Skip to main content
Create Free Account

Integrations

Keep Your Systems. ComplyFlow Connects to Them Three Ways.

Native connectors for twelve systems, an open REST API for anything else with an API, and an MCP server for your AI assistant. Your ERP, your identity provider, and your BI tool stay where they are; the compliance record sits beside them.

  • IT & Data
  • Procurement
  • Facilities
  • Operations
  • Safety & HSE
ISO 27001 certified, hosted in Australia, every endpoint documented in the open

What the Integrations Do.

ComplyFlow connects to the systems you already run in three ways: native connectors for twelve named systems, an open REST API for anything else with an API, and an MCP server for your AI assistant. Nothing is replaced; the compliance record sits beside your ERP, your identity provider, and your BI tool.

  • Way one: twelve systems connect natively. Microsoft and Okta for sign-on; Yardi and TechnologyOne; KeyWatcher, Unicard, and Torus for access and keys; intelliPermit, hsi, and solv; Power BI and CoreVision for reporting.
  • Way two: everything else with an API uses ours. Every module read; staff, sites, work orders, inspections, and competencies written. JWT, a test environment, a documented endpoint per module.
  • Way three: your AI assistant reads it through MCP. Claude, Claude Code, or GitHub Copilot on scoped, expiring, read-only tokens, with the permissions of the person who made them.
  • Whichever way, your ERP asks before it releases work. A work order arrives with its supplier; your system reads the supplier’s compliance and holds the job until they are cleared.
A systems analyst at a two-monitor desk in an Australian corporate office, API documentation open on one screen and a reporting dashboard on the other, both soft

Open API & MCP reach everything below, and anything else with an API

Find Your Systems

Is Your Stack Here? Twelve Natively. The Rest Through the API & MCP.

The systems around the hub connect natively. Every group below reaches the record through the open API or the MCP server, and so does anything else with an API.

  • Nothing to Rip OutFinance, HR, facilities, and work orders stay where they are. ComplyFlow sits beside them and holds the compliance record.
  • Your ERP Asks Before It ReleasesA work order arrives through the API with its supplier. Your system reads that supplier’s compliance from ComplyFlow and holds the job until they are cleared.
  • Documented in the OpenEvery endpoint in the Help Centre, with a test environment, before your developers ever talk to us.

Read the API Documentation

Connects to the systems you already run

  • Native connectors TorusKeyWatcher AustraliaMicrosofthsisolvOktaYardiintelliPermitUnicardCoreVisionPower BITechnologyOne
  • ERP & finance, through the API SAPOracleMicrosoft Dynamics 365EpicorInfor Also Pronto and any ERP with an API
  • HR & payroll, through the API WorkdaySAP SuccessFactorsADPDayforceUKG Also ELMO and BambooHR
  • Maintenance & assets, through the API IBM MaximoServiceNow Also MEX, Pronto, and your CMMS
  • Procurement, through the API SAP AribaIvaluaKinaxis Also Coupa and Felix
  • Reporting, through the API Power BILookerQlikDomoMetabase
  • AI assistants, through MCP Claude and Claude CodeGitHub CopilotChatGPTAnthropicOpenAIGeminiMistralPerplexity
  • Identity, native MicrosoftMicrosoft Entra IDOkta Your MFA and conditional access policies apply

How the Data Moves, Whichever Way It Connects

Work Comes In. Clearance and Proof Go Out.

Read it left to right: the systems that raise work and hold identity, the one record that checks it, and the systems that read the result.

What sends to ComplyFlow

Work orders from your ERP or maintenance systemYardi and TechnologyOne natively; SAP, Oracle, Maximo, MEX, and Pronto through the API API
Access control and key cabinetsKeyWatcher Australia, Unicard, and Torus native
Permit and safety systemsintelliPermit, hsi, and solv native
Sign-on from Microsoft or OktaYour people log in the way they already do, with your MFA and conditional access native
Training completions from your LMSA completion lands on the Worker’s competency through the API
PrequalificationWorkforce ComplianceTraining & InductionSite AccessVisitor Sign-InSite DocumentsDigital PermitsInspections & AuditsPlant & EquipmentIncident ManagementRisk Management ComplyFlow. One Record.

What reads from ComplyFlow

Power BI and CoreVision dashboardsCompliance beside spend and safety, on your refresh schedule native
Your ERP, before it releases the jobSupplier compliance read through the API; the order is held until the supplier is cleared API
Your AI assistant, through MCPClaude, Claude Code, and GitHub Copilot read the record and cannot change it MCP
Owners, auditors, and investigatorsThe sign-in book, approvals, and inspections as PDF, with names and dates
Your own codeJWT authentication, a test environment, and a documented endpoint per module

Twelve connectors are ComplyFlow’s own. Everything else in your stack connects through the open API and MCP, so if a system has an API, it belongs on this drawing.

