C1 provides identity governance for Blackline. Integrate your Blackline instance with C1 to run user access reviews (UARs) and automatically create and deprovision Blackline accounts.
This connector is in beta. This means it’s undergoing ongoing testing and development while we gather feedback, validate functionality, and improve stability. Beta connectors are generally stable, but they may have limited feature support, incomplete error handling, or occasional issues.We recommend closely monitoring workflows that use this connector and contacting our Support team with any issues or feedback.
Additional functionality:The Blackline connector supports automatic account provisioning for user accounts. Team membership and role assignment remain read-only.
Create Blackline accounts without a password. The connector requires a username, first name, last name, and email. The username is sent as Blackline’s loginId string (for example, sample.user); it is not the numeric user id.
Start Blackline’s asynchronous account deprovision process. Blackline disables the account and removes its access assignments instead of hard-deleting it. C1 evaluates Blackline’s immediate response, but it does not track a failure that happens later while Blackline finishes the process in the background.
Configuring the connector requires you to pass in information from Blackline. Gather these configuration details before you move on.Here’s the information you’ll need:
Client ID
Client Secret
Username
Password (API key)
Scope
Environment Subdomain
Sync requires a Blackline administrator role. Creating or deprovisioning accounts requires a Blackline System Administrator role.Environment Subdomain is the BlackLine region used to build the API host https://{environment}.api.blackline.com (for example us, eu, or sbeu). This is the BlackLine region, not your company or instance name.Scope must contain the API scope name(s) plus your instance identifier, entered as instance_<GUID> and separated by spaces — for example:
The exact scope names and your instance GUID are unique to your instance and are provided by the BlackLine support team — enter the values BlackLine gives you rather than the placeholder above, and include a scope for each resource the connector syncs (users, teams, and roles). If the instance_<GUID> token is omitted, authentication fails with invalid_grant: Invalid instance GUID.The connector uses the following endpoints:
The Connector Administrator or Super Administrator role in C1
Access to the set of Blackline configuration information gathered by following the instructions above
Cloud-hosted
Self-hosted
Follow these instructions to use a built-in, no-code connector hosted by C1.
1
In C1, navigate to Apps > Connectors and click Add connector.
2
Search for Blackline and click Add.
3
Choose where to add the connector: Create a new app, or Add to an existing app (then select the app).If you’re creating a new app, choose whether to link it to an application discovered from your identity provider: select Yes and pick the IdP application, or No to continue with just the connector.
4
Set the connector’s Name and, optionally, a Description.
5
Click the pencil icon next to Owners to choose who can configure and manage this connector.
6
Click Add. The connector is created and its configuration page opens.
7
Find the Settings area of the page and click Edit.
8
Enter the configuration information from the previous section.
9
Click Save.
10
The connector’s label changes to Syncing, followed by Connected. You can view the logs to ensure that information is syncing.
Done. Your Blackline connector is now pulling access data into C1.
Follow these instructions to use the Blackline connector, hosted and run in your own environment.When running in service mode on Kubernetes, a self-hosted connector maintains an ongoing connection with C1, automatically syncing and uploading data at regular intervals. This data is immediately available in the C1 UI for access reviews and access requests.
In C1, navigate to Apps > Connectors > Add connector.
2
Search for Baton and click Add.
3
Choose where to add the connector: Create a new app, or Add to an existing app (then select the app).If you’re creating a new app, choose whether to link it to an application discovered from your identity provider: select Yes and pick the IdP application, or No to continue with just the connector.
4
Set the connector’s Name and, optionally, a Description.
5
Click the pencil icon next to Owners to choose who can configure and manage this connector.
6
Click Add. The connector is created and its configuration page opens.
7
In the Settings area of the page, click Edit.
8
Click Rotate to generate a new Client ID and Secret.
Carefully copy and save these credentials. We’ll use them in Step 2.
# baton-blackline-secrets.yamlapiVersion: v1kind: Secretmetadata: name: baton-blackline-secretstype: OpaquestringData: # C1 credentials BATON_CLIENT_ID: <C1 client ID> BATON_CLIENT_SECRET: <C1 client secret> # Blackline config BATON_BLACKLINE_CLIENT_ID: <Client ID for your Blackline instance> BATON_BLACKLINE_CLIENT_SECRET: <Client Secret for your Blackline instance> BATON_BLACKLINE_ENVIRONMENT: <Regional environment subdomain (e.g. 'us', 'eu', 'sbeu'). Do not include an instance number — use 'sbeu', not 'sbeu3'.> BATON_BLACKLINE_USERNAME: <BlackLine user account> BATON_BLACKLINE_PASSWORD: <BlackLine user account API key, retrieved from FCS user details page> BATON_BLACKLINE_SCOPE: <API scope name(s) plus instance ID as 'instance_<GUID>', space-separated (e.g. 'bl.users instance_<GUID>'). Provided per-instance by BlackLine support.> # Optional: include if you want C1 to create and deprovision accounts using this connector BATON_PROVISIONING: true
See the connector’s README or run --help to see all available configuration flags and environment variables.
Create a namespace in which to run C1 connectors (if desired), then apply the secret config and deployment config files.
2
Check that the connector data uploaded correctly. In C1, click Apps. On the Managed apps tab, locate and click the name of the application you added the Blackline connector to. Blackline data should be found on the Entitlements and Accounts tabs.
Done. Your Blackline connector is now pulling access data into C1.