Ellipse Gradient for Header

BeyondTrust Integration Guide

Connect BeyondTrust product APIs and selected security events with enterprise workflows, service management, identity, and monitoring systems.

BeyondTrust integration options at a glance

BeyondTrust integration is product-specific, with REST APIs as the primary programmatic mechanism for BeyondInsight, Password Safe, Remote Support, and Privileged Remote Access capabilities. Selected products may provide event, notification, audit, or logging integrations, but universal webhook coverage is not confirmed. Martini can authenticate with environment-managed API keys, user credentials, session tokens, or product-specific access configurations, then orchestrate scheduled retrieval, supported event handling, pagination, filtering, mapping, and target-system updates. File-transfer capabilities exist in remote-session contexts, but a general attachment API should not be assumed. Direct database access and general-purpose GraphQL or SOAP APIs are not recommended integration methods.

Integration pointSupported by BeyondTrust?Common use casesHow Martini supports it
REST APIsYesBeyondInsight and Password Safe expose documented REST operations for managed accounts, managed systems, requests, sessions, users, and administrative data. Remote-access products expose product-specific functions that require separate validation.Martini can consume the relevant product REST API, manage authentication, paginate responses, apply filters, transform objects, and write results to enterprise targets.
Webhooks / outbound callbacksLimitedSelected BeyondTrust products may provide event, notification, audit, or integration capabilities for selected security, access, or session events. Universal object-change webhook coverage is not confirmed.Martini can receive supported webhook-style notifications and then retrieve the complete BeyondTrust object through REST APIs; scheduled reconciliation should cover unsupported events.
Event and logging integrationsLimitedDeployments can produce audit, access, and session events for monitoring and security operations, with delivery methods varying by product and deployment.Martini can normalize supported event or log inputs, enrich them with API data, and forward structured events to monitoring or analytics platforms.
File / attachment APIsLimitedRemote-access products support file transfer during sessions, but a common general-purpose BeyondTrust attachment API was not confirmed.Martini can orchestrate documented file-transfer or export interfaces when available, while treating session file transfer as product-specific and requiring validation.
Bulk / async / batch APIsNot confirmedSome administrative operations may support bulk request patterns, but a universal BeyondTrust bulk or asynchronous API was not established.Martini can implement controlled batching and scheduled workflows around confirmed endpoints without assuming a vendor-wide bulk API.
AuthenticationYesAPI keys or application keys, user credentials, session or bearer tokens, and product-specific OAuth or SSO configurations may be involved.Martini can store keys, credentials, client secrets, and tokens in environment-specific secrets and reuse isolated authentication configuration across workflows.
Directory integrationYesActive Directory and LDAP can support identity and group administration for applicable BeyondTrust products, distinct from the authentication method of a particular API.Martini can orchestrate related identity synchronization or provisioning workflows where documented APIs and permissions are available.
Database accessNoDirect database access is not a recommended application-integration method for BeyondTrust.Martini should use documented REST APIs, supported exports, audit integrations, or event mechanisms instead of connecting directly to product databases.

How BeyondTrust exposes data and business events

BeyondTrust REST APIs

REST APIs are the principal programmatic integration mechanism across BeyondTrust products, but resources, authentication, identifiers, and fields vary between Password Safe, BeyondInsight, Remote Support, and Privileged Remote Access. The relevant product and API version must be selected before implementation.

Martini implementation pattern

Martini implementation pattern: a workflow acquires or refreshes the required BeyondTrust session, calls product-specific endpoints with documented pagination and filters, maps the response into a canonical model, applies business rules, and writes to the target system. Authentication, authorization, and error handling remain separate from business mappings.

Implementation sequence

Identify the BeyondTrust product, deployment, API version, and base URL
Load API keys and credentials from Martini environment secrets
Acquire or refresh the required session or access token
Retrieve paginated resources using documented filters
Map BeyondTrust objects to the target model
Apply authorization and lifecycle business rules before writing changes

BeyondTrust event and notification integrations

BeyondTrust products can provide selected audit, access, session, event, or notification integrations, but universal webhook coverage for every object and event is not confirmed. Delivery methods and event coverage must be validated for the deployed product.

