC tool. The C1 Terraform provider sets them automatically; you can also set them manually for other tools. +A set of reserved keys mark an object as managed by an IaC tool. The C1.ai Terraform provider sets them automatically; you can also set them manually for other tools. | Key | What it means | Set by the Terraform provider? | | :--- | :--- | :--- | @@ -106,12 +106,12 @@ When these keys are present, the object's detail page shows a **Managed by [tool ### Take ownership -When you edit any field on an IaC-managed object in the C1 UI — other than the annotations themselves — C1 clears the IaC keys in the same operation and shows a confirmation toast. This signals that C1, not your IaC tool, now manages the object. +When you edit any field on an IaC-managed object in the C1.ai UI — other than the annotations themselves — C1.ai clears the IaC keys in the same operation and shows a confirmation toast. This signals that C1.ai, not your IaC tool, now manages the object. Editing annotations directly, or editing the object via the API or `c1i`, does not trigger this transfer — the IaC keys are left in place. -If your IaC tool runs `terraform apply` after you take ownership in the C1 UI, it will attempt to reconcile the object back to the state in your configuration. To avoid overwriting your change, remove the resource from your IaC configuration or run `terraform state rm` on it. +If your IaC tool runs `terraform apply` after you take ownership in the C1.ai UI, it will attempt to reconcile the object back to the state in your configuration. To avoid overwriting your change, remove the resource from your IaC configuration or run `terraform state rm` on it. ## Use annotations in policy and automation logic diff --git a/product/admin/organization-contacts.mdx b/product/admin/organization-contacts.mdx index 157c8e88..2b8a92a9 100644 --- a/product/admin/organization-contacts.mdx +++ b/product/admin/organization-contacts.mdx @@ -1,6 +1,6 @@ --- title: Organization contacts -og:title: Organization contacts - C1 docs +og:title: Organization contacts - C1.ai docs og:description: Store and manage contact email addresses for your organization's security, billing, and operations teams. description: Store and manage contact email addresses for your organization's security, billing, and operations teams. --- @@ -11,7 +11,7 @@ Organization contacts let you store email addresses for your organization's secu ## Manage organization contacts -Managing organization contacts requires the **Super Administrator** role in C1. Other users can view the configured lists but cannot make changes. +Managing organization contacts requires the **Super Administrator** role in C1.ai. Other users can view the configured lists but cannot make changes. diff --git a/product/admin/policies.mdx b/product/admin/policies.mdx index 78f1641b..f57ed725 100644 --- a/product/admin/policies.mdx +++ b/product/admin/policies.mdx @@ -1,6 +1,6 @@ --- title: Policies -og:title: Policies - C1 docs +og:title: Policies - C1.ai docs og:description: Policies are re-usable bundles of instructions for how access will be requested, reviewed, and revoked. description: Policies are re-usable bundles of instructions for how access will be requested, reviewed, and revoked. --- @@ -10,7 +10,7 @@ description: Policies are re-usable bundles of instructions for how access will Policies are reusable rule sets that define a process for requesting, reviewing, or revoking access. Policies are **extremely** powerful, as they allow you to bundle similar processes into a single policy that can be reused across applications, resources, and entitlements. -Here are just a few examples of the many kinds of policies that can be created in C1: +Here are just a few examples of the many kinds of policies that can be created in C1.ai: | Policy name | Policy type | What it does | Used for | | :---------- | :---------- | :----------- | :-------- | @@ -19,11 +19,11 @@ Here are just a few examples of the many kinds of policies that can be created i | App Owner Certification | Review | Routes access reviews to application owners | Finance apps | | Leaver Confirmation | Revoke | Routes role "leaver" changes to the user's manager to confirm before removing or changing access | All leaver changes | -By default, all C1 tenants are created with a set of built-in **best practice** policies. If these policies don't meet your needs, you can create as many custom policies as you require. +By default, all C1.ai tenants are created with a set of built-in **best practice** policies. If these policies don't meet your needs, you can create as many custom policies as you require. ### Policy types -There are three policy types in C1: +There are three policy types in C1.ai: - **Request**: Used for granting access to roles, apps, resources, and entitlements - **Review**: Used to define access review workflows @@ -42,7 +42,7 @@ Rules allow for configuring pre-approvals or complex rule logic based on an exte ### The baseline rule -Each policy starts with a "baseline" rule. You can add up to 16 additional rules. The baseline rule sets the action to be taken if no other rules are present or if no other rules match. C1 reads policies from top to bottom, taking action as soon as it finds a matching condition. When forming your conditional policy, make sure you organize the rules you create from most to least specific. +Each policy starts with a "baseline" rule. You can add up to 16 additional rules. The baseline rule sets the action to be taken if no other rules are present or if no other rules match. C1.ai reads policies from top to bottom, taking action as soon as it finds a matching condition. When forming your conditional policy, make sure you organize the rules you create from most to least specific. Here's an example. This request policy has three rules plus a baseline: @@ -78,7 +78,7 @@ On the **Policies** page, click **Create with Policy assistant** to get started ## Create a new policy -C1 provides built-in policies to get you started. You can view these and any other policies currently saved in your C1 instance on the **Policies** page. +C1.ai provides built-in policies to get you started. You can view these and any other policies currently saved in your C1.ai instance on the **Policies** page. If the existing policies don't match the workflow you need, you can edit them or create a whole new policy. For built-in policies like **App Owner Approval**, you can also edit the post actions — the follow-up steps that run after the policy completes — directly from the policy's detail page in the UI. @@ -200,25 +200,25 @@ If needed, click **Add step** to add either another wait condition check or a re 1. Select a reviewer: - - **User:** C1 will assign the task to the specific individual or individuals who you select as reviewers. + - **User:** C1.ai will assign the task to the specific individual or individuals who you select as reviewers. - - **Group:** C1 will assign the task to the members of the selected group. Only one member needs to complete the task, but all members will be notified. If there are more then 128 members in the selected group, the task will not notify the group's members, but will instead use the fallback reviewer. + - **Group:** C1.ai will assign the task to the members of the selected group. Only one member needs to complete the task, but all members will be notified. If there are more then 128 members in the selected group, the task will not notify the group's members, but will instead use the fallback reviewer. - - **Manager:** C1 will identify the user's manager (via the information pulled from your company's identity provider) and assign them the task. + - **Manager:** C1.ai will identify the user's manager (via the information pulled from your company's identity provider) and assign them the task. - - **Account owner:** The task will be assigned to the user identified as the owner of the application account in C1. In almost all cases, selecting this option results in a self-review of the access. + - **Account owner:** The task will be assigned to the user identified as the owner of the application account in C1.ai. In almost all cases, selecting this option results in a self-review of the access. - - **App owner:** The task will be assigned to the owner or owners set for the application in C1. + - **App owner:** The task will be assigned to the owner or owners set for the application in C1.ai. - - **Entitlement owner:** The task will be assigned to the owner or owners set for the entitlement in C1. + - **Entitlement owner:** The task will be assigned to the owner or owners set for the entitlement in C1.ai. - - **Resource owner:** The task will be assigned to the owner or owners set for the resource in C1. + - **Resource owner:** The task will be assigned to the owner or owners set for the resource in C1.ai. - - **Expression:** C1 will evaluate the Common Expression Language (CEL) expression you enter here and assign the task to the returned user or users. See [Write conditional policy rules](/product/admin/expressions) for examples and more instructions. + - **Expression:** C1.ai will evaluate the Common Expression Language (CEL) expression you enter here and assign the task to the returned user or users. See [Write conditional policy rules](/product/admin/expressions) for examples and more instructions. - - **Webhook:** C1 will fire a synchronous webhook which can be used to drive notifications or change the policy steps. See [Webhooks](/product/admin/webhooks) for instructions on setting up webhooks. + - **Webhook:** C1.ai will fire a synchronous webhook which can be used to drive notifications or change the policy steps. See [Webhooks](/product/admin/webhooks) for instructions on setting up webhooks. - - **Agent:** C1's AI agent evaluates the request and takes action based on the instructions you provide. This option is available on request and review policies. When you select **Agent**, three additional settings appear: + - **Agent:** C1.ai's AI agent evaluates the request and takes action based on the instructions you provide. This option is available on request and review policies. When you select **Agent**, three additional settings appear: - **Agent mode:** Controls which actions the agent can take on this step. @@ -232,9 +232,9 @@ If needed, click **Add step** to add either another wait condition check or a re - **Reassign to super admins:** The task is reassigned to your tenant's super admins. - **Skip policy step:** The step is skipped and the request moves to the next step in the policy. - - **Agent instructions:** Free-text instructions that tell the agent how to evaluate requests that reach this step — for example, conditions under which to approve or deny. C1's built-in evaluation guidance is always applied in addition to any instructions you provide. + - **Agent instructions:** Free-text instructions that tell the agent how to evaluate requests that reach this step — for example, conditions under which to approve or deny. C1.ai's built-in evaluation guidance is always applied in addition to any instructions you provide. -2. If you selected **Manager**, **Group**, **Account owner**, or **Entitlement owner**, you have the option to provide a fallback reviewer, which can be one or more users, or a group. In the event that C1 cannot identify the specified reviewer on a task (or the task is assigned to a group with more than 128 members), the system will fall back to the reviewer you set here. +2. If you selected **Manager**, **Group**, **Account owner**, or **Entitlement owner**, you have the option to provide a fallback reviewer, which can be one or more users, or a group. In the event that C1.ai cannot identify the specified reviewer on a task (or the task is assigned to a group with more than 128 members), the system will fall back to the reviewer you set here. - If you check **Permit reviewer to reassign task** on the policy, the fallback reviewer can then reassign the task to an appropriate contact. @@ -274,7 +274,7 @@ If needed, click **Add step** to add either another approval step (for instance, For review tasks only. -1. In the **Follow-up steps** section of the page, set whether C1 should automatically create a revoke task if the access review is denied. +1. In the **Follow-up steps** section of the page, set whether C1.ai should automatically create a revoke task if the access review is denied. **Done.** Your policy is now ready for use. You can review or edit the policy's details any time by clicking on its name on the **Policies** page. @@ -309,6 +309,6 @@ Follow the instructions above to edit existing policy rules and steps, or to add ## Export policy rules to CSV -Export a policy's rules to CSV for auditing, documentation, or review outside C1. Open the policy and click the export icon above the rules list. +Export a policy's rules to CSV for auditing, documentation, or review outside C1.ai. Open the policy and click the export icon above the rules list. The exported file includes each rule and its conditions. diff --git a/product/admin/profile-types.mdx b/product/admin/profile-types.mdx index f746c08d..09246e77 100644 --- a/product/admin/profile-types.mdx +++ b/product/admin/profile-types.mdx @@ -1,6 +1,6 @@ --- title: Segment users with profile types -og:title: Segment users with profile types - C1 docs +og:title: Segment users with profile types - C1.ai docs og:description: Profile types allow you to categorize your users and define a customized, relevant set of attributes for each segment, enabling precise data management and targeted access reviews. description: Profile types allow you to categorize your users and define a customized, relevant set of attributes for each segment, enabling precise data management and targeted access reviews. sidebarTitle: Profile types @@ -9,7 +9,7 @@ sidebarTitle: Profile types ## What are profile types? -In C1, profile types provide the foundation for managing user data with precision and efficiency. They offer a powerful way to segment your workforce and ensure that your administrators and reviewers only see the information relevant to a specific user group. +In C1.ai, profile types provide the foundation for managing user data with precision and efficiency. They offer a powerful way to segment your workforce and ensure that your administrators and reviewers only see the information relevant to a specific user group. Profile types solve the challenge of managing diverse user populations (like full-time employees, contractors, and vendors) within a single system. Instead of applying every possible user attribute to every single person, profile types allow you to select a specific, tailored set of attributes (like work_location or contract_end_date) that are relevant only to that group. This eliminates noise and makes user profiles cleaner and easier to read. @@ -31,22 +31,22 @@ The ideal profile type design will depend on how your organization is structured ## How do custom attributes reach user profiles? -Custom attribute data doesn't appear on a C1 user automatically. It flows through a series of steps, and each step must be configured for the data to reach the user's profile. Understanding this chain helps you troubleshoot when an attribute you expect to see isn't showing up. +Custom attribute data doesn't appear on a C1.ai user automatically. It flows through a series of steps, and each step must be configured for the data to reach the user's profile. Understanding this chain helps you troubleshoot when an attribute you expect to see isn't showing up. Here's the full lifecycle of a custom attribute: -1. **Connector syncs data from the source system.** When a connector syncs with a source application (like Workday, Active Directory, or Okta), it pulls user account data into C1. This data is stored on the user's **account** within the connected application. Custom fields from the source system are included in the account's profile as key-value pairs. +1. **Connector syncs data from the source system.** When a connector syncs with a source application (like Workday, Active Directory, or Okta), it pulls user account data into C1.ai. This data is stored on the user's **account** within the connected application. Custom fields from the source system are included in the account's profile as key-value pairs. -2. **You create an attribute mapping.** In the [Attribute manager](/product/admin/attributes), you create a custom attribute and tell C1 which application and which field to pull the data from. This is how C1 knows, for example, that "Employment Type" should come from the `employmentType` field on the user's Workday account. +2. **You create an attribute mapping.** In the [Attribute manager](/product/admin/attributes), you create a custom attribute and tell C1.ai which application and which field to pull the data from. This is how C1.ai knows, for example, that "Employment Type" should come from the `employmentType` field on the user's Workday account. 3. **You bind the attribute to a profile type.** When you [create or edit a profile type](#step-2-add-relevant-attributes-to-the-profile-type), you select which custom attributes belong to it. This binding controls which attributes appear on users assigned to that profile type. -4. **You assign users to the profile type.** Using a [user automation rule](#step-3-assign-users-to-the-profile-type) or manual assignment, you define which C1 users belong to the profile type. Users who aren't assigned to any profile type with the attribute won't see that attribute on their profile. +4. **You assign users to the profile type.** Using a [user automation rule](#step-3-assign-users-to-the-profile-type) or manual assignment, you define which C1.ai users belong to the profile type. Users who aren't assigned to any profile type with the attribute won't see that attribute on their profile. -5. **The attribute appears on the C1 user.** After the next directory sync, the attribute value flows from the account through the mapping and profile type, and appears in the **Profile attributes** section of the C1 user's page. From here, it can be used in policies, access review campaigns, CEL expressions, and [account correlation](#example-using-a-custom-ad-attribute-for-account-correlation). +5. **The attribute appears on the C1.ai user.** After the next directory sync, the attribute value flows from the account through the mapping and profile type, and appears in the **Profile attributes** section of the C1.ai user's page. From here, it can be used in policies, access review campaigns, CEL expressions, and [account correlation](#example-using-a-custom-ad-attribute-for-account-correlation). -If any step in this chain is missing, the attribute won't appear on the C1 user. The most common issue is creating the attribute mapping and profile type but forgetting to assign users to the profile type. +If any step in this chain is missing, the attribute won't appear on the C1.ai user. The most common issue is creating the attribute mapping and profile type but forgetting to assign users to the profile type. ### Example: Workday cost center for policy routing @@ -73,7 +73,7 @@ After the next connector sync and directory merge, the Cost Center value appears ### Example: Active Directory attribute for account correlation -Suppose your organization stores GitHub usernames in a custom Active Directory attribute called `githubUserName`, and you want C1 to use that attribute to match users to their GitHub accounts. +Suppose your organization stores GitHub usernames in a custom Active Directory attribute called `githubUserName`, and you want C1.ai to use that attribute to match users to their GitHub accounts. @@ -86,7 +86,7 @@ Navigate to **Identities** > **Directory sources** > **Attribute manager** and c Add the **GitHub Username** attribute to the appropriate profile type and make sure the relevant users are assigned to it. -After the next sync, the GitHub Username value appears on each assigned C1 user's profile. You can now use this attribute in an [account correlation rule](/product/admin/managing-accounts) to automatically match C1 users to their GitHub accounts. +After the next sync, the GitHub Username value appears on each assigned C1.ai user's profile. You can now use this attribute in an [account correlation rule](/product/admin/managing-accounts) to automatically match C1.ai users to their GitHub accounts. @@ -103,7 +103,7 @@ After the next sync, the GitHub Username value appears on each assigned C1 user' ## Create a new profile type -By default, a C1 tenant supports two profile types. For customers whose tenants were in use before November 2025, you'll initially find one auto-created **Legacy** profile type containing all your users and the capacity to create two additional profile types. +By default, a C1.ai tenant supports two profile types. For customers whose tenants were in use before November 2025, you'll initially find one auto-created **Legacy** profile type containing all your users and the capacity to create two additional profile types. Need more than two profile types? Let us know, we'll be happy to get you set up. @@ -134,7 +134,7 @@ Give the profile type a descriptive name. You can add a description as well, if -Upload an icon to associate with the profile type across C1. Click **Upload image** and select an image of at least 200x200px in either PNG, JPED, or WebP format. +Upload an icon to associate with the profile type across C1.ai. Click **Upload image** and select an image of at least 200x200px in either PNG, JPED, or WebP format. Click **Save profile type**. The new profile type will now appear in your list. @@ -167,7 +167,7 @@ Click **Save**. ### Step 3: Assign users to the profile type -Finally, define the criteria C1 will use to automatically assign users to this profile type. You can also add users manually, if needed. +Finally, define the criteria C1.ai will use to automatically assign users to this profile type. You can also add users manually, if needed. @@ -202,10 +202,10 @@ Choose how to form your user automation rule: When you're satisfied, click **Save**. The automation syncs and adds a list of matching users on the **Assigned users** tab. - Depending on the number of users in your C1 installation, syncing might take some time. You can kick off a new sync any time from the **User automation** tab. + Depending on the number of users in your C1.ai installation, syncing might take some time. You can kick off a new sync any time from the **User automation** tab. -**Done.** Repeat this process to add additional profile types. Once they're set up, you're ready to start using them across C1. +**Done.** Repeat this process to add additional profile types. Once they're set up, you're ready to start using them across C1.ai. diff --git a/product/admin/profiles.mdx b/product/admin/profiles.mdx index ad4bce38..5a09ffd4 100644 --- a/product/admin/profiles.mdx +++ b/product/admin/profiles.mdx @@ -1,6 +1,6 @@ --- title: Create access profiles -og:title: Create access profiles - C1 docs +og:title: Create access profiles - C1.ai docs og:description: An access profile is a curated list of apps scoped to a specific employee group, so every person can see and request the access relevant to their work. description: An access profile is a curated list of apps scoped to a specific employee group, so every person can see and request the access relevant to their work. --- @@ -16,7 +16,7 @@ Access profiles are groups of resources and entitlements. You determine the cont - Access profiles scoped to certain departments, job types, or access levels, which are only visible to the folks in those groups -When [requesting access](/product/how-to/create-requests/) in C1 or through Slack, each employee can see and request the contents of all the access profiles they have access to, but nothing more. +When [requesting access](/product/how-to/create-requests/) in C1.ai or through Slack, each employee can see and request the contents of all the access profiles they have access to, but nothing more. You also have the option to allow employees to ask for _all_ the resources and entitlements in an access profile. This is called a _profile request_, and is especially useful for onboarding or times when employees will need access to several interrelated entitlements. @@ -47,7 +47,7 @@ Click **Continue**. The new access profile's details page opens. Assign an owner to the access profile. Click the pencil icon next to **Owners:** at the top of the page and select one or more owners. - Because an access profile is a resource within [the C1 application](/product/admin/c1-for-c1), naming an owner or owners makes it possible to set up review, request, and revoke [policies](/product/admin/policies) that assign these tasks to the owner of the access profile. + Because an access profile is a resource within [the C1.ai application](/product/admin/c1-for-c1), naming an owner or owners makes it possible to set up review, request, and revoke [policies](/product/admin/policies) that assign these tasks to the owner of the access profile. Add apps and entitlements to the profile. On the **Apps** tab, click **Manage**, then select the apps you want to include in the profile (step 1) and the entitlements within each app (step 2). @@ -65,7 +65,7 @@ Add apps and entitlements to the profile. On the **Apps** tab, click **Manage**, **2. Make sure every entitlement you add has a request policy set.** Make sure that each entitlement you add to an access profile has a request policy set on either [the application](/product/admin/access-requests#set-app-level-access-request-rules) or [the entitlement](/product/admin/access-requests#configure-access-request-settings-on-an-individual-entitlement). If no request policy is set, users attempting to request the entitlement will see an error message. This is a known issue and will be corrected. - **3. Take advantage of role mining recommendations.** Once your access profile begins to take shape, C1 can offer data-driven recommendations for which entitlements to add to the access profile. [Read more about role mining.](/product/admin/profiles#use-role-mining-recommendations) + **3. Take advantage of role mining recommendations.** Once your access profile begins to take shape, C1.ai can offer data-driven recommendations for which entitlements to add to the access profile. [Read more about role mining.](/product/admin/profiles#use-role-mining-recommendations) @@ -86,7 +86,7 @@ Under **Profile is visible to**, set whether this access profile can be viewed a Under **Allow requests for**, set whether employees can request only the entitlements in the profile, or the entire access profile (membership) as well. Membership in the access profile means that changes to the profile will be automatically applied to its members' access. - C1 will automatically create individual request tickets for each entitlement in the access profile not yet granted to the employee. + C1.ai will automatically create individual request tickets for each entitlement in the access profile not yet granted to the employee. Click **Save**. @@ -97,7 +97,7 @@ Click **Save**. ### Use role mining recommendations -Role mining analyzes access patterns across your organization to suggest entitlements for access profiles. C1 assigns a confidence score to each entitlement suggestion: +Role mining analyzes access patterns across your organization to suggest entitlements for access profiles. C1.ai assigns a confidence score to each entitlement suggestion: * 80% or higher — This entitlement is a great fit for this access profile * 50%–79% — This entitlement might be a good fit for this access profile @@ -121,7 +121,7 @@ On the **Apps** tab of an access profile's details page, entitlements are organi **Enrolled users are not automatically granted new entitlements added to the access profile.** -If you want all currently enrolled users to receive the entitlements you've added to the access profile, check the **Create requests for currently enrolled users** box before saving your changes. C1 will automatically create access request tasks for each new entitlement for each enrolled user. Alternatively, you can leave the box unchecked and follow the process in [Update a current access profile holder's grant](/product/admin/profiles#update-a-current-access-profile-holders-grant). +If you want all currently enrolled users to receive the entitlements you've added to the access profile, check the **Create requests for currently enrolled users** box before saving your changes. C1.ai will automatically create access request tasks for each new entitlement for each enrolled user. Alternatively, you can leave the box unchecked and follow the process in [Update a current access profile holder's grant](/product/admin/profiles#update-a-current-access-profile-holders-grant). ### Add an entitlement on the entitlement's details page @@ -179,11 +179,11 @@ Any users who have been granted the full access profile but do not currently hav -**Done.** C1 automatically creates an access request for the entitlement for each user. You can track the progress of the access requests at any time by returning to the **Manage provisioning** drawer. +**Done.** C1.ai automatically creates an access request for the entitlement for each user. You can track the progress of the access requests at any time by returning to the **Manage provisioning** drawer. ## Grant duration and expiration in access profiles -Access profiles control how long a user can be *enrolled*, but they don't control how long the underlying grants last. When a user enrolls in a profile, C1 creates individual grants for each entitlement in the profile — and each grant follows the duration configured on that entitlement, not the profile's enrollment duration. If different entitlements in the same profile have different durations configured, their grants will expire at different times, independently of each other and independently of when the enrollment itself expires. +Access profiles control how long a user can be *enrolled*, but they don't control how long the underlying grants last. When a user enrolls in a profile, C1.ai creates individual grants for each entitlement in the profile — and each grant follows the duration configured on that entitlement, not the profile's enrollment duration. If different entitlements in the same profile have different durations configured, their grants will expire at different times, independently of each other and independently of when the enrollment itself expires. What happens to those grants when a profile enrollment ends depends on the profile's **When enrollment expires** setting. Depending on how this is configured, grants may be left in place, revoked, or revoked unless the user has another active enrollment justifying them. @@ -192,7 +192,7 @@ What happens to those grants when a profile enrollment ends depends on the profi Access profiles have two settings that control enrollment duration and what happens when it ends. You can find and set these on the access profile's **JML** tab. - **Maximum membership duration** — the longest enrollment period a user can request. If a user requests a duration longer than the maximum, it's capped. If they don't specify a duration, the maximum is used as the default. -- **Access change behavior** — what C1 does to a user's entitlement grants when their profile enrollment period ends. There are three options: +- **Access change behavior** — what C1.ai does to a user's entitlement grants when their profile enrollment period ends. There are three options: - **Leave access as-is** — grants are not touched when enrollment expires. Access continues until grants expire on their own schedule or are revoked manually. - **Revoke all entitlements** — all grants created by this enrollment are revoked when enrollment expires, regardless of any other access the user holds. - **Revoke unjustified entitlements** — grants are revoked when enrollment expires, unless the user is still enrolled in another active profile that includes the same entitlement. A direct grant to the same entitlement does not count as justification. diff --git a/product/admin/provisioning.mdx b/product/admin/provisioning.mdx index 1428c15c..375a89e3 100644 --- a/product/admin/provisioning.mdx +++ b/product/admin/provisioning.mdx @@ -1,15 +1,15 @@ --- title: Understanding entitlement provisioning -og:title: Understanding entitlement provisioning - C1 docs -og:description: Follow this guide to understand how entitlement provisioning works in C1. -description: Learn how entitlement provisioning works in C1. +og:title: Understanding entitlement provisioning - C1.ai docs +og:description: Follow this guide to understand how entitlement provisioning works in C1.ai. +description: Learn how entitlement provisioning works in C1.ai. sidebarTitle: Understanding provisioning --- {/* Editor Refresh: 2026-01-07 */} Provisioning is hard! (And complicated.) We're identity people, we know. -C1 supports multiple methods for provisioning access. This allows you to add governance and access control to all of your apps and technologies. +C1.ai supports multiple methods for provisioning access. This allows you to add governance and access control to all of your apps and technologies. We'll walk you through the different methods for provisioning, from simplest to most sophisticated, and when to use each one. @@ -21,7 +21,7 @@ We'll walk you through the different methods for provisioning, from simplest to Direct provisioning is the default provisioning strategy for apps with a connector. -This is the easiest method. Provisioning-enabled C1 connectors complete the provisioning process directly, without any input needed from you. C1 can provision fine-grained entitlements and permissions directly in the connected application or infrastructure. By default, C1 will use the connector when provisioning or deprovisioning access. To determine if a connector supports provisioning, see the connector's documentation. +This is the easiest method. Provisioning-enabled C1.ai connectors complete the provisioning process directly, without any input needed from you. C1.ai can provision fine-grained entitlements and permissions directly in the connected application or infrastructure. By default, C1.ai will use the connector when provisioning or deprovisioning access. To determine if a connector supports provisioning, see the connector's documentation. ## Method 2: Linked entitlements @@ -31,7 +31,7 @@ This is the easiest method. Provisioning-enabled C1 connectors complete the prov Use linked entitlements if the application is in your SSO directory or identity provider and you need basic access control. -C1 allows you to manage the apps from your SSO directory or identity provider. Once these apps are managed, C1 will discover "linked entitlements". These are entitlements in the SSO directory or identity provider that have a relationship with the application. +C1.ai allows you to manage the apps from your SSO directory or identity provider. Once these apps are managed, C1.ai will discover "linked entitlements". These are entitlements in the SSO directory or identity provider that have a relationship with the application. Examples of linked entitlements: @@ -41,9 +41,9 @@ Examples of linked entitlements: In each example above, access is "controlled" by assigning the user to the entitlement (such as group membership) in the SSO directory or identity provider. -C1 allows you to manage provisioning in the downstream app by creating the linkage between that managed app in C1 and the SSO directory or identity provider. +C1.ai allows you to manage provisioning in the downstream app by creating the linkage between that managed app in C1.ai and the SSO directory or identity provider. -To use this method, first ensure that app is managed by C1: +To use this method, first ensure that app is managed by C1.ai: @@ -73,11 +73,11 @@ Click the **Entitlements** tab. Click the **Linked entitlements** icon at the top right corner of the entitlements table (it looks like a Venn diagram). -In the **Linked entitlements** drawer, either create new roles or resources in C1 that map to those entitlements, or map those to existing roles or resources (if you've already added a connector to the app). +In the **Linked entitlements** drawer, either create new roles or resources in C1.ai that map to those entitlements, or map those to existing roles or resources (if you've already added a connector to the app). -Once set up, C1 will provision the entitlement by provisioning the "linked" entitlement in the SSO directory or identity provider. This is transparent to the end user. +Once set up, C1.ai will provision the entitlement by provisioning the "linked" entitlement in the SSO directory or identity provider. This is transparent to the end user. ## Method 3: Manual provisioning @@ -87,7 +87,7 @@ Once set up, C1 will provision the entitlement by provisioning the "linked" enti Use manual provisioning as a last resort. Nobody likes touching provisioning requests. -Manual provisioning treats the provisioning step as if C1 were a ticketing engine. The provisioning task is assigned to one or more users to complete the provisioning. +Manual provisioning treats the provisioning step as if C1.ai were a ticketing engine. The provisioning task is assigned to one or more users to complete the provisioning. Manual provisioning can be configured by clicking the provisioning settings on an entitlement. @@ -103,9 +103,9 @@ If there is an error or issue in provisioning, manual provisioning is used as th Use ticket-based provisioning if you need access requests to flow through your helpdesk. -C1 supports helpdesk ticket creation as a method for provisioning access. To use ticket provisioning, you'll first need to add a connector that supports ticket provisioning. Examples of ticketing-enabled connectors are [Jira](/baton/jira/) and [ServiceNow](/baton/servicenow/). +C1.ai supports helpdesk ticket creation as a method for provisioning access. To use ticket provisioning, you'll first need to add a connector that supports ticket provisioning. Examples of ticketing-enabled connectors are [Jira](/baton/jira/) and [ServiceNow](/baton/servicenow/). -Once a connector with ticketing is added, configure how C1 will create tickets in the system (see [External ticketing](/product/admin/external-ticketing) for instructions), then set provisioning to use the external ticketing option. Once set up, a helpdesk ticket will be automatically created any time provisioning is required. C1 will track the progress of the helpdesk ticket and update or close the provisioning task accordingly. +Once a connector with ticketing is added, configure how C1.ai will create tickets in the system (see [External ticketing](/product/admin/external-ticketing) for instructions), then set provisioning to use the external ticketing option. Once set up, a helpdesk ticket will be automatically created any time provisioning is required. C1.ai will track the progress of the helpdesk ticket and update or close the provisioning task accordingly. ## Method 5: Webhook provisioning @@ -125,7 +125,7 @@ Navigate to **Platform** > **Webhooks**. Follow the instructions in [Using webhooks](/product/admin/webhooks/) to set up a new webhook endpoint. -In C1, click **Apps**. +In C1.ai, click **Apps**. Select an application and click **Entitlements**. @@ -158,7 +158,7 @@ To configure multi-step provisioning: -In C1, click **Apps**. +In C1.ai, click **Apps**. Select an application and click **Entitlements**. @@ -176,9 +176,9 @@ Click **Save**. ## Deprovisioning -The process of **deprovisioning** (removing a user's access) is automatically handled by C1 and generally mirrors the configured provisioning method. +The process of **deprovisioning** (removing a user's access) is automatically handled by C1.ai and generally mirrors the configured provisioning method. -By **default**, C1 attempts to infer and perform the **inverse action** of the configured provisioning method for an entitlement. For example: +By **default**, C1.ai attempts to infer and perform the **inverse action** of the configured provisioning method for an entitlement. For example: * If the provisioning method is **Connector provisioning**, the system will attempt to use the connector to directly deprovision the entitlement in the target application. (Not all connectors support deprovisioning, see the connector's docs for details.) @@ -196,7 +196,7 @@ To configure a custom deprovisioning flow for an entitlement: -In C1, click **Apps**. +In C1.ai, click **Apps**. Select an application and click **Entitlements**. diff --git a/product/admin/push-rules.mdx b/product/admin/push-rules.mdx index 205d3e2e..6e97a518 100644 --- a/product/admin/push-rules.mdx +++ b/product/admin/push-rules.mdx @@ -1,20 +1,20 @@ --- title: "Attribute push rules" og:title: "Attribute push rules" -description: "Automatically sync user attributes from C1 to connected applications to keep user data consistent across your integrated systems." -og:description: "Automatically sync user attributes from C1 to connected applications to keep user data consistent across your integrated systems." +description: "Automatically sync user attributes from C1.ai to connected applications to keep user data consistent across your integrated systems." +og:description: "Automatically sync user attributes from C1.ai to connected applications to keep user data consistent across your integrated systems." sidebarTitle: "Attribute push rules" --- {/* Editor Refresh: 2026-02-09 */} -**Early access.** This feature is in early access, which means it's undergoing ongoing testing and development while we gather feedback, validate functionality, and improve outputs. Contact the C1 Support team if you'd like to try it out or share feedback. +**Early access.** This feature is in early access, which means it's undergoing ongoing testing and development while we gather feedback, validate functionality, and improve outputs. Contact the C1.ai Support team if you'd like to try it out or share feedback. Attribute push rules let you control which user attributes are synchronized to specific applications and how they're mapped. You can: -- Sync C1 attributes to application user profiles +- Sync C1.ai attributes to application user profiles - Transform attribute values using CEL expressions - Target specific users based on conditions - Map to both standard and custom attributes (when supported by the connector) @@ -39,28 +39,28 @@ Use attribute push rules when you need to: ## How attribute push works -Attribute push keeps user attributes synchronized between C1 and your connected applications. +Attribute push keeps user attributes synchronized between C1.ai and your connected applications. In broad strokes, here's how to set up a push rule: 1. Select the connector you want to push attributes to -2. Map C1 attributes to the target application's user attributes +2. Map C1.ai attributes to the target application's user attributes 3. Optionally use CEL expressions to transform values 4. Choose which users to target (all users or specific users) 5. Enable the configuration to begin syncing -Once enabled, C1 automatically pushes attributes to the target application whenever: +Once enabled, C1.ai automatically pushes attributes to the target application whenever: - The push configuration is created or updated -- A user's attribute values change in C1 +- A user's attribute values change in C1.ai ## Configure attribute push rules ### Prerequisites -- The **Super Admin** role in C1 +- The **Super Admin** role in C1.ai - A configured connector for the target application -- User attribute mappings defined in C1 (**Identities** > **Directory sources**) +- User attribute mappings defined in C1.ai (**Identities** > **Directory sources**) ### Create a push rule @@ -87,7 +87,7 @@ Under **Select users to push to**, choose: For each attribute you want to sync: - Choose the target attribute name from the connector's available attributes - - Select a C1 attribute to map, or click the **Change to expression** icon and write a CEL expression for custom logic + - Select a C1.ai attribute to map, or click the **Change to expression** icon and write a CEL expression for custom logic - If the connector supports custom attributes, you can specify a custom name @@ -152,9 +152,9 @@ Both views support filtering by status, account, attribute, and date range. ### Direct attribute mapping -Select a C1 attribute from the dropdown to sync its value directly to the target application. +Select a C1.ai attribute from the dropdown to sync its value directly to the target application. -**Example**: Map the `Department` attribute in C1 to the `department` field in the target application. +**Example**: Map the `Department` attribute in C1.ai to the `department` field in the target application. ### CEL expressions @@ -176,7 +176,7 @@ user.department == "Engineering" ? "tech@company.com" : "general@company.com" ### All users -Syncs attributes for all users in your C1 tenant. +Syncs attributes for all users in your C1.ai tenant. ### Specific users diff --git a/product/admin/query.mdx b/product/admin/query.mdx index 2b37149e..3ef4e365 100644 --- a/product/admin/query.mdx +++ b/product/admin/query.mdx @@ -1,8 +1,8 @@ --- title: Get quick insight into access data -og:title: Get quick insight into access data - C1 docs -og:description: Use C1's dashboards and pre-built access queries to quickly zoom in on important access information relevant to your organization's security. -description: Use C1's dashboards and pre-built access queries to quickly zoom in on important access information relevant to your organization's security. +og:title: Get quick insight into access data - C1.ai docs +og:description: Use C1.ai's dashboards and pre-built access queries to quickly zoom in on important access information relevant to your organization's security. +description: Use C1.ai's dashboards and pre-built access queries to quickly zoom in on important access information relevant to your organization's security. sidebarTitle: Explore access data --- {/* Editor Refresh: 2026-01-07 */} @@ -21,7 +21,7 @@ On the **Access explorer** page you'll find pre-built queries to help you explor | Accounts without an account owner | All accounts for all applications with no account owner set. | By app | | High-risk accounts | Accounts granted at least one entitlement designated [high risk](/product/admin/global-settings#set-attribute-values). | _None_ | | Orphaned accounts | All accounts for all applications with either no account owner or a deactivated user set as the account owner. | By app | -| Active external accounts | All accounts that are marked external in C1 because their associated email address is not set as a [trusted domain](/product/admin/global-settings#set-trusted-domains) | _None_ | +| Active external accounts | All accounts that are marked external in C1.ai because their associated email address is not set as a [trusted domain](/product/admin/global-settings#set-trusted-domains) | _None_ | | Past grants | All accounts with access grants that have expired or been removed, with grant and removal dates. | By app
By entitlement | | Apps with a deactivated owner | Applications with a designated application owner whose account is deactivated. | By app | | Apps with one owner | Applications that have a single designated application owner. | By app | diff --git a/product/admin/relationships.mdx b/product/admin/relationships.mdx index b678d8e8..dd85d4ab 100644 --- a/product/admin/relationships.mdx +++ b/product/admin/relationships.mdx @@ -1,6 +1,6 @@ --- title: Clarify complex entitlement relationships -og:title: Clarify complex entitlement relationships - C1 docs +og:title: Clarify complex entitlement relationships - C1.ai docs og:description: Linked, bound, and virtual entitlements help you establish relationships between entitlements and make it clearer to your colleagues what they need to request or review. description: Linked, bound, and virtual entitlements help you establish relationships between entitlements and make it clearer to your colleagues what they need to request or review. sidebarTitle: Complex entitlement relationships @@ -9,34 +9,34 @@ sidebarTitle: Complex entitlement relationships ## Choosing the right tool -C1 offers three tools to help you create relationships between entitlements. Use bound, virtual, or linked entitlements when you have a complex relationship between entitlements that you need to model within C1 or want to present to your colleagues in a simplified way. +C1.ai offers three tools to help you create relationships between entitlements. Use bound, virtual, or linked entitlements when you have a complex relationship between entitlements that you need to model within C1.ai or want to present to your colleagues in a simplified way. Here's an overview of the three tools and when to use each one: ### Linked entitlements -Linked entitlements are existing relationships between IdP- and non-IdP entitlements that C1 identifies for you. You configure how these entitlements show up in C1. +Linked entitlements are existing relationships between IdP- and non-IdP entitlements that C1.ai identifies for you. You configure how these entitlements show up in C1.ai. **Use when:** You want to clarify the relationship between IdP resources and the apps they grant access to. ### Bound entitlements -Bound entitlements create relationships between entitlements where access to one (the source) implies access to another (the destination). When a user has access to the source entitlement, C1 automatically shows them as having access to the destination entitlement as well. +Bound entitlements create relationships between entitlements where access to one (the source) implies access to another (the destination). When a user has access to the source entitlement, C1.ai automatically shows them as having access to the destination entitlement as well. **Use when:** You need to model access hierarchies, cross-application dependencies, or any situation where one entitlement logically includes another. ### Virtual entitlements -Virtual entitlements are special proxy entitlements that exist only in C1, and that can be bound to other entitlements. +Virtual entitlements are special proxy entitlements that exist only in C1.ai, and that can be bound to other entitlements. **Use when:** You need to create a clear and easily understood target for user access requests while preserving the underlying complexity of your apps' configuration. ## How bound entitlements work -A bound entitlement (also called a proxy binding) links a **source entitlement** to a **destination entitlement**. When someone has the source entitlement, C1 records that they also have access to the destination. +A bound entitlement (also called a proxy binding) links a **source entitlement** to a **destination entitlement**. When someone has the source entitlement, C1.ai records that they also have access to the destination. -Bound entitlements are a visibility and tracking layer in C1. They do not trigger additional provisioning to external systems—provisioning only happens through the source entitlement's connector. +Bound entitlements are a visibility and tracking layer in C1.ai. They do not trigger additional provisioning to external systems—provisioning only happens through the source entitlement's connector. ### What bound entitlements do @@ -56,7 +56,7 @@ Bound entitlements are a visibility and tracking layer in C1. They do not trigge **System-managed bindings** are created automatically when a connector discovers role hierarchies in an external system (for example, AWS IAM policy relationships). You can enable or disable these bindings, but you cannot delete them. -**Manual bindings** are created by administrators to model relationships that C1 doesn't automatically detect. You have full control over their lifecycle. +**Manual bindings** are created by administrators to model relationships that C1.ai doesn't automatically detect. You have full control over their lifecycle. ## When to use bound entitlements @@ -94,9 +94,9 @@ When performing access reviews: ## Set up a linked entitlement {/* header name used in links, change with caution */} -When C1 identifies a relationship between an entitlement in an IdP and one in a standalone application, that relationship is called a linked entitlement. You'll find any linked entitlements C1 has identified on the **Linked entitlements** tab on an application's details page. You can set how you want C1 to treat each linked entitlement. +When C1.ai identifies a relationship between an entitlement in an IdP and one in a standalone application, that relationship is called a linked entitlement. You'll find any linked entitlements C1.ai has identified on the **Linked entitlements** tab on an application's details page. You can set how you want C1.ai to treat each linked entitlement. -C1 identifies a group in your IdP as a linked entitlement to a downstream app when the app is managed in C1 and the IdP group is either assigned directly to the app (SSO assignment) or is a push group that SCIMs membership into the app. If access is granted through a different mechanism — for example, group nesting outside the direct app assignment, or an IdP rule that doesn't surface a direct group-to-app relationship — C1 may not auto-detect the link. In that case, use [Add a manual binding](#add-a-manual-binding) below to model the relationship, or create a virtual entitlement in the managed app and manually bind it to the IdP group. +C1.ai identifies a group in your IdP as a linked entitlement to a downstream app when the app is managed in C1.ai and the IdP group is either assigned directly to the app (SSO assignment) or is a push group that SCIMs membership into the app. If access is granted through a different mechanism — for example, group nesting outside the direct app assignment, or an IdP rule that doesn't surface a direct group-to-app relationship — C1.ai may not auto-detect the link. In that case, use [Add a manual binding](#add-a-manual-binding) below to model the relationship, or create a virtual entitlement in the managed app and manually bind it to the IdP group. To set up a linked entitlement: @@ -113,15 +113,15 @@ On an app's **Entitlements** page, click the **Linked entitlements** icon at the In the **Linked entitlements** drawer, click the **Setup** tab.
-For each IdP entitlement C1 has identified as linked to the app, choose an action: +For each IdP entitlement C1.ai has identified as linked to the app, choose an action: - - **Create virtual role**: Set up a new role in the app that will be linked to the IdP entitlement. This role will only exist in C1, and will function as an alias for the IdP entitlement. Your colleagues can request and review the role, which will appear as part of the app, but they will in actuality be requesting or reviewing the IdP entitlement. + - **Create virtual role**: Set up a new role in the app that will be linked to the IdP entitlement. This role will only exist in C1.ai, and will function as an alias for the IdP entitlement. Your colleagues can request and review the role, which will appear as part of the app, but they will in actuality be requesting or reviewing the IdP entitlement. - **Provision access for**: Link the IdP entitlement to an existing entitlement in the app. When your colleagues request or review the app entitlement, they will also be requesting or reviewing the IdP entitlement. - **Skip**: Do nothing. - In both cases, granting the entitlement actually provisions the underlying IdP entitlement (for example, adding the user to an Okta push group) — C1 relies on the IdP's own SCIM or SSO mechanism to carry that access into the app. **Skip** leaves the relationship as a visibility-only link, with no provisioning configured either way. + In both cases, granting the entitlement actually provisions the underlying IdP entitlement (for example, adding the user to an Okta push group) — C1.ai relies on the IdP's own SCIM or SSO mechanism to carry that access into the app. **Skip** leaves the relationship as a visibility-only link, with no provisioning configured either way. When you've made all of your selections, click **Save**. @@ -161,12 +161,12 @@ Click **Add binding**. Your new manual binding is added to the list of bindings for the active entitlement. If you've created an outgoing binding, the details of the additional access grants that are bound to access to the active entitlement are shown in the **Inherited entitlements** area. -A manual binding models the relationship inside C1 for visibility and access reviews only — it never provisions access in the destination application, no matter how the destination entitlement is configured. If someone needs real access in the destination app, grant them the destination entitlement directly, through whatever provisioning method it already uses. The only way to get C1 to automatically provision downstream access from a binding is the [linked entitlements](#set-up-a-linked-entitlement) flow: choosing **Provision access for** or **Create virtual role** delegates provisioning back to the IdP entitlement, so granting the destination entitlement actually grants the IdP group — and it's the IdP's own SCIM or SSO connection that carries that access into the app. +A manual binding models the relationship inside C1.ai for visibility and access reviews only — it never provisions access in the destination application, no matter how the destination entitlement is configured. If someone needs real access in the destination app, grant them the destination entitlement directly, through whatever provisioning method it already uses. The only way to get C1.ai to automatically provision downstream access from a binding is the [linked entitlements](#set-up-a-linked-entitlement) flow: choosing **Provision access for** or **Create virtual role** delegates provisioning back to the IdP entitlement, so granting the destination entitlement actually grants the IdP group — and it's the IdP's own SCIM or SSO connection that carries that access into the app. ## Create a virtual entitlement -Virtual entitlements are ideal when you need to create a custom target entitlement that is easy for users to understand. A virtual entitlement exists only in C1 (it does not get written back to the source application). You can bind it to other entitlements, using the virtual entitlement as a proxy, then include the virtual entitlement in access profiles and access review campaigns. +Virtual entitlements are ideal when you need to create a custom target entitlement that is easy for users to understand. A virtual entitlement exists only in C1.ai (it does not get written back to the source application). You can bind it to other entitlements, using the virtual entitlement as a proxy, then include the virtual entitlement in access profiles and access review campaigns. To create a virtual entitlement: @@ -185,7 +185,7 @@ Give the new resource a name and description. If needed, edit the default entitlement. -**Optional.** If C1 has identified any entitlements in your IdP that are linked to this app, you have the option to select one to be linked to the custom app. +**Optional.** If C1.ai has identified any entitlements in your IdP that are linked to this app, you have the option to select one to be linked to the custom app. **Optional.** Select the owner (or multiple owners) of the new resource. diff --git a/product/admin/requirements.mdx b/product/admin/requirements.mdx index 25810574..496fb1e6 100644 --- a/product/admin/requirements.mdx +++ b/product/admin/requirements.mdx @@ -1,15 +1,15 @@ --- -title: C1 network requirements +title: C1.ai network requirements sidebarTitle: Network requirements -description: Egress IPs, hostnames, and firewall requirements for C1 cloud-hosted connectors, self-hosted connectors, and the web application. +description: Egress IPs, hostnames, and firewall requirements for C1.ai cloud-hosted connectors, self-hosted connectors, and the web application. --- {/* Editor Refresh: 2026-05-04 */} -C1 has different network requirements depending on how you deploy connectors and how users access the web application. Review each section that applies to your environment. +C1.ai has different network requirements depending on how you deploy connectors and how users access the web application. Review each section that applies to your environment. ## Cloud-hosted connectors: application allowlisting -If you use C1's cloud-hosted connectors and your SaaS or cloud applications enforce IP-based allowlisting, add the following IP addresses to those applications' allowlists. This allows C1's connectors and functions to reach your integrated systems — for example, if Okta network zones restrict which source IPs can call the Okta API. +If you use C1.ai's cloud-hosted connectors and your SaaS or cloud applications enforce IP-based allowlisting, add the following IP addresses to those applications' allowlists. This allows C1.ai's connectors and functions to reach your integrated systems — for example, if Okta network zones restrict which source IPs can call the Okta API. ### Connector egress IPs @@ -51,18 +51,18 @@ Cloud-hosted connectors use the following source IP addresses when syncing data 3.123.76.40 ``` -## Self-hosted connectors: outbound access to C1 +## Self-hosted connectors: outbound access to C1.ai Self-hosted connectors have the following network behavior: -- The connector initiates all connections to C1 — no inbound ports are required. +- The connector initiates all connections to C1.ai — no inbound ports are required. - Works behind NAT and most firewalls without additional configuration. If your network enforces egress filtering, allow outbound HTTPS (port 443) to whichever domain matches your tenant's hosting region — default instance: `*.conductor.one`, EU data residency instance: `*.c1eu.ai`. ## Web application and MCP: corporate device access -If users access the C1 web application or MCP server from corporate devices behind a proxy, content filter, or firewall, add the following hostnames to your allowlist: +If users access the C1.ai web application or MCP server from corporate devices behind a proxy, content filter, or firewall, add the following hostnames to your allowlist: | Hostname | Port | Purpose | |---|---|---| @@ -74,7 +74,7 @@ If users access the C1 web application or MCP server from corporate devices behi | `-mcp.c1eu.ai` | 443 | AI traffic (MCP protocol) (for EU instances) | | `accounts.c1eu.ai` | 443 | Login and SSO flow (for EU instances) | -Replace `` with your organization's C1 tenant name. +Replace `` with your organization's C1.ai tenant name. ## Staying informed of changes diff --git a/product/admin/role-mining.mdx b/product/admin/role-mining.mdx index f348987d..ccfeff59 100644 --- a/product/admin/role-mining.mdx +++ b/product/admin/role-mining.mdx @@ -1,7 +1,7 @@ --- title: "Discover access profiles with role mining" description: "Role mining analyzes access patterns across your organization to suggest entitlements for access profiles." -og:title: "Discover access profiles with role mining - C1 docs" +og:title: "Discover access profiles with role mining - C1.ai docs" og:description: "Role mining analyzes access patterns across your organization to suggest entitlements for access profiles." sidebarTitle: "Role mining" --- @@ -9,7 +9,7 @@ sidebarTitle: "Role mining" ## What is role mining? -Role mining analyzes the access granted to your organization's users and identifies patterns that suggest well-defined access profiles. Instead of building access profiles by hand, you can use role mining to let C1 surface which entitlements are commonly held by similar groups of people, then turn those patterns into ready-to-use profiles. +Role mining analyzes the access granted to your organization's users and identifies patterns that suggest well-defined access profiles. Instead of building access profiles by hand, you can use role mining to let C1.ai surface which entitlements are commonly held by similar groups of people, then turn those patterns into ready-to-use profiles. ## How role mining works @@ -19,7 +19,7 @@ If you're starting from a specific entitlement and want to know who should have ## Before you begin -- You must have the **Super Admin** role in C1 to use role mining. +- You must have the **Super Admin** role in C1.ai to use role mining. - At least one connector must be configured and have completed a sync. Role mining analyzes existing access grants, so it requires data to work with. ## Run a role mining analysis @@ -40,7 +40,7 @@ If you're starting from a specific entitlement and want to know who should have - Add more filters as needed with **Add filter**. C1 updates the results as you build your cohort. + Add more filters as needed with **Add filter**. C1.ai updates the results as you build your cohort.
@@ -66,7 +66,7 @@ The results appear in two tabs: The action bar at the bottom of the page shows a summary of the current cohort (for example, "7 of the 18 users have the 100 entitlements selected") and two actions: -- **Create access profile** — opens a modal where you name the profile, optionally enable membership automation, and review the selected entitlements. When membership automation is enabled, C1 generates a CEL expression from your filters and automatically enrolls users who match it. Turn on **Create access request tasks for membership changes** to route those automatic enrollments through an access request task for approval, instead of enrolling matching users immediately. +- **Create access profile** — opens a modal where you name the profile, optionally enable membership automation, and review the selected entitlements. When membership automation is enabled, C1.ai generates a CEL expression from your filters and automatically enrolls users who match it. Turn on **Create access request tasks for membership changes** to route those automatic enrollments through an access request task for approval, instead of enrolling matching users immediately. - **Add to existing profile** — opens a modal to add the cohort's selected entitlements to an access profile you've already created. ## Revisit past analyses @@ -85,6 +85,6 @@ Role mining becomes more accurate as your organization's data grows. If you've r - C1 creates the access profile with the entitlements from your cohort. If you enabled membership automation, users who match the profile's CEL expression are enrolled automatically and kept in sync as your organization changes — unless you also enabled **Create access request tasks for membership changes**, in which case matching users get an access request task instead of immediate enrollment. If you didn't enable automation, the profile starts with no enrolled members — add members from the profile's **Enrollment** tab. + C1.ai creates the access profile with the entitlements from your cohort. If you enabled membership automation, users who match the profile's CEL expression are enrolled automatically and kept in sync as your organization changes — unless you also enabled **Create access request tasks for membership changes**, in which case matching users get an access request task instead of immediate enrollment. If you didn't enable automation, the profile starts with no enrolled members — add members from the profile's **Enrollment** tab. diff --git a/product/admin/secret-sharing.mdx b/product/admin/secret-sharing.mdx index 139e985f..137a81f6 100644 --- a/product/admin/secret-sharing.mdx +++ b/product/admin/secret-sharing.mdx @@ -1,6 +1,6 @@ --- title: Secret sharing -og:title: Secret sharing - C1 docs +og:title: Secret sharing - C1.ai docs og:description: Share sensitive credentials, files, and notes securely with internal team members or external contacts. description: Share sensitive credentials, files, and notes securely with internal team members or external contacts. sidebarTitle: Secret sharing @@ -10,10 +10,10 @@ sidebarTitle: Secret sharing ## How it works -Secret sharing is designed so that C1 never has access to your secrets. Encryption happens in your browser, before anything leaves your device. Here's how a secret moves from creation to delivery: +Secret sharing is designed so that C1.ai never has access to your secrets. Encryption happens in your browser, before anything leaves your device. Here's how a secret moves from creation to delivery: 1. **Create** — choose who can access the secret, add your content, and decide how long it should stay available and how many times it can be viewed. -2. **Encrypt** — your browser encrypts the content before upload. C1 stores only the encrypted result and never sees your plaintext. +2. **Encrypt** — your browser encrypts the content before upload. C1.ai stores only the encrypted result and never sees your plaintext. 3. **Share** — copy the generated link and send it to recipients through whatever channel you choose: email, Slack, a ticket, or anything else. 4. **Access** — recipients click the link and authenticate (SSO for internal users, a one-time email magic link for external contacts), then view or download the content. @@ -21,14 +21,14 @@ Secret sharing is designed so that C1 never has access to your secrets. Encrypti -In C1, navigate to **My resources** in the left sidebar, select the **Shared secrets** tab, then click **Share a secret**. +In C1.ai, navigate to **My resources** in the left sidebar, select the **Shared secrets** tab, then click **Share a secret**. **Choose your audience.** | Audience | Description | | :--- | :--- | -| **Team members** | Share with C1 users in your organization. Recipients authenticate via SSO. | +| **Team members** | Share with C1.ai users in your organization. Recipients authenticate via SSO. | | **External recipients** | Share with anyone via email address. Recipients verify their identity with a one-time magic link. | @@ -63,7 +63,7 @@ Click **Share secret**. Copy the generated **share code** and **share URL** and send them to recipients via email, Slack, Teams, or another preferred channel. -**C1 does not notify recipients.** The share URL is the only way to access the secret, and you must distribute it yourself. +**C1.ai does not notify recipients.** The share URL is the only way to access the secret, and you must distribute it yourself. @@ -159,11 +159,11 @@ Click **View** on any secret to view the JSON metadata for the secret. ## Secret-sharing security -Content is encrypted in your browser before it's uploaded. C1 stores only encrypted blobs and never sees your plaintext. When a recipient accesses a secret, an isolated vault service decrypts and delivers the content to that specific recipient. Plaintext is never stored, logged, or persisted. +Content is encrypted in your browser before it's uploaded. C1.ai stores only encrypted blobs and never sees your plaintext. When a recipient accesses a secret, an isolated vault service decrypts and delivers the content to that specific recipient. Plaintext is never stored, logged, or persisted. | Control | Detail | | :--- | :--- | -| **Browser-side encryption** | Content is encrypted before upload; plaintext never touches C1 servers or logs. | +| **Browser-side encryption** | Content is encrypted before upload; plaintext never touches C1.ai servers or logs. | | **Isolated decryption** | A dedicated vault service handles decryption, with access controlled by AWS KMS with hardware security modules. | | **View limits and expiration** | Content is permanently deleted after the view limit is reached or the expiration time passes. | | **Magic link protection** | Magic link tokens are single-use and expire after 15 minutes. | @@ -172,8 +172,8 @@ Content is encrypted in your browser before it's uploaded. C1 stores only encryp ## Frequently asked questions about secret sharing - - Absolutely not. C1 stores only encrypted blobs. Decryption occurs in an isolated vault service and plaintext is never stored or logged. + + Absolutely not. C1.ai stores only encrypted blobs. Decryption occurs in an isolated vault service and plaintext is never stored or logged. @@ -207,7 +207,7 @@ Content is encrypted in your browser before it's uploaded. C1 stores only encryp ## Secret sharing events in system logs -All secret-sharing activity is recorded in the C1 system log. Events use the `paper_secret_` prefix. For details on accessing, exporting, and querying log data, see [System logs](/product/admin/system-log). +All secret-sharing activity is recorded in the C1.ai system log. Events use the `paper_secret_` prefix. For details on accessing, exporting, and querying log data, see [System logs](/product/admin/system-log). ### Event types diff --git a/product/admin/service-principals/aws-iam.mdx b/product/admin/service-principals/aws-iam.mdx index 40c570ac..f64091d0 100644 --- a/product/admin/service-principals/aws-iam.mdx +++ b/product/admin/service-principals/aws-iam.mdx @@ -1,14 +1,14 @@ --- title: AWS IAM integration -og:title: AWS IAM integration - C1 docs -og:description: Set up secretless authentication from AWS workloads to C1 using IAM outbound identity federation. -description: Set up secretless authentication from AWS workloads to C1 using IAM outbound identity federation. +og:title: AWS IAM integration - C1.ai docs +og:description: Set up secretless authentication from AWS workloads to C1.ai using IAM outbound identity federation. +description: Set up secretless authentication from AWS workloads to C1.ai using IAM outbound identity federation. sidebarTitle: AWS IAM --- {/* Editor Refresh: 2026-03-18 */} -AWS IAM outbound identity federation lets your AWS workloads (EC2 instances, Lambda functions, ECS tasks, and more) obtain signed JWTs that C1 can trust directly. No long-lived API keys to store or rotate. +AWS IAM outbound identity federation lets your AWS workloads (EC2 instances, Lambda functions, ECS tasks, and more) obtain signed JWTs that C1.ai can trust directly. No long-lived API keys to store or rotate. These examples use `conductor.one`. If your organization is on the EU data residency instance, substitute `c1eu.ai` in URLs, client IDs, and hostnames. @@ -44,7 +44,7 @@ Before your workloads can request tokens, enable the feature in your AWS account ## Step 2: Configure IAM permissions -Create an IAM policy that grants `sts:GetWebIdentityToken` with your C1 tenant domain as the audience. Attach this policy to the IAM role used by your workload. +Create an IAM policy that grants `sts:GetWebIdentityToken` with your C1.ai tenant domain as the audience. Attach this policy to the IAM role used by your workload. ```json { @@ -64,13 +64,13 @@ Create an IAM policy that grants `sts:GetWebIdentityToken` with your C1 tenant d } ``` -## Step 3: Create a federation trust in C1 +## Step 3: Create a federation trust in C1.ai -When creating the provider in C1, select the **AWS IAM Outbound** preset and enter the issuer URL from Step 1. Then create a trust with a CEL expression to control which AWS principals can authenticate. See [set up federation](/product/admin/service-principals/federation-setup) for the full walkthrough. +When creating the provider in C1.ai, select the **AWS IAM Outbound** preset and enter the issuer URL from Step 1. Then create a trust with a CEL expression to control which AWS principals can authenticate. See [set up federation](/product/admin/service-principals/federation-setup) for the full walkthrough. ## Step 4: Request and exchange the token -From your AWS workload, call `GetWebIdentityToken` to get a signed JWT, then exchange it for a C1 access token: +From your AWS workload, call `GetWebIdentityToken` to get a signed JWT, then exchange it for a C1.ai access token: ```bash # Request a JWT from AWS STS @@ -88,16 +88,16 @@ C1_ACCESS_TOKEN=$(curl -s -X POST \ | jq -r '.access_token') ``` -Use the access token in an `Authorization: Bearer` header for C1 API calls: +Use the access token in an `Authorization: Bearer` header for C1.ai API calls: ```bash curl -s "https://yourcompany.conductor.one/api/v1/apps" \ -H "Authorization: Bearer $C1_ACCESS_TOKEN" ``` -### Using with C1 tools +### Using with C1.ai tools -When using C1 tools (`cone`, Terraform provider), you must set both of these environment variables. The tools require them to handle the token exchange internally: +When using C1.ai tools (`cone`, Terraform provider), you must set both of these environment variables. The tools require them to handle the token exchange internally: ```bash export CONDUCTORONE_OIDC_TOKEN=$AWS_JWT diff --git a/product/admin/service-principals/client-credentials.mdx b/product/admin/service-principals/client-credentials.mdx index 511e37d1..6d626be8 100644 --- a/product/admin/service-principals/client-credentials.mdx +++ b/product/admin/service-principals/client-credentials.mdx @@ -1,6 +1,6 @@ --- title: "Quick start: Client credentials" -og:title: "Quick start: Client credentials - C1 docs" +og:title: "Quick start: Client credentials - C1.ai docs" og:description: Create a service principal, generate credentials, and make your first API call in under 5 minutes. description: Create a service principal, generate credentials, and make your first API call in under 5 minutes. sidebarTitle: Client credentials @@ -93,7 +93,7 @@ curl -s "https://yourcompany.conductor.one/api/v1/apps" \ ## Use with the Terraform provider -Configure the [C1 Terraform provider](/developer/terraform) with your service principal credentials. The server URL is derived automatically from the client ID, so you only need two values: +Configure the [C1.ai Terraform provider](/developer/terraform) with your service principal credentials. The server URL is derived automatically from the client ID, so you only need two values: ```hcl provider "conductorone" { diff --git a/product/admin/service-principals/custom-oidc.mdx b/product/admin/service-principals/custom-oidc.mdx index 6a89d1be..30b3ed9e 100644 --- a/product/admin/service-principals/custom-oidc.mdx +++ b/product/admin/service-principals/custom-oidc.mdx @@ -1,6 +1,6 @@ --- title: Custom OIDC providers -og:title: Custom OIDC providers - C1 docs +og:title: Custom OIDC providers - C1.ai docs og:description: Set up workload federation with any OIDC-compliant identity provider. description: Set up workload federation with any OIDC-compliant identity provider. sidebarTitle: Custom OIDC providers @@ -27,7 +27,7 @@ Your OIDC provider must: ## Exchange the token -Send the external OIDC JWT to C1's token exchange endpoint: +Send the external OIDC JWT to C1.ai's token exchange endpoint: ```bash curl -s -X POST "https://yourcompany.conductor.one/auth/v1/token" \ @@ -57,7 +57,7 @@ The JWT must satisfy these requirements: | Requirement | Detail | | :--- | :--- | | **Issuer (`iss`)** | Must match the provider's issuer URL exactly | -| **Audience (`aud`)** | Must contain your C1 tenant domain (for example `yourcompany.conductor.one`) | +| **Audience (`aud`)** | Must contain your C1.ai tenant domain (for example `yourcompany.conductor.one`) | | **Expiration (`exp`)** | Must not be expired | | **Issued at (`iat`)** | Must be within the last 10 minutes | | **Signature** | Must be verifiable via the provider's JWKS endpoint | @@ -82,9 +82,9 @@ claims.sub == "expected-subject" && claims.custom_claim == "expected-value" Use the **Test expression** tool at **Settings** > **Workload Federation** to validate your expressions against sample claims before deploying. */} -## Using with C1 tools +## Using with C1.ai tools -Once you have the access token, set the `CONDUCTORONE_ACCESS_TOKEN` environment variable and all C1 tools pick it up automatically: +Once you have the access token, set the `CONDUCTORONE_ACCESS_TOKEN` environment variable and all C1.ai tools pick it up automatically: ```bash export CONDUCTORONE_ACCESS_TOKEN=$(curl -s -X POST ... | jq -r '.access_token') diff --git a/product/admin/service-principals/federation-setup.mdx b/product/admin/service-principals/federation-setup.mdx index 2333a1a5..e4b092ce 100644 --- a/product/admin/service-principals/federation-setup.mdx +++ b/product/admin/service-principals/federation-setup.mdx @@ -1,6 +1,6 @@ --- title: Set up workload federation -og:title: Set up workload federation - C1 docs +og:title: Set up workload federation - C1.ai docs og:description: Walk through the federation wizard to create a provider and trust, then test your token. description: Walk through the federation wizard to create a provider and trust, then test your token. sidebarTitle: Set up a provider @@ -8,7 +8,7 @@ sidebarTitle: Set up a provider {/* Editor Refresh: 2026-02-14 */} -This guide walks through the C1 federation wizard to create a provider and trust. Before starting, you need a service principal -- if you don't have one yet, follow Step 1 of the [client credentials quick start](/product/admin/service-principals/client-credentials#step-1-create-a-service-principal). You don't need to create a credential; federation replaces credentials with OIDC tokens. +This guide walks through the C1.ai federation wizard to create a provider and trust. Before starting, you need a service principal -- if you don't have one yet, follow Step 1 of the [client credentials quick start](/product/admin/service-principals/client-credentials#step-1-create-a-service-principal). You don't need to create a credential; federation replaces credentials with OIDC tokens. ## Create a federation trust @@ -23,7 +23,7 @@ This guide walks through the C1 federation wizard to create a provider and trust Click **Setup federation**.