The Three Ways, in Depth

Native, API, and MCP. What Each One Carries.

One column per way in. Everything below is in the product today and documented in the Help Centre.

Native Connectors

  • Single sign-on, opens the Help Centre in a new tab

    Microsoft and Okta; your MFA and conditional access apply.

    • Microsoft
    • Okta
  • Property, ERP, and work orders

    Yardi and TechnologyOne, connected to the record.

    • Yardi
    • TechnologyOne
  • Access control and keys

    KeyWatcher Australia, Unicard, and Torus, tied to the person.

    • KeyWatcher
    • Unicard
    • Torus
  • Permits and safety systems

    intelliPermit, hsi, and solv alongside the compliance record.

    • intelliPermit
    • hsi
    • solv
  • Reporting, opens the Help Centre in a new tab

    Power BI and CoreVision read the record for your dashboards.

    • Power BI
    • CoreVision

The REST API

MCP & Your Assistant

Where the Help Centre documents an item, its name links to the article. The native connector list is ComplyFlow’s own, from the 2026 brochure.

How It Works

Four Screens That Carry the Feature.

The tokens your tools hold, the work orders your ERP sent, the suppliers your BI tool reads, and the assistant asking the record.

The Tokens, and What Each May Read.

Every connected tool holds a personal token named for what it is. Each carries only the read scopes it needs and expires within a year.

  • Scopes per module, read-only
  • Expiry from 7 days to one year
  • Shown once; up to 10 per user

The Work Order, Checked Before It Is Released.

Your maintenance system adds the order through the API and reads the supplier’s compliance before it releases the job. Cleared, and the Worker signs in to the order; not cleared, and your system holds it with the reason on the supplier’s record.

  • Add, update, list, and read work orders
  • Supplier compliance read through the API
  • Workers sign in to the order in Live Access

The Suppliers, as Your BI Tool Sees Them.

The supplier list with each company’s status and the documents behind it is one API call. Enterprise Clients pull it into Power BI beside spend and safety data.

  • Supplier list, details, and compliance endpoints
  • Documents and expiries behind each status
  • Refreshed on your schedule, not ours

The Assistant, Asking the Record.

A safety manager asks which sites reported incidents this month. Through MCP the assistant reads the register with the scopes on their token and answers with the rows. It reads; it cannot create, change, or delete.

  • Claude, Claude Code, and GitHub Copilot
  • Read-only, with the user’s own permissions
  • Configured in a few lines from the Help Centre

The Third Way: Model Context Protocol

Ask Your AI Assistant About Your Sites. It Reads ComplyFlow.

What it is
MCP is the open standard that lets an AI assistant read another system safely. ComplyFlow ships an MCP server, so the assistant your team already uses can read your compliance record.
What it lets you do
Ask who is on site, which suppliers are not cleared, which inspections are overdue, or what happened at a site last month, in plain English, and get the answer from the live record.

Read-only by design. A personal token with only the scopes you choose, expiring within a year, and never more than the person who made it is allowed to see.

The first contractor compliance platform we can find with its own MCP server Read the MCP Guide
MCP Claude and Claude CodeGitHub CopilotChatGPTGemini
  • Who is on site at Gate B right now?
  • Which suppliers with open work orders are not cleared?
  • What is overdue on the risk register?
  • List incidents reported this month

Who It Is For

What the Integrations Mean for Me.

Find your job. The three lines under it are what connecting your systems changes for you.

ComplyFlow Is Already Trusted.

Systems at property, transport, resources, manufacturing, government sites, and more already read their compliance record from ComplyFlow.

  • Toll
  • National Intermodal
  • BlueScope
  • ISPT
  • Maersk
  • NSW Planning, Industry and Environment

Book a Demo

Bring Your IT Lead. We Will Answer the API Questions Live.

A 30-minute call with someone who has connected ComplyFlow to maintenance systems, identity providers, and BI tools: your systems, our endpoints, and the token scopes, on screen.

  • Your systems mapped to the three ways in, native, API, and MCP
  • A supplier’s compliance read through the API beside a work order
  • A scoped, read-only token created and revoked in front of you
Talk to Us Instead

No slides, no hard sell. A working session on your own set-up.

Book Your Demo

Thirty minutes, on your own requirements.

Book Demo

The form loads from HubSpot. If it does not appear, the button takes you to the demo request page.

