.png)
BeyondTrust Integration Guide
Connect BeyondTrust product APIs and selected security events with enterprise workflows, service management, identity, and monitoring systems.
BeyondTrust integration options at a glance
BeyondTrust integration is product-specific, with REST APIs as the primary programmatic mechanism for BeyondInsight, Password Safe, Remote Support, and Privileged Remote Access capabilities. Selected products may provide event, notification, audit, or logging integrations, but universal webhook coverage is not confirmed. Martini can authenticate with environment-managed API keys, user credentials, session tokens, or product-specific access configurations, then orchestrate scheduled retrieval, supported event handling, pagination, filtering, mapping, and target-system updates. File-transfer capabilities exist in remote-session contexts, but a general attachment API should not be assumed. Direct database access and general-purpose GraphQL or SOAP APIs are not recommended integration methods.
| Integration point | Supported by BeyondTrust? | Common use cases | How Martini supports it |
|---|---|---|---|
| REST APIs | Yes | BeyondInsight and Password Safe expose documented REST operations for managed accounts, managed systems, requests, sessions, users, and administrative data. Remote-access products expose product-specific functions that require separate validation. | Martini can consume the relevant product REST API, manage authentication, paginate responses, apply filters, transform objects, and write results to enterprise targets. |
| Webhooks / outbound callbacks | Limited | Selected BeyondTrust products may provide event, notification, audit, or integration capabilities for selected security, access, or session events. Universal object-change webhook coverage is not confirmed. | Martini can receive supported webhook-style notifications and then retrieve the complete BeyondTrust object through REST APIs; scheduled reconciliation should cover unsupported events. |
| Event and logging integrations | Limited | Deployments can produce audit, access, and session events for monitoring and security operations, with delivery methods varying by product and deployment. | Martini can normalize supported event or log inputs, enrich them with API data, and forward structured events to monitoring or analytics platforms. |
| File / attachment APIs | Limited | Remote-access products support file transfer during sessions, but a common general-purpose BeyondTrust attachment API was not confirmed. | Martini can orchestrate documented file-transfer or export interfaces when available, while treating session file transfer as product-specific and requiring validation. |
| Bulk / async / batch APIs | Not confirmed | Some administrative operations may support bulk request patterns, but a universal BeyondTrust bulk or asynchronous API was not established. | Martini can implement controlled batching and scheduled workflows around confirmed endpoints without assuming a vendor-wide bulk API. |
| Authentication | Yes | API keys or application keys, user credentials, session or bearer tokens, and product-specific OAuth or SSO configurations may be involved. | Martini can store keys, credentials, client secrets, and tokens in environment-specific secrets and reuse isolated authentication configuration across workflows. |
| Directory integration | Yes | Active Directory and LDAP can support identity and group administration for applicable BeyondTrust products, distinct from the authentication method of a particular API. | Martini can orchestrate related identity synchronization or provisioning workflows where documented APIs and permissions are available. |
| Database access | No | Direct database access is not a recommended application-integration method for BeyondTrust. | Martini should use documented REST APIs, supported exports, audit integrations, or event mechanisms instead of connecting directly to product databases. |
How BeyondTrust exposes data and business events
BeyondTrust REST APIs
REST APIs are the principal programmatic integration mechanism across BeyondTrust products, but resources, authentication, identifiers, and fields vary between Password Safe, BeyondInsight, Remote Support, and Privileged Remote Access. The relevant product and API version must be selected before implementation.
Martini implementation pattern
Martini implementation pattern: a workflow acquires or refreshes the required BeyondTrust session, calls product-specific endpoints with documented pagination and filters, maps the response into a canonical model, applies business rules, and writes to the target system. Authentication, authorization, and error handling remain separate from business mappings.
Implementation sequence
BeyondTrust event and notification integrations
BeyondTrust products can provide selected audit, access, session, event, or notification integrations, but universal webhook coverage for every object and event is not confirmed. Delivery methods and event coverage must be validated for the deployed product.
Martini implementation pattern
Martini implementation pattern: receive a supported notification when available, validate its authenticity and event type, use the notification as a trigger to retrieve the complete object through the REST API, and use scheduled reconciliation for events without supported notifications.
Implementation sequence
BeyondTrust scheduled synchronization
Scheduled REST polling is the dependable fallback for resources without documented event coverage. It is suitable for inventory, request status, session reporting, and reconciliation workflows.
Martini implementation pattern
Martini implementation pattern: a scheduler starts a workflow, the workflow reads a persisted high-water mark or overlap window, retrieves changed resources page by page, processes each object idempotently, and stores the new checkpoint only after successful target writes.