- Next, choose a provider. Select an existing provider, or create a new one. C1 includes presets for common platforms: + Next, choose a provider. Select an existing provider, or create a new one. C1.ai includes presets for common platforms: | Provider | Issuer URL | Notes | | :--- | :--- | :--- | diff --git a/product/admin/service-principals/github-actions.mdx b/product/admin/service-principals/github-actions.mdx index 314d412b..189ce8be 100644 --- a/product/admin/service-principals/github-actions.mdx +++ b/product/admin/service-principals/github-actions.mdx @@ -1,14 +1,14 @@ --- title: GitHub Actions integration -og:title: GitHub Actions integration - C1 docs -og:description: Set up secretless authentication from GitHub Actions to C1 using the oidc-token-action. -description: Set up secretless authentication from GitHub Actions to C1 using the oidc-token-action. +og:title: GitHub Actions integration - C1.ai docs +og:description: Set up secretless authentication from GitHub Actions to C1.ai using the oidc-token-action. +description: Set up secretless authentication from GitHub Actions to C1.ai using the oidc-token-action. sidebarTitle: GitHub Actions --- {/* Editor Refresh: 2026-02-14 */} -The `conductorone/oidc-token-action` GitHub Action exchanges a GitHub Actions OIDC token for a C1 access token in a single step. No secrets to store or rotate. +The `conductorone/oidc-token-action` GitHub Action exchanges a GitHub Actions OIDC token for a C1.ai access token in a single step. No secrets to store or rotate. These examples use `conductor.one`. If your organization is on the EU data residency instance, substitute `c1eu.ai` in URLs, client IDs, and hostnames. @@ -44,14 +44,14 @@ jobs: The action: 1. Requests a GitHub OIDC token with your tenant domain as the audience -2. Exchanges it for a C1 access token via token exchange +2. Exchanges it for a C1.ai access token via token exchange 3. Exports `CONDUCTORONE_ACCESS_TOKEN` and `CONDUCTORONE_CLIENT_ID` as environment variables 4. Masks the token in logs to prevent accidental exposure 5. Cleans up the environment variables when the job finishes ## Use with downstream tools -After the action runs, `CONDUCTORONE_ACCESS_TOKEN` is available to all subsequent steps. Every C1 tool recognizes this variable automatically. +After the action runs, `CONDUCTORONE_ACCESS_TOKEN` is available to all subsequent steps. Every C1.ai tool recognizes this variable automatically. ### Cone CLI diff --git a/product/admin/service-principals/gitlab-ci.mdx b/product/admin/service-principals/gitlab-ci.mdx index 93324d61..dc19c7e6 100644 --- a/product/admin/service-principals/gitlab-ci.mdx +++ b/product/admin/service-principals/gitlab-ci.mdx @@ -1,14 +1,14 @@ --- title: GitLab CI integration -og:title: GitLab CI integration - C1 docs -og:description: Set up secretless authentication from GitLab CI to C1 using OIDC id_tokens. -description: Set up secretless authentication from GitLab CI to C1 using OIDC id_tokens. +og:title: GitLab CI integration - C1.ai docs +og:description: Set up secretless authentication from GitLab CI to C1.ai using OIDC id_tokens. +description: Set up secretless authentication from GitLab CI to C1.ai using OIDC id_tokens. sidebarTitle: GitLab CI --- {/* Editor Refresh: 2026-02-14 */} -GitLab CI/CD can issue OIDC tokens for each job via the `id_tokens` keyword. You exchange this token for a C1 access token using a curl command in your pipeline. +GitLab CI/CD can issue OIDC tokens for each job via the `id_tokens` keyword. You exchange this token for a C1.ai access token using a curl command in your pipeline. These examples use `conductor.one`. If your organization is on the EU data residency instance, substitute `c1eu.ai` in URLs, client IDs, and hostnames. @@ -19,7 +19,7 @@ GitLab CI/CD can issue OIDC tokens for each job via the `id_tokens` keyword. You ## Configure the pipeline -Add `id_tokens` to your job to request a GitLab OIDC token, then exchange it for a C1 access token: +Add `id_tokens` to your job to request a GitLab OIDC token, then exchange it for a C1.ai access token: ```yaml # .gitlab-ci.yml @@ -41,7 +41,7 @@ deploy: -H "Authorization: Bearer $C1_ACCESS_TOKEN" ``` -The `id_tokens` block tells GitLab to generate a signed JWT with your C1 tenant domain as the audience. The token is available as the `C1_TOKEN` environment variable within the job. +The `id_tokens` block tells GitLab to generate a signed JWT with your C1.ai tenant domain as the audience. The token is available as the `C1_TOKEN` environment variable within the job. ## CEL expression examples diff --git a/product/admin/service-principals/hcp-terraform.mdx b/product/admin/service-principals/hcp-terraform.mdx index 80b74785..f0bc3f7c 100644 --- a/product/admin/service-principals/hcp-terraform.mdx +++ b/product/admin/service-principals/hcp-terraform.mdx @@ -1,14 +1,14 @@ --- title: HCP Terraform integration -og:title: HCP Terraform integration - C1 docs -og:description: Set up secretless authentication from HCP Terraform to C1 using workload identity tokens. -description: Set up secretless authentication from HCP Terraform to C1 using workload identity tokens. +og:title: HCP Terraform integration - C1.ai docs +og:description: Set up secretless authentication from HCP Terraform to C1.ai using workload identity tokens. +description: Set up secretless authentication from HCP Terraform to C1.ai using workload identity tokens. sidebarTitle: HCP Terraform --- {/* Editor Refresh: 2026-02-14 */} -HCP Terraform (formerly Terraform Cloud) can issue workload identity tokens for each run. The C1 Terraform provider auto-detects these tokens, so your runs authenticate without stored secrets. +HCP Terraform (formerly Terraform Cloud) can issue workload identity tokens for each run. The C1.ai Terraform provider auto-detects these tokens, so your runs authenticate without stored secrets. These examples use `conductor.one`. If your organization is on the EU data residency instance, substitute `c1eu.ai` in URLs, client IDs, and hostnames. @@ -23,13 +23,13 @@ In your HCP Terraform workspace, set this environment variable: | Variable | Value | | :--- | :--- | -| `TFC_WORKLOAD_IDENTITY_AUDIENCE` | `yourcompany.conductor.one` (your C1 tenant domain) | +| `TFC_WORKLOAD_IDENTITY_AUDIENCE` | `yourcompany.conductor.one` (your C1.ai tenant domain) | HCP Terraform automatically generates a `TFC_WORKLOAD_IDENTITY_TOKEN` environment variable for each run. This token is a signed JWT containing metadata about the Terraform run. ## Step 2: Configure the provider -The C1 Terraform provider auto-detects `TFC_WORKLOAD_IDENTITY_TOKEN`. You only need to provide the trust's client ID: +The C1.ai Terraform provider auto-detects `TFC_WORKLOAD_IDENTITY_TOKEN`. You only need to provide the trust's client ID: ```hcl provider "conductorone" { @@ -38,7 +38,7 @@ provider "conductorone" { } ``` -That's it. When `terraform plan` or `terraform apply` runs in HCP Terraform, the provider exchanges the workload identity token for a C1 access token automatically. +That's it. When `terraform plan` or `terraform apply` runs in HCP Terraform, the provider exchanges the workload identity token for a C1.ai access token automatically. ### Explicit configuration diff --git a/product/admin/service-principals/manage.mdx b/product/admin/service-principals/manage.mdx index b958ec5b..69cf0af7 100644 --- a/product/admin/service-principals/manage.mdx +++ b/product/admin/service-principals/manage.mdx @@ -1,6 +1,6 @@ --- title: Manage service principals -og:title: Manage service principals - C1 docs +og:title: Manage service principals - C1.ai docs og:description: View, edit, disable, delete, rotate credentials, and assign owners for service principals. description: View, edit, disable, delete, rotate credentials, and assign owners for service principals. sidebarTitle: Manage service principals @@ -37,7 +37,7 @@ Click any credential in the **Credentials** tab to open its detail drawer. You c Credential expiration can't be changed after creation. To use a different expiration, create a new credential and revoke the old one. -Super Administrators receive an alert in their daily C1 digest when any service principal credential is expiring within 30 days or has already expired. The alert includes a countdown and a direct link to the credential. +Super Administrators receive an alert in their daily C1.ai digest when any service principal credential is expiring within 30 days or has already expired. The alert includes a countdown and a direct link to the credential. ## Editing federation trusts @@ -126,7 +126,7 @@ Only [Super Admins](/product/admin/user-roles#super-administrator) can create ne ## Entitlements -A service principal has its own C1 account, just like a human user, and that account can hold entitlements -- app access, group membership, and so on -- the same way a human user's account does. +A service principal has its own C1.ai account, just like a human user, and that account can hold entitlements -- app access, group membership, and so on -- the same way a human user's account does. On the service principal detail page, the **Accounts** tab lists the accounts linked to the service principal. Open an account's entitlements to view or revoke what it can access, using the same entitlements interface described in [Managing entitlements](/product/admin/managing-entitlements). diff --git a/product/admin/service-principals/overview.mdx b/product/admin/service-principals/overview.mdx index a3715ac4..90e18dae 100644 --- a/product/admin/service-principals/overview.mdx +++ b/product/admin/service-principals/overview.mdx @@ -1,6 +1,6 @@ --- title: Service principals -og:title: Service principals - C1 docs +og:title: Service principals - C1.ai docs og:description: Create machine identities for API automation with client credentials or secretless workload federation. description: Create machine identities for API automation with client credentials or secretless workload federation. sidebarTitle: Overview @@ -8,7 +8,7 @@ sidebarTitle: Overview {/* Editor Refresh: 2026-02-14 */} -Service principals are machine identities in C1. They give your scripts, CI/CD pipelines, and Terraform runs their own identity and credentials, separate from any human user. +Service principals are machine identities in C1.ai. They give your scripts, CI/CD pipelines, and Terraform runs their own identity and credentials, separate from any human user. ## What's a service principal? @@ -17,13 +17,13 @@ A service principal is a dedicated, non-human identity purpose-built for automat Each service principal: - Has a display name and unique ID -- Can be assigned C1 roles, just like a human user +- Can be assigned C1.ai roles, just like a human user - Has owners who manage it - Can have multiple credentials or federation trusts -- Has its own C1 account, so [entitlements](/product/admin/service-principals/manage#entitlements) work the same way as for a human user's account +- Has its own C1.ai account, so [entitlements](/product/admin/service-principals/manage#entitlements) work the same way as for a human user's account -You don't need a service principal to use the C1 API for personal use. You can use existing personal API credentials (**Profile** > **AI & API** > **API credentials**) for individual tasks. Service principals are designed for shared automation where the identity should not be tied to a specific person. +You don't need a service principal to use the C1.ai API for personal use. You can use existing personal API credentials (**Profile** > **AI & API** > **API credentials**) for individual tasks. Service principals are designed for shared automation where the identity should not be tied to a specific person. ## Two ways to authenticate @@ -32,7 +32,7 @@ Service principals support two authentication methods. You can use either one, o | | Client credentials | Workload federation | | :--- | :--- | :--- | -| **How it works** | Client ID + secret sent to token endpoint | External OIDC (OpenID Connect) token exchanged for C1 token | +| **How it works** | Client ID + secret sent to token endpoint | External OIDC (OpenID Connect) token exchanged for C1.ai token | | **Secrets** | Client secret must be stored and rotated | No secrets -- uses your CI/CD platform's built-in OIDC | | **Best for** | Local development, scripts, cron jobs, Terraform (simple setup) | GitHub Actions, GitLab CI, HCP Terraform, AWS, SPIFFE (production) | | **Credential lifetime** | Maximum 180 days; must be rotated before expiry | No credentials to manage; tokens are per-run | @@ -46,7 +46,7 @@ Service principals support two authentication methods. You can use either one, o ## Environment variables -All C1 client tools (Go SDK, [Terraform provider](/developer/terraform), [Cone CLI](/product/cli/install), oidc-token-action) recognize the same environment variables: +All C1.ai client tools (Go SDK, [Terraform provider](/developer/terraform), [Cone CLI](/product/cli/install), oidc-token-action) recognize the same environment variables: | Variable | Purpose | | :--- | :--- | @@ -67,7 +67,7 @@ When multiple variables are set, tools use this priority order: Before creating service principals: -1. Contact your C1 account team to enable the feature. +1. Contact your C1.ai account team to enable the feature. 2. You need **[Super Admin](/product/admin/user-roles#super-administrator)** permissions to create and manage service principals. ## Next steps diff --git a/product/admin/service-principals/security.mdx b/product/admin/service-principals/security.mdx index d38bd874..7bdc5cd8 100644 --- a/product/admin/service-principals/security.mdx +++ b/product/admin/service-principals/security.mdx @@ -1,6 +1,6 @@ --- title: Security controls -og:title: Security controls - C1 docs +og:title: Security controls - C1.ai docs og:description: Scoped roles, IP allowlists, credential expiration, DPoP, CEL expressions, and audit log events for service principals. description: Scoped roles, IP allowlists, credential expiration, DPoP, CEL expressions, and audit log events for service principals. sidebarTitle: Security controls @@ -16,7 +16,7 @@ Scoping happens in two steps: first you assign the service principal its base ro ### Step 1: Assign base roles -On the service principal's **Details** tab, the **Role** field assigns one or more of C1's standard roles to the service principal -- the same roles you'd assign to a human user. See [User roles](/product/admin/user-roles) for the full list and descriptions of each role. +On the service principal's **Details** tab, the **Role** field assigns one or more of C1.ai's standard roles to the service principal -- the same roles you'd assign to a human user. See [User roles](/product/admin/user-roles) for the full list and descriptions of each role. ### Step 2: Scope a credential or trust (optional) @@ -112,7 +112,7 @@ For more on CEL syntax, see the [CEL expressions](/product/admin/expressions) do ## System log events -All service principal and workload federation activity is recorded in the C1 system log. +All service principal and workload federation activity is recorded in the C1.ai system log. ### Authentication events diff --git a/product/admin/service-principals/spiffe.mdx b/product/admin/service-principals/spiffe.mdx index 15516bb7..72cefa72 100644 --- a/product/admin/service-principals/spiffe.mdx +++ b/product/admin/service-principals/spiffe.mdx @@ -1,14 +1,14 @@ --- title: SPIFFE integration -og:title: SPIFFE integration - C1 docs -og:description: Set up secretless authentication from SPIFFE/SPIRE workload identities to C1 using JWT-SVIDs. -description: Set up secretless authentication from SPIFFE/SPIRE workload identities to C1 using JWT-SVIDs. +og:title: SPIFFE integration - C1.ai docs +og:description: Set up secretless authentication from SPIFFE/SPIRE workload identities to C1.ai using JWT-SVIDs. +description: Set up secretless authentication from SPIFFE/SPIRE workload identities to C1.ai using JWT-SVIDs. sidebarTitle: SPIFFE --- {/* Editor Refresh: 2026-08-05 */} -SPIFFE (Secure Production Identity Framework For Everyone) issues workloads a cryptographically verifiable identity in the form of a JWT-SVID (JWT SVID). C1 can trust JWT-SVIDs directly from any SPIFFE implementation, including [SPIRE](https://spiffe.io/docs/latest/spire-about/), so your workloads authenticate without stored secrets. +SPIFFE (Secure Production Identity Framework For Everyone) issues workloads a cryptographically verifiable identity in the form of a JWT-SVID (JWT SVID). C1.ai can trust JWT-SVIDs directly from any SPIFFE implementation, including [SPIRE](https://spiffe.io/docs/latest/spire-about/), so your workloads authenticate without stored secrets. These examples use `conductor.one`. If your organization is on the EU data residency instance, substitute `c1eu.ai` in URLs, client IDs, and hostnames. @@ -18,7 +18,7 @@ SPIFFE (Secure Production Identity Framework For Everyone) issues workloads a cr - A service principal with a SPIFFE federation trust. See [set up federation](/product/admin/service-principals/federation-setup) if you haven't created one yet. Use the **SPIFFE** preset. - The trust's **client ID** (for example `still-heron-30217@yourcompany.conductor.one/wfe`) -## Step 1: Configure the provider in C1 +## Step 1: Configure the provider in C1.ai When creating the provider, select the **SPIFFE** preset and provide: @@ -27,7 +27,7 @@ When creating the provider, select the **SPIFFE** preset and provide: | **Trust domain** | Your SPIFFE trust domain, for example `prod.acme.internal` | | **Bundle endpoint URL** | The publicly accessible URL where your SPIFFE implementation serves its JWKS bundle | -C1 verifies every JWT-SVID's signature against this bundle endpoint, and confirms the token's trust domain matches the one you configured -- this check happens server-side, not in the trust's CEL expression. +C1.ai verifies every JWT-SVID's signature against this bundle endpoint, and confirms the token's trust domain matches the one you configured -- this check happens server-side, not in the trust's CEL expression. ## Step 2: Create a federation trust @@ -35,7 +35,7 @@ Configure the trust with the workload path you want to allow. The wizard generat ## Step 3: Request and exchange the token -From your workload, request a JWT-SVID from your SPIFFE implementation (for example the SPIRE Workload API), then exchange it for a C1 access token: +From your workload, request a JWT-SVID from your SPIFFE implementation (for example the SPIRE Workload API), then exchange it for a C1.ai access token: ```bash # Fetch a JWT-SVID from the SPIRE agent (audience must match your C1 tenant domain) @@ -85,7 +85,7 @@ JWT-SVIDs carry minimal claims compared to platform-specific OIDC tokens: | `iat` | `1700000000` | Token issued-at time (Unix timestamp), if present | -The `iat` claim is optional under the JWT-SVID specification, and many SPIFFE implementations (including SPIRE) omit it. C1 only enforces the token-freshness check when `iat` is present. +The `iat` claim is optional under the JWT-SVID specification, and many SPIFFE implementations (including SPIRE) omit it. C1.ai only enforces the token-freshness check when `iat` is present. ## Security best practices for SPIFFE @@ -95,5 +95,5 @@ Trust domain verification confirms which SPIFFE implementation issued the token,
- **Scope by workload path**: Use `url(claims.sub).path` to restrict which specific workload identity can use this trust, not just the trust domain. -- **Keep bundle endpoints current**: If your SPIFFE implementation rotates its signing keys, make sure the bundle endpoint URL configured in C1 stays reachable so signature verification keeps working. +- **Keep bundle endpoints current**: If your SPIFFE implementation rotates its signing keys, make sure the bundle endpoint URL configured in C1.ai stays reachable so signature verification keeps working. - **Scope trust roles**: Use scoped roles on the federation trust to limit what the exchanged token can do. See [security controls](/product/admin/service-principals/security) for details. diff --git a/product/admin/service-principals/workload-federation.mdx b/product/admin/service-principals/workload-federation.mdx index 909ff9ad..64b3b8e9 100644 --- a/product/admin/service-principals/workload-federation.mdx +++ b/product/admin/service-principals/workload-federation.mdx @@ -1,23 +1,23 @@ --- title: Workload federation -og:title: Workload federation - C1 docs -og:description: Eliminate stored secrets by exchanging OIDC tokens from CI/CD platforms for C1 access tokens. -description: Eliminate stored secrets by exchanging OIDC tokens from CI/CD platforms for C1 access tokens. +og:title: Workload federation - C1.ai docs +og:description: Eliminate stored secrets by exchanging OIDC tokens from CI/CD platforms for C1.ai access tokens. +description: Eliminate stored secrets by exchanging OIDC tokens from CI/CD platforms for C1.ai access tokens. sidebarTitle: Workload federation --- {/* Editor Refresh: 2026-02-14 */} -Workload federation eliminates stored secrets entirely. Your CI/CD platform's built-in OIDC (OpenID Connect) tokens are exchanged directly for C1 access tokens -- no client secrets to store, rotate, or risk leaking. +Workload federation eliminates stored secrets entirely. Your CI/CD platform's built-in OIDC (OpenID Connect) tokens are exchanged directly for C1.ai access tokens -- no client secrets to store, rotate, or risk leaking. ## How it works -Most CI/CD platforms (GitHub Actions, GitLab CI, HCP Terraform) can issue short-lived OIDC tokens that identify the running workload. Workload federation lets C1 trust these tokens directly: +Most CI/CD platforms (GitHub Actions, GitLab CI, HCP Terraform) can issue short-lived OIDC tokens that identify the running workload. Workload federation lets C1.ai trust these tokens directly: 1. Your CI/CD platform issues a signed JWT (JSON Web Token) for the current workflow run -2. Your workflow sends this JWT to C1's token exchange endpoint -3. C1 validates the token: issuer, signature, audience, freshness, and your conditions -4. C1 issues a short-lived access token scoped to the service principal's roles +2. Your workflow sends this JWT to C1.ai's token exchange endpoint +3. C1.ai validates the token: issuer, signature, audience, freshness, and your conditions +4. C1.ai issues a short-lived access token scoped to the service principal's roles The entire flow is secretless. No credentials are stored anywhere -- the OIDC token is only valid for a single CI/CD run, typically for a few minutes. @@ -33,7 +33,7 @@ Each provider has: - An **issuer URL** (for example `https://token.actions.githubusercontent.com` for GitHub Actions) - A public JWKS (JSON Web Key Set) endpoint for signature verification -C1 includes presets for common platforms: +C1.ai includes presets for common platforms: | Provider | Issuer URL | Notes | | :--- | :--- | :--- | diff --git a/product/admin/shadow-apps.mdx b/product/admin/shadow-apps.mdx index 2cbcd5f2..e30a4b08 100644 --- a/product/admin/shadow-apps.mdx +++ b/product/admin/shadow-apps.mdx @@ -1,15 +1,15 @@ --- title: Detect and manage shadow apps -og:title: Detect and manage shadow apps - C1 docs -og:description: C1 helps businesses manage shadow IT by detecting unauthorized apps employees use and bringing them under management. -description: C1 helps businesses manage shadow IT by detecting unauthorized apps employees use and bringing them under management. +og:title: Detect and manage shadow apps - C1.ai docs +og:description: C1.ai helps businesses manage shadow IT by detecting unauthorized apps employees use and bringing them under management. +description: C1.ai helps businesses manage shadow IT by detecting unauthorized apps employees use and bringing them under management. sidebarTitle: Manage shadow apps --- {/* Editor Refresh: 2026-01-07 */} ## What are shadow apps? -Shadow apps are applications and cloud services not managed or approved by an organization's IT department that employees sign into using their corporate email. In C1, you can track the shadow apps that users sign into using their IdP credentials and bring key shadow apps under management. +Shadow apps are applications and cloud services not managed or approved by an organization's IT department that employees sign into using their corporate email. In C1.ai, you can track the shadow apps that users sign into using their IdP credentials and bring key shadow apps under management. ## IdP support and integration requirements @@ -17,15 +17,15 @@ Shadow apps are applications and cloud services not managed or approved by an or ## Discover shadow apps -C1 monitors the OAuth scopes granted to apps when an employee’s email is used to sign into an unmanaged app. The list of these apps is shown on the **Shadow apps** tab. +C1.ai monitors the OAuth scopes granted to apps when an employee’s email is used to sign into an unmanaged app. The list of these apps is shown on the **Shadow apps** tab. -In C1, click **Apps** > **Shadow apps**. The list of discovered shadow apps is shown. +In C1.ai, click **Apps** > **Shadow apps**. The list of discovered shadow apps is shown. A new shadow app is discovered whenever an employee in your organization first logs into it using their Google Workspace or Entra IdP credentials. - When you first begin using shadow apps, you'll see historic data from the 30 days (for Entra users) or the 180 days (for Google Workspace users) before the feature was added to your C1 instance. + When you first begin using shadow apps, you'll see historic data from the 30 days (for Entra users) or the 180 days (for Google Workspace users) before the feature was added to your C1.ai instance. Click the name of a shadow app to view its details, the list of users who have accessed the app, and how recently each user signed in. @@ -36,7 +36,7 @@ Click the name of a shadow app to view its details, the list of users who have a ### Authorize a shadow app -Authorizing a shadow app brings it under C1 management. Once a shadow app is authorized, it is added to your list of applications in C1. You can then add it to [access profiles](/product/admin/profiles), include it in [UAR campaigns](/product/admin/campaigns), and work with it like any other app. +Authorizing a shadow app brings it under C1.ai management. Once a shadow app is authorized, it is added to your list of applications in C1.ai. You can then add it to [access profiles](/product/admin/profiles), include it in [UAR campaigns](/product/admin/campaigns), and work with it like any other app. @@ -50,7 +50,7 @@ Click **Authorize**. - The app is removed from the list of discovered apps on the **Shadow apps** tab and a new entry is created for it in the list on the **Managed apps** tab. The shadow app's users are mapped to C1 users and shown on the app's **Accounts** tab. + The app is removed from the list of discovered apps on the **Shadow apps** tab and a new entry is created for it in the list on the **Managed apps** tab. The shadow app's users are mapped to C1.ai users and shown on the app's **Accounts** tab. On the application's **Connectors** tab, you'll see that the shadow app feed has been added as a connector. View the log to see recent activity on the feed. @@ -87,9 +87,9 @@ If you don't see anything on the **Shadow apps** tab, run a new sync of your [Go -[Google's documentation on data retention and lag times](https://support.google.com/a/answer/7061566?hl=en) states that it can take "up to a few hours" to pass OAuth login information to its endpoints. This means there might be a delay between when the login occurs and when the information appears in C1. +[Google's documentation on data retention and lag times](https://support.google.com/a/answer/7061566?hl=en) states that it can take "up to a few hours" to pass OAuth login information to its endpoints. This means there might be a delay between when the login occurs and when the information appears in C1.ai. - + When deleted, the app returns to the list of shadow apps, where you can ignore it or re-authorize it in the future. The app's full history and logs are preserved. diff --git a/product/admin/step-up-auth.mdx b/product/admin/step-up-auth.mdx index 9c44251a..f537a4ac 100644 --- a/product/admin/step-up-auth.mdx +++ b/product/admin/step-up-auth.mdx @@ -1,6 +1,6 @@ --- title: Step-up authentication -og:title: Step-up authentication - C1 docs +og:title: Step-up authentication - C1.ai docs og:description: Require additional authentication for sensitive approvals to enhance security and create clear audit trails. description: Require additional authentication for sensitive approvals to enhance security and create clear audit trails. sidebarTitle: Step-up authentication @@ -10,16 +10,16 @@ sidebarTitle: Step-up authentication ## What's step-up authentication? -Step-up authentication enhances your approval workflows by requiring approvers to re-authenticate with stronger verification before they can approve sensitive requests. Instead of relying solely on a user's initial session, C1 issues a fresh authentication challenge at the moment of approval, creating a clear security boundary and audit trail for critical actions. +Step-up authentication enhances your approval workflows by requiring approvers to re-authenticate with stronger verification before they can approve sensitive requests. Instead of relying solely on a user's initial session, C1.ai issues a fresh authentication challenge at the moment of approval, creating a clear security boundary and audit trail for critical actions. The flow works like this: -1. Users authenticate normally to access C1 +1. Users authenticate normally to access C1.ai 2. When attempting to approve sensitive requests, users are redirected to your identity provider 3. The identity provider verifies the user with the required authentication factors (such as MFA) 4. Upon verification, the approval is processed with an audit trail of the enhanced authentication -C1 implements the [RFC 9470 OAuth 2.0 Step Up Authentication Challenge Protocol](https://www.rfc-editor.org/rfc/rfc9470.html), which means each approval requiring step-up authentication generates a new authentication challenge. In other words, authentication state isn't cached between approvals. +C1.ai implements the [RFC 9470 OAuth 2.0 Step Up Authentication Challenge Protocol](https://www.rfc-editor.org/rfc/rfc9470.html), which means each approval requiring step-up authentication generates a new authentication challenge. In other words, authentication state isn't cached between approvals. ## When to use step-up authentication @@ -36,7 +36,7 @@ Consider enabling step-up authentication for approval workflows involving: Confirm that you have: -- The **Super Administrator** role in C1 +- The **Super Administrator** role in C1.ai - Administrator access to your identity provider (Okta or Microsoft Entra) - The ability to create OAuth applications in your identity provider - **Microsoft Entra only**: Microsoft Entra ID P1 or P2 license if using Conditional Access for MFA @@ -47,7 +47,7 @@ Confirm that you have: Step-up authentication is currently **not supported** for approvals made through Slack, Teams, or the `cone` CLI. -C1 supports two provider types: +C1.ai supports two provider types: - **OAuth2 providers** (RFC 9470 compliant): [Okta](#okta-integration-guide) and other compliant providers - **[Microsoft Entra](#microsoft-entra-integration-guide)**: Uses Conditional Access policies or authentication contexts @@ -73,9 +73,9 @@ Select **OIDC - OpenID Connect** and **Web Application**, then click **Next**. Configure the application: - - **Name**: C1 Step Up Authentication + - **Name**: C1.ai Step Up Authentication - **Grant type**: Authorization Code - - **Sign-in redirect URIs** (use whichever matches your C1 tenant's domain): + - **Sign-in redirect URIs** (use whichever matches your C1.ai tenant's domain): - Default instance: `https://accounts.conductor.one/auth/callback` - EU data residency instance: `https://accounts.c1eu.ai/auth/callback` - **Controlled access**: Select options based on your security requirements @@ -84,7 +84,7 @@ Configure the application: Click **Save**. -Copy the **Client ID** and **Client Secret** for use in C1. +Copy the **Client ID** and **Client Secret** for use in C1.ai. @@ -97,13 +97,13 @@ For granular control over authentication requirements: Navigate to **Security** > **Authentication Policies**. -Create a policy specifically for C1 Step Up Authentication. +Create a policy specifically for C1.ai Step Up Authentication. Define rules that require stronger authentication methods (such as MFA). -Assign the policy to your C1 Step Up application. +Assign the policy to your C1.ai Step Up application. @@ -111,7 +111,7 @@ Assign the policy to your C1 Step Up application. -In C1, navigate to **Settings** > **Step-up authentication**. +In C1.ai, navigate to **Settings** > **Step-up authentication**. Click **Add step-up provider**. @@ -156,7 +156,7 @@ Microsoft Entra supports two validation modes for step-up authentication: -This approach uses Conditional Access policies targeting the C1 Cloud App. It's recommended for most deployments. +This approach uses Conditional Access policies targeting the C1.ai Cloud App. It's recommended for most deployments. ### Part 1: Configure Microsoft Entra @@ -171,9 +171,9 @@ Click **New registration**. Configure the application: - - **Name**: C1 Step-Up Authentication + - **Name**: C1.ai Step-Up Authentication - **Supported account types**: Accounts in this organizational directory only (Single tenant) - - **Redirect URI**: Platform: Web. URI (use whichever matches your C1 tenant's domain): + - **Redirect URI**: Platform: Web. URI (use whichever matches your C1.ai tenant's domain): - Default instance: `https://accounts.conductor.one/auth/callback` - EU data residency instance: `https://accounts.c1eu.ai/auth/callback` @@ -227,7 +227,7 @@ Navigate to **Manage** > **Certificates & secrets**. Click **New client secret**. -Provide a description (for example, "C1 Step-Up") and select an expiration period. +Provide a description (for example, "C1.ai Step-Up") and select an expiration period. Click **Add**. @@ -252,9 +252,9 @@ Click **New policy**. Configure the policy: - - **Name**: Require MFA for C1 Step-Up + - **Name**: Require MFA for C1.ai Step-Up - **Users**: Include users or groups who will use step-up authentication - - **Target resources**: Select **Cloud apps**, then choose the C1 app registration you created + - **Target resources**: Select **Cloud apps**, then choose the C1.ai app registration you created - **Grant**: Select "Grant access" and check **Require multi-factor authentication** @@ -270,7 +270,7 @@ Collect these values from Azure: - **Client secret**: The value you copied in Step 4 - **Tenant ID**: Located in **Microsoft Entra** > **Overview** -### Part 2: Configure C1 +### Part 2: Configure C1.ai @@ -317,9 +317,9 @@ Click **New registration**. Configure the application: - - **Name**: C1 Step-Up Authentication + - **Name**: C1.ai Step-Up Authentication - **Supported account types**: Accounts in this organizational directory only (Single tenant) - - **Redirect URI**: Platform: Web. URI (use whichever matches your C1 tenant's domain): + - **Redirect URI**: Platform: Web. URI (use whichever matches your C1.ai tenant's domain): - Default instance: `https://accounts.conductor.one/auth/callback` - EU data residency instance: `https://accounts.c1eu.ai/auth/callback` @@ -374,9 +374,9 @@ Click **New authentication context**. Configure the context: - **Display name**: Step-Up for Approvals - - **Description**: Required for approving sensitive access requests in C1 + - **Description**: Required for approving sensitive access requests in C1.ai - **Publish to apps**: Enable this option - - **ID**: Select an available identifier (C1 through C99) + - **ID**: Select an available identifier (C1.ai through C99) Click **Save** and note the ID you selected. @@ -393,8 +393,8 @@ In Conditional Access, go to **Policies** and click **New policy**. Configure the policy: - **Name**: Require MFA for Step-Up Context - **Users**: Include users or groups who will use step-up authentication - - **Cloud apps**: Select the C1 app registration - - **Conditions** > **Authentication context**: Choose the context you created (for example, C1) + - **Cloud apps**: Select the C1.ai app registration + - **Conditions** > **Authentication context**: Choose the context you created (for example, C1.ai) - **Grant**: Select "Grant access" and check **Require multi-factor authentication** @@ -409,9 +409,9 @@ Collect these values from Azure: - **Application (client) ID**: Found in your app registration overview - **Client secret**: The value you copied in Step 3 - **Tenant ID**: Located in **Microsoft Entra** > **Overview** -- **Conditional Access ID**: The authentication context ID from Step 4 (for example, C1) +- **Conditional Access ID**: The authentication context ID from Step 4 (for example, C1.ai) -### Part 2: Configure C1 +### Part 2: Configure C1.ai @@ -427,7 +427,7 @@ Enter the configuration details: - **Client ID**: Your Application (client) ID from Azure - **Client secret**: The secret value from Step 3 - **Validation mode**: Select **Require ACRS** - - **Conditional Access IDs**: The authentication context ID(s) you created (for example, C1) + - **Conditional Access IDs**: The authentication context ID(s) you created (for example, C1.ai) - **Microsoft Tenant ID**: Your Azure tenant ID @@ -450,7 +450,7 @@ From the **Step-up authentication providers** page, click the **...** (more acti Complete the authentication flow with your identity provider. -Verify you're redirected back to C1 with a success message. +Verify you're redirected back to C1.ai with a success message. @@ -462,7 +462,7 @@ Once your provider is configured and tested, enable step-up authentication in yo -Navigate to **Policies** in C1. +Navigate to **Policies** in C1.ai. Edit an existing policy or create a new one. @@ -486,7 +486,7 @@ When a task requires step-up authentication for approval: 2. Instead of a standard **Approve** button, users see **Approve (step-up required)**. 3. Clicking this button redirects the user to the configured identity provider. 4. The user completes the required authentication steps (such as MFA). -5. Upon successful authentication, the user is returned to C1. +5. Upon successful authentication, the user is returned to C1.ai. 6. The approval is processed and an audit trail is created. If the approval policy also requires a comment, clicking **Approve (step-up required)** opens a dialog to enter your comment first. Saving the comment starts the same step-up authentication flow described above, and the approval completes once you're verified. diff --git a/product/admin/system-log.mdx b/product/admin/system-log.mdx index 3c80a633..5d630cfd 100644 --- a/product/admin/system-log.mdx +++ b/product/admin/system-log.mdx @@ -1,21 +1,21 @@ --- -title: C1 system logs -og:title: C1 system logs - C1 docs -og:description: Export system log data on every call made to the C1 API -description: Access C1 system log via API or export log data for storage or usage in SIEM. +title: C1.ai system logs +og:title: C1.ai system logs - C1.ai docs +og:description: Export system log data on every call made to the C1.ai API +description: Access C1.ai system log via API or export log data for storage or usage in SIEM. sidebarTitle: System logs --- {/* Editor Refresh: 2026-08-27 */} -## What's included in C1 system logs? +## What's included in C1.ai system logs? -System logs include a record of actions taken by the C1 API. The C1 API is used for all app-level actions and captures both end-user and administrative activities. +System logs include a record of actions taken by the C1.ai API. The C1.ai API is used for all app-level actions and captures both end-user and administrative activities. -C1 system logs are stored in OCSF (Open Cybersecurity Schema Framework), a leading open-source data format developed by AWS, IBM, and Splunk. Learn more about OCSF by viewing the [OCSF schema documentation](https://schema.ocsf.io). +C1.ai system logs are stored in OCSF (Open Cybersecurity Schema Framework), a leading open-source data format developed by AWS, IBM, and Splunk. Learn more about OCSF by viewing the [OCSF schema documentation](https://schema.ocsf.io). ## How do I get access to the system logs? -System logs are stored internally in C1 and can be [accessed via API](/conductorone-api/api) or exported to an [external data source](/product/admin/external-datasources) such as an S3 bucket or Azure Blob container. +System logs are stored internally in C1.ai and can be [accessed via API](/conductorone-api/api) or exported to an [external data source](/product/admin/external-datasources) such as an S3 bucket or Azure Blob container. ## Where can I see a list of all the API events included in the system logs? @@ -25,12 +25,12 @@ You can download our authoritative list of API events, which is presented in Sig * **JSON format**: Go to `/api/v1/ocsf-events.json` -## Sync C1 system logs into your SIEM +## Sync C1.ai system logs into your SIEM -Follow this process to import C1 logs into your security information and event management (SIEM) platform. +Follow this process to import C1.ai logs into your security information and event management (SIEM) platform. -This task requires the **Super Administrator** role in C1. +This task requires the **Super Administrator** role in C1.ai. ### Step 1: Create an external data source @@ -40,7 +40,7 @@ If you haven't already done so, [create an external data source](/product/admin/ **Reusing an existing external data source?** -If you're reusing an existing data source that you've already created and integrated with C1, ensure that it was created with the ability to accept writes. For example, for S3 buckets, the policy will require the `"s3:PutObject"` permission. +If you're reusing an existing data source that you've already created and integrated with C1.ai, ensure that it was created with the ability to accept writes. For example, for S3 buckets, the policy will require the `"s3:PutObject"` permission. ### Step 2: Create a system log exporter @@ -76,21 +76,21 @@ A partial list of SIEM directions: - [Import S3 buckets into Splunk](https://splunkbase.splunk.com/app/1876) - [Import S3 buckets into CrowdStrike Falcon Next-Gen SIEM](https://marketplace.crowdstrike.com/listings/amazon-s3-data-connector) -#### Using C1 logs with CrowdStrike Falcon Next-Gen SIEM +#### Using C1.ai logs with CrowdStrike Falcon Next-Gen SIEM Ingesting an S3 bucket via the Amazon S3 Data Connector requires a **Falcon Next-Gen SIEM** subscription. Without it, the connector appears in the CrowdStrike Store but can't be configured. -Because C1 system logs are OCSF, they map cleanly to CrowdStrike's data model. When you set up the [Amazon S3 Data Connector](https://marketplace.crowdstrike.com/listings/amazon-s3-data-connector) to ingest your external data source, select an **OCSF parser** so events normalize to the CrowdStrike Parsing Standard (CPS) rather than authoring your own. CrowdStrike's [Amazon Security Lake Data Connector](https://marketplace.crowdstrike.com/listings/amazon-security-lake-data-connector/) includes an OCSF-to-CPS parser you can reference, and Next-Gen SIEM can also generate a parser for you. +Because C1.ai system logs are OCSF, they map cleanly to CrowdStrike's data model. When you set up the [Amazon S3 Data Connector](https://marketplace.crowdstrike.com/listings/amazon-s3-data-connector) to ingest your external data source, select an **OCSF parser** so events normalize to the CrowdStrike Parsing Standard (CPS) rather than authoring your own. CrowdStrike's [Amazon Security Lake Data Connector](https://marketplace.crowdstrike.com/listings/amazon-security-lake-data-connector/) includes an OCSF-to-CPS parser you can reference, and Next-Gen SIEM can also generate a parser for you. -The connector listing covers the AWS resources you'll create (an SQS queue for object-created notifications and an IAM role CrowdStrike assumes) and the current console steps. Once ingested, C1 access events are searchable and alertable alongside the rest of your Falcon telemetry. +The connector listing covers the AWS resources you'll create (an SQS queue for object-created notifications and an IAM role CrowdStrike assumes) and the current console steps. Once ingested, C1.ai access events are searchable and alertable alongside the rest of your Falcon telemetry. ## Reading system log files -C1 system logs use the Open Cybersecurity Schema Framework (OCSF) to format log events. Check out the OCSF documentation for full details of [OCSF API activity formatting](https://schema.ocsf.io/1.3.0/classes/api_activity?extensions=), but here are a few key details to help you quickly make sense of C1 system log output. +C1.ai system logs use the Open Cybersecurity Schema Framework (OCSF) to format log events. Check out the OCSF documentation for full details of [OCSF API activity formatting](https://schema.ocsf.io/1.3.0/classes/api_activity?extensions=), but here are a few key details to help you quickly make sense of C1.ai system log output. -- **"activity_id"**: The "activity_id" entry in a log line tells you what type of API call activity triggered the event. By filtering logs by these activity IDs, you can zero in on key types of activity in the C1 system. +- **"activity_id"**: The "activity_id" entry in a log line tells you what type of API call activity triggered the event. By filtering logs by these activity IDs, you can zero in on key types of activity in the C1.ai system. - "activity_id":1 - "Create" activity - "activity_id":2 - "Read" activity @@ -123,7 +123,7 @@ API Activity events also now include `class_name` and `category_name` captions. ### Identity & Access events -C1 emits four Identity & Access event classes in addition to existing event types: +C1.ai emits four Identity & Access event classes in addition to existing event types: | class_uid | Event type | Reports | | :--- | :--- | :--- | diff --git a/product/admin/tool-call-hooks.mdx b/product/admin/tool-call-hooks.mdx index 4c8f9f08..3609d95c 100644 --- a/product/admin/tool-call-hooks.mdx +++ b/product/admin/tool-call-hooks.mdx @@ -1,14 +1,14 @@ --- title: Tool call hooks description: Intercept MCP tool calls with built-in patterns or custom functions to redact, modify, or block calls at runtime. -og:title: Tool call hooks - C1 docs +og:title: Tool call hooks - C1.ai docs og:description: Intercept MCP tool calls with built-in patterns or custom functions to redact, modify, or block calls at runtime. --- {/* Editor Refresh: 2026-09-02 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. Tool call hooks are interception points that run on every governed MCP tool call. They can observe a call, modify its inputs or outputs, or deny it outright. Use them to redact sensitive data, cap risky parameters, or enforce conditional access rules that see beyond the entitlement grant model. @@ -19,7 +19,7 @@ Each hook fires on one of three events: | Event | When it runs | What it can do | | :--- | :--- | :--- | -| **Pre-tool use** | Before C1 forwards the call to the MCP server | Inspect or rewrite the input, or deny the call | +| **Pre-tool use** | Before C1.ai forwards the call to the MCP server | Inspect or rewrite the input, or deny the call | | **Post-tool use** | After the MCP server returns | Inspect or rewrite the output, or deny the response from reaching the client | | **Pre-output** | Before a chunk of the assistant's generated response leaves the process (Slack or web chat). No tool call is involved. | Inspect or rewrite the outgoing response chunk, or withhold it | @@ -101,7 +101,7 @@ What events you can pick between depends on the hook type: | **Built-in pattern** | Fixed by the pattern you pick. Most patterns lock to a single event, greyed out once selected — the **Event** column in [Built-in patterns](#built-in-patterns) is the authoritative list. **Link filter** is the one pattern that offers a real choice, between **Post-tool use** and **Pre-output**. | | **Patch tool input** | Locked to **Pre-tool use**. | -C1 rejects a mismatch between the selected event and pattern when you save the hook. +C1.ai rejects a mismatch between the selected event and pattern when you save the hook. **Custom function hooks cannot use the Pre-output event.** Saving one is rejected. Pre-output is reachable only through a built-in pattern: **Block output** (locked to it) or **Link filter** (selectable). @@ -168,7 +168,7 @@ Where a pattern takes a list, a value you configure **replaces** the default lis ## Custom function hooks -When the built-in patterns don't fit, write a [function](/product/admin/functions) and attach it to a hook. C1 invokes the function with a JSON payload describing the call and uses the return value to decide whether to allow, modify, or deny. +When the built-in patterns don't fit, write a [function](/product/admin/functions) and attach it to a hook. C1.ai invokes the function with a JSON payload describing the call and uses the return value to decide whether to allow, modify, or deny. See the [Functions overview](/product/admin/functions) and [Create a function](/product/admin/functions-create) for how to author and deploy a function. diff --git a/product/admin/tools-and-toolsets.mdx b/product/admin/tools-and-toolsets.mdx index 36c7b57c..4d361adf 100644 --- a/product/admin/tools-and-toolsets.mdx +++ b/product/admin/tools-and-toolsets.mdx @@ -1,14 +1,14 @@ --- title: Govern tools and toolsets description: Review discovered tools, approve and classify them, bundle them into toolsets, and bind toolsets to access profiles. -og:title: Govern tools and toolsets - C1 docs +og:title: Govern tools and toolsets - C1.ai docs og:description: Review discovered tools, approve and classify them, bundle them into toolsets, and bind toolsets to access profiles. --- {/* Editor Refresh: 2026-09-02 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. After registering an MCP server, every tool it exposes starts life as **Unset**. This page covers reviewing those tools, approving the safe ones, classifying them, bundling them into toolsets, and binding toolsets to access profiles so end users can request them. @@ -30,11 +30,11 @@ Click the **Tools** tab. -The list shows every tool C1 has discovered, its current state, classification, and last-used timestamp. +The list shows every tool C1.ai has discovered, its current state, classification, and last-used timestamp. ### Classify a tool -C1 captures a single **Classification** field per tool. It isn't enforced at call time on its own, but it isn't purely decorative either: the auto-maintained **Read tools** toolset (see [C1-maintained toolsets](#c1-maintained-toolsets) below) selects its members by `Classification = Read`, so classifying a tool as Read widens what that toolset grants. Classification is also readable by [tool call hooks](/product/admin/tool-call-hooks) as `context.classification`, and it's the field the Write authorization hook pattern blocks against. +C1.ai captures a single **Classification** field per tool. It isn't enforced at call time on its own, but it isn't purely decorative either: the auto-maintained **Read tools** toolset (see [C1.ai-maintained toolsets](#c1-maintained-toolsets) below) selects its members by `Classification = Read`, so classifying a tool as Read widens what that toolset grants. Classification is also readable by [tool call hooks](/product/admin/tool-call-hooks) as `context.classification`, and it's the field the Write authorization hook pattern blocks against. | Value | Meaning | | :--- | :--- | @@ -92,7 +92,7 @@ Each approved tool has overrides that take precedence over the tenant defaults. ### Tool lifecycle on re-sync -C1 periodically re-runs tool discovery against each registered MCP server. When the inventory changes: +C1.ai periodically re-runs tool discovery against each registered MCP server. When the inventory changes: - **New tool detected** — added to the list as **Unset**. - **Existing tool changes** (description, parameters) — the change is recorded; the tool keeps its current state and classification. @@ -102,9 +102,9 @@ C1 periodically re-runs tool discovery against each registered MCP server. When A **toolset** is a named bundle of approved tools. -### C1-maintained toolsets +### C1.ai-maintained toolsets -C1 ships and auto-maintains two toolsets per connector: +C1.ai ships and auto-maintains two toolsets per connector: - **All approved tools** — every tool in **Approved** state on that connector. - **Read tools** — every **Approved** tool on that connector with Classification = Read. @@ -139,7 +139,7 @@ To edit a toolset, open it and add or remove tools. Changes propagate to any acc ## Bind a toolset to an access profile -AIAM uses C1's existing access profile mechanism. A toolset becomes requestable by end users only after it is bound to an access profile. There are two ways to do this. +AIAM uses C1.ai's existing access profile mechanism. A toolset becomes requestable by end users only after it is bound to an access profile. There are two ways to do this. ### Option 1: From the toolset @@ -158,14 +158,14 @@ The toolset's tools are now included in that profile. ### Option 2: From the access profile -You can also start from the access profile side and add toolsets as entitlements. This is required for C1-maintained toolsets and is the better path when you're setting up access profiles from scratch or adding multiple toolsets to a single profile. +You can also start from the access profile side and add toolsets as entitlements. This is required for C1.ai-maintained toolsets and is the better path when you're setting up access profiles from scratch or adding multiple toolsets to a single profile. Go to **Access profiles** and either create a new profile or open an existing one. -Add the toolset as an entitlement — both C1-maintained toolsets (**All approved tools**, **Read tools**) and custom toolsets appear as options. +Add the toolset as an entitlement — both C1.ai-maintained toolsets (**All approved tools**, **Read tools**) and custom toolsets appear as options. Set the access policy on the profile (auto-approve, JIT with expiry, or approval required). diff --git a/product/admin/user-roles.mdx b/product/admin/user-roles.mdx index ec2c8820..e691390a 100644 --- a/product/admin/user-roles.mdx +++ b/product/admin/user-roles.mdx @@ -1,32 +1,32 @@ --- title: User roles -og:title: User roles and permissions - C1 docs -og:description: C1 user roles control who can access and manage what in your tenant. Assign roles to add an administrator, promote someone to Super Administrator, or limit a user to read-only or end-user access. -description: C1 user roles control who can access and manage what in your tenant. Assign roles to add an administrator, promote someone to Super Administrator, or limit a user to read-only or end-user access. +og:title: User roles and permissions - C1.ai docs +og:description: C1.ai user roles control who can access and manage what in your tenant. Assign roles to add an administrator, promote someone to Super Administrator, or limit a user to read-only or end-user access. +description: C1.ai user roles control who can access and manage what in your tenant. Assign roles to add an administrator, promote someone to Super Administrator, or limit a user to read-only or end-user access. sidebarTitle: User roles --- {/* Editor Refresh: 2026-05-15 */} ## Default user roles -The person who initially sets C1 up for your company is given the **Super Administrator** role. After that, all users who sign into C1 for the first time are automatically given the **Basic User** role. Read more about these and the other available user roles below. +The person who initially sets C1.ai up for your company is given the **Super Administrator** role. After that, all users who sign into C1.ai for the first time are automatically given the **Basic User** role. Read more about these and the other available user roles below. You can keep these roles as-is, or assign new roles depending on what each user needs to get done. Users can have more than one role, and a user is granted all the permissions of every role they're assigned. ## Hidden information based on role -If your user role doesn't grant you access to certain information, C1 hides that information rather than showing it. Hidden fields appear blank, the same way they would if that information were simply unavailable. +If your user role doesn't grant you access to certain information, C1.ai hides that information rather than showing it. Hidden fields appear blank, the same way they would if that information were simply unavailable. For example, a **Basic User** can't view another user's profile details unless it's their own record or someone they manage, but users with an administrator-level role can view this information for any user. -When a page contains hidden information, C1 shows a toast message: "Some information on this page is hidden based on your permissions." +When a page contains hidden information, C1.ai shows a toast message: "Some information on this page is hidden based on your permissions." ## Assign a new user role to a user To change a user's roles — including making them an administrator or promoting them to Super Administrator — use the **Users** page. Users can have more than one role and receive all the permissions of every role they're assigned. See [Administrator user roles](#administrator-user-roles) for what each admin role can do. -This task requires the **Super Administrator** role in C1. +This task requires the **Super Administrator** role in C1.ai. @@ -52,7 +52,7 @@ Click **Save**. Changing roles for a group of users one at a time is tedious when onboarding a team or correcting assignments in bulk. Select multiple users on the **Users** page and assign roles to all of them in a single action. The selected roles replace all existing roles for every selected user. -This task requires the **Super Administrator** role in C1. +This task requires the **Super Administrator** role in C1.ai. @@ -77,13 +77,13 @@ The new roles take effect immediately for all selected users. ## End-user user roles -C1 has two user roles tailored to end users and scoped to the work they do. +C1.ai has two user roles tailored to end users and scoped to the work they do. ### Basic User Users with this role can: -- View the C1 home page +- View the C1.ai home page - Complete assigned access review tasks - Request personal access to apps and resources - (Managers only) request access to apps and resources for direct reports @@ -101,7 +101,7 @@ Users with this role can: ## Administrator user roles -Users with an administrator-level user role can also access the **Admin** section of C1. +Users with an administrator-level user role can also access the **Admin** section of C1.ai. | | Access Request Admin | AI Governance Admin | Application Admin | Campaign Admin | Connector Admin | Read-Only Super Admin | Super Admin | | :--- | :--- | :--- | :--- | :--- | :--- | :--- | :--- | @@ -183,11 +183,11 @@ Users with this role can: ### Read-Only Administrator -This is a special role, intended for auditors or other individuals who need visibility into C1 without the ability to make changes. +This is a special role, intended for auditors or other individuals who need visibility into C1.ai without the ability to make changes. Users with this role can: -- View C1 assets: +- View C1.ai assets: - Campaigns - Applications - Conflict monitors @@ -209,7 +209,7 @@ Users with this role can: - Do everything listed in the **Basic User** role - Request access to apps and resources for any user -- View, create, and manage all C1 assets: +- View, create, and manage all C1.ai assets: - Campaigns - Applications - Conflict monitors @@ -225,7 +225,7 @@ Users with this role can: - View and work with access explorer and access graph - Create and download reports - View, create, and manage request forms -- View, create, and manage all C1 settings +- View, create, and manage all C1.ai settings - View all tenant secret metadata (not content), revoke any secret, access secret audit logs diff --git a/product/admin/vaults.mdx b/product/admin/vaults.mdx index 12349779..f53ffbea 100644 --- a/product/admin/vaults.mdx +++ b/product/admin/vaults.mdx @@ -1,22 +1,22 @@ --- title: Set up credential stores -og:title: Set up credential stores - C1 -og:description: Securely manage and distribute the initial passwords for application accounts provisioned through C1. -description: Securely manage and distribute the initial passwords for application accounts provisioned through C1. +og:title: Set up credential stores - C1.ai +og:description: Securely manage and distribute the initial passwords for application accounts provisioned through C1.ai. +description: Securely manage and distribute the initial passwords for application accounts provisioned through C1.ai. sidebarTitle: Provisioned credentials --- {/* Editor Refresh: 2026-01-09 */} -## How are credential stores used in C1? +## How are credential stores used in C1.ai? -When you use C1 to provision new application accounts through connectors that support [automatic account provisioning](/product/admin/account-provisioning), these new accounts are often created with a starter password. Credential stores provide a secure location to collect these initial passwords. This allows credential store owners to easily distribute them to the owners of the new accounts, whether through email, Slack, or your preferred communication method. +When you use C1.ai to provision new application accounts through connectors that support [automatic account provisioning](/product/admin/account-provisioning), these new accounts are often created with a starter password. Credential stores provide a secure location to collect these initial passwords. This allows credential store owners to easily distribute them to the owners of the new accounts, whether through email, Slack, or your preferred communication method. For added convenience, the new account password is also included in the entry for the new account on the user's **Requests** page. The account recipient can always decrypt their own password. Credential store owners can decrypt passwords on behalf of other users. ## Set up a new credential store -This task requires the **Super Administrator** role in C1. +This task requires the **Super Administrator** role in C1.ai. diff --git a/product/admin/webhooks-inbound.mdx b/product/admin/webhooks-inbound.mdx index 08c8d54c..7be38675 100644 --- a/product/admin/webhooks-inbound.mdx +++ b/product/admin/webhooks-inbound.mdx @@ -1,14 +1,14 @@ --- title: "Inbound webhooks" -og:title: "Inbound webhooks - C1 docs" -og:description: "Configure inbound webhooks to let external systems trigger C1 automations via authenticated HTTP requests." -description: "Configure inbound webhooks to let external systems trigger C1 automations via authenticated HTTP requests." +og:title: "Inbound webhooks - C1.ai docs" +og:description: "Configure inbound webhooks to let external systems trigger C1.ai automations via authenticated HTTP requests." +description: "Configure inbound webhooks to let external systems trigger C1.ai automations via authenticated HTTP requests." sidebarTitle: "Inbound webhooks" --- {/* Editor Refresh: 2026-02-27 */} -Inbound webhooks let external systems trigger [automations](/product/admin/automations) in C1 by sending authenticated HTTP POST requests, so events in your HRIS, ticketing system, or CI/CD pipeline can initiate access management workflows automatically. +Inbound webhooks let external systems trigger [automations](/product/admin/automations) in C1.ai by sending authenticated HTTP POST requests, so events in your HRIS, ticketing system, or CI/CD pipeline can initiate access management workflows automatically. For example, you can use inbound webhooks to: @@ -20,9 +20,9 @@ For example, you can use inbound webhooks to: ## How it works 1. You create an automation with an **Incoming webhook** trigger, choosing either HMAC or JWT authentication. -2. C1 generates a unique webhook listener endpoint URL. +2. C1.ai generates a unique webhook listener endpoint URL. 3. Your external system sends authenticated POST requests to that URL with a JSON payload. -4. C1 validates the request's authentication and runs the automation, passing the webhook payload as context data that can be used in automation steps. +4. C1.ai validates the request's authentication and runs the automation, passing the webhook payload as context data that can be used in automation steps. ``` External system C1 @@ -42,7 +42,7 @@ External system C1 ## Set up an inbound webhook -A user with the **Super Admin** role in C1 must complete this task. +A user with the **Super Admin** role in C1.ai must complete this task. @@ -55,13 +55,13 @@ Click **Set automation trigger** and select **Incoming webhook**. Choose an authentication method: -- **HMAC** (recommended for simplicity): C1 generates a shared secret. You use this secret to sign each request. -- **JWT**: You provide a JWKS URL where C1 can fetch your public keys. You sign each request with your private key. +- **HMAC** (recommended for simplicity): C1.ai generates a shared secret. You use this secret to sign each request. +- **JWT**: You provide a JWKS URL where C1.ai can fetch your public keys. You sign each request with your private key. See [Authentication methods](#authentication-methods) for details on each option. -Save the trigger configuration. C1 generates the full webhook endpoint URL and displays it in the drawer, ready to copy: +Save the trigger configuration. C1.ai generates the full webhook endpoint URL and displays it in the drawer, ready to copy: ``` https://{your-tenant}.conductor.one/api/v1/webhooks/incoming/{listener_id} @@ -77,7 +77,7 @@ Configure your external system to send POST requests to the webhook URL with the ## Authentication methods -Every inbound webhook request must be authenticated. C1 supports two methods: +Every inbound webhook request must be authenticated. C1.ai supports two methods: ### HMAC authentication @@ -85,9 +85,9 @@ HMAC (Hash-based Message Authentication Code) uses a shared secret to sign reque **How it works:** -1. When you configure the webhook trigger, C1 generates a 256-bit secret and provides it as a base64url-encoded string. +1. When you configure the webhook trigger, C1.ai generates a 256-bit secret and provides it as a base64url-encoded string. 2. For each request, you compute an HMAC-SHA256 signature over the timestamp, event ID, and request body. -3. C1 verifies the signature against the stored secret. +3. C1.ai verifies the signature against the stored secret. **Computing the signature:** @@ -131,7 +131,7 @@ resp = requests.post( ### JWT authentication -JWT (JSON Web Token) authentication uses public key cryptography. You host a JWKS (JSON Web Key Set) endpoint, and C1 fetches your public keys to verify request signatures. +JWT (JSON Web Token) authentication uses public key cryptography. You host a JWKS (JSON Web Key Set) endpoint, and C1.ai fetches your public keys to verify request signatures. **Supported algorithms:** RS256, ES256, EdDSA @@ -140,7 +140,7 @@ JWT (JSON Web Token) authentication uses public key cryptography. You host a JWK 1. You generate a key pair and host the public key as a JWKS endpoint. 2. When you configure the webhook trigger, you provide the JWKS URL. 3. For each request, you create a JWT with specific claims and sign it with your private key. -4. C1 fetches your JWKS and verifies the JWT signature and claims. +4. C1.ai fetches your JWKS and verifies the JWT signature and claims. @@ -187,7 +187,7 @@ In the automation's webhook trigger settings, select **JWT authentication** and | Claim | Description | | :--- | :--- | -| `sub` | Your C1 tenant base URL (e.g., `https://your-tenant.conductor.one`) | +| `sub` | Your C1.ai tenant base URL (e.g., `https://your-tenant.conductor.one`) | | `aud` | The full webhook endpoint URL (e.g., `https://your-tenant.conductor.one/api/v1/webhooks/incoming/{listener_id}`) | | `exp` | Token expiration (must be within 10 minutes of the current time) | | `jti` | A UUID v4 matching the `Webhook-Event-Id` header | @@ -257,7 +257,7 @@ https://{your-tenant}.conductor.one/api/v1/webhooks/incoming/{listener_id} | Header | Description | | :--- | :--- | -| `Webhook-Timestamp` | Current Unix timestamp in seconds. Must be within 5 minutes of C1's server time. | +| `Webhook-Timestamp` | Current Unix timestamp in seconds. Must be within 5 minutes of C1.ai's server time. | | `Webhook-Event-Id` | A UUID v4 that uniquely identifies this event. Used for idempotency. | | `Authorization` | (JWT auth only) `Bearer {jwt_token}` | | `Webhook-Signature` | (HMAC auth only) Base64url-encoded HMAC-SHA256 signature (no padding). | @@ -321,7 +321,7 @@ Inbound webhooks include several layers of protection against replay attacks and ### Idempotency -Each request includes a `Webhook-Event-Id` header with a UUID v4. If C1 receives a second request with the same event ID for the same listener, it returns a `409` response and does not re-run the automation. Event records are retained for 7 days. +Each request includes a `Webhook-Event-Id` header with a UUID v4. If C1.ai receives a second request with the same event ID for the same listener, it returns a `409` response and does not re-run the automation. Event records are retained for 7 days. ### Timestamp validation @@ -336,7 +336,7 @@ You can optionally restrict inbound webhooks to specific source IP ranges by con Both authentication methods verify the integrity of the request body: - **HMAC**: The body is included in the HMAC signature input, so any modification invalidates the signature. -- **JWT**: The `htb_s256` claim contains a SHA-256 hash of the body, verified by C1. +- **JWT**: The `htb_s256` claim contains a SHA-256 hash of the body, verified by C1.ai. ## Use webhook data in automation steps diff --git a/product/admin/webhooks.mdx b/product/admin/webhooks.mdx index 9ecc7b90..624e1dbc 100644 --- a/product/admin/webhooks.mdx +++ b/product/admin/webhooks.mdx @@ -1,15 +1,15 @@ --- title: Configure webhooks -og:title: Configure webhooks - C1 -og:description: Set up outbound webhooks in C1 to extend workflows across multiple tools, and learn how to respond to webhooks synchronously or asynchronously. -description: Set up outbound webhooks in C1 to extend workflows across multiple tools, and learn how to respond to webhooks synchronously or asynchronously. +og:title: Configure webhooks - C1.ai +og:description: Set up outbound webhooks in C1.ai to extend workflows across multiple tools, and learn how to respond to webhooks synchronously or asynchronously. +description: Set up outbound webhooks in C1.ai to extend workflows across multiple tools, and learn how to respond to webhooks synchronously or asynchronously. sidebarTitle: Webhooks --- {/* Editor Refresh: 2026-07-20 */} -Use webhooks to extend your access control workflows across the tools your organization uses — create service desk tickets, call internal APIs, send notifications, or drive custom provisioning and approval logic. C1 sends each webhook as an authenticated HTTP POST request to a URL you configure, and your endpoint can answer immediately or complete the work later using a callback. +Use webhooks to extend your access control workflows across the tools your organization uses — create service desk tickets, call internal APIs, send notifications, or drive custom provisioning and approval logic. C1.ai sends each webhook as an authenticated HTTP POST request to a URL you configure, and your endpoint can answer immediately or complete the work later using a callback. -C1 fires outbound webhooks in these situations: +C1.ai fires outbound webhooks in these situations: * **Provisioning:** An entitlement uses a webhook as its [provisioning strategy](/product/admin/provisioning), and access was approved. @@ -20,12 +20,12 @@ C1 fires outbound webhooks in these situations: * **Testing:** You manually send a test webhook. -This page covers *outbound* webhooks (C1 calling your systems). To let external systems trigger C1 automations instead, see [Inbound webhooks](/product/admin/webhooks-inbound). +This page covers *outbound* webhooks (C1.ai calling your systems). To let external systems trigger C1.ai automations instead, see [Inbound webhooks](/product/admin/webhooks-inbound). ## Add a new webhook -Create the webhook in C1 first, then reference it from a provisioning policy, policy step, or automation. +Create the webhook in C1.ai first, then reference it from a provisioning policy, policy step, or automation. @@ -41,7 +41,7 @@ Give the webhook a name and description so that you and your colleagues can easi Enter the URL for the webhook. See [Webhook URL requirements](#webhook-url-requirements). -**Optional.** Set **Callback timeout (days)**, which controls how long C1 waits for an [asynchronous callback](#respond-asynchronously-202-and-callback) before failing the webhook. Choose from 1 to 30 days. The default is 8 days. +**Optional.** Set **Callback timeout (days)**, which controls how long C1.ai waits for an [asynchronous callback](#respond-asynchronously-202-and-callback) before failing the webhook. Choose from 1 to 30 days. The default is 8 days. Click **Save**. The new webhook is set up and assigned an ID. Click **View history** to see the webhook's recent activity. @@ -54,15 +54,15 @@ Click **Save**. The new webhook is set up and assigned an ID. Click **View histo * The URL must not contain a username or password. -* The URL must resolve to a publicly routable address. C1 blocks requests to private, loopback, and link-local IP ranges, including after redirects. +* The URL must resolve to a publicly routable address. C1.ai blocks requests to private, loopback, and link-local IP ranges, including after redirects. ### Test a webhook -Here's how to test a webhook once you've set it up in C1: +Here's how to test a webhook once you've set it up in C1.ai: -On the **Webhooks** tab, click the more actions (**...**) menu and select **Test webhook**. C1 sends a `c1.webhooks.v1.PayloadTest` event with an empty payload through the same signed delivery pipeline as production events. +On the **Webhooks** tab, click the more actions (**...**) menu and select **Test webhook**. C1.ai sends a `c1.webhooks.v1.PayloadTest` event with an empty payload through the same signed delivery pipeline as production events. Click **View history** to see details of the webhook's payload and status. @@ -120,7 +120,7 @@ Here's an explanation of the fields in the envelope: ## Webhook authentication -Webhooks include the `Authorization` header set with a bearer token that can be used to authenticate that the webhook came from C1. This bearer token is a JWT that can be verified using the JWKS available at `https://.conductor.one/auth/v1/jwks`. Tokens are signed with RS256, ES256, or EdDSA, depending on your tenant's signing key. After the token is verified, you can validate the request body by comparing its SHA-256 checksum against the `htb_s256` claim included in the token. +Webhooks include the `Authorization` header set with a bearer token that can be used to authenticate that the webhook came from C1.ai. This bearer token is a JWT that can be verified using the JWKS available at `https://.conductor.one/auth/v1/jwks`. Tokens are signed with RS256, ES256, or EdDSA, depending on your tenant's signing key. After the token is verified, you can validate the request body by comparing its SHA-256 checksum against the `htb_s256` claim included in the token. The payload of the JWT looks like this: @@ -142,7 +142,7 @@ The payload of the JWT looks like this: | Claim | Description | | :--- | :--- | | `aud` | The hostname of the webhook's destination URL. | -| `c1typ` | The type of token from C1. This will be `wh` for webhooks. | +| `c1typ` | The type of token from C1.ai. This will be `wh` for webhooks. | | `exp` | The expiration time. Webhook tokens are short-lived: they expire two minutes after they are issued. | | `htb_s256` | The base64-encoded SHA-256 checksum of the request body. This matches the `Content-Digest` header. | | `htm` | The HTTP method that the webhook was delivered with. Always `POST`. | @@ -154,11 +154,11 @@ The payload of the JWT looks like this: ## Responding to webhooks -Your endpoint's HTTP status code tells C1 whether you're answering the webhook immediately or completing it later: +Your endpoint's HTTP status code tells C1.ai whether you're answering the webhook immediately or completing it later: -* **Respond synchronously** by returning any 2xx status code *except* 202 (typically 200) with a [response document](#webhook-response-formats) as the response body. C1 processes your response right away, and the webhook is complete. +* **Respond synchronously** by returning any 2xx status code *except* 202 (typically 200) with a [response document](#webhook-response-formats) as the response body. C1.ai processes your response right away, and the webhook is complete. -* **Respond asynchronously** by returning HTTP status code **202 Accepted**. This tells C1 that you've received the webhook and will finish the work later. C1 ignores the response body and waits for you to POST a response document to the webhook's callback URL. +* **Respond asynchronously** by returning HTTP status code **202 Accepted**. This tells C1.ai that you've received the webhook and will finish the work later. C1.ai ignores the response body and waits for you to POST a response document to the webhook's callback URL. Synchronous responses are the simplest option when your endpoint can decide immediately — for example, a service that auto-approves requests based on your own business rules. Asynchronous responses are the right choice when the outcome depends on work that takes longer than a single HTTP request, such as waiting for a service desk ticket to be closed or for a human to act in another tool. @@ -189,19 +189,19 @@ When sending the callback: * Each callback URL can be used only once. After a successful callback, or after the webhook expires, further POSTs to the URL are rejected with HTTP status code 400. -* C1 responds to a successful callback with HTTP status code 200. +* C1.ai responds to a successful callback with HTTP status code 200. You must send the callback before the webhook's **callback timeout** elapses (8 days by default, configurable per webhook up to 30 days). The timeout countdown starts when the webhook first fires. If no callback arrives in time, the webhook fails, and the originating task or automation step is treated as failed. -### How C1 interprets your response status +### How C1.ai interprets your response status -| Your endpoint's response | What C1 does | +| Your endpoint's response | What C1.ai does | | :--- | :--- | -| 2xx (except 202) | Delivery succeeded. C1 parses the response body as a synchronous response document. | -| 202 | Delivery succeeded. C1 waits for a response at the callback URL. | -| 410 | C1 treats the destination as permanently gone, and stops delivery immediately without retrying. | -| Any other status code | Delivery failed. C1 retries. | -| Timeout or connection error | Delivery failed. C1 retries. Each delivery attempt times out after 30 seconds. | +| 2xx (except 202) | Delivery succeeded. C1.ai parses the response body as a synchronous response document. | +| 202 | Delivery succeeded. C1.ai waits for a response at the callback URL. | +| 410 | C1.ai treats the destination as permanently gone, and stops delivery immediately without retrying. | +| Any other status code | Delivery failed. C1.ai retries. | +| Timeout or connection error | Delivery failed. C1.ai retries. Each delivery attempt times out after 30 seconds. | ## Webhook response formats @@ -309,9 +309,9 @@ Test webhooks don't require a meaningful response — returning any 2xx status c ## Delivery retries and failures -If a delivery attempt fails — the connection fails, the request times out after 30 seconds, or your endpoint returns a status code that isn't 2xx — C1 retries with a short randomized delay (3 to 15 seconds) between attempts, up to 50 attempts. Two situations stop delivery early: +If a delivery attempt fails — the connection fails, the request times out after 30 seconds, or your endpoint returns a status code that isn't 2xx — C1.ai retries with a short randomized delay (3 to 15 seconds) between attempts, up to 50 attempts. Two situations stop delivery early: -* Your endpoint returns **410 Gone**, which C1 treats as a permanent signal to stop. +* Your endpoint returns **410 Gone**, which C1.ai treats as a permanent signal to stop. * The webhook's callback timeout window elapses. @@ -327,13 +327,13 @@ When a webhook fails permanently, the failure is recorded and the originating wo Click **View history** on a webhook to see its recent deliveries, including each delivery's event type, status, payload, and per-attempt details such as the response status code. History is retained for the webhook's callback timeout window — 8 days by default, or up to 30 days if you've configured a longer callback timeout. -## Using a webhook to trigger a C1 automation +## Using a webhook to trigger a C1.ai automation -You can configure external systems to trigger C1 automations by sending authenticated HTTP requests to an inbound webhook endpoint. C1 supports both HMAC and JWT authentication methods. +You can configure external systems to trigger C1.ai automations by sending authenticated HTTP requests to an inbound webhook endpoint. C1.ai supports both HMAC and JWT authentication methods. For complete setup instructions, authentication details, code examples, and troubleshooting, see [Inbound webhooks](/product/admin/webhooks-inbound). -## Using webhooks for provisioning in C1 +## Using webhooks for provisioning in C1.ai You can configure an entitlement to use a webhook as its [provisioning strategy](/product/admin/access-requests#set-how-an-entitlement-is-provisioned), meaning that when access to the entitlement is approved, the webhook will automatically fire. The webhook can perform a wide variety of work to automate the provisioning process, such as: @@ -352,5 +352,5 @@ Because provisioning webhooks support [asynchronous responses](#respond-asynchro **Middleware for webhooks.