Connect Thousands of Apps
Your employees can connect to the apps your team already uses, Gmail, Slack, Notion, HubSpot, and hundreds more, through secure OAuth.
TL;DR
Connect an app once and any employee you enable it for can take real action inside it, not just talk about it. One authorization covers your whole company, and you switch access on or off per employee. No API keys to manage, one click to connect, one click to revoke.
How It Works
Enabling an app for an employee and authorizing it are the same motion the first time. Pick the app from any employee's Tools tab, and if your company hasn't connected it yet, a sign-in window opens right there. Once authorized, every other employee can be switched on to the same app with a single click, no repeat login.
| Step | What Happens |
|---|---|
| 1. Open | Go to an employee's Tools tab and click Add Apps |
| 2. Pick | Search the catalog and select the app you want |
| 3. Authorize | First time only: a sign-in window opens for that app. Approve it and the connection is active for your whole company |
| 4. Use | The employee can now take actions on that app |
What It Can Do
A selection of the most popular apps from the thousands of integrations available:
How to Set It Up
- Select any employee and click the Tools tab
- Click Add Apps, then search for the app you want
- Select it. It's enabled for this employee right away
- If it's the first time anyone at your company uses this app, a sign-in window opens. Sign in and approve access
- Done. The app is connected for your company and enabled for this employee
To give another employee the same app, open their Tools tab, click Add Apps, and select it. No sign-in step this time, since the company connection already exists.
Choose what becomes trained knowledge
Connecting an app authorizes actions and reads allowed by that provider. It does not automatically import its data into company knowledge. When you choose Train for a connected app, select the pages, channels, folders, projects, or records to include wherever the provider exposes them. If it cannot provide a useful selection list, Sistava asks you to explicitly confirm an all-accessible-content import. See Training for the full flow.
Click any connected app's card to open its settings:
| Action | What it does | Where |
|---|---|---|
| Enable / Disable | Turns the app on or off for this employee | Toggle on the app's card |
| Approvals | Choose whether the employee acts on its own or checks with you first, and add free-text rules like "only post to #marketing" or "never email John" | Open the app, then the Approvals section |
| Disconnect | Revokes the connection and turns the app off for every employee | Open the app, then Disconnect next to its connection status |
Tips & Tricks
- Connect before you need it. If an employee asks you for a tool mid-conversation, connecting it notifies that same employee in that same thread so it can pick the work back up
- Be specific about the target. "Send this to the #marketing channel on Slack" is better than "post it on Slack"
- Gmail and Outlook sends always ask first. Reading email can run automatically once connected, but every send, reply, or forward goes through an approval card, even if the app's broader setting is automatic
- One connection per app. All employees share the same company-wide connection. You don't need to sign in again for each employee
Behind the Scenes
| Powered by | Composio |
| Auth | OAuth 2.0, one click, no API keys |
| Token management | Composio handles all tokens, refresh cycles, and revocation. Nothing stored in our database |
Integrations vs Built-in Tools
| Integrations | Built-in Tools | |
|---|---|---|
| Examples | Gmail, Slack, HubSpot | Web Search, Web Scraper, Image Generator |
| Setup | Sign-in required | None, available immediately |
| Scope | Company-wide connection, per-employee toggle | Per-employee toggle only |
| Provider | External services | Platform-native |
| Best for | Acting on external systems | Research, content creation, internal tasks |
What It Costs
| Cost | Each action the employee takes through a connected app is billed as credits based on that app's own usage, on top of the employee's normal thinking cost |
| Rate limits | Each external app enforces its own limits. If a call is rejected, the employee sees the app's error and reports it to you |
Is It Safe
- OAuth only. No passwords or API keys are stored. Connections use industry-standard OAuth 2.0 with scoped permissions
- Token isolation. OAuth tokens are managed by Composio and never stored in our database. We never see your credentials
- Revoke anytime. Disconnect an app with one click. Access is revoked immediately for all employees
- Scoped access. Each app requests only the permissions it needs. You approve the scope during sign-in
- Controlled knowledge imports. OAuth scope controls what the provider lets the connection read. Training selection controls which accessible items enter your company's shared knowledge
Good to Know
- One connection per company. When you connect Gmail, it's one Google account for the whole company. Individual employees can be enabled or disabled independently
- Employees ask before acting. With approvals set to ask, the employee requests your sign-off before taking an action on a connected app. Gmail and Outlook sends require approval regardless of that setting
- Disconnecting. Revoking a connection immediately turns the app off for every employee. No data is deleted from the external service
Frequently Asked Questions
Q: Is my data safe? Who has access to my OAuth tokens? A: OAuth tokens are managed by Composio and never stored in our database. You can revoke access anytime from an employee's Tools tab, and the app's own security settings always apply.
Q: Do all employees automatically get access when I connect an app? A: No. Connecting an app the first time enables it for the employee you connected it through. Every other employee needs the app added to their Tools tab too, though they won't need to sign in again.
Q: Can I connect multiple accounts for the same app (e.g., two Gmail accounts)? A: Currently, one connection per app per company. If you need to send from different accounts, use the one connected account and specify the recipient in your instructions.
Q: What happens if the OAuth token expires? A: Token refresh is handled automatically. If a refresh fails (e.g., password changed), the connection status will show as expired or failed and you'll need to reconnect it.
Q: Can the employee create new integrations or connect apps on their own? A: No. Only you (the employer) can authorize a connection. An employee that needs a tool it doesn't have will ask you for it, then pick the work back up once you connect it.
Q: Does connecting an app automatically train all of its content? A: No. Training is a separate action. Select the content to import when the app can list it, or explicitly confirm an all-accessible-content import when it cannot.