Martini implementation pattern

Martini implementation pattern: receive a supported notification when available, validate its authenticity and event type, use the notification as a trigger to retrieve the complete object through the REST API, and use scheduled reconciliation for events without supported notifications.

Implementation sequence

Receive the supported BeyondTrust notification or event
Validate the event type and source correlation identifier
Retrieve the current BeyondTrust object through the product API
Map and enrich the event for the target platform
Apply idempotent upsert and audit rules
Run scheduled reconciliation for missed or unsupported events

BeyondTrust scheduled synchronization

Scheduled REST polling is the dependable fallback for resources without documented event coverage. It is suitable for inventory, request status, session reporting, and reconciliation workflows.

Martini implementation pattern

Martini implementation pattern: a scheduler starts a workflow, the workflow reads a persisted high-water mark or overlap window, retrieves changed resources page by page, processes each object idempotently, and stores the new checkpoint only after successful target writes.

Implementation sequence

Start the workflow on a defined schedule
Read the prior checkpoint and overlap window
Retrieve changed resources with server-side filters where available
Process each page and persist source identifiers
Retry transient failures with bounded backoff
Store the checkpoint after successful processing

Common BeyondTrust integration patterns

Pattern 1: Synchronize Password Safe requests with ServiceNow

When to use this pattern

Use this pattern when privileged-access approvals must be visible in the service-management process. Requests can be polled or driven by a supported event, then enriched with related Managed Accounts and Managed Systems before the target ticket is updated.

Integration direction
BeyondTrust
Martini
ServiceNow
Example Mapping
BeyondTrust FieldCanonical FieldTarget Field
Request.idaccessRequestIdCorrelation ID
Request.statusaccessRequestStatusApproval status
Managed Account.namemanagedAccountNamePrivileged account
Managed System.namemanagedSystemNameConfiguration item
Martini implementation pattern

A Martini workflow retrieves the request and related objects, validates status transitions, applies approval and least-privilege rules, and performs an idempotent ServiceNow update. Request identifiers are stored for correlation, while transient API failures are retried and authorization failures are routed for review.

Martini capabilities used
  • workflows
  • API consumption
  • data mapping
  • business rules
  • idempotency
  • error handling

Pattern 2: Forward privileged sessions to security monitoring

When to use this pattern

Use this pattern when security teams need centralized visibility into BeyondTrust privileged activity. Session metadata and supported audit events are normalized before delivery to a monitoring platform.

Integration direction
BeyondTrust
Martini
Splunk
Example Mapping
BeyondTrust FieldCanonical FieldTarget Field
Session.useractoruser
Session.systemresourcedest
Session.startTimestartedAtstart_time
Session.outcomeresultaction_result
Martini implementation pattern

Martini retrieves supported Sessions or receives selected audit notifications, enriches incomplete events through REST retrieval, normalizes timestamps and outcomes, and sends structured events to Splunk. Duplicate session identifiers are deduplicated and failed deliveries are retried without exposing credentials or sensitive session content.

Martini capabilities used
  • event-driven workflows
  • scheduled synchronization
  • data transformation
  • API consumption
  • retry handling
  • monitoring

Pattern 3: Synchronize managed account and system inventory

When to use this pattern

Use this pattern when the Password Safe inventory must align with an enterprise asset repository or CMDB. It supports incremental retrieval where the relevant API provides modification filters and reconciliation when it does not.

Integration direction
BeyondTrust
Martini
ServiceNow
Example Mapping
BeyondTrust FieldCanonical FieldTarget Field
Managed System.idsourceSystemIdExternal ID
Managed System.namehostnameName
Managed Account.nameaccountNamePrivileged account
Managed System.modifiedDatelastChangedAtUpdated
Martini implementation pattern

A scheduled Martini workflow retrieves changed Managed Systems and Managed Accounts, maps source identifiers to CMDB records, validates required fields, and upserts records. A durable checkpoint with an overlap window supports recovery from late-arriving changes, while duplicate records are prevented through stable external keys.