** -Configuring a webhook for use between C1 and another tool often requires the creation of some middleware code. Integration Platform as a Service (iPaaS) tools such as Celigo, MuleSoft, or Zapier can help you to create this code. +Configuring a webhook for use between C1.ai and another tool often requires the creation of some middleware code. Integration Platform as a Service (iPaaS) tools such as Celigo, MuleSoft, or Zapier can help you to create this code. diff --git a/product/cli/c1i-agent-skills.mdx b/product/cli/c1i-agent-skills.mdx index 4b2befca..6f87174e 100644 --- a/product/cli/c1i-agent-skills.mdx +++ b/product/cli/c1i-agent-skills.mdx @@ -1,14 +1,14 @@ --- title: "Use c1i with AI coding agents" -og:title: Use c1i with AI coding agents | Docs - C1 -og:description: Set up c1i as a skill for Claude Code, Cursor, and other AI coding agents so they can manage users, apps, entitlements, and access requests in C1. -description: Set up c1i as a skill for Claude Code, Cursor, and other AI coding agents so they can manage users, apps, entitlements, and access requests in C1. +og:title: Use c1i with AI coding agents | Docs - C1.ai +og:description: Set up c1i as a skill for Claude Code, Cursor, and other AI coding agents so they can manage users, apps, entitlements, and access requests in C1.ai. +description: Set up c1i as a skill for Claude Code, Cursor, and other AI coding agents so they can manage users, apps, entitlements, and access requests in C1.ai. sidebarTitle: "Use c1i with AI agents" --- {/* Editor Refresh: 2026-05-07 */} -c1i is designed from the ground up for AI agents. The `c1i docs skill` command exports a self-contained skill file that teaches your AI coding agent how to use every c1i command, discover API endpoints, and manage C1 resources — without needing external documentation. +c1i is designed from the ground up for AI agents. The `c1i docs skill` command exports a self-contained skill file that teaches your AI coding agent how to use every c1i command, discover API endpoints, and manage C1.ai resources — without needing external documentation. ## What is a skill file? @@ -19,7 +19,7 @@ A **skill file** is a structured markdown document that gives an AI coding agent - Common API endpoints and pagination patterns - Authentication setup -When you add this skill file to your agent's context, the agent can manage users, apps, entitlements, tasks, and access requests in C1 through natural-language instructions. +When you add this skill file to your agent's context, the agent can manage users, apps, entitlements, tasks, and access requests in C1.ai through natural-language instructions. ## Generate the skill file @@ -216,7 +216,7 @@ The agent runs `c1i tasks list --state=open --assigned-to-me`, filters the resul "Find all unmapped accounts in the Okta app and list their details" ``` -The agent runs `c1i accounts list --app-id= --unmapped-only` to surface accounts that haven't been linked to C1 users. +The agent runs `c1i accounts list --app-id= --unmapped-only` to surface accounts that haven't been linked to C1.ai users. ## Keep the skill file up to date diff --git a/product/cli/c1i-commands.mdx b/product/cli/c1i-commands.mdx index b15cc578..287c539f 100644 --- a/product/cli/c1i-commands.mdx +++ b/product/cli/c1i-commands.mdx @@ -1,6 +1,6 @@ --- title: c1i command reference -og:title: c1i command reference | Docs - C1 +og:title: c1i command reference | Docs - C1.ai og:description: A comprehensive reference for all c1i commands, subcommands, and flags. description: A comprehensive reference for all c1i commands, subcommands, and flags. sidebarTitle: "c1i commands" @@ -18,7 +18,7 @@ Run `c1i --help` or `c1i -h` for help with a specific comman ## Overview -c1i interacts with the C1 API to manage users, apps, accounts, entitlements, tasks, and access requests. +c1i interacts with the C1.ai API to manage users, apps, accounts, entitlements, tasks, and access requests. **Usage:** @@ -30,7 +30,7 @@ c1i [command] | :--- | :--- | :--- | | `docs` | `search` `page` `endpoints` `endpoint` `openapi` `skill` | Explore API documentation (no auth required). | | `auth` | `login` `logout` `status` `whoami` `token` | Manage authentication. | -| `users` | `list` | Search and list C1 users. | +| `users` | `list` | Search and list C1.ai users. | | `apps` | `list` `create` `delete` `set-owners` | Manage applications. | | `accounts` | `list` `set-owner` | Manage application accounts. | | `entitlements` | `list` | Search and list application entitlements. | @@ -38,8 +38,8 @@ c1i [command] | `requests` | `create grant` `create revoke` | Create access requests. | | `connectors` | `list` | List connectors. | | `policies` | `list` `search` `get` `create` `update` `delete` `validate-cel` | Manage policies (approval, provisioning, and certification workflows). | -| `mcp` | `gateway list-tools` `gateway call` | Call the C1 MCP gateway directly (list and invoke tools end to end). | -| `api` | | Make raw C1 API requests. | +| `mcp` | `gateway list-tools` `gateway call` | Call the C1.ai MCP gateway directly (list and invoke tools end to end). | +| `api` | | Make raw C1.ai API requests. | | `version` | | Print the c1i version. | | `completion` | `bash` `fish` `powershell` `zsh` | Generate a shell completion script. | @@ -47,12 +47,12 @@ c1i [command] | Flag | Description | | :--- | :--- | -| `--url string` | C1 tenant URL. | +| `--url string` | C1.ai tenant URL. | | `-h`, `--help` | Help for any command. | ## Docs -Explore C1 API documentation and schemas. These commands do **not** require authentication. +Explore C1.ai API documentation and schemas. These commands do **not** require authentication. **Usage:** @@ -62,7 +62,7 @@ c1i docs [command] | Subcommand | Description | | :--- | :--- | -| `search` | Search C1 documentation by keyword. | +| `search` | Search C1.ai documentation by keyword. | | `page` | Fetch a full documentation page. | | `endpoints` | List all API endpoints. | | `endpoint` | Show the full request/response schema for an endpoint. | @@ -71,7 +71,7 @@ c1i docs [command] ### `search` -Search C1 documentation by keyword. +Search C1.ai documentation by keyword. **Usage:** @@ -174,7 +174,7 @@ c1i auth [command] ### `login` -Authenticate to C1. Opens a browser for OAuth device flow authorization, or accepts credentials directly. +Authenticate to C1.ai. Opens a browser for OAuth device flow authorization, or accepts credentials directly. **Usage:** @@ -184,7 +184,7 @@ c1i auth login [flags] | Flag | Description | | :--- | :--- | -| `--url string` | C1 tenant URL. | +| `--url string` | C1.ai tenant URL. | | `--client-id string` | Client ID (for non-interactive auth). | | `--client-secret string` | Client secret (for non-interactive auth). | @@ -212,7 +212,7 @@ c1i auth logout ### `status` -Check whether valid C1 credentials are stored and working. Reports which source (environment, keyring, or file) served the active credentials. +Check whether valid C1.ai credentials are stored and working. Reports which source (environment, keyring, or file) served the active credentials. **Usage:** @@ -257,7 +257,7 @@ curl -H "Authorization: Bearer $(c1i auth token)" \ https://your-tenant.conductor.one/api/v1/apps ``` -The token is audience-scoped to the C1 API host. +The token is audience-scoped to the C1.ai API host. ## Credential storage @@ -274,11 +274,11 @@ The file fallback is used automatically when no OS keyring is available — typi ## Users -Manage C1 users. +Manage C1.ai users. ### `list` -Search and list C1 users. Outputs NDJSON. +Search and list C1.ai users. Outputs NDJSON. **Usage:** @@ -366,7 +366,7 @@ c1i apps set-owners --user-id [flags] | Flag | Description | | :--- | :--- | -| `--user-id strings` | C1 user ID to set as owner (repeatable; replaces the full owner list). (Required.) | +| `--user-id strings` | C1.ai user ID to set as owner (repeatable; replaces the full owner list). (Required.) | | `--wait` | Block and poll until every requested owner appears, or `--wait-timeout` elapses. | | `--wait-timeout duration` | Max time to wait with `--wait` (default `4m`). | @@ -417,7 +417,7 @@ c1i accounts set-owner --app-id --app-user-id --user-id < | :--- | :--- | | `--app-id string` | Application ID. (Required.) | | `--app-user-id string` | App user ID. (Required.) | -| `--user-id string` | C1 user ID to set as owner. (Required.) | +| `--user-id string` | C1.ai user ID to set as owner. (Required.) | ## Entitlements @@ -591,7 +591,7 @@ c1i connectors list --app-id [flags] ## Policies -Manage policies — the objects that describe how C1 processes a task (an access request, a certification, a provisioning action): who approves it, what happens on escalation or timeout, and how the underlying resource gets provisioned. +Manage policies — the objects that describe how C1.ai processes a task (an access request, a certification, a provisioning action): who approves it, what happens on escalation or timeout, and how the underlying resource gets provisioned. **Usage:** @@ -749,7 +749,7 @@ This validates the CEL environment rules run in (`subject`, `account`, `entitlem ## MCP gateway -Call the C1 MCP gateway directly over its MCP transport — the same handshake an MCP host performs — to verify what a registered server actually exposes. This closes the configure-then-verify loop: register a server, approve its tools, then list or call them here. +Call the C1.ai MCP gateway directly over its MCP transport — the same handshake an MCP host performs — to verify what a registered server actually exposes. This closes the configure-then-verify loop: register a server, approve its tools, then list or call them here. This covers only the `gateway` subcommand. `c1i mcp` also has `servers`, `tools`, `toolsets`, and `bindings` subcommands for managing the MCP surface itself; those aren't covered on this page yet. @@ -810,7 +810,7 @@ c1i mcp gateway call my_tool --args '{"id":"abc"}' ## API -Make raw C1 API requests. This is an escape hatch for accessing any API endpoint not covered by the built-in commands. +Make raw C1.ai API requests. This is an escape hatch for accessing any API endpoint not covered by the built-in commands. **Usage:** @@ -856,7 +856,7 @@ Three flags control how much data flows: | Flag | Effect | | :--- | :--- | -| `--page-size N` | Per-call batch size. The C1 API caps this at 100; c1i clamps client-side, so `--page-size 500` is treated as 100. Default is 50. | +| `--page-size N` | Per-call batch size. The C1.ai API caps this at 100; c1i clamps client-side, so `--page-size 500` is treated as 100. Default is 50. | | `--page-token TOKEN` | Resume from a specific cursor. When set, c1i fetches a single page and exits — auto-pagination is disabled. | | `--limit N` | Cap the *total* number of results emitted across all pages (0 = unlimited). Auto-pagination stops fetching new pages once the cap is reached, and c1i tightens the per-call request size when `--limit` is smaller than `--page-size` so it doesn't over-fetch. | diff --git a/product/cli/c1i.mdx b/product/cli/c1i.mdx index e730726d..a88e81db 100644 --- a/product/cli/c1i.mdx +++ b/product/cli/c1i.mdx @@ -1,8 +1,8 @@ --- title: "Install c1i, the agent-oriented CLI" -og:title: Install c1i, the agent-oriented CLI | Docs - C1 -og:description: c1i is an agent-oriented CLI for the C1 API, designed for automation, scripting, and AI agent workflows. -description: c1i is an agent-oriented CLI for the C1 API, designed for automation, scripting, and AI agent workflows. +og:title: Install c1i, the agent-oriented CLI | Docs - C1.ai +og:description: c1i is an agent-oriented CLI for the C1.ai API, designed for automation, scripting, and AI agent workflows. +description: c1i is an agent-oriented CLI for the C1.ai API, designed for automation, scripting, and AI agent workflows. sidebarTitle: "Install c1i" --- @@ -10,28 +10,28 @@ sidebarTitle: "Install c1i" ## What is c1i? -c1i (pronounced "see-one-eye" — it looks like `cli`, get it?) is an **agent-oriented** command-line interface for the C1 API. It's purpose-built for automation, scripting, and AI agent workflows. +c1i (pronounced "see-one-eye" — it looks like `cli`, get it?) is an **agent-oriented** command-line interface for the C1.ai API. It's purpose-built for automation, scripting, and AI agent workflows. Unlike [Cone](/product/cli/install), which is designed for interactive human use, c1i prioritizes machine-readable output and predictable behavior: - **Structured output**: All data commands produce NDJSON (newline-delimited JSON) — never mixed or human-formatted output. -- **Self-documenting API**: The `docs` commands let agents explore and understand the C1 API without credentials or external documentation. +- **Self-documenting API**: The `docs` commands let agents explore and understand the C1.ai API without credentials or external documentation. - **Predictable pagination**: List commands auto-paginate by default. `--page-token` gives manual control, and `--limit N` caps the total number of results when you want a quick peek. -- **Raw API escape hatch**: The `api` command can call any C1 API endpoint directly, with optional NDJSON pagination. +- **Raw API escape hatch**: The `api` command can call any C1.ai API endpoint directly, with optional NDJSON pagination. ## c1i vs Cone -C1 provides two CLI tools for different use cases: +C1.ai provides two CLI tools for different use cases: | | **Cone** | **c1i** | | :--- | :--- | :--- | | **Designed for** | Humans | Agents, scripts, and automation | | **Output format** | Tables, interactive prompts | NDJSON, JSON | -| **Key workflows** | Search, get, drop entitlements | List, query, and manage all C1 objects | +| **Key workflows** | Search, get, drop entitlements | List, query, and manage all C1.ai objects | | **API coverage** | Access request workflows | Broad API access with raw endpoint escape hatch | | **Interactive** | Yes (prompts, formatted output) | No (structured, parseable output only) | -Use **Cone** when you're working at the terminal interactively. Use **c1i** when you're building automation, writing scripts, or integrating C1 into an AI agent workflow. +Use **Cone** when you're working at the terminal interactively. Use **c1i** when you're building automation, writing scripts, or integrating C1.ai into an AI agent workflow. **Using an AI coding agent?** Run `c1i docs skill` to generate a skill file that teaches your agent how to use c1i. See [Use c1i with AI agents](/product/cli/c1i-agent-skills) for setup instructions for Claude Code, Cursor, and other agents. @@ -39,7 +39,7 @@ Use **Cone** when you're working at the terminal interactively. Use **c1i** when ## Install c1i -Download signed binaries with checksums, provenance, and SBOM attestations from the [C1 distribution center](https://dist.conductorone.com/ConductorOne/c1i). +Download signed binaries with checksums, provenance, and SBOM attestations from the [C1.ai distribution center](https://dist.conductorone.com/ConductorOne/c1i). ```shell # Install with Homebrew @@ -51,9 +51,9 @@ docker pull public.ecr.aws/conductorone/c1i: These examples use `conductor.one`. If your organization is on the EU data residency instance, substitute `c1eu.ai` in URLs, client IDs, and hostnames. -## Configure your C1 URL +## Configure your C1.ai URL -c1i needs to know your C1 tenant URL. You can provide it in any of these ways (listed in order of precedence): +c1i needs to know your C1.ai tenant URL. You can provide it in any of these ways (listed in order of precedence): 1. **Flag**: `--url https://example.conductor.one` 2. **Environment variable**: `C1I_URL=https://example.conductor.one` @@ -125,7 +125,7 @@ c1i reads credentials from the first source that has them, in this order: ## Explore the API without credentials -The `docs` commands work without authentication, so you can explore the C1 API before logging in: +The `docs` commands work without authentication, so you can explore the C1.ai API before logging in: ```shell # Search documentation diff --git a/product/cli/commands.mdx b/product/cli/commands.mdx index d40f9155..fd7f9876 100644 --- a/product/cli/commands.mdx +++ b/product/cli/commands.mdx @@ -1,8 +1,8 @@ --- title: Cone command reference -og:title: Cone command reference | Docs - C1 -og:description: This page is a comprehensive reference for all the commands, subcommands, and flags for C1's CLI tool, Cone. -description: This page is a comprehensive reference for all the commands, subcommands, and flags for C1's CLI tool, Cone. +og:title: Cone command reference | Docs - C1.ai +og:description: This page is a comprehensive reference for all the commands, subcommands, and flags for C1.ai's CLI tool, Cone. +description: This page is a comprehensive reference for all the commands, subcommands, and flags for C1.ai's CLI tool, Cone. sidebarTitle: "Cone commands" --- {/* Editor Refresh: 2026-01-07 */} @@ -17,7 +17,7 @@ Run `cone --help` or `cone -h` for help with a specific comm ## Overview -Cone interacts with the C1 API to manage access to entitlements. +Cone interacts with the C1.ai API to manage access to entitlements. **Usage:** @@ -30,12 +30,12 @@ cone [command] | `aws` | `setup` `credentials` | AWS SSO integration: configure profiles and get credentials. | | `completion` | `bash` `fish` `powershell` `zsh` | Generate the autocompletion script for the specified shell. | | `drop` | | Create a revoke access ticket for an entitlement by alias. | -| `generate-alias` | | Generate aliases for entitlements in C1. | +| `generate-alias` | | Generate aliases for entitlements in C1.ai. | | `get` | | Create an access request for an entitlement by alias. | | `get-user` | | Get a user by ID. | | `has` | | Check if the current user has a specific entitlement for an app. | | `help` | | Help for any command | -| `login` | | Authenticate to C1, creating config.yaml if it doesn't exist. | +| `login` | | Authenticate to C1.ai, creating config.yaml if it doesn't exist. | | `search` | | | | `task` | `approve`  `comment` `deny` `escalate` `get` `search` | Interact with tasks directly. | | `virtual-entitlements` | `create` | Create virtual (manually-managed) entitlements on an app. | @@ -58,7 +58,7 @@ To see Cone's current version number, run `cone --version` or `cone -v`. ## AWS -AWS SSO integration commands. Cone can configure AWS CLI profiles backed by C1 access controls and fetch temporary credentials via AWS SSO. +AWS SSO integration commands. Cone can configure AWS CLI profiles backed by C1.ai access controls and fetch temporary credentials via AWS SSO. For a full walkthrough, see [Using Cone with AWS SSO](/product/how-to/cone-aws-sso-integration). @@ -75,7 +75,7 @@ cone aws [command] ### `setup` -Scans C1 for all AWS permission set entitlements available to you and creates corresponding profiles in `~/.aws/config`. Each profile uses `credential_process` to call `cone aws credentials` when the AWS CLI needs credentials. +Scans C1.ai for all AWS permission set entitlements available to you and creates corresponding profiles in `~/.aws/config`. Each profile uses `credential_process` to call `cone aws credentials` when the AWS CLI needs credentials. On first run, provide your SSO start URL and regions. These are saved to `~/.conductorone/config.yaml` for future runs. @@ -114,7 +114,7 @@ cone aws setup show Retrieve temporary AWS credentials for an AWS SSO profile managed by Cone. -This command checks C1 for an active grant. If you don't have access, it automatically submits an access request, polls for up to 90 seconds for auto-approval, and returns credentials if approved. If the request requires manual approval, it tells you the request is pending. +This command checks C1.ai for an active grant. If you don't have access, it automatically submits an access request, polls for up to 90 seconds for auto-approval, and returns credentials if approved. If the request requires manual approval, it tells you the request is pending. Can be used directly or as an AWS `credential_process`. @@ -276,7 +276,7 @@ Create a revoke access ticket for an entitlement by alias. ## Generate-alias -Generate aliases for entitlements in C1. This command scans entitlements, generates aliases based on a configurable schema, and updates them via the C1 API. +Generate aliases for entitlements in C1.ai. This command scans entitlements, generates aliases based on a configurable schema, and updates them via the C1.ai API. **Usage:** @@ -425,7 +425,7 @@ cone help [command] [flags] ## Login -Authenticate to C1, creating the config.yaml file if it doesn't exist. +Authenticate to C1.ai, creating the config.yaml file if it doesn't exist. **Usage:** @@ -574,11 +574,11 @@ cone task search [flags] | `--query string` | Query string to filter tasks. | | `--state string` | Filter tasks by their state (open, closed). | | `--task-type string` | Filter tasks by their task type (grant, revoke, certify). | -| `--user-subject-ids strings` | Filter tasks by user subject IDs (C1 user target of the task). | +| `--user-subject-ids strings` | Filter tasks by user subject IDs (C1.ai user target of the task). | ## Virtual-entitlements -Create virtual (manually-managed) resource types, resources, and entitlements on a C1 app. +Create virtual (manually-managed) resource types, resources, and entitlements on a C1.ai app. **Usage:** diff --git a/product/cli/install.mdx b/product/cli/install.mdx index 439169be..2945ac9d 100644 --- a/product/cli/install.mdx +++ b/product/cli/install.mdx @@ -1,8 +1,8 @@ --- -title: "Install Cone, the C1 CLI" -og:title: Install Cone, the C1 CLI | Docs - C1 -og:description: C1's CLI brings key access request workflows to the command line. -description: C1's CLI brings key access request workflows to the command line. +title: "Install Cone, the C1.ai CLI" +og:title: Install Cone, the C1.ai CLI | Docs - C1.ai +og:description: C1.ai's CLI brings key access request workflows to the command line. +description: C1.ai's CLI brings key access request workflows to the command line. sidebarTitle: "Install Cone" --- {/* Editor Refresh: 2026-01-07 */} @@ -11,19 +11,19 @@ sidebarTitle: "Install Cone" A CLI, or command-line interface, is a text-based user interface that allows users to interact with a computer by typing commands. CLIs are popular with developers, system administrators, and security engineers because of the speed, control, and flexibility they offer. -We created the C1's CLI, **Cone**, to bring the power of C1 to the command line. +We created the C1.ai's CLI, **Cone**, to bring the power of C1.ai to the command line. -If you're building automation, scripts, or AI agent workflows, C1 also provides [c1i](/product/cli/c1i) — a separate CLI designed for machine-readable output and broad API access. +If you're building automation, scripts, or AI agent workflows, C1.ai also provides [c1i](/product/cli/c1i) — a separate CLI designed for machine-readable output and broad API access. ## Why is it called Cone? -Our product name is C1 — spell out the "1" and you get "C-one". Cone! +Our product name is C1.ai — spell out the "1" and you get "C-one". Cone! ## What can I do with Cone? -Here are just a few of key C1 tasks you can perform on the command line by using Cone. +Here are just a few of key C1.ai tasks you can perform on the command line by using Cone. ### Search for available entitlements @@ -47,7 +47,7 @@ For example: cone get aws-prod-admin ``` -This command will find an entitlement in C1 with the alias `aws-prod-admin`. If you already have access to this entitlement, `cone` will exit successfully (exit status 0). However, if you don't currently have access but the entitlement is available to you (in other words, it's present in one of your access profiles), `cone` will create an access request in C1 and notify the necessary approvers. Based on the entitlement's settings, the command may prompt you to enter a justification or length of access. +This command will find an entitlement in C1.ai with the alias `aws-prod-admin`. If you already have access to this entitlement, `cone` will exit successfully (exit status 0). However, if you don't currently have access but the entitlement is available to you (in other words, it's present in one of your access profiles), `cone` will create an access request in C1.ai and notify the necessary approvers. Based on the entitlement's settings, the command may prompt you to enter a justification or length of access. Once the request is approved, you'll be able to access the entitlement. @@ -65,7 +65,7 @@ For example: cone drop aws-prod-admin ``` -If you currently have access to this entitlement, `cone` will create a revocation request in the C1 and, following any required review, deprovision the access. If you don't have acccess to the entitlement, `cone` will exit successfully (exit status 0). +If you currently have access to this entitlement, `cone` will create a revocation request in the C1.ai and, following any required review, deprovision the access. If you don't have acccess to the entitlement, `cone` will exit successfully (exit status 0). ### Use Cone with AWS SSO @@ -73,11 +73,11 @@ If your organization uses AWS IAM Identity Center, Cone can request and retrieve ## Supported operating systems -C1 provides `cone` binaries for popular operating systems including macOS, Windows, and Linux on the x86 and ARM platforms. If your platform is not listed, please [contact us](mailto:support@c1.ai) or build from source. +C1.ai provides `cone` binaries for popular operating systems including macOS, Windows, and Linux on the x86 and ARM platforms. If your platform is not listed, please [contact us](mailto:support@c1.ai) or build from source. ## Install Cone -Install `cone` from the [C1 distribution center](https://dist.conductorone.com/ConductorOne/cone). Each release includes signed binaries, checksums, provenance, and SBOM attestations. +Install `cone` from the [C1.ai distribution center](https://dist.conductorone.com/ConductorOne/cone). Each release includes signed binaries, checksums, provenance, and SBOM attestations. ```shell # Install with Homebrew @@ -95,7 +95,7 @@ To authorize `cone`: -Run `cone login `, passing in the name (such as `example.conductor.one`) or URL (such as `https://example.conductor.one`) of your C1 instance. +Run `cone login `, passing in the name (such as `example.conductor.one`) or URL (such as `https://example.conductor.one`) of your C1.ai instance. A new browser window opens with an authorization message and code. Review the authorization code against the code shown in your terminal and click **Authorize**. Once you see the **Cone has been authorized** message, it's safe to close this browser tab. @@ -109,7 +109,7 @@ Cone generates an API key for you, and then creates a config file at `$HOME/ -Log into C1 by clicking the link in your email, Slack notification, or Teams notification. +Log into C1.ai by clicking the link in your email, Slack notification, or Teams notification. @@ -45,10 +45,10 @@ Each line in the table is a task assigned to you. For each task, complete the ap **If you're a reviewer for emergency access requests:** - Go to [Enable emergency access requests](/product/admin/emergency) to learn more about how and when these special requests are created and how they're designated in the C1 app. + Go to [Enable emergency access requests](/product/admin/emergency) to learn more about how and when these special requests are created and how they're designated in the C1.ai app. - On the **Insights** tab, view insights from C1 to help make your decision. + On the **Insights** tab, view insights from C1.ai to help make your decision. The detail view of a request task showing a list of Insights. @@ -88,11 +88,11 @@ A request to grant new access has already been reviewed and approved. A provisio ### Step 1: Receive a notification and go to the task -C1 sends you notifications by email and Slack or Teams (if enabled) whenever a provisioning task is assigned to you. Make sure that notification emails can reach your inbox by adding [no-reply@c1.ai](mailto:no-reply@c1.ai) to your email contacts list. +C1.ai sends you notifications by email and Slack or Teams (if enabled) whenever a provisioning task is assigned to you. Make sure that notification emails can reach your inbox by adding [no-reply@c1.ai](mailto:no-reply@c1.ai) to your email contacts list. -Log into C1 by clicking the link in your email, Slack notification, or Teams notification. +Log into C1.ai by clicking the link in your email, Slack notification, or Teams notification. If the link in your notification does not automatically direct you to the task, locate it by clicking on **Requests** and navigating to the **Assigned to me** tab. @@ -112,12 +112,12 @@ Each line in the table with a **Provisioned** button awaiting your action is a p Complete the provisioning process in the requested app, then click **Provisioned**. Click the more actions (**...**) menu for additional options, such as marking the task as **Won't provision**. - If this task exists because connector provisioning failed for a technical reason — for example, the app was linked to a broken group — fix the underlying issue, then click **Retry failed provisioning** in the **...** menu to have C1 retry the original connector action. This doesn't re-collect approvals, so it's a better option than restarting the task from scratch. To retry several affected tasks at once, select them from the **Task log** and choose **Retry failed provisioning** from the bulk actions menu. + If this task exists because connector provisioning failed for a technical reason — for example, the app was linked to a broken group — fix the underlying issue, then click **Retry failed provisioning** in the **...** menu to have C1.ai retry the original connector action. This doesn't re-collect approvals, so it's a better option than restarting the task from scratch. To retry several affected tasks at once, select them from the **Task log** and choose **Retry failed provisioning** from the bulk actions menu. If you need additional guidance or context, click the task number to open the details view. Here you'll find additional information: - - If the C1 admins at your company have provided any notes or instructions for how to complete the provisioning assignment, these are shown here. + - If the C1.ai admins at your company have provided any notes or instructions for how to complete the provisioning assignment, these are shown here. - The **Comments** section shows any notes other members of your organization have made about this task. (Comments posted in Slack about this task are also displayed here.) @@ -135,15 +135,15 @@ Repeat these steps to complete each provisioning task assigned to you. Click **C Revocation tasks are generated when someone (such as a manager or app owner) decides that some access is no longer used, needed, or appropriate, and recommends its removal. -C1 creates a revocation task and assigns it to the appropriate reviewer (you're likely reading this because that's you!). Reviewers are assigned based on the applicable [revocation policy](/product/admin/policies). +C1.ai creates a revocation task and assigns it to the appropriate reviewer (you're likely reading this because that's you!). Reviewers are assigned based on the applicable [revocation policy](/product/admin/policies). ### Step 1: Receive a notification and go to the task -C1 sends you notifications by email and Slack or Teams (if enabled) whenever a revocation task is assigned to you. Make sure that notification emails can reach your inbox by adding [no-reply@c1.ai](mailto:no-reply@c1.ai) to your email contacts list. +C1.ai sends you notifications by email and Slack or Teams (if enabled) whenever a revocation task is assigned to you. Make sure that notification emails can reach your inbox by adding [no-reply@c1.ai](mailto:no-reply@c1.ai) to your email contacts list. -Log into C1 by clicking the link in your email, Slack notification, or Teams notification. +Log into C1.ai by clicking the link in your email, Slack notification, or Teams notification. If the link in your notification does not automatically direct you to the task, locate it by clicking on **Requests** and navigating to the **Assigned to me** tab. @@ -195,11 +195,11 @@ A revocation proposal (see above) has already been reviewed and approved. A depr ### Step 1: Receive a notification and go to the task -C1 sends you notifications by email and Slack or Teams (if enabled) whenever a deprovisioning task is assigned to you. Make sure that notification emails can reach your inbox by adding [no-reply@c1.ai](mailto:no-reply@c1.ai) to your email contacts list. +C1.ai sends you notifications by email and Slack or Teams (if enabled) whenever a deprovisioning task is assigned to you. Make sure that notification emails can reach your inbox by adding [no-reply@c1.ai](mailto:no-reply@c1.ai) to your email contacts list. -Log into C1 by clicking the link in your email, Slack notification, or Teams notification. +Log into C1.ai by clicking the link in your email, Slack notification, or Teams notification. If the link in your notification does not automatically direct you to the task, locate it by clicking on **Requests** and navigating to the **Assigned to me** tab. @@ -222,7 +222,7 @@ Complete the deprovisioning process in the requested app, then click **Deprovisi If you need additional guidance or context, click the task number to open the details view. Here you'll find additional information to help you: - - If the C1 admins at your company have provided any notes or instructions for how to complete the deprovisioning assignment, these are shown here. + - If the C1.ai admins at your company have provided any notes or instructions for how to complete the deprovisioning assignment, these are shown here. - The **Comments** section shows any notes other members of your organization have made about this task. (Comments posted in Slack about this task are also displayed here.) @@ -254,7 +254,7 @@ The newly assigned reviewer will receive email and Slack or Teams (if enabled) n ## Additional task actions -Depending on your user permissions in C1, the task type, and the current status of the task, you might have additional task actions available to you in the **...** (more actions) menu. +Depending on your user permissions in C1.ai, the task type, and the current status of the task, you might have additional task actions available to you in the **...** (more actions) menu. Actions labeled with a symbol are only available to users who have the **Super Administrator** role. @@ -262,7 +262,7 @@ Actions labeled with a | Stop the task and close it with **Canceled** status. The task remains in the **Task log**. | You don't want or need to complete a task, but want to retain a record of its existence. | | | | | -| **Delete** | Stop the task and delete it from C1 entirely. No record of the task is retained in the **Task log**. | You don't want or need to complete a task, and want the record of its existence removed from C1. | +| **Delete** | Stop the task and delete it from C1.ai entirely. No record of the task is retained in the **Task log**. | You don't want or need to complete a task, and want the record of its existence removed from C1.ai. | | | | | | **(Action) with comment** | Take an action (such as certify, approve, mark as provisioned) and add a comment to the task. | You want to provide context or documentation with your decision | | | | | diff --git a/product/how-to/ai-tools.mdx b/product/how-to/ai-tools.mdx index 61d29473..084cb782 100644 --- a/product/how-to/ai-tools.mdx +++ b/product/how-to/ai-tools.mdx @@ -1,57 +1,57 @@ --- title: How to request AI tools -description: Connect your AI client to C1, request access to governed AI tools, and start using them. -og:title: How to request AI tools - C1 docs -og:description: Connect your AI client to C1, request access to governed AI tools, and start using them. +description: Connect your AI client to C1.ai, request access to governed AI tools, and start using them. +og:title: How to request AI tools - C1.ai docs +og:description: Connect your AI client to C1.ai, request access to governed AI tools, and start using them. --- {/* Editor Refresh: 2026-05-08 */} -**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, an admin from your organization must [contact the C1 support team](mailto:support@c1.ai) for a walkthrough. +**Activation required.** AI access management must be enabled for your tenant before you can use it. To get started, an admin from your organization must [contact the C1.ai support team](mailto:support@c1.ai) for a walkthrough. -This guide covers the AI access management (AIAM) path, where C1 proxies your agent's tool calls. If your organization uses enterprise-managed authorization instead — where C1 issues tokens and your agent calls MCP servers directly — see [Connect your MCP client to C1](/product/how-to/connect-mcp-client). +This guide covers the AI access management (AIAM) path, where C1.ai proxies your agent's tool calls. If your organization uses enterprise-managed authorization instead — where C1.ai issues tokens and your agent calls MCP servers directly — see [Connect your MCP client to C1.ai](/product/how-to/connect-mcp-client). -If your IT or Security team has rolled out AI access management with C1, follow this guide to learn how to: +If your IT or Security team has rolled out AI access management with C1.ai, follow this guide to learn how to: -1. Connect your AI client (such as Claude, ChatGPT, Cursor, or Copilot) to C1 so it can call governed tools. -2. Find the AI tools you need and request access to them from C1. +1. Connect your AI client (such as Claude, ChatGPT, Cursor, or Copilot) to C1.ai so it can call governed tools. +2. Find the AI tools you need and request access to them from C1.ai. 3. Use those tools in your AI client and know what to do when something gets denied. -You don't need an admin role — anyone with a C1 account can do this. +You don't need an admin role — anyone with a C1.ai account can do this. -## Connect your AI client to C1 +## Connect your AI client to C1.ai -C1 governs AI tool access by sitting between your AI client and the underlying tools (Salesforce, GitHub, and so on). Once you connect, your client sees only the tools your IT team has approved for you. +C1.ai governs AI tool access by sitting between your AI client and the underlying tools (Salesforce, GitHub, and so on). Once you connect, your client sees only the tools your IT team has approved for you. -### Step 1: Get the C1 MCP URL +### Step 1: Get the C1.ai MCP URL -In C1, go to your profile menu and click **AI & API**. +In C1.ai, go to your profile menu and click **AI & API**. On the **AI connections** tab, copy the **MCP server URL**. -### Step 2: Add C1 MCP to your AI client +### Step 2: Add C1.ai MCP to your AI client The exact steps depend on your client: - **Claude Desktop** — **Settings > Connectors > Add connector**, then paste the MCP URL. - **Claude Code** — Add the URL via `claude mcp add` or in `.claude/settings.json`. See the [Claude Code MCP docs](https://docs.anthropic.com/en/docs/claude-code/mcp) for syntax. -- **Copilot Studio** — See [Connect Copilot Studio to C1](/product/admin/mcp-server/copilot-studio), which also covers publishing the agent to Microsoft 365 Copilot. +- **Copilot Studio** — See [Connect Copilot Studio to C1.ai](/product/admin/mcp-server/copilot-studio), which also covers publishing the agent to Microsoft 365 Copilot. - **ChatGPT / Cursor** — Follow your client's documentation for adding an MCP server connection. ### Step 3: Authenticate -The first time your client tries to use C1 MCP, you'll be redirected to C1 to sign in. After signing in, you'll see a list of the C1 tools your access profiles grant you. +The first time your client tries to use C1.ai MCP, you'll be redirected to C1.ai to sign in. After signing in, you'll see a list of the C1.ai tools your access profiles grant you. -If your AI client offers a way to test the connection, run a "list tools" prompt — you should see C1 tools appear. +If your AI client offers a way to test the connection, run a "list tools" prompt — you should see C1.ai tools appear. ### When a tool needs your own credentials (per-user OAuth) @@ -67,13 +67,13 @@ In all three cases, no data on your machine is deleted — only your ability to ## Find and request AI tool access -Access profiles containing toolsets appear in the C1 catalog. Browse to find what's available, then submit a request from the web or Slack. +Access profiles containing toolsets appear in the C1.ai catalog. Browse to find what's available, then submit a request from the web or Slack. ### Browse the catalog -In C1, click **Requests**. +In C1.ai, click **Requests**. Access profiles containing tools appear in the catalog alongside app entitlements. Each item shows what toolset it grants, what tools are in the toolset, and what the approval policy is (auto-approve, requires approval, or JIT with an expiry). @@ -101,11 +101,11 @@ You'll see the status on your **My requests** page. ### Submit a request via Slack -If your org has the C1 Slack integration: +If your org has the C1.ai Slack integration: -Run `/c1 request` (or message the C1 bot). +Run `/c1 request` (or message the C1.ai bot). Search for the access profile. @@ -120,7 +120,7 @@ The same approval flow runs whether you submit from web or Slack. ### Check request status - **Web** — **My requests**. -- **Slack** — the C1 bot DMs you when status changes (approved / denied / more info needed). +- **Slack** — the C1.ai bot DMs you when status changes (approved / denied / more info needed). - **Email** — same notifications by email if your org has email notifications enabled. ## Use AI tools in your client diff --git a/product/how-to/automate-revocation-tickets.mdx b/product/how-to/automate-revocation-tickets.mdx index 3678d736..54adf537 100644 --- a/product/how-to/automate-revocation-tickets.mdx +++ b/product/how-to/automate-revocation-tickets.mdx @@ -1,21 +1,21 @@ --- title: Route campaign revocations to your ITSM -og:title: Route campaign revocations to your ITSM - C1 docs -og:description: Configure C1 to automatically open an ITSM ticket whenever an access review campaign revokes access. -description: Configure C1 to automatically open an ITSM ticket whenever an access review campaign revokes access. +og:title: Route campaign revocations to your ITSM - C1.ai docs +og:description: Configure C1.ai to automatically open an ITSM ticket whenever an access review campaign revokes access. +description: Configure C1.ai to automatically open an ITSM ticket whenever an access review campaign revokes access. sidebarTitle: Route revocations to ITSM --- {/* Editor Refresh: 2026-09-01 */} Route campaign-driven revocations straight into your ITSM as a ticket, instead of relying on someone to manually deprovision the account. This is especially useful for apps that don't have a connector capable of automatic deprovisioning — the ticket becomes the deprovisioning record instead. -This guide connects three C1 features: entitlement deprovisioning, ticket templates, and campaign review policies. +This guide connects three C1.ai features: entitlement deprovisioning, ticket templates, and campaign review policies. ## Before you begin You'll need: -- C1 **Super Administrator** role, or **Application Admin** on the apps you're configuring +- C1.ai **Super Administrator** role, or **Application Admin** on the apps you're configuring - An [external ticketing provisioner already configured](/product/admin/external-ticketing) for your ITSM (Jira, ServiceNow, Freshservice, Linear, or HaloITSM) - The name of the review policy your target campaigns use — you'll edit its follow-up steps in Step 3 @@ -59,7 +59,7 @@ By default, a denied access review doesn't revoke access on its own — a Campai Navigate to **Platform** > **Policies** and open the review policy used by your campaign. -In the **Follow-up steps** section, set C1 to automatically create a revoke task when an access review is denied. +In the **Follow-up steps** section, set C1.ai to automatically create a revoke task when an access review is denied. Click **Save**. @@ -70,7 +70,7 @@ Denied reviews in campaigns using this policy now automatically create a revocat ## What happens next -When a reviewer denies access during a campaign that uses this policy, C1 automatically creates a revocation task, deprovisions it using the method you set in Step 1, and opens a ticket in your ITSM using the template from Step 2. Track the outcome from the [campaign report](/product/admin/manage-campaigns#generate-a-campaign-report) — add the **External ticket** and **External ticket status** columns to see ticket status per revocation. +When a reviewer denies access during a campaign that uses this policy, C1.ai automatically creates a revocation task, deprovisions it using the method you set in Step 1, and opens a ticket in your ITSM using the template from Step 2. Track the outcome from the [campaign report](/product/admin/manage-campaigns#generate-a-campaign-report) — add the **External ticket** and **External ticket status** columns to see ticket status per revocation. ## Frequently asked questions about revocation ticketing @@ -87,7 +87,7 @@ Denied reviews still show up on the campaign's **Access reviews** tab, but a Cam -Yes. If an app's connector doesn't support automatic deprovisioning, C1 normally falls back to a manual deprovisioning task. Setting the deprovisioning method to **External ticketing** replaces that manual fallback with an automatically created ticket in your ITSM. +Yes. If an app's connector doesn't support automatic deprovisioning, C1.ai normally falls back to a manual deprovisioning task. Setting the deprovisioning method to **External ticketing** replaces that manual fallback with an automatically created ticket in your ITSM. diff --git a/product/how-to/cone-aws-sso-integration.mdx b/product/how-to/cone-aws-sso-integration.mdx index 81290749..bea35b6d 100644 --- a/product/how-to/cone-aws-sso-integration.mdx +++ b/product/how-to/cone-aws-sso-integration.mdx @@ -1,20 +1,20 @@ --- title: How to use Cone with AWS IAM Identity Center -og:title: How to use Cone with AWS IAM Identity Center - C1 docs +og:title: How to use Cone with AWS IAM Identity Center - C1.ai docs og:description: Configure Cone to integrate with AWS IAM Identity Center so you can request and use AWS access directly from the AWS CLI. description: Configure Cone to integrate with AWS IAM Identity Center so you can request and use AWS access directly from the AWS CLI. sidebarTitle: Use Cone with AWS IAM Identity Center --- {/* Editor Refresh: 2026-04-03 */} -Cone integrates with AWS IAM Identity Center to provide just-in-time access to AWS accounts through C1. Instead of managing long-lived credentials or navigating the IAM Identity Center access portal, you use your normal AWS CLI workflow and Cone handles access requests and credential fetching behind the scenes. +Cone integrates with AWS IAM Identity Center to provide just-in-time access to AWS accounts through C1.ai. Instead of managing long-lived credentials or navigating the IAM Identity Center access portal, you use your normal AWS CLI workflow and Cone handles access requests and credential fetching behind the scenes. ## How it works When you run an AWS CLI command with a Cone-managed profile, the following happens automatically: 1. The AWS CLI calls `cone aws credentials` via the profile's `credential_process`. -2. Cone checks C1 for an active grant on the permission set using the entitlement and app IDs stored in the profile. +2. Cone checks C1.ai for an active grant on the permission set using the entitlement and app IDs stored in the profile. 3. If you have access, Cone fetches temporary credentials from AWS IAM Identity Center and returns them to the AWS CLI. 4. If you don't have access, Cone automatically submits an access request, monitors the policy step, and returns credentials if the request is auto-approved. @@ -26,7 +26,7 @@ Before you begin, make sure you have the following: - [Cone](/product/cli/install) installed and authenticated (`cone login`) - [AWS CLI v2](https://aws.amazon.com/cli/) installed and available on your PATH -- Your organization uses C1 to manage AWS IAM Identity Center permission sets +- Your organization uses C1.ai to manage AWS IAM Identity Center permission sets If you haven't authenticated Cone yet, run `cone login ` first. See [Install and authenticate Cone](/product/cli/install) for details. @@ -34,7 +34,7 @@ If you haven't authenticated Cone yet, run `cone login ` first. See ## Set up Cone for AWS IAM Identity Center -Run `cone aws setup` to configure your SSO settings and generate AWS CLI profiles for every AWS permission set available to you in C1. +Run `cone aws setup` to configure your SSO settings and generate AWS CLI profiles for every AWS permission set available to you in C1.ai. ### Step 1: Run the setup command @@ -71,7 +71,7 @@ cone aws setup \ | `--sso-region` | AWS region where IAM Identity Center is configured. Default: `us-east-1`. | | `--region` | Default AWS region for generated CLI profiles. Default: `us-east-1`. | -This command saves your settings to `~/.conductorone/config.yaml`, queries C1 for all AWS permission set entitlements you can see, and creates a profile in `~/.aws/config` for each one. Each profile stores the C1 app and entitlement IDs so that credential lookups work without any additional configuration. +This command saves your settings to `~/.conductorone/config.yaml`, queries C1.ai for all AWS permission set entitlements you can see, and creates a profile in `~/.aws/config` for each one. Each profile stores the C1.ai app and entitlement IDs so that credential lookups work without any additional configuration. @@ -87,7 +87,7 @@ This displays the saved SSO URL, SSO region, and default region. ### Step 3: Refresh profiles when needed -If new AWS permission sets are added in C1, re-run the setup command. Existing profiles are skipped automatically, and new ones are added. +If new AWS permission sets are added in C1.ai, re-run the setup command. Existing profiles are skipped automatically, and new ones are added. ```bash cone aws setup @@ -108,7 +108,7 @@ aws ec2 describe-instances --profile staging-readonly ### What happens when you have access -If you have an active grant for the permission set in C1, Cone fetches temporary credentials from AWS IAM Identity Center and returns them to the AWS CLI. The command succeeds as if you were using native AWS IAM Identity Center. +If you have an active grant for the permission set in C1.ai, Cone fetches temporary credentials from AWS IAM Identity Center and returns them to the AWS CLI. The command succeeds as if you were using native AWS IAM Identity Center. If your SSO session has expired, Cone automatically opens a browser for you to re-authenticate (the same flow as `aws sso login`). @@ -217,7 +217,7 @@ The entitlement has custom form fields that must be filled out when requesting a ### "A pending request already exists" -A previous access request for this permission set is still open. Use `cone task get ` to check its status, or complete it in the C1 web UI. +A previous access request for this permission set is still open. Use `cone task get ` to check its status, or complete it in the C1.ai web UI. ### "The AWS CLI is required but was not found on PATH" @@ -225,4 +225,4 @@ Install [AWS CLI v2](https://aws.amazon.com/cli/) and make sure the `aws` comman ### Profiles not appearing after setup -`cone aws setup` only creates profiles for entitlements that C1 identifies as AWS permission sets. If your AWS integration was recently set up, the permission sets may not have synced yet. Check the C1 admin console to confirm the integration is active. +`cone aws setup` only creates profiles for entitlements that C1.ai identifies as AWS permission sets. If your AWS integration was recently set up, the permission sets may not have synced yet. Check the C1.ai admin console to confirm the integration is active. diff --git a/product/how-to/connect-mcp-client.mdx b/product/how-to/connect-mcp-client.mdx index e0e8b0ab..275b1a16 100644 --- a/product/how-to/connect-mcp-client.mdx +++ b/product/how-to/connect-mcp-client.mdx @@ -1,28 +1,28 @@ --- title: How to connect your MCP client -description: Authenticate once to C1, then let your AI agent reach the MCP servers you're entitled to — with short-lived, scoped tokens instead of long-lived API keys. -og:title: How to connect your MCP client - C1 docs -og:description: Authenticate once to C1, then let your AI agent reach the MCP servers you're entitled to — with short-lived, scoped tokens instead of long-lived API keys. +description: Authenticate once to C1.ai, then let your AI agent reach the MCP servers you're entitled to — with short-lived, scoped tokens instead of long-lived API keys. +og:title: How to connect your MCP client - C1.ai docs +og:description: Authenticate once to C1.ai, then let your AI agent reach the MCP servers you're entitled to — with short-lived, scoped tokens instead of long-lived API keys. sidebarTitle: How to connect your MCP client --- {/* Editor Refresh: 2026-06-13 */} -**Activation required.** AI access management must be enabled for your organization's C1 tenant before you can use it. +**Activation required.** AI access management must be enabled for your organization's C1.ai tenant before you can use it. -With enterprise-managed authorization, you authenticate once to C1, and from then on your AI agent can reach the MCP servers you've been granted access to — no per-tool login, and no long-lived API keys. Your agent signs you in to C1, exchanges your identity for a short-lived token scoped to the server you want, and calls that server directly. +With enterprise-managed authorization, you authenticate once to C1.ai, and from then on your AI agent can reach the MCP servers you've been granted access to — no per-tool login, and no long-lived API keys. Your agent signs you in to C1.ai, exchanges your identity for a short-lived token scoped to the server you want, and calls that server directly. -What this looks like in your client depends on which one you use: in Claude it shows up as "enterprise-managed auth" through connectors, and in VS Code as "enterprise-managed MCP authentication." Either way, it connects to the same enterprise-managed authorization your C1 admin set up. +What this looks like in your client depends on which one you use: in Claude it shows up as "enterprise-managed auth" through connectors, and in VS Code as "enterprise-managed MCP authentication." Either way, it connects to the same enterprise-managed authorization your C1.ai admin set up. ## How setup is divided -Connecting your MCP client to C1 involves three people — you don't need an admin role for your part: +Connecting your MCP client to C1.ai involves three people — you don't need an admin role for your part: -- Your C1 admin enables enterprise-managed authorization, registers the MCP servers, and grants you access. -- The owner of each MCP server configures it to trust C1 as a token issuer. See [Support enterprise-managed authorization in your MCP server](/product/admin/enterprise-managed-authorization/support-in-your-app). -- You connect your client to C1 and add each server, which is what this guide covers. +- Your C1.ai admin enables enterprise-managed authorization, registers the MCP servers, and grants you access. +- The owner of each MCP server configures it to trust C1.ai as a token issuer. See [Support enterprise-managed authorization in your MCP server](/product/admin/enterprise-managed-authorization/support-in-your-app). +- You connect your client to C1.ai and add each server, which is what this guide covers. If your agent runs as its own identity, a service principal, rather than as you, the connection is set up against that identity instead. See [Service principals](/product/admin/service-principals/overview). @@ -32,15 +32,15 @@ Enterprise-managed authorization in Claude Code is gated by the `CLAUDE_CODE_ENA ## Before you begin -Collect the following from the people who own each piece. Without all of it, the token request fails. The last item is the most commonly overlooked: if you haven't been granted access in C1, the exchange is denied even when everything else is correct. +Collect the following from the people who own each piece. Without all of it, the token request fails. The last item is the most commonly overlooked: if you haven't been granted access in C1.ai, the exchange is denied even when everything else is correct. | What to collect | Who provides it | | :--- | :--- | -| Your C1 issuer URL | Your C1 admin | -| The agent client's ID and secret at C1 (your agent's identity at C1, used to sign you in) | Your C1 admin | +| Your C1.ai issuer URL | Your C1.ai admin | +| The agent client's ID and secret at C1.ai (your agent's identity at C1.ai, used to sign you in) | Your C1.ai admin | | For each MCP server: its URL, plus a client ID and secret at that server's authorization server (a different credential) | The server owner | -| Confirmation that the server already trusts C1 as a token issuer | The server owner | -| Confirmation that your access is already granted, meaning you requested the scope or access profile in C1 | You | +| Confirmation that the server already trusts C1.ai as a token issuer | The server owner | +| Confirmation that your access is already granted, meaning you requested the scope or access profile in C1.ai | You | ## Set up your client @@ -58,26 +58,26 @@ export CLAUDE_CODE_ENABLE_XAA=1 ``` -**Connect to C1 once.** This configures the one C1 connection that every server reuses. Put the agent client's secret in the environment variable that `--client-secret` reads, then run setup. +**Connect to C1.ai once.** This configures the one C1.ai connection that every server reuses. Put the agent client's secret in the environment variable that `--client-secret` reads, then run setup. ```bash export MCP_XAA_IDP_CLIENT_SECRET='' claude mcp xaa setup --issuer --client-id --client-secret ``` -The `--client-secret` flag takes no inline value. It reads the secret from `MCP_XAA_IDP_CLIENT_SECRET`. Add `--callback-port ` only if your C1 connection doesn't allow any loopback port for the browser sign-in. +The `--client-secret` flag takes no inline value. It reads the secret from `MCP_XAA_IDP_CLIENT_SECRET`. Add `--callback-port ` only if your C1.ai connection doesn't allow any loopback port for the browser sign-in. -**Sign in to C1.** This opens C1 in your browser and caches the session. +**Sign in to C1.ai.** This opens C1.ai in your browser and caches the session. ```bash claude mcp xaa login ``` -If you can't use a browser, pass a C1-issued ID token directly instead: `claude mcp xaa login --id-token `. +If you can't use a browser, pass a C1.ai-issued ID token directly instead: `claude mcp xaa login --id-token `. -**Add an MCP server.** Give Claude Code the server's URL and the client credentials for that server's authorization server. These are different from the C1 credentials in step 2. Repeat this step for each server you want to use. +**Add an MCP server.** Give Claude Code the server's URL and the client credentials for that server's authorization server. These are different from the C1.ai credentials in step 2. Repeat this step for each server you want to use. ```bash claude mcp add --xaa --transport --client-id --client-secret @@ -97,13 +97,13 @@ Set `--transport` to `http` or `sse` to match the server; only HTTP and SSE serv **Preview.** VS Code's enterprise-managed MCP authentication is a Preview feature, available in VS Code **v1.123 and later**. The steps below reflect that release. -VS Code authenticates to C1 once, then connects to your enterprise-managed MCP servers silently. There are two pieces of configuration: the C1 identity provider, set once in `settings.json`, and each MCP server, listed in `mcp.json`. +VS Code authenticates to C1.ai once, then connects to your enterprise-managed MCP servers silently. There are two pieces of configuration: the C1.ai identity provider, set once in `settings.json`, and each MCP server, listed in `mcp.json`. In a managed organization, your admin usually delivers the identity-provider settings for you through enterprise policy — Windows Group Policy, macOS managed preferences, or `/etc/vscode/policy.json` on Linux — so you may not need to set them by hand. If you're setting things up individually, put them in your `settings.json`. -**Configure the C1 identity provider.** In `settings.json`, set `mcp.enterpriseManagedAuth.idp` with the issuer URL and OIDC client credentials your C1 admin gives you. +**Configure the C1.ai identity provider.** In `settings.json`, set `mcp.enterpriseManagedAuth.idp` with the issuer URL and OIDC client credentials your C1.ai admin gives you. ```jsonc "mcp.enterpriseManagedAuth.idp": { @@ -133,13 +133,13 @@ If your admin delivers this through enterprise policy, it's already set and you } ``` -The `oauth.clientId` here is the client ID at the **MCP server's authorization server** — the credential the server owner gives you, not the C1 identity-provider client ID from the previous step. +The `oauth.clientId` here is the client ID at the **MCP server's authorization server** — the credential the server owner gives you, not the C1.ai identity-provider client ID from the previous step. **Set the server's client secret.** Don't put the secret in `mcp.json`. Use the **Client secret** code lens that appears above the `oauth` block to store it; VS Code keeps it in your operating system's secret store, not in the file. -**Sign in once.** The first time you connect to an enterprise-managed server, VS Code opens a browser to sign you in to C1. After that, every enterprise-managed server connects silently — no per-server prompt. +**Sign in once.** The first time you connect to an enterprise-managed server, VS Code opens a browser to sign you in to C1.ai. After that, every enterprise-managed server connects silently — no per-server prompt. @@ -149,25 +149,25 @@ Find the error you're seeing below for the cause and who to ask. | What you see | What it means and who to ask | | :--- | :--- | -| Sign-in never starts, or VS Code reports no identity provider | The C1 identity provider isn't configured. Set `mcp.enterpriseManagedAuth.idp` in `settings.json`, or ask your admin whether it should arrive through enterprise policy. | +| Sign-in never starts, or VS Code reports no identity provider | The C1.ai identity provider isn't configured. Set `mcp.enterpriseManagedAuth.idp` in `settings.json`, or ask your admin whether it should arrive through enterprise policy. | | The server connects without enterprise-managed auth, or VS Code can't discover its authorization server | The MCP server didn't advertise protected-resource metadata or list its `authorization_servers`. Ask the server owner to finish setup. See [Support enterprise-managed authorization in your MCP server](/product/admin/enterprise-managed-authorization/support-in-your-app). | -| The connection is denied because you don't have the scope | Your access hasn't been granted. Ask your C1 admin to grant you the scope or access profile. | -| The server rejects the token even though sign-in worked | The token's signature may use an algorithm the server doesn't verify. Ask your C1 admin to check the signing algorithm set for that server. | +| The connection is denied because you don't have the scope | Your access hasn't been granted. Ask your C1.ai admin to grant you the scope or access profile. | +| The server rejects the token even though sign-in worked | The token's signature may use an algorithm the server doesn't verify. Ask your C1.ai admin to check the signing algorithm set for that server. |