Implementation sequence
Common BeyondTrust integration patterns
Pattern 1: Synchronize Password Safe requests with ServiceNow
When to use this pattern
Use this pattern when privileged-access approvals must be visible in the service-management process. Requests can be polled or driven by a supported event, then enriched with related Managed Accounts and Managed Systems before the target ticket is updated.
Integration direction
Example Mapping
| BeyondTrust Field | Canonical Field | Target Field |
|---|---|---|
| Request.id | accessRequestId | Correlation ID |
| Request.status | accessRequestStatus | Approval status |
| Managed Account.name | managedAccountName | Privileged account |
| Managed System.name | managedSystemName | Configuration item |
Martini implementation pattern
A Martini workflow retrieves the request and related objects, validates status transitions, applies approval and least-privilege rules, and performs an idempotent ServiceNow update. Request identifiers are stored for correlation, while transient API failures are retried and authorization failures are routed for review.
Martini capabilities used
- workflows
- API consumption
- data mapping
- business rules
- idempotency
- error handling
Pattern 2: Forward privileged sessions to security monitoring
When to use this pattern
Use this pattern when security teams need centralized visibility into BeyondTrust privileged activity. Session metadata and supported audit events are normalized before delivery to a monitoring platform.
Integration direction
Example Mapping
| BeyondTrust Field | Canonical Field | Target Field |
|---|---|---|
| Session.user | actor | user |
| Session.system | resource | dest |
| Session.startTime | startedAt | start_time |
| Session.outcome | result | action_result |
Martini implementation pattern
Martini retrieves supported Sessions or receives selected audit notifications, enriches incomplete events through REST retrieval, normalizes timestamps and outcomes, and sends structured events to Splunk. Duplicate session identifiers are deduplicated and failed deliveries are retried without exposing credentials or sensitive session content.
Martini capabilities used
- event-driven workflows
- scheduled synchronization
- data transformation
- API consumption
- retry handling
- monitoring
Pattern 3: Synchronize managed account and system inventory
When to use this pattern
Use this pattern when the Password Safe inventory must align with an enterprise asset repository or CMDB. It supports incremental retrieval where the relevant API provides modification filters and reconciliation when it does not.
Integration direction
Example Mapping
| BeyondTrust Field | Canonical Field | Target Field |
|---|---|---|
| Managed System.id | sourceSystemId | External ID |
| Managed System.name | hostname | Name |
| Managed Account.name | accountName | Privileged account |
| Managed System.modifiedDate | lastChangedAt | Updated |
Martini implementation pattern
A scheduled Martini workflow retrieves changed Managed Systems and Managed Accounts, maps source identifiers to CMDB records, validates required fields, and upserts records. A durable checkpoint with an overlap window supports recovery from late-arriving changes, while duplicate records are prevented through stable external keys.
Martini capabilities used
- scheduler triggers
- workflows
- pagination
- mapping
- validation
- checkpointing
Pattern 4: Report Remote Support sessions
When to use this pattern
Use this pattern when support operations or compliance teams need Remote Support session activity associated with service cases. The exact fields and endpoints must be confirmed for the deployed Remote Support edition.
Integration direction
Example Mapping
| BeyondTrust Field | Canonical Field | Target Field |
|---|---|---|
| Support Session.id | supportSessionId | Session reference |
| Representative.id | agentId | Assignee reference |
| Customer.id | customerId | Customer reference |
| Queue.name | supportQueue | Queue |
Martini implementation pattern
Martini retrieves completed Support Sessions and related Representatives, Customers, Queues, and Jump Clients, correlates them with Jira issues where a case key is available, and publishes operational data. Missing relationships are quarantined for review and retried retrieval is controlled by session identifiers and completion timestamps.
Martini capabilities used
- API consumption
- workflow orchestration
- data correlation
- mapping
- validation
- error handling
Applications commonly integrated with BeyondTrust
BeyondTrust is commonly positioned alongside service management, security monitoring, identity, and privileged-access platforms. Exact integration behavior depends on the BeyondTrust product, deployment model, API version, and enabled modules.
