The Ashby integration enables security and compliance teams to monitor individual user access and roles within your Ashby platform for compliance purposes.
It connects Drata to Ashby through an API key, allowing Drata to automate access verification and evidence collection for compliance testing.
Key Capabilities
User Access Monitoring: Tracks individuals’ access and roles in Ashby for compliance.
Automated Evidence Collection: Syncs user access information into Drata to streamline reviews.
Prerequisites & Data Access
Must have Admin, Information Security Lead, DevOps Engineer, or Workspace Manager roles in Drata.
Must have Organization Administrator privileges within your Ashby account.
Must be able to generate an API key in Ashby.
API key must include read permission for the Organization module.
Refer to Ashby’s official documentation for details on setting up permissions and generating API keys.
Note: Web Application Firewall (WAF) allowlisting is not typically required for this integration since Drata connects securely over HTTPS. Only allowlist Drata IPs if your organization enforces strict outbound network restrictions.
Permissions & Data Table
Permission/Scope | Why It’s Needed | Data Accessed (Read Only) |
Organization module — read | Allows Drata to retrieve user access and role information for compliance monitoring. | User roles and organizational access data |
Step-by-Step Setup
Step 1: Generate an API Key in Ashby
Log in to your Ashby account with an Organization Administrator role.
Navigate to API Key Management (refer to Ashby’s documentation for exact navigation).
Create a new API key.
Under Endpoint Permissions, select read permission for the Organization module.
Copy the generated API key and store it securely. You will need it when connecting to Drata.
Expected outcome: You now have a valid API key with the correct endpoint permissions to connect to Drata.
Step 2: Complete the Connection in Drata
In Drata, navigate to Connections → Available Connections.
Search for Ashby and select Connect.
Enter the following information:
Drata Field | Ashby Value |
API Key | API key with read permission for the Organization module |
Troubleshoot
If an error message is displayed after connecting, ensure that your API key has the correct endpoint permissions.