-Enterprise-managed authorization is built on an open standard, so any client that implements it follows the same shape: one connection to C1 using its issuer URL and client credentials, plus, for each MCP server, the client's own credentials at that server's authorization server. Claude Code and VS Code support it today, as covered above; other clients will follow the same pattern as they add support. +Enterprise-managed authorization is built on an open standard, so any client that implements it follows the same shape: one connection to C1.ai using its issuer URL and client credentials, plus, for each MCP server, the client's own credentials at that server's authorization server. Claude Code and VS Code support it today, as covered above; other clients will follow the same pattern as they add support. ## Manage your connection -Use these commands to check or reset your C1 connection: +Use these commands to check or reset your C1.ai connection: - `claude mcp xaa show` checks your current connection. -- `claude mcp xaa login --force` signs you in to C1 again, for example after your access was reset. +- `claude mcp xaa login --force` signs you in to C1.ai again, for example after your access was reset. - `claude mcp xaa clear` clears the connection so you can start over. ## When something doesn't work @@ -177,8 +177,8 @@ Find the error you're seeing below for the cause and who to ask. | What you see | What it means and who to ask | | :--- | :--- | | `XAA is not enabled (set CLAUDE_CODE_ENABLE_XAA=1)` | The gate is off. Set `CLAUDE_CODE_ENABLE_XAA=1` in your shell profile and restart your shell. | -| `XAA: no IdP connection configured` | You haven't connected to C1 yet. Run `claude mcp xaa setup`, then `claude mcp xaa login`. | +| `XAA: no IdP connection configured` | You haven't connected to C1.ai yet. Run `claude mcp xaa setup`, then `claude mcp xaa login`. | | `XAA: server '' needs an AS client_id` or a missing AS client secret | The server is missing its client ID or secret. Re-run `claude mcp add --xaa` for that server. | -| `Resource server does not implement OAuth 2.0 Protected Resource Metadata`, `PRM discovery failed`, or `no authorization server supports jwt-bearer` | The server doesn't publish the metadata C1 needs, or doesn't support the JWT bearer grant. Ask the server owner to finish setup. See [Support enterprise-managed authorization in your MCP server](/product/admin/enterprise-managed-authorization/support-in-your-app). | -| The token request is denied because you don't have the scope | Your access hasn't been granted. Ask your C1 admin to grant you the scope or access profile. | -| The server rejects the token even though sign-in worked | The token's signature may use an algorithm the server doesn't verify. Ask your C1 admin to check the signing algorithm set for that server. | +| `Resource server does not implement OAuth 2.0 Protected Resource Metadata`, `PRM discovery failed`, or `no authorization server supports jwt-bearer` | The server doesn't publish the metadata C1.ai needs, or doesn't support the JWT bearer grant. Ask the server owner to finish setup. See [Support enterprise-managed authorization in your MCP server](/product/admin/enterprise-managed-authorization/support-in-your-app). | +| The token request is denied because you don't have the scope | Your access hasn't been granted. Ask your C1.ai admin to grant you the scope or access profile. | +| The server rejects the token even though sign-in worked | The token's signature may use an algorithm the server doesn't verify. Ask your C1.ai admin to check the signing algorithm set for that server. | diff --git a/product/how-to/create-requests.mdx b/product/how-to/create-requests.mdx index 7c711fb0..4df8b027 100644 --- a/product/how-to/create-requests.mdx +++ b/product/how-to/create-requests.mdx @@ -1,8 +1,8 @@ --- title: How to request new access -og:title: How to request new access - C1 docs -og:description: Whenever you need access to a certain application, or access to a resource on like a group, repo, or role within an app, make a request through C1. -description: Whenever you need access to a certain application, or access to a resource on like a group, repo, or role within an app, make a request through C1. +og:title: How to request new access - C1.ai docs +og:description: Whenever you need access to a certain application, or access to a resource on like a group, repo, or role within an app, make a request through C1.ai. +description: Whenever you need access to a certain application, or access to a resource on like a group, repo, or role within an app, make a request through C1.ai. --- {/* Editor Refresh: 2026-05-01 */} @@ -16,13 +16,13 @@ You've got some choices! 3. Do you want to make a request without leaving your Slack or Microsoft Teams workspace? **Use [Slack](/product/how-to/create-requests#request-using-the-slack-app) or [MS Teams](/product/how-to/create-requests#request-using-the-microsoft-teams-app).** -4. Do you prefer to request access from the command line? **Use the [C1 CLI](/product/cli/install).** +4. Do you prefer to request access from the command line? **Use the [C1.ai CLI](/product/cli/install).** ## Why don't I see all the apps my company uses? For both simplicity and security, the list of apps and permissions you can request is limited. If you're in the Accounting department, you probably don't need access to the tools the Product Design team uses, or vice versa. -The C1 admins at your company set up groups of apps and permissions called _access profiles_. Some access profiles are visible to everyone, but others are just for certain departments or job types. The access profiles you have access to determine which apps you can see and ask for. +The C1.ai admins at your company set up groups of apps and permissions called _access profiles_. Some access profiles are visible to everyone, but others are just for certain departments or job types. The access profiles you have access to determine which apps you can see and ask for. The admins also have the option to let you ask for **all** the apps in an access profile in a single request. If these are available to you, you'll find them on the **Profiles** tab. @@ -32,16 +32,16 @@ Most users can only request their own access, but there are a few exceptions: * **Managers** can request access for the members of their team. -* C1 users with the **Access Request Helpdesk**, **Access Request Admin**, or **Super Administrator** roles can request access for any active user. +* C1.ai users with the **Access Request Helpdesk**, **Access Request Admin**, or **Super Administrator** roles can request access for any active user. -If you're a manager or have one of these user roles, you'll see an option to request new access for others when creating an access request. Note that you cannot request access for a user who is suspended or deleted in C1. +If you're a manager or have one of these user roles, you'll see an option to request new access for others when creating an access request. Note that you cannot request access for a user who is suspended or deleted in C1.ai. Review all the access you've requested for others, as well as any you've requested for yourself, by navigating to **Requests** > **My requests**. **Do I have to approve the access I request for another user?** -If you request access for another person, your approval of that person receiving that access is understood to be implicit. So if the policy governing the requested access would normally assign an access request task to you for your approval, C1 will auto-approve the request on your behalf. +If you request access for another person, your approval of that person receiving that access is understood to be implicit. So if the policy governing the requested access would normally assign an access request task to you for your approval, C1.ai will auto-approve the request on your behalf. ## Request from the Requests page @@ -62,7 +62,7 @@ A green checkmark on an app's tile indicates that you have access to that app. W **Looking for a specific entitlement?** Use the search filter on the **App catalog** tab to search for entitlements across all applications. This is especially helpful when you know the name of the permission you need but aren't sure which app it belongs to. -If your search matches a resource that isn't an entitlement's name — for example, a specific repository — C1 also shows an **Entitlements matching "\"** section listing entitlements that indirectly grant access to it, such as a team whose repository access includes the one you searched for. Click **View access graph** on any result to see everything that entitlement grants, with your search match highlighted. +If your search matches a resource that isn't an entitlement's name — for example, a specific repository — C1.ai also shows an **Entitlements matching "\"** section listing entitlements that indirectly grant access to it, such as a team whose repository access includes the one you searched for. Click **View access graph** on any result to see everything that entitlement grants, with your search match highlighted. To request new access: @@ -91,7 +91,7 @@ Click an app and select what you want to request: Set how long you need the access for. Some sensitive or expensive resources can only be requested for a limited time. Choose from one of the pre-set options, or enter a custom timeframe by selecting **Custom**. - When you're granted access for a limited time, C1 will send you reminders that the access is expiring, at 30 days, 14 days, three days, one day, and one hour before the grant ends (whichever of these apply to how long your access lasts). Expiring access is also shown in C1 digests. + When you're granted access for a limited time, C1.ai will send you reminders that the access is expiring, at 30 days, 14 days, three days, one day, and one hour before the grant ends (whichever of these apply to how long your access lasts). Expiring access is also shown in C1.ai digests. @@ -112,7 +112,7 @@ Click **Submit request**. A drawer pops open to show you the details of the newl -**Done.** C1 will send you an email when your request is approved or rejected, and another when the new access is granted. +**Done.** C1.ai will send you an email when your request is approved or rejected, and another when the new access is granted. ### Request a profile @@ -134,7 +134,7 @@ Click **Request** at the top of the page. Set how long you need the access for. Some sensitive or expensive access profiles can only be requested for a limited time. Choose from one of the pre-set options, or enter a custom timeframe by selecting **Custom**. - When you're granted access for a limited time, C1 will send you reminders that the access is expiring, at 30 days, 14 days, three days, one day, and one hour before the grant ends (whichever of these apply to how long your access lasts). Expiring access is also shown in C1 digests. + When you're granted access for a limited time, C1.ai will send you reminders that the access is expiring, at 30 days, 14 days, three days, one day, and one hour before the grant ends (whichever of these apply to how long your access lasts). Expiring access is also shown in C1.ai digests. @@ -150,7 +150,7 @@ Click **Enroll**. While a request is pending, a link to the request task is shown. Click the link to view the status of the request and see who the assigned reviewers are. You can leave a comment on any request, and even cancel it if needed. -C1 will send you an email when your request is approved or rejected, and another when the new access is granted. +C1.ai will send you an email when your request is approved or rejected, and another when the new access is granted. ## Request on the New request page @@ -160,7 +160,7 @@ If you already know what access you need, use the **New request** page to quickl -In C1, click **New request** and select the **Access profiles** tab. +In C1.ai, click **New request** and select the **Access profiles** tab. @@ -170,7 +170,7 @@ Select the profile you want to request. Set how long you need the access for. Some sensitive or expensive profiles can only be requested for a limited time. Choose from one of the pre-set options, or enter a custom timeframe by selecting **Custom**. - When you're granted access for a limited time, C1 will send you reminders that the access is expiring, at 30 days, 14 days, three days, one day, and one hour before the grant ends (whichever of these apply to how long your access lasts). Expiring access is also shown in C1 digests. + When you're granted access for a limited time, C1.ai will send you reminders that the access is expiring, at 30 days, 14 days, three days, one day, and one hour before the grant ends (whichever of these apply to how long your access lasts). Expiring access is also shown in C1.ai digests. Tell the reviewer why you're requesting this profile. This helps them make their decision, so be specific. @@ -181,15 +181,15 @@ Click **Request profile**. -**Done.** C1 will automatically create individual requests for everything in the access profile that you don't already have access to. You can view the status of the requests on your **My requests** list on the **Requests** page. You can leave a comment on any request, and even cancel it if needed. +**Done.** C1.ai will automatically create individual requests for everything in the access profile that you don't already have access to. You can view the status of the requests on your **My requests** list on the **Requests** page. You can leave a comment on any request, and even cancel it if needed. -C1 will send you an email when your requests are approved or rejected, and another when new access is granted. +C1.ai will send you an email when your requests are approved or rejected, and another when new access is granted. ### Request an app or permission -In C1, click **New request** and select the **Apps** tab. +In C1.ai, click **New request** and select the **Apps** tab. @@ -222,7 +222,7 @@ Select the specific entitlements you need. Based on the type of access available Set how long you need the access for. Some sensitive or expensive resources can only be requested for a limited time. Choose from one of the pre-set options, or enter a custom timeframe by selecting **Custom**. - When you're granted access for a limited time, C1 will send you reminders that the access is expiring, at 30 days, 14 days, three days, one day, and one hour before the grant ends (whichever of these apply to how long your access lasts). Expiring access is also shown in C1 digests. + When you're granted access for a limited time, C1.ai will send you reminders that the access is expiring, at 30 days, 14 days, three days, one day, and one hour before the grant ends (whichever of these apply to how long your access lasts). Expiring access is also shown in C1.ai digests. @@ -247,18 +247,18 @@ Click **Submit request**. A drawer pops open to shown you the details of the new -**Done.** C1 will send you an email when your request is approved or rejected, and another when the new access is granted. +**Done.** C1.ai will send you an email when your request is approved or rejected, and another when the new access is granted. -## Request using the C1 app for Slack +## Request using the C1.ai app for Slack -If your company uses Slack and an admin has set up the C1 app for Slack, you can request new access and receive notifications directly from the platform. +If your company uses Slack and an admin has set up the C1.ai app for Slack, you can request new access and receive notifications directly from the platform. -### Add the C1 app for Slack to your account +### Add the C1.ai app for Slack to your account **Before you begin:** -A Slack administrator at your company must install the C1 app in your Slack workspace. +A Slack administrator at your company must install the C1.ai app in your Slack workspace. @@ -267,15 +267,15 @@ In Slack, navigate to the **Apps** section of the navigation bar. -Click **Add apps** and search for C1. +Click **Add apps** and search for C1.ai. -Click the C1 app and follow the prompts to add it to your Slack account. +Click the C1.ai app and follow the prompts to add it to your Slack account. -**Done.** You can now interact with C1 directly from Slack. +**Done.** You can now interact with C1.ai directly from Slack. ### Create an access request @@ -283,12 +283,12 @@ Click the C1 app and follow the prompts to add it to your Slack account. In any Slack channel, type `/c1 request`. - Alternatively, navigate to the C1 app for Slack and click **Home** > **Request Access**. + Alternatively, navigate to the C1.ai app for Slack and click **Home** > **Request Access**. The **Submit a Request** form opens. - The C1 app for Slack showing the Submit a Request form. + The C1.ai app for Slack showing the Submit a Request form. @@ -300,7 +300,7 @@ Select the specific entitlement (permission) you need. If you're looking for a n If asked, specify how long you need the access for. Some sensitive or expensive resources have limited duration requirements, others can be requested indefinitely (if you're requesting one of these, you won't be asked about a duration). - When you're granted access for a limited time, C1 will send you reminders that the access is expiring, at 30 days, 14 days, three days, one day, and one hour before the grant ends (whichever of these apply to how long your access lasts). Expiring access is also shown in C1 digests. + When you're granted access for a limited time, C1.ai will send you reminders that the access is expiring, at 30 days, 14 days, three days, one day, and one hour before the grant ends (whichever of these apply to how long your access lasts). Expiring access is also shown in C1.ai digests. @@ -312,27 +312,27 @@ Click **Submit**. -**Done.** You'll immediately get a new access request notification on the **Messages** tab of the C1 app for Slack. +**Done.** You'll immediately get a new access request notification on the **Messages** tab of the C1.ai app for Slack. -The C1 app for Slack showing the New request form with the Submit button. +The C1.ai app for Slack showing the New request form with the Submit button. -This is also where you'll be notified when your new access is granted. Comments or updates on your request will be added to it in a thread. You can also type new comments in the thread, and they will be automatically copied to the request's details view in the C1 web app and sent to the request's assigned approvers in Slack. +This is also where you'll be notified when your new access is granted. Comments or updates on your request will be added to it in a thread. You can also type new comments in the thread, and they will be automatically copied to the request's details view in the C1.ai web app and sent to the request's assigned approvers in Slack. -If you want to see the access request task with all its details, click the blue **Grant [your name] [your requested access]** link in the notification to go to the request's details view in the C1 web app. +If you want to see the access request task with all its details, click the blue **Grant [your name] [your requested access]** link in the notification to go to the request's details view in the C1.ai web app. ## Request using the Microsoft Teams app -If your company uses Microsoft Teams and an admin has set up the C1 Microsoft Teams app, you can request new access and receive notifications directly from the platform. +If your company uses Microsoft Teams and an admin has set up the C1.ai Microsoft Teams app, you can request new access and receive notifications directly from the platform. -### Set up the C1 MS Teams app on an individual workstation +### Set up the C1.ai MS Teams app on an individual workstation -If a Teams admin at your organization has not automatically added the C1 app to your organization's Teams interface, you can set it up on your workstation yourself. Here's what to do: +If a Teams admin at your organization has not automatically added the C1.ai app to your organization's Teams interface, you can set it up on your workstation yourself. Here's what to do: -Go to [Microsoft Marketplace](https://marketplace.microsoft.com/en-us/), search for "C1" and download the app. +Go to [Microsoft Marketplace](https://marketplace.microsoft.com/en-us/), search for "C1.ai" and download the app. If the app isn't available, check with an admin to ensure that they've completed the installation steps above. @@ -340,13 +340,13 @@ Go to [Microsoft Marketplace](https://marketplace.microsoft.com/en-us/), search -**Done.** You're set up and ready to work with C1 from the comfort of your Teams interface. +**Done.** You're set up and ready to work with C1.ai from the comfort of your Teams interface. ### Create an access request -In Microsoft Teams, click the **+** (Actions and apps) icon and select the C1 app. +In Microsoft Teams, click the **+** (Actions and apps) icon and select the C1.ai app. @@ -358,7 +358,7 @@ Select the specific entitlement (permission) you need. If you're looking for a n If asked, specify how long you need the access for. Some sensitive or expensive resources have limited duration requirements, others can be requested indefinitely (if you're requesting one of these, you won't be asked about a duration). - When you're granted access for a limited time, C1 will send you reminders that the access is expiring, at 30 days, 14 days, three days, one day, and one hour before the grant ends (whichever of these apply to how long your access lasts). Expiring access is also shown in C1 digests. + When you're granted access for a limited time, C1.ai will send you reminders that the access is expiring, at 30 days, 14 days, three days, one day, and one hour before the grant ends (whichever of these apply to how long your access lasts). Expiring access is also shown in C1.ai digests. diff --git a/product/how-to/intro.mdx b/product/how-to/intro.mdx index 7e2f7237..d0b2b145 100644 --- a/product/how-to/intro.mdx +++ b/product/how-to/intro.mdx @@ -1,16 +1,16 @@ --- -title: "Welcome to C1" -og:title: "Welcome to C1" -og:description: "Request access, complete review and approval tasks, and work with AI tools in C1." -description: "Request access, complete review and approval tasks, and work with AI tools in C1." +title: "Welcome to C1.ai" +og:title: "Welcome to C1.ai" +og:description: "Request access, complete review and approval tasks, and work with AI tools in C1.ai." +description: "Request access, complete review and approval tasks, and work with AI tools in C1.ai." sidebarTitle: "Overview" --- {/* Editor Refresh: 2026-08-04 */} -Welcome! If you're using C1 to request access, review your colleagues' access, or connect AI tools, you'll find instructions and guidance here. +Welcome! If you're using C1.ai to request access, review your colleagues' access, or connect AI tools, you'll find instructions and guidance here. -Working on setting up C1 for your organization? Go to [Administer C1](/product/intro). +Working on setting up C1.ai for your organization? Go to [Administer C1.ai](/product/intro). ## What are you trying to do? @@ -20,7 +20,7 @@ Working on setting up C1 for your organization? Go to [Administer C1](/product/i Ask for access to an application, group, role, or other resource. - Get access to governed AI tools and connect your AI client or MCP server to C1. + Get access to governed AI tools and connect your AI client or MCP server to C1.ai. Verify that your access, or access you're responsible for, is still appropriate. @@ -29,7 +29,7 @@ Working on setting up C1 for your organization? Go to [Administer C1](/product/i Approve, provision, or revoke access assigned to you as a task. - Request operational actions like device provisioning through C1's Actions catalog. + Request operational actions like device provisioning through C1.ai's Actions catalog. @@ -48,12 +48,12 @@ Working on setting up C1 for your organization? Go to [Administer C1](/product/i A request is something you ask for, like access to an app. A review is something you're asked to do, like confirming that a colleague's access is still appropriate as part of a [user access review campaign](/product/how-to/review-tasks). Both can show up as tasks that need your attention. - C1 admins control which apps and permissions you can see and request, based on your department or role. See [How to request new access](/product/how-to/create-requests) for more on how this works. + C1.ai admins control which apps and permissions you can see and request, based on your department or role. See [How to request new access](/product/how-to/create-requests) for more on how this works. Someone with the right permissions — an approver, an admin, or an automated policy — can grant or revoke access on your behalf. Check [How to complete access change tasks](/product/how-to/access-change-tasks) if you're the one responsible for making that change for someone else. - C1 notifies you by email, Slack, or Microsoft Teams. Confirm your notification preferences on the [notification settings page](/product/admin/notifications-user-settings). + C1.ai notifies you by email, Slack, or Microsoft Teams. Confirm your notification preferences on the [notification settings page](/product/admin/notifications-user-settings). diff --git a/product/how-to/qs-aws-jit-identity-center.mdx b/product/how-to/qs-aws-jit-identity-center.mdx index 8241afd2..1b25cd83 100644 --- a/product/how-to/qs-aws-jit-identity-center.mdx +++ b/product/how-to/qs-aws-jit-identity-center.mdx @@ -1,6 +1,6 @@ --- title: "Get started with JIT access for AWS (using Identity Center)" -og:title: "How to set up AWS just-in-time access - C1 docs" +og:title: "How to set up AWS just-in-time access - C1.ai docs" og:description: "Follow this guide to get started with just-in-time (JIT) access to your Amazon Web Services (AWS) resources." description: "Follow this guide to get started with just-in-time (JIT) access to your Amazon Web Services (AWS) resources." sidebarTitle: "AWS JIT" @@ -11,7 +11,7 @@ sidebarTitle: "AWS JIT" To complete this guide, you'll need: -- C1 **Super Administrator** role +- C1.ai **Super Administrator** role - AWS with Identity Center configured - Ability to set up an AWS role trust @@ -19,18 +19,18 @@ To complete this guide, you'll need: ## Step 1: Integrate your AWS instance -Integrate your AWS instance with C1. Follow our instructions to set up the [AWS v2 connector](/baton/aws). +Integrate your AWS instance with C1.ai. Follow our instructions to set up the [AWS v2 connector](/baton/aws). Make sure to select these configuration options on the connector setup screen: - Enable support for AWS Organizations - Enable support for AWS IAM Identity Center -Once connected, C1 ingests all of the resources and entitlements for AWS. This includes accounts, roles within accounts, identity center users, identity center groups, and permission sets. You can see all the resources and entitlements by going to **Apps** > **AWS** and clicking **Entitlements**. +Once connected, C1.ai ingests all of the resources and entitlements for AWS. This includes accounts, roles within accounts, identity center users, identity center groups, and permission sets. You can see all the resources and entitlements by going to **Apps** > **AWS** and clicking **Entitlements**. ## Step 2: Configure AWS accounts for JIT access -Now that AWS is hooked up to C1, set AWS accounts as available for just-in-time access. To do this, we'll configure entitlement management rules for each of the AWS accounts. +Now that AWS is hooked up to C1.ai, set AWS accounts as available for just-in-time access. To do this, we'll configure entitlement management rules for each of the AWS accounts. @@ -65,7 +65,7 @@ Let's go request AWS JIT access! -In C1, click **Requests** and make sure that **App catalog** is selected. +In C1.ai, click **Requests** and make sure that **App catalog** is selected. Click **AWS**. A panel opens with the account resources available for you to request. diff --git a/product/how-to/qs-entra-app-requests.mdx b/product/how-to/qs-entra-app-requests.mdx index 54d041c8..09724da8 100644 --- a/product/how-to/qs-entra-app-requests.mdx +++ b/product/how-to/qs-entra-app-requests.mdx @@ -1,6 +1,6 @@ --- title: Get started with Microsoft Entra application requests -og:title: How to set up access requests with Microsoft Entra apps - C1 docs +og:title: How to set up access requests with Microsoft Entra apps - C1.ai docs og:description: Follow this guide to get started with access requests for Microsoft Entra applications description: Follow this guide to get started with self service requests for Microsoft Entra apps. sidebarTitle: Microsoft Entra app requests @@ -11,20 +11,20 @@ sidebarTitle: Microsoft Entra app requests To complete this guide, you'll need: -- C1 **Super Administrator** or **Connector Administrator** role +- C1.ai **Super Administrator** or **Connector Administrator** role - A Microsoft Entra account **Estimated time:** 10 minutes ## Step 1: Integrate your Microsoft Entra instance -Start by integrating your Microsoft Entra instance with C1. Use the [Microsoft Entra connector](/baton/microsoft-entra) to sync Microsoft Entra to C1. +Start by integrating your Microsoft Entra instance with C1.ai. Use the [Microsoft Entra connector](/baton/microsoft-entra) to sync Microsoft Entra to C1.ai. -Once connected, C1 ingests all of the users, apps, groups, and other entitlements and resources from Microsoft Entra. +Once connected, C1.ai ingests all of the users, apps, groups, and other entitlements and resources from Microsoft Entra. ## Step 2: Convert a Microsoft Entra app to a managed app -Before managing access to a Microsoft Entra app, you'll need to begin managing it with C1. +Before managing access to a Microsoft Entra app, you'll need to begin managing it with C1.ai. @@ -41,18 +41,18 @@ Click **Manage**. **Don’t stress.** -Converting an app from unmanaged to managed in C1 does not change any configuration in the IdP. +Converting an app from unmanaged to managed in C1.ai does not change any configuration in the IdP. Once an application is managed, you can enforce access controls, run user access reviews, and drive lifecycle management for the app. ## Step 3: Configure the app entitlements (optional) -Every managed application in C1 comes with a **Credential** resource. This "access entitlement" is used to manage account-level access to application. In Microsoft Entra, at a minimum, this means that the user is assigned to the Microsoft Entra app. +Every managed application in C1.ai comes with a **Credential** resource. This "access entitlement" is used to manage account-level access to application. In Microsoft Entra, at a minimum, this means that the user is assigned to the Microsoft Entra app. -Additionally, applications configured in Microsoft Entra may use groups to SCIM roles and permissions to the connected application. C1 can easily convert these **linked entitlements** into resources and entitlements in your C1 instance. +Additionally, applications configured in Microsoft Entra may use groups to SCIM roles and permissions to the connected application. C1.ai can easily convert these **linked entitlements** into resources and entitlements in your C1.ai instance. -If groups are assigned to the application in Microsoft Entra, you can convert these linked entitlements from Microsoft Entra into in-app entitlements in the C1 app: +If groups are assigned to the application in Microsoft Entra, you can convert these linked entitlements from Microsoft Entra into in-app entitlements in the C1.ai app: @@ -62,9 +62,9 @@ Click **Entitlements**, then click the **Linked entitlements** icon at the top r In the **Linked entitlements** drawer, click the **Setup** tab. -For each IdP entitlement C1 has identified as linked to the app, choose an action: +For each IdP entitlement C1.ai has identified as linked to the app, choose an action: - - **Create virtual role**: Set up a new role in the app that will be linked to the IdP entitlement. This role will only exist in C1, and will function as an alias for the IdP entitlement. Your colleagues can request and review the role, which will appear as part of the app, but they will in actuality be requesting or reviewing the IdP entitlement. + - **Create virtual role**: Set up a new role in the app that will be linked to the IdP entitlement. This role will only exist in C1.ai, and will function as an alias for the IdP entitlement. Your colleagues can request and review the role, which will appear as part of the app, but they will in actuality be requesting or reviewing the IdP entitlement. - **Provision access for**: Link the IdP entitlement to an existing entitlement in the app. When your colleagues request or review the app entitlement, they will also be requesting or reviewing the IdP entitlement. @@ -75,7 +75,7 @@ When you've made all of your selections, click **Save**. -C1 will now create the resources and entitlements in the managed app and set a binding for that entitlement to the Microsoft Entra group. This binding is what allows C1 to automatically provision access when a user is granted the entitlement. +C1.ai will now create the resources and entitlements in the managed app and set a binding for that entitlement to the Microsoft Entra group. This binding is what allows C1.ai to automatically provision access when a user is granted the entitlement. ## Step 4: Configure the app and entitlements for self-service @@ -127,6 +127,6 @@ Enter the justification and click **Request**. ## Success! -The request will be auto-approved based on the policy, and C1 will provision your access by assigning you to the application and the correct groups in Microsoft Entra. +The request will be auto-approved based on the policy, and C1.ai will provision your access by assigning you to the application and the correct groups in Microsoft Entra. diff --git a/product/how-to/qs-gcp-jit.mdx b/product/how-to/qs-gcp-jit.mdx index 409a55ec..c0fc76ec 100644 --- a/product/how-to/qs-gcp-jit.mdx +++ b/product/how-to/qs-gcp-jit.mdx @@ -1,6 +1,6 @@ --- title: "Get started with just-in-time access in Google Cloud Platform" -og:title: "How to set up GCP just-in-time (JIT) access - C1 docs" +og:title: "How to set up GCP just-in-time (JIT) access - C1.ai docs" og:description: "Follow this guide to get started with just-in-time (JIT) access to your Google Cloud Platform (GCP) resources." description: "Follow this guide to get started with just-in-time (JIT) access to your Google Cloud Platform (GCP) resources." sidebarTitle: "GCP JIT" @@ -11,7 +11,7 @@ sidebarTitle: "GCP JIT" To complete this guide, you'll need: -- C1 **Connector Administrator** role or **Super Administrator** role +- C1.ai **Connector Administrator** role or **Super Administrator** role - A Google Cloud Platform account - Ability to set up a service account in GCP @@ -19,13 +19,13 @@ To complete this guide, you'll need: ## Step 1: Integrate your GCP instance -Start by integrating your GCP instance with C1 by following the instructions in [Google Workspace & Google Cloud Platform](/baton/google-cloud-platform). +Start by integrating your GCP instance with C1.ai by following the instructions in [Google Workspace & Google Cloud Platform](/baton/google-cloud-platform). -Once connected, C1 ingests all of the projects, resources, and entitlements for Google Cloud. This includes projects and roles. You can see all the resources and entitlements by navigating to **Apps** > **Google Cloud Platform** and clicking **Entitlements**. +Once connected, C1.ai ingests all of the projects, resources, and entitlements for Google Cloud. This includes projects and roles. You can see all the resources and entitlements by navigating to **Apps** > **Google Cloud Platform** and clicking **Entitlements**. ## Step 2: Configure GCP projects for JIT access -Now that GCP is hooked up to C1, set GCP projects and roles as available for just-in-time access. To do this, we'll configure entitlement management rules for each of the GCP projects. +Now that GCP is hooked up to C1.ai, set GCP projects and roles as available for just-in-time access. To do this, we'll configure entitlement management rules for each of the GCP projects. diff --git a/product/how-to/qs-okta-app-requests.mdx b/product/how-to/qs-okta-app-requests.mdx index d6a35afa..707356a8 100644 --- a/product/how-to/qs-okta-app-requests.mdx +++ b/product/how-to/qs-okta-app-requests.mdx @@ -1,6 +1,6 @@ --- title: Get started with Okta application requests -og:title: How to set up access requests with Okta apps - C1 docs +og:title: How to set up access requests with Okta apps - C1.ai docs og:description: Follow this guide to get started with access requests for Okta applications description: Follow this guide to get started with self service requests for Okta apps. sidebarTitle: Okta app requests @@ -11,20 +11,20 @@ sidebarTitle: Okta app requests To complete this guide, you'll need: -- C1 **Super Administrator** or **Connector Administrator** role +- C1.ai **Super Administrator** or **Connector Administrator** role - An Okta account **Estimated time:** 10 minutes ## Step 1: Integrate your Okta instance -Start by integrating your Okta instance with C1. Use the [Okta connector](/baton/okta) to sync Okta to C1. +Start by integrating your Okta instance with C1.ai. Use the [Okta connector](/baton/okta) to sync Okta to C1.ai. -Once connected, C1 ingests all of the users, apps, groups, and other entitlements and resources from Okta. +Once connected, C1.ai ingests all of the users, apps, groups, and other entitlements and resources from Okta. ## Step 2: Convert an Okta app to a managed app -Before managing access to an Okta app, you'll need to begin managing it with C1. +Before managing access to an Okta app, you'll need to begin managing it with C1.ai. @@ -40,18 +40,18 @@ Click **Manage**. **Don’t stress.** -Converting an app from unmanaged to managed in C1 does not change any configuration in the IdP. +Converting an app from unmanaged to managed in C1.ai does not change any configuration in the IdP. Once an application is managed, you can enforce access controls, run user access reviews, and drive lifecycle management for the app. ## Step 3: Configure the app entitlements (optional) -Every managed application in C1 comes with a **Credential** resource. This "access entitlement" is used to manage account level access to application. In Okta, at a minimum, this means that the user is assigned to the Okta app. +Every managed application in C1.ai comes with a **Credential** resource. This "access entitlement" is used to manage account level access to application. In Okta, at a minimum, this means that the user is assigned to the Okta app. -Additionally, applications configured in Okta may use groups to SCIM roles and permissions to the connected application. C1 can easily convert these **linked entitlements** into resources and entitlements in your C1 instance. +Additionally, applications configured in Okta may use groups to SCIM roles and permissions to the connected application. C1.ai can easily convert these **linked entitlements** into resources and entitlements in your C1.ai instance. -If groups are assigned to the application in Okta, you can convert these linked entitlements from Okta into in-app entitlements in the C1 app: +If groups are assigned to the application in Okta, you can convert these linked entitlements from Okta into in-app entitlements in the C1.ai app: @@ -61,9 +61,9 @@ Click **Entitlements**, then click the **Linked entitlements** icon at the top r In the **Linked entitlements** drawer, click the **Setup** tab. -For each IdP entitlement C1 has identified as linked to the app, choose an action: +For each IdP entitlement C1.ai has identified as linked to the app, choose an action: - - **Create virtual role**: Set up a new role in the app that will be linked to the IdP entitlement. This role will only exist in C1, and will function as an alias for the IdP entitlement. Your colleagues can request and review the role, which will appear as part of the app, but they will in actuality be requesting or reviewing the IdP entitlement. + - **Create virtual role**: Set up a new role in the app that will be linked to the IdP entitlement. This role will only exist in C1.ai, and will function as an alias for the IdP entitlement. Your colleagues can request and review the role, which will appear as part of the app, but they will in actuality be requesting or reviewing the IdP entitlement. - **Provision access for**: Link the IdP entitlement to an existing entitlement in the app. When your colleagues request or review the app entitlement, they will also be requesting or reviewing the IdP entitlement. @@ -73,7 +73,7 @@ For each IdP entitlement C1 has identified as linked to the app, choose an actio When you've made all of your selections, click **Save**. -C1 will now create the resources and entitlements in the managed app and set a binding for that entitlement to the Okta group. This binding is what allows C1 to automatically provision access when a user is granted the entitlement. +C1.ai will now create the resources and entitlements in the managed app and set a binding for that entitlement to the Okta group. This binding is what allows C1.ai to automatically provision access when a user is granted the entitlement. ## Step 4: Configure the app and entitlements for self-service @@ -125,6 +125,6 @@ Enter the justification and click **Request**. ## Success! -The request will be auto-approved based on the policy, and C1 will provision your access by assigning you to the application and the correct groups in Okta. +The request will be auto-approved based on the policy, and C1.ai will provision your access by assigning you to the application and the correct groups in Okta. diff --git a/product/how-to/qs-on-call-access-control.mdx b/product/how-to/qs-on-call-access-control.mdx index 25e2a1f6..d58c7ee8 100644 --- a/product/how-to/qs-on-call-access-control.mdx +++ b/product/how-to/qs-on-call-access-control.mdx @@ -1,6 +1,6 @@ --- title: "Get started with on-call access control" -og:title: "How to automate on-call access controls - C1 docs" +og:title: "How to automate on-call access controls - C1.ai docs" og:description: "Follow this guide to get started automating access controls for on-call rotations" description: "Follow this guide to get started automating access controls for on-call rotations." sidebarTitle: "On-call access control" @@ -11,14 +11,14 @@ sidebarTitle: "On-call access control" To complete this guide, you'll need: -- C1 **Super Administrator** role +- C1.ai **Super Administrator** role - A PagerDuty, OpsGenie, or other on-call-enabled application **Estimated time:** 15 minutes ## Step 1: Integrate your on-call platform -Start by following the docs to integrate your on-call platform with C1: +Start by following the docs to integrate your on-call platform with C1.ai: @@ -29,7 +29,7 @@ Start by following the docs to integrate your on-call platform with C1: **Don't see your on-call platform?** Don't stress. We'll build a connector for it. [Get in touch](mailto:support@c1.ai) and tell us what you need. -Once connected, C1 ingests the users and roles within the platform, and surfaces on-call rotations as resources. +Once connected, C1.ai ingests the users and roles within the platform, and surfaces on-call rotations as resources. ## Step 2: Create your on-call access profile diff --git a/product/how-to/qs-onelogin-app-requests.mdx b/product/how-to/qs-onelogin-app-requests.mdx index 51025e84..aa442f8a 100644 --- a/product/how-to/qs-onelogin-app-requests.mdx +++ b/product/how-to/qs-onelogin-app-requests.mdx @@ -1,6 +1,6 @@ --- title: Get started with OneLogin application requests -og:title: How to set up access requests with OneLogin apps - C1 docs +og:title: How to set up access requests with OneLogin apps - C1.ai docs og:description: Follow this guide to get started with access requests for OneLogin applications description: Follow this guide to get started with self service requests for OneLogin apps. sidebarTitle: OneLogin app requests @@ -11,20 +11,20 @@ sidebarTitle: OneLogin app requests To complete this guide, you'll need: -- C1 **Super Administrator** or **Connector Administrator** role +- C1.ai **Super Administrator** or **Connector Administrator** role - A OneLogin account **Estimated time:** 10 minutes ## Step 1: Integrate your OneLogin instance -Start by integrating your OneLogin instance with C1. Use the [OneLogin connector](/baton/onelogin) to sync OneLogin to C1. +Start by integrating your OneLogin instance with C1.ai. Use the [OneLogin connector](/baton/onelogin) to sync OneLogin to C1.ai. -Once connected, C1 ingests all of the users, apps, groups, and other entitlements and resources from OneLogin. +Once connected, C1.ai ingests all of the users, apps, groups, and other entitlements and resources from OneLogin. ## Step 2: Convert an OneLogin app to a managed app -Before managing access to a OneLogin app, you'll need to begin managing it with C1. +Before managing access to a OneLogin app, you'll need to begin managing it with C1.ai. @@ -40,18 +40,18 @@ Click **Manage**. **Don’t stress.** -Converting an app from unmanaged to managed in C1 does not change any configuration in the IdP. +Converting an app from unmanaged to managed in C1.ai does not change any configuration in the IdP. Once an application is managed, you can enforce access controls, run user access reviews, and drive lifecycle management for the app. ## Step 3: Configure the app entitlements (optional) -Every managed application in C1 comes with a **Credential** resource. This "access entitlement" is used to manage account level access to application. In OneLogin, at a minimum, this means that the user is assigned to the OneLogin app. +Every managed application in C1.ai comes with a **Credential** resource. This "access entitlement" is used to manage account level access to application. In OneLogin, at a minimum, this means that the user is assigned to the OneLogin app. -Additionally, applications configured in OneLogin may use groups to SCIM roles and permissions to the connected application. C1 can easily convert these **linked entitlements** into resources and entitlements in your C1 instance. +Additionally, applications configured in OneLogin may use groups to SCIM roles and permissions to the connected application. C1.ai can easily convert these **linked entitlements** into resources and entitlements in your C1.ai instance. -If groups are assigned to the application in OneLogin, you can convert these linked entitlements from OneLogin into in-app entitlements in the C1 app: +If groups are assigned to the application in OneLogin, you can convert these linked entitlements from OneLogin into in-app entitlements in the C1.ai app: @@ -61,9 +61,9 @@ Click **Entitlements**, then click the **Linked entitlements** icon at the top r In the **Linked entitlements** drawer, click the **Setup** tab. -For each IdP entitlement C1 has identified as linked to the app, choose an action: +For each IdP entitlement C1.ai has identified as linked to the app, choose an action: - - **Create virtual role**: Set up a new role in the app that will be linked to the IdP entitlement. This role will only exist in C1, and will function as an alias for the IdP entitlement. Your colleagues can request and review the role, which will appear as part of the app, but they will in actuality be requesting or reviewing the IdP entitlement. + - **Create virtual role**: Set up a new role in the app that will be linked to the IdP entitlement. This role will only exist in C1.ai, and will function as an alias for the IdP entitlement. Your colleagues can request and review the role, which will appear as part of the app, but they will in actuality be requesting or reviewing the IdP entitlement. - **Provision access for**: Link the IdP entitlement to an existing entitlement in the app. When your colleagues request or review the app entitlement, they will also be requesting or reviewing the IdP entitlement. @@ -74,7 +74,7 @@ When you've made all of your selections, click **Save**. -C1 will now create the resources and entitlements in the managed app and set a binding for that entitlement to the OneLogin group. This binding is what allows C1 to automatically provision access when a user is granted the entitlement. +C1.ai will now create the resources and entitlements in the managed app and set a binding for that entitlement to the OneLogin group. This binding is what allows C1.ai to automatically provision access when a user is granted the entitlement. ## Step 4: Configure the app and entitlements for self-service @@ -126,6 +126,6 @@ Enter the justification and click **Request**. ## Success! -The request will be auto-approved based on the policy, and C1 will provision your access by assigning you to the application and the correct groups in OneLogin. +The request will be auto-approved based on the policy, and C1.ai will provision your access by assigning you to the application and the correct groups in OneLogin. diff --git a/product/how-to/qs-self-service-requests.mdx b/product/how-to/qs-self-service-requests.mdx index b3d7a97c..72d355bb 100644 --- a/product/how-to/qs-self-service-requests.mdx +++ b/product/how-to/qs-self-service-requests.mdx @@ -1,25 +1,25 @@ --- title: Get started with self service requests -og:title: Get started with self-service requests - C1 docs -og:description: Follow our step-by-step guide to setting up self-service access requests with C1. -description: Follow our step-by-step guide to setting up self-service access requests with C1. +og:title: Get started with self-service requests - C1.ai docs +og:description: Follow our step-by-step guide to setting up self-service access requests with C1.ai. +description: Follow our step-by-step guide to setting up self-service access requests with C1.ai. sidebarTitle: Self-service requests --- {/* Editor Refresh: 2026-01-07 */} -In this guide we'll set up self-service access requests for the **Connector Administrator** role in C1. Once setup is complete, users can request this role, either permanently or temporarily through JIT (just-in-time) access. +In this guide we'll set up self-service access requests for the **Connector Administrator** role in C1.ai. Once setup is complete, users can request this role, either permanently or temporarily through JIT (just-in-time) access. ## Before you begin To complete this guide, you'll need: -- C1 **Super Administrator** role +- C1.ai **Super Administrator** role **Estimated time:** 5 minutes -## Step 1: Navigate to the C1 app +## Step 1: Navigate to the C1.ai app -First, we need to find the C1 application: +First, we need to find the C1.ai application: @@ -38,12 +38,12 @@ Next, make the **Connector Administrator** role requestable: Click **Entitlements**. -Click the **Resource type** filter to show only roles in C1. +Click the **Resource type** filter to show only roles in C1.ai. Locate the **Connector Administrator** entitlement. - We're going to configure this entitlement for self-service access requests using C1 access controls. + We're going to configure this entitlement for self-service access requests using C1.ai access controls. In the **Requests** column for the entitlement, click to edit the access request settings. The configuration drawer opens. @@ -55,11 +55,11 @@ In the **Access profiles** field, search for and select **Everyone**. No need to Click **Save**. -We have now published the **Connector Administrator** role to the **Everyone** access profile in C1. Now any C1 user can request it. +We have now published the **Connector Administrator** role to the **Everyone** access profile in C1.ai. Now any C1.ai user can request it. ## Step 3: Test it out -Let's walk through the experience of a C1 end user requesting the **Connector Administrator** role. We'll pretend that the requesting user (that's you!) temporarily needs the **Connector Administrator** role in order to create a new connector. +Let's walk through the experience of a C1.ai end user requesting the **Connector Administrator** role. We'll pretend that the requesting user (that's you!) temporarily needs the **Connector Administrator** role in order to create a new connector. @@ -96,6 +96,6 @@ Your request is submitted and a summary is shown. Because of the default settings for this tenant, the access request will be automatically approved and provisioned. You have been granted the **Connector Administrator** role for one hour. -This is a simple example of what C1 can do. From here, you can add more applications, enforce access controls on other entitlements and resources, and configure your approval policies. +This is a simple example of what C1.ai can do. From here, you can add more applications, enforce access controls on other entitlements and resources, and configure your approval policies. diff --git a/product/how-to/qs-set-up-c1.mdx b/product/how-to/qs-set-up-c1.mdx index 25f0dd4a..a0bf0572 100644 --- a/product/how-to/qs-set-up-c1.mdx +++ b/product/how-to/qs-set-up-c1.mdx @@ -1,9 +1,9 @@ --- -title: Create a C1 tenant +title: Create a C1.ai tenant sidebarTitle: Create a tenant and set up SSO -og:title: Create a C1 tenant and set up SSO - C1 docs -og:description: Create your C1 tenant and configure single sign-on (SSO) with your identity provider — Okta, Google, Microsoft Entra ID, OneLogin, JumpCloud, PingOne, or any OIDC provider. -description: Create your C1 tenant and configure single sign-on (SSO) with your identity provider — Okta, Google, Microsoft Entra ID, OneLogin, JumpCloud, PingOne, or any OIDC provider. +og:title: Create a C1.ai tenant and set up SSO - C1.ai docs +og:description: Create your C1.ai tenant and configure single sign-on (SSO) with your identity provider — Okta, Google, Microsoft Entra ID, OneLogin, JumpCloud, PingOne, or any OIDC provider. +description: Create your C1.ai tenant and configure single sign-on (SSO) with your identity provider — Okta, Google, Microsoft Entra ID, OneLogin, JumpCloud, PingOne, or any OIDC provider. --- {/* Editor Refresh: 2026-01-07 */} @@ -11,12 +11,12 @@ description: Create your C1 tenant and configure single sign-on (SSO) with your To complete this guide, you'll need: -- A C1 enrollment code (if you don't have an enrollment code, contact [support@c1.ai](mailto:support@c1.ai)) +- A C1.ai enrollment code (if you don't have an enrollment code, contact [support@c1.ai](mailto:support@c1.ai)) - Ability to create an SSO app in the IdP (if using Okta, OneLogin, or JumpCloud) ## Hosting regions -C1 runs two hosting options: a **default instance** and an **EU data residency instance**. Your tenant is provisioned in one region, and every tenant-specific URL — login, redirect URIs, API and webhook endpoints, MCP server, and CLI configuration — reflects that region. Choose carefully: hosting region is a one-time choice made at signup and can't be changed afterward. +C1.ai runs two hosting options: a **default instance** and an **EU data residency instance**. Your tenant is provisioned in one region, and every tenant-specific URL — login, redirect URIs, API and webhook endpoints, MCP server, and CLI configuration — reflects that region. Choose carefully: hosting region is a one-time choice made at signup and can't be changed afterward. | | Default instance | EU data residency instance | |---|---|---| @@ -26,16 +26,16 @@ C1 runs two hosting options: a **default instance** and an **EU data residency i | Redirect and callback URLs | `accounts.conductor.one` | `accounts.c1eu.ai` | | API, webhook, and MCP endpoints | `conductor.one` | `c1eu.ai` | -Please note that Microsoft Teams as a C1 notification and interaction surface is not yet supported on the EU data residency instance. +Please note that Microsoft Teams as a C1.ai notification and interaction surface is not yet supported on the EU data residency instance. -## Step 1: Register your C1 domain +## Step 1: Register your C1.ai domain Go to [accounts.conductor.one/accounts/signup](https://accounts.conductor.one/accounts/signup) or [accounts.c1eu.ai/accounts/signup](https://accounts.c1eu.ai/accounts/signup) for EU instances. -In the **Domain** field, enter the domain you want to use for your C1 instance. +In the **Domain** field, enter the domain you want to use for your C1.ai instance. For example, if you work at Acme Co., enter `acmeco` to create an `acmeco.conductor.one` domain. @@ -43,7 +43,7 @@ In the **Domain** field, enter the domain you want to use for your C1 instance. In the **Display name** field, enter the name of your company. -In the **Invite code** field, paste in the invite code you received from C1. The code is case-sensitive. +In the **Invite code** field, paste in the invite code you received from C1.ai. The code is case-sensitive. Click **Sign up with [your SSO provider]**. @@ -68,40 +68,40 @@ Jump to the instructions for your SSO provider: When prompted to login, click your corporate account and continue logging in. -Google will now re-authenticate you, if needed, and log you in to C1. +Google will now re-authenticate you, if needed, and log you in to C1.ai. ## Authenticate with Okta -### Step 1: Add the C1 app in Okta +### Step 1: Add the C1.ai app in Okta -First, add the C1 app to Okta. +First, add the C1.ai app to Okta. In a new browser tab, navigate to the [Okta admin console](https://www.okta.com/login/) and click **Applications** > **Applications** > **Browse App Catalog**. -Search for "C1" and select the C1 app, then click **Add Integration**. +Search for "C1.ai" and select the C1.ai app, then click **Add Integration**. -In the **Subdomain** field, enter the domain you chose for your C1 instance. +In the **Subdomain** field, enter the domain you chose for your C1.ai instance. -Select whether you want to make the C1 application visible to users, then click **Done**. +Select whether you want to make the C1.ai application visible to users, then click **Done**. ### Step 2: Assign users to the Okta app -Next, assign the C1 app to an Okta user or group so the user or group can access and use the app. +Next, assign the C1.ai app to an Okta user or group so the user or group can access and use the app. -If you do not assign the Okta app to yourself, you will receive an error at login and your C1 tenant will not be created! +If you do not assign the Okta app to yourself, you will receive an error at login and your C1.ai tenant will not be created! -Still in the Okta admin console, click the C1 app's **Assignments** tab. +Still in the Okta admin console, click the C1.ai app's **Assignments** tab. Click **Assign** and select either **Assign to People** or **Assign to Groups**. @@ -110,45 +110,45 @@ Click **Assign** and select either **Assign to People** or **Assign to Groups**. Locate the user or group you want to assign the app integration to and click **Assign**. -Confirm that the data is correct in the **Assign C1 to** dialog. +Confirm that the data is correct in the **Assign C1.ai to** dialog. Click **Save and Go Back**. The **Assigned** button for the user or group is disabled to indicate the app integration is assigned. -If necessary, repeat steps 2-6 to assign the C1 app to additional users or groups. +If necessary, repeat steps 2-6 to assign the C1.ai app to additional users or groups. Click **Done**. -### Step 3: Input OAuth credentials into Okta C1 app +### Step 3: Input OAuth credentials into Okta C1.ai app -In this step, you'll configure the SSO settings for the C1 app in Okta. To complete this step you'll move back and forth between your Okta tab and the C1 registration tab. +In this step, you'll configure the SSO settings for the C1.ai app in Okta. To complete this step you'll move back and forth between your Okta tab and the C1.ai registration tab. -In Okta, click **Applications** > **Applications** > **C1** to return to the new C1 application's details screen. +In Okta, click **Applications** > **Applications** > **C1** to return to the new C1.ai application's details screen. -Copy your Okta domain (such as `acmeco.okta.com`) from the browser's address bar and paste your Okta domain into the **Okta domain** field in C1. +Copy your Okta domain (such as `acmeco.okta.com`) from the browser's address bar and paste your Okta domain into the **Okta domain** field in C1.ai. -In Okta, click the **Sign On** tab. Copy the C1 app's client ID by clicking the **Copy to clipboard** icon. +In Okta, click the **Sign On** tab. Copy the C1.ai app's client ID by clicking the **Copy to clipboard** icon. -In C1, paste the client ID into the **Client ID** field. +In C1.ai, paste the client ID into the **Client ID** field. -In Okta, copy the C1 app's client secret by clicking the **Copy to clipboard** icon, then paste the client secret into the **Client secret** field in C1. +In Okta, copy the C1.ai app's client secret by clicking the **Copy to clipboard** icon, then paste the client secret into the **Client secret** field in C1.ai. -In C1, click **Sign up with Okta**. +In C1.ai, click **Sign up with Okta**. -Okta will guide you through the SSO sign-in process and redirect you to the C1 dashboard. +Okta will guide you through the SSO sign-in process and redirect you to the C1.ai dashboard. ## Authenticate with OneLogin @@ -170,7 +170,7 @@ Enter the following information in the specified fields: - Display name: **C1** - (Optional) Logo: - C1 logo + C1.ai logo Click **Save**. @@ -179,7 +179,7 @@ Click **Save**. On the **Configuration** tab, fill out the specified fields as follows: - Login Url: Leave this field blank - - Redirect URI's: Enter whichever matches your C1 tenant's domain — default instance: `https://accounts.conductor.one/auth/callback`, EU data residency instance: `https://accounts.c1eu.ai/auth/callback` + - Redirect URI's: Enter whichever matches your C1.ai tenant's domain — default instance: `https://accounts.conductor.one/auth/callback`, EU data residency instance: `https://accounts.c1eu.ai/auth/callback` - Post Logout Redirect URIs: Leave this field blank @@ -190,44 +190,44 @@ On the **SSO** tab, make the following selections: -### Step 2: Configure the SSO settings on the OneLogin C1 app +### Step 2: Configure the SSO settings on the OneLogin C1.ai app -In this step, you'll configure the SSO settings for the C1 app in OneLogin. To complete this step you'll move back and forth between your OneLogin tab and the C1 registration tab. +In this step, you'll configure the SSO settings for the C1.ai app in OneLogin. To complete this step you'll move back and forth between your OneLogin tab and the C1.ai registration tab. In OneLogin, copy your OneLogin domain (such as `acmeco.onelogin.com`) from the browser's address bar. -In C1, paste your OneLogin domain into the **OneLogin domain** field. +In C1.ai, paste your OneLogin domain into the **OneLogin domain** field. -In OneLogin, on the **SSO** tab, copy the C1 app's Client ID. +In OneLogin, on the **SSO** tab, copy the C1.ai app's Client ID. -In C1, paste the Client ID into the **Client ID** field. +In C1.ai, paste the Client ID into the **Client ID** field. -In OneLogin, copy the C1 app's Client Secret. +In OneLogin, copy the C1.ai app's Client Secret. -In C1, paste the Client Secret into the **Client secret** field. +In C1.ai, paste the Client Secret into the **Client secret** field. -In C1, click **Sign up with OneLogin**. OneLogin will now guide you through the SSO sign-in process and redirect you to the C1 dashboard. +In C1.ai, click **Sign up with OneLogin**. OneLogin will now guide you through the SSO sign-in process and redirect you to the C1.ai dashboard. -### Step 3: Assign users to the OneLogin C1 app +### Step 3: Assign users to the OneLogin C1.ai app -Lastly, give your colleagues access to C1 via OneLogin SSO by adding the new C1 app to one or more OneLogin user groups. +Lastly, give your colleagues access to C1.ai via OneLogin SSO by adding the new C1.ai app to one or more OneLogin user groups. In the OneLogin admin portal, navigate to **User Groups**. -Select the existing user group you'd like to give access to C1 (or create a new user group by clicking the **Create** button). +Select the existing user group you'd like to give access to C1.ai (or create a new user group by clicking the **Create** button). Click **Applications** and select **C1**. @@ -256,7 +256,7 @@ Enter the following information in the specified fields: - Display Label: **C1** - (Optional) Logo: - C1 logo + C1.ai logo Click **Save**. @@ -264,50 +264,50 @@ Click **Save**. On the **SSO** tab, fill out the specified fields as follows: - - Redirect URIs: Enter whichever matches your C1 tenant's domain — default instance: `https://accounts.conductor.one/auth/callback`, EU data residency instance: `https://accounts.c1eu.ai/auth/callback` + - Redirect URIs: Enter whichever matches your C1.ai tenant's domain — default instance: `https://accounts.conductor.one/auth/callback`, EU data residency instance: `https://accounts.c1eu.ai/auth/callback` - Client Authentication Type: Client Secret POST - - Login URL: use the C1 domain you chose in Step 1 — default instance: `https://YOUR_DOMAIN.conductor.one/login?sso_operation=initiate_login`, EU data residency instance: `https://YOUR_DOMAIN.c1eu.ai/login?sso_operation=initiate_login` + - Login URL: use the C1.ai domain you chose in Step 1 — default instance: `https://YOUR_DOMAIN.conductor.one/login?sso_operation=initiate_login`, EU data residency instance: `https://YOUR_DOMAIN.c1eu.ai/login?sso_operation=initiate_login` In the **User Attribute Mapping** section, enter `email` in the **Service Provider Attribute Name** field and select `email` in the **JumpCloud Attribute Name** field, then click **Add Attribute**. -On the **User Groups** tab, select one or more groups to assign access to C1. +On the **User Groups** tab, select one or more groups to assign access to C1.ai. Click **Activate**. Leave the **Application Saved** popup that displays the Client ID and the Client Secret fields open. You'll use these values in the next step. -### Step 2: Configure OIDC settings on the JumpCloud C1 app +### Step 2: Configure OIDC settings on the JumpCloud C1.ai app -In this step, you'll configure the SSO settings for the C1 app in OneLogin. To complete this step you'll move back and forth between your JumpCloud tab and the C1 registration tab. +In this step, you'll configure the SSO settings for the C1.ai app in OneLogin. To complete this step you'll move back and forth between your JumpCloud tab and the C1.ai registration tab. -In JumpCloud, copy the C1 app's Client ID from the **Application Saved** popup. +In JumpCloud, copy the C1.ai app's Client ID from the **Application Saved** popup. -In C1, paste the Client ID into the **Client ID** field. +In C1.ai, paste the Client ID into the **Client ID** field. -In JumpCloud, copy the C1 app's client secret and paste it into the **Client secret** field in C1. +In JumpCloud, copy the C1.ai app's client secret and paste it into the **Client secret** field in C1.ai. -In C1, click **Sign up with JumpCloud**. JumpCloud will now guide you through the SSO sign-in process and redirect you to the C1 dashboard. +In C1.ai, click **Sign up with JumpCloud**. JumpCloud will now guide you through the SSO sign-in process and redirect you to the C1.ai dashboard. ### Step 3: Grant users access and login -Lastly, give your colleagues access to C1 via JumpCloud SSO by adding the new C1 app to a JumpCloud user group. +Lastly, give your colleagues access to C1.ai via JumpCloud SSO by adding the new C1.ai app to a JumpCloud user group. In the JumpCloud Admin Portal, navigate to **User Groups**. -Select the existing user group you'd like to give access to C1 (or create a new user group by clicking the **Create** button). +Select the existing user group you'd like to give access to C1.ai (or create a new user group by clicking the **Create** button). Click **Applications** and select **C1**. @@ -324,17 +324,17 @@ Click **Save**. When prompted to authenticate with Microsoft, select your corporate account. -Review the permissions requested by C1. These permissions are needed to establish the SSO link between Microsoft and C1. +Review the permissions requested by C1.ai. These permissions are needed to establish the SSO link between Microsoft and C1.ai. - - If you have the correct permission level in Microsoft, check the box to **Consent on behalf of your organization**. This enables the requested C1 permissions for all users in your organization. - - If you do not have the permissions needed to check the box, before other users attempt to sign into C1 using SSO, direct your Microsoft administrator to manage permissions for the C1 application in by navigating to **Enterprise applications** > **C1 SSO** > **Permissions** and clicking **Grant admin consent for ...**. + - If you have the correct permission level in Microsoft, check the box to **Consent on behalf of your organization**. This enables the requested C1.ai permissions for all users in your organization. + - If you do not have the permissions needed to check the box, before other users attempt to sign into C1.ai using SSO, direct your Microsoft administrator to manage permissions for the C1.ai application in by navigating to **Enterprise applications** > **C1 SSO** > **Permissions** and clicking **Grant admin consent for ...**. Click **Accept**. -Microsoft will now guide you through the SSO sign-in process and redirect you to the C1 dashboard. +Microsoft will now guide you through the SSO sign-in process and redirect you to the C1.ai dashboard. ## Authenticate with PingOne @@ -352,7 +352,7 @@ Enter the following information in the specified fields: - Application name: **C1** - (Optional) Logo: - C1 logo + C1.ai logo In the **Application Type** area of the page, select **OIDC Web App**. @@ -364,8 +364,8 @@ Click **Save**. On the **Configuration** tab, click **Edit** and fill out the specified fields as follows: - Token Endpoint Authentication Method: Client Secret Post - - Redirect URI's: Enter whichever matches your C1 tenant's domain — default instance: `https://accounts.conductor.one/auth/callback`, EU data residency instance: `https://accounts.c1eu.ai/auth/callback` - - Initiate Login URI: use your own C1 domain — default instance: `https://your_domain.conductor.one/login`, EU data residency instance: `https://your_domain.c1eu.ai/login` + - Redirect URI's: Enter whichever matches your C1.ai tenant's domain — default instance: `https://accounts.conductor.one/auth/callback`, EU data residency instance: `https://accounts.c1eu.ai/auth/callback` + - Initiate Login URI: use your own C1.ai domain — default instance: `https://your_domain.conductor.one/login`, EU data residency instance: `https://your_domain.c1eu.ai/login` Click **Save**. @@ -378,14 +378,14 @@ Return to the **Configuration** tab and carefully copy and save the new app's ** -### Step 2: Configure the SSO settings on the OneLogin C1 app +### Step 2: Configure the SSO settings on the OneLogin C1.ai app -Back in the C1 setup tab, paste the **Client ID**, **Client secret**, and **Environment ID** into the form at the right of the page. +Back in the C1.ai setup tab, paste the **Client ID**, **Client secret**, and **Environment ID** into the form at the right of the page. -Click **Sign up with PingOne**. PingOne will now guide you through the SSO sign-in process and redirect you to the C1 dashboard. +Click **Sign up with PingOne**. PingOne will now guide you through the SSO sign-in process and redirect you to the C1.ai dashboard. @@ -397,11 +397,11 @@ Click **Sign up with PingOne**. PingOne will now guide you through the SSO sign- In a new browser tab, log into your identity provider and create a new OIDC application. - - Configure the redirect URI to use whichever matches your C1 tenant's domain — default instance: `https://accounts.conductor.one/auth/callback`, EU data residency instance: `https://accounts.c1eu.ai/auth/callback`. + - Configure the redirect URI to use whichever matches your C1.ai tenant's domain — default instance: `https://accounts.conductor.one/auth/callback`, EU data residency instance: `https://accounts.c1eu.ai/auth/callback`. - Ensure the authorization code flow is enabled. -Gather OIDC credentials to pass to C1: +Gather OIDC credentials to pass to C1.ai: - Issuer URL (the base URL of your OIDC provider) - Client ID @@ -409,17 +409,17 @@ Gather OIDC credentials to pass to C1: - Optional: Additional scopes beyond openid, profile, and email -Back in the C1 setup tab, paste the **Issuer URL**, **Client ID**, **Client secret**, and any **OIDC scopes** into the relevant fields in the form at the right of the page. +Back in the C1.ai setup tab, paste the **Issuer URL**, **Client ID**, **Client secret**, and any **OIDC scopes** into the relevant fields in the form at the right of the page. -Click **Sign up with OIDC**. Your identity provider will now guide you through the SSO sign-in process and redirect you to the C1 dashboard. +Click **Sign up with OIDC**. Your identity provider will now guide you through the SSO sign-in process and redirect you to the C1.ai dashboard. ## Success! -Your C1 tenant is created and you are logged in! +Your C1.ai tenant is created and you are logged in! -C1AI opens automatically to walk you through a short, personalized onboarding: it asks about your organization and what you're trying to accomplish, then builds you a step-by-step plan — handling some steps for you directly in the chat. See [Use the C1 AI assistant](/product/admin/ai-assistant) to learn more, or dismiss the plan at any time to explore C1 on your own. +C1AI opens automatically to walk you through a short, personalized onboarding: it asks about your organization and what you're trying to accomplish, then builds you a step-by-step plan — handling some steps for you directly in the chat. See [Use the C1.ai AI assistant](/product/admin/ai-assistant) to learn more, or dismiss the plan at any time to explore C1.ai on your own. diff --git a/product/how-to/qs-user-access-reviews.mdx b/product/how-to/qs-user-access-reviews.mdx index bdfd8565..536f45ca 100644 --- a/product/how-to/qs-user-access-reviews.mdx +++ b/product/how-to/qs-user-access-reviews.mdx @@ -1,19 +1,19 @@ --- title: Get started with user access reviews -og:title: Get started with user access reviews (UARs) - C1 docs -og:description: Follow our step-by-step guide to running an access review with C1. -description: Follow this guide to run your first user access review campaign in C1. +og:title: Get started with user access reviews (UARs) - C1.ai docs +og:description: Follow our step-by-step guide to running an access review with C1.ai. +description: Follow this guide to run your first user access review campaign in C1.ai. sidebarTitle: "User access reviews" --- {/* Editor Refresh: 2026-04-10 */} -In this guide, we'll demonstrate how to run an access review ... of C1! You don't need to have any applications connected to C1 for this demo. We'll run a review of everyone with the **Super Administrator** role in C1. +In this guide, we'll demonstrate how to run an access review ... of C1.ai! You don't need to have any applications connected to C1.ai for this demo. We'll run a review of everyone with the **Super Administrator** role in C1.ai. ## Before you begin To complete this guide, you'll need: -- C1 **Super Administrator** or **Campaign Administrator** role +- C1.ai **Super Administrator** or **Campaign Administrator** role **Estimated time:** 10 minutes @@ -30,7 +30,7 @@ Navigate to **Governance** > **Campaigns**. Click **New campaign** and fill out the form as follows: - - **Campaign name**: "C1 Super Admin UAR" + - **Campaign name**: "C1.ai Super Admin UAR" - **Description**: Leave this blank - **Campaign type**: Single instance - **Due date**: Use the auto-selected date @@ -45,7 +45,7 @@ Click **Continue**. ## Step 2: Scope the campaign -We now need to set the scope of the campaign. We're going to scope this campaign to reviewing anyone who has **Super Administrator** access to the C1 console. +We now need to set the scope of the campaign. We're going to scope this campaign to reviewing anyone who has **Super Administrator** access to the C1.ai console. @@ -55,7 +55,7 @@ On the **Scope** tab of the campaign, find the **Apps and entitlements** section Click **Entitlements**. -Search for the term "super" and find the **Super Administrator** role listed for the C1 application. +Search for the term "super" and find the **Super Administrator** role listed for the C1.ai application. Select the **Super Administrator** role and click **Save**. @@ -70,7 +70,7 @@ Before a campaign can be started, it must be staged. Staging a campaign takes a Click **Stage campaign**. When prompted by the pop-up, click **Stage**. - We now have our access reviews prepared for the campaign. Because we selected **App Owner Certify Policy** as the policy for this campaign, when the campaign begins these reviews will be assigned to the application owner of the C1 application. + We now have our access reviews prepared for the campaign. Because we selected **App Owner Certify Policy** as the policy for this campaign, when the campaign begins these reviews will be assigned to the application owner of the C1.ai application. When you're ready, click **Start campaign now** and decide whether to send out campaign notifications. @@ -86,7 +86,7 @@ Your campaign is underway! ## Step 4: Manage the campaign -C1 provides a deep bench of tools for managing the successful completion of user access reviews in a timely fashion. These include: +C1.ai provides a deep bench of tools for managing the successful completion of user access reviews in a timely fashion. These include: - Sending reminders - Canceling reviews @@ -109,5 +109,5 @@ At any point during or after the campaign, generate an auditor-ready campaign re ## Success! -By following these steps, you’ve completed a successful certification campaign using C1 ... for C1! +By following these steps, you’ve completed a successful certification campaign using C1.ai ... for C1.ai! diff --git a/product/how-to/request-actions.mdx b/product/how-to/request-actions.mdx index c99da81d..68a0ae61 100644 --- a/product/how-to/request-actions.mdx +++ b/product/how-to/request-actions.mdx @@ -1,14 +1,14 @@ --- title: How to request actions -og:title: How to request actions - C1 docs -og:description: Request on-demand actions like device provisioning, resource creation, or operational workflows through C1's Actions catalog. -description: Request on-demand actions like device provisioning, resource creation, or operational workflows through C1's Actions catalog. +og:title: How to request actions - C1.ai docs +og:description: Request on-demand actions like device provisioning, resource creation, or operational workflows through C1.ai's Actions catalog. +description: Request on-demand actions like device provisioning, resource creation, or operational workflows through C1.ai's Actions catalog. --- {/* Editor Refresh: 2026-01-19 */} ## What are actions? -Actions are on-demand workflows that you can request through C1. Unlike regular access requests, they're designed for operations that go beyond normal access requests, such as: +Actions are on-demand workflows that you can request through C1.ai. Unlike regular access requests, they're designed for operations that go beyond normal access requests, such as: - Requesting a new laptop or other device - Creating or modifying resources (for example, AD groups, GitHub repos) @@ -25,7 +25,7 @@ You can find and request actions in three places: 2. **New request form**: Click **New request** and select the **Actions** tab. -3. **AI assistant**: Ask the C1 AI assistant in the C1 app for Slack what actions are available to you. +3. **AI assistant**: Ask the C1.ai AI assistant in the C1.ai app for Slack what actions are available to you. You'll only see actions that you have permission to request. If you don't see an action you need, contact your IT administrator. @@ -54,24 +54,24 @@ A drawer pops open to show you the details of the newly created action task. ## Request an action from the AI assistant -If your company uses Slack and an admin has set up the C1 app for Slack, you can discover and request actions directly from the C1 AI assistant, without navigating to the Actions catalog. +If your company uses Slack and an admin has set up the C1.ai app for Slack, you can discover and request actions directly from the C1.ai AI assistant, without navigating to the Actions catalog. -Open the C1 app for Slack and go to the **Chat** tab, or type `@C1` in any channel where the app is installed. +Open the C1.ai app for Slack and go to the **Chat** tab, or type `@C1` in any channel where the app is installed. Ask the assistant what actions are available to you. It will return a list of the actions you have permission to request. -The C1 assistant responding to 'What actions can I request right now?' with a table listing available actions and their descriptions. +The C1.ai assistant responding to 'What actions can I request right now?' with a table listing available actions and their descriptions. Tell the assistant which action you'd like to request. It will pull up the form for that action. -The C1 assistant surfacing the 'Can't find an application?' request form with a Fill out form button. +The C1.ai assistant surfacing the 'Can't find an application?' request form with a Fill out form button. @@ -87,7 +87,7 @@ After you submit an action request: 1. **Approval (if required)**: If the action requires approval, it will be routed to the appropriate approvers (for example, your manager, IT lead, or the app owner). You'll receive a notification when your request is approved or denied. -2. **Execution**: Once approved (or if auto-approved), the action runs automatically. C1 executes the workflow steps using the information you provided in the form. +2. **Execution**: Once approved (or if auto-approved), the action runs automatically. C1.ai executes the workflow steps using the information you provided in the form. 3. **Completion**: You'll receive a notification when the action is completed. You can view the full history of your request, including all approvals and execution details, on the **My requests** page. @@ -97,14 +97,14 @@ Most users can only request actions for themselves, but there are a few exceptio - **Managers** can request actions for the members of their team. -- C1 users with the **Access Request Helpdesk**, **Access Request Admin**, or **Super Administrator** roles can request actions for any active user. +- C1.ai users with the **Access Request Helpdesk**, **Access Request Admin**, or **Super Administrator** roles can request actions for any active user. If you're a manager or have one of these user roles, you'll see an option to request actions for others when creating an action request. **Do I have to approve the action I request for another user?** -If you request an action for another person, your approval of that action is understood to be implicit. So if the policy governing the action would normally assign a task to you for your approval, C1 will auto-approve the request on your behalf. +If you request an action for another person, your approval of that action is understood to be implicit. So if the policy governing the action would normally assign a task to you for your approval, C1.ai will auto-approve the request on your behalf. diff --git a/product/how-to/review-tasks.mdx b/product/how-to/review-tasks.mdx index 26de5042..993bca06 100644 --- a/product/how-to/review-tasks.mdx +++ b/product/how-to/review-tasks.mdx @@ -1,6 +1,6 @@ --- title: How to review access -og:title: How to review access - C1 docs +og:title: How to review access - C1.ai docs og:description: Review tasks are assigned to you when your expertise is needed to review access to applications and specific resources as part of a user access review (UAR) campaign. description: Review tasks are assigned to you when your expertise is needed to review access to applications and specific resources as part of a user access review (UAR) campaign. --- @@ -8,7 +8,7 @@ description: Review tasks are assigned to you when your expertise is needed to r ## Complete your reviews -Your organization uses C1 to run user access review (UAR) campaigns. You'll be assigned reviews in C1 to verify that current access is still appropriate and needed. +Your organization uses C1.ai to run user access review (UAR) campaigns. You'll be assigned reviews in C1.ai to verify that current access is still appropriate and needed. You might be asked to review: @@ -22,7 +22,7 @@ You might be asked to review: ### Step 1: Receive a notification -C1 sends notifications by email and in the [C1 app for Slack](/product/admin/integration-for-Slack) or [MS Teams app](/product/admin/ms-teams-public) (if enabled) when reviews are assigned to you. +C1.ai sends notifications by email and in the [C1.ai app for Slack](/product/admin/integration-for-Slack) or [MS Teams app](/product/admin/ms-teams-public) (if enabled) when reviews are assigned to you. **Make sure that notification emails reach you:** @@ -30,7 +30,7 @@ C1 sends notifications by email and in the [C1 app for Slack](/product/admin/int Add [no-reply@c1.ai](mailto:no-reply@c1.ai) to your email contacts list. -Go directly to your reviews by clicking the link in your email or Slack/Teams notification. Or log into C1 and click **Reviews**, then select the campaign. +Go directly to your reviews by clicking the link in your email or Slack/Teams notification. Or log into C1.ai and click **Reviews**, then select the campaign. ### Step 2: Select how to view your reviews @@ -122,7 +122,7 @@ View the submission log. ## Review recommendations and insights -C1 provides insights and recommendations to help you complete your reviews. +C1.ai provides insights and recommendations to help you complete your reviews. In the list view and in a task's details view, you'll see icons drawing your attention to important information about the access under review. @@ -130,12 +130,12 @@ In the list view and in a task's details view, you'll see icons drawing your att A list of campaign review tasks showing flags in the Insights column. -C1 makes two kinds of recommendations about individual reviews: +C1.ai makes two kinds of recommendations about individual reviews: - Take a closer look - Remove this access -If C1 suggests removing or taking a closer look at the access, you'll see a note in the **Recommendation** column. Hover over the icon or open the task's details view to see an explanation of the recommendation. +If C1.ai suggests removing or taking a closer look at the access, you'll see a note in the **Recommendation** column. Hover over the icon or open the task's details view to see an explanation of the recommendation. ## Get agent help reviewing access @@ -158,7 +158,7 @@ The review assistant remembers your previous instructions and actions, so you ca ## Additional task actions -Depending on your user permissions in C1 and the current status of the review task, you might have additional task actions available to you in the **...** (more actions) menu. +Depending on your user permissions in C1.ai and the current status of the review task, you might have additional task actions available to you in the **...