| Application | Scenario | Direction | Martini Pattern |
|---|---|---|---|
| ServiceNow | Link privileged-access requests, approvals, incidents, and configuration items with BeyondTrust activity. | ServiceNow → Martini → BeyondTrust | Use a Martini workflow to receive or poll ServiceNow requests, call BeyondTrust APIs for Requests and related Managed Accounts or Managed Systems, apply approval rules, and synchronize status using durable request identifiers. |
| Splunk | Centralize BeyondTrust privileged-session, authentication, and audit data for investigation and security monitoring. | BeyondTrust → Martini → Splunk | Retrieve supported session or audit data through BeyondTrust APIs or logging mechanisms, normalize the events in Martini, and forward structured records with correlation identifiers and retry handling. |
| Microsoft Sentinel | Correlate BeyondTrust privileged-access events with identity, endpoint, and cloud security telemetry. | BeyondTrust → Martini → Microsoft Sentinel | Use scheduled REST retrieval or supported event delivery, transform BeyondTrust Sessions and audit events into the target security schema, and route transient failures through bounded retries. |
| Active Directory | Use enterprise users and groups for BeyondTrust identity administration and access control where the deployed product supports directory integration. | Active Directory → Martini → BeyondTrust | Treat directory integration as a product capability rather than a universal BeyondTrust API. Where API synchronization is required, Martini can orchestrate directory-derived identity data and BeyondTrust API updates under least-privilege rules. |
| Okta | Provide federated identity or SSO for BeyondTrust users where the selected product supports the required federation path. | Okta → Martini → BeyondTrust | Use Martini for surrounding provisioning, audit, or reconciliation workflows while product-specific SSO and federation remain configured according to BeyondTrust and Okta capabilities. |
| Jira Service Management | Associate privileged-access requests or remote-support activity with service tickets and change records. | Jira Service Management → Martini → BeyondTrust | Map Jira issues or approvals to BeyondTrust Requests, retrieve related object details, and synchronize outcomes and session references with idempotent updates. |
| CyberArk | Compare or coordinate privileged-account inventories and governance processes in environments using multiple PAM products. | BeyondTrust → Martini → CyberArk | Use product APIs to extract approved inventory or audit fields, normalize them in Martini, and deliver comparison or governance data to CyberArk or a shared repository; treat this as a custom design rather than a standard native integration. |
How to build a BeyondTrust integration in Martini
Objective
Identify the exact BeyondTrust product and API version, then configure its base URL and product-specific authentication without embedding secrets in workflows.
Instructions in Martini
- Select the relevant BeyondTrust product, deployment, and API version
- Configure API keys, credentials, client secrets, or token settings in Martini environment configuration
- Use a dedicated service account with narrowly scoped permissions
- Separate development, test, and production credentials
Objective
Select a supported product notification when available; otherwise use scheduled REST polling with a durable checkpoint and overlap window.
Instructions in Martini
- Validate whether the required event has documented notification coverage
- Use a webhook-style trigger only for supported product events
- Configure a scheduler for inventory, reporting, and reconciliation workflows
- Define the polling interval, overlap window, and checkpoint strategy
Objective
Call the appropriate BeyondTrust REST resources and retrieve complete objects rather than relying only on notification payloads.
Instructions in Martini
- Acquire or refresh the BeyondTrust session or access token
- Use documented pagination, filtering, and continuation behavior
- Retrieve related objects such as Managed Accounts and Managed Systems when required
- Capture source identifiers, timestamps, and response status
Objective
Build the Martini workflow that coordinates retrieval, enrichment, validation, target writes, and recovery behavior.
Instructions in Martini
- Branch by product object or event type where necessary
- Separate authentication, retrieval, mapping, and target operations
- Apply authorization and lifecycle rules before privileged operations
- Record correlation identifiers for auditability
Objective
Convert product-specific BeyondTrust objects into a stable canonical model and target-specific payloads.
Instructions in Martini
- Map actual objects such as Requests, Sessions, Representatives, and Jump Clients
- Normalize timestamps, statuses, identifiers, and enumerations
- Validate required fields before downstream writes
- Preserve relevant unknown audit fields where practical
Objective
Create or update service-management, monitoring, identity, inventory, or reporting records with idempotent behavior.
Instructions in Martini
- Use stable BeyondTrust IDs as external correlation keys
- Apply target-specific create and update rules
- Avoid persisting passwords, tokens, or sensitive session content
- Only advance synchronization checkpoints after successful writes
Common BeyondTrust data objects used in integrations
| Object | Typical Use | Common target systems | Martini handling |
|---|---|---|---|
| Managed Accounts | Represent privileged or service accounts managed through Password Safe. | ServiceNow, asset inventories, CyberArk, governance repositories | Martini retrieves account metadata through product-specific REST endpoints, maps identifiers and lifecycle fields, and performs idempotent creates or updates. |
| Managed Systems | Represent servers, network devices, databases, and other systems associated with managed accounts. | ServiceNow CMDB, asset platforms, security analytics | Martini uses incremental filters or a durable high-water mark where available, validates required fields, and reconciles source identifiers with target configuration records. |
| Requests | Represent requests to obtain access to a managed account or system. | ServiceNow, Jira Service Management, approval repositories | Martini correlates requests by stable identifiers, maps status transitions explicitly, applies authorization rules, and prevents duplicate downstream updates. |
| Sessions | Represent privileged or remote-access sessions and associated metadata. | Splunk, Microsoft Sentinel, data warehouses, service-management platforms | Martini retrieves supported session data, normalizes user, system, start, end, and outcome fields, and forwards audit data without exposing sensitive credentials. |
| Representatives | Represent support or privileged-access personnel who initiate remote sessions. | ServiceNow, Jira Service Management, reporting platforms | Martini maps representative identifiers and attributes to support or audit models after validating the relevant Remote Support or Privileged Remote Access API. |
| Jump Clients | Represent endpoint agents used to establish managed remote-access connections. | ServiceNow CMDB, asset inventories, reporting platforms | Martini synchronizes documented metadata, applies product-specific field mappings, and records source identifiers for reconciliation. |
Authentication and security considerations
Product-specific authentication
BeyondTrust API authentication varies by product and deployment. Common patterns include administrator-created API or application keys, user credentials, session or bearer tokens, and selected OAuth or federated identity configurations.
