OSO Audit

Integrations

Your systems stay the source. The audit graph stays ours.

Every import records who authorised it, what arrived, its row counts and content hash — because a connector that cannot prove what it pulled is just a faster way to import an unproven population. Statuses below follow our standing rule: built means shipped and testable today; anything else says so.

Accounting & ERP connectors

Live API connectors with client-authorised, read-only access. Every pull lands as a hashed, row-counted batch before anything downstream is allowed to consume it.

SystemMethodStatus
QuickBooks OnlineOAuth 2.0 API — GL, chart of accounts, vendor & customer mastersBuilt
XeroOAuth API connectorBuilt
NetSuiteAPI connectorBuilt
Sage IntacctAPI connectorBuilt
Microsoft Dynamics 365 BCAPI connectorBuilt
Oracle FusionAPI connectorBuilt
SAPAPI connector + direct-extract pathBuilt
Any systemStructured CSV/XLSX import with schema mapping, corruption detection and reconciliationBuilt
Bank feeds / open bankingDirect bank-data connectivityPlanned

Identity & enterprise access

SSO — SAML 2.0 & OIDC

Microsoft Entra, Okta and OneLogin patterns supported. Your identity provider stays the source of truth, and we read its MFA assertion rather than trusting a checkbox.

SCIM provisioning

User lifecycle provisioning from your directory. Scoped deliberately: users today, with the honest limits documented rather than hidden.

MFA

TOTP multi-factor for privileged roles, enforced in the product — not just recommended in a policy document.

Working surfaces

Excel

Trial-balance import, findings and ledger export, and an add-in surface — because pretending auditors will abandon Excel is how vendors lose to it.

Power BI & Tableau

Read endpoints for firm reporting, so portfolio analytics can live in the BI stack you already run.

E-signature

DocuSign integration for confirmation workflows today; broader document signing is scoped against jurisdiction-specific validity rules.

Webhooks & API

HMAC-signed webhook subscriptions with delivery logs, scoped API keys issued under step-up authentication, and a GraphQL surface for structured reads.

Regulatory data

SEC EDGAR ingestion for issuer context, and a standards-watch pipeline that monitors six regulator feeds for amendments.

Confirmation networks

Deliberately integrate-first: the respondent-trust network is a business of its own. Our confirmation workflow is built; the external network integration is an adapter away, and we say that plainly rather than shipping a mock and calling it a network.

No lock-in, stated as a design rule

Engagements export as signed, hash-manifested evidence packs with an offline verifier — readable without us. If we ever make leaving hard, we have broken our own product thesis.

Evaluate the fit

Tell us what your stack looks like.

Run a pilot Security & deployment