Skip to main content

Connecting Vanta & CATS

J
Written by Jaquez Hodo
Updated today

Vanta integrates with CATS to monitor and manage access to your tools. By syncing user access data, Vanta helps ensure that only active employees retain access and that access is promptly removed when personnel leave. This supports automated compliance needs, streamlines access reviews, and powers automated access requests.

Estimated setup time: Less than 5 minutes

How It Works

Vanta connects to CATS to sync user data on a regular basis. This data supports three key workflows:

  • Automated compliance tests – Vanta automatically checks that accounts are linked to employees and deprovisioned when personnel leave.

  • Access Reviews – Synced users are surfaced in Vanta’s Access Reviews, where approvers can validate appropriate access, confirm least-privilege access, and provide audit evidence.

  • Access Requests – Entitlements from CATS are pulled into Vanta. Requesters can ask for specific access levels, approvers can review with context, and admins can track provisioning.

Please note: Vanta connects to CATS through Merge.dev, a secure third-party integration platform.

Use Cases

Connecting CATS to Vanta will enable you to:

  • Monitor and manage personnel access to CATS in real time

  • Ensure only active employees retain access to company systems

  • Simplify access reviews and support compliance requirements

Requirements

  • Vanta administrator account

  • CATS administrator account

  • CATS subdomain

  • API Key from CATS admin settings

Connect the Integration

  • Log in to CATS using your subdomain

  • In the top bar, navigate to Settings → Administrator → API Key

  • Create a new API Key:

    • Go to Site Management → API Keys

    • Select Add API Key

    • Enter a name and select Generate

    • Copy the generated key

  • In Vanta, go to the Integrations tab and search for CATS

    • Select View Details

    • In the right panel, select Connect

    • Select Connect CATS – you will be redirected to the Merge.dev linking flow

    • Enter your CATS subdomain and select Next

    • Paste the API Key and select Next

Employees will appear in Vanta within about 30 minutes.

Capabilities

Resource

Supported

Usage

Users

Permissions

Vanta accesses the following data from the CATS API:

Vanta can read:

  • Data about your users

    • Used to confirm only active employees retain access

    • Ensures terminated employees are deprovisioned promptly

    • Enables Access Requests to display available users when tracking or assigning access

Vanta can write:

  • Nothing (Vanta does not have write permissions)

Related Articles

Troubleshooting FAQ

“I don’t see roles/groups available when creating an access level in Vanta.”

  • Likely cause: The CATS API does not expose entitlements, or they have not been synced yet. Confirm that the correct scopes are granted.