Secret and privilege management
- Store API keys, passwords, client secrets, and tokens in Martini environment secrets.
- Use dedicated service accounts with the minimum product permissions required.
- Separate authentication configuration from mappings and business logic.
- Protect logs and workflow data from exposing credentials, authorization headers, passwords, or sensitive session content.
Operational considerations for BeyondTrust integrations
Pagination and incremental retrieval
Do not assume that one request returns all BeyondTrust objects. Follow the product's documented page, offset, cursor, or continuation behavior and use server-side filters where available.
Resilience and reconciliation
- Confirm rate limits and concurrency guidance for the selected deployment.
- Use bounded exponential backoff for transient HTTP failures.
- Use stable object, request, and session identifiers for idempotency.
- Maintain a high-water mark with an overlap window for scheduled synchronization.
- Use reconciliation workflows for missed notifications or temporary API outages.
Version and schema management
BeyondTrust resources, fields, status values, and authentication behavior can differ by product and API version. Validate required fields, preserve useful audit fields where practical, and test mappings against the deployed version before production release.
Why use Martini instead of scripts or point-to-point integrations?
Orchestration beyond a script
Martini provides a maintainable workflow layer for authentication, API retrieval, event handling, pagination, mapping, business rules, target updates, and recovery behavior. This avoids embedding the full integration lifecycle in one-off scripts.
Reusable enterprise integration behavior
Teams can separate secrets and environment configuration from reusable workflows, expose controlled APIs for downstream applications, and apply consistent validation, retries, idempotency, logging, and monitoring across BeyondTrust integrations.
Adaptability across products
Because BeyondTrust APIs differ across Password Safe, BeyondInsight, Remote Support, and Privileged Remote Access, Martini's API consumption and transformation capabilities allow each product-specific payload to be mapped into a common enterprise model without assuming a single universal connector.
Frequently asked questions
BeyondTrust is integrated primarily through product-specific REST APIs, supplemented by selected event, notification, audit, logging, directory, or file-transfer mechanisms. The exact approach depends on whether the integration targets Password Safe, BeyondInsight, Privileged Remote Access, Remote Support, or another product.
Yes. Martini can consume BeyondTrust REST APIs, authenticate with product-specific credentials or tokens, orchestrate scheduled and event-driven workflows, map objects such as Requests and Sessions, and send results to enterprise systems. Supported product notifications can also trigger workflows where available.
No. A dedicated BeyondTrust connector is not required. Martini can integrate using BeyondTrust's documented REST APIs, supported product-specific notifications, authentication methods, audit or logging mechanisms, and other confirmed endpoints.
Lonti does not charge an additional per-connector or per-vendor fee to integrate BeyondTrust. Integrations are subject to the provisioned capacity of the Martini environment. Separate costs may apply from BeyondTrust, infrastructure providers, or other third-party systems depending on subscription, usage, and deployment model.
REST APIs are the primary recommended mechanism for current programmatic integrations. Selected event, notification, audit, or logging methods can be used when confirmed for the product and event type. General-purpose GraphQL and SOAP APIs were not confirmed, and direct database access is not recommended.
Selected BeyondTrust products provide product-specific event, notification, audit, or integration capabilities, but universal webhook coverage for all object changes is not confirmed. Martini can receive supported notifications and retrieve the full object, while scheduled REST reconciliation covers unsupported or missed events.
Martini can use event-triggered retrieval where supported or scheduled REST polling for inventory, requests, sessions, and reconciliation. Workflows use pagination, filters, high-water marks or overlap windows, stable source IDs, idempotent upserts, and checkpoints that advance only after successful target processing.
Martini workflows can capture HTTP status codes and BeyondTrust error payloads, distinguish authorization and validation failures from transient errors, apply bounded retries with backoff, and route unresolved failures for review. Stable request, session, account, and system identifiers support idempotency and duplicate-event protection.
Related Martini documentation
Workflows
Connect BeyondTrust with enterprise systems
Use Martini to build secure, maintainable BeyondTrust integrations across privileged access, service management, security monitoring, identity, and operational reporting.