How connectors work
Every integration in Plugboard is a connector. The application never depends on Jamf, or Synergetic, or Zendesk. It depends on a capability, and a connector declares which capabilities it implements.
That is why a school running Intune and one running Jamf use the same repairs screen, and why swapping an MDM is a configuration change rather than a project.
The three words
Section titled “The three words”Capability. A named operation the platform can ask for:
device.lookupBySerial, sis.getRoster, email.send. Full list in
capabilities.
Connector. A definition: a category, an authentication kind, a configuration form, a secret form, and the capabilities it implements.
Connector instance. A connector you have configured, with your URL and your credentials. Credentials are encrypted before they touch the database.
When a feature needs something done it asks for a capability. The platform finds an enabled instance implementing it and calls the handler. If there is no such instance, the feature says so plainly rather than failing obscurely.
The catalogue
Section titled “The catalogue”The guides below cover common integrations. The generated connector reference lists every registered provider and distinguishes live handlers, demo workflows, blocked actions and unsupported contracts. A registered handler alone is not a promise that an operation works in live mode or is available in your deployed release.
Admin orders the catalogue by setup priority from 0.14.2. Core identity, device and student systems come before supporting integrations; new providers stay in their relevant category. The guides below are grouped for reference.
AV, rooms and school operations
Section titled “AV, rooms and school operations”- Q-SYS, PJLink, Crestron XiO Cloud and Zoom Rooms provide read-only monitoring. Hardware and vendor-account pilots are required before production rollout. Extron and Teams Rooms adapters remain planned.
- TeamViewer adds device status through explicit mappings to existing remote support targets; it does not create or control a remote session.
- Xero and MYOB support reviewed purchasing exports after authorization, account/tax mapping and the required approvals.
- Microsoft 365 and Google calendars, Teams Workflows and Google Chat extend the existing directory connections with explicit work-item publishing.
See School operations for the supported operations, setup requirements and provider limits, and Remote support for TeamViewer status.
Device management (MDM)
Section titled “Device management (MDM)”| Connector | Auth | Notes |
|---|---|---|
| Jamf Pro | OAuth client credentials | The most capable. Supports smart group pull for loan pools |
| Microsoft Intune | OAuth client credentials | Via Microsoft Graph |
| Kandji | API token | |
| Mosyle | API token | Manager and Business. Common in Apple-heavy schools |
| Chrome Enterprise | Service account | Chromebooks, via the Google Admin SDK |
| Mock MDM | Any | For demos and tests |
Student information (SIS)
Section titled “Student information (SIS)”| Connector | Auth | Notes |
|---|---|---|
| Synergetic | API token | Common in independent schools. Reaches a private network |
| Sentral | API key plus tenant key | Widespread in New South Wales |
| Compass Education | Service account credentials | Dominant in Victoria |
| OneRoster | OAuth 2 client credentials | Read-only 1.1/1.2 roster preview; school-provider validation required |
Identity and directory
Section titled “Identity and directory”| Connector | Auth | Notes |
|---|---|---|
| LDAP and Active Directory | Bind account | Authenticate, look up, reset passwords. Reaches a private network |
| Directory management | Provider-dependent | Legacy directory actions use demo data. Live identity support varies by provider; see the generated reference |
Email and SMS
Section titled “Email and SMS”| Connector | Auth | Notes |
|---|---|---|
| SMTP | Username and password | Any SMTP server. The simplest option |
| Google Workspace | Service account | Sends via the Gmail API with delegation |
| Console email | None | Logs instead of sending. Development only |
| Twilio | Account SID and auth token | SMS |
Ticketing
Section titled “Ticketing”| Connector | Auth | Notes |
|---|---|---|
| Zendesk | API token | Create, comment on and close tickets |
| Web Help Desk | API key | SolarWinds. Reaches a private network |
Warranty and repair vendors
Section titled “Warranty and repair vendors”| Connector | Auth | Notes |
|---|---|---|
| Apple GSX | API token | Warranty and AppleCare coverage |
| Dell warranty | Client credentials | Entitlement by service tag |
| CompNow | API token | Lodge external repairs and sync status |
Printing
Section titled “Printing”| Connector | Auth | Notes |
|---|---|---|
| Printers over SNMP | SNMP community string | Toner, status and errors. Reaches a private network |
| PaperCut | Auth token | Balances, page counts, and writing the tap card. Reaches a private network |
Everything else
Section titled “Everything else”| Connector | Category | Notes |
|---|---|---|
| ThreatLocker | Security | Endpoint allowlisting approvals |
| Salesforce | CRM | Accounts, contacts and cases |
| Google Sheets | Spreadsheet | Induction roster import |
| Ollama | AI | A separately configured local model; container deployments can use a sidecar |
| Anthropic | AI | Claude, on your own key |
| OpenAI-compatible | AI | Any OpenAI-style endpoint, hosted or your own GPU box |
Choosing between connectors that overlap
Section titled “Choosing between connectors that overlap”More than one MDM. You can configure several, and a device resolves through whichever one knows it, which is what a mixed fleet needs: Jamf for Macs, Intune for Windows, Chrome Enterprise for Chromebooks.
More than one SIS. Unusual, but supported. Rosters merge and people are de-duplicated.
Email. Pick one. SMTP is simpler and works with anything. Google Workspace sends as a real mailbox in your domain, which some schools prefer for deliverability.
Ticketing. If you already run Zendesk or Web Help Desk, connect it and switch
off the built-in module.tickets. Running both queues means work gets lost
between them.
How many you can configure
Section titled “How many you can configure”Core includes three connectors. Standard and above are unlimited.
Adding one past the limit is refused, and tells you what to do about it. Nothing already configured is ever touched: reconfiguring an existing connector is always allowed, and deployments licensed before the cap existed stay uncapped.
Connectors installed on first run, meaning the bundled AI model and vendor-hosted AI, do not count against your allowance.
Admin, Licence shows connectors used against the limit.
Demo mode
Section titled “Demo mode”Most connectors have a demo mode that returns realistic fictional data instead of calling the real system.
Turn it on to see a feature work before credentials arrive, then turn it off. Leaving it on in production is the most common configuration mistake in the product. The compliance page counts connectors still in demo mode, precisely so it gets noticed.
Connectors that need a private network
Section titled “Connectors that need a private network”Some connectors talk to something that normally lives inside a school network: Active Directory, a Synergetic SQL Server, PaperCut, a printer answering SNMP, Web Help Desk.
A self-hosted install on that network reaches them directly and needs nothing extra.
A managed deployment cannot, and uses a connector agent: a small program installed inside your network which dials out, collects queued work and returns results. No inbound firewall rule.
Note the framing: whether an agent is needed depends on where the deployment runs, not on the connector.
Security
Section titled “Security”Connector credentials are protected with envelope encryption. They are encrypted before they reach the database and decrypted in memory only for the duration of a call. A connector handler never gets database access; it returns data and the platform decides what to persist.
The master key is SECRETS_MASTER_KEY. See secrets and
keys.
- Configuring a connector for the mechanics.
- Connector agents if you are hosted and need private systems.
- Getting one built if the system you run is not in the catalogue.