** (more actions) menu. Actions labeled with a symbol are only available to users who have the **Super Administrator** role. @@ -166,7 +166,7 @@ Actions labeled with a | Stop the task and close it with **Canceled** status. The task remains in the **Task log**. | You don't want or need to complete a task, but want to retain a record of its existence. | | | | | -| **Delete** | Stop the task and delete it from C1 entirely. No record of the task is retained in the **Task log**. | You don't want or need to complete a task, and want the record of its existence removed from C1. | +| **Delete** | Stop the task and delete it from C1.ai entirely. No record of the task is retained in the **Task log**. | You don't want or need to complete a task, and want the record of its existence removed from C1.ai. | | | | | | **(Action) with comment** | Take an action (such as certify, approve, mark as provisioned) and add a comment to the task. | You want to provide context or documentation with your decision | | | | | diff --git a/product/intro.mdx b/product/intro.mdx index 23e0efc9..ecab6e7d 100644 --- a/product/intro.mdx +++ b/product/intro.mdx @@ -1,14 +1,14 @@ --- -title: Introducing C1 -og:title: What is ConductorOne (C1)? | Docs - C1 -og:description: Welcome to the C1 admin documentation! -description: Welcome to the C1 admin documentation! +title: Introducing C1.ai +og:title: What is ConductorOne (C1.ai)? | Docs - C1.ai +og:description: Welcome to the C1.ai admin documentation! +description: Welcome to the C1.ai admin documentation! --- {/* Editor Refresh: 2026-01-07 */} -## What is C1? +## What is C1.ai? -C1 is an identity security platform for governing access across your human, non-human, and AI identities. With C1, you can: +C1.ai is an identity security platform for governing access across your human, non-human, and AI identities. With C1.ai, you can: - **Govern access for AI agents and tools** — manage and audit what your AI agents and MCP servers can access across apps, data sources, and infrastructure. - **Provision and deprovision access** — grant and remove access across your connected applications automatically. @@ -16,10 +16,10 @@ C1 is an identity security platform for governing access across your human, non- - **Run user access reviews (UARs)** — systematically verify who has access to what and certify or revoke it. - **Centralize visibility and audit** — keep an auditable record of access, entitlements, and changes across every connected app. -C1 connects to your apps through [connectors](/baton/intro) and governs access with [policies](/product/admin/policies) and [automations](/product/admin/automations). +C1.ai connects to your apps through [connectors](/baton/intro) and governs access with [policies](/product/admin/policies) and [automations](/product/admin/automations). -Looking to review access, request access, or use AI tools in C1? Go to [Use C1](/product/how-to/intro). +Looking to review access, request access, or use AI tools in C1.ai? Go to [Use C1.ai](/product/how-to/intro). ## What’s new @@ -33,8 +33,8 @@ The latest new features, enhancements, and resolved issues. ## Popular resources - - Add C1 egress IPs and hostnames to your firewall and proxy allowlists. + + Add C1.ai egress IPs and hostnames to your firewall and proxy allowlists. diff --git a/product/release-notes-archive.mdx b/product/release-notes-archive.mdx index 86462caf..cf747e6c 100644 --- a/product/release-notes-archive.mdx +++ b/product/release-notes-archive.mdx @@ -1,12 +1,12 @@ --- -title: C1 release notes archive -og:title: Release notes archive - C1 -og:description: C1 release notes from November 2022 through December 2024. -description: C1 release notes from November 2022 through December 2024. +title: C1.ai release notes archive +og:title: Release notes archive - C1.ai +og:description: C1.ai release notes from November 2022 through December 2024. +description: C1.ai release notes from November 2022 through December 2024. sidebarTitle: Release notes archive --- -This page archives C1 release notes from November 2022 through December 2024. For current release notes, see [C1 release notes](/product/release-notes). +This page archives C1.ai release notes from November 2022 through December 2024. For current release notes, see [C1.ai release notes](/product/release-notes). @@ -27,7 +27,7 @@ This page archives C1 release notes from November 2022 through December 2024. Fo * The **Reviews** page has an updated design, making it easier to see the access reviews work assigned to you. -* Files in `.csv` format uploaded to C1 can now contain either tab- or comma-separated values. +* Files in `.csv` format uploaded to C1.ai can now contain either tab- or comma-separated values. @@ -57,7 +57,7 @@ Set the account type (user, system, or service account) for multiple accounts on ### Connectors -* Setting the domain when configuring Google Workspace v2 is now optional. If you don't specify a domain, C1 will sync all available Google Workspace domains. +* Setting the domain when configuring Google Workspace v2 is now optional. If you don't specify a domain, C1.ai will sync all available Google Workspace domains. * We made updates and fixes to these connectors: @@ -68,7 +68,7 @@ Set the account type (user, system, or service account) for multiple accounts on * Google Cloud Platform (fixed a bug when granting access) * Jamf * Google BigQuery (fixed an API permissions error) - * ServiceNow (fixed the cause of errors in ServiceNow tickets created by C1) + * ServiceNow (fixed the cause of errors in ServiceNow tickets created by C1.ai) ### Usability improvements @@ -88,13 +88,13 @@ Set the account type (user, system, or service account) for multiple accounts on ### Condition expressions -We've expanded the C1 CEL expression language with user, task, task analysis, IP, and IP CIDR objects to support more sophisticated policy and group condition expressions. +We've expanded the C1.ai CEL expression language with user, task, task analysis, IP, and IP CIDR objects to support more sophisticated policy and group condition expressions. Check out our docs on [condition expressions](/product/admin/expressions) to learn more and to see sample expressions for use cases such as "route a request based on how it was created", "check whether a request will cause an access conflict", and "route a request based on whether the access is requested permanently or temporarily". ### Bulk actions -Two new bulk actions are here to help you work more efficiently in C1: +Two new bulk actions are here to help you work more efficiently in C1.ai: - Revoke multiple users' access to an entitlement by navigating to the **Entitlements** tab and clicking the **Grants** count. @@ -112,7 +112,7 @@ Two new bulk actions are here to help you work more efficiently in C1: - You can now set an owner or owners on a file connector. -- If public Slack channels aren't allowed by your organization, C1 will automatically create a private access review campaign Slack channel instead. +- If public Slack channels aren't allowed by your organization, C1.ai will automatically create a private access review campaign Slack channel instead. - To support an upcoming feature, we've added a pre-built **Auto approval** request policy, which cannot be edited or deleted. @@ -168,7 +168,7 @@ Set or update the provisioning settings for multiple entitlements at once on an ### Bulk actions -To help you get more done with fewer clicks, we've added two new bulk action capabilities to C1: +To help you get more done with fewer clicks, we've added two new bulk action capabilities to C1.ai: - Update the ownership of multiple apps at once on the **Applications** page. @@ -185,7 +185,7 @@ To help you get more done with fewer clicks, we've added two new bulk action cap ### Global IP allow lists -To enhance security and ensure that C1 is only accessed over trusted networks, you can now set up global IP allow lists on the **Settings** page. Check out [Configure global IP allow lists](/product/admin/global-settings#configure-global-ip-allow-lists) to learn more. +To enhance security and ensure that C1.ai is only accessed over trusted networks, you can now set up global IP allow lists on the **Settings** page. Check out [Configure global IP allow lists](/product/admin/global-settings#configure-global-ip-allow-lists) to learn more. ### Connectors @@ -193,7 +193,7 @@ To enhance security and ensure that C1 is only accessed over trusted networks, y - A new configuration option on the Okta v2 connector lets you opt into syncing custom roles. -- The status of terminated NetSuite users is now correctly shown in C1. +- The status of terminated NetSuite users is now correctly shown in C1.ai. ### Usability improvements @@ -273,7 +273,7 @@ To enhance security and ensure that C1 is only accessed over trusted networks, y ### Access grant change feed -Click the log icon on any application, entitlement, user, or account page to open the new **Grant feed**. This running audit history of access changes for the application, entitlement, user, or account lets you quickly see how access has changed over time, with links to related C1 tasks. +Click the log icon on any application, entitlement, user, or account page to open the new **Grant feed**. This running audit history of access changes for the application, entitlement, user, or account lets you quickly see how access has changed over time, with links to related C1.ai tasks. ### Connectors @@ -353,13 +353,13 @@ We've overhauled the campaign-building experience, introducing a scoping flow th - A new **API keys** tab on the **Settings** page allows users with the **Super Administrator** user role to see all personal API keys created by the tenant's users, and to delete API keys if needed. -- Download a list of all OCSF events from the C1 system logs, published in YAML and JSON with Sigma Detection Format. Go to [System logs](/product/admin/system-log) for instructions on how to access the files. +- Download a list of all OCSF events from the C1.ai system logs, published in YAML and JSON with Sigma Detection Format. Go to [System logs](/product/admin/system-log) for instructions on how to access the files. ### Unmanaged apps -A new **Unmanaged apps** tab on the **Applications** page shows all the applications that C1 discovered in your SSO, identity, or federation provider. You can leave an unmanaged app as-is, or click **Manage** to start tracking the app's access data and enforcing access controls with C1. [Learn more about working with unmanaged apps.](/product/admin/applications) +A new **Unmanaged apps** tab on the **Applications** page shows all the applications that C1.ai discovered in your SSO, identity, or federation provider. You can leave an unmanaged app as-is, or click **Manage** to start tracking the app's access data and enforcing access controls with C1.ai. [Learn more about working with unmanaged apps.](/product/admin/applications) ### Connectors @@ -367,7 +367,7 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat ### Usability improvements -- User task reports now include each task's type and a link to the task in C1. +- User task reports now include each task's type and a link to the task in C1.ai. - Edit group and catalog names, as well as group descriptions and catalog owners, in the header of the group or catalog. @@ -429,7 +429,7 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat - Request catalogs have a new **Allow self-service** control, which replaces the concept of publishing and unpublishing catalogs. -- A new **Sync now** button on [C1 groups](/product/admin/groups) lets you update group membership on demand, rather than waiting for the next scheduled hourly sync. +- A new **Sync now** button on [C1.ai groups](/product/admin/groups) lets you update group membership on demand, rather than waiting for the next scheduled hourly sync. - You can now expand and collapse the JSON records associated with a log entry. @@ -439,10 +439,10 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat - The policy you select when creating a duplicate campaign is correctly applied to the new campaign. -- We fixed some fonts that were looking a little funky when C1 was viewed using Safari. +- We fixed some fonts that were looking a little funky when C1.ai was viewed using Safari. -**Entitlement summary refresh.** Entitlement summaries across C1 have a new look! We've reorganized the information in these summaries to make them easier to locate, read, and work with. +**Entitlement summary refresh.** Entitlement summaries across C1.ai have a new look! We've reorganized the information in these summaries to make them easier to locate, read, and work with. **Connectors** @@ -456,7 +456,7 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat **Usability improvements** -- When creating a [C1 group](/product/admin/groups), you now can specify a list of users who will be excluded from the group, even if they match the membership rule. We've also improved the performance of the group preview on the membership rule configuration pane. +- When creating a [C1.ai group](/product/admin/groups), you now can specify a list of users who will be excluded from the group, even if they match the membership rule. We've also improved the performance of the group preview on the membership rule configuration pane. - Users with the **Super Admin** user role now have a **Hard reset** option on a task's details page. Hard resetting a task undoes any review progress made to date, recalculates and reapplies the task's policy, and reassigns reviewers. @@ -475,7 +475,7 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat -**Export system logs.** You can now automatically export C1 system logs to an S3 bucket. The logs contain a record of every action taken by the C1 API, presented in OCSF format. Go to [Export system logs](/product/admin/system-log) to learn more and get started. +**Export system logs.** You can now automatically export C1.ai system logs to an S3 bucket. The logs contain a record of every action taken by the C1.ai API, presented in OCSF format. Go to [Export system logs](/product/admin/system-log) to learn more and get started. **Connectors** @@ -523,7 +523,7 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat -**C1 groups.** You can now create custom groups that dynamically adjust their membership based on adherence to a membership rule. These special groups can be used to manage who can access a catalog, to assign reviews in a policy step, and more. Check out [Groups in the C1 app](/product/admin/groups) for more info. +**C1.ai groups.** You can now create custom groups that dynamically adjust their membership based on adherence to a membership rule. These special groups can be used to manage who can access a catalog, to assign reviews in a policy step, and more. Check out [Groups in the C1.ai app](/product/admin/groups) for more info. **Connectors** @@ -539,7 +539,7 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat - When creating access requests from Jira Service management tickets, Copilot now checks if you have the permission to request on behalf of others, and fills in the access request or shows an error accordingly. -- Connectors for applications that you have deleted from C1 are no longer shown on the **Connectors** page. +- Connectors for applications that you have deleted from C1.ai are no longer shown on the **Connectors** page. **Fixed!** @@ -551,7 +551,7 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat -**Helpdesk automation.** We're delighted to announce that our Copilot-powered helpdesk automation for Jira Service Management is now generally available. Copilot automatically transforms a request for access made in Jira into a C1 task, and updates the Jira ticket throughout the approval and provisioning process. To learn more about this feature, go to Generate access requests via a service desk. +**Helpdesk automation.** We're delighted to announce that our Copilot-powered helpdesk automation for Jira Service Management is now generally available. Copilot automatically transforms a request for access made in Jira into a C1.ai task, and updates the Jira ticket throughout the approval and provisioning process. To learn more about this feature, go to Generate access requests via a service desk. **Connectors** @@ -566,7 +566,7 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat -**The C1 app.** The new C1 app lets you view and manage C1 access within C1. This means you can now include C1 user roles in your access review campaigns, and allow users to request new C1 user roles. To learn more, go to [Work with the C1 app](/product/admin/c1-for-c1). +**The C1.ai app.** The new C1.ai app lets you view and manage C1.ai access within C1.ai. This means you can now include C1.ai user roles in your access review campaigns, and allow users to request new C1.ai user roles. To learn more, go to [Work with the C1.ai app](/product/admin/c1-for-c1). **Connectors** @@ -584,7 +584,7 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat **Fixed!** -- Users with the Super Admin role in C1 can request access for any other user. +- Users with the Super Admin role in C1.ai can request access for any other user. - When completing access reviews using the **By application** view, you no longer need to reload the page when switching between applications. @@ -595,13 +595,13 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat - You can now set up the [Databricks](/baton/databricks) connector using your choice of OAuth, a personal access token, or a username and password. -- Accounts in [Docusign](/baton/docusign) that have a **Pending** status are now shown as **Disabled** in C1. +- Accounts in [Docusign](/baton/docusign) that have a **Pending** status are now shown as **Disabled** in C1.ai. **Usability improvements** - If you attempt to create a duplicate revocation request, you'll see a link to the existing revocation task in the error message. -- We've streamlined the way dates and timestamps are shown in C1, and set the timezone to UTC. +- We've streamlined the way dates and timestamps are shown in C1.ai, and set the timezone to UTC. - When you select multiple tasks in a table, you'll now find a **Clear selection** control next to the menu of bulk action options. @@ -614,11 +614,11 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat -**Connectors page revamp.** We've redesigned and renamed the **Integrations** page. On the new **Connectors** page, you'll find a list of all your active connectors with their owner, status, and last sync date. Click **Add connector** to see the list of all available connectors and to add a new one to your C1 instance. +**Connectors page revamp.** We've redesigned and renamed the **Integrations** page. On the new **Connectors** page, you'll find a list of all your active connectors with their owner, status, and last sync date. Click **Add connector** to see the list of all available connectors and to add a new one to your C1.ai instance. **Access request configuration rules.** This powerful new method of setting configuration details for access requests lets you set app-wide defaults and override them as needed with entitlement-specific settings. To get started creating your own rules, go to [Configure access requests](/product/admin/access-requests). -**Bundles.** Admins now have the option to allow users to request everything in a request catalog as a bundle. View and request your available bundles on the **Browse access** page and the **Request access** form. (Bundles are not yet available in the C1 Slack app.) Check out [Create request catalogs and bundles](/product/admin/profiles) to learn more. +**Bundles.** Admins now have the option to allow users to request everything in a request catalog as a bundle. View and request your available bundles on the **Browse access** page and the **Request access** form. (Bundles are not yet available in the C1.ai Slack app.) Check out [Create request catalogs and bundles](/product/admin/profiles) to learn more. **Connectors** @@ -643,7 +643,7 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat - The **Insights** section on review and request tasks now includes information about relevant conflict monitors. If existing access previously triggered an alert, this is shown on review tasks. If the requested access would trigger an alert if granted, this is shown on request tasks. -- Need to [set up an AWS S3 bucket](/product/admin/external-datasources) to use as a data source for an application in C1? We've relocated these settings to the **External data sources** tab on the **Settings** page. +- Need to [set up an AWS S3 bucket](/product/admin/external-datasources) to use as a data source for an application in C1.ai? We've relocated these settings to the **External data sources** tab on the **Settings** page. - If an integration can be set up in more than one way, you'll now see the option to select your preferred authentication method on the integration page. @@ -656,7 +656,7 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat - Send notifications of new alerts generated by a conflict monitor to the Slack channel of your choice. Go to [Set up notifications](/product/admin/access-conflicts#optional-set-up-notifications) in the conflict monitor docs to learn more. -- C1 Slack app notification pop-ups now contain a preview of the new message. +- C1.ai Slack app notification pop-ups now contain a preview of the new message. - You can now cancel your own open access requests on the **Open requests** page. @@ -675,13 +675,13 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat **Usability improvements** -- Need to set up the C1 Slack app for your organization? We've relocated those controls to the **Notifications** tab on the **Settings** page. +- Need to set up the C1.ai Slack app for your organization? We've relocated those controls to the **Notifications** tab on the **Settings** page. - You can filter your conflict monitor's alerts by account owner and status. - When setting up a new application, your username is now auto-populated in the app owner field, which you can change or add to as needed. -- Email aliases using a `yourname+alias@company.tld` pattern are automatically mapped to the corresponding `yourname@company.tld` account in C1. +- Email aliases using a `yourname+alias@company.tld` pattern are automatically mapped to the corresponding `yourname@company.tld` account in C1.ai. - You can now use `Manager ID` as a spreadsheet column header or data value mapping. @@ -689,7 +689,7 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat **Fixed!** -- Comments you type in Slack that are pulled onto a task's comments field in C1 are now tagged with your C1 user name rather than your alphanumeric Slack ID. +- Comments you type in Slack that are pulled onto a task's comments field in C1.ai are now tagged with your C1.ai user name rather than your alphanumeric Slack ID. - Access requests for app access entitlements that use delegated provisioning are now successfully processed. @@ -700,13 +700,13 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat **Access conflicts.** Create custom access conflict monitors that alert you whenever a user is granted a combination of access that violates your organization's separation-of-duties policy or best practice. Go to [Get alerts about conflicting access](/product/admin/access-conflicts) to learn more and get started. -**C1 Slack app** +**C1.ai Slack app** - Summon the **Request access** form in any Slack channel by typing `/c1 request`. - Slack messages about open requests and assigned tasks are automatically updated with the task's current status. -- Comments made on a task in Slack are automatically copied to the task's comments section in C1. And comments posted in C1 are automatically added to the task's thread in Slack. +- Comments made on a task in Slack are automatically copied to the task's comments section in C1.ai. And comments posted in C1.ai are automatically added to the task's thread in Slack. **You must reinstall Slack to start using these new features.** On the **Settings** page, click **Notifications**. Open the **...** menu in the Slack section of the page and select **Reinstall**, then follow the prompts. @@ -773,7 +773,7 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat -**Webhooks.** We're excited to introduce webhooks to C1, which can be used today in your access provisioning workflows. [Learn more about working with webhooks](/product/admin/webhooks) and stay tuned: we'll be adding more ways to use webhooks soon. +**Webhooks.** We're excited to introduce webhooks to C1.ai, which can be used today in your access provisioning workflows. [Learn more about working with webhooks](/product/admin/webhooks) and stay tuned: we'll be adding more ways to use webhooks soon. **Usability improvements** @@ -806,7 +806,7 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat **Usability improvements** -- Users with the Super Admin role in C1 can request access for any other user. +- Users with the Super Admin role in C1.ai can request access for any other user. - A Slack notification will be sent whenever a user has a new deprovisioning task. @@ -891,11 +891,11 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat **New integrations.** We're closing out March by adding four more integrations to our growing library: [Elastic](/baton/elastic), [MongoDB Atlas](/baton/mongodb-atlas), [Miro](/baton/miro), and [Docker Hub](/baton/dockerhub). These integrations are currently in early access as we fine-tune their details and gather feedback. If you're ready to set up any of our new integrations, let us know! -**Create custom entitlements.** On an application's **Entitlements** tab, you'll now find the option to create a custom entitlement in that application. A custom entitlement exists only in C1, and can be bound to other entitlements. Custom entitlements are ideal for creating clear and easily understood targets for user access requests while preserving the underlying complexity of your SCIMed apps' configuration. +**Create custom entitlements.** On an application's **Entitlements** tab, you'll now find the option to create a custom entitlement in that application. A custom entitlement exists only in C1.ai, and can be bound to other entitlements. Custom entitlements are ideal for creating clear and easily understood targets for user access requests while preserving the underlying complexity of your SCIMed apps' configuration. **Usability improvements** -- If you have multiple C1 environments, we can now help you tell them apart at a glance. Let us know if you'd like us to add a **Sandbox** tag to the top of your development environment. +- If you have multiple C1.ai environments, we can now help you tell them apart at a glance. Let us know if you'd like us to add a **Sandbox** tag to the top of your development environment. - You'll no longer receive email or Slack notifications when a revocation task is completed. @@ -914,7 +914,7 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat -**Shadow apps.** Our newest feature helps IT and security teams to see, understand, and manage shadow applications. On the new **Shadow apps** page, you can see the apps that employees have logged into using their corporate email addresses, bring key shadow apps under management with C1, and ignore the shadow apps that aren't of concern. Go to [Detect and manage shadow apps](/product/admin/shadow-apps) to learn more and get started. +**Shadow apps.** Our newest feature helps IT and security teams to see, understand, and manage shadow applications. On the new **Shadow apps** page, you can see the apps that employees have logged into using their corporate email addresses, bring key shadow apps under management with C1.ai, and ignore the shadow apps that aren't of concern. Go to [Detect and manage shadow apps](/product/admin/shadow-apps) to learn more and get started. **Linked entitlements.** To make it easier to manage, request, and review SCIMed access, we're pleased to introduce the **Linked entitlements** tab on each application's page. On this tab you'll find a list of the entitlements currently linked from the IdP. You can link these to existing entitlements in the SCIMed application, or create new roles in the SCIMed app that represent the IdP permissions. @@ -968,11 +968,11 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat **Usability improvements** -- The [entitlement's slug](/product/admin/managing-entitlements) is now included as part of the entitlement name in the C1 Slack app, both on the request access form and in the notifications about an access request. +- The [entitlement's slug](/product/admin/managing-entitlements) is now included as part of the entitlement name in the C1.ai Slack app, both on the request access form and in the notifications about an access request. -- When requesting new access through the C1 Slack app, you can now enter a custom timeframe. +- When requesting new access through the C1.ai Slack app, you can now enter a custom timeframe. -- The status of deleted and disabled Confluence accounts is now shown in C1. +- The status of deleted and disabled Confluence accounts is now shown in C1.ai. **Fixed!** @@ -983,11 +983,11 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat -**Updated navigation panel.** We're welcoming March by freshening C1's navigation panel with a new color treatment and a top navigation bar. +**Updated navigation panel.** We're welcoming March by freshening C1.ai's navigation panel with a new color treatment and a top navigation bar. **Usability improvements** -- When selecting how long new access is needed for on the **Request access** or **Browse access** pages, you now have the option to enter a custom timeframe. If the timeframe you enter is longer than the max grant duration allowed, C1 shows information about the limit to help you choose an approved timeframe. +- When selecting how long new access is needed for on the **Request access** or **Browse access** pages, you now have the option to enter a custom timeframe. If the timeframe you enter is longer than the max grant duration allowed, C1.ai shows information about the limit to help you choose an approved timeframe. - On each user's details page, you'll now find an **Accounts** tab with a list of all the application accounts associated with the user. @@ -995,11 +995,11 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat - Information about an application's sources of access data is now shown on the **Data sources** tab on the application's details page. -- The colors assigned to user status indicators are now used consistently across C1: active is always green, deleted is always red. +- The colors assigned to user status indicators are now used consistently across C1.ai: active is always green, deleted is always red. - You can now pass a SCIM endpoint and access token to the AWS integration to enable pulling user statuses from AWS. -- Bitbucket users now have the option to integrate individual Bitbucket workspaces with C1. +- Bitbucket users now have the option to integrate individual Bitbucket workspaces with C1.ai. **Fixed!** @@ -1014,7 +1014,7 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat - We've added a new **Age** filter to the **Tasks** page, which lets you quickly view tasks that are more than seven, 14, or 30 days old. -- A new **Deactivated user issues** section in the digest email alerts C1 admins to any apps, resources, or entitlements currently owned by deactivated users. +- A new **Deactivated user issues** section in the digest email alerts C1.ai admins to any apps, resources, or entitlements currently owned by deactivated users. - A query for resources with a deactivated owner is now available on the **Access explorer** page. @@ -1035,7 +1035,7 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat - To save time on each sync, the Okta integration no longer syncs role assignments for deprovisioned and suspended Okta accounts. -- The name of the C1 page you're viewing is now shown in the browser tab. +- The name of the C1.ai page you're viewing is now shown in the browser tab. - To prevent accidentally losing in-progress configuration work, we now ask you to confirm that you want to exit without saving your changes. @@ -1045,13 +1045,13 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat - When you make multiple access requests on behalf of someone else by clicking **Make another request**, each request for access is made for the selected user, not for you. -- We've repaired an issue impacting how conditional review policies treated app accounts without an associated C1 user. +- We've repaired an issue impacting how conditional review policies treated app accounts without an associated C1.ai user. -- If a reassigned task is not assigned to any active user, C1 now falls back to assigning it to the system owner or system owners on record. +- If a reassigned task is not assigned to any active user, C1.ai now falls back to assigning it to the system owner or system owners on record. -**New features now generally available.** We're happy to announce that access explorer and the security dashboard are now generally available! Users with the Super Admin role in C1 will see a new **Security** tab on their dashboard. Get started with access explorer by clicking **Explore** in the navigation panel. +**New features now generally available.** We're happy to announce that access explorer and the security dashboard are now generally available! Users with the Super Admin role in C1.ai will see a new **Security** tab on their dashboard. Get started with access explorer by clicking **Explore** in the navigation panel. **Usability improvements** @@ -1072,7 +1072,7 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat **Access explorer.** Get answers to complex identity and access-related questions with just a few clicks. Choose from a list of powerful queries and quickly zoom in on the apps, users, and accounts that matter most. Go to [Query access data to gain insight](/product/admin/query) to see a full list of available queries, and let us know what else you'd like to see in this early access feature! -**Security dashboard.** The new **Security** tab on the C1 dashboard provides a quick overview of key access risks such as orphaned accounts, inactive accounts, high-risk role grants, and standing privileges. Click any item or card displayed on the security dashboard to learn more. The security dashboard is also in early access, so let us know if you're ready to take it for a spin. +**Security dashboard.** The new **Security** tab on the C1.ai dashboard provides a quick overview of key access risks such as orphaned accounts, inactive accounts, high-risk role grants, and standing privileges. Click any item or card displayed on the security dashboard to learn more. The security dashboard is also in early access, so let us know if you're ready to take it for a spin. **Updated integrations.** Three integrations are now generally available: [Snipe-IT](/baton/snipe-it), [Fastly](/baton/fastly), and [GitHub Enterprise](/baton/github-enterprise). Check out the documentation to get started with these integrations today. @@ -1084,7 +1084,7 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat - The **Mark errored** option on provisioning and deprovisioning tasks has been renamed **Won't provision/deprovision** or **Won't do** to better reflect common workflows. -- The C1 Slack app now displays an error if you already have an open request for the access that you're currently trying to request. +- The C1.ai Slack app now displays an error if you already have an open request for the access that you're currently trying to request. - When you click an entitlement's name on a task's details page, you'll now find links to the entitlement, resource, and application details pages. @@ -1133,7 +1133,7 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat -**Customize your session length.** By default, C1 sessions time out after 20 hours. You can now customize the session length to suit your organization's needs and security policies. Go to [Configure session length](/product/admin/global-settings#configure-session-length) to learn more. +**Customize your session length.** By default, C1.ai sessions time out after 20 hours. You can now customize the session length to suit your organization's needs and security policies. Go to [Configure session length](/product/admin/global-settings#configure-session-length) to learn more. **New integration.** This week [Xero](/baton/xero) joined our integrations library. This integration is currently in early access as we fine-tune its details and gather feedback. Let us know if you're eager to get started with Xero and we'll get you set up! @@ -1154,7 +1154,7 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat - The **GitHub Enterprise** integration has been updated, and now supports automatic provisioning of repo permissions. -- Clicking your username at the bottom of the navigation panel now opens the user menu. Use the user menu to log out of C1, navigate to your personal API keys page, or jump to your own user details page. +- Clicking your username at the bottom of the navigation panel now opens the user menu. Use the user menu to log out of C1.ai, navigate to your personal API keys page, or jump to your own user details page. - Previously, if a user's username or manager was not known, the **Username** or **Manager** fields on the user details page were omitted entirely. These fields are now shown with a "None found" message. @@ -1169,13 +1169,13 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat -**:sparkles: Copilot insights and recommendations on access requests.** To help approvers make faster and better-informed decisions about granting new access, C1 Access Copilot now flags key insights about access being requested and makes recommendations on how to proceed. This new feature is in early access while we gather feedback and fine-tune its details. Let us know if you're eager to give it a try! +**:sparkles: Copilot insights and recommendations on access requests.** To help approvers make faster and better-informed decisions about granting new access, C1.ai Access Copilot now flags key insights about access being requested and makes recommendations on how to proceed. This new feature is in early access while we gather feedback and fine-tune its details. Let us know if you're eager to give it a try! **Conditional policies.** We're pleased to announce that conditional policies are now generally available. Conditional policies allow you to define a single policy that applies different instructions based on the user's role, department, job type, or other relevant criteria. Check out the [policy documentation](/product/admin/policies#step-3-optional-add-conditional-policy-rules) to learn more. Many thanks to everyone who provided their feedback and input as we developed this new feature! **Usability improvements** -- Managers can now request new access for the members of their team through the C1 Slack app. +- Managers can now request new access for the members of their team through the C1.ai Slack app. - When an error occurs during provisioning, more context about the error is now shown in the task's audit log. @@ -1186,7 +1186,7 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat -**New dashboard.** We've spruced up the C1 dashboard, making it more helpful and comprehensive. Your dashboard now summarizes and links out to all your reviews, requests, approvals, and campaigns. +**New dashboard.** We've spruced up the C1.ai dashboard, making it more helpful and comprehensive. Your dashboard now summarizes and links out to all your reviews, requests, approvals, and campaigns. **New integrations.** Microsoft 365 and [New Relic](/baton/newrelic) joined our integrations library this week. These new integrations are in early access while we fine-tune their details and gather feedback. Let us know if you're eager to add one or both to your Integrations page. @@ -1194,9 +1194,9 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat **Usability improvements** -- We revised and streamlined the sections of the navigation panel used by C1 users with admin-level user roles. +- We revised and streamlined the sections of the navigation panel used by C1.ai users with admin-level user roles. -- [Entitlement descriptions](/product/admin/managing-entitlements) that have been edited in C1 are now shown when requesting or approving access in the Slack app. If an entitlement's description has not been edited but its [resource description](/product/admin/managing-resources#change-resource-description) has been, the resource description is shown. +- [Entitlement descriptions](/product/admin/managing-entitlements) that have been edited in C1.ai are now shown when requesting or approving access in the Slack app. If an entitlement's description has not been edited but its [resource description](/product/admin/managing-resources#change-resource-description) has been, the resource description is shown. **Fixed!** @@ -1207,7 +1207,7 @@ A new **Unmanaged apps** tab on the **Applications** page shows all the applicat -**:sparkles: Copilot insights and recommendations.** C1 Access Copilot is here to help you and your team make faster, better-informed decisions when completing access reviews. Copilot flags key insights about the access under review and makes recommendations on how to proceed. +**:sparkles: Copilot insights and recommendations.** C1.ai Access Copilot is here to help you and your team make faster, better-informed decisions when completing access reviews. Copilot flags key insights about the access under review and makes recommendations on how to proceed. This new feature is in early access while we gather feedback and fine-tune its details. If you're ready to try it out, let us know! @@ -1217,7 +1217,7 @@ This new feature is in early access while we gather feedback and fine-tune its d - The [Bitbucket](/baton/bitbucket) integration has been updated to support group provisioning, and to use an app password rather than an OAuth consumer for integration configuration. -- We've streamlined the process of signing up for C1 with Okta by adding a direct link to the C1 Okta application on the signup screen. +- We've streamlined the process of signing up for C1.ai with Okta by adding a direct link to the C1.ai Okta application on the signup screen. - When an automatic action is triggered by a match on a conditional policy rule, the matching rule and the automatic action are now shown on the task's details page and in its audit log. @@ -1236,13 +1236,13 @@ This new feature is in early access while we gather feedback and fine-tune its d **Usability improvements** -- Applications that are set as [user directories](/product/admin/directory/) in C1 are now designated with a **directory** chip in the list of applications. To help you quickly find these special apps, we've also added a **Show only directories** filter to the **Applications** page. +- Applications that are set as [user directories](/product/admin/directory/) in C1.ai are now designated with a **directory** chip in the list of applications. To help you quickly find these special apps, we've also added a **Show only directories** filter to the **Applications** page. - If a max grant duration isn't set for an entitlement, the grant duration selection prompt and dropdown are not shown when requesting access to the entitlement. - [Custom entitlement descriptions](/product/admin/managing-entitlements) are now shown on the **Browse access** page. -- We've standardized on a **Month, day year** date format throughout C1. +- We've standardized on a **Month, day year** date format throughout C1.ai. - The Slack connector now syncs each user's `status_text` and `status_emoji` attributes. You can set these as [custom user attributes](/product/admin/attributes) and use this data when [writing conditional policy rules](/product/admin/expressions). @@ -1293,7 +1293,7 @@ This new feature is in early access while we gather feedback and fine-tune its d **Usability improvements** -- We've added an expiring access section to the C1 Slack app. You can now see how long is left on your access grants that have a limited duration, and request an extension if one is needed. +- We've added an expiring access section to the C1.ai Slack app. You can now see how long is left on your access grants that have a limited duration, and request an extension if one is needed. - We've also improved how the Slack app reports the time remaining in campaigns. Instead of rounding down to the nearest week, Slack now shows the number of remaining weeks and days. @@ -1327,7 +1327,7 @@ This new feature is in early access while we gather feedback and fine-tune its d **Usability improvements** -- When you delete an application from C1, that app's entitlements now display a **Deleted** badge and a zero grants count in any catalog that they are included in. +- When you delete an application from C1.ai, that app's entitlements now display a **Deleted** badge and a zero grants count in any catalog that they are included in. - We've added [entitlement slugs](/product/admin/managing-entitlements) to entitlements pulled in by the AWS integration. @@ -1350,7 +1350,7 @@ This new feature is in early access while we gather feedback and fine-tune its d - We've fixed a validation timeout issue in the Bitbucket integration that was causing a `context deadline exceeded` error. -- The C1 Slack application no longer loads indefinitely if a user cannot be found. +- The C1.ai Slack application no longer loads indefinitely if a user cannot be found. @@ -1359,7 +1359,7 @@ This new feature is in early access while we gather feedback and fine-tune its d **Usability improvements** -- The C1 Slack app now includes an **Approval Reason** field on access request notifications. If the request policy in effect requires a reason but one is not provided, Slack asks the reviewer to enter a reason and resubmit their decision. If a reason is not required by the policy, the **Approval Reason** field is optional. +- The C1.ai Slack app now includes an **Approval Reason** field on access request notifications. If the request policy in effect requires a reason but one is not provided, Slack asks the reviewer to enter a reason and resubmit their decision. If a reason is not required by the policy, the **Approval Reason** field is optional. - To make better use of the available space, we've removed the **Due** column from the table of access reviews organized by application. The campaign due date is still shown at the top of the page. @@ -1376,9 +1376,9 @@ This new feature is in early access while we gather feedback and fine-tune its d - When requesting access through the Slack app, the list of entitlement names now includes more information to help you find the entitlement you need. -- The JumpCloud integration now creates a **JumpCloud Administration** application in C1, and assigns all JumpCloud administrators in your organization to that app. +- The JumpCloud integration now creates a **JumpCloud Administration** application in C1.ai, and assigns all JumpCloud administrators in your organization to that app. -- When requesting access on the **Request access** page or in the Slack app for a C1 user who has multiple accounts in the selected application, you are now asked to select which account needs access. +- When requesting access on the **Request access** page or in the Slack app for a C1.ai user who has multiple accounts in the selected application, you are now asked to select which account needs access. - If access is granted indefinitely, the email notification of new access no longer includes information about the length of the grant's duration. @@ -1391,9 +1391,9 @@ This new feature is in early access while we gather feedback and fine-tune its d **Usability improvements** -- When requesting access on the **Browse access** page for a C1 user who has multiple accounts in the selected application, you are now asked to select which account needs access. +- When requesting access on the **Browse access** page for a C1.ai user who has multiple accounts in the selected application, you are now asked to select which account needs access. -- A new **SSO configuration** section is now shown on the **Settings** page. When SSO is enabled for your C1 tenant, the SSO provider in use is shown here. +- A new **SSO configuration** section is now shown on the **Settings** page. When SSO is enabled for your C1.ai tenant, the SSO provider in use is shown here. - Because Salesforce users can include a company's customers, the Salesforce integration no longer syncs several non-employee user types. @@ -1448,7 +1448,7 @@ This new feature is in early access while we gather feedback and fine-tune its d **New integrations.** This week we're welcoming [LDAP](/baton/ldap), [ServiceNow](/baton/servicenow), and [CrowdStrike](/baton/crowdstrike) to our integrations library. If you're ready to get started with one or more of these integrations, let us know. We'll be happy to help get you set up! -**Access request user roles.** To support teams administering access requests in C1, we've launched **Access Request Helpdesk** and **Access Request Administrator** user roles. Any user assigned one of these roles can create an access request ticket on behalf of any other user. Access Request Administrators can also create and manage request catalogs. Go to [Assign user roles](/product/admin/user-roles/) to learn more. +**Access request user roles.** To support teams administering access requests in C1.ai, we've launched **Access Request Helpdesk** and **Access Request Administrator** user roles. Any user assigned one of these roles can create an access request ticket on behalf of any other user. Access Request Administrators can also create and manage request catalogs. Go to [Assign user roles](/product/admin/user-roles/) to learn more. **Usability improvements** @@ -1473,11 +1473,11 @@ This new feature is in early access while we gather feedback and fine-tune its d - You can now sort your list of campaigns by name, description, or target completion date. -- Users with the Super Admin role in C1 can now [revoke any account's access to an entitlement](/product/admin/managing-accounts#manually-revoke-an-accounts-access-to-an-entitlement). +- Users with the Super Admin role in C1.ai can now [revoke any account's access to an entitlement](/product/admin/managing-accounts#manually-revoke-an-accounts-access-to-an-entitlement). **Fixed!** -- Google Workspace accounts with an Archived status are now assigned Disabled status in C1. +- Google Workspace accounts with an Archived status are now assigned Disabled status in C1.ai. @@ -1503,7 +1503,7 @@ This new feature is in early access while we gather feedback and fine-tune its d - If you create a request for emergency access when you already have an open request for non-emergency access to the same app or resource, you'll now see a `duplicate ticket` error with a link to the original request. This makes it easier to escalate the original request to emergency access rather than creating a duplicate request. -- C1 now pulls in more key account data from OneLogin, including manager, title, company, and department. +- C1.ai now pulls in more key account data from OneLogin, including manager, title, company, and department. @@ -1523,9 +1523,9 @@ This new feature is in early access while we gather feedback and fine-tune its d -**Emergency access requests.** We've added emergency access requests to C1 in order to support IT and security teams' need to quickly gain access to key resources in order to respond to emergencies such as production outages. You can now choose which entitlements can be requested during an emergency and build dedicated emergency access policies to use during the expedited approval process. Go to [Enable emergency access requests](/product/admin/emergency/) for more on setting up emergency access requests for your team. +**Emergency access requests.** We've added emergency access requests to C1.ai in order to support IT and security teams' need to quickly gain access to key resources in order to respond to emergencies such as production outages. You can now choose which entitlements can be requested during an emergency and build dedicated emergency access policies to use during the expedited approval process. Go to [Enable emergency access requests](/product/admin/emergency/) for more on setting up emergency access requests for your team. -**Cone, the C1 command line interface (CLI).** If the command line is your happy place, we've got you covered. Use `cone` commands to manage the full access request workflow: view available entitlements, request access, drop access when it's no longer needed, review access requests, and much more. Check out the [Cone docs](/product/cli/install) to learn more and get started. +**Cone, the C1.ai command line interface (CLI).** If the command line is your happy place, we've got you covered. Use `cone` commands to manage the full access request workflow: view available entitlements, request access, drop access when it's no longer needed, review access requests, and much more. Check out the [Cone docs](/product/cli/install) to learn more and get started. **Usability improvements** @@ -1558,7 +1558,7 @@ This new feature is in early access while we gather feedback and fine-tune its d -**New integration.** We're excited to add [1Password](/baton/1password) to our library of integrations. The 1Password integration uses our Baton connector to pull usage data from your 1Password instance. Check out the docs to learn more and get started using 1Password with C1. +**New integration.** We're excited to add [1Password](/baton/1password) to our library of integrations. The 1Password integration uses our Baton connector to pull usage data from your 1Password instance. Check out the docs to learn more and get started using 1Password with C1.ai. **Usability improvements** @@ -1608,7 +1608,7 @@ This new feature is in early access while we gather feedback and fine-tune its d -**Email digest of your open tasks.** We all know that notification emails can quickly go from a help to a burden. That's why we're delighted to introduce a new digest format that summarizes all your open C1 tasks in one quick email. Digest emails can be sent to all C1 users at your organization who currently have open tasks either every weekday or once per week, so you can set the cadence that's best for you and your colleagues. Go to [Email digest notifications](/product/admin/notifications) to learn more and get set up. +**Email digest of your open tasks.** We all know that notification emails can quickly go from a help to a burden. That's why we're delighted to introduce a new digest format that summarizes all your open C1.ai tasks in one quick email. Digest emails can be sent to all C1.ai users at your organization who currently have open tasks either every weekday or once per week, so you can set the cadence that's best for you and your colleagues. Go to [Email digest notifications](/product/admin/notifications) to learn more and get set up. **New integrations.** This week we welcome [UKG](/baton/ukg), [Panther](/baton/panther), and [CloudAMQP](/baton/cloudamqp) to our integrations library. These new integrations are in early access while we gather feedback and fine-tune their details. If you'd like to use one or more of these integrations, let us know! We'd be delighted to get you set up. @@ -1631,10 +1631,10 @@ This new feature is in early access while we gather feedback and fine-tune its d - You can now designate application accounts as system accounts on the application's **Accounts** page. -- C1 now supports two new columns in uploaded spreadsheets and CSV files: +- C1.ai now supports two new columns in uploaded spreadsheets and CSV files: - **User type** to designate whether each account is a user account, service account, or system account - - **Account owner** to automatically map the account owner to the correct C1 user by matching email addresses + - **Account owner** to automatically map the account owner to the correct C1.ai user by matching email addresses **Fixed!** @@ -1660,13 +1660,13 @@ This new feature is in early access while we gather feedback and fine-tune its d **Usability improvements** -- If you have more than one Docusign account, you can now specify the Docusign API Account ID when setting up an integration so that the correct account's data is pulled into C1. +- If you have more than one Docusign account, you can now specify the Docusign API Account ID when setting up an integration so that the correct account's data is pulled into C1.ai. **Fixed!** - You can now successfully set a time limit for an entitlement even if the entitlement is not included in any request catalogs. -- C1 now reads the Okta attribute `managersEmail` as a source for the Manager user attribute. +- C1.ai now reads the Okta attribute `managersEmail` as a source for the Manager user attribute. - When you searched for a user's name in a dropdown field (such as when adding an owner to an app), your search input remained in the field even after you found and selected the right user from the list. We've fixed this. @@ -1675,7 +1675,7 @@ This new feature is in early access while we gather feedback and fine-tune its d -**Directories and user attribute mapping.** We're pleased to announce that these two features are now generally available, and send our thanks to all our users who provided feedback and helped us refine them. [Setting your directory apps](/product/admin/directory) as the sources of truth for employee data is a key step in setting up C1. [User attribute mapping](/product/admin/attributes) helps you to ensure that key employee data is pulled into C1 correctly so it can be used to add context or narrow scope as needed. +**Directories and user attribute mapping.** We're pleased to announce that these two features are now generally available, and send our thanks to all our users who provided feedback and helped us refine them. [Setting your directory apps](/product/admin/directory) as the sources of truth for employee data is a key step in setting up C1.ai. [User attribute mapping](/product/admin/attributes) helps you to ensure that key employee data is pulled into C1.ai correctly so it can be used to add context or narrow scope as needed. **Request access.** The **+ Request access** page in the navigation panel is now generally available for our Access Requests customers. Use this simplified form to request new access for yourself or the folks you manage with a few clicks. Check out [Request access to apps and resources](/product/how-to/create-requests) to learn more. @@ -1685,7 +1685,7 @@ This new feature is in early access while we gather feedback and fine-tune its d **Usability improvements** -- You can now upload files of up to 256MB to C1. +- You can now upload files of up to 256MB to C1.ai. - Your choices when setting campaign parameters now include key user attributes such as Manager, Department, and Job Title. @@ -1703,7 +1703,7 @@ This new feature is in early access while we gather feedback and fine-tune its d **Usability improvements** -- When setting up a Salesforce integration, you now have the option of telling C1 to use Salesforce usernames (which are formed as unique email addresses) as email addresses, rather than the contents of the Salesforce email field. This setting helps C1 to properly sync Salesforce service accounts, which often all use `noreply@salesforce.com` as their email address. +- When setting up a Salesforce integration, you now have the option of telling C1.ai to use Salesforce usernames (which are formed as unique email addresses) as email addresses, rather than the contents of the Salesforce email field. This setting helps C1.ai to properly sync Salesforce service accounts, which often all use `noreply@salesforce.com` as their email address. **Fixed!** @@ -1733,7 +1733,7 @@ This new feature is in early access while we gather feedback and fine-tune its d **A new organization of your application and resource information.** Your application pages now have a new design, organized so that your application, resource, and entitlement data are more intuitively nested. On each application's main page you can view (and in many cases, edit) application details such as the application's owners, governing policies, cost per seat, and data sources. You'll also find new tabs that break out the groups, roles, and other resources present in the application. (If you prefer to see everything together in a single list, use the Entitlements tab.) Click into any resource on the Groups, Roles, or Resources tabs to see and edit the resource's details and the specific entitlements that can be granted to users. Click an entitlement to reach the final layer, where you can edit the entitlement's details and associated attributes, set entitlement-level policies, and more. -**Delegate a user's tasks.** If you want to avoid sending C1 tasks or notifications to a certain user, such as an executive or a colleague who is out on leave, you can now set a delegate to whom that user's tasks will be automatically reassigned. Check out [Delegate a user's tasks](/product/admin/delegate) to get started with this new feature. +**Delegate a user's tasks.** If you want to avoid sending C1.ai tasks or notifications to a certain user, such as an executive or a colleague who is out on leave, you can now set a delegate to whom that user's tasks will be automatically reassigned. Check out [Delegate a user's tasks](/product/admin/delegate) to get started with this new feature. **New and updated integrations.** We're pleased to announce that the [Cloudflare Zero Trust](/baton/cloudflare-zero-trust) and [Sentry](/baton/v1/sentry) integrations are now generally available. Check out the documentation to get up and running with these integrations. We've also added [Asana](/baton/asana), [Expensify](/baton/expensify), [Linear](/baton/linear), and [Slack](/baton/slack) integrations, which are all in early access while we gather more feedback. Let us know if you'd like to add any (or all!) of these new integrations to your Integrations page. @@ -1748,7 +1748,7 @@ This new feature is in early access while we gather feedback and fine-tune its d -**Sign up for C1 using JumpCloud for SSO.** You can now configure an OpenID Connect (OIDC) app in JumpCloud that will enable single-sign-on access to C1 for your users. To get started, go to [Sign up using JumpCloud](/product/how-to/qs-set-up-c1#authenticate-with-jumpcloud). +**Sign up for C1.ai using JumpCloud for SSO.** You can now configure an OpenID Connect (OIDC) app in JumpCloud that will enable single-sign-on access to C1.ai for your users. To get started, go to [Sign up using JumpCloud](/product/how-to/qs-set-up-c1#authenticate-with-jumpcloud). **Usability improvements** @@ -1787,9 +1787,9 @@ This new feature is in early access while we gather feedback and fine-tune its d -**Assign review and access tasks to a group.** You can now assign review and approval tasks to any group in any app integrated with C1. All members of the group will receive notification that a task needs their attention, and any member can complete the task. Get started with group approvals by adding a step to any policy and selecting **Group** as the reviewer. +**Assign review and access tasks to a group.** You can now assign review and approval tasks to any group in any app integrated with C1.ai. All members of the group will receive notification that a task needs their attention, and any member can complete the task. Get started with group approvals by adding a step to any policy and selecting **Group** as the reviewer. -**Google Identity Platform integration.** Good news, Google Identity Platform users: we now have an integration that pulls and syncs Google Identity Platform user data with C1. This new integration is currently in early access, so contact us if you'd like to add it to your **Integrations** page. +**Google Identity Platform integration.** Good news, Google Identity Platform users: we now have an integration that pulls and syncs Google Identity Platform user data with C1.ai. This new integration is currently in early access, so contact us if you'd like to add it to your **Integrations** page. **Fixed!** @@ -1819,7 +1819,7 @@ This new feature is in early access while we gather feedback and fine-tune its d - If an automated step in a task (such as automated connector provisioning or deprovisioning) isn't completed because of a system error, the error is now shown on the relevant step in the task's details view. -- When setting up a Slack channel for a campaign, C1 now checks to see if the channel name you've entered already exists in your Slack instance. If the channel exists, C1 will invite reviewers and send campaign notifications in that the Slack channel instead of creating a new one. +- When setting up a Slack channel for a campaign, C1.ai now checks to see if the channel name you've entered already exists in your Slack instance. If the channel exists, C1.ai will invite reviewers and send campaign notifications in that the Slack channel instead of creating a new one. **Fixed!** @@ -1829,9 +1829,9 @@ This new feature is in early access while we gather feedback and fine-tune its d -**Delegate integration setup to an integration owner.** When you're working on integrating a new application with C1, you can now tap your company's resident expert in that app to create and enter all the relevant credentials. +**Delegate integration setup to an integration owner.** When you're working on integrating a new application with C1.ai, you can now tap your company's resident expert in that app to create and enter all the relevant credentials. -The new delegated integration owner workflow starts with an admin setting up the integration and naming an integration owner to finish the process. C1 notifies the integration owner by email that their help is needed to complete the integration setup, and directs them to the relevant page. Check out the docs for any integration to learn more about how the process works. +The new delegated integration owner workflow starts with an admin setting up the integration and naming an integration owner to finish the process. C1.ai notifies the integration owner by email that their help is needed to complete the integration setup, and directs them to the relevant page. Check out the docs for any integration to learn more about how the process works. **Usability improvements** @@ -1851,12 +1851,12 @@ The new delegated integration owner workflow starts with an admin setting up the - Info drawers are now correctly shown in front of modals when both are open at the same time. -- If an application name was created using double spaces, the app name was displayed with only a single space. If you tried to delete the application and typed in the name as displayed--with single spaces--you received an error because despite what it showed you, C1 expected the name of the app to contain double spaces. Phew. This is now fixed. +- If an application name was created using double spaces, the app name was displayed with only a single space. If you tried to delete the application and typed in the name as displayed--with single spaces--you received an error because despite what it showed you, C1.ai expected the name of the app to contain double spaces. Phew. This is now fixed. -**Google Cloud Platform connector no longer syncs empty roles.** The Google Cloud Platform (GCP) connector no longer syncs roles that do not have any grants. This change is necessary because by default, each GCP project contains roughly 1,000 roles. Removing empty roles from the sync significantly improves the performance of the connector and the usability of the entitlement data it pulls into C1. If you want to include an empty GCP role in your access review, assign a service account to the role before creating the campaign. +**Google Cloud Platform connector no longer syncs empty roles.** The Google Cloud Platform (GCP) connector no longer syncs roles that do not have any grants. This change is necessary because by default, each GCP project contains roughly 1,000 roles. Removing empty roles from the sync significantly improves the performance of the connector and the usability of the entitlement data it pulls into C1.ai. If you want to include an empty GCP role in your access review, assign a service account to the role before creating the campaign. **Fixed!** @@ -1869,19 +1869,19 @@ The new delegated integration owner workflow starts with an admin setting up the -**Data value mappings for imported data.** When you import application data using a CSV file or an Excel spreadsheet, C1 attempts to match the data values in your file to the data values the system expects. We're pleased to introduce a new mapping interface that's designed to make it easier to reconcile the data output by your application and the data model used by C1. Check out the new mapping interface by uploading a file to a new or existing application and then clicking **Set Mappings**. +**Data value mappings for imported data.** When you import application data using a CSV file or an Excel spreadsheet, C1.ai attempts to match the data values in your file to the data values the system expects. We're pleased to introduce a new mapping interface that's designed to make it easier to reconcile the data output by your application and the data model used by C1.ai. Check out the new mapping interface by uploading a file to a new or existing application and then clicking **Set Mappings**. **Usability improvements** -- We've improved the search autocomplete experience across C1, making it easier for you to find what you're looking for. +- We've improved the search autocomplete experience across C1.ai, making it easier for you to find what you're looking for. - The progress bar on your list of access review tasks now shows the number of tasks competed, rather than the percentage. - On pages in the **My work** area where every entry in the task type or current state column was always the same, we removed the redundant columns. -- A user's job title and department is now displayed in list views, if that information is available to C1. If not, the user's email address is shown instead. +- A user's job title and department is now displayed in list views, if that information is available to C1.ai. If not, the user's email address is shown instead. -- You can now include account profile attributes in your file imports to pull in more data about your application accounts to C1. +- You can now include account profile attributes in your file imports to pull in more data about your application accounts to C1.ai. - Tasks that you've acted on but that are assigned to you for a subsequent step are now shown in your tasks list. Only tasks on which no further action is currently required from you are shown as completed tasks. @@ -1976,7 +1976,7 @@ The new delegated integration owner workflow starts with an admin setting up the **Usability improvements** -- We've upgraded tables throughout C1 to include loading indicators, sticky headers, infinite scroll, and other improvements to help you browse and get your work done more efficiently. +- We've upgraded tables throughout C1.ai to include loading indicators, sticky headers, infinite scroll, and other improvements to help you browse and get your work done more efficiently. - If automatic app provisioning or deprovisioning for a user fails, the task is now automatically reassigned to the application's owner. @@ -1997,7 +1997,7 @@ The new delegated integration owner workflow starts with an admin setting up the -**OneLogin connector is now generally available.** Check out the [OneLogin integration instructions](/baton/onelogin) to connect your OneLogin instance with C1. +**OneLogin connector is now generally available.** Check out the [OneLogin integration instructions](/baton/onelogin) to connect your OneLogin instance with C1.ai. **Policy details on demand.