Skip to content

How connectors work

Every integration in Plugboard is a connector. The application never depends on Jamf, or Synergetic, or Zendesk. It depends on a capability, and a connector declares which capabilities it implements.

That is why a school running Intune and one running Jamf use the same repairs screen, and why swapping an MDM is a configuration change rather than a project.

Capability. A named operation the platform can ask for: device.lookupBySerial, sis.getRoster, email.send. Full list in capabilities.

Connector. A definition: a category, an authentication kind, a configuration form, a secret form, and the capabilities it implements.

Connector instance. A connector you have configured, with your URL and your credentials. Credentials are encrypted before they touch the database.

When a feature needs something done it asks for a capability. The platform finds an enabled instance implementing it and calls the handler. If there is no such instance, the feature says so plainly rather than failing obscurely.

The guides below cover common integrations. The generated connector reference lists every registered provider and distinguishes live handlers, demo workflows, blocked actions and unsupported contracts. A registered handler alone is not a promise that an operation works in live mode or is available in your deployed release.

Admin orders the catalogue by setup priority from 0.14.2. Core identity, device and student systems come before supporting integrations; new providers stay in their relevant category. The guides below are grouped for reference.

  • Q-SYS, PJLink, Crestron XiO Cloud and Zoom Rooms provide read-only monitoring. Hardware and vendor-account pilots are required before production rollout. Extron and Teams Rooms adapters remain planned.
  • TeamViewer adds device status through explicit mappings to existing remote support targets; it does not create or control a remote session.
  • Xero and MYOB support reviewed purchasing exports after authorization, account/tax mapping and the required approvals.
  • Microsoft 365 and Google calendars, Teams Workflows and Google Chat extend the existing directory connections with explicit work-item publishing.

See School operations for the supported operations, setup requirements and provider limits, and Remote support for TeamViewer status.

Connector Auth Notes
Jamf Pro OAuth client credentials The most capable. Supports smart group pull for loan pools
Microsoft Intune OAuth client credentials Via Microsoft Graph
Kandji API token
Mosyle API token Manager and Business. Common in Apple-heavy schools
Chrome Enterprise Service account Chromebooks, via the Google Admin SDK
Mock MDM Any For demos and tests
Connector Auth Notes
Synergetic API token Common in independent schools. Reaches a private network
Sentral API key plus tenant key Widespread in New South Wales
Compass Education Service account credentials Dominant in Victoria
OneRoster OAuth 2 client credentials Read-only 1.1/1.2 roster preview; school-provider validation required
Connector Auth Notes
LDAP and Active Directory Bind account Authenticate, look up, reset passwords. Reaches a private network
Directory management Provider-dependent Legacy directory actions use demo data. Live identity support varies by provider; see the generated reference
Connector Auth Notes
SMTP Username and password Any SMTP server. The simplest option
Google Workspace Service account Sends via the Gmail API with delegation
Console email None Logs instead of sending. Development only
Twilio Account SID and auth token SMS
Connector Auth Notes
Zendesk API token Create, comment on and close tickets
Web Help Desk API key SolarWinds. Reaches a private network
Connector Auth Notes
Apple GSX API token Warranty and AppleCare coverage
Dell warranty Client credentials Entitlement by service tag
CompNow API token Lodge external repairs and sync status
Connector Auth Notes
Printers over SNMP SNMP community string Toner, status and errors. Reaches a private network
PaperCut Auth token Balances, page counts, and writing the tap card. Reaches a private network
Connector Category Notes
ThreatLocker Security Endpoint allowlisting approvals
Salesforce CRM Accounts, contacts and cases
Google Sheets Spreadsheet Induction roster import
Ollama AI A separately configured local model; container deployments can use a sidecar
Anthropic AI Claude, on your own key
OpenAI-compatible AI Any OpenAI-style endpoint, hosted or your own GPU box

More than one MDM. You can configure several, and a device resolves through whichever one knows it, which is what a mixed fleet needs: Jamf for Macs, Intune for Windows, Chrome Enterprise for Chromebooks.

More than one SIS. Unusual, but supported. Rosters merge and people are de-duplicated.

Email. Pick one. SMTP is simpler and works with anything. Google Workspace sends as a real mailbox in your domain, which some schools prefer for deliverability.

Ticketing. If you already run Zendesk or Web Help Desk, connect it and switch off the built-in module.tickets. Running both queues means work gets lost between them.

Core includes three connectors. Standard and above are unlimited.

Adding one past the limit is refused, and tells you what to do about it. Nothing already configured is ever touched: reconfiguring an existing connector is always allowed, and deployments licensed before the cap existed stay uncapped.

Connectors installed on first run, meaning the bundled AI model and vendor-hosted AI, do not count against your allowance.

Admin, Licence shows connectors used against the limit.

Most connectors have a demo mode that returns realistic fictional data instead of calling the real system.

Turn it on to see a feature work before credentials arrive, then turn it off. Leaving it on in production is the most common configuration mistake in the product. The compliance page counts connectors still in demo mode, precisely so it gets noticed.

Some connectors talk to something that normally lives inside a school network: Active Directory, a Synergetic SQL Server, PaperCut, a printer answering SNMP, Web Help Desk.

A self-hosted install on that network reaches them directly and needs nothing extra.

A managed deployment cannot, and uses a connector agent: a small program installed inside your network which dials out, collects queued work and returns results. No inbound firewall rule.

Note the framing: whether an agent is needed depends on where the deployment runs, not on the connector.

Connector credentials are protected with envelope encryption. They are encrypted before they reach the database and decrypted in memory only for the duration of a call. A connector handler never gets database access; it returns data and the platform decides what to persist.

The master key is SECRETS_MASTER_KEY. See secrets and keys.