Martini capabilities used
  • scheduler triggers
  • workflows
  • pagination
  • mapping
  • validation
  • checkpointing

Pattern 4: Report Remote Support sessions

When to use this pattern

Use this pattern when support operations or compliance teams need Remote Support session activity associated with service cases. The exact fields and endpoints must be confirmed for the deployed Remote Support edition.

Integration direction
BeyondTrust
Martini
Jira Service Management
Example Mapping
BeyondTrust FieldCanonical FieldTarget Field
Support Session.idsupportSessionIdSession reference
Representative.idagentIdAssignee reference
Customer.idcustomerIdCustomer reference
Queue.namesupportQueueQueue
Martini implementation pattern

Martini retrieves completed Support Sessions and related Representatives, Customers, Queues, and Jump Clients, correlates them with Jira issues where a case key is available, and publishes operational data. Missing relationships are quarantined for review and retried retrieval is controlled by session identifiers and completion timestamps.

Martini capabilities used
  • API consumption
  • workflow orchestration
  • data correlation
  • mapping
  • validation
  • error handling

Applications commonly integrated with BeyondTrust

BeyondTrust is commonly positioned alongside service management, security monitoring, identity, and privileged-access platforms. Exact integration behavior depends on the BeyondTrust product, deployment model, API version, and enabled modules.

Application Scenario Direction Martini Pattern
ServiceNow Link privileged-access requests, approvals, incidents, and configuration items with BeyondTrust activity. ServiceNow → Martini → BeyondTrust Use a Martini workflow to receive or poll ServiceNow requests, call BeyondTrust APIs for Requests and related Managed Accounts or Managed Systems, apply approval rules, and synchronize status using durable request identifiers.
Splunk Centralize BeyondTrust privileged-session, authentication, and audit data for investigation and security monitoring. BeyondTrust → Martini → Splunk Retrieve supported session or audit data through BeyondTrust APIs or logging mechanisms, normalize the events in Martini, and forward structured records with correlation identifiers and retry handling.
Microsoft Sentinel Correlate BeyondTrust privileged-access events with identity, endpoint, and cloud security telemetry. BeyondTrust → Martini → Microsoft Sentinel Use scheduled REST retrieval or supported event delivery, transform BeyondTrust Sessions and audit events into the target security schema, and route transient failures through bounded retries.
Active Directory Use enterprise users and groups for BeyondTrust identity administration and access control where the deployed product supports directory integration. Active Directory → Martini → BeyondTrust Treat directory integration as a product capability rather than a universal BeyondTrust API. Where API synchronization is required, Martini can orchestrate directory-derived identity data and BeyondTrust API updates under least-privilege rules.
Okta Provide federated identity or SSO for BeyondTrust users where the selected product supports the required federation path. Okta → Martini → BeyondTrust Use Martini for surrounding provisioning, audit, or reconciliation workflows while product-specific SSO and federation remain configured according to BeyondTrust and Okta capabilities.
Jira Service Management Associate privileged-access requests or remote-support activity with service tickets and change records. Jira Service Management → Martini → BeyondTrust Map Jira issues or approvals to BeyondTrust Requests, retrieve related object details, and synchronize outcomes and session references with idempotent updates.
CyberArk Compare or coordinate privileged-account inventories and governance processes in environments using multiple PAM products. BeyondTrust → Martini → CyberArk Use product APIs to extract approved inventory or audit fields, normalize them in Martini, and deliver comparison or governance data to CyberArk or a shared repository; treat this as a custom design rather than a standard native integration.

How to build a BeyondTrust integration in Martini

Objective

Identify the exact BeyondTrust product and API version, then configure its base URL and product-specific authentication without embedding secrets in workflows.

