Synk.to is a SaaS-first identity governance and administration (IGA) platform. It gives you three things most identity tools don’t cover together: Shadow IT and Shadow AI detection across your core identity providers, continuous SaaS access reviews, and cross-system sync to enforce the access decisions you make.Native SCIM-based user/group sync is usually locked behind Enterprise-tier SaaS plans that cost 2.5x more on average than Pro/Team plans. Synk.to gets you governance and sync without forcing an Enterprise upgrade across your whole stack.
What is Shadow IT, and how does Synk.to detect it?
Shadow IT is any SaaS app or third-party integration connected to your company’s systems without IT’s knowledge or approval — a Chrome extension authorized with a work email, an OAuth grant to a productivity tool, a self-issued Google Apps Script project. Synk.to detects it by reading the OAuth grants and connected-app inventory exposed by your identity provider’s Admin API (Google Workspace, Microsoft Entra ID, Microsoft 365), then scoring each one for risk based on scope breadth and data sensitivity.
What is Shadow AI, and how does Synk.to detect it?
Shadow AI is the subset of Shadow IT made up of AI tools and agents — copilots, browser extensions, autonomous agents — that employees have authorized with company credentials, often with standing access to email, drive, or chat data. Synk.to surfaces these the same way it surfaces other Shadow IT: by reading connected-app and OAuth grant data from your identity provider, with no endpoint agent required.
What are SaaS access reviews, and how does Synk.to help?
Access reviews answer the question “should this access still exist?” — surfacing over-privileged users, orphaned accounts, and admin rights left behind by former employees or contractors. Synk.to centralizes entitlement data across every connected SaaS system into one view, so reviews are continuous instead of a periodic spreadsheet exercise. See User Access Reviews for the full breakdown. Do I need read-write access to use Synk.to?
No. To start using Synk.to for Shadow IT/Shadow AI detection and access reviews, read-only access to your identity provider is enough — this keeps exposure and risk to a minimum. Read-write access is only required if you also want Synk.to to enforce access changes automatically (creating, suspending, or syncing users and groups across systems).
A Source system is the reference system for users and groups that get synced to Replica systems — usually the first system where your users appear. It’s typically Google Workspace, Entra ID (Azure AD), or an HR system (BambooHR, Rippling, etc.).
What is a Replica system?
A Replica system is a third-party SaaS solution that receives the changes made in a Source system. Common examples are issue trackers (Jira Cloud, Asana), communication tools (Slack, Microsoft Teams), code repositories (GitLab, Bitbucket), and other business SaaS systems.
If I make a change in a Source or Replica system, when is it reflected in Synk.to?
Open the Source and Replica connection settings to see changes immediately, along with the current status and upcoming action for each user ahead of the next sync cycle. Users and groups sync to Replica systems according to the interval set in Connection Details. Due to rate limits on SaaS APIs, 15 minutes is the shortest interval you can set.
Can I exclude certain users from sync?
Yes — move them to the “To Ignore” state in the “Group Mapping” tab of your connection settings. This is especially useful for technical, testing, or service accounts in your groups. You’ll need to set this for every group mapping you have.
How to allowlist the Synk.to OAuth application?
If your organization restricts which third-party apps users can authorize, add the Synk.to OAuth app to your identity provider’s trusted apps allowlist by its Client ID.For Google Workspace, allowlist the app in the Admin Console under Security > API Controls > App Access Control, using the Client ID that matches the access level you connected with:
- Read-only app:
947718023567-v026licl1bnf8certfjke25vi7otfjbv.apps.googleusercontent.com
- Read-write app:
156322307703-2c5j40s66lg62sfvimhj07tvst2pqbno.apps.googleusercontent.com
For Microsoft Entra ID, add the app under Enterprise Applications (or via Conditional Access / admin consent policies) using its Application (client) ID:
d5bba094-32ef-49b3-997a-fbe62cbd9b97
Unlike Google Workspace, Synk.to uses a single Entra ID app for both read-only and read-write access — the level of access is controlled by the scopes granted during admin consent, not by connecting to a different app.
How much does Synk.to cost?
Every account starts with a 14-day free trial with full access to all features, no credit card required. After the trial, the Pro plan is a flat $1 per synced user per month (excluding VAT), billed on the peak number of unique users across your connected systems during the billing period.For more information, check out our pricing page. Is there a free trial period?
Yes. Every new account gets a 14-day free trial with full access to all features, with no user or group limits, and no credit card required to start.
What happens when my trial ends?
If you haven’t added a payment method by the end of your 14-day trial, synchronization pauses and you won’t be able to add new connections until you upgrade. Your existing connections and configuration stay in place and pick back up once you subscribe.
How do you count synced users for billing?
The charge is based on the peak number of unique users (excluding users in “To Ignore” state) across your connected systems during a given billing period. You can review current usage and upcoming invoices on your Profile page in the app.
How can I upgrade to Pro?
Go to your Profile page in the app and click “Upgrade Plan” (or “Upgrade now” if your trial has expired). You’ll be redirected to Stripe Checkout to add a payment method, and billing starts once checkout completes.
How do I cancel or manage my subscription?
Go to your Profile page and click “Manage Subscription” to open the Stripe billing portal, where you can update your payment method or cancel your subscription.
What will happen to my connections if I cancel my subscription?
They’ll be kept in your account, but synchronization pauses until you resubscribe.
No, we don’t currently support annual payments.
What will happen if my payment fails?
Stripe will automatically retry the failed payment. If it continues to fail, your subscription moves to past due and synchronization pauses until you update your payment method.
What system integrations do you support?
We currently support Google Workspace, Microsoft Entra ID, Slack, Jira Cloud, Confluence, Asana, Zoom, and BambooHR.For Slack, creation, suspension, and deletion of users are only supported on the Slack Business+ plan.
What systems do you plan to support in the future?
We’re continuously adding support for more SaaS solutions. We’re currently working on AWS, Notion, Okta, Microsoft Teams, and Jira Enterprise, among others.
There's an integration or feature I want, but I don't see it in Synk.to. Can I request it?
Yes — we continuously develop our product and want to hear from our users. Submit your request using the “Contact Us” form on our landing page. We’ll evaluate it, and if it fits our product strategy, we’ll integrate it free of charge. How do I sign up to hear about new functionality?
Just sign in to our service and we’ll let you know about product updates.