A printed spreadsheet of contractor records spread across an office desk beside a laptop, columns highlighted by hand, and a USB stick and a coffee cup on the pages

How It Stacks Up

Where Integration Usually Lives, and What Each Misses.

Most compliance systems integrate by CSV export, by an API you have to ask about, or by a connector for one named product.

CSV exportsWorks once; wrong by the time it is openedAn API on requestDocumented after you signA connector for one productNothing for the rest of your stack ComplyFlowOne record, your standard
Native connectors to named systems Not thereNot therePartly Twelve, including sign-on, property, access control, and reporting
Documented in the open, before you buy Not thereNot therePartly A public Help Centre collection, grouped by module
Reads every module; writes where work is raised PartlyPartlyNot there Reads all; writes staff, sites, work orders, inspections, competencies
Work orders checked against supplier compliance Not therePartlyPartly Add and update through the API; compliance read beside them
Your AI assistant reads the live record Not thereNot thereNot there MCP server; read-only; scoped tokens
A test environment to build against Not therePartlyPartly Test and production base URLs, documented

This compares kinds of approach, by how they are sold, not named vendors. Named comparisons, with dates and sources, live on the comparison pages.

Getting Started

We Set It Up With You. We Stay With You.

You are not handed an API key and left to it. Our team maps your systems, sets up the test environment with your developers, and stays on hand once the first work order comes through.

  • Mitch Bourne, ComplyFlow
  • Jessica Morgan, ComplyFlow
  • Sam Bourne, ComplyFlow
  • Phil Wallach, ComplyFlow
  • John McCann, ComplyFlow
  1. 1 We Map Your Systems

    Which system raises work, which holds identity, which reports, and which training records need to land on the Worker.

  2. 2 We Switch On the Connectors

    Sign-on, property, access control, and reporting connectors where you run them, and the test environment for everything else.

  3. 3 We Connect Your Assistant

    Scoped tokens for the MCP server in Claude Code or Copilot, and the first questions answered from your data.

  4. 4 You Go Live, We Stay Close

    The first work orders checked, the first reports refreshed, and a support team that picks up the phone.

  • ISO 27001 certified ISO 27001Certified 2019
  • AWS Qualified Software Certified 2023
  • GDPR, General Data Protection Regulation Compliant 2020
  • Microsoft Okta Single sign-on

Security & Data

Certified, Audited & Hosted in Australia.

Your compliance record is the evidence you rely on when somebody asks, so where it lives and who can reach it matters. ComplyFlow is ISO 27001 certified, runs on AWS in Australia, and your people sign in with the accounts they already have.

Questions

Questions IT Teams Ask About Integrations Before a Demo.

Which systems connect natively?

Twelve: Microsoft and Okta for sign-on; Yardi and TechnologyOne; KeyWatcher Australia, Unicard, and Torus for access control and key management; intelliPermit, hsi, and solv; and Power BI and CoreVision for reporting. Everything else connects through the open API and MCP.

Is the API documented, and can we read it before we buy?

Yes. The API Documentation collection in the Help Centre is public and grouped by module: authorisation, staff, suppliers and contractors, Workers, documents, plant, training, incidents, inspections, Live Access, the risk register, forms and permits, work orders, and sites.

How does authentication work?

The REST API uses JSON Web Tokens against a test or a production base URL. The MCP server uses personal API tokens prefixed cf_pat_, scoped per module, read-only, and expiring within a year. Single sign-on through Microsoft uses OAuth 2.0 with short-lived tokens and no password stored.

Can our ERP or maintenance system gate work on compliance?

Yes, once it is set up to ask. Work orders are added and updated through the API, and a separate endpoint returns a supplier’s compliance. ComplyFlow holds the status; your system reads it before it releases the order and holds the job if the supplier is not cleared.

Can we report on the data in Power BI?

Yes. Power BI and CoreVision connect natively, every module is readable through the API, and enterprise Clients already build their own reporting on it.

What can an AI assistant do through MCP, and what can it not?

Read. Claude, Claude Code, and GitHub Copilot can look up and summarise incidents, inspections, suppliers and contractors, Workers, the risk register, plant, sites, and permits, within the token’s scopes and the user’s permissions. They cannot create, change, or delete anything.

See It Against Your Own Systems.

Book a 30-minute demo and bring your IT lead. We will walk the endpoints your systems need, create a scoped token live, and read a supplier’s compliance beside a work order. No slides, no hard sell.

  • ISO 27001
  • Hosted on AWS
  • Microsoft & Okta SSO
  • API & MCP
  • Data in Australia

Compliance you can prove, instantly.