** Click a policy's name in a task or a campaign overview to learn more about the policy and see the full list of its steps, all without leaving the current page. diff --git a/product/release-notes.mdx b/product/release-notes.mdx index 4f0bb972..30bb74e0 100644 --- a/product/release-notes.mdx +++ b/product/release-notes.mdx @@ -1,8 +1,8 @@ --- -title: C1 release notes -og:title: Release notes - C1 -og:description: Here are the latest new features, enhancements, and resolved issues for C1. -description: Here are the latest new features, enhancements, and resolved issues for C1. +title: C1.ai release notes +og:title: Release notes - C1.ai +og:description: Here are the latest new features, enhancements, and resolved issues for C1.ai. +description: Here are the latest new features, enhancements, and resolved issues for C1.ai. rss: true sidebarTitle: Release notes --- @@ -12,9 +12,9 @@ sidebarTitle: Release notes ### EU data residency instance now available -C1 now offers an EU data residency instance alongside the existing default instance, for organizations that need customer data stored and processed in the European Union. You choose your hosting region when you register your C1 domain, and it determines every tenant-specific URL from then on — login, redirect URIs, API and webhook endpoints, MCP server, and CLI configuration. +C1.ai now offers an EU data residency instance alongside the existing default instance, for organizations that need customer data stored and processed in the European Union. You choose your hosting region when you register your C1.ai domain, and it determines every tenant-specific URL from then on — login, redirect URIs, API and webhook endpoints, MCP server, and CLI configuration. -Please note that Microsoft Teams as a C1 notification and interaction surface is not yet supported on the EU data residency instance. +Please note that Microsoft Teams as a C1.ai notification and interaction surface is not yet supported on the EU data residency instance. See [Hosting regions](/product/how-to/qs-set-up-c1#hosting-regions) for details. @@ -24,12 +24,12 @@ See [Hosting regions](/product/how-to/qs-set-up-c1#hosting-regions) for details. ### A consolidated nav and a dashboard for every section -We've reorganized the C1 admin navigation to keep pace with everything we've shipped recently. Many features have new homes, but nothing about how each section works has changed. +We've reorganized the C1.ai admin navigation to keep pace with everything we've shipped recently. Many features have new homes, but nothing about how each section works has changed. Here's what's different: - **Apps** — same as before, plus **Connectors**, which now lives here since it powers governance for each app. -- **AI** — unchanged: still your hub for the C1 MCP, MCP Gateway, MCP connections, and AI agents. +- **AI** — unchanged: still your hub for the C1.ai MCP, MCP Gateway, MCP connections, and AI agents. - **Governance** — now includes **Automations**, a more natural fit alongside onboarding and offboarding flows. **Policies**, **Forms**, and **Functions** have moved to the new **Platform** section. - **Identities** — the former **Directory** nav. - **Security** — the former **Identity security** nav, now also home to **Decoys** and the **Graph** explorer. @@ -57,7 +57,7 @@ See [Agent classifiers](/product/admin/agent-classifiers) for details. - **A guided flow for connecting MCP servers**: Registering an MCP server now walks through one question at a time — which server, where it's hosted, the URL, who can use it and when, what happens to newly discovered tools, and how it authenticates — instead of a single multi-step form. -- **Admins can now review and approve MCP resources and URI templates**: When C1 discovers a server that exposes static resources or URI templates, these appear on a new **Resources** tab where an admin can approve them. Each approved resource gets its own read entitlement, so access to a resource is governed separately from tool and toolset access — a user needs an explicit grant to read it. See [Govern MCP resources](/product/admin/mcp-resources) for details. +- **Admins can now review and approve MCP resources and URI templates**: When C1.ai discovers a server that exposes static resources or URI templates, these appear on a new **Resources** tab where an admin can approve them. Each approved resource gets its own read entitlement, so access to a resource is governed separately from tool and toolset access — a user needs an explicit grant to read it. See [Govern MCP resources](/product/admin/mcp-resources) for details. ### Role mining @@ -85,7 +85,7 @@ See [Agent classifiers](/product/admin/agent-classifiers) for details. ### Slack app improvements -- **External Slack accounts can no longer bind to a C1 user**: Slack accounts from outside your workspace — including Slack Connect members — can no longer be linked to a C1 user account by email match. Legitimate workspace members are unaffected; a C1 user whose only Slack match is external now has notifications skipped with a warning. +- **External Slack accounts can no longer bind to a C1.ai user**: Slack accounts from outside your workspace — including Slack Connect members — can no longer be linked to a C1.ai user account by email match. Legitimate workspace members are unaffected; a C1.ai user whose only Slack match is external now has notifications skipped with a warning. - **Slack notifications are more reliable**: A stale Approve/Deny/Provision click now shows an "expired" message instead of failing the workflow and paging oncall, stale or unresolvable interactions fail fast instead of retrying forever, and user-submitted text renders cleanly instead of showing artifacts like trailing asterisks. @@ -151,13 +151,13 @@ Smart revocation traces where an entitlement's access really comes from and revo - **Circuit-breaker logs now play nice with your SIEM**: Automation circuit-breaker system-log events include the standard OCSF time field, so you no longer need a workaround to parse them into your SIEM. -### C1 MCP improvements +### C1.ai MCP improvements - **Find MCP servers from anywhere**: MCP servers are now searchable from the global search (Cmd+K) — search by name, and recently opened servers show up in **Your recent searches** too. -- **Bring governed tools into Copilot Studio**: Build a Copilot Studio agent that calls the tools your IT team approved through C1, with every call authorized and logged under the calling user's own identity, then publish it to Microsoft 365 Copilot and Teams for your whole organization. See [Connect Copilot Studio to C1](/product/admin/mcp-server/copilot-studio). +- **Bring governed tools into Copilot Studio**: Build a Copilot Studio agent that calls the tools your IT team approved through C1.ai, with every call authorized and logged under the calling user's own identity, then publish it to Microsoft 365 Copilot and Teams for your whole organization. See [Connect Copilot Studio to C1.ai](/product/admin/mcp-server/copilot-studio). -- **Bring governed tools into Gemini Enterprise**: Gemini Enterprise can now call the C1 MCP gateway as a tool source, with every tool call attributed to the person who made it instead of a shared service account. See [Connect Gemini Enterprise to C1](/product/admin/mcp-server/gemini-enterprise). +- **Bring governed tools into Gemini Enterprise**: Gemini Enterprise can now call the C1.ai MCP gateway as a tool source, with every tool call attributed to the person who made it instead of a shared service account. See [Connect Gemini Enterprise to C1.ai](/product/admin/mcp-server/gemini-enterprise). ### Ask C1AI improvements @@ -166,13 +166,13 @@ The assistant can now answer when access changed and why it was granted, not jus - **Access history**: Ask for grants and revocations over a period of time, ordered by most recent. Previously the assistant could only tell you who has access today. - **Why access exists**: Each grant now comes back with the reason behind it — an access request, group automation, catalog membership, uplift, and so on. Previously the assistant could report who had access but not why. -See [Ask the C1 AI assistant about access history](/product/admin/ai-assistant#ask-questions-and-take-action). +See [Ask the C1.ai AI assistant about access history](/product/admin/ai-assistant#ask-questions-and-take-action). ### Usability improvements - **Wide task lists no longer get squeezed**: Task lists — including access reviews — now size each column to fit its content and scroll sideways instead of cramming every column into the same width. Long entitlement names truncate with an ellipsis and show the full name on hover. -- **Know when a page is hiding something from you**: Information your role doesn't grant access to used to appear blank, with no way to tell whether a field was empty or just hidden. When a page contains information your role hides, C1 now shows a toast: "Some information on this page is hidden based on your permissions." See [Hidden information based on role](/product/admin/user-roles#hidden-information-based-on-role). +- **Know when a page is hiding something from you**: Information your role doesn't grant access to used to appear blank, with no way to tell whether a field was empty or just hidden. When a page contains information your role hides, C1.ai now shows a toast: "Some information on this page is hidden based on your permissions." See [Hidden information based on role](/product/admin/user-roles#hidden-information-based-on-role). - **See exactly what every push rule did — and why one failed**: Push rules ran with no record of what happened, so a failed push meant trying again and hoping. Every attribute push now shows up in execution history: go to the **Executions** tab on the **Push rule** page for pushes across all connectors, or **View execution history** in a push rule's row menu for just that connector's. Each entry records who was pushed, when, which attributes changed, and — on failure — the reason the target system gave for rejecting it. See [View push execution history](/product/admin/push-rules#view-push-execution-history). @@ -186,7 +186,7 @@ This release cycle tightens up correctness and consistency across the agent-focu **Breaking changes:** - c1i now requires a full `https://` tenant URL — the bare short-name shortcut has been retired, and a non-HTTPS URL is rejected instead of silently upgraded. -- On `mcp servers register`, `mcp servers test-connection`, and `mcp servers update-credentials`, the external MCP server URL flag is now `--server-url` instead of `--url`. Previously the local `--url` flag on these three commands shadowed the global `--url`, so there was no flag that could select the C1 tenant — it had to come from `C1I_URL` or `~/.c1i.yaml`. The global `--url` now selects the tenant on these commands too, as it does everywhere else. +- On `mcp servers register`, `mcp servers test-connection`, and `mcp servers update-credentials`, the external MCP server URL flag is now `--server-url` instead of `--url`. Previously the local `--url` flag on these three commands shadowed the global `--url`, so there was no flag that could select the C1.ai tenant — it had to come from `C1I_URL` or `~/.c1i.yaml`. The global `--url` now selects the tenant on these commands too, as it does everywhere else. See the [v0.5.0](https://github.com/ConductorOne/c1i/releases/tag/v0.5.0) release notes for the full changelog, and [Install c1i](/product/cli/c1i) for setup instructions. See the [c1i command reference](/product/cli/c1i-commands) for the new `apps create`/`delete`/`set-owners`, `auth token`, `mcp gateway list-tools`/`call`, and `policies` commands. @@ -200,7 +200,7 @@ Learn about recent connector updates and our latest batch of new connectors in t ### Catch access risks automatically -Catching an unowned service account, an exposed credential, or a misclassified identity has usually meant someone remembering to go looking for it. Findings does the looking for you. Turn on the conditions you care about, and C1 checks for them on every connector sync. From there, transformation and routing rules let you triage, escalate, or resolve what it finds automatically instead of reviewing every finding by hand. +Catching an unowned service account, an exposed credential, or a misclassified identity has usually meant someone remembering to go looking for it. Findings does the looking for you. Turn on the conditions you care about, and C1.ai checks for them on every connector sync. From there, transformation and routing rules let you triage, escalate, or resolve what it finds automatically instead of reviewing every finding by hand. Decoys are one of the signals Findings watches for. Plant a tripwire credential that looks real but grants no access — any attempt to use it raises a Critical finding. Whoever's using it just sees an ordinary authentication failure, with nothing to tell them they tripped a wire. @@ -236,7 +236,7 @@ Setting up an access review campaign means configuring policy, owners, and scope ### Guided setup for new tenants -When a new C1 tenant is created, you'll now get guided setup for access profiles, access reviews, and automated access management in one flow — reducing time-to-value and eliminating the configuration overhead that slows down early adoption. See [Get a personalized onboarding plan](/product/admin/ai-assistant#get-a-personalized-onboarding-plan) for details. +When a new C1.ai tenant is created, you'll now get guided setup for access profiles, access reviews, and automated access management in one flow — reducing time-to-value and eliminating the configuration overhead that slows down early adoption. See [Get a personalized onboarding plan](/product/admin/ai-assistant#get-a-personalized-onboarding-plan) for details. ### Access review improvements @@ -252,11 +252,11 @@ When a new C1 tenant is created, you'll now get guided setup for access profiles - **Resume paused MCP servers faster**: The MCP servers list now shows a **Resume** button inline to make it easier to find and restart paused servers. -- **Trend charts from C1AI**: C1AI can now generate trend charts (such as grants versus revocations, review decisions, and automation runs) directly from C1's aggregated metrics — fast, with exact numbers you can trace to their source, rather than hand-computed from raw records. +- **Trend charts from C1AI**: C1AI can now generate trend charts (such as grants versus revocations, review decisions, and automation runs) directly from C1.ai's aggregated metrics — fast, with exact numbers you can trace to their source, rather than hand-computed from raw records. ### Usability improvements -- **Date and person fields on request forms**: Request and automation forms could previously only capture free text or dropdown choices, so questions like "what date do you need this by" or "who is this for" had no native answer. Forms now support date fields (with optional earliest/latest limits, fixed or relative to today) and C1-user fields (single- or multi-select, optionally narrowed to a specific set of people). +- **Date and person fields on request forms**: Request and automation forms could previously only capture free text or dropdown choices, so questions like "what date do you need this by" or "who is this for" had no native answer. Forms now support date fields (with optional earliest/latest limits, fixed or relative to today) and C1.ai-user fields (single- or multi-select, optionally narrowed to a specific set of people). - **TypeScript-aware function editor**: Writing a function against the ConductorOne SDK previously meant catching typos and wrong argument types at runtime. The function editor now provides full TypeScript typing and autocomplete for `@c1/functions-sdk` and `@c1/test`, surfacing mistakes like misspelled methods or wrong argument types as you type. @@ -276,7 +276,7 @@ Learn about recent connector updates and our latest batch of new connectors in t ### Assign policy steps to an agent -You can now assign a workflow step in a request or review policy to C1 AI. The agent evaluates each request that reaches the step using C1's built-in guidance plus any custom instructions you provide. +You can now assign a workflow step in a request or review policy to C1.ai AI. The agent evaluates each request that reaches the step using C1.ai's built-in guidance plus any custom instructions you provide. Each agent evaluation is attributed to the built-in **C1 System** agent identity and labeled as an AI-agent action in the audit log. Every evaluation is also recorded as a conversation you can review. See [Policies](/product/admin/policies#assign-for-review) for full details. @@ -300,9 +300,9 @@ Click **View access graph** on any result to see the full grant chain, with your ### Access request improvements -- **Requestable C1 groups**: [C1 groups](/product/admin/groups) can now be added to a request catalog or access profile, so users can request group membership through the same approval flow as other requestable access. +- **Requestable C1.ai groups**: [C1.ai groups](/product/admin/groups) can now be added to a request catalog or access profile, so users can request group membership through the same approval flow as other requestable access. -- **Entitlements created ahead of sync no longer block requests**: Requesting access to an entitlement created ahead of a connector sync — such as through Terraform — previously failed to provision because C1 didn't yet recognize the entitlement. These requests now wait instead, show why they're waiting, and resume automatically once the next sync completes, falling back to manual provisioning after 24 hours. See [Requesting access to entitlements created ahead of sync](/product/admin/managing-entitlements#requesting-access-to-entitlements-created-ahead-of-sync) for details. +- **Entitlements created ahead of sync no longer block requests**: Requesting access to an entitlement created ahead of a connector sync — such as through Terraform — previously failed to provision because C1.ai didn't yet recognize the entitlement. These requests now wait instead, show why they're waiting, and resume automatically once the next sync completes, falling back to manual provisioning after 24 hours. See [Requesting access to entitlements created ahead of sync](/product/admin/managing-entitlements#requesting-access-to-entitlements-created-ahead-of-sync) for details. ### Task approval improvements @@ -312,9 +312,9 @@ Click **View access graph** on any result to see the full grant chain, with your ### Agentic AI and MCP improvements -- **Data lineage for agentic reports**: When the C1 AI assistant generates a report, you can now click **View lineage** to see the exact queries behind each number, confirm each source was verified against the execution log, and copy the lineage for audit workpapers. +- **Data lineage for agentic reports**: When the C1.ai AI assistant generates a report, you can now click **View lineage** to see the exact queries behind each number, confirm each source was verified against the execution log, and copy the lineage for audit workpapers. -- **Multi-chart dashboards and composed reports**: Ask C1 AI for multiple charts and they now render together as an aligned grid, each with its own export and sources. C1 AI can also answer reporting questions with a composed report — stat cards, a trend chart, and a data table in one response, each showing the sources behind it. +- **Multi-chart dashboards and composed reports**: Ask C1.ai AI for multiple charts and they now render together as an aligned grid, each with its own export and sources. C1.ai AI can also answer reporting questions with a composed report — stat cards, a trend chart, and a data table in one response, each showing the sources behind it. - **Generate CEL conditions from plain English**: Writing a CEL condition previously meant working through an AI chat to iterate toward the right expression. Describe the condition you need in plain English and the CEL editor's **Generate** action drops the expression directly into the field in one step. @@ -348,17 +348,17 @@ We also strengthened the safety net that pauses automations before removing an u ### Bulk revoke access from the app account page -App owners can now revoke access directly from their app in C1. On the app's **Accounts** page, select one or more accounts and revoke specific entitlements or remove all access at once. You can also click into a specific app account, find the **Grants** tab and revoke entitlements individually or in bulk. +App owners can now revoke access directly from their app in C1.ai. On the app's **Accounts** page, select one or more accounts and revoke specific entitlements or remove all access at once. You can also click into a specific app account, find the **Grants** tab and revoke entitlements individually or in bulk. ### Condition builder for Directory sources -Configuring which accounts from a Directory source get imported into C1 previously required a raw CEL expression with no way to preview the results before saving. The import configuration now uses the same visual condition builder available elsewhere in C1. A built-in **Data preview** shows how many accounts match and lets you spot-check individual accounts before saving. Custom CEL is still available for complex conditions. See [Connect a directory](/product/admin/directory#optional-limit-which-accounts-will-be-pulled-into-c1). +Configuring which accounts from a Directory source get imported into C1.ai previously required a raw CEL expression with no way to preview the results before saving. The import configuration now uses the same visual condition builder available elsewhere in C1.ai. A built-in **Data preview** shows how many accounts match and lets you spot-check individual accounts before saving. Custom CEL is still available for complex conditions. See [Connect a directory](/product/admin/directory#optional-limit-which-accounts-will-be-pulled-into-c1). ### Navigation updates -We've reorganized parts of the C1 navigation to better reflect how the product has grown: +We've reorganized parts of the C1.ai navigation to better reflect how the product has grown: -- **AI** is now a top-level section. MCP server configuration lives under **AI > MCP**, and C1 Gateway settings, connected clients, and hooks are under **AI > C1 Gateway**. +- **AI** is now a top-level section. MCP server configuration lives under **AI > MCP**, and C1.ai Gateway settings, connected clients, and hooks are under **AI > C1.ai Gateway**. - **Identity security** is a new top-level section. Inventory has moved here from Explore. @@ -372,11 +372,11 @@ See [User roles](/product/admin/user-roles#ai-governance-administrator) for the ### Agentic AI and MCP improvements -- **Richer AI assistant responses in Slack**: The C1 AI assistant in Slack now uses rich interactive responses — buttons, forms, and pickers — so users can complete tasks without leaving the conversation. See [Interact with C1 via Slack](/product/admin/integration-for-Slack). +- **Richer AI assistant responses in Slack**: The C1.ai AI assistant in Slack now uses rich interactive responses — buttons, forms, and pickers — so users can complete tasks without leaving the conversation. See [Interact with C1.ai via Slack](/product/admin/integration-for-Slack). - **Slack conversations in the admin console**: The Agentic AI **Conversations** page now has separate **Web** and **Slack** tabs with full visibility of agent activity across both surfaces. See [Audit AI tool usage](/product/admin/audit-ai-tool-usage). -- **MCP server setup without client credentials**: Hosted and external MCP servers that support OAuth Dynamic Client Registration (DCR) can now be connected without entering a client ID or secret. Enable **Use dynamic client registration** when adding the server and C1 handles registration automatically. See [Set up an MCP server](/product/admin/mcp-servers). +- **MCP server setup without client credentials**: Hosted and external MCP servers that support OAuth Dynamic Client Registration (DCR) can now be connected without entering a client ID or secret. Enable **Use dynamic client registration** when adding the server and C1.ai handles registration automatically. See [Set up an MCP server](/product/admin/mcp-servers). - **Toolset contents visible on hover**: Reviewers can see which tools a toolset includes by hovering over it in the task view, without navigating into entitlement detail pages. See [Govern tools and toolsets](/product/admin/tools-and-toolsets). @@ -419,7 +419,7 @@ Starting in **[provider v1.4.0](https://registry.terraform.io/providers/Conducto If you cannot migrate right away, remove or comment out the `user_ids` field to prevent Terraform drift after this change takes effect. -Contact the C1 support team if you have questions or run into issues. +Contact the C1.ai support team if you have questions or run into issues. ### Connector updates @@ -431,9 +431,9 @@ Learn about recent connector updates and our latest batch of new connectors in t ### Connect private MCP servers through a bridge -If your MCP servers run in a private network — on-prem, in an air-gapped cluster, or behind a firewall — you can now govern their tools through C1 without opening inbound firewall rules or exposing them to the public internet. A lightweight bridge agent (`bridge-client`) runs next to your server and maintains an outbound connection to C1; from there, tool access is requested, approved, reviewed, and audited exactly like any other entitlement in C1. +If your MCP servers run in a private network — on-prem, in an air-gapped cluster, or behind a firewall — you can now govern their tools through C1.ai without opening inbound firewall rules or exposing them to the public internet. A lightweight bridge agent (`bridge-client`) runs next to your server and maintains an outbound connection to C1.ai; from there, tool access is requested, approved, reviewed, and audited exactly like any other entitlement in C1.ai. -AI access management must be enabled for your tenant. See [Connect a private MCP server through a bridge](/product/admin/mcp-server/mcp-bridge) for setup instructions, and contact the C1 support team if you'd like to try it out. +AI access management must be enabled for your tenant. See [Connect a private MCP server through a bridge](/product/admin/mcp-server/mcp-bridge) for setup instructions, and contact the C1.ai support team if you'd like to try it out. @@ -453,13 +453,13 @@ See [Discover access profiles with role mining](/product/admin/role-mining) for ### Early access: custom email provider -C1 notification emails sent from `no-reply@conductorone.com` can look unfamiliar to recipients and get caught by email security tools that flag external senders. With a custom email provider, you can send those same notifications from an address on your own domain, so emails land reliably and recipients recognize the sender immediately. Supported providers are Google Workspace, AWS SES, Microsoft 365, and SendGrid. +C1.ai notification emails sent from `no-reply@conductorone.com` can look unfamiliar to recipients and get caught by email security tools that flag external senders. With a custom email provider, you can send those same notifications from an address on your own domain, so emails land reliably and recipients recognize the sender immediately. Supported providers are Google Workspace, AWS SES, Microsoft 365, and SendGrid. -See [Send email from your domain](/product/admin/email-provider) for details, and contact the C1 Support team if you'd like to try it out or share feedback. +See [Send email from your domain](/product/admin/email-provider) for details, and contact the C1.ai Support team if you'd like to try it out or share feedback. ### Bulk role assignment -Assigning or correcting C1 user roles one user at a time is tedious, especially when onboarding a team or cleaning up after an org change. You can now select multiple users on the **Users** page and assign roles to all of them at once with the bulk **Change role** action. See [User roles](/product/admin/user-roles) for details on available roles. +Assigning or correcting C1.ai user roles one user at a time is tedious, especially when onboarding a team or cleaning up after an org change. You can now select multiple users on the **Users** page and assign roles to all of them at once with the bulk **Change role** action. See [User roles](/product/admin/user-roles) for details on available roles. ### Customizable columns and CSV export for key tables @@ -479,8 +479,8 @@ Step-by-step setup guides are now available for 38 catalog MCP servers, covering - **Full webhook URL provided**: When setting up an [inbound webhook](/product/admin/webhooks-inbound), you previously had to construct the full endpoint URL from the listener ID. The trigger drawer now shows the complete URL ready to copy. - **Task log "Current step" filter**: Finding tasks stuck waiting for approval or provisioning previously meant scanning the full task log. A new **Current step** filter lets you filter directly for tasks awaiting approval or awaiting provisioning. - **MCP server tools table sorting**: You can now sort the **Tools** table on an MCP server by tool name, visibility, classification, state, and last updated, making it easier to find specific tools in a long list. See [MCP servers](/product/admin/mcp-servers) for details. -- **Export policy rules to CSV**: You can now export [policy](/product/admin/policies) rules to CSV directly from a policy's detail page or the policy list page, making it easier to audit or document your policies outside C1. -- **Owner selection when creating apps**: When creating an app, you now assign owners through the full **Select owners** modal, with the same search, filtering, and Users/Entitlements tabs available elsewhere in C1. +- **Export policy rules to CSV**: You can now export [policy](/product/admin/policies) rules to CSV directly from a policy's detail page or the policy list page, making it easier to audit or document your policies outside C1.ai. +- **Owner selection when creating apps**: When creating an app, you now assign owners through the full **Select owners** modal, with the same search, filtering, and Users/Entitlements tabs available elsewhere in C1.ai. ### Connector updates @@ -490,9 +490,9 @@ Learn about recent connector updates and our latest batch of new connectors in t -### Ask C1AI is now available in C1 +### Ask C1AI is now available in C1.ai -Ask questions about your org's access data and take action on what you find — from anywhere in C1, without navigating away from what you're doing. Click **Ask C1AI** in the bottom-right corner of any page to open a floating chat panel. +Ask questions about your org's access data and take action on what you find — from anywhere in C1.ai, without navigating away from what you're doing. Click **Ask C1AI** in the bottom-right corner of any page to open a floating chat panel. @@ -500,7 +500,7 @@ Ask questions about your org's access data and take action on what you find — The assistant can see the context of the page you're on — the application, entitlements, or policy in view — and use it to answer your questions more precisely. Use the toggle in the chat panel to include or exclude that context from the conversation. -See [Use the C1 AI assistant](/product/admin/ai-assistant) for details. +See [Use the C1.ai AI assistant](/product/admin/ai-assistant) for details. @@ -508,9 +508,9 @@ See [Use the C1 AI assistant](/product/admin/ai-assistant) for details. ### Early access: Enterprise-managed authorization -Enterprise-managed authorization lets AI agents (such as Claude and VS Code) reach the MCP servers your organization runs — without per-tool authorization prompts and without persistent secrets. Users authenticate once to C1; their agents then receive short-lived, scoped tokens checked against entitlements before each issuance. Access is requested, approved, reviewed, and revoked through the same workflow you use for any other access in C1, and every token request is recorded. Built on the open Cross-App Access (XAA) standard. +Enterprise-managed authorization lets AI agents (such as Claude and VS Code) reach the MCP servers your organization runs — without per-tool authorization prompts and without persistent secrets. Users authenticate once to C1.ai; their agents then receive short-lived, scoped tokens checked against entitlements before each issuance. Access is requested, approved, reviewed, and revoked through the same workflow you use for any other access in C1.ai, and every token request is recorded. Built on the open Cross-App Access (XAA) standard. -See [Enterprise-managed authorization](/product/admin/enterprise-managed-authorization/overview) for details, and contact the C1 Support team if you'd like to try it out or share feedback. +See [Enterprise-managed authorization](/product/admin/enterprise-managed-authorization/overview) for details, and contact the C1.ai Support team if you'd like to try it out or share feedback. @@ -518,14 +518,14 @@ See [Enterprise-managed authorization](/product/admin/enterprise-managed-authori ## Product digest: June 12, 2026 -*An update on our release notes: Major new features now appear here the day they ship. For everything else, this biweekly digest is your complete picture of what's new in C1 over the past two weeks.* +*An update on our release notes: Major new features now appear here the day they ship. For everything else, this biweekly digest is your complete picture of what's new in C1.ai over the past two weeks.* ### Trigger requestable actions with the AI assistant The AI assistant can now discover and trigger **requestable actions** directly from Slack. Ask what actions are available to you, pick one, and the assistant surfaces the form right in the conversation. Every submission is a deliberate click on your part, and requests run through their configured approval flow. -The C1 app for Slack showing the assistant surfacing a request action form with a Fill out form button. +The C1.ai app for Slack showing the assistant surfacing a request action form with a Fill out form button. See [Request an action from the AI assistant](/product/how-to/request-actions#request-an-action-from-the-ai-assistant) for details. @@ -534,7 +534,7 @@ See [Request an action from the AI assistant](/product/how-to/request-actions#re - **Simplified MCP server authentication**: When you add an MCP server, the authentication step now opens pre-filled with the server's recommended configuration — in most cases, you just enter your credentials and you're done. Servers that support multiple authentication options present each as its own selectable recommended choice. -- **Connection verification**: When connecting an external MCP server, C1 now verifies the server URL and credentials before saving. A **Test auth config** button lets you check the connection at any time and see a clear error message if it fails. +- **Connection verification**: When connecting an external MCP server, C1.ai now verifies the server URL and credentials before saving. A **Test auth config** button lets you check the connection at any time and see a clear error message if it fails. ### Assign a group (or any entitlement) as the owner of a resource @@ -570,15 +570,15 @@ The **Store credential** automation step can now deliver a credential to multipl ### Early access: Cloud infrastructure governance with hierarchical access modeling -C1 now represents cloud infrastructure access the way cloud platforms model it natively — as bindings between a principal, a role, and a scope — instead of materializing every inherited permission combination as a flat row. The result is a navigable resource hierarchy with breadcrumb navigation, so users can request the right role at the right scope, and reviewers can evaluate access with full hierarchy context rather than working through thousands of identical entries. +C1.ai now represents cloud infrastructure access the way cloud platforms model it natively — as bindings between a principal, a role, and a scope — instead of materializing every inherited permission combination as a flat row. The result is a navigable resource hierarchy with breadcrumb navigation, so users can request the right role at the right scope, and reviewers can evaluate access with full hierarchy context rather than working through thousands of identical entries. This early access release supports [Azure](/baton/azure). Access requests, access reviews, JML automation, and provisioning all work on the hierarchical model from day one. -See [Cloud Infrastructure Access](/product/admin/cloud-infrastructure-access) for details, and contact the C1 Support team if you'd like to try it out or share feedback. +See [Cloud Infrastructure Access](/product/admin/cloud-infrastructure-access) for details, and contact the C1.ai Support team if you'd like to try it out or share feedback. ### Scope access reviews by inheritance -A new **By inheritance** scope type is available when creating access review campaigns. Instead of selecting individual entitlements, you select resources and role assignments, and C1 resolves all the access that flows into them — including access inherited from parent resources in the hierarchy and through group membership. Reviewers see not just who has access, but why they have it. +A new **By inheritance** scope type is available when creating access review campaigns. Instead of selecting individual entitlements, you select resources and role assignments, and C1.ai resolves all the access that flows into them — including access inherited from parent resources in the hierarchy and through group membership. Reviewers see not just who has access, but why they have it. See [Scope an access review campaign by inheritance](/product/admin/campaign-scope-by-inheritance) for details. @@ -592,9 +592,9 @@ See [Entitlement configuration rules](/product/admin/entitlement-config-rules) f -### C1 AI assistant for Slack +### C1.ai AI assistant for Slack -The C1 AI assistant is now available directly in Slack. To start a conversation, type `@C1` in any channel where the app is installed, or open the C1 app and use the new **Chat** tab. +The C1.ai AI assistant is now available directly in Slack. To start a conversation, type `@C1` in any channel where the app is installed, or open the C1.ai app and use the new **Chat** tab. The assistant answers questions about your org's access data — who has what access, how your org is structured, what's in your entitlement catalog — and can act on what it finds. @@ -604,9 +604,9 @@ On your explicit approval, it can approve, deny, reassign, or escalate requests, The Slack assistant being asked for a list of open revocation tasks, and the returned results. -You can also ask for data in a specific format and the assistant generates a downloadable report — CSV, JSON, PDF, or plain text — linked directly in your Slack thread. It only sees and acts on what your C1 role allows. +You can also ask for data in a specific format and the assistant generates a downloadable report — CSV, JSON, PDF, or plain text — linked directly in your Slack thread. It only sees and acts on what your C1.ai role allows. -See [Interact with C1 via Slack](/product/admin/integration-for-Slack#ask-questions-and-take-action-with-the-c1-ai-assistant) for details. +See [Interact with C1.ai via Slack](/product/admin/integration-for-Slack#ask-questions-and-take-action-with-the-c1-ai-assistant) for details. @@ -656,7 +656,7 @@ Admins can now surface select app user profile attributes in an access review to ### Terraform provider v1.4.0 -Version 1.4.0 of the C1 Terraform provider is now available. This release adds `annotations` support to most writable resources — the provider automatically populates `managed_by` and `iac_workspace` annotations, and user-supplied values always take precedence. +Version 1.4.0 of the C1.ai Terraform provider is now available. This release adds `annotations` support to most writable resources — the provider automatically populates `managed_by` and `iac_workspace` annotations, and user-supplied values always take precedence. **Breaking change:** `conductorone_access_profile.grant_policy_id` is removed from both the resource and data source. Grant policy is now managed via `AppEntitlement.grant_policy_id`. @@ -668,25 +668,25 @@ See [the Terraform provider's documentation](https://registry.terraform.io/names ### AI access management -AI tools used by your team can now be governed through the same identity platform you use for application access. When AI access management (AIAM) is enabled, every tool call from an MCP-compatible AI client routes through C1's identity-aware proxy, which authenticates the caller, enforces access policies, and logs the call with full identity context — closing a gap that most organizations currently have no visibility into. +AI tools used by your team can now be governed through the same identity platform you use for application access. When AI access management (AIAM) is enabled, every tool call from an MCP-compatible AI client routes through C1.ai's identity-aware proxy, which authenticates the caller, enforces access policies, and logs the call with full identity context — closing a gap that most organizations currently have no visibility into. -Admins register MCP servers from a catalog of 3,000+ integrations, review and approve individual tools, bundle approved tools into toolsets, and bind toolsets to access profiles with the standard C1 request and approval workflow. Downstream credentials are vaulted in C1 and never stored on end-user devices. +Admins register MCP servers from a catalog of 3,000+ integrations, review and approve individual tools, bundle approved tools into toolsets, and bind toolsets to access profiles with the standard C1.ai request and approval workflow. Downstream credentials are vaulted in C1.ai and never stored on end-user devices. -AIAM requires activation. Contact [C1 Support](mailto:support@c1.ai) to enable it for your tenant. +AIAM requires activation. Contact [C1.ai Support](mailto:support@c1.ai) to enable it for your tenant. See [AI access management overview](/product/admin/aiam-overview) to get started. ### Automation circuit breaker -Automations triggered by directory or connector sync events can fire at unexpectedly high volume during bulk imports or data quality issues. The circuit breaker lets you set a rate limit on any automation: if it runs more than a configured number of times within a set period, C1 pauses it and queues new trigger events for review rather than running them. +Automations triggered by directory or connector sync events can fire at unexpectedly high volume during bulk imports or data quality issues. The circuit breaker lets you set a rate limit on any automation: if it runs more than a configured number of times within a set period, C1.ai pauses it and queues new trigger events for review rather than running them. See [Automation circuit breaker](/product/admin/automation-circuit-breaker) for configuration details. ### Object annotations -You can now attach custom key/value metadata to policies, apps, app entitlements, app resources, access profiles, automations, and access review templates — through the C1 UI, API, or Terraform provider. Use annotations to track cost centers, compliance scope, ownership, or any other context your team needs. +You can now attach custom key/value metadata to policies, apps, app entitlements, app resources, access profiles, automations, and access review templates — through the C1.ai UI, API, or Terraform provider. Use annotations to track cost centers, compliance scope, ownership, or any other context your team needs. -Objects managed by Terraform, OpenTofu, or Pulumi display a **Managed by** chip on their detail page, so anyone opening the object in the UI knows it's IaC-managed before making changes. Editing an IaC-managed object in the C1 UI transfers ownership to C1. +Objects managed by Terraform, OpenTofu, or Pulumi display a **Managed by** chip on their detail page, so anyone opening the object in the UI knows it's IaC-managed before making changes. Editing an IaC-managed object in the C1.ai UI transfers ownership to C1.ai. See [Object annotations](/product/admin/object-annotations) for details. @@ -708,7 +708,7 @@ See [Object annotations](/product/admin/object-annotations) for details. - Policy step approver expressions can now use `c1.directory.apps.v1.GetEntitlementOwners` to route approval tasks to the owners of the entitlement being requested. Pass in the `entitlement` variable or specify an explicit `(app_id, entitlement_id)` pair to get the list of entitlement owners — so approvals reach the right people without requiring app-wide ownership grants. -- You'll now find a **Pause sync** button at the top of each connector's detail page. When you disable all resource types on a connector, C1 now prompts you to pause the connector instead of saving an empty configuration. +- You'll now find a **Pause sync** button at the top of each connector's detail page. When you disable all resource types on a connector, C1.ai now prompts you to pause the connector instead of saving an empty configuration. ### Fixes @@ -720,15 +720,15 @@ See [Object annotations](/product/admin/object-annotations) for details. ### AI connections -You can now connect AI assistants — including Claude Desktop, Claude Code, Codex, Cursor, and VS Code — to your C1 data using the Model Context Protocol (MCP). Connected assistants can query users, resources, entitlements, access reviews, and more. All queries are read-only and logged in the system log. +You can now connect AI assistants — including Claude Desktop, Claude Code, Codex, Cursor, and VS Code — to your C1.ai data using the Model Context Protocol (MCP). Connected assistants can query users, resources, entitlements, access reviews, and more. All queries are read-only and logged in the system log. A Super Admin must enable AI connections before users can connect. Optional IP restrictions let you limit which networks can use the feature. -See [C1 MCP](/product/admin/c1-mcp) for setup instructions. +See [C1.ai MCP](/product/admin/c1-mcp) for setup instructions. ### External insights with Wiz Insights -C1 can now sync security issues from Wiz and surface them in context across C1. Reviewers see identity-level security findings for user and service accounts directly on access review tasks, in the task log, and on access request approval tasks — without leaving C1. +C1.ai can now sync security issues from Wiz and surface them in context across C1.ai. Reviewers see identity-level security findings for user and service accounts directly on access review tasks, in the task log, and on access request approval tasks — without leaving C1.ai. External insights are enabled automatically once the Wiz Insights connector is configured and syncing. No additional setup is required. To get started, see [Set up a Wiz Insights connector](/baton/wiz-insights) and [External insights](/product/admin/external-insights). @@ -740,7 +740,7 @@ External insights are enabled automatically once the Wiz Insights connector is c - Users can now revoke their own membership in a time-bound access profile before it expires, as long as they have permission to request that profile. Previously, early revocation returned an error. To revoke, open the access profile and select **Revoke access**. -- The C1 Slack app now supports Enterprise Grid org-wide installs. When an org-wide app is installed, it handles messages and interactions from any workspace in the enterprise without needing separate workspace-level installations. +- The C1.ai Slack app now supports Enterprise Grid org-wide installs. When an org-wide app is installed, it handles messages and interactions from any workspace in the enterprise without needing separate workspace-level installations. @@ -748,7 +748,7 @@ External insights are enabled automatically once the Wiz Insights connector is c ### Early access: c1i -c1i is a new command-line interface for C1 designed for use by AI agents and automation tooling. It provides structured NDJSON output, built-in API documentation you can query without credentials, and automatic pagination — making it easy to integrate C1 data into scripts, pipelines, and agent workflows. +c1i is a new command-line interface for C1.ai designed for use by AI agents and automation tooling. It provides structured NDJSON output, built-in API documentation you can query without credentials, and automatic pagination — making it easy to integrate C1.ai data into scripts, pipelines, and agent workflows. c1i is available now at [github.com/ConductorOne/c1i](https://github.com/ConductorOne/c1i). See [Install c1i](/product/cli/c1i) for setup instructions. For a human-friendly CLI experience, see [Cone](/product/cli/install). @@ -770,7 +770,7 @@ Azure Blob Storage is now supported as an external data source. Admins can confi - The **Automations** page now includes an **Executions** tab with a combined log of all automation runs across your organization. Filter by automation, status, or app to find specific runs without opening each automation individually. -- The C1 Slack app has a new name and logo. Use **@C1** instead of the now-retired **@ConductorOne** to mention or message the app in your workspace. +- The C1.ai Slack app has a new name and logo. Use **@C1.ai** instead of the now-retired **@ConductorOne** to mention or message the app in your workspace. ### Fixes @@ -788,7 +788,7 @@ See the [automation steps reference](/product/admin/automations-steps-reference) ### Custom merge matching for directories -Admins can now configure custom merge matching rules for each directory, to control how C1 links directory accounts to C1 users. Instead of the default email and employee ID matching, you can define an ordered list of rules that pair directory account fields with C1 user fields — choosing from primary email, all emails, username, display name, and employee ID. Rules support optional email normalization and custom CEL expressions for advanced cases. +Admins can now configure custom merge matching rules for each directory, to control how C1.ai links directory accounts to C1.ai users. Instead of the default email and employee ID matching, you can define an ordered list of rules that pair directory account fields with C1.ai user fields — choosing from primary email, all emails, username, display name, and employee ID. Rules support optional email normalization and custom CEL expressions for advanced cases. See [Configure merge matching](/product/admin/directory#configure-merge-matching) for details. @@ -824,9 +824,9 @@ See [Organization contacts](/product/admin/organization-contacts) for details. -### ConductorOne is now C1 +### ConductorOne is now C1.ai -We've always been C1 — now our name matches. You'll notice a new logo, updated colors, and refreshed visuals across the product. Nothing about how C1 works has changed. +We've always been C1.ai — now our name matches. You'll notice a new logo, updated colors, and refreshed visuals across the product. Nothing about how C1.ai works has changed. Your tenant URL (`tenant.conductor.one`) stays the same, and there's nothing you need to do. Read [our announcement](https://www.c1.ai/blog/wearec1) for the full story. @@ -854,14 +854,14 @@ See [Create a campaign](/product/admin/campaigns) and [Complete access review ta ### Early access: Role mining -Role mining analyzes your organization's access patterns and surfaces suggested access profiles based on what it finds. Instead of building access profiles by hand, you can let C1 identify which entitlements are commonly held by similar groups and turn those patterns into ready-to-use profiles with just a few clicks. +Role mining analyzes your organization's access patterns and surfaces suggested access profiles based on what it finds. Instead of building access profiles by hand, you can let C1.ai identify which entitlements are commonly held by similar groups and turn those patterns into ready-to-use profiles with just a few clicks. -C1 offers two ways to use role mining: +C1.ai offers two ways to use role mining: - **Suggestions**: Recommended profiles surface automatically after each connector sync. - **Custom analysis**: Define a specific cohort and analyze that group's access patterns on demand. -To learn more, visit [Discover access profiles with role mining](/product/admin/role-mining). Ready to try it out? Contact the C1 Support team to enable the feature for your tenant. +To learn more, visit [Discover access profiles with role mining](/product/admin/role-mining). Ready to try it out? Contact the C1.ai Support team to enable the feature for your tenant. ### Automation improvements @@ -869,7 +869,7 @@ To learn more, visit [Discover access profiles with role mining](/product/admin/ ### Use Cone with AWS SSO -Cone, the C1 CLI, now supports AWS IAM Identity Center (SSO). Run `cone aws setup` once to generate AWS CLI profiles for every permission set available to you in C1, then use your normal AWS CLI workflow — Cone handles access requests and credential fetching in the background. See [Use Cone with AWS SSO](/product/how-to/cone-aws-sso-integration) for setup instructions. +Cone, the C1.ai CLI, now supports AWS IAM Identity Center (SSO). Run `cone aws setup` once to generate AWS CLI profiles for every permission set available to you in C1.ai, then use your normal AWS CLI workflow — Cone handles access requests and credential fetching in the background. See [Use Cone with AWS SSO](/product/how-to/cone-aws-sso-integration) for setup instructions. ### Resource visibility controls @@ -885,7 +885,7 @@ Admins can now control the visibility of resources and their entitlements. Each ### External insights with CrowdStrike Falcon Identity Protection -C1 can now sync identity risk scores from CrowdStrike Falcon Identity Protection and surface them in context across C1. Reviewers see an identity's risk score and contributing risk factors directly on access review tasks, in the task log, and on access request approval tasks — without leaving C1. +C1.ai can now sync identity risk scores from CrowdStrike Falcon Identity Protection and surface them in context across C1.ai. Reviewers see an identity's risk score and contributing risk factors directly on access review tasks, in the task log, and on access request approval tasks — without leaving C1.ai. External insights are enabled automatically once the CrowdStrike connector is configured and syncing. No additional setup is required. To get started, visit [External insights](/product/admin/external-insights). @@ -911,7 +911,7 @@ External insights are enabled automatically once the CrowdStrike connector is co ### We turned on the dark -C1 now supports dark mode! If your operating system is configured to prefer dark mode, C1 will automatically use the dark theme when you sign in. +C1.ai now supports dark mode! If your operating system is configured to prefer dark mode, C1.ai will automatically use the dark theme when you sign in. To switch themes manually, click your username in the lower left corner of the screen and use the theme switcher. @@ -929,7 +929,7 @@ We've refreshed the navigation and layout on app, resource, and entitlement deta * Advanced filtering options are now available when selecting entitlements on the request access form. Use the new **Resource type** filter to narrow down your entitlement choices. -* C1 now prevents you from requesting access to an access profile you're already enrolled in, avoiding duplicate enrollment tasks and notifications. +* C1.ai now prevents you from requesting access to an access profile you're already enrolled in, avoiding duplicate enrollment tasks and notifications. * When scoping a campaign by user, you can now select up to 200 users (previously limited to 32). @@ -947,13 +947,13 @@ Our new review assistant is an AI agent that helps you complete your assigned ac Tell the agent what actions to take, preview the staged changes, and make any adjustments before submitting. This keeps you in control while moving through reviews more efficiently. -Excited to try out the review assistant? Contact the C1 Support team to enable the feature for your tenant. +Excited to try out the review assistant? Contact the C1.ai Support team to enable the feature for your tenant. ### Scope access review campaigns by risk level and compliance framework When defining a campaign's scope, a new **By criteria** option lets you target entitlements by risk level or compliance framework rather than selecting them individually. -When used in a campaign template, the criteria are saved dynamically — each time you prepare a campaign from the template, C1 re-evaluates which entitlements match, so newly tagged entitlements are automatically included without any manual template updates. +When used in a campaign template, the criteria are saved dynamically — each time you prepare a campaign from the template, C1.ai re-evaluates which entitlements match, so newly tagged entitlements are automatically included without any manual template updates. ### Usability improvements @@ -1003,7 +1003,7 @@ Access review campaigns can now be scoped by access conflicts. When creating a c ### Secret sharing -You can securely share credentials, files, API keys, and other sensitive content with teammates or external contacts from C1. Content is encrypted in your browser before upload, so C1 never sees your plaintext. Recipients authenticate via SSO (internal) or a one-time magic link (external),and you control how long a secret stays available as well as how many times it can be viewed. Administrators can view metadata and audit logs for all secrets across the tenant. +You can securely share credentials, files, API keys, and other sensitive content with teammates or external contacts from C1.ai. Content is encrypted in your browser before upload, so C1.ai never sees your plaintext. Recipients authenticate via SSO (internal) or a one-time magic link (external),and you control how long a secret stays available as well as how many times it can be viewed. Administrators can view metadata and audit logs for all secrets across the tenant. To learn more, visit [Secret sharing](/product/admin/secret-sharing). @@ -1017,22 +1017,22 @@ To learn more, visit [Secret sharing](/product/admin/secret-sharing). ### Early access: Service principals -Service principals are machine identities for non-human actors (such as scripts, CI/CD pipelines, Terraform runs, and API integrations) that are fully separate from any human user account. Assigning C1 roles to a service principal instead of a human account means automated processes have only the access they need, and that access is auditable, ownable, and revocable. Learn more in the [Service principals](/product/admin/service-principals/overview) documentation. +Service principals are machine identities for non-human actors (such as scripts, CI/CD pipelines, Terraform runs, and API integrations) that are fully separate from any human user account. Assigning C1.ai roles to a service principal instead of a human account means automated processes have only the access they need, and that access is auditable, ownable, and revocable. Learn more in the [Service principals](/product/admin/service-principals/overview) documentation. Service principals support two authentication methods: - **Client credentials** — a client ID and secret for scripts, local development, and environments where storing a secret is acceptable (up to 180-day credential lifetime). - **Workload federation** — secretless authentication using your CI/CD platform's built-in OIDC tokens, so there are no secrets to store or rotate. Supported platforms include GitHub Actions, GitLab CI, HCP Terraform, and any custom OIDC provider. -Ready to get started with service principals? Contact the C1 Support team to enable the feature for your tenant. +Ready to get started with service principals? Contact the C1.ai Support team to enable the feature for your tenant. ### Early access: Functions -Functions are serverless TypeScript functions that let you extend C1's identity governance capabilities with your own logic — without managing infrastructure. Use them to call external APIs, implement organization-specific workflows, and automate tasks that go beyond built-in features. +Functions are serverless TypeScript functions that let you extend C1.ai's identity governance capabilities with your own logic — without managing infrastructure. Use them to call external APIs, implement organization-specific workflows, and automate tasks that go beyond built-in features. Functions can run as steps in automations (triggered by user lifecycle events, access events, review events, or schedules) or be invoked manually from the web UI. Each function runs in an isolated sandbox with a network allowlist, secrets management, and execution logging. Learn more in [Extend with custom code](/product/admin/functions). -Excited to give functions a try? Contact the C1 Support team to enable the feature for your tenant. +Excited to give functions a try? Contact the C1.ai Support team to enable the feature for your tenant. ### Usability improvements @@ -1066,7 +1066,7 @@ Excited to give functions a try? Contact the C1 Support team to enable the featu ### Usability improvements -- To speed up the creation of new [C1 groups](/product/admin/groups), you can now click **Duplicate** on any existing group to create a new group pre-filled with the original's name, description, and automation rules, then make your adjustments from there. +- To speed up the creation of new [C1.ai groups](/product/admin/groups), you can now click **Duplicate** on any existing group to create a new group pre-filled with the original's name, description, and automation rules, then make your adjustments from there. - You can now attach a custom request form to an application's [entitlement configuration rule](/product/admin/access-requests#set-access-request-settings-on-specific-resource-types). The form automatically applies to all entitlements governed by that rule, making it faster to configure request requirements across large sets of entitlements. @@ -1074,7 +1074,7 @@ Excited to give functions a try? Contact the C1 Support team to enable the featu - You can now export lists of an application's entitlements and resources as CSV files from their respective tabs on the application's page. The exports include unique resource and entitlement IDs, making it easier to analyze your access data or use it in external tools. -- An application's grant feed CSV export now includes a **TaskID** column showing the associated task ID for each grant added or removed in C1. This provides parity with the information shown in the **Grant feed** drawer and simplifies audit workflows. +- An application's grant feed CSV export now includes a **TaskID** column showing the associated task ID for each grant added or removed in C1.ai. This provides parity with the information shown in the **Grant feed** drawer and simplifies audit workflows. - The **Task log** page now includes a **Task age** column showing how long each task has been open, so you can quickly identify tasks that may need attention. Hover over the age to see the exact creation timestamp. @@ -1106,7 +1106,7 @@ We've redesigned the navigation with a unified left sidebar that consolidates en We're launching two new AI-powered agents designed specifically to help you build automations and policies faster and more accurately: -- The **Automation architect** is a purpose-built agent for creating automations in C1. Describe the workflow you want, and the agent generates the complete automation with triggers and actions, making it faster to set up complex workflows. You'll find this agent on the **Automations** page. +- The **Automation architect** is a purpose-built agent for creating automations in C1.ai. Describe the workflow you want, and the agent generates the complete automation with triggers and actions, making it faster to set up complex workflows. You'll find this agent on the **Automations** page. - The **Policy architect** helps you build access policies by translating your high-level requirements into detailed CEL expressions. Simply describe the access control rules you need, and the agent generates the corresponding policy conditions. You'll find this agent on the **Policies** page when creating or editing a policy. @@ -1124,7 +1124,7 @@ You can now require step-up authentication for approval workflows involving sens ### Usability improvements -- You can now display your organization's name and logo in the C1 interface. Navigate to **Settings** > **Branding** to upload your logo and set a display name. +- You can now display your organization's name and logo in the C1.ai interface. Navigate to **Settings** > **Branding** to upload your logo and set a display name. - You can now write policy conditions that check account types using `AppUserType.SERVICE_ACCOUNT`, `AppUserType.SYSTEM_ACCOUNT`, and `AppUserType.USER`, making it possible to create policies that apply differently to service accounts, system accounts, and human users. @@ -1214,7 +1214,7 @@ When an extension grant task is canceled because the associated app user was del ### Accessibility improvements -We've made significant accessibility improvements to end-user pages in C1. These pages now meet WCAG 2.0 Level AA standards, ensuring a more inclusive experience for all users. +We've made significant accessibility improvements to end-user pages in C1.ai. These pages now meet WCAG 2.0 Level AA standards, ensuring a more inclusive experience for all users. Key improvements include: @@ -1251,7 +1251,7 @@ This dashboard is designed to help teams quickly understand where access is abou ### Microsoft Teams app live on Microsoft Marketplace -The [C1 integration for Microsoft Teams](https://marketplace.microsoft.com/en-us/product/office/WA200009797) is now live on Microsoft Marketplace, making it easier to discover, install, and deploy C1 directly within your Microsoft ecosystem. Ready to bring C1 into your Teams workspace? Check out our docs on the [MS Teams integration](/product/admin/ms-teams-public) to get started. +The [C1.ai integration for Microsoft Teams](https://marketplace.microsoft.com/en-us/product/office/WA200009797) is now live on Microsoft Marketplace, making it easier to discover, install, and deploy C1.ai directly within your Microsoft ecosystem. Ready to bring C1.ai into your Teams workspace? Check out our docs on the [MS Teams integration](/product/admin/ms-teams-public) to get started. ### Usability updates @@ -1305,9 +1305,9 @@ You'll find the updated dashboard on every running and completed campaign. A screenshot of the App catalog tab with the Revoke button for a granted entitlement highlighted. -* We've added a new control on the **Notifications** page that lets admins disable all email notifications for their C1 tenant, including digest emails. +* We've added a new control on the **Notifications** page that lets admins disable all email notifications for their C1.ai tenant, including digest emails. -* Good news, Microsoft Teams users: you can now use the C1 app for Teams to create new access requests. Check out [Request using the Microsoft Teams app](/product/how-to/create-requests#request-using-the-microsoft-teams-app) for details. +* Good news, Microsoft Teams users: you can now use the C1.ai app for Teams to create new access requests. Check out [Request using the Microsoft Teams app](/product/how-to/create-requests#request-using-the-microsoft-teams-app) for details. * The `cone get` command now supports [custom form fields](/product/admin/customize-requests#collect-additional-information-from-requestors-using-request-forms) for entitlements, allowing you to provide required data either interactively or non-interactively via the `--form-data` flag. For details, check out [Custom forms](/product/cli/commands#custom-form-fields) in the `cone` docs. @@ -1315,7 +1315,7 @@ You'll find the updated dashboard on every running and completed campaign. ### Customize user avatars -C1 now supports custom user avatars! To change your own user avatar, open your profile menu in the upper right corner of the screen, click your name, then click the edit icon on your current avatar image. +C1.ai now supports custom user avatars! To change your own user avatar, open your profile menu in the upper right corner of the screen, click your name, then click the edit icon on your current avatar image. Not content just updating your own avatar? On on the user details pages, managers can also upload avatars for their direct reports, and Super Admins can upload avatars for any user. @@ -1355,7 +1355,7 @@ Not content just updating your own avatar? On on the user details pages, manager ### Fixed! -* We resolved an issue that was impacting the accuracy of grant counts on the C1 app. +* We resolved an issue that was impacting the accuracy of grant counts on the C1.ai app. * The data preview shown when adding user profile attributes now accurately accounts for all mapping sources and profile types, ensuring you can reliably test your mappings before deployment. @@ -1373,7 +1373,7 @@ Not content just updating your own avatar? On on the user details pages, manager ### Customize your columns and filters -A highly requested feature is here! You can now customize and rearrange the columns displayed on the **Task log** page and when completing access reviews using the **Unstructured** view. To create your personalized table, click the column icon in the upper-left corner of the table, select the columns you want to see on the page, and drag them into the order you prefer. C1 will save your customizations even when you refresh the page or navigate away. +A highly requested feature is here! You can now customize and rearrange the columns displayed on the **Task log** page and when completing access reviews using the **Unstructured** view. To create your personalized table, click the column icon in the upper-left corner of the table, select the columns you want to see on the page, and drag them into the order you prefer. C1.ai will save your customizations even when you refresh the page or navigate away. A screenshot of the Task log page with the column personalization dropdown open and three columns selected. @@ -1409,21 +1409,21 @@ You can also select which filters you want to use on the **Task log** page by us ### Introducing Super Directory -We've launched a powerful update to C1 user management, separating account creation from attribute management. Designate a single source of truth for users and effortlessly pull additional user data from any connected app. View the docs on [connecting a directory](/product/admin/directory) and [mapping user data](/product/admin/attributes) for details. +We've launched a powerful update to C1.ai user management, separating account creation from attribute management. Designate a single source of truth for users and effortlessly pull additional user data from any connected app. View the docs on [connecting a directory](/product/admin/directory) and [mapping user data](/product/admin/attributes) for details. Plus, meet **profile types**. This new feature lets you easily segment your diverse workforce (like employees versus contractors) to ensure administrators only see the exact user data they need, simplifying management and boosting efficiency. To learn more and get started, visit the [profile types](/product/admin/profile-types) documentation. ### Microsoft Teams integration -With the new [C1 app for Microsoft Teams](/product/admin/ms-teams-public), you can interact directly with C1 without leaving Teams to manage access requests, receive notifications for new approval tasks, and approve or deny requests directly from the Teams interface. This integration also allows users to track the progress of their open access requests and get immediate updates. +With the new [C1.ai app for Microsoft Teams](/product/admin/ms-teams-public), you can interact directly with C1.ai without leaving Teams to manage access requests, receive notifications for new approval tasks, and approve or deny requests directly from the Teams interface. This integration also allows users to track the progress of their open access requests and get immediate updates. ### Usability improvements -* The [updated access reviews experience](/product/release-notes#updated-access-reviews-experience) we announced a few weeks ago is now live for all C1 customers. We've also added the toggle that lets you move between all assigned reviews and those still awaiting a decision to the unstructured reviews view. +* The [updated access reviews experience](/product/release-notes#updated-access-reviews-experience) we announced a few weeks ago is now live for all C1.ai customers. We've also added the toggle that lets you move between all assigned reviews and those still awaiting a decision to the unstructured reviews view. * On the **Analytics** page, you'll now find cards tracking the average completion time for request, revocation, and review tasks. Additionally, we've introduced a new **Identities** section, which displays new and total accounts broken down by user or service type. (Please note that data in this section from before November 1, 2025 might not be accurate.) -* Accounts that are not associated with an email address from a [trusted domain](/product/admin/global-settings#set-trusted-domains) are now labeled **External** across C1, and indicated on each entitlement's **Grants** tab with a globe icon. +* Accounts that are not associated with an email address from a [trusted domain](/product/admin/global-settings#set-trusted-domains) are now labeled **External** across C1.ai, and indicated on each entitlement's **Grants** tab with a globe icon. * We've added a dropdown data type to [custom forms](/product/admin/customize-requests#collect-additional-information-from-requestors-using-request-forms), allowing administrators to define selectable options for users. @@ -1431,7 +1431,7 @@ With the new [C1 app for Microsoft Teams](/product/admin/ms-teams-public), you c ### Platform updates -* You can now manage [vaults](/product/admin/vaults) using the C1 API and Terraform provider. +* You can now manage [vaults](/product/admin/vaults) using the C1.ai API and Terraform provider. ### Fixed! @@ -1445,7 +1445,7 @@ With the new [C1 app for Microsoft Teams](/product/admin/ms-teams-public), you c ### Early access: Analytics -We're excited to bring you an early access launch of a much-requested feature, which will help you see at a glance how access is changing over time in your organization. On the new **Analytics** page, you'll find customizable graphs and high-level metrics about the requests, revocations, and reviews flowing through C1 in the past day, week, or month. +We're excited to bring you an early access launch of a much-requested feature, which will help you see at a glance how access is changing over time in your organization. On the new **Analytics** page, you'll find customizable graphs and high-level metrics about the requests, revocations, and reviews flowing through C1.ai in the past day, week, or month. A screenshot of new Analytics page showing graphs and summary data of requests and revocations in the past month. @@ -1484,7 +1484,7 @@ We're rolling out an updated experience for completing access reviews by app. Th - Users with the **Super Admin** role can now create a revoke task for a grant when access is no longer needed or appropriate from the **Accounts** tab of a user's details page. -- For teams using C1's Copilot-powered service desk integration, a new **Auto-submit requests** setting is available. When enabled, all valid requests will be automatically submitted, and only invalid requests will be routed to your team for manual review. +- For teams using C1.ai's Copilot-powered service desk integration, a new **Auto-submit requests** setting is available. When enabled, all valid requests will be automatically submitted, and only invalid requests will be routed to your team for manual review. - You'll now see a notification popup when the process of closing a campaign gets underway, and another when the campaign has been successfully closed. @@ -1520,7 +1520,7 @@ We're rolling out an updated experience for completing access reviews by app. Th * On a campaign's **Tasks** tab, you can now filter the list of tasks by account type (user, system account, or service account). Additionally, the **Task** filter is now called **Task type** and allows you to zero in on review or revoke tasks. -* To prevent backend issues with the source of C1 users, if your C1 tenant lacks at least one [directory app](/product/admin/directory/), you'll now see an alert on the admin dashboard. +* To prevent backend issues with the source of C1.ai users, if your C1.ai tenant lacks at least one [directory app](/product/admin/directory/), you'll now see an alert on the admin dashboard. ### Fixed! @@ -1530,7 +1530,7 @@ We're rolling out an updated experience for completing access reviews by app. Th ### Usability updates -* In lists of tasks, such as on the **Task log** page or on a campaign's **Tasks** tab, you'll now see a **Suspended** or **Deleted** chip next to the name of any task assignee whose C1 account is not active. +* In lists of tasks, such as on the **Task log** page or on a campaign's **Tasks** tab, you'll now see a **Suspended** or **Deleted** chip next to the name of any task assignee whose C1.ai account is not active. * If an application has more than 10 resource types, you'll now find a dropdown resource type filter on the app's **Entitlements** tab, rather than quick filter buttons for each resource type. @@ -1594,9 +1594,9 @@ We're rolling out an updated experience for completing access reviews by app. Th A screenshot of the Accounts tab on a Requests end user page, highlighting the View accounts button and then showing the account details drawer with Revoke buttons emphasized. -* Only users with the **Super Admin** role in C1 can [move unmanaged apps to managed](/product/admin/applications#move-an-unmanaged-app-to-managed). +* Only users with the **Super Admin** role in C1.ai can [move unmanaged apps to managed](/product/admin/applications#move-an-unmanaged-app-to-managed). -* Application owners with the **Application Admin** role in C1 can now add existing request forms to the entitlements in their apps. Only users with the **Super Admin** role can create new request forms and modify existing forms. +* Application owners with the **Application Admin** role in C1.ai can now add existing request forms to the entitlements in their apps. Only users with the **Super Admin** role can create new request forms and modify existing forms. * We made improvements to the input fields for the **Task action** automation step. You'll now find it easier to customize an automation to close or reassign the tickets concerning a user or assigned to a user. @@ -1604,7 +1604,7 @@ We're rolling out an updated experience for completing access reviews by app. Th ### Platform updates -* Use Terraform to link a new custom C1 group to an existing IdP group so that C1 matches and merges the two groups during the first sync of the IdP. Learn more and see an example script in the [Terraform docs](/developer/terraform#specialized-terraform-capabilities). +* Use Terraform to link a new custom C1.ai group to an existing IdP group so that C1.ai matches and merges the two groups during the first sync of the IdP. Learn more and see an example script in the [Terraform docs](/developer/terraform#specialized-terraform-capabilities). ### Fixed! @@ -1614,9 +1614,9 @@ We're rolling out an updated experience for completing access reviews by app. Th ### System management controls -On the new **System management** page in the **Settings** section, we've added controls that allow Super Admins to disable all Slack and email notifications, access profile membership automations, and automations for your C1 tenant. +On the new **System management** page in the **Settings** section, we've added controls that allow Super Admins to disable all Slack and email notifications, access profile membership automations, and automations for your C1.ai tenant. -Use one or all of these controls when a temporary pause in regular C1 operations is necessary for testing, to prevent unintended consequences, or to perform critical maintenance. Check out [Temporarily disable system features](/product/admin/global-settings#temporarily-disable-system-features) for all the details. +Use one or all of these controls when a temporary pause in regular C1.ai operations is necessary for testing, to prevent unintended consequences, or to perform critical maintenance. Check out [Temporarily disable system features](/product/admin/global-settings#temporarily-disable-system-features) for all the details. ### Usability updates @@ -1659,7 +1659,7 @@ If you need requestors to answer questions or provide additional information whe * Assigned access request approvers and users with the **Super Admin** user role can now change the duration of a requested grant before approving the request. The change in duration will be noted in the task's audit log. - A screenshot of a request task in the C1 UI, showing the duration field in its active edit state. + A screenshot of a request task in the C1.ai UI, showing the duration field in its active edit state. @@ -1682,7 +1682,7 @@ If you need requestors to answer questions or provide additional information whe ### Role mining -To help you construct well-scoped access profiles and identify overlaps in current access across groups of employees, we've introduced data-driven role mining recommendations in the access profile **Manage entitlements** drawer. C1 automatically identifies apps strongly recommended for addition to an access profile as well as those that might be a good fit. Go to [Role mining recommendations](/product/admin/profiles#use-role-mining-recommendations) to learn more. +To help you construct well-scoped access profiles and identify overlaps in current access across groups of employees, we've introduced data-driven role mining recommendations in the access profile **Manage entitlements** drawer. C1.ai automatically identifies apps strongly recommended for addition to an access profile as well as those that might be a good fit. Go to [Role mining recommendations](/product/admin/profiles#use-role-mining-recommendations) to learn more. A screenshot of an access profile's manage entitlements drawer, showing entitlements tagged with a recommendation to add or consider adding to the profile. @@ -1696,7 +1696,7 @@ To help you construct well-scoped access profiles and identify overlaps in curre * Click a connector's **Connected** or **Error** status chip to quickly open the connector's log and sync history. -* [C1 groups](/product/admin/groups) and access profiles can now be included in conflict monitors. +* [C1.ai groups](/product/admin/groups) and access profiles can now be included in conflict monitors. * When creating an access profile or setting an app’s standard audience and choosing the conditions for membership, you can now choose any entitlements (not just groups). @@ -1728,7 +1728,7 @@ You can also set up tailored unused access automations from this section to noti * Use the new `UserType` enum with the new `type` property in [CEL expressions](/product/admin/expressions) to focus on certain user types (human, agent, service, or system). For example, `subject.type == UserType.SERVICE` can be used to locate all service accounts. -* To help you know how policies are being used across your C1 tenant, we've added a count to the top of each policy's details page showing the number of apps, entitlements, campaigns, and campaign templates the policy is applied on. +* To help you know how policies are being used across your C1.ai tenant, we've added a count to the top of each policy's details page showing the number of apps, entitlements, campaigns, and campaign templates the policy is applied on. A screenshot of the top of a policy details page, showing that the policy is applied to 3 apps, 2 entitlements, 75 campaigns, and 2 campaign templates. @@ -1770,7 +1770,7 @@ You can also set up tailored unused access automations from this section to noti ### Introducing automations -We're thrilled to introduce [automations](/product/admin/automations), a powerful new feature designed to dramatically streamline your operational processes within C1. Build custom workflows to handle repetitive tasks, reduce manual effort, improve compliance, and achieve greater efficiency. +We're thrilled to introduce [automations](/product/admin/automations), a powerful new feature designed to dramatically streamline your operational processes within C1.ai. Build custom workflows to handle repetitive tasks, reduce manual effort, improve compliance, and achieve greater efficiency. Automations are ideal for: @@ -1784,7 +1784,7 @@ Explore these new capabilities on the **Automations** page! ### Inventory page -This new page in the **Explore** section gives you a comprehensive, single-pane-of-glass view of all your resources and identities synced to C1. You'll also get insight into key sensitive credentials like API tokens and service account keys from select integrations. +This new page in the **Explore** section gives you a comprehensive, single-pane-of-glass view of all your resources and identities synced to C1.ai. You'll also get insight into key sensitive credentials like API tokens and service account keys from select integrations. A screenshot of the Inventory page, showing the Identities tab with the service accounts filter engaged. @@ -1806,7 +1806,7 @@ With easy-to-use sort and filter tools on each tab, you can quickly pinpoint the ### camelCase CEL expressions -We are adopting camelCase for all [CEL expressions](/product/admin/expressions), and moving away from snake_case. This change will make writing and reading CEL expressions in C1 more consistent, and is intended to improve the overall developer experience. You don't need to modify any expressions you're using today, but new expressions should be written in camelCase. +We are adopting camelCase for all [CEL expressions](/product/admin/expressions), and moving away from snake_case. This change will make writing and reading CEL expressions in C1.ai more consistent, and is intended to improve the overall developer experience. You don't need to modify any expressions you're using today, but new expressions should be written in camelCase. @@ -1826,7 +1826,7 @@ We are adopting camelCase for all [CEL expressions](/product/admin/expressions), ### App account deprovisioning -By default, C1 automatically sets the account deprovisioning process based on your app's provisioning configuration. To customize deprovisioning, go to the app's **Controls** tab and [set how app accounts are deprovisioned](/product/admin/access-requests#set-how-app-accounts-are-deprovisioned). +By default, C1.ai automatically sets the account deprovisioning process based on your app's provisioning