Instructions in Martini

  • Select the relevant BeyondTrust product, deployment, and API version
  • Configure API keys, credentials, client secrets, or token settings in Martini environment configuration
  • Use a dedicated service account with narrowly scoped permissions
  • Separate development, test, and production credentials

Objective

Select a supported product notification when available; otherwise use scheduled REST polling with a durable checkpoint and overlap window.

Instructions in Martini

  • Validate whether the required event has documented notification coverage
  • Use a webhook-style trigger only for supported product events
  • Configure a scheduler for inventory, reporting, and reconciliation workflows
  • Define the polling interval, overlap window, and checkpoint strategy

Objective

Call the appropriate BeyondTrust REST resources and retrieve complete objects rather than relying only on notification payloads.

Instructions in Martini

  • Acquire or refresh the BeyondTrust session or access token
  • Use documented pagination, filtering, and continuation behavior
  • Retrieve related objects such as Managed Accounts and Managed Systems when required
  • Capture source identifiers, timestamps, and response status

Objective

Build the Martini workflow that coordinates retrieval, enrichment, validation, target writes, and recovery behavior.

Instructions in Martini

  • Branch by product object or event type where necessary
  • Separate authentication, retrieval, mapping, and target operations
  • Apply authorization and lifecycle rules before privileged operations
  • Record correlation identifiers for auditability

Objective

Convert product-specific BeyondTrust objects into a stable canonical model and target-specific payloads.

Instructions in Martini

  • Map actual objects such as Requests, Sessions, Representatives, and Jump Clients
  • Normalize timestamps, statuses, identifiers, and enumerations
  • Validate required fields before downstream writes
  • Preserve relevant unknown audit fields where practical

Objective

Create or update service-management, monitoring, identity, inventory, or reporting records with idempotent behavior.

Instructions in Martini

  • Use stable BeyondTrust IDs as external correlation keys
  • Apply target-specific create and update rules
  • Avoid persisting passwords, tokens, or sensitive session content
  • Only advance synchronization checkpoints after successful writes

Common BeyondTrust data objects used in integrations

ObjectTypical UseCommon target systemsMartini handling
Managed AccountsRepresent privileged or service accounts managed through Password Safe.ServiceNow, asset inventories, CyberArk, governance repositoriesMartini retrieves account metadata through product-specific REST endpoints, maps identifiers and lifecycle fields, and performs idempotent creates or updates.
Managed SystemsRepresent servers, network devices, databases, and other systems associated with managed accounts.ServiceNow CMDB, asset platforms, security analyticsMartini uses incremental filters or a durable high-water mark where available, validates required fields, and reconciles source identifiers with target configuration records.
RequestsRepresent requests to obtain access to a managed account or system.ServiceNow, Jira Service Management, approval repositoriesMartini correlates requests by stable identifiers, maps status transitions explicitly, applies authorization rules, and prevents duplicate downstream updates.
SessionsRepresent privileged or remote-access sessions and associated metadata.Splunk, Microsoft Sentinel, data warehouses, service-management platformsMartini retrieves supported session data, normalizes user, system, start, end, and outcome fields, and forwards audit data without exposing sensitive credentials.
RepresentativesRepresent support or privileged-access personnel who initiate remote sessions.ServiceNow, Jira Service Management, reporting platformsMartini maps representative identifiers and attributes to support or audit models after validating the relevant Remote Support or Privileged Remote Access API.
Jump ClientsRepresent endpoint agents used to establish managed remote-access connections.ServiceNow CMDB, asset inventories, reporting platformsMartini synchronizes documented metadata, applies product-specific field mappings, and records source identifiers for reconciliation.

Authentication and security considerations

Product-specific authentication

BeyondTrust API authentication varies by product and deployment. Common patterns include administrator-created API or application keys, user credentials, session or bearer tokens, and selected OAuth or federated identity configurations.

Secret and privilege management

  • Store API keys, passwords, client secrets, and tokens in Martini environment secrets.
  • Use dedicated service accounts with the minimum product permissions required.
  • Separate authentication configuration from mappings and business logic.
  • Protect logs and workflow data from exposing credentials, authorization headers, passwords, or sensitive session content.

