How connecting an app works
Add the app in AccessOwl
Invite the integration account to the app
The AccessOwl integration account completes the setup
What the pending status means
After you connect an app, the integration shows as pending until the setup is complete. AccessOwl is either waiting for the integration account to be invited to the app, or still finishing the account setup and the first user sync. As long as you have completed the invitation step, no action is needed on your side. The setup can take up to 10 hours, but it usually completes much faster than that. If the integration stays pending longer than expected, double-check that the invitation was sent to the integration account’s email address and that the assigned role matches the setup instructions.Connection errors
When AccessOwl can’t connect to an app, the integration shows an error state. A Partial Sync Error is usually a routine transient. It means the app was briefly unreachable when AccessOwl last tried to sync. AccessOwl keeps retrying automatically, and the error clears on its own once the next sync goes through. No action is needed on your side unless the error persists across several syncs. The three error states below require action on your side.Integration account not invited
AccessOwl could not find the integration account in the app. Invite the integration account, give it the role listed in the setup instructions, and click Retry.Not enough permissions
The integration account exists in the app, but its role does not allow it to manage users. Verify that the integration account has the role listed in the setup instructions and click Retry.Access denied
The integration account is blocked from signing in to the app. The most common causes:Google Error 403 - App not enabled for user
Google Error 403 - App not enabled for user
Google Error 400 - Access not configured
Google Error 400 - Access not configured
The integration account is behind Okta or OneLogin
The integration account is behind Okta or OneLogin
Access to accounts via Single Sign On (SSO) is restricted
Access to accounts via Single Sign On (SSO) is restricted
Access Denied - Invalid Credentials
Access Denied - Invalid Credentials
FAQ
Who manages the integration account's password and 2FA?
Who manages the integration account's password and 2FA?
How do I disconnect an app that is connected to AccessOwl?
How do I disconnect an app that is connected to AccessOwl?
Does AccessOwl deactivate, remove, or delete users?
Does AccessOwl deactivate, remove, or delete users?
Does the integration account purchase a seat when none are left?
Does the integration account purchase a seat when none are left?