configuration. To customize deprovisioning, go to the app's **Controls** tab and [set how app accounts are deprovisioned](/product/admin/access-requests#set-how-app-accounts-are-deprovisioned). ### Usability improvements @@ -1847,9 +1847,9 @@ We've given the **App catalog** tab on your **Requests** page a refresh to strea ### View your profile and set your own OoO delegate -The new **My profile** page in your profile menu shows all the vital info about your C1 user, including your manager and any direct reports. +The new **My profile** page in your profile menu shows all the vital info about your C1.ai user, including your manager and any direct reports. -It's also where you can now [set your own delegate](/product/admin/delegate) for times when you'll be out of the office and unable to complete your assigned C1 tasks. +It's also where you can now [set your own delegate](/product/admin/delegate) for times when you'll be out of the office and unable to complete your assigned C1.ai tasks. ### Usability improvements @@ -1918,7 +1918,7 @@ The connector docs have a new home! Visit the [connector release notes](/baton/_ ### Vaults -Our new **Vaults** feature allows you to securely manage and distribute the initial passwords for application accounts provisioned through C1. +Our new **Vaults** feature allows you to securely manage and distribute the initial passwords for application accounts provisioned through C1.ai. Configure a vault on the **Vaults** page in the **Settings** menu, then direct an application configured for automatic account provisioning to deposit newly created account passwords in the vault. Only the vault owner and the new account's owner can decrypt the new credential. Go to [Vaults](/product/admin/vaults) to learn more and get started. @@ -1977,7 +1977,7 @@ In our continuous effort to create a more intuitive experience, we're making som * The new [Zendesk v2](/baton/zendesk) connector adds support for syncing roles and provisioning roles, orgs, and groups. Learn more about [connector versions and migration](/baton/migration). -* You can now specify which [user attributes](/product/admin/attributes) a connector syncs to C1. Go to [Select which attributes a connector syncs](/baton/configure) to get started. +* You can now specify which [user attributes](/product/admin/attributes) a connector syncs to C1.ai. Go to [Select which attributes a connector syncs](/baton/configure) to get started. * A new configuration field on the [Snyk](/baton/snyk) connector adds support for users who use regional hostnames other than `api.snyk.io`. @@ -1991,9 +1991,9 @@ In our continuous effort to create a more intuitive experience, we're making som ### Fixed! -* You can now successfully remove a deleted user from a C1 group. +* You can now successfully remove a deleted user from a C1.ai group. -* We fixed a bug that was hiding the **Sync now** button on C1 groups in some circumstances. +* We fixed a bug that was hiding the **Sync now** button on C1.ai groups in some circumstances. @@ -2023,7 +2023,7 @@ We've reorganized and simplified the old end-user **Tasks** page, giving it a ne ### Usability improvements -* We're pulling like things together to make C1 easier to navigate. The **Users**, **Groups**, and **User data sources** pages are now gathered in the new **Directory** menu. +* We're pulling like things together to make C1.ai easier to navigate. The **Users**, **Groups**, and **User data sources** pages are now gathered in the new **Directory** menu. * You'll now find the **Policies** page in the **Settings** menu. @@ -2119,7 +2119,7 @@ Some of the key improvements we've made include: * A connector's configuration details, audit trail, and sync history are all shown in a new **Connector log** drawer on the associated application's details page. -* Current information about an [external ticket created by C1 for a provisioning assignment](/product/admin/external-ticketing), including ticket status and a link to the ticket, is now shown on the associated task's details page. We've also improved the logging of fatal errors in external tickets, helping you to more easily understand and resolve issues. +* Current information about an [external ticket created by C1.ai for a provisioning assignment](/product/admin/external-ticketing), including ticket status and a link to the ticket, is now shown on the associated task's details page. We've also improved the logging of fatal errors in external tickets, helping you to more easily understand and resolve issues. * Deleted users are now excluded by default from the **Users** page. Use the **Status** filter to show deleted users. @@ -2139,7 +2139,7 @@ Some of the key improvements we've made include: ### Platform updates -* We've added two new associated IP addresses: `52.33.197.26` and `54.68.132.142`. All C1 IP addresses are listed at the top of the [Connectors overview and FAQ doc](/baton/faq/). +* We've added two new associated IP addresses: `52.33.197.26` and `54.68.132.142`. All C1.ai IP addresses are listed at the top of the [Connectors overview and FAQ doc](/baton/faq/). * A new field, `user.username`, has been added to the User object and can be referenced in condition expressions. @@ -2147,7 +2147,7 @@ Some of the key improvements we've made include: ### Fixed! -* Name changes to access profiles are now shown correctly throughout C1. +* Name changes to access profiles are now shown correctly throughout C1.ai. * The **Generate report** button is no longer displayed if a user does not have permission to generate reports. @@ -2155,7 +2155,7 @@ Some of the key improvements we've made include: * Application owners can only delete the apps that they own. -* The C1 Slack app now shows a more helpful error message if a search for apps returns more than 100 results. +* The C1.ai Slack app now shows a more helpful error message if a search for apps returns more than 100 results. * We fixed an issue that was preventing the successful scoping of campaigns by unused access. @@ -2193,17 +2193,17 @@ At the bottom of the page, click **Create link** to create a sharable link to th * On the **Manage access** page, we've added an **Accounts** tab listing all your application accounts with their status, user roles, and last login information, as available. If you're managing access for another user, use this tab to quickly view a summary of their current accounts. -* You can now use Markdown formatting in comments on tasks to make your notes to other C1 users as bold, italicized, or linked as you'd like. +* You can now use Markdown formatting in comments on tasks to make your notes to other C1.ai users as bold, italicized, or linked as you'd like. * If the user who is the subject of an access review task is deleted after the campaign has started but before the task has been completed, that task is now automatically canceled. -* When an external ticket for a provisioning assignment created by C1 is resolved, this is now noted in the associated task's audit log. +* When an external ticket for a provisioning assignment created by C1.ai is resolved, this is now noted in the associated task's audit log. * On the **Users** tab, you can now download a custom report of the full users list or a filtered selection. ### Fixed! -* When writing CEL expressions to configure account provisioning, enter `subject.attributes.CUSTOM USER ATTRIBUTE` to reference a custom user attribute you've set up in C1. (This replaces the `subject.profile.CUSTOM USER ATTRIBUTE` syntax used previously.) +* When writing CEL expressions to configure account provisioning, enter `subject.attributes.CUSTOM USER ATTRIBUTE` to reference a custom user attribute you've set up in C1.ai. (This replaces the `subject.profile.CUSTOM USER ATTRIBUTE` syntax used previously.) * You can successfully apply multiple filters to the **Task log** page. @@ -2213,7 +2213,7 @@ At the bottom of the page, click **Create link** to create a sharable link to th ### Updates to app creation and management -Building and managing applications in C1 just got easier! Our updated **Applications** experience features an intuitive [app creation flow](/product/admin/applications#create-a-new-application) for seamless data source integration and a powerful new app details page where you can kick off connector syncs, view top-line application stats, and configure account lifecycle management. +Building and managing applications in C1.ai just got easier! Our updated **Applications** experience features an intuitive [app creation flow](/product/admin/applications#create-a-new-application) for seamless data source integration and a powerful new app details page where you can kick off connector syncs, view top-line application stats, and configure account lifecycle management. ### New user role: Application Admin @@ -2271,7 +2271,7 @@ This new feature is in early access while we gather feedback and fine-tune its d ### Usability improvements -* On the new **Organization** page in the **Settings** area, you have the option to [set your organization's trusted domains](/product/admin/global-settings#set-trusted-domains). Accounts associated with a domain not on the list of trusted domains will be marked **External** in C1. +* On the new **Organization** page in the **Settings** area, you have the option to [set your organization's trusted domains](/product/admin/global-settings#set-trusted-domains). Accounts associated with a domain not on the list of trusted domains will be marked **External** in C1.ai. * You'll now find a **Created between** date range option when filtering tasks on the **Task log** page. @@ -2293,7 +2293,7 @@ This new feature is in early access while we gather feedback and fine-tune its d * New this week: [Redis](/baton/redis) and [Galileo Financial Technologies](/baton/galileo-ft). -* You can speed up the provisioning of Entra groups and roles by enabling the new **Schedule SCIM provisioning** option when configuring the Entra connector. This option forces a SCIM sync in Entra whenever new access is provisioned in C1. +* You can speed up the provisioning of Entra groups and roles by enabling the new **Schedule SCIM provisioning** option when configuring the Entra connector. This option forces a SCIM sync in Entra whenever new access is provisioned in C1.ai. * The Concur connector now supports role provisioning. @@ -2423,7 +2423,7 @@ If you've dismissed a banner but need a refresher, click the life-preserver icon ### New user role: Read-Only Admin -The new **Read-Only Admin** user role is ideal for auditors and others who need visibility into C1 without the ability to make changes. Learn more about this new user role's permissions and limitations in the [User roles](/product/admin/user-roles) doc. +The new **Read-Only Admin** user role is ideal for auditors and others who need visibility into C1.ai without the ability to make changes. Learn more about this new user role's permissions and limitations in the [User roles](/product/admin/user-roles) doc. ### Connectors @@ -2458,7 +2458,7 @@ The new **Read-Only Admin** user role is ideal for auditors and others who need ### PingOne and OpenID Connect SSO support -You can now set up a C1 tenant to use PingOne or generic OpenID Connect (OIDC) SSO for user sign-in. Go to [Create a C1 tenant](/product/how-to/qs-set-up-c1) to learn more. +You can now set up a C1.ai tenant to use PingOne or generic OpenID Connect (OIDC) SSO for user sign-in. Go to [Create a C1.ai tenant](/product/how-to/qs-set-up-c1) to learn more. ### Connectors @@ -2487,7 +2487,7 @@ You can now set up a C1 tenant to use PingOne or generic OpenID Connect (OIDC) S ### Automated unenrollment from access profiles -We're excited to launch automated unenrollment for access profiles, complementing our previously released enrollment functionality. Now, when a user no longer meets the membership conditions of an access profile, C1 automatically initiates the unenrollment process you've configured. +We're excited to launch automated unenrollment for access profiles, complementing our previously released enrollment functionality. Now, when a user no longer meets the membership conditions of an access profile, C1.ai automatically initiates the unenrollment process you've configured. To learn more about unenrolling users, check out [Automate onboarding & offboarding access changes](/product/admin/dynamic-access-control). @@ -2509,7 +2509,7 @@ To learn more about unenrolling users, check out [Automate onboarding & offboard * We've added click-to-copy controls to the tooltips that show user and account information, making it easier to grab an email address or other info for use elsewhere. -* If you're a manager or have the Access Request Helpdesk, Access Request Admin, or Super Administrator user roles in C1, you can now request an access profile for another user on the **Request access** form. +* If you're a manager or have the Access Request Helpdesk, Access Request Admin, or Super Administrator user roles in C1.ai, you can now request an access profile for another user on the **Request access** form. ### Fixed! From c4b2c0e348539d96be3ef6205f289481e6d46dde Mon Sep 17 00:00:00 2001 From: Melinda Moreland Date: Wed, 16 Sep 2026 10:06:08 -0700 Subject: [PATCH 2/3] docs: rename C1 to C1.ai in developer/API docs, RAP docs, and internal skill files Renames "C1" -> "C1.ai" in running prose per the new naming style guide, across developer/*.mdx, conductorone-api/*.mdx, rap/*.md (AI-agent retrieval docs), root-level docs (README, index, connector template), and the repo's internal .claude/skills/*.md writing guides. Also manually updates the docs-writing skill's own "Product name" rule (it still said "Always use C1"), and adds the missing c1eu.ai row to its exceptions table, since that file is the source of the now-outdated rule this whole change supersedes. Co-Authored-By: Claude Sonnet 5 --- .claude/skills/connector-docs.md | 18 +- .claude/skills/docs-writing.md | 38 +- .claude/skills/rap-documentation.md | 4 +- README.md | 8 +- conductorone-api/api.mdx | 20 +- conductorone-api/authenticate.mdx | 398 +++++++++--------- conductorone-api/pagination.mdx | 166 ++++---- connector-template.mdx | 20 +- developer/baton-sdk.mdx | 2 +- developer/build-connector.mdx | 6 +- developer/c1-api.mdx | 30 +- developer/community.mdx | 8 +- developer/concepts.mdx | 28 +- developer/config-schema.mdx | 4 +- developer/debugging.mdx | 4 +- developer/glossary.mdx | 22 +- developer/http-authoring.mdx | 18 +- developer/intro.mdx | 24 +- developer/postman.mdx | 10 +- developer/provisioning.mdx | 2 +- developer/recipes-id.mdx | 6 +- developer/sdk.mdx | 14 +- developer/submit.mdx | 10 +- developer/syncing.mdx | 10 +- developer/terraform-best-practices.mdx | 44 +- developer/terraform.mdx | 30 +- index.mdx | 16 +- rap/INDEX.md | 6 +- .../env-account-provisioning.md | 2 +- rap/cel-expressions/env-workflow.md | 2 +- rap/cel-expressions/functions-strings.md | 4 +- rap/cel-expressions/index.md | 4 +- rap/cel-expressions/overview-intro.md | 8 +- rap/cel-expressions/terraform-examples.md | 4 +- rap/cel-expressions/types.md | 10 +- rap/connectors/INDEX.md | 6 +- rap/connectors/community.md | 2 +- rap/connectors/concepts-ids.md | 8 +- rap/connectors/concepts-overview.md | 6 +- rap/connectors/concepts-resources.md | 2 +- rap/connectors/concepts-sync.md | 4 +- rap/connectors/ops-modes.md | 14 +- rap/connectors/ref-c1api.md | 4 +- rap/connectors/ref-config.md | 4 +- rap/connectors/ref-faq.md | 4 +- rap/connectors/ref-glossary.md | 6 +- rap/mcp-gateway/INDEX.md | 10 +- rap/mcp-gateway/concepts-gateway.md | 20 +- rap/mcp-gateway/use-access-requests.md | 14 +- rap/mcp-gateway/use-async-executions.md | 2 +- rap/mcp-gateway/use-code-mode.md | 2 +- rap/service-principals/INDEX.md | 6 +- rap/service-principals/auth-tools.md | 2 +- rap/service-principals/concepts-env-vars.md | 2 +- rap/service-principals/concepts-overview.md | 8 +- rap/service-principals/federation-overview.md | 6 +- rap/service-principals/federation-setup.md | 2 +- rap/service-principals/manage-permissions.md | 2 +- rap/service-principals/platform-aws.md | 4 +- rap/service-principals/platform-github.md | 2 +- rap/service-principals/platform-terraform.md | 2 +- rap/service-principals/security-audit.md | 4 +- 62 files changed, 574 insertions(+), 574 deletions(-) diff --git a/.claude/skills/connector-docs.md b/.claude/skills/connector-docs.md index e9e84f6e..561fa597 100644 --- a/.claude/skills/connector-docs.md +++ b/.claude/skills/connector-docs.md @@ -1,13 +1,13 @@ --- name: c1-connector-docs -description: Write connector documentation for C1 following the established template structure. Use when creating new connector docs in /baton/, updating existing connector pages, or reviewing connector documentation. Ensures consistency with the standardized connector doc format including capabilities tables, credential gathering, and cloud/self-hosted configuration tabs. +description: Write connector documentation for C1.ai following the established template structure. Use when creating new connector docs in /baton/, updating existing connector pages, or reviewing connector documentation. Ensures consistency with the standardized connector doc format including capabilities tables, credential gathering, and cloud/self-hosted configuration tabs. --- -# C1 Connector Documentation +# C1.ai Connector Documentation > **Heads up:** A copy of this skill also lives in [`ConductorOne/baton-admin`](https://github.com/ConductorOne/baton-admin/blob/main/pkg/files/.claude/skills/connector/build-connector-docs.md). If you update this file, copy the changes there too. -Write connector documentation for the `/baton/` directory following C1's standardized template. +Write connector documentation for the `/baton/` directory following C1.ai's standardized template. ## When to Use This Skill @@ -19,7 +19,7 @@ Use this skill when: ## File Format -**Location:** Connector docs live in the connector's GitHub repository in the [C1 organization](https://github.com/ConductorOne), not in this docs repo. Search for the connector repo by name (e.g., `baton-okta`, `baton-salesforce`) to find the right repo. +**Location:** Connector docs live in the connector's GitHub repository in the [C1.ai organization](https://github.com/ConductorOne), not in this docs repo. Search for the connector repo by name (e.g., `baton-okta`, `baton-salesforce`) to find the right repo. **Naming:** The doc file should be named `docs.mdx` and placed in the root or a `docs/` directory of the connector repo, following the convention already established in that repo. @@ -156,7 +156,7 @@ The [App Name] connector supports [automatic account provisioning](/product/admi ### Connector Actions Section (if applicable) -Some connectors support custom actions that can be used in C1 automations. Add this section after the Capabilities table if the connector supports actions. +Some connectors support custom actions that can be used in C1.ai automations. Add this section after the Capabilities table if the connector supports actions. ```mdx ### Connector actions @@ -359,15 +359,15 @@ For more information, see [link to vendor docs]. name: baton-[connector-name]-secrets type: Opaque stringData: - # C1 credentials - BATON_CLIENT_ID: - BATON_CLIENT_SECRET: + # C1.ai credentials + BATON_CLIENT_ID: + BATON_CLIENT_SECRET: # [App Name] credentials BATON_[APP]_[CREDENTIAL_1]: BATON_[APP]_[CREDENTIAL_2]: - # Optional: include if you want C1 to provision access using this connector + # Optional: include if you want C1.ai to provision access using this connector BATON_PROVISIONING: true ``` diff --git a/.claude/skills/docs-writing.md b/.claude/skills/docs-writing.md index 2a830fa5..ae2d074f 100644 --- a/.claude/skills/docs-writing.md +++ b/.claude/skills/docs-writing.md @@ -1,16 +1,16 @@ --- name: c1-docs-writer -description: Write documentation for C1's website following established voice, tone, and style guidelines. Use when creating new documentation pages, updating existing docs, writing how-to guides, or any content for conductorone.com/docs. Ensures consistency with C1's direct, action-oriented documentation style. +description: Write documentation for C1.ai's website following established voice, tone, and style guidelines. Use when creating new documentation pages, updating existing docs, writing how-to guides, or any content for conductorone.com/docs. Ensures consistency with C1.ai's direct, action-oriented documentation style. --- -# C1 Documentation Writer +# C1.ai Documentation Writer -Write C1 documentation that matches the established voice, tone, and style of the existing docs site. +Write C1.ai documentation that matches the established voice, tone, and style of the existing docs site. ## When to Use This Skill Use this skill when: -- Creating new documentation pages for C1 +- Creating new documentation pages for C1.ai - Writing or updating how-to guides - Drafting admin guides or end-user documentation - Creating quickstart guides @@ -18,11 +18,11 @@ Use this skill when: ## The docs voice -Documentation has a different job than marketing. Marketing makes a case for C1. Docs assume the reader already chose C1 — they're here to get something done. The voice shifts accordingly: less energetic, more instructive. +Documentation has a different job than marketing. Marketing makes a case for C1.ai. Docs assume the reader already chose C1.ai — they're here to get something done. The voice shifts accordingly: less energetic, more instructive. **Outside-in framing.** Lead with what the reader is trying to accomplish, not with the feature name or how it works internally. "If you run recurring campaigns, use a template to avoid reconfiguring from scratch each time" is outside-in. "Campaign templates are a feature that allows..." is not. The opening sentence of every page should tell the reader what they can *do* after reading it — not what the feature *is*. -**Declarative, not hedged.** If something is true, say it plainly. Don't write "C1 can help streamline the approval process." Write "C1 auto-approves requests that meet policy." Hedging makes docs feel uncertain; readers lose confidence in the product. +**Declarative, not hedged.** If something is true, say it plainly. Don't write "C1.ai can help streamline the approval process." Write "C1.ai auto-approves requests that meet policy." Hedging makes docs feel uncertain; readers lose confidence in the product. **Peer-level respect.** The reader is a security or IT professional. They know why access reviews matter. They need to know how to run one. Skip context they already have and get to the task. @@ -31,7 +31,7 @@ Documentation has a different job than marketing. Marketing makes a case for C1. - Do: "New tasks will now be automatically reassigned to your delegate." - Don't: "That's it! Tasks will now be assigned to your delegate." -**Active voice, specific verbs.** "C1 sends a notification" not "a notification is sent." "Click **Save**" not "the Save button should be clicked." +**Active voice, specific verbs.** "C1.ai sends a notification" not "a notification is sent." "Click **Save**" not "the Save button should be clicked." **Avoid hedging verbs.** These drain sentences of authority: - "helps you to" → use a direct verb @@ -45,7 +45,7 @@ Documentation has a different job than marketing. Marketing makes a case for C1. ## File Format -**Always use .mdx format** for C1 documentation files. MDX (Markdown with JSX) is the required format for the docs site. When creating new documentation, save files with the `.mdx` extension. +**Always use .mdx format** for C1.ai documentation files. MDX (Markdown with JSX) is the required format for the docs site. When creating new documentation, save files with the `.mdx` extension. ### Content Structure @@ -56,7 +56,7 @@ Documentation has a different job than marketing. Marketing makes a case for C1. ## File and Folder Structure -C1 docs use Mintlify, where **file path = URL**. Structure decisions are permanent without redirects, so be intentional. +C1.ai docs use Mintlify, where **file path = URL**. Structure decisions are permanent without redirects, so be intentional. ### Folder rules @@ -95,7 +95,7 @@ Sidebar grouping in `docs.json` is independent of folder structure. You can visu - Are there any hedging verbs, editorializing phrases, or throat-clearing openers? - Does any sentence try to serve too many stakeholders at once? Split it or cut it. - After each procedure, is there an outcome sentence stating what changed? - - Is the company name "C1" throughout? + - Is the company name "C1.ai" throughout? ## Key Style Points @@ -211,14 +211,14 @@ When documenting features that are in early access, add a standardized warning c **Key points:** - Always use `` (not `` or ``) -- Always use "the C1 Support team" (not "our Support team" or "your account team") +- Always use "the C1.ai Support team" (not "our Support team" or "your account team") - Don't name the specific feature (use "This feature") - Include the explanation of what early access means - Use "share feedback" (not "have any feedback") ## Hosting region references (default instance vs. EU data residency) -C1 runs two hosting options — a **default instance** (`conductor.one`) and an **EU data residency instance** (`c1eu.ai`). A tenant is provisioned in one region, and every tenant-specific URL, hostname, or IP address reflects it. See the "Hosting regions" table in [Create a C1 tenant](/product/how-to/qs-set-up-c1) for the canonical explainer — link there rather than re-explaining the concept on other pages. +C1.ai runs two hosting options — a **default instance** (`conductor.one`) and an **EU data residency instance** (`c1eu.ai`). A tenant is provisioned in one region, and every tenant-specific URL, hostname, or IP address reflects it. See the "Hosting regions" table in [Create a C1.ai tenant](/product/how-to/qs-set-up-c1) for the canonical explainer — link there rather than re-explaining the concept on other pages. Anywhere a region-specific value appears, use one of the two treatments below based on how the value is used — not on which section of the docs it's in. @@ -229,9 +229,9 @@ Anywhere a region-specific value appears, use one of the two treatments below ba - EU data residency instance: `https://accounts.c1eu.ai/auth/callback` ``` -Lead into the pair with wording that tells the reader how to choose — "whichever matches your C1 tenant's domain" — rather than assuming they already know which hosting option they're on. This applies even when the value is tenant-specific (contains a placeholder like `` or `YOUR_DOMAIN`): show both domain suffixes, not just `conductor.one`. +Lead into the pair with wording that tells the reader how to choose — "whichever matches your C1.ai tenant's domain" — rather than assuming they already know which hosting option they're on. This applies even when the value is tenant-specific (contains a placeholder like `` or `YOUR_DOMAIN`): show both domain suffixes, not just `conductor.one`. -Don't use this pattern for a value the reader copies directly from their own C1 account (for example, an MCP server URL shown on an "AI connections" page) — the product already displays the tenant's real, region-correct value, so there's nothing to disambiguate. +Don't use this pattern for a value the reader copies directly from their own C1.ai account (for example, an MCP server URL shown on an "AI connections" page) — the product already displays the tenant's real, region-correct value, so there's nothing to disambiguate. **Reference and example-heavy pages** (API docs, CLI docs, service-principal/workload-federation guides) where `conductor.one` appears repeatedly inside code blocks or curl examples — don't rewrite every example. Add one callout near the section the examples belong to instead: @@ -255,15 +255,15 @@ Don't use this pattern for a value the reader copies directly from their own C1 ## Product name -Always use **C1** to refer to the product and company in prose. Do not use "ConductorOne" in new documentation. +Always use **C1.ai** to refer to the product and company in prose. Do not use "ConductorOne" in new documentation. **Marketing website:** The marketing website is **c1.ai** — use this for any links to the public marketing site. Do not use `conductorone.com` for marketing links. -**Exceptions — never change these to C1:** +**Exceptions — never change these to C1.ai:** | What | Examples | | :--- | :--- | -| Product and tenant URLs | `conductor.one`, tenant URLs like `example.conductor.one` | +| Product and tenant URLs | `conductor.one`, tenant URLs like `example.conductor.one`, and `c1eu.ai` (the EU data-residency domain) | | File and directory paths generated by tools | `~/.conductorone/config.yaml` | | Code identifiers | Environment variables (`CONDUCTORONE_CLIENT_ID`), package names, binary names | | GitHub organization in URLs | `github.com/ConductorOne/...` | @@ -272,14 +272,14 @@ When in doubt: if a user would type it into a terminal or config file, leave it ## Common Mistakes to Avoid -- **Hedging verbs**: "helps you to," "can help," "is designed to," "allows you to" — use direct verbs instead ("lets you," "C1 does X") +- **Hedging verbs**: "helps you to," "can help," "is designed to," "allows you to" — use direct verbs instead ("lets you," "C1.ai does X") - **Feature-first openers**: "Campaign templates are a feature that allows..." → lead with what the reader can do instead - **Celebrating task completion**: "That's it!", "Done.", "You're all set!" → state the outcome - **Multi-clause sentences serving too many stakeholders at once** — split or cut - **Editorializing**: "it's important to note," "it's worth mentioning," "please note" - **Promotional language**: "powerful," "robust," "seamless," "innovative" - **Excessive conjunctions**: "moreover," "furthermore," "additionally" -- **Using "ConductorOne"** instead of "C1" in prose +- **Using "ConductorOne"** instead of "C1.ai" in prose - **Using "bool"** — use "Boolean" - **Title case in headings** — sentence case only - **Context-free headings** like "FAQ" or "Related" — always include the subject ("Frequently asked questions about automations") diff --git a/.claude/skills/rap-documentation.md b/.claude/skills/rap-documentation.md index 7b2baafa..31977649 100644 --- a/.claude/skills/rap-documentation.md +++ b/.claude/skills/rap-documentation.md @@ -120,9 +120,9 @@ RAP files target LLM agents, not humans. Write differently than human-facing doc **Example contrast:** -Human docs: "The Baton connector framework solves this elegantly: you write one integration, and C1 handles the rest." +Human docs: "The Baton connector framework solves this elegantly: you write one integration, and C1.ai handles the rest." -RAP docs: "A connector translates access data from any system into C1's common format." +RAP docs: "A connector translates access data from any system into C1.ai's common format." The human version has warmth and sells the benefit. The RAP version states the fact. Both are correct; they serve different audiences. diff --git a/README.md b/README.md index 8c71663c..46d5b94a 100644 --- a/README.md +++ b/README.md @@ -1,6 +1,6 @@ -# C1 documentation +# C1.ai documentation -Welcome to the official repository for [C1 documentation](https://www.conductorone.com/docs)! +Welcome to the official repository for [C1.ai documentation](https://www.conductorone.com/docs)! We believe that great documentation is a community effort. This repository contains the source files for our docs site, and we’re excited to open it up for public contributions. Whether you've found a typo, a broken link, or have a suggestion for a new guide, we welcome your input. @@ -20,9 +20,9 @@ If you have larger changes or want to work locally: ## 📝 Review process -Every contribution, no matter how small, helps improve the experience for all C1 users. So thank you! +Every contribution, no matter how small, helps improve the experience for all C1.ai users. So thank you! -Once you submit a pull request, the **C1 documentation team** will review your suggestions. We may ask for clarification or make minor adjustments to ensure consistency with our style guide. Once approved, we’ll merge your changes and they’ll be live on the site shortly after! +Once you submit a pull request, the **C1.ai documentation team** will review your suggestions. We may ask for clarification or make minor adjustments to ensure consistency with our style guide. Once approved, we’ll merge your changes and they’ll be live on the site shortly after! ## 🤖 Writing with Claude diff --git a/conductorone-api/api.mdx b/conductorone-api/api.mdx index 346fcd00..23bcaa39 100644 --- a/conductorone-api/api.mdx +++ b/conductorone-api/api.mdx @@ -1,20 +1,20 @@ --- -title: Introducing C1's API -og:title: Introducing C1's API - C1 -og:description: The C1 API can be used to access data, automate tasks, and create integrations. -description: The C1 API can be used to access data, automate tasks, and create integrations. -sidebarTitle: "C1 API and keys" +title: Introducing C1.ai's API +og:title: Introducing C1.ai's API - C1.ai +og:description: The C1.ai API can be used to access data, automate tasks, and create integrations. +description: The C1.ai API can be used to access data, automate tasks, and create integrations. +sidebarTitle: "C1.ai API and keys" --- -The C1 application programming interface (API) is a set of rules that defines how C1 can communicate with other software programs. The C1 API lets developers access C1 data and functionality, automate workflows, and connect C1 to other tools and interfaces. +The C1.ai application programming interface (API) is a set of rules that defines how C1.ai can communicate with other software programs. The C1.ai API lets developers access C1.ai data and functionality, automate workflows, and connect C1.ai to other tools and interfaces. ## Create a personal API key -Create a personal API key to use when working with the C1 API. +Create a personal API key to use when working with the C1.ai API. - In the C1 web app, open your profile menu and select **API keys**. + In the C1.ai web app, open your profile menu and select **API keys**. Click **Create credential**. @@ -46,10 +46,10 @@ Your new API key is created and the client ID and client secret are shown. Caref The API key is added to list of your personal API clients, and its client ID and usage data for the key are shown. If needed, you can delete the API key from this page. -## View and manage all API keys for your C1 tenant +## View and manage all API keys for your C1.ai tenant -Only users with the **Super Administrator** [user role](/product/admin/user-roles) in C1 can view and manage API keys other than their own. +Only users with the **Super Administrator** [user role](/product/admin/user-roles) in C1.ai can view and manage API keys other than their own. diff --git a/conductorone-api/authenticate.mdx b/conductorone-api/authenticate.mdx index b212b3b6..87bdd760 100644 --- a/conductorone-api/authenticate.mdx +++ b/conductorone-api/authenticate.mdx @@ -1,199 +1,199 @@ ---- -title: How to authenticate requests -description: "To use the C1 API, you must authenticate your requests. This document guides you through the process of obtaining and utilizing an API key, as well as establishing an access token." ---- - -These examples use `conductor.one`. If your organization is on the EU data residency instance, substitute `c1eu.ai` in URLs, client IDs, and hostnames. - -## Step 1: Obtain an API key - -The first step in the process is to obtain your API key from C1: - - - -In the C1 app, navigate to the User's API Settings page by clicking your username at the bottom of the screen and selecting **AI & API**. - - -In the **API credentials** section of the page, click **Create credential**. - - -Enter a descriptive name for your API key. - - -Set the API key's lifespan. Select from 30 days, 90 days, or never expires. - - -If necessary, limit the source IPs the API key can be used from by entering one or more CIDR blocks in the **Allowed IPs** field. - - -Select the scope of permissions for the API key. You can choose either **Full Permissions** or select specific roles to assign to the API key. - - -Click **Create** to generate the API key. - - - -Your new key is created, and its Client ID and Client Secret are generated and displayed. Take note that the Client Secret is shown to you once, so make sure to securely store this information. - -On the API credentials table, you'll view the name and Client ID of each API key you've created, the key's expiration date (if relevant), the scope granted to the key, and its created on and last used dates. - -### Details about the Client ID and Client Secret - -The Client ID is a stable format that includes a random ID, the base hostname, and the use-case. It is represented in the format: `@/`. For example: `strange-hydra-68836@acme.conductor.one/pcc`. - -The Client Secret follows the format: `secret-token:conductorone.com:${base64url encoded JWK}`. It contains an `ed25519` private key that you may parse to get the private key. For example: - -```bash -secret-token:conductorone.com:v1:eyJrdHkiOiJPS1AiLCJjcnYiOiJFZDI1NTE5IiwieCI6IkMySEx5Y0d6eUhfZDQwcjJvejZoNkpqdndvRVFBZ0FTRVc2eDB6emh6Y2MiLCJkIjoiLTgzVkxXUVUtZVhQY0ZCWVhDb2NpU29XVmhrYnRXUm9zdkZUZ3JqcXNVbyJ9 -``` - -Remember to securely handle and store your Client ID and Client Secret. They play a critical role in the security and integrity of your interaction with our API. - -## Step 2: Determine your API root and token endpoint - -A crucial part of interacting with the C1 API involves determining the appropriate endpoints for your requests. Two key components in this process are your API root and the token endpoint. These can be inferred from your Client ID. - -### Extracting the hostname from the Client ID - - -Your Client ID is in the format `@/`. The hostname for your API client can be identified as the portion of your Client ID immediately following the `@` and preceding the `/`. - -For instance, for the Client ID `strange-hydra-68836@acme.conductor.one/pcc`, the hostname is `acme.conductor.one`. - -### Identifying the token endpoint - -With the hostname in hand, the token endpoint can be determined. It resides under the hostname at the path `/auth/v1/token`. So for the example Client ID above, the token endpoint is `https://acme.conductor.one/auth/v1/token`. - -### Identifying the API root - -Similar to the token endpoint, the API root is also located under the hostname. It resides at the path `/api/v1`. In our example Client ID, the API root is `https://acme.conductor.one/api/v1`. - -## Step 3: Get an access token - -There are two methods available for obtaining an access token. Choose the one that best fits your needs. - -### Get a basic access token - -A basic access token can be obtained by utilizing your Client ID and Client Secret with the OAuth2 Token Endpoint. - -To achieve this: - -POST a request to Token Endpoint using the `application/x-www-form-urlencoded` content type. - -Include the following data in your request: - -- `grant_type=client_credentials` -- `client_id=${CLIENT_ID}` -- `client_secret=${CLIENT_SECRET}` - -You will receive a JSON response which includes an an `access_token`, `token_type`, and an `expires_in` value that indicates the number of seconds until the access token expires. - -Example JSON response: - -```json -{ - "access_token": "secret_access_token_value", - "token_type": "Bearer", - "expires_in": 600 -} -``` - -#### Example requests for a basic access token - -The examples below use placeholder values. Replace ``, ``, and `` with values from your own API credential (see Step 1) and the hostname extracted from your Client ID (see Step 2). - - -```bash curl -curl -X POST "https:///auth/v1/token" \ - -H "Content-Type: application/x-www-form-urlencoded" \ - --data-urlencode "grant_type=client_credentials" \ - --data-urlencode "client_id=" \ - --data-urlencode "client_secret=" -``` - -```python Python -import requests - -CLIENT_ID = "" -CLIENT_SECRET = "" -HOSTNAME = "" # for example, "acme.conductor.one" - -response = requests.post( - f"https://{HOSTNAME}/auth/v1/token", - data={ - "grant_type": "client_credentials", - "client_id": CLIENT_ID, - "client_secret": CLIENT_SECRET, - }, - headers={"Content-Type": "application/x-www-form-urlencoded"}, -) -response.raise_for_status() - -access_token = response.json()["access_token"] - -# Use the token in subsequent requests -api_response = requests.get( - f"https://{HOSTNAME}/api/v1/apps", - headers={"Authorization": f"Bearer {access_token}"}, -) -``` - - -### Get an access token using a Signed Client Assertion - -For a more secure authentication process, a JWT can be created and signed using the JWK private key derived from the parsed Client Secret. - -Here are the key requirements for the signed JWT: - -- The issuer (iss) should be set to the `${CLIENT_ID}` value. -- The subject (sub) should be set to the `${CLIENT_ID}` value. -- The audience (aud) should be set to the Tenant's Domain. -- The expiration time (exp) of the JWT must be within five minutes of the current time. Infinitely valid JWTs are not allowed. - -To authenticate using a signed client assertion, you should POST a request to `${TOKEN_ENDPOINT}` using the `application/x-www-form-urlencoded` content type with the following data: - -- `grant_type=client_credentials` -- `client_assertion_type=urn:ietf:params:oauth:client-assertion-type:jwt-bearer` -- `client_id=${CLIENT_ID}` -- `client_assertion=${CLIENT_ASSERTION}` - -You will receive a JSON response which includes an `access_token`, `token_type`, and an `expires_in` value that indicates the number of seconds until the access token expires. - -Example JSON response: - -```json -{ - "access_token": "secret_access_token_value", - "token_type": "Bearer", - "expires_in": 600 -} -``` - - -Here's an example of creating a OAuth Token Source for this signing mechanism using Cone: [https://github.com/conductorone/cone/blob/main/pkg/client/token\_source.go](https://github.com/conductorone/cone/blob/main/pkg/client/token_source.go) - - -## Making requests to the API using an access token - -Once you have successfully obtained an access token, you are ready to make authenticated requests to the C1 API. - -Here's how to include the access token in your request: - -Set the `Authorization` HTTP header to `Bearer ${ACCESS_TOKEN}`. - -Example: - -```bash -GET /api/v1/endpoint HTTP/1.1 -Host: acme.conductor.one -Authorization: Bearer ${ACCESS_TOKEN} -``` -Remember to replace `${ACCESS_TOKEN}` with your actual access token. - -Keep in mind that your access token will expire after a period of time (as indicated by the `expires_in` field in the JSON response when you obtained your access token). When this happens, any request you make with the expired access token will be denied. - -To avoid service interruption: - -- Track the `expires_in` time for your access token. -- Generate and implement a new access token before the `expires_in` time has passed. This will ensure continuous access to the C1 API. - +--- +title: How to authenticate requests +description: "To use the C1.ai API, you must authenticate your requests. This document guides you through the process of obtaining and utilizing an API key, as well as establishing an access token." +--- + +These examples use `conductor.one`. If your organization is on the EU data residency instance, substitute `c1eu.ai` in URLs, client IDs, and hostnames. + +## Step 1: Obtain an API key + +The first step in the process is to obtain your API key from C1.ai: + + + +In the C1.ai app, navigate to the User's API Settings page by clicking your username at the bottom of the screen and selecting **AI & API**. + + +In the **API credentials** section of the page, click **Create credential**. + + +Enter a descriptive name for your API key. + + +Set the API key's lifespan. Select from 30 days, 90 days, or never expires. + + +If necessary, limit the source IPs the API key can be used from by entering one or more CIDR blocks in the **Allowed IPs** field. + + +Select the scope of permissions for the API key. You can choose either **Full Permissions** or select specific roles to assign to the API key. + + +Click **Create** to generate the API key. + + + +Your new key is created, and its Client ID and Client Secret are generated and displayed. Take note that the Client Secret is shown to you once, so make sure to securely store this information. + +On the API credentials table, you'll view the name and Client ID of each API key you've created, the key's expiration date (if relevant), the scope granted to the key, and its created on and last used dates. + +### Details about the Client ID and Client Secret + +The Client ID is a stable format that includes a random ID, the base hostname, and the use-case. It is represented in the format: `@/`. For example: `strange-hydra-68836@acme.conductor.one/pcc`. + +The Client Secret follows the format: `secret-token:conductorone.com:${base64url encoded JWK}`. It contains an `ed25519` private key that you may parse to get the private key. For example: + +```bash +secret-token:conductorone.com:v1:eyJrdHkiOiJPS1AiLCJjcnYiOiJFZDI1NTE5IiwieCI6IkMySEx5Y0d6eUhfZDQwcjJvejZoNkpqdndvRVFBZ0FTRVc2eDB6emh6Y2MiLCJkIjoiLTgzVkxXUVUtZVhQY0ZCWVhDb2NpU29XVmhrYnRXUm9zdkZUZ3JqcXNVbyJ9 +``` + +Remember to securely handle and store your Client ID and Client Secret. They play a critical role in the security and integrity of your interaction with our API. + +## Step 2: Determine your API root and token endpoint + +A crucial part of interacting with the C1.ai API involves determining the appropriate endpoints for your requests. Two key components in this process are your API root and the token endpoint. These can be inferred from your Client ID. + +### Extracting the hostname from the Client ID + + +Your Client ID is in the format `@/`. The hostname for your API client can be identified as the portion of your Client ID immediately following the `@` and preceding the `/`. + +For instance, for the Client ID `strange-hydra-68836@acme.conductor.one/pcc`, the hostname is `acme.conductor.one`. + +### Identifying the token endpoint + +With the hostname in hand, the token endpoint can be determined. It resides under the hostname at the path `/auth/v1/token`. So for the example Client ID above, the token endpoint is `https://acme.conductor.one/auth/v1/token`. + +### Identifying the API root + +Similar to the token endpoint, the API root is also located under the hostname. It resides at the path `/api/v1`. In our example Client ID, the API root is `https://acme.conductor.one/api/v1`. + +## Step 3: Get an access token + +There are two methods available for obtaining an access token. Choose the one that best fits your needs. + +### Get a basic access token + +A basic access token can be obtained by utilizing your Client ID and Client Secret with the OAuth2 Token Endpoint. + +To achieve this: + +POST a request to Token Endpoint using the `application/x-www-form-urlencoded` content type. + +Include the following data in your request: + +- `grant_type=client_credentials` +- `client_id=${CLIENT_ID}` +- `client_secret=${CLIENT_SECRET}` + +You will receive a JSON response which includes an an `access_token`, `token_type`, and an `expires_in` value that indicates the number of seconds until the access token expires. + +Example JSON response: + +```json +{ + "access_token": "secret_access_token_value", + "token_type": "Bearer", + "expires_in": 600 +} +``` + +#### Example requests for a basic access token + +The examples below use placeholder values. Replace ``, ``, and `` with values from your own API credential (see Step 1) and the hostname extracted from your Client ID (see Step 2). + + +```bash curl +curl -X POST "https:///auth/v1/token" \ + -H "Content-Type: application/x-www-form-urlencoded" \ + --data-urlencode "grant_type=client_credentials" \ + --data-urlencode "client_id=" \ + --data-urlencode "client_secret=" +``` + +```python Python +import requests + +CLIENT_ID = "" +CLIENT_SECRET = "" +HOSTNAME = "" # for example, "acme.conductor.one" + +response = requests.post( + f"https://{HOSTNAME}/auth/v1/token", + data={ + "grant_type": "client_credentials", + "client_id": CLIENT_ID, + "client_secret": CLIENT_SECRET, + }, + headers={"Content-Type": "application/x-www-form-urlencoded"}, +) +response.raise_for_status() + +access_token = response.json()["access_token"] + +# Use the token in subsequent requests +api_response = requests.get( + f"https://{HOSTNAME}/api/v1/apps", + headers={"Authorization": f"Bearer {access_token}"}, +) +``` + + +### Get an access token using a Signed Client Assertion + +For a more secure authentication process, a JWT can be created and signed using the JWK private key derived from the parsed Client Secret. + +Here are the key requirements for the signed JWT: + +- The issuer (iss) should be set to the `${CLIENT_ID}` value. +- The subject (sub) should be set to the `${CLIENT_ID}` value. +- The audience (aud) should be set to the Tenant's Domain. +- The expiration time (exp) of the JWT must be within five minutes of the current time. Infinitely valid JWTs are not allowed. + +To authenticate using a signed client assertion, you should POST a request to `${TOKEN_ENDPOINT}` using the `application/x-www-form-urlencoded` content type with the following data: + +- `grant_type=client_credentials` +- `client_assertion_type=urn:ietf:params:oauth:client-assertion-type:jwt-bearer` +- `client_id=${CLIENT_ID}` +- `client_assertion=${CLIENT_ASSERTION}` + +You will receive a JSON response which includes an `access_token`, `token_type`, and an `expires_in` value that indicates the number of seconds until the access token expires. + +Example JSON response: + +```json +{ + "access_token": "secret_access_token_value", + "token_type": "Bearer", + "expires_in": 600 +} +``` + + +Here's an example of creating a OAuth Token Source for this signing mechanism using Cone: [https://github.com/conductorone/cone/blob/main/pkg/client/token\_source.go](https://github.com/conductorone/cone/blob/main/pkg/client/token_source.go) + + +## Making requests to the API using an access token + +Once you have successfully obtained an access token, you are ready to make authenticated requests to the C1.ai API. + +Here's how to include the access token in your request: + +Set the `Authorization` HTTP header to `Bearer ${ACCESS_TOKEN}`. + +Example: + +```bash +GET /api/v1/endpoint HTTP/1.1 +Host: acme.conductor.one +Authorization: Bearer ${ACCESS_TOKEN} +``` +Remember to replace `${ACCESS_TOKEN}` with your actual access token. + +Keep in mind that your access token will expire after a period of time (as indicated by the `expires_in` field in the JSON response when you obtained your access token). When this happens, any request you make with the expired access token will be denied. + +To avoid service interruption: + +- Track the `expires_in` time for your access token. +- Generate and implement a new access token before the `expires_in` time has passed. This will ensure continuous access to the C1.ai API. + diff --git a/conductorone-api/pagination.mdx b/conductorone-api/pagination.mdx index 30293f7e..5f5bf94a 100644 --- a/conductorone-api/pagination.mdx +++ b/conductorone-api/pagination.mdx @@ -1,83 +1,83 @@ ---- -title: Pagination in the C1 API -description: "When making `LIST` or `SEARCH` requests to the C1 API, use the `page_size` and `page_token` parameters to navigate through the list of results." ---- - -These examples use `conductor.one`. If your organization is on the EU data residency instance, substitute `c1eu.ai` in URLs, client IDs, and hostnames. - -## Using page\_size - -Include the `page_size` parameter to tell the API how many search or list results to show on each page. - -**`page_size` accepts a number between 10 and 100.** - -- If you enter a number smaller than 10, the system will return 10 results per page. -- If you enter a number larger than 100, the system will return 100 results per page. -- The default value is 25. - -## Using page\_token - -If your query returns more results than will fit on one page of the size you specified with `page_size`, you'll see a unique `nextPageToken` value at the bottom of the response. Include this value with the `page_token` parameter in your next request to see the next page of results. - -You do not need to include `page_token` in your initial request (or you can include it but leave it empty), but you must do so for each subsequent request. - -Here's a simplified example of using `page_token` to navigate a list of results: - -```bash First request - -curl --request GET \ - --url 'https://example.conductor.one/api/v1/apps/sample/entitlements?page_size=50' -``` - -```json First response -{ - "list": [ - { - "appEntitlement": { - // List of 50 app entitlements with their details. - } - ], - "nextPageToken": "samplepaggetoken1" -} -``` - - -```bash Second request - -curl --request GET \ - --url 'https://example.conductor.one/api/v1/apps/sample/entitlements?page_size=50&page_token=samplepagetoken1' -``` - - -**Note:** For this `GET` example, the `page_size` and `page_token` are included in the query. For `POST` requests, `page_size` and `page_token` are included in the body instead. - - -```json Second response -"list": [ - { - "appEntitlement": { - // List of 50 more app entitlements with their details. - } - ], - "nextPageToken": "samplepaggetoken2" -} -``` -```bash Third request - -curl --request GET \ - --url 'https://example.conductor.one/api/v1/apps/sample/entitlements?page_size=50&page_token=samplepagetoken2' -``` -```json Third response -{ - "list": [ - { - "appEntitlement": { - // List of 26 more app entitlements with their details. - } - ], - "nextPageToken": "" - // An empty nextPageToken is printed in the third response because the user has reached the end of the list of results. -} -``` - - +--- +title: Pagination in the C1.ai API +description: "When making `LIST` or `SEARCH` requests to the C1.ai API, use the `page_size` and `page_token` parameters to navigate through the list of results." +--- + +These examples use `conductor.one`. If your organization is on the EU data residency instance, substitute `c1eu.ai` in URLs, client IDs, and hostnames. + +## Using page\_size + +Include the `page_size` parameter to tell the API how many search or list results to show on each page. + +**`page_size` accepts a number between 10 and 100.** + +- If you enter a number smaller than 10, the system will return 10 results per page. +- If you enter a number larger than 100, the system will return 100 results per page. +- The default value is 25. + +## Using page\_token + +If your query returns more results than will fit on one page of the size you specified with `page_size`, you'll see a unique `nextPageToken` value at the bottom of the response. Include this value with the `page_token` parameter in your next request to see the next page of results. + +You do not need to include `page_token` in your initial request (or you can include it but leave it empty), but you must do so for each subsequent request. + +Here's a simplified example of using `page_token` to navigate a list of results: + +```bash First request + +curl --request GET \ + --url 'https://example.conductor.one/api/v1/apps/sample/entitlements?page_size=50' +``` + +```json First response +{ + "list": [ + { + "appEntitlement": { + // List of 50 app entitlements with their details. + } + ], + "nextPageToken": "samplepaggetoken1" +} +``` + + +```bash Second request + +curl --request GET \ + --url 'https://example.conductor.one/api/v1/apps/sample/entitlements?page_size=50&page_token=samplepagetoken1' +``` + + +**Note:** For this `GET` example, the `page_size` and `page_token` are included in the query. For `POST` requests, `page_size` and `page_token` are included in the body instead. + + +```json Second response +"list": [ + { + "appEntitlement": { + // List of 50 more app entitlements with their details. + } + ], + "nextPageToken": "samplepaggetoken2" +} +``` +```bash Third request + +curl --request GET \ + --url 'https://example.conductor.one/api/v1/apps/sample/entitlements?page_size=50&page_token=samplepagetoken2' +``` +```json Third response +{ + "list": [ + { + "appEntitlement": { + // List of 26 more app entitlements with their details. + } + ], + "nextPageToken": "" + // An empty nextPageToken is printed in the third response because the user has reached the end of the list of results. +} +``` + + diff --git a/connector-template.mdx b/connector-template.mdx index a93c2a6c..38e2a24b 100644 --- a/connector-template.mdx +++ b/connector-template.mdx @@ -1,8 +1,8 @@ --- title: "Set up a [Connector Name] connector" og:title: "Set up a [Connector Name] connector" -description: "C1 provides identity governance and just-in-time provisioning for [App Name]. Integrate your [App Name] instance with C1 to run user access reviews (UARs), enable just-in-time access requests, and automatically provision and deprovision access." -og:description: "C1 provides identity governance and just-in-time provisioning for [App Name]. Integrate your [App Name] instance with C1 to run user access reviews (UARs), enable just-in-time access requests, and automatically provision and deprovision access." +description: "C1.ai provides identity governance and just-in-time provisioning for [App Name]. Integrate your [App Name] instance with C1.ai to run user access reviews (UARs), enable just-in-time access requests, and automatically provision and deprovision access." +og:description: "C1.ai provides identity governance and just-in-time provisioning for [App Name]. Integrate your [App Name] instance with C1.ai to run user access reviews (UARs), enable just-in-time access requests, and automatically provision and deprovision access." sidebarTitle: "[Connector Name]" --- @@ -66,7 +66,7 @@ To configure the [App Name] connector, you need [specific permission level] perm - `scope:name` - [Brief description] - The **scope:name** scope is used by C1 when automatically provisioning and deprovisioning access. **If you do not want C1 to perform these tasks, do not give your token this scope.** + The **scope:name** scope is used by C1.ai when automatically provisioning and deprovisioning access. **If you do not want C1.ai to perform these tasks, do not give your token this scope.** 5. Click **[Generate/Create]** @@ -86,11 +86,11 @@ To configure the [App Name] connector, you need [specific permission level] perm - Follow these instructions to use a built-in, no-code connector hosted by C1. + Follow these instructions to use a built-in, no-code connector hosted by C1.ai. - 1. In C1, navigate to **Apps** > **Connectors** and click **Add connector**. + 1. In C1.ai, navigate to **Apps** > **Connectors** and click **Add connector**. 2. Search for **[Connector Name]** and click **Add**. @@ -123,7 +123,7 @@ To configure the [App Name] connector, you need [specific permission level] perm - Click **Save**. C1 will begin syncing data from [App Name]. + Click **Save**. C1.ai will begin syncing data from [App Name]. To verify the sync is working: 1. Navigate to **Apps** > **Connectors**. @@ -132,7 +132,7 @@ To configure the [App Name] connector, you need [specific permission level] perm - **Done.** Your [App Name] connector is now pulling access data into C1. + **Done.** Your [App Name] connector is now pulling access data into C1.ai. @@ -140,9 +140,9 @@ To configure the [App Name] connector, you need [specific permission level] perm - 1. In C1, navigate to **Apps** > **Connectors** and click **Add connector**. + 1. In C1.ai, navigate to **Apps** > **Connectors** and click **Add connector**. 2. Search for **[Connector Name]** and click **Add**. - 3. Choose how you want to set up your [App Name] app in C1 (see cloud-hosted instructions above for details). + 3. Choose how you want to set up your [App Name] app in C1.ai (see cloud-hosted instructions above for details). 4. Set the app owner. 5. Click **Save**. 6. Make note of the **Client ID** and **Client Secret** that are displayed. You'll need these values in the next step. @@ -242,7 +242,7 @@ To configure the [App Name] connector, you need [specific permission level] perm - **Done.** Your [App Name] connector is now pulling access data into C1. + **Done.** Your [App Name] connector is now pulling access data into C1.ai. diff --git a/developer/baton-sdk.mdx b/developer/baton-sdk.mdx index 9e958a89..5ad944a2 100644 --- a/developer/baton-sdk.mdx +++ b/developer/baton-sdk.mdx @@ -218,7 +218,7 @@ type CredentialManager interface { } ``` -Returns plaintext credentials; the SDK encrypts them before sending to C1. +Returns plaintext credentials; the SDK encrypts them before sending to C1.ai. Enables `CAPABILITY_CREDENTIAL_ROTATION`. diff --git a/developer/build-connector.mdx b/developer/build-connector.mdx index 3ab8cfd4..e1a8ea97 100644 --- a/developer/build-connector.mdx +++ b/developer/build-connector.mdx @@ -1,12 +1,12 @@ --- title: Build a new Baton connector -og:title: Build a new Baton connector - C1 -og:description: If you need to connect C1 to a homegrown or backoffice piece of infrastructure, you can build your own connector with the Baton software development kit (SDK). +og:title: Build a new Baton connector - C1.ai +og:description: If you need to connect C1.ai to a homegrown or backoffice piece of infrastructure, you can build your own connector with the Baton software development kit (SDK). description: Use the Baton software development kit to build your own connector if a pre-built cloud connector isn't available. sidebarTitle: "Build a new connector" --- -If you need to connect C1 to a homegrown or backoffice piece of infrastructure, or to software that doesn't yet have a [pre-built connector](https://github.com/conductorone), you can build your own connector with the Baton software development kit (SDK). Once built, these connectors can be integrated directly with C1. +If you need to connect C1.ai to a homegrown or backoffice piece of infrastructure, or to software that doesn't yet have a [pre-built connector](https://github.com/conductorone), you can build your own connector with the Baton software development kit (SDK). Once built, these connectors can be integrated directly with C1.ai. Check out our tutorial video to learn how to build your own Baton connector: diff --git a/developer/c1-api.mdx b/developer/c1-api.mdx index a5acd77e..a8c19d24 100644 --- a/developer/c1-api.mdx +++ b/developer/c1-api.mdx @@ -1,12 +1,12 @@ --- -title: "C1 API integration reference" -sidebarTitle: "C1 API" -description: "How connectors communicate with the C1 platform in daemon mode." +title: "C1.ai API integration reference" +sidebarTitle: "C1.ai API" +description: "How connectors communicate with the C1.ai platform in daemon mode." --- -When running in daemon mode, connectors communicate with C1 via gRPC. The SDK handles all API communication - connector developers implement interfaces, the SDK calls your code when tasks arrive. +When running in daemon mode, connectors communicate with C1.ai via gRPC. The SDK handles all API communication - connector developers implement interfaces, the SDK calls your code when tasks arrive. -This document describes the C1 APIs that connectors use internally. You don't call these APIs directly; the SDK manages them. +This document describes the C1.ai APIs that connectors use internally. You don't call these APIs directly; the SDK manages them. ## Communication architecture @@ -78,7 +78,7 @@ type SyncTask struct { } ``` -**Connector produces:** c1z file uploaded to C1 +**Connector produces:** c1z file uploaded to C1.ai ### Grant task @@ -112,7 +112,7 @@ type CreateAccountTask struct { } ``` -**Returns to C1:** Created account, credentials (encrypted by SDK) +**Returns to C1.ai:** Created account, credentials (encrypted by SDK) ### DeleteResource task @@ -132,7 +132,7 @@ type RotateCredentialTask struct { } ``` -**Returns to C1:** New credentials (encrypted by SDK) +**Returns to C1.ai:** New credentials (encrypted by SDK) ## Task lifecycle @@ -169,7 +169,7 @@ var ( ) ``` -C1 can adjust heartbeat interval per-task. If heartbeats stop, the task may be reassigned to another connector instance. +C1.ai can adjust heartbeat interval per-task. If heartbeats stop, the task may be reassigned to another connector instance. ### Task completion @@ -233,13 +233,13 @@ Connectors authenticate using OAuth2 client credentials: ``` The SDK handles: -- Token acquisition from C1's OAuth endpoint +- Token acquisition from C1.ai's OAuth endpoint - Token refresh before expiration - Token injection into request metadata ### Host identification -Connectors identify themselves to C1: +Connectors identify themselves to C1.ai: ```go hostId := os.Getenv("BATON_HOST_ID") @@ -248,7 +248,7 @@ if hostId == "" { } ``` -This helps C1 track which host is running which connector instance. +This helps C1.ai track which host is running which connector instance. ## Error handling @@ -266,12 +266,12 @@ taskMaximumHeartbeatFailures = 10 ### Error flow -| Connector Error | SDK Handling | C1 Action | +| Connector Error | SDK Handling | C1.ai Action | |-----------------|--------------|---------------------| | Temporary failure | Retry with backoff | Task stays queued | | Permanent failure | FinishTask(FAILED) | Task marked failed | | Heartbeat timeout | Task abandoned | Reassign to other instance | -| Cancelled by C1 | Stop processing | Task cancelled | +| Cancelled by C1.ai | Stop processing | Task cancelled | ### Annotations for error context @@ -318,7 +318,7 @@ Debug output includes: |---------|--------------|----------| | `authentication error` | Invalid client credentials | Verify client-id/secret | | `task heartbeat failed` | Processing too slow | Optimize or add heartbeats | -| `connection refused` | Network/firewall issue | Check connectivity to C1 | +| `connection refused` | Network/firewall issue | Check connectivity to C1.ai | | `task cancelled` | Task timeout or user cancel | Check task duration | | `upload failed` | Large c1z or network issue | Check file size, retry | diff --git a/developer/community.mdx b/developer/community.mdx index b85337c2..98684826 100644 --- a/developer/community.mdx +++ b/developer/community.mdx @@ -41,7 +41,7 @@ Include: |---------|--------------|---------| | GitHub Issues | Days | Bugs, connector feature requests | | GitHub Discussions | Days | Questions, how-to help | -| C1 Support | Hours | Production issues (customers), product feature requests | +| C1.ai Support | Hours | Production issues (customers), product feature requests | ## Reporting issues @@ -157,12 +157,12 @@ All complaints will be reviewed and investigated promptly and fairly. ### Decision making -The Baton ecosystem is maintained by C1 with community input. +The Baton ecosystem is maintained by C1.ai with community input. | Decision type | Who decides | |--------------|-------------| -| SDK changes | C1 team | -| New connectors (C1 org) | C1 team | +| SDK changes | C1.ai team | +| New connectors (C1.ai org) | C1.ai team | | New connectors (your org) | You | | Feature requests | Maintainers of affected repo | diff --git a/developer/concepts.mdx b/developer/concepts.mdx index f92c2e12..5f4e716c 100644 --- a/developer/concepts.mdx +++ b/developer/concepts.mdx @@ -6,13 +6,13 @@ description: "Build a correct mental model of the resource/entitlement/grant gra Every target system has its own vocabulary (teams vs groups, roles vs permission sets, projects vs workspaces). This diversity is a strength - each system evolved for its specific purpose. But it creates a challenge: how do you get unified visibility across all of them? -Baton solves this by normalizing every system into a consistent shape so C1 can ask one question across all systems: who has access to what? Without this normalization, each system would be an island - auditors would see chaos, and access reviews would require expert knowledge of every platform. +Baton solves this by normalizing every system into a consistent shape so C1.ai can ask one question across all systems: who has access to what? Without this normalization, each system would be an island - auditors would see chaos, and access reviews would require expert knowledge of every platform. The minimal "connector surface area" is expressed through the SDK's `ResourceSyncer` interface: list resources, list entitlements, list grants. ## The access graph -Your connector produces an access graph that powers access reviews, certification campaigns, provisioning workflows, and compliance reporting. This single data structure drives everything C1 does. The graph has three main node/edge types: +Your connector produces an access graph that powers access reviews, certification campaigns, provisioning workflows, and compliance reporting. This single data structure drives everything C1.ai does. The graph has three main node/edge types: ```mermaid flowchart LR @@ -41,7 +41,7 @@ This is not a theoretical model: these are concrete protobuf types and services Most access management systems flatten everything into a single list. Baton takes a different approach: resources can have parent-child relationships. This preserves the natural structure of your target systems. -Consider GitHub: organizations contain repositories, repositories have branches. Or AWS: accounts contain services, services have resources. When your connector models these hierarchies, C1 can: +Consider GitHub: organizations contain repositories, repositories have branches. Or AWS: accounts contain services, services have resources. When your connector models these hierarchies, C1.ai can: - Show access in context (this role applies to *this* project, not globally) - Enable scoped access reviews (review all access within a single org unit) @@ -51,7 +51,7 @@ You express hierarchy through the `parentResourceID` parameter in your `List()` ## Resource types and traits -Every resource has a **resource type** (string id) and can declare **traits** that tell C1 how to interpret it. Traits let C1 understand *what kind of thing* a resource is, even when different systems call it different names. +Every resource has a **resource type** (string id) and can declare **traits** that tell C1.ai how to interpret it. Traits let C1.ai understand *what kind of thing* a resource is, even when different systems call it different names. ```go var userResourceType = &v2.ResourceType{ @@ -69,7 +69,7 @@ The trait enum includes: - `TRAIT_SECRET` - `TRAIT_ROLE_SCOPE` -Traits are optional for custom resource types, but they unlock powerful features. When you mark a resource with `TRAIT_USER`, C1 knows it can correlate that resource with users from other systems, display it in user-centric views, and apply user-specific policies. +Traits are optional for custom resource types, but they unlock powerful features. When you mark a resource with `TRAIT_USER`, C1.ai knows it can correlate that resource with users from other systems, display it in user-centric views, and apply user-specific policies. | Trait | Use for | |-------|---------| @@ -97,7 +97,7 @@ One resource can offer multiple entitlements. A GitHub repository might offer: r #### Entitlement purpose -Entitlements have a `purpose` field that tells C1 how to interpret them: +Entitlements have a `purpose` field that tells C1.ai how to interpret them: | Purpose | Use For | Example | |---------|---------|---------| @@ -154,7 +154,7 @@ Stage 4: Grants() ### The sync pipeline -When a connector runs, data flows through several stages. The clean separation between what you control and what C1 controls makes the system reliable and testable: +When a connector runs, data flows through several stages. The clean separation between what you control and what C1.ai controls makes the system reliable and testable: ```mermaid flowchart LR @@ -168,16 +168,16 @@ flowchart LR 1. **Fetch** - Your connector calls the external API 2. **Transform** - Your connector creates Resource/Entitlement/Grant objects 3. **Output** - SDK writes objects to a .c1z file (gzip-compressed SQLite) -4. **Ingest** - C1's sync service reads the .c1z file +4. **Ingest** - C1.ai's sync service reads the .c1z file 5. **Uplift** - Raw connector records become domain objects (Apps, Resources, Grants) **What you control:** Steps 1-3. Your connector fetches, transforms, and outputs. -**What C1 controls:** Steps 4-5. The sync service and uplift process. +**What C1.ai controls:** Steps 4-5. The sync service and uplift process. ### ID correlation -C1 needs to know whether a resource in this sync is the same resource from a previous sync. This is where the `RawId` annotation matters. +C1.ai needs to know whether a resource in this sync is the same resource from a previous sync. This is where the `RawId` annotation matters. When you build a resource, include its external system ID: @@ -197,7 +197,7 @@ The `RawId` annotation carries the external system's identifier through the pipe - **Sync storage**: Stored as `external_id` on the connector record - **Domain objects**: Tracked in `source_connector_ids` map -This enables C1 to: +This enables C1.ai to: - Correlate resources across syncs (same ID = same resource) - Track which connector discovered which resource - Support pre-sync reservation patterns @@ -206,7 +206,7 @@ This enables C1 to: ### ID vocabulary -These terms appear throughout C1 when discussing identity correlation: +These terms appear throughout C1.ai when discussing identity correlation: | Term | Where it appears | Purpose | |------|-----------------|---------| @@ -220,7 +220,7 @@ The flow is: `RawId` (connector) -> `external_id` (sync) -> `source_connector_id ## Modeling decisions -Your modeling choices expand or constrain what your organization can do with access control. Two connectors can both be "correct" and still produce very different experiences in C1: +Your modeling choices expand or constrain what your organization can do with access control. Two connectors can both be "correct" and still produce very different experiences in C1.ai: - **Entitlement granularity** - Fine-grained (read/write/admin): more precision in reviews and provisioning, more total grants and API calls. @@ -261,7 +261,7 @@ Connectors can run in different modes: | Mode | Trigger | Behavior | |------|---------|----------| | **One-shot** | No `--client-id` | Run, sync to file, exit | -| **Daemon** | `--client-id` provided | Connect to C1, process tasks continuously | +| **Daemon** | `--client-id` provided | Connect to C1.ai, process tasks continuously | See [Deployment](/baton/deploy) for operational details on each mode. diff --git a/developer/config-schema.mdx b/developer/config-schema.mdx index ff9ff097..580741b7 100644 --- a/developer/config-schema.mdx +++ b/developer/config-schema.mdx @@ -27,8 +27,8 @@ Every connector automatically has these flags via the SDK. | Flag | Type | Description | |------|------|-------------| -| `--client-id` | string | C1 OAuth client ID (enables daemon mode) | -| `--client-secret` | string | C1 OAuth client secret | +| `--client-id` | string | C1.ai OAuth client ID (enables daemon mode) | +| `--client-secret` | string | C1.ai OAuth client secret | | `--skip-full-sync` | bool | Disable full sync in daemon mode | ### Provisioning operations diff --git a/developer/debugging.mdx b/developer/debugging.mdx index 90562d28..4db81ecb 100644 --- a/developer/debugging.mdx +++ b/developer/debugging.mdx @@ -228,7 +228,7 @@ details, _ := client.GetUsersWithDetails(ctx, userIDs) **Symptoms:** Daemon runs but never processes anything Check: -- Connector registered in C1 admin UI +- Connector registered in C1.ai admin UI - Sync scheduled - Correct connector ID @@ -263,7 +263,7 @@ Verify capabilities: ### Symptom -After running a sync, you see duplicate resources in C1: one created via Terraform/API and a separate one discovered by the connector. +After running a sync, you see duplicate resources in C1.ai: one created via Terraform/API and a separate one discovered by the connector. ### Causes diff --git a/developer/glossary.mdx b/developer/glossary.mdx index 9521d914..cb5f45d9 100644 --- a/developer/glossary.mdx +++ b/developer/glossary.mdx @@ -12,11 +12,11 @@ When in doubt about terminology, check here first. |------|------------| | **Baton** | The connector framework: Go SDK + individual connectors | | **baton-sdk** | Go library that handles sync orchestration, pagination, and connector runtime | -| **Connector** | A Go binary that syncs access control data from a third-party service into C1 | +| **Connector** | A Go binary that syncs access control data from a third-party service into C1.ai | | **c1z** | Compressed sync output file format (gzip SQLite) | -| **c1in** | C1 Integration Network - the overall connector ecosystem | -| **cone** | C1 CLI for access management | -| **conductorone-sdk-go** | Go SDK for C1 API integration | +| **c1in** | C1.ai Integration Network - the overall connector ecosystem | +| **cone** | C1.ai CLI for access management | +| **conductorone-sdk-go** | Go SDK for C1.ai API integration | | **Connector Hub** | User-facing name for the connector marketplace | | **Meta-connector** | Configuration-driven connector that maps external systems via YAML instead of Go code | | **baton-http** | Meta-connector for REST APIs using YAML configuration and CEL expressions | @@ -58,11 +58,11 @@ When in doubt about terminology, check here first. | Term | Definition | |------|------------| | **One-shot mode** | CLI mode: runs once, produces c1z file, exits (no --client-id) | -| **Daemon mode** | Long-running mode that polls C1 for tasks (requires --client-id and --client-secret) | -| **Hosted mode** | Connector run by C1 infrastructure on behalf of customers | +| **Daemon mode** | Long-running mode that polls C1.ai for tasks (requires --client-id and --client-secret) | +| **Hosted mode** | Connector run by C1.ai infrastructure on behalf of customers | | **Service mode** | Synonym for daemon mode | -| **Client credentials** | OAuth2 client ID and secret for authenticating connector to C1 | -| **Task polling** | Daemon mode behavior of periodically checking C1 for work | +| **Client credentials** | OAuth2 client ID and secret for authenticating connector to C1.ai | +| **Task polling** | Daemon mode behavior of periodically checking C1.ai for work | ## Provisioning operations @@ -81,13 +81,13 @@ When in doubt about terminology, check here first. | Term | Definition | |------|------------| -| **Sync** | Reading access data from a system into C1; produces .c1z file | -| **Uplift** | C1 process that transforms raw connector records into domain objects (Apps, Resources, Grants) | +| **Sync** | Reading access data from a system into C1.ai; produces .c1z file | +| **Uplift** | C1.ai process that transforms raw connector records into domain objects (Apps, Resources, Grants) | | **Provision** | Writing access changes back to a system (grant, revoke, create, delete) | | **Reconciliation** | Comparing actual access (from sync) to desired access (from policy) and correcting drift | | **external_id** | The identifier from an external system, stored with connector records during sync | | **source_connector_ids** | Map on domain objects tracking which connector provided which external ID | -| **ID Correlation** | Matching connector output to existing C1 objects using RawId and external_id | +| **ID Correlation** | Matching connector output to existing C1.ai objects using RawId and external_id | | **JIT Provisioning** | Just-In-Time provisioning - creating user account when first needed, not before | | **IdP** | Identity Provider - authoritative source of user identities (Okta, Azure AD, Google Workspace) | | **Source of Truth** | The system that authoritatively defines an entity (IdPs are typically source of truth for users) | diff --git a/developer/http-authoring.mdx b/developer/http-authoring.mdx index f0bb562f..a79338ba 100644 --- a/developer/http-authoring.mdx +++ b/developer/http-authoring.mdx @@ -4,7 +4,7 @@ sidebarTitle: "HTTP authoring" description: "Integrate any REST API without writing Go code. Configuration only." --- -Baton-HTTP is a configuration-driven connector that lets you write YAML instead of Go code. Instead of implementing the `ResourceSyncer` interface, you describe how to map an API to C1's resource model. Your ops team can own integrations directly — no engineering queue. +Baton-HTTP is a configuration-driven connector that lets you write YAML instead of Go code. Instead of implementing the `ResourceSyncer` interface, you describe how to map an API to C1.ai's resource model. Your ops team can own integrations directly — no engineering queue. ## Resources @@ -30,8 +30,8 @@ Baton-HTTP is a configuration-driven connector that lets you write YAML instead | `--config-path` | **(Required)** Path to the YAML configuration file | | `--validate-config-only` | Validate the configuration file and exit without running | | `--enable-command-actions` | Enable command actions (shell script execution) | -| `--client-id` | C1 client ID for service mode | -| `--client-secret` | C1 client secret for service mode | +| `--client-id` | C1.ai client ID for service mode | +| `--client-secret` | C1.ai client secret for service mode | Authentication credentials for the target API are configured in the YAML file using environment variable interpolation (e.g., `${API_TOKEN}`), not via command-line flags. @@ -183,7 +183,7 @@ auth: ## Resource type configuration -Resource types define the entities you want to sync. Each resource type specifies how to list resources and map API responses to C1 resources. +Resource types define the entities you want to sync. Each resource type specifies how to list resources and map API responses to C1.ai resources. ### Basic structure @@ -429,10 +429,10 @@ grants: ## Provisioning -Enable provisioning to grant and revoke access through C1. +Enable provisioning to grant and revoke access through C1.ai. -baton-http supports **access provisioning** (granting and revoking entitlements on existing accounts) through the `provisioning.grant` and `provisioning.revoke` request blocks below. It does not support **account provisioning** — creating new user accounts in the target system, or JIT-creating accounts when a grant fires. Account provisioning requires implementing the `AccountManager` interface in a custom Go connector built with the [Baton SDK](/developer/baton-sdk). Once such a connector exists, you can configure it in C1 following [Configure account provisioning](/product/admin/account-provisioning). +baton-http supports **access provisioning** (granting and revoking entitlements on existing accounts) through the `provisioning.grant` and `provisioning.revoke` request blocks below. It does not support **account provisioning** — creating new user accounts in the target system, or JIT-creating accounts when a grant fires. Account provisioning requires implementing the `AccountManager` interface in a custom Go connector built with the [Baton SDK](/developer/baton-sdk). Once such a connector exists, you can configure it in C1.ai following [Configure account provisioning](/product/admin/account-provisioning). ### Grant and revoke @@ -539,11 +539,11 @@ baton-http --config-path ./config.yaml \ ## Deploying to Kubernetes -### Step 1: Set up a new connector in C1 +### Step 1: Set up a new connector in C1.ai -In C1, navigate to **Connectors** > **Add connector**. +In C1.ai, navigate to **Connectors** > **Add connector**. Search for **Baton** and click **Add**. @@ -656,7 +656,7 @@ spec: ### Step 3: Deploy -Apply the configuration files to your Kubernetes cluster and verify the connector appears in C1 under **Applications** > **Managed apps**. +Apply the configuration files to your Kubernetes cluster and verify the connector appears in C1.ai under **Applications** > **Managed apps**. ## Example: GitHub integration diff --git a/developer/intro.mdx b/developer/intro.mdx index 32fa3ca4..d08fa339 100644 --- a/developer/intro.mdx +++ b/developer/intro.mdx @@ -8,9 +8,9 @@ What happens when an employee leaves your company but still has access to your p A **connector** answers the question: *who has access to what?