Operational considerations for BeyondTrust integrations

Pagination and incremental retrieval

Do not assume that one request returns all BeyondTrust objects. Follow the product's documented page, offset, cursor, or continuation behavior and use server-side filters where available.

Resilience and reconciliation

  • Confirm rate limits and concurrency guidance for the selected deployment.
  • Use bounded exponential backoff for transient HTTP failures.
  • Use stable object, request, and session identifiers for idempotency.
  • Maintain a high-water mark with an overlap window for scheduled synchronization.
  • Use reconciliation workflows for missed notifications or temporary API outages.

Version and schema management

BeyondTrust resources, fields, status values, and authentication behavior can differ by product and API version. Validate required fields, preserve useful audit fields where practical, and test mappings against the deployed version before production release.

Why use Martini instead of scripts or point-to-point integrations?

Orchestration beyond a script

Martini provides a maintainable workflow layer for authentication, API retrieval, event handling, pagination, mapping, business rules, target updates, and recovery behavior. This avoids embedding the full integration lifecycle in one-off scripts.

Reusable enterprise integration behavior

Teams can separate secrets and environment configuration from reusable workflows, expose controlled APIs for downstream applications, and apply consistent validation, retries, idempotency, logging, and monitoring across BeyondTrust integrations.

Adaptability across products

Because BeyondTrust APIs differ across Password Safe, BeyondInsight, Remote Support, and Privileged Remote Access, Martini's API consumption and transformation capabilities allow each product-specific payload to be mapped into a common enterprise model without assuming a single universal connector.

Frequently asked questions

How can BeyondTrust be integrated with enterprise systems?

BeyondTrust is integrated primarily through product-specific REST APIs, supplemented by selected event, notification, audit, logging, directory, or file-transfer mechanisms. The exact approach depends on whether the integration targets Password Safe, BeyondInsight, Privileged Remote Access, Remote Support, or another product.

Can Martini integrate with BeyondTrust?

Yes. Martini can consume BeyondTrust REST APIs, authenticate with product-specific credentials or tokens, orchestrate scheduled and event-driven workflows, map objects such as Requests and Sessions, and send results to enterprise systems. Supported product notifications can also trigger workflows where available.

Do I need a connector to integrate BeyondTrust with Martini?

No. A dedicated BeyondTrust connector is not required. Martini can integrate using BeyondTrust's documented REST APIs, supported product-specific notifications, authentication methods, audit or logging mechanisms, and other confirmed endpoints.

Is there any extra Lonti cost to integrate BeyondTrust with Martini?

Lonti does not charge an additional per-connector or per-vendor fee to integrate BeyondTrust. Integrations are subject to the provisioned capacity of the Martini environment. Separate costs may apply from BeyondTrust, infrastructure providers, or other third-party systems depending on subscription, usage, and deployment model.

Which BeyondTrust integration methods should be used?

REST APIs are the primary recommended mechanism for current programmatic integrations. Selected event, notification, audit, or logging methods can be used when confirmed for the product and event type. General-purpose GraphQL and SOAP APIs were not confirmed, and direct database access is not recommended.

Are BeyondTrust webhooks or events available?

Selected BeyondTrust products provide product-specific event, notification, audit, or integration capabilities, but universal webhook coverage for all object changes is not confirmed. Martini can receive supported notifications and retrieve the full object, while scheduled REST reconciliation covers unsupported or missed events.

How does synchronization with BeyondTrust work?

Martini can use event-triggered retrieval where supported or scheduled REST polling for inventory, requests, sessions, and reconciliation. Workflows use pagination, filters, high-water marks or overlap windows, stable source IDs, idempotent upserts, and checkpoints that advance only after successful target processing.

How does Martini handle BeyondTrust errors, retries, and duplicates?

Martini workflows can capture HTTP status codes and BeyondTrust error payloads, distinguish authorization and validation failures from transient errors, apply bounded retries with backoff, and route unresolved failures for review. Stable request, session, account, and system identifiers support idempotency and duplicate-event protection.