The SendGrid integration enables security and compliance teams to review who has access to SendGrid in their organization. It connects Drata to SendGrid so your team can monitor user access and roles to support compliance and access governance requirements.
Key Capabilities
User access review data: Review users with access to SendGrid
Role visibility: Monitor assigned roles within the platform
Automated evidence collection: Sync access data into Drata for compliance reviews
This integration is used to automate tests such as user access review verification and privileged access review, helping prove compliance with access control and least privilege policies.
Prerequisites & Data Access
Owner privileges in your SendGrid account
Ability to generate a SendGrid API Key
Required Drata Role with Write access: Admin, Workspace Managers, DevOps Engineer
Access Reviewers (Access Reviewers can only Read the connection page they can’t make changes)
Permissions & Data Table
Permission/Scope | Why It’s Needed |
SendGrid API Key | Allows Drata to authenticate and retrieve SendGrid user access information |
Step-by-Step Setup
Step 1: Generate a SendGrid API Key
Log in to SendGrid.
Navigate to Settings.
Select API Keys.
Select Create API Key.
Enter a name for the API key.
Configure the required permissions for the key.
Create the API key.
Copy and securely store the API key.
Expected outcome: You have a SendGrid API key required to authenticate the integration.
Step 2: Connect SendGrid in Drata
Log in to Drata → go to the Connections page.
Navigate to your Available Connections.
Search for and start the SendGrid connection process.
Enter your SendGrid API Key when prompted.
Expected outcome:
SendGrid is successfully connected and user access data begins syncing to Drata.
Important Notes
This integration is used for User Access Review and focuses on reviewing users and roles within SendGrid.
Ensure the API key is generated from Settings → API Keys → Create API Key in SendGrid.
If your organization uses a Web Application Firewall (WAF), ensure required IP addresses are allowlisted for the integration.
The provided information does not specify the exact IP permissions or scopes required for the API key.
