Capabilities
Provisioning
AccessOwl assigns the requested role to existing Drata users during access requests.
Deprovisioning
AccessOwl removes users from their assigned role in Drata during access revocations.
Drata users are created through your connected identity provider, not by AccessOwl. AccessOwl manages the roles of users who already exist in Drata, and the user must be in Drata before a role can be assigned.
Prerequisites
- Admin access to your Drata account, so you can assign the integration account a role.
Setup
1
Add Drata in AccessOwl
Either add a new application or open Applications and click the +-symbol, then continue.
2
Assign the integration account the Admin role
AccessOwl shows you the integration account’s email address. The integration account must already exist in Drata through your identity provider. In Drata:
- Open Settings and go to Role Administration.
- Select Admins.
- Search for the integration account by name and assign it the Admin role.
The integration account needs the Admin role because only Admins can assign, change, and remove user roles in Drata.

