NEWFreshservice is now a Ploy integrationSee what shipped
INTEGRATIONSCLOUD INFRASTRUCTURE
Tailscale28 OF 28 CAPABILITIES ASSESSED

Tailnet groups and roles, granted and revoked from Ploy

Tailnet users, groups and roles, with membership granted and revoked through the ACL policy file.

TYPE · INFRA
Tailscale connectorHOURLY SYNCCAPABILITIES
WHAT PLOY DOES
Sync tailnet users, status and last activityEvery user on the tailnet, whether the account is active, and when it was last used.
READ
Discover the groups and roles in the ACLThe groups and user roles Tailscale defines, so a grant has a named thing to attach to.
READ
Map who holds which group and roleGroup membership and role assignment resolve to the user holding them, alongside their access to Tailscale itself.
READ
Grant and revoke group membershipMembership is written through etag-locked edits to the ACL policy file. The group has to exist in the ACL already: Ploy does not create one.
WRITE
Raise and lower a user rolePloy assigns a role and takes it back. Taking it back demotes the user to the baseline member role rather than clearing the grant outright.
WRITE
2.1WHAT IT UNLOCKS

Three jobs this connector does on day one

TAILNET ACCESS

The ACL file is the grant

An approved request is written into the Tailscale ACL policy file as group membership, with an etag lock so a concurrent edit cannot overwrite it. The group has to exist in the ACL already.

ROLES

Admin is granted and taken back

Ploy raises a user to the role the work needs and lowers them again afterwards, which returns them to the baseline member role.

REVIEWS AND EVIDENCE

Who is on the tailnet, and since when

Every tailnet user arrives with their status, their last activity and the groups and roles they hold, which is what a reviewer needs on the row.

2.3

SETUP

TYPICALLY 10 MINUTES
STEP 01

Connect with least privilege

Grant Ploy a scoped, read-only role in Tailscale to begin with.

STEP 02

Watch the first sync

Identities, roles and keys land in the graph.

STEP 03

Turn on writes

Choose which roles Ploy may grant and revoke, and who approves.

2.4OFTEN CONNECTED TOGETHER
OktaIDENTITY SOURCEGitHubSOURCE CONTROLSlackAPPROVALS
BROWSE ALL 62 INTEGRATIONS

Connect Tailscale, see it in 10 minutes.