* -C1 needs to know about users, groups, roles, and permissions across all your systems. But every system stores this information differently. Okta has users and groups. AWS has IAM roles and policies. Salesforce has profiles and permission sets. The Baton connector framework solves this: you write one integration, and C1 handles the rest. +C1.ai needs to know about users, groups, roles, and permissions across all your systems. But every system stores this information differently. Okta has users and groups. AWS has IAM roles and policies. Salesforce has profiles and permission sets. The Baton connector framework solves this: you write one integration, and C1.ai handles the rest. -A connector bridges this gap. It translates access data from any system into a common format that C1 understands. Once connected, you get unified visibility across your entire infrastructure. +A connector bridges this gap. It translates access data from any system into a common format that C1.ai understands. Once connected, you get unified visibility across your entire infrastructure. In Baton terms, a connector is a program that can: - **List resources** (users, groups, roles, apps, projects, etc.) @@ -48,7 +48,7 @@ Most people interact with connectors in two ways: Connectors do two things: -**Sync** (read): Pull access data from your systems into C1 +**Sync** (read): Pull access data from your systems into C1.ai - Who exists? What groups? What roles? - What permissions are available? - Who has what access right now? @@ -59,7 +59,7 @@ Connectors do two things: - **Create Account**: JIT (Just-In-Time) provisioning - **Delete Resource**: Remove accounts entirely -Together, sync and provision create a **reconciliation loop**: C1 sees what access exists (sync), compares it to what access *should* exist (policy), and corrects any drift (provision). Your access controls become self-healing. +Together, sync and provision create a **reconciliation loop**: C1.ai sees what access exists (sync), compares it to what access *should* exist (policy), and corrects any drift (provision). Your access controls become self-healing. ### The special role of identity providers @@ -74,7 +74,7 @@ When you connect an IdP, you're establishing the identity foundation that other ## Understanding the tools -Before diving into implementation, it helps to understand which tools do what. The C1 ecosystem has several SDKs and CLIs with different purposes. +Before diving into implementation, it helps to understand which tools do what. The C1.ai ecosystem has several SDKs and CLIs with different purposes. ### For connector developers @@ -101,14 +101,14 @@ baton grants -f sync.c1z # List grants baton entitlements -f sync.c1z # List entitlements ``` -### For C1 users (not connector development) +### For C1.ai users (not connector development) | Tool | Purpose | When to use | |------|---------|-------------| -| **cone** | CLI for C1 platform | Access requests, approvals, searches | -| **conductorone-sdk-go** | Go SDK for C1 API | Integrating with C1 platform | +| **cone** | CLI for C1.ai platform | Access requests, approvals, searches | +| **conductorone-sdk-go** | Go SDK for C1.ai API | Integrating with C1.ai platform | -**cone** is the C1 CLI for end-users and administrators. It handles access management workflows: +**cone** is the C1.ai CLI for end-users and administrators. It handles access management workflows: ```bash cone login # Authenticate to C1 @@ -123,7 +123,7 @@ cone task approve # Approve access requests | Build a new connector | `baton-sdk` | | Debug my connector's output | `baton` CLI | | Request or approve access | `cone` CLI | -| Build an app that uses C1 | `conductorone-sdk-go` | +| Build an app that uses C1.ai | `conductorone-sdk-go` | | Deploy a pre-built connector | The connector binary | @@ -136,8 +136,8 @@ When you build a connector, you produce a standalone binary (e.g., `baton-okta`, - **Embeds the SDK** - It's compiled with `baton-sdk`, not dependent on it at runtime - **Is self-contained** - No runtime dependencies except the target system's API -- **Runs independently** - You don't need any other C1 tools installed -- **Produces standard output** - A `.c1z` file that any C1 environment can consume +- **Runs independently** - You don't need any other C1.ai tools installed +- **Produces standard output** - A `.c1z` file that any C1.ai environment can consume ```bash # The connector IS the binary diff --git a/developer/postman.mdx b/developer/postman.mdx index 8f8a31e2..9ebd30c3 100644 --- a/developer/postman.mdx +++ b/developer/postman.mdx @@ -1,13 +1,13 @@ --- -title: C1's Postman instance -og:title: C1's Postman instance - C1 -og:description: Use Postman to send requests to the C1 API, inspect responses, and automate testing. -description: Use Postman to send requests to the C1 API, inspect responses, and automate testing. +title: C1.ai's Postman instance +og:title: C1.ai's Postman instance - C1.ai +og:description: Use Postman to send requests to the C1.ai API, inspect responses, and automate testing. +description: Use Postman to send requests to the C1.ai API, inspect responses, and automate testing. sidebarTitle: "Postman" --- Postman is an API development and testing platform that allows you to send requests to APIs, inspect the responses, and save requests for future use. Its ease of use makes it a popular tool among developers and testers for testing the functionality, performance, and security of APIs. -Visit [C1's Postman SDK on GitHub](https://github.com/conductorone/conductorone-sdk-postman) to get started using the C1 API in Postman. +Visit [C1.ai's Postman SDK on GitHub](https://github.com/conductorone/conductorone-sdk-postman) to get started using the C1.ai API in Postman. diff --git a/developer/provisioning.mdx b/developer/provisioning.mdx index 4444faa0..97cd8626 100644 --- a/developer/provisioning.mdx +++ b/developer/provisioning.mdx @@ -4,7 +4,7 @@ sidebarTitle: "Provisioning" description: "Grant and revoke access programmatically. Create accounts. Delete resources. This is where your connector becomes actionable." --- -Sync tells C1 what access exists. Provisioning lets C1 *change* access. +Sync tells C1.ai what access exists. Provisioning lets C1.ai *change* access. | Operation | What it does | |-----------|--------------| diff --git a/developer/recipes-id.mdx b/developer/recipes-id.mdx index fde22b20..e96843fc 100644 --- a/developer/recipes-id.mdx +++ b/developer/recipes-id.mdx @@ -22,7 +22,7 @@ Each recipe includes the problem, solution code, and rationale. | **Salesforce** | Salesforce ID | 18-char ID | `00e3h000000bRQAAA2` | | **Google Workspace** | Google Group ID | Variable | `00gjdgxs3x1h123` | -**Why this matters:** C1 uses these IDs to correlate resources across syncs. Using the wrong ID causes duplicate objects or failed correlations. +**Why this matters:** C1.ai uses these IDs to correlate resources across syncs. Using the wrong ID causes duplicate objects or failed correlations. **Key points:** - Azure AD has two IDs: Object ID (use this) and Application ID (client ID for OAuth) @@ -31,9 +31,9 @@ Each recipe includes the problem, solution code, and rationale. ## Setting RawId annotation -**Problem:** Ensure C1 can correlate your resources across syncs and match resources created via Terraform. +**Problem:** Ensure C1.ai can correlate your resources across syncs and match resources created via Terraform. -**What is RawId?** A string annotation containing the external system's native identifier. C1 uses this to match resources across syncs and to merge Terraform-created objects with connector-discovered ones. +**What is RawId?** A string annotation containing the external system's native identifier. C1.ai uses this to match resources across syncs and to merge Terraform-created objects with connector-discovered ones. **Solution:** Add the `RawId` annotation when building resources: diff --git a/developer/sdk.mdx b/developer/sdk.mdx index 0f498cfd..8fbe91a7 100644 --- a/developer/sdk.mdx +++ b/developer/sdk.mdx @@ -1,23 +1,23 @@ --- -title: Using C1's SDKs -og:title: Using C1's SDKs - C1 -sidebarTitle: "C1 SDKs" +title: Using C1.ai's SDKs +og:title: Using C1.ai's SDKs - C1.ai +sidebarTitle: "C1.ai SDKs" --- A software development kit (SDK) is a collection of tools, libraries, and documentation that helps developers create software. SDKs save developers time and effort by providing pre-written code that can be used to build applications and integrations. -C1 offers SDKs to help developers work efficiently with our API. Get started with the SDK in the language of your choice by following the directions below. +C1.ai offers SDKs to help developers work efficiently with our API. Get started with the SDK in the language of your choice by following the directions below. -Are you eager for a C1 SDK in a different language? [Let us know!](mailto:support@c1.ai) +Are you eager for a C1.ai SDK in a different language? [Let us know!](mailto:support@c1.ai) ## Go SDK -Access the [C1 Go SDK](https://github.com/conductorone/conductorone-sdk-go) on GitHub, where you'll find installation instructions, example usage, and a full list of available resources and operations. +Access the [C1.ai Go SDK](https://github.com/conductorone/conductorone-sdk-go) on GitHub, where you'll find installation instructions, example usage, and a full list of available resources and operations. ## Typescript SDK -Access the [C1 Typescript SDK](https://github.com/conductorone/conductorone-sdk-typescript) on GitHub, where you'll find installation instructions, example usage, and a full list of available resources and operations. +Access the [C1.ai Typescript SDK](https://github.com/conductorone/conductorone-sdk-typescript) on GitHub, where you'll find installation instructions, example usage, and a full list of available resources and operations. diff --git a/developer/submit.mdx b/developer/submit.mdx index 441db54b..2c0d486e 100644 --- a/developer/submit.mdx +++ b/developer/submit.mdx @@ -4,10 +4,10 @@ sidebarTitle: "Publishing" description: "Share your connector with the community. Make access management better for everyone." --- -You've built a connector that works. Publishing makes it available to everyone using C1: +You've built a connector that works. Publishing makes it available to everyone using C1.ai: - Other organizations can deploy it - It appears in the Connector Hub -- It becomes eligible for hosted mode (C1 runs it for customers) +- It becomes eligible for hosted mode (C1.ai runs it for customers) - The community can contribute improvements ## Publishing flow @@ -65,8 +65,8 @@ Before building a new connector, check if one already exists. If it does but lac ### New connectors -**Option A: Open source under C1** -- Work with C1 to host in their GitHub org +**Option A: Open source under C1.ai** +- Work with C1.ai to host in their GitHub org - Benefits from existing CI/CD and publishing infrastructure **Option B: Open source under your organization** @@ -146,7 +146,7 @@ make test 1. Use the standard project structure 2. Ensure CI/CD is configured with standard GitHub workflows -3. Contact C1 if you want official hosting: +3. Contact C1.ai if you want official hosting: - Open an issue on [baton-sdk](https://github.com/conductorone/baton-sdk/issues) - Include: target system name, API documentation link, your use case 4. Or publish independently under your organization diff --git a/developer/syncing.mdx b/developer/syncing.mdx index 54347dc8..75447b31 100644 --- a/developer/syncing.mdx +++ b/developer/syncing.mdx @@ -12,7 +12,7 @@ Your connector answers three questions: 2. **What permissions are available?** Entitlements that can be granted 3. **Who has what?** Grants connecting users to permissions -The Baton SDK handles orchestration, output format, pagination coordination, and communication with C1. You focus on translating your system's API into the Resource/Entitlement/Grant model. +The Baton SDK handles orchestration, output format, pagination coordination, and communication with C1.ai. You focus on translating your system's API into the Resource/Entitlement/Grant model. ## Project structure @@ -177,7 +177,7 @@ func (u *userBuilder) ResourceType(ctx context.Context) *v2.ResourceType { } ``` -Traits tell C1 how to interpret the resource. Use `TRAIT_USER` for people, `TRAIT_GROUP` for collections, `TRAIT_ROLE` for permission bundles. +Traits tell C1.ai how to interpret the resource. Use `TRAIT_USER` for people, `TRAIT_GROUP` for collections, `TRAIT_ROLE` for permission bundles. ### List() @@ -224,7 +224,7 @@ if err != nil { r.WithAnnotation(&v2.RawId{Id: user.ID}) ``` -**Why this matters:** C1 uses the `RawId` to: +**Why this matters:** C1.ai uses the `RawId` to: - **Correlate resources across syncs** - Same ID = same resource, not a duplicate - **Track provenance** - Know which connector discovered which resource - **Enable pre-sync patterns** - Support reservation mechanisms that create placeholders before sync @@ -287,7 +287,7 @@ func (g *groupBuilder) Grants(ctx context.Context, resource *v2.Resource, ## Modeling decisions -How you structure resources and entitlements determines what C1 can manage. +How you structure resources and entitlements determines what C1.ai can manage. ### What to sync as a resource? @@ -344,7 +344,7 @@ Your connector is ready when: - **Sync works deterministically** (same inputs produce stable IDs and consistent results across runs) - **Pagination works** (no token loops; handles large datasets) -- **You can run without production C1 credentials** (local testing story exists) +- **You can run without production C1.ai credentials** (local testing story exists) ### Build and test diff --git a/developer/terraform-best-practices.mdx b/developer/terraform-best-practices.mdx index d4d9ccb9..fe6f645a 100644 --- a/developer/terraform-best-practices.mdx +++ b/developer/terraform-best-practices.mdx @@ -1,30 +1,30 @@ --- -title: "C1 Terraform best practices" -og:title: "C1 Terraform best practices - C1" -og:description: "Best practices for using the C1 Terraform provider, including creating groups, entitlements, access profiles, and policies." -description: "Best practices for using the C1 Terraform provider, including creating groups, entitlements, access profiles, and policies." +title: "C1.ai Terraform best practices" +og:title: "C1.ai Terraform best practices - C1.ai" +og:description: "Best practices for using the C1.ai Terraform provider, including creating groups, entitlements, access profiles, and policies." +description: "Best practices for using the C1.ai Terraform provider, including creating groups, entitlements, access profiles, and policies." sidebarTitle: "Terraform best practices" --- {/* Editor Refresh: 2026-04-29 */} -This guide covers best practices for Terraform practitioners managing C1 resources. Each section is self-contained, so you can read them in any order. +This guide covers best practices for Terraform practitioners managing C1.ai resources. Each section is self-contained, so you can read them in any order. -Before you begin, make sure the C1 Terraform provider is installed and configured. See [C1 Terraform provider](/developer/terraform). +Before you begin, make sure the C1.ai Terraform provider is installed and configured. See [C1.ai Terraform provider](/developer/terraform). -## Creating groups in C1 +## Creating groups in C1.ai -Creating a group in C1 requires three resources working together: +Creating a group in C1.ai requires three resources working together: 1. **An app resource** — the group object itself 2. **A custom app entitlement** — defines the "member" role that users can request 3. **An entitlement automation** — evaluates a CEL expression against user attributes and automatically grants or revokes group membership, with no manual access request required -### Example: create a C1 group with dynamic membership +### Example: create a C1.ai group with dynamic membership -The following example creates a group in the C1 application and automatically adds any user whose `department` attribute contains "engineering." +The following example creates a group in the C1.ai application and automatically adds any user whose `department` attribute contains "engineering." ```hcl # Look up the C1 app. You can also store this ID as a local variable @@ -78,24 +78,24 @@ resource "conductorone_app_entitlement_automation" "dynamic_group_expression" { ### Keep in mind -- **Don't create a new resource type.** The resource type for groups already exists in C1. Creating a duplicate will cause a conflict. -- **The C1 app ID is stable within your tenant.** You can look it up once with a data source, or store it as a local variable if you reference it in multiple places. +- **Don't create a new resource type.** The resource type for groups already exists in C1.ai. Creating a duplicate will cause a conflict. +- **The C1.ai app ID is stable within your tenant.** You can look it up once with a data source, or store it as a local variable if you reference it in multiple places. - **Consider wrapping this pattern in a reusable Terraform module.** You'll repeat these same three resources for every group you create. --- ## Custom app entitlements vs app entitlements -There are two Terraform resources for managing entitlements. Choosing the right one depends on whether the entitlement already exists in C1. +There are two Terraform resources for managing entitlements. Choosing the right one depends on whether the entitlement already exists in C1.ai. -- Use `conductorone_custom_app_entitlement` to **create** a new entitlement that does not yet exist in C1 — for virtual entitlements, or when pre-creating an IDP group before a connector sync. +- Use `conductorone_custom_app_entitlement` to **create** a new entitlement that does not yet exist in C1.ai — for virtual entitlements, or when pre-creating an IDP group before a connector sync. - Use `conductorone_app_entitlement` to **configure or update** an entitlement that a connector already manages. This resource is update-only; it cannot create or delete entitlements. ### Creating virtual entitlements Use [conductorone_custom_app_entitlement](https://registry.terraform.io/providers/ConductorOne/conductorone/latest/docs/resources/custom_app_entitlement) when you need to create a virtual entitlement for a permission not yet discovered by a connector. -This resource also supports the `match_baton_id` field, which links the Terraform resource to an external ID (such as an Okta group ID). When the connector syncs, C1 merges the two rather than creating a duplicate. +This resource also supports the `match_baton_id` field, which links the Terraform resource to an external ID (such as an Okta group ID). When the connector syncs, C1.ai merges the two rather than creating a duplicate. ```hcl data "conductorone_app" "okta_app" { @@ -151,12 +151,12 @@ Use [conductorone_app_entitlement](https://registry.terraform.io/providers/Condu This resource is also used to manage the app access entitlement, a static entitlement that exists on every app. -`conductorone_app_entitlement` is update-only. Running `terraform destroy` removes the resource from Terraform state, but the entitlement still exists in C1. To roll back a change, run a subsequent `terraform apply` with the previous configuration values. +`conductorone_app_entitlement` is update-only. Running `terraform destroy` removes the resource from Terraform state, but the entitlement still exists in C1.ai. To roll back a change, run a subsequent `terraform apply` with the previous configuration values. ### Example: configure app access with account provisioning -Use this pattern when you want C1 to provision a new account in the target system when access is granted, rather than assigning an existing account. +Use this pattern when you want C1.ai to provision a new account in the target system when access is granted, rather than assigning an existing account. ```hcl resource "conductorone_app_entitlement" "app_access" { @@ -216,7 +216,7 @@ resource "conductorone_app_entitlement" "test_entitlement_update_multistep" { - **Terraform import is not required.** Reference the entitlement by ID using a data source lookup. - **JSON encoding is required** for `multi_step` provisioning and `account_provision` config blocks. -- **Entitlement owners** are managed with a separate resource, [conductorone_app_entitlement_owner](https://registry.terraform.io/providers/ConductorOne/conductorone/latest/docs/resources/app_entitlement_owner). Owners are always a list of C1 users — the resource accepts `user_ids` only, and setting the list replaces any existing owners for that entitlement. See the example below. +- **Entitlement owners** are managed with a separate resource, [conductorone_app_entitlement_owner](https://registry.terraform.io/providers/ConductorOne/conductorone/latest/docs/resources/app_entitlement_owner). Owners are always a list of C1.ai users — the resource accepts `user_ids` only, and setting the list replaces any existing owners for that entitlement. See the example below. - **App-level owners** are managed with [conductorone_app_owner](https://registry.terraform.io/providers/ConductorOne/conductorone/latest/docs/resources/app_owner), which takes an `app_id` and a `user_ids` list. Setting `user_ids` replaces any existing owners for the app, and changing either field forces the resource to be replaced. ### Example: manage entitlement owners @@ -259,7 +259,7 @@ When looking up users, the [conductorone_user](https://registry.terraform.io/pro ## Creating access profiles -Access profiles group multiple entitlements into a single requestable bundle. The C1 UI calls these "access profiles," but the Terraform provider and API use the term "catalog" — you'll see `catalog_id` as a field name throughout these resources. +Access profiles group multiple entitlements into a single requestable bundle. The C1.ai UI calls these "access profiles," but the Terraform provider and API use the term "catalog" — you'll see `catalog_id` as a field name throughout these resources. A fully configured access profile requires five related resources: @@ -444,7 +444,7 @@ Policies define the approval workflow for access requests — who reviews, in wh ### Always include a baseline rule -Every policy must include a `grant` key with at least one step. Without it, any request that does not match a named rule's condition will fail or get stuck in an undefined state. Terraform does not validate this requirement — C1 enforces it at runtime. +Every policy must include a `grant` key with at least one step. Without it, any request that does not match a named rule's condition will fail or get stuck in an undefined state. Terraform does not validate this requirement — C1.ai enforces it at runtime. The `grant` key is the catch-all baseline rule. It runs for every request that does not match any named rule's condition. In the examples below, it rejects those unmatched requests by default, so only requests satisfying `my_policy_key`'s condition are auto-approved. @@ -518,7 +518,7 @@ resource "conductorone_policy" "auto_approve_policy" { ### Use built-in policies as templates -Terraform does not validate policy structure the same way the C1 UI does. The safest starting point is to generate HCL from an existing, working policy. +Terraform does not validate policy structure the same way the C1.ai UI does. The safest starting point is to generate HCL from an existing, working policy. @@ -558,7 +558,7 @@ Terraform does not validate policy structure the same way the C1 UI does. The sa ## Related resources -- [C1 Terraform provider](/developer/terraform) +- [C1.ai Terraform provider](/developer/terraform) - [CEL expressions](/product/admin/expressions) - [CEL expressions reference](/product/admin/expressions-reference) - [conductorone_policy on the Terraform Registry](https://registry.terraform.io/providers/ConductorOne/conductorone/latest/docs/resources/policy) diff --git a/developer/terraform.mdx b/developer/terraform.mdx index 1b61941e..b1b96481 100644 --- a/developer/terraform.mdx +++ b/developer/terraform.mdx @@ -1,14 +1,14 @@ --- -title: C1 Terraform provider -og:title: C1 Terraform provider - C1 -og:description: C1's Terraform provider lets you define and manage C1 infrastructure in a declarative way. -description: C1's Terraform provider lets you define and manage C1 infrastructure in a declarative way. -sidebarTitle: "C1 Terraform provider" +title: C1.ai Terraform provider +og:title: C1.ai Terraform provider - C1.ai +og:description: C1.ai's Terraform provider lets you define and manage C1.ai infrastructure in a declarative way. +description: C1.ai's Terraform provider lets you define and manage C1.ai infrastructure in a declarative way. +sidebarTitle: "C1.ai Terraform provider" --- Terraform is an open-source infrastructure-as-code (IAC) tool that lets developers define and manage cloud infrastructure using code. Terraform is declarative, which means that you define the desired state of your infrastructure, and Terraform then automatically creates or updates your infrastructure to match the desired state. This can be helpful for creating and managing complex infrastructure deployments. -C1's Terraform provider can help you automate the provisioning, configuration, and management of C1 resources and integrations. The C1 Terraform provider allows you to configure important management objects, including: +C1.ai's Terraform provider can help you automate the provisioning, configuration, and management of C1.ai resources and integrations. The C1.ai Terraform provider allows you to configure important management objects, including: - Policies - Integrations @@ -25,29 +25,29 @@ The Terraform provider supports three authentication methods: For details on setting up service principals and choosing an authentication method, see [service principals](/product/admin/service-principals/overview). -## Getting started with C1's Terraform provider +## Getting started with C1.ai's Terraform provider -Find [C1's Terraform provider](https://registry.terraform.io/providers/ConductorOne/conductorone/latest) on the Terraform registry. +Find [C1.ai's Terraform provider](https://registry.terraform.io/providers/ConductorOne/conductorone/latest) on the Terraform registry. -C1 Terraform provider on the Terraform registry +C1.ai Terraform provider on the Terraform registry Click **Documentation** on the registry homepage to see the full list of resources and data sources available in the provider. -To get started, click **Use Provider** and follow the instructions provided to add C1's Terraform provider to your Terraform configuration file. +To get started, click **Use Provider** and follow the instructions provided to add C1.ai's Terraform provider to your Terraform configuration file. ## Specialized Terraform capabilities -C1 has built some specialized capabilities in Terraform to address use cases unique to this manner of setting up and using our product. These capabilities do not have equivalents in the web UI. +C1.ai has built some specialized capabilities in Terraform to address use cases unique to this manner of setting up and using our product. These capabilities do not have equivalents in the web UI. -### Merge an IdP group with a C1 group +### Merge an IdP group with a C1.ai group -Traditionally, creating a group in an IdP and then configuring its properties in C1 required a multi-step, manual process. You'd have to run Terraform against the IdP, wait for C1 to sync the new group, and then run a separate Terraform script against C1 after manually matching the group names. This was inefficient and prone to errors. +Traditionally, creating a group in an IdP and then configuring its properties in C1.ai required a multi-step, manual process. You'd have to run Terraform against the IdP, wait for C1.ai to sync the new group, and then run a separate Terraform script against C1.ai after manually matching the group names. This was inefficient and prone to errors. -Now, with the Group ID as a join key, you can perform a single Terraform run that creates a group in C1 and simultaneously merges that group with the corresponding IdP group. This eliminates the need to wait for multiple C1 syncs and dramatically simplifies your group management process. +Now, with the Group ID as a join key, you can perform a single Terraform run that creates a group in C1.ai and simultaneously merges that group with the corresponding IdP group. This eliminates the need to wait for multiple C1.ai syncs and dramatically simplifies your group management process. -Here are sample Terraform files demonstrating how to use the `match_baton_id` key to sync a C1 group with Okta: +Here are sample Terraform files demonstrating how to use the `match_baton_id` key to sync a C1.ai group with Okta: **okta.tf file:** diff --git a/index.mdx b/index.mdx index bb34570e..1585bf36 100644 --- a/index.mdx +++ b/index.mdx @@ -1,5 +1,5 @@ --- -title: "C1 documentation" +title: "C1.ai documentation" mode: "custom" ---
@@ -7,10 +7,10 @@ mode: "custom"

- C1 docs + C1.ai docs

- Everything you need to configure, extend, and get the most out of C1. + Everything you need to configure, extend, and get the most out of C1.ai.

@@ -58,10 +58,10 @@ mode: "custom"

- Use C1 + Use C1.ai

- Request access, complete review tasks, and use AI tools and MCP clients as an end user of C1. + Request access, complete review tasks, and use AI tools and MCP clients as an end user of C1.ai.

Learn more @@ -77,7 +77,7 @@ mode: "custom"

- Administer C1 + Administer C1.ai

Automate security for all your human, non-human, and AI identities. Run access reviews, enable self-service access, and set up just-in-time access for key resources. @@ -122,7 +122,7 @@ mode: "custom" Developer

- Work with our Go and TypeScript SDKs, Terraform provider, and Postman integration. Integrate with, manage, and extend the C1 platform programmatically. + Work with our Go and TypeScript SDKs, Terraform provider, and Postman integration. Integrate with, manage, and extend the C1.ai platform programmatically.

Learn more @@ -144,7 +144,7 @@ mode: "custom" API

- Extend C1's power into your own ecosystem. Automate access requests, export audit data for compliance reporting, and integrate identity security directly into your internal tools and developer workflows. + Extend C1.ai's power into your own ecosystem. Automate access requests, export audit data for compliance reporting, and integrate identity security directly into your internal tools and developer workflows.

Learn more diff --git a/rap/INDEX.md b/rap/INDEX.md index 7de79fc0..dad5ce27 100644 --- a/rap/INDEX.md +++ b/rap/INDEX.md @@ -1,4 +1,4 @@ -# C1 RAP Documentation +# C1.ai RAP Documentation Retrieval Augmented Prompt (RAP) documentation for AI agents. Each subdirectory contains focused, self-contained documentation chunks optimized for selective retrieval. @@ -17,7 +17,7 @@ Retrieval Augmented Prompt (RAP) documentation for AI agents. Each subdirectory | **Connectors** | `connectors/INDEX.md` | Building Baton connectors, sync/provision patterns, SDK interfaces | | **Service Principals** | `service-principals/INDEX.md` | API automation, client credentials, workload federation, CI/CD integration | | **CEL Expressions** | `cel-expressions/index.md` | Writing CEL in policies, dynamic groups, automations, access reviews | -| **MCP Gateway** | `mcp-gateway/INDEX.md` | Interacting with C1's MCP gateway and code mode as an AI agent | +| **MCP Gateway** | `mcp-gateway/INDEX.md` | Interacting with C1.ai's MCP gateway and code mode as an AI agent | ## Quick Routing Guide @@ -30,7 +30,7 @@ Retrieval Augmented Prompt (RAP) documentation for AI agents. Each subdirectory **User asks about expressions, policies, dynamic groups, automation conditions:** → `cel-expressions/index.md` -**User's agent is connected to C1's MCP endpoint, or asks about code mode, `execute`, `describe`, tool access denials, access-request envelopes:** +**User's agent is connected to C1.ai's MCP endpoint, or asks about code mode, `execute`, `describe`, tool access denials, access-request envelopes:** → `mcp-gateway/INDEX.md` ## Subdirectory Structure diff --git a/rap/cel-expressions/env-account-provisioning.md b/rap/cel-expressions/env-account-provisioning.md index 739db723..31aee1d7 100644 --- a/rap/cel-expressions/env-account-provisioning.md +++ b/rap/cel-expressions/env-account-provisioning.md @@ -109,7 +109,7 @@ c1.user.v1.GetAppUsersForUser(subject, "app-id") | Scenario | What Happens | How to Handle | |----------|--------------|---------------| | Profile attribute missing | Empty string or error | Use `has()` check | -| Attribute mapping not found | Empty value | Check mapping exists in C1 config | +| Attribute mapping not found | Empty value | Check mapping exists in C1.ai config | | `entitlement` not available | Compile error if referenced | Check context provides entitlement | | `task` not available | Compile error if referenced | Check context provides task | diff --git a/rap/cel-expressions/env-workflow.md b/rap/cel-expressions/env-workflow.md index 95834d6b..f5a180b9 100644 --- a/rap/cel-expressions/env-workflow.md +++ b/rap/cel-expressions/env-workflow.md @@ -1,6 +1,6 @@ # Workflow Execution Expressions -Dynamic data access within C1 workflow automations. Supports template interpolation and step-to-step data flow. +Dynamic data access within C1.ai workflow automations. Supports template interpolation and step-to-step data flow. ## When to Use diff --git a/rap/cel-expressions/functions-strings.md b/rap/cel-expressions/functions-strings.md index 27f3fbaa..fe91936b 100644 --- a/rap/cel-expressions/functions-strings.md +++ b/rap/cel-expressions/functions-strings.md @@ -1,10 +1,10 @@ # String Functions -Standard CEL string methods plus C1 extensions. +Standard CEL string methods plus C1.ai extensions. ## ifEmpty() -Return a default value if string is empty. C1 extension. +Return a default value if string is empty. C1.ai extension. ```cel string.ifEmpty(default: string) -> string diff --git a/rap/cel-expressions/index.md b/rap/cel-expressions/index.md index 6dae5b11..38aff612 100644 --- a/rap/cel-expressions/index.md +++ b/rap/cel-expressions/index.md @@ -1,10 +1,10 @@ # CEL Expression Knowledge Base -This directory contains focused documentation chunks for CEL (Common Expression Language) in C1. Each file is self-contained and designed for selective retrieval. +This directory contains focused documentation chunks for CEL (Common Expression Language) in C1.ai. Each file is self-contained and designed for selective retrieval. ## How to Use This Index -When answering questions about CEL expressions in C1: +When answering questions about CEL expressions in C1.ai: 1. Identify the question type from the tables below 2. Retrieve 1-3 relevant files from this directory diff --git a/rap/cel-expressions/overview-intro.md b/rap/cel-expressions/overview-intro.md index 45265fd4..032eb12e 100644 --- a/rap/cel-expressions/overview-intro.md +++ b/rap/cel-expressions/overview-intro.md @@ -1,6 +1,6 @@ # CEL Overview -CEL (Common Expression Language) is Google's expression language for policy evaluation. C1 uses CEL to let you encode access logic that would be impossible with dropdown menus. +CEL (Common Expression Language) is Google's expression language for policy evaluation. C1.ai uses CEL to let you encode access logic that would be impossible with dropdown menus. ## Why CEL for Authorization @@ -37,15 +37,15 @@ c1.directory.users.v1.GetManagers(subject) size(managers) > 0 ? managers : appOwners ``` -## What's C1's vs Google's +## What's C1.ai's vs Google's -| Layer | Google's CEL | C1's Extensions | +| Layer | Google's CEL | C1.ai's Extensions | |-------|--------------|---------------------------| | Syntax | All operators, macros (`has()`, `size()`) | Nothing added | | Types | Primitives, lists, maps, timestamps | `User`, `Task`, `AppEntitlement` | | Functions | String methods, math | `c1.directory.*`, `c1.user.*` | -**Rule of thumb:** If it starts with `c1.`, it's C1's extension. +**Rule of thumb:** If it starts with `c1.`, it's C1.ai's extension. ## How Expressions are Evaluated diff --git a/rap/cel-expressions/terraform-examples.md b/rap/cel-expressions/terraform-examples.md index 9b62a54a..ad274cba 100644 --- a/rap/cel-expressions/terraform-examples.md +++ b/rap/cel-expressions/terraform-examples.md @@ -1,6 +1,6 @@ # CEL in Terraform -CEL expressions in the C1 Terraform provider. +CEL expressions in the C1.ai Terraform provider. ## Resources Supporting CEL @@ -155,6 +155,6 @@ EOT ## Tips -1. **Validate in UI first** - Test expressions in the C1 UI before deploying via Terraform +1. **Validate in UI first** - Test expressions in the C1.ai UI before deploying via Terraform 2. **Use heredoc for readability** - Complex expressions are easier to read with heredoc syntax 3. **Check return types** - Conditions return `bool`, approvers return `User`/`list` diff --git a/rap/cel-expressions/types.md b/rap/cel-expressions/types.md index a0fd2e0c..594fc5fa 100644 --- a/rap/cel-expressions/types.md +++ b/rap/cel-expressions/types.md @@ -1,6 +1,6 @@ # CEL Type Definitions -This document covers all types used in C1 CEL expressions: primitives, time types, collections, enums, and object types. +This document covers all types used in C1.ai CEL expressions: primitives, time types, collections, enums, and object types. ## Primitive Types @@ -74,7 +74,7 @@ Always use the full enum name (e.g., `UserStatus.ENABLED`, not just `ENABLED`). | Value | Meaning | |:------|:--------| -| `TaskOrigin.WEBAPP` | Created in C1 web interface | +| `TaskOrigin.WEBAPP` | Created in C1.ai web interface | | `TaskOrigin.SLACK` | Created via Slack integration | | `TaskOrigin.API` | Created via API | | `TaskOrigin.JIRA` | Created via Jira integration | @@ -106,14 +106,14 @@ Used in `ctx.trigger.oldAccount.status.status` and `ctx.trigger.newAccount.statu ### User vs AppUser These are different types: -- **User** = A person in the C1 directory (synced from identity provider) +- **User** = A person in the C1.ai directory (synced from identity provider) - **AppUser** = That person's account in a specific app (GitHub account, Okta account, etc.) One User can have many AppUsers across different connected applications. ### User -A person in the C1 directory. +A person in the C1.ai directory. **Returned by:** `FindByEmail`, `GetByID`, `GetManagers`, `DirectReports`, `GetEntitlementMembers` @@ -164,7 +164,7 @@ A user's account within a specific connected application. ### Group -A C1 group (entitlement in the builtin Groups app). +A C1.ai group (entitlement in the builtin Groups app). **Returned by:** `FindByName` diff --git a/rap/connectors/INDEX.md b/rap/connectors/INDEX.md index a5f616c4..b11ad6f1 100644 --- a/rap/connectors/INDEX.md +++ b/rap/connectors/INDEX.md @@ -1,6 +1,6 @@ # Baton Connector Documentation Index -Documentation for building C1 Baton connectors. Request relevant sections based on user's question. +Documentation for building C1.ai Baton connectors. Request relevant sections based on user's question. ## How to Use @@ -72,7 +72,7 @@ Documentation for building C1 Baton connectors. Request relevant sections based |---------|------|--------| | SDK interfaces | `ref-sdk.md` | ConnectorBuilder, ResourceSyncer, Provisioner | | Configuration | `ref-config.md` | Flags, env vars, field types | -| C1 API | `ref-c1api.md` | Task types, lifecycle, heartbeat | +| C1.ai API | `ref-c1api.md` | Task types, lifecycle, heartbeat | | FAQ | `ref-faq.md` | Common questions | | Glossary | `ref-glossary.md` | Term definitions | @@ -128,7 +128,7 @@ Documentation for building C1 Baton connectors. Request relevant sections based **Architecture** - SDK interfaces -> `ref-sdk.md` -- C1 communication -> `ref-c1api.md` +- C1.ai communication -> `ref-c1api.md` --- diff --git a/rap/connectors/community.md b/rap/connectors/community.md index a117479c..66ebfde5 100644 --- a/rap/connectors/community.md +++ b/rap/connectors/community.md @@ -39,7 +39,7 @@ Good: "Sync fails with 'unauthorized' when listing users. Using baton-okta v0.5. |---------|----------|---------| | GitHub Issues | Days | Bugs, features | | GitHub Discussions | Days | Questions | -| C1 Support | Hours | Production (customers) | +| C1.ai Support | Hours | Production (customers) | --- diff --git a/rap/connectors/concepts-ids.md b/rap/connectors/concepts-ids.md index c6169bd3..54cdcd82 100644 --- a/rap/connectors/concepts-ids.md +++ b/rap/connectors/concepts-ids.md @@ -1,12 +1,12 @@ # concepts-ids -RawId annotation, external_id, and how C1 matches resources across syncs. +RawId annotation, external_id, and how C1.ai matches resources across syncs. --- ## Why ID Correlation Matters -C1 needs to know if a resource in this sync is the same resource from a previous sync. This enables: +C1.ai needs to know if a resource in this sync is the same resource from a previous sync. This enables: - Tracking changes over time - Correlating resources across connectors - Supporting pre-sync reservation patterns @@ -60,8 +60,8 @@ Use the external system's native, stable identifier: **Using composite keys:** If you construct `org/repo`, changes to either part break correlation. -**Omitting RawId:** Without it, C1 can't correlate resources across syncs. +**Omitting RawId:** Without it, C1.ai can't correlate resources across syncs. ## Pre-sync Reservation -The `match_baton_id` field (in Terraform/API) allows creating C1 objects before the connector discovers them. When the connector syncs, resources are matched by this ID. +The `match_baton_id` field (in Terraform/API) allows creating C1.ai objects before the connector discovers them. When the connector syncs, resources are matched by this ID. diff --git a/rap/connectors/concepts-overview.md b/rap/connectors/concepts-overview.md index ba6da3c4..97b7a0f1 100644 --- a/rap/connectors/concepts-overview.md +++ b/rap/connectors/concepts-overview.md @@ -8,7 +8,7 @@ What connectors do, sync vs provision, the reconciliation loop. A **connector** answers: *who has access to what?* -C1 needs visibility into users, groups, roles, and permissions across all systems. Every system stores this differently - Okta has users and groups, AWS has IAM roles and policies, Salesforce has profiles and permission sets. +C1.ai needs visibility into users, groups, roles, and permissions across all systems. Every system stores this differently - Okta has users and groups, AWS has IAM roles and policies, Salesforce has profiles and permission sets. A connector translates access data from any system into a common format. Once connected, you get unified visibility across your infrastructure. @@ -21,7 +21,7 @@ In Baton terms, a connector is a program that can: ## Sync vs Provision -**Sync** (read): Pull access data into C1 +**Sync** (read): Pull access data into C1.ai - Who exists? What groups? What roles? - What permissions are available? - Who has what access right now? @@ -36,7 +36,7 @@ In Baton terms, a connector is a program that can: Together, sync and provision create a reconciliation loop: -1. C1 sees what access exists (sync) +1. C1.ai sees what access exists (sync) 2. Compares to what access *should* exist (policy) 3. Corrects any drift (provision) diff --git a/rap/connectors/concepts-resources.md b/rap/connectors/concepts-resources.md index 1fa00406..9b238f63 100644 --- a/rap/connectors/concepts-resources.md +++ b/rap/connectors/concepts-resources.md @@ -35,7 +35,7 @@ Each resource has a **resource type** with optional **traits**. ## Traits -Traits tell C1 how to interpret a resource: +Traits tell C1.ai how to interpret a resource: | Trait | Use For | |-------|---------| diff --git a/rap/connectors/concepts-sync.md b/rap/connectors/concepts-sync.md index d141d3bc..7e31cfdd 100644 --- a/rap/connectors/concepts-sync.md +++ b/rap/connectors/concepts-sync.md @@ -77,8 +77,8 @@ flowchart LR 1. **Fetch** - Your connector calls external API 2. **Transform** - Create Resource/Entitlement/Grant objects 3. **Output** - SDK writes to .c1z file (gzip SQLite) -4. **Ingest** - C1 reads the file +4. **Ingest** - C1.ai reads the file 5. **Uplift** - Raw records become domain objects **You control:** Steps 1-3 -**C1 controls:** Steps 4-5 +**C1.ai controls:** Steps 4-5 diff --git a/rap/connectors/ops-modes.md b/rap/connectors/ops-modes.md index a5c3a10c..fca7c4f8 100644 --- a/rap/connectors/ops-modes.md +++ b/rap/connectors/ops-modes.md @@ -9,8 +9,8 @@ One-shot vs daemon vs hosted mode. | Mode | Trigger | Behavior | |------|---------|----------| | **One-shot** | No `--client-id` | Run once, produce .c1z file, exit | -| **Daemon** | `--client-id` provided | Connect to C1, poll for tasks, run continuously | -| **Hosted** | C1 infrastructure | Managed by C1, no local deployment | +| **Daemon** | `--client-id` provided | Connect to C1.ai, poll for tasks, run continuously | +| **Hosted** | C1.ai infrastructure | Managed by C1.ai, no local deployment | ## One-Shot Mode @@ -34,7 +34,7 @@ Use for: ## Daemon Mode -Connect to C1 and process tasks continuously: +Connect to C1.ai and process tasks continuously: ```bash ./baton-myservice \ @@ -44,7 +44,7 @@ Connect to C1 and process tasks continuously: ``` The connector: -1. Authenticates to C1 +1. Authenticates to C1.ai 2. Polls for sync/provisioning tasks 3. Executes tasks and reports results 4. Repeats until stopped @@ -56,12 +56,12 @@ Use for: ## Hosted Mode -C1 runs the connector for you: +C1.ai runs the connector for you: - No infrastructure to manage - Automatic updates -- Credentials stored in C1 +- Credentials stored in C1.ai -Check if your connector is available as hosted in the C1 console. +Check if your connector is available as hosted in the C1.ai console. ## Provisioning Flag diff --git a/rap/connectors/ref-c1api.md b/rap/connectors/ref-c1api.md index 10c1ebfb..1d021198 100644 --- a/rap/connectors/ref-c1api.md +++ b/rap/connectors/ref-c1api.md @@ -1,6 +1,6 @@ # ref-c1api -How connectors communicate with C1 platform. SDK handles this; understanding helps debugging. +How connectors communicate with C1.ai platform. SDK handles this; understanding helps debugging. --- @@ -50,7 +50,7 @@ type SyncTask struct { } ``` -Produces: c1z file uploaded to C1 +Produces: c1z file uploaded to C1.ai ### GrantTask diff --git a/rap/connectors/ref-config.md b/rap/connectors/ref-config.md index 6c6aa839..d8991e99 100644 --- a/rap/connectors/ref-config.md +++ b/rap/connectors/ref-config.md @@ -28,8 +28,8 @@ CLI wins over env, env wins over file. | Flag | Description | |------|-------------| -| `--client-id` | C1 OAuth client ID (enables daemon mode) | -| `--client-secret` | C1 OAuth client secret | +| `--client-id` | C1.ai OAuth client ID (enables daemon mode) | +| `--client-secret` | C1.ai OAuth client secret | | `--skip-full-sync` | Disable full sync in daemon mode | ### Provisioning diff --git a/rap/connectors/ref-faq.md b/rap/connectors/ref-faq.md index 8e3fbf2b..0176020b 100644 --- a/rap/connectors/ref-faq.md +++ b/rap/connectors/ref-faq.md @@ -11,8 +11,8 @@ Common questions about baton connectors. | Tool | Purpose | User | |------|---------|------| | baton-sdk | Go SDK for building connectors | Connector developers | -| cone | CLI for C1 platform ops | End users (requests, approvals) | -| conductorone-sdk-go | Go SDK for C1 API | App integrators | +| cone | CLI for C1.ai platform ops | End users (requests, approvals) | +| conductorone-sdk-go | Go SDK for C1.ai API | App integrators | Building a connector? Use baton-sdk. diff --git a/rap/connectors/ref-glossary.md b/rap/connectors/ref-glossary.md index 1c465c27..6db4bc3d 100644 --- a/rap/connectors/ref-glossary.md +++ b/rap/connectors/ref-glossary.md @@ -40,7 +40,7 @@ Term definitions for Baton connector development. | Term | Definition | |------|------------| | **Sync** | Reading access data from a system | -| **Uplift** | C1 process transforming raw records to domain objects | +| **Uplift** | C1.ai process transforming raw records to domain objects | | **ID Correlation** | Matching resources across syncs using RawId | ## Provisioning @@ -58,8 +58,8 @@ Term definitions for Baton connector development. | Term | Definition | |------|------------| | **One-shot** | Run once, produce c1z file, exit | -| **Daemon** | Long-running, polls C1 for tasks | -| **Hosted** | Run by C1 infrastructure | +| **Daemon** | Long-running, polls C1.ai for tasks | +| **Hosted** | Run by C1.ai infrastructure | ## Meta-Connector Terms diff --git a/rap/mcp-gateway/INDEX.md b/rap/mcp-gateway/INDEX.md index 3e99950d..77d3583e 100644 --- a/rap/mcp-gateway/INDEX.md +++ b/rap/mcp-gateway/INDEX.md @@ -1,8 +1,8 @@ # MCP Gateway Documentation Index -Documentation for interacting with ConductorOne (C1) as an MCP gateway, and for the code-mode interface agents use to call governed tools through it. Request relevant sections based on the user's question. +Documentation for interacting with ConductorOne (C1.ai) as an MCP gateway, and for the code-mode interface agents use to call governed tools through it. Request relevant sections based on the user's question. -C1 is an MCP gateway: an AI client connects to one C1 MCP endpoint, and C1 sits in front of the organization's approved MCP servers. Agents do not connect to those upstream servers directly. Every call is identity-aware, governed per tool, and audit logged. +C1.ai is an MCP gateway: an AI client connects to one C1.ai MCP endpoint, and C1.ai sits in front of the organization's approved MCP servers. Agents do not connect to those upstream servers directly. Every call is identity-aware, governed per tool, and audit logged. ## How to Use @@ -25,7 +25,7 @@ C1 is an MCP gateway: an AI client connects to one C1 MCP endpoint, and C1 sits ## Selection Guidelines **"What is..."** -- C1 MCP / the C1 gateway / C1 MCP URL -> `concepts-gateway.md` +- C1.ai MCP / the C1.ai gateway / C1.ai MCP URL -> `concepts-gateway.md` - Code mode -> `concepts-gateway.md`, `use-code-mode.md` - `describe` / `execute` -> `use-code-mode.md` - `get_execution` -> `use-async-executions.md` @@ -57,7 +57,7 @@ C1 is an MCP gateway: an AI client connects to one C1 MCP endpoint, and C1 sits **Governance questions** - Why a call was blocked -> `concepts-gateway.md`, `use-access-requests.md` -- What C1 logs per call -> `concepts-gateway.md` +- What C1.ai logs per call -> `concepts-gateway.md` - Which client types get code mode -> `concepts-gateway.md` --- @@ -76,7 +76,7 @@ Retrieve: `use-access-requests.md` User: "execute came back pending with an execution_id" Retrieve: `use-async-executions.md` -User: "How does C1 decide whether my agent can call a tool?" +User: "How does C1.ai decide whether my agent can call a tool?" Retrieve: `concepts-gateway.md` User: "The result came back with the salary field redacted" diff --git a/rap/mcp-gateway/concepts-gateway.md b/rap/mcp-gateway/concepts-gateway.md index c3431fe5..e6dfe40c 100644 --- a/rap/mcp-gateway/concepts-gateway.md +++ b/rap/mcp-gateway/concepts-gateway.md @@ -1,15 +1,15 @@ -# C1 as an MCP Gateway +# C1.ai as an MCP Gateway -ConductorOne (C1) is an MCP gateway. An AI client connects to one C1 MCP endpoint, and C1 sits in front of the organization's approved MCP servers and integrations. Agents do not connect to those upstream servers directly. +ConductorOne (C1.ai) is an MCP gateway. An AI client connects to one C1.ai MCP endpoint, and C1.ai sits in front of the organization's approved MCP servers and integrations. Agents do not connect to those upstream servers directly. Mental model: **one MCP connection, many governed systems behind it.** ## What the Gateway Does on Every Call -1. **Authenticates the caller.** C1 resolves the human or workload identity behind the agent. Every tool call carries that identity — the gateway is identity-aware, not an anonymous relay. +1. **Authenticates the caller.** C1.ai resolves the human or workload identity behind the agent. Every tool call carries that identity — the gateway is identity-aware, not an anonymous relay. 2. **Checks governance.** The tool must be **Enabled** by an admin, and the caller must hold a **grant** for it. Both conditions are required. Enabling a tool does not grant it to anyone. 3. **Runs hooks.** Admin-configured pre-tool-use hooks may rewrite the input or deny the call. -4. **Routes upstream.** C1 forwards the call to the correct upstream server using that server's configured auth mode, so the agent never handles upstream credentials. +4. **Routes upstream.** C1.ai forwards the call to the correct upstream server using that server's configured auth mode, so the agent never handles upstream credentials. 5. **Runs post hooks.** Post-tool-use hooks may rewrite, redact, or deny the returned output. 6. **Writes an audit log entry** with identity, client, server, tool, result, denial reason, and latency. @@ -19,17 +19,17 @@ The agent cannot tell these apart and does not need to. All appear as tools behi | Upstream | What it is | |----------|------------| -| Hosted catalog server | An MCP server C1 hosts and registers on the org's behalf | +| Hosted catalog server | An MCP server C1.ai hosts and registers on the org's behalf | | Vendor MCP server | A third-party MCP server registered by an admin | -| Bridged server | A private or on-premises MCP server reached through C1's MCP bridge | +| Bridged server | A private or on-premises MCP server reached through C1.ai's MCP bridge | ## Toolsets, Access Profiles, and Grants - A **tool** is one capability exposed by an upstream MCP server (for example, `github_create_issue`). - Discovered tools start in an unreviewed state. An admin approves/enables them and may classify them by action (read / write / delete) and risk. -- Approved tools are bundled into a **toolset** — either C1-maintained ("All approved", "Read-only") or an admin-curated custom toolset. +- Approved tools are bundled into a **toolset** — either C1.ai-maintained ("All approved", "Read-only") or an admin-curated custom toolset. - A toolset is bound to an **access profile**, which carries the approval policy, approvers, and expiry. -- A user requests the access profile from the C1 catalog (web, Slack, or from their AI client). Once approved, the grant makes the toolset's tools callable by that user's clients. +- A user requests the access profile from the C1.ai catalog (web, Slack, or from their AI client). Once approved, the grant makes the toolset's tools callable by that user's clients. Consequence for agents: the tool surface is per-caller, not per-tenant. Two agents connected to the same gateway can see and call different sets of tools. @@ -71,7 +71,7 @@ Governance is identical in both shapes. Code mode changes the calling interface, When the caller lacks access to a tool, the gateway does not fail with a generic error. It returns a structured envelope: -- `{status: 'request_created', tool, task_id, task_number, task_url, entitlement_id}` — the tool is requestable. C1 opened an access request; the upstream API was **not** called. Once the request is approved, the same call executes. +- `{status: 'request_created', tool, task_id, task_number, task_url, entitlement_id}` — the tool is requestable. C1.ai opened an access request; the upstream API was **not** called. Once the request is approved, the same call executes. - `{status: 'denied', reason}` — no access path exists for this caller. This is the gateway's signature behavior and the thing agents most often misread. A `request_created` result is not a failure and not an empty result set — it means a request was filed and the human needs the task link. @@ -80,7 +80,7 @@ Correct agent behavior: check for these envelopes before touching any domain fie ## Two Governance Paths, One Platform -C1 governs MCP access two ways. The gateway path (this document) proxies the agent's tool calls through C1. In **enterprise-managed authorization**, C1 instead issues a short-lived scoped token and the agent calls the MCP server directly. Code mode, `describe`/`execute`, and access-request envelopes belong to the gateway path only. +C1.ai governs MCP access two ways. The gateway path (this document) proxies the agent's tool calls through C1.ai. In **enterprise-managed authorization**, C1.ai instead issues a short-lived scoped token and the agent calls the MCP server directly. Code mode, `describe`/`execute`, and access-request envelopes belong to the gateway path only. ## Also in This Domain diff --git a/rap/mcp-gateway/use-access-requests.md b/rap/mcp-gateway/use-access-requests.md index 48708439..e874a08c 100644 --- a/rap/mcp-gateway/use-access-requests.md +++ b/rap/mcp-gateway/use-access-requests.md @@ -1,6 +1,6 @@ # Handling Access-Request Envelopes -ConductorOne (C1) is an MCP gateway: one MCP endpoint in front of the organization's approved MCP servers, enforcing governance on every call. A tool call only executes when the tool is **Enabled** by an admin and the caller holds a **grant** for it. When the caller lacks access, the gateway does not fail opaquely — it returns a structured envelope in place of domain data. +ConductorOne (C1.ai) is an MCP gateway: one MCP endpoint in front of the organization's approved MCP servers, enforcing governance on every call. A tool call only executes when the tool is **Enabled** by an admin and the caller holds a **grant** for it. When the caller lacks access, the gateway does not fail opaquely — it returns a structured envelope in place of domain data. This applies to any `tools.()` call inside an `execute` program, and to directly named tool calls where code mode is off. @@ -19,7 +19,7 @@ This applies to any `tools.()` call inside an `execute` program, and t } ``` -Meaning: the tool is *requestable* by this caller but not yet granted. C1 opened an access request on the caller's behalf. **The upstream API was not called** — no data was read, nothing was written. Approval flows through the tool's normal policy (manager approval, auto-approve, JIT expiry, and so on). Once the grant lands, the same call executes normally. +Meaning: the tool is *requestable* by this caller but not yet granted. C1.ai opened an access request on the caller's behalf. **The upstream API was not called** — no data was read, nothing was written. Approval flows through the tool's normal policy (manager approval, auto-approve, JIT expiry, and so on). Once the grant lands, the same call executes normally. **No access path:** @@ -80,7 +80,7 @@ if (blocked) return blocked; ## Agent Behavior After `request_created` 1. Stop that line of work. Do not proceed with dependent steps that need the missing data. -2. Give the user the `task_url` directly, plus which tool it is for. The user (or an approver) acts on it in C1. +2. Give the user the `task_url` directly, plus which tool it is for. The user (or an approver) acts on it in C1.ai. 3. Report what remains blocked so the user knows what will resume. 4. Retry only after the user confirms approval. Retrying before approval returns the same envelope, and may re-surface the same pending task. 5. If part of the task is independently answerable with tools that did succeed, complete that part and state clearly what is still blocked. @@ -102,15 +102,15 @@ In both cases, report what happened and stop. Do not retry with the same input, ## How a Caller Gets Access -Tool access is granted through C1's normal request-and-approval flow. Approved tools are bundled into **toolsets**, toolsets are bound to **access profiles**, and a user requests the access profile: +Tool access is granted through C1.ai's normal request-and-approval flow. Approved tools are bundled into **toolsets**, toolsets are bound to **access profiles**, and a user requests the access profile: -1. In C1, go to **Requests**. Access profiles containing toolsets appear in the catalog next to app entitlements, each showing which toolset it grants, which tools are in it, and the approval policy (auto-approve, requires approval, or JIT with an expiry). +1. In C1.ai, go to **Requests**. Access profiles containing toolsets appear in the catalog next to app entitlements, each showing which toolset it grants, which tools are in it, and the approval policy (auto-approve, requires approval, or JIT with an expiry). 2. Open the access profile and click **Request access**, adding a justification if required. -3. Alternatively submit from Slack with `/c1 request` where the C1 Slack integration is installed. The same approval flow runs either way. +3. Alternatively submit from Slack with `/c1 request` where the C1.ai Slack integration is installed. The same approval flow runs either way. 4. Track status on **My requests**; notifications arrive by Slack or email depending on tenant configuration. A `request_created` envelope has already filed this request — the user follows the `task_url` rather than starting a new one. -Once approved, the granted tools become callable from the user's AI client, usually after the connection refreshes. Some upstream services also require the user's own credentials (per-user OAuth); the user authorizes those from their C1 profile under **AI & API > MCP connections**. +Once approved, the granted tools become callable from the user's AI client, usually after the connection refreshes. Some upstream services also require the user's own credentials (per-user OAuth); the user authorizes those from their C1.ai profile under **AI & API > MCP connections**. Access can also disappear mid-session: a revoked grant, an expired JIT grant, a flipped kill switch, or a client closed for inactivity all cause subsequent calls to return a denial. In-flight calls finish. diff --git a/rap/mcp-gateway/use-async-executions.md b/rap/mcp-gateway/use-async-executions.md index 4644c847..0ce3a881 100644 --- a/rap/mcp-gateway/use-async-executions.md +++ b/rap/mcp-gateway/use-async-executions.md @@ -1,6 +1,6 @@ # Async Executions and Polling -ConductorOne (C1) is an MCP gateway: one MCP endpoint in front of the organization's approved MCP servers. In code mode, the agent runs work by passing a TypeScript program to `execute`. A program that runs longer than the synchronous wait window does not fail — it continues server-side and is collected by polling. +ConductorOne (C1.ai) is an MCP gateway: one MCP endpoint in front of the organization's approved MCP servers. In code mode, the agent runs work by passing a TypeScript program to `execute`. A program that runs longer than the synchronous wait window does not fail — it continues server-side and is collected by polling. ## The Contract diff --git a/rap/mcp-gateway/use-code-mode.md b/rap/mcp-gateway/use-code-mode.md index 66b4c223..21789e2c 100644 --- a/rap/mcp-gateway/use-code-mode.md +++ b/rap/mcp-gateway/use-code-mode.md @@ -1,6 +1,6 @@ # Using Code Mode -ConductorOne (C1) is an MCP gateway: one MCP endpoint in front of the organization's approved MCP servers. In **code mode**, the gateway does not list each upstream tool as its own named tool. It exposes two entrypoints, and the agent invokes upstream tools by writing a short TypeScript program. +ConductorOne (C1.ai) is an MCP gateway: one MCP endpoint in front of the organization's approved MCP servers. In **code mode**, the gateway does not list each upstream tool as its own named tool. It exposes two entrypoints, and the agent invokes upstream tools by writing a short TypeScript program. | Entrypoint | Purpose | |------------|---------| diff --git a/rap/service-principals/INDEX.md b/rap/service-principals/INDEX.md index 91304a50..a7fe2c58 100644 --- a/rap/service-principals/INDEX.md +++ b/rap/service-principals/INDEX.md @@ -1,6 +1,6 @@ # Service Principals Documentation Index -Documentation for C1 service principals and workload federation. Request relevant sections based on user's question. +Documentation for C1.ai service principals and workload federation. Request relevant sections based on user's question. ## How to Use @@ -97,7 +97,7 @@ Documentation for C1 service principals and workload federation. Request relevan User: "How do I authenticate from GitHub Actions?" Retrieve: `platform-github.md` -User: "Set up Terraform with C1" +User: "Set up Terraform with C1.ai" Retrieve: `auth-tools.md`, `platform-terraform.md` User: "How do I authenticate from AWS?" @@ -109,7 +109,7 @@ Retrieve: `manage-credentials.md` User: "CEL expression for specific repository" Retrieve: `security-cel.md`, `platform-github.md` -User: "What environment variables does C1 use?" +User: "What environment variables does C1.ai use?" Retrieve: `concepts-env-vars.md` User: "Difference between client credentials and workload federation" diff --git a/rap/service-principals/auth-tools.md b/rap/service-principals/auth-tools.md index cdc21866..4cc27c94 100644 --- a/rap/service-principals/auth-tools.md +++ b/rap/service-principals/auth-tools.md @@ -1,6 +1,6 @@ # Terraform and Cone CLI -Configure C1 tools with service principal credentials. +Configure C1.ai tools with service principal credentials. ## Terraform Provider diff --git a/rap/service-principals/concepts-env-vars.md b/rap/service-principals/concepts-env-vars.md index 097267a3..d434967e 100644 --- a/rap/service-principals/concepts-env-vars.md +++ b/rap/service-principals/concepts-env-vars.md @@ -1,6 +1,6 @@ # Environment Variables -All C1 client tools recognize these environment variables. +All C1.ai client tools recognize these environment variables. ## Variables diff --git a/rap/service-principals/concepts-overview.md b/rap/service-principals/concepts-overview.md index 4d5bbc16..b3beefca 100644 --- a/rap/service-principals/concepts-overview.md +++ b/rap/service-principals/concepts-overview.md @@ -1,6 +1,6 @@ # Service Principals Overview -Machine identities for C1 API automation. +Machine identities for C1.ai API automation. ## What Service Principals Are @@ -8,7 +8,7 @@ A service principal is a non-human identity for scripts, CI/CD pipelines, Terraf Each service principal has: - Display name and unique ID -- Assigned C1 roles (same as human users) +- Assigned C1.ai roles (same as human users) - One or more owners who manage it - Multiple credentials or federation trusts @@ -27,7 +27,7 @@ Each service principal has: | Aspect | Client Credentials | Workload Federation | |--------|-------------------|---------------------| -| How | Client ID + secret to token endpoint | External OIDC token exchanged for C1 token | +| How | Client ID + secret to token endpoint | External OIDC token exchanged for C1.ai token | | Secrets | Must store and rotate client secret | No secrets - uses CI/CD platform's OIDC | | Best for | Local dev, scripts, cron jobs | GitHub Actions, GitLab CI, HCP Terraform | | Lifetime | Max 180 days, must rotate | No credentials to manage | @@ -44,7 +44,7 @@ A single service principal can use both methods simultaneously. ## Requirements -- Feature must be enabled (contact C1 account team during early access) +- Feature must be enabled (contact C1.ai account team during early access) - Super Admin role required to create service principals ## Limits diff --git a/rap/service-principals/federation-overview.md b/rap/service-principals/federation-overview.md index 64081d12..b2676135 100644 --- a/rap/service-principals/federation-overview.md +++ b/rap/service-principals/federation-overview.md @@ -5,9 +5,9 @@ Secretless authentication using OIDC tokens from CI/CD platforms. ## How It Works 1. CI/CD platform issues signed JWT for current workflow run -2. Workflow sends JWT to C1 token exchange endpoint -3. C1 validates: issuer, signature, audience, freshness, CEL conditions -4. C1 issues short-lived access token scoped to service principal's roles +2. Workflow sends JWT to C1.ai token exchange endpoint +3. C1.ai validates: issuer, signature, audience, freshness, CEL conditions +4. C1.ai issues short-lived access token scoped to service principal's roles No secrets stored. OIDC token valid only for single CI/CD run. diff --git a/rap/service-principals/federation-setup.md b/rap/service-principals/federation-setup.md index 8bd684aa..9270e8f9 100644 --- a/rap/service-principals/federation-setup.md +++ b/rap/service-principals/federation-setup.md @@ -1,6 +1,6 @@ # Setting Up Federation -Create a provider and trust using the C1 wizard. +Create a provider and trust using the C1.ai wizard. ## Prerequisites diff --git a/rap/service-principals/manage-permissions.md b/rap/service-principals/manage-permissions.md index 39c597c2..87535692 100644 --- a/rap/service-principals/manage-permissions.md +++ b/rap/service-principals/manage-permissions.md @@ -36,6 +36,6 @@ Once created, Super Admin can assign owners who then manage independently. ## Assigning Roles -Service principals are assigned C1 roles like human users. Role assignment controlled by Super Admins. +Service principals are assigned C1.ai roles like human users. Role assignment controlled by Super Admins. Credentials and trusts can further restrict effective permissions via scoped roles (intersection of assigned roles and scoped roles). diff --git a/rap/service-principals/platform-aws.md b/rap/service-principals/platform-aws.md index 2a9709f5..d2c9ffed 100644 --- a/rap/service-principals/platform-aws.md +++ b/rap/service-principals/platform-aws.md @@ -17,7 +17,7 @@ aws iam enable-outbound-web-identity-federation aws iam get-outbound-web-identity-federation-info ``` -Returns account-specific issuer URL (e.g., `https://abc123-def456.tokens.sts.global.api.aws`). Use this as the provider issuer URL in C1. +Returns account-specific issuer URL (e.g., `https://abc123-def456.tokens.sts.global.api.aws`). Use this as the provider issuer URL in C1.ai. ### IAM permissions @@ -59,7 +59,7 @@ C1_ACCESS_TOKEN=$(curl -s -X POST \ | jq -r '.access_token') ``` -When using C1 tools (`cone`, Terraform provider), you must set these environment variables. Do not skip this step — the tools require both to be set to handle the token exchange internally: +When using C1.ai tools (`cone`, Terraform provider), you must set these environment variables. Do not skip this step — the tools require both to be set to handle the token exchange internally: ```bash export CONDUCTORONE_OIDC_TOKEN=$AWS_JWT diff --git a/rap/service-principals/platform-github.md b/rap/service-principals/platform-github.md index 1b82398c..b5aa68be 100644 --- a/rap/service-principals/platform-github.md +++ b/rap/service-principals/platform-github.md @@ -32,7 +32,7 @@ jobs: The action: 1. Requests GitHub OIDC token with tenant as audience -2. Exchanges for C1 access token +2. Exchanges for C1.ai access token 3. Exports `CONDUCTORONE_ACCESS_TOKEN` and `CONDUCTORONE_CLIENT_ID` 4. Masks token in logs 5. Cleans up when job finishes diff --git a/rap/service-principals/platform-terraform.md b/rap/service-principals/platform-terraform.md index 0ed278f6..7ed6a28c 100644 --- a/rap/service-principals/platform-terraform.md +++ b/rap/service-principals/platform-terraform.md @@ -1,6 +1,6 @@ # HCP Terraform Integration -C1 Terraform provider auto-detects HCP Terraform workload identity tokens. +C1.ai Terraform provider auto-detects HCP Terraform workload identity tokens. ## Prerequisites diff --git a/rap/service-principals/security-audit.md b/rap/service-principals/security-audit.md index e6c5859e..b1e1fce3 100644 --- a/rap/service-principals/security-audit.md +++ b/rap/service-principals/security-audit.md @@ -1,6 +1,6 @@ # Audit Events -All service principal and workload federation activity recorded in C1 system log. +All service principal and workload federation activity recorded in C1.ai system log. ## Authentication Events @@ -46,4 +46,4 @@ CRUD operations logged as OCSF API Activity events. ## Viewing Events -Navigate to system log in C1 admin console. +Navigate to system log in C1.ai admin console. From 46973ae5d98d34f86504467e111ccf3c57ffcee1 Mon Sep 17 00:00:00 2001 From: Melinda Moreland Date: Wed, 16 Sep 2026 10:21:01 -0700 Subject: [PATCH 3/3] docs: rename C1 to C1.ai in docs.json nav labels Renames the 6 nav-config prose labels that referred to the product by name: site title, "Sign into", "Use", "Administer" tabs, and the "developer tools"/"CLIs" group labels. Leaves "C1 MCP" as-is -- it matches the literal page title and body text of product/admin/c1-mcp.mdx (a live feature name, not prose), consistent with how that page was already handled in PR #541. Co-Authored-By: Claude Sonnet 5 --- docs.json | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/docs.json b/docs.json index da3b3a1f..6ff8c60b 100644 --- a/docs.json +++ b/docs.json @@ -45,12 +45,12 @@ "href": "/", "light": "/logo/dark.svg" }, - "name": "C1 documentation", + "name": "C1.ai documentation", "navbar": { "links": [ { "href": "https://accounts.conductor.one/accounts", - "label": "Sign into C1" + "label": "Sign into C1.ai" } ], "primary": { @@ -88,7 +88,7 @@ ] } ], - "tab": "Use C1" + "tab": "Use C1.ai" }, { "icon": "gear", @@ -404,7 +404,7 @@ ] }, { - "group": "C1 CLIs", + "group": "C1.ai CLIs", "pages": [ { "group": "Cone (for humans)", @@ -427,7 +427,7 @@ ] } ], - "tab": "Administer C1" + "tab": "Administer C1.ai" }, { "icon": "code-merge", @@ -928,7 +928,7 @@ ] }, { - "group": "C1 developer tools", + "group": "C1.ai developer tools", "pages": [ "developer/sdk", "developer/postman",