Skip to main content

How Integration Access and Connection Ownership Works

How integration access works

Hatz can connect to external systems such as Microsoft 365, HubSpot, Salesforce, ConnectWise, Autotask, Halo, Slack, and other supported tools. Access depends on two layers: the user's Hatz permissions and the permissions granted by the connected external account.

Connections are not the same as Workshop sharing

Sharing an App, Workflow, or Agent controls who can see and run that Hatz item. It does not automatically share the original creator's external credentials with every user or group.

Apps cannot use integrations. If a shared Workflow or Agent uses a tool that requires authentication, each user may need to connect their own external account, or the item may use the connection pattern supported by that integration. The specific integration article explains whether that connection is tenant-wide, per-user, or backed by a service account/API member.

Common connection patterns

  • Per-user OAuth connections: Microsoft 365, HubSpot, Salesforce, Slack, and similar tools often run with the permissions of the user who connected the account.

  • Service account or API-member connections: PSA and admin-managed integrations may run with the permissions granted to the configured API member or service account.

  • Workspace availability: Admins can make a connection type available to a tenant, but availability does not always mean every user has authenticated access.

What to check when a tool fails

  1. Confirm the user can access the Hatz feature they are using, such as Chat, Workshop, or the shared item.

  2. Confirm the integration is connected for the user, tenant, or service-account pattern required by that integration.

  3. Confirm the connected external account has permission to the specific mailbox, file, folder, object, ticket, agreement, company, contact, or record being requested.

  4. Check whether the requested action is available in the Hatz tool picker. Integrations support the actions listed in Hatz, not every action available in the external product's API.

  5. If the issue continues, send Support the tool call, tool result, screenshot, tenant, user, integration, and approximate time.

Unsupported or custom integration requests

If you need a generic API connector, custom MCP server, or an integration that is not currently listed, submit or upvote the integration request with the vendor name, workflow, and whether the vendor provides an API or hosted MCP server. Custom integration availability and security review depend on product and security approval.

Did this answer your question?