Prerequisites
- A Vanta organization with a user who can create applications in Settings -> Developer Console (Admin role recommended).
- Optional: the Vanta Person ID of whoever Oleria should record as the offboarding acknowledger, if you plan to run the Offboard Person action.
Oleria requests an OAuth scope per connection, not per application - you don’t grant any scope inside Vanta itself. You choose Read-only or Read-write later, in Oleria’s connection form.
What Oleria discovers
Vanta’s REST API doesn’t expose role or permission-profile assignments, so Oleria can’t inventory who holds which Vanta role. See Notes and limitations below.
Set up the integration
Vanta authentication uses OAuth 2.0 client credentials. You register an application in Vanta’s Developer Console and provide the credentials to Oleria.1
Create an OAuth application
- Log in to Vanta and go to Settings -> Developer Console.
- Select Create.
- For Application type, select Manage Vanta. Vanta’s other application types - Build Integrations (Private or Public) and Auditor - are for different use cases and don’t apply to this integration.
-
Enter an application name (for example,
Oleria) and a description, then save.
2
Copy your credentials
- Copy the Client ID - Vanta generates this automatically when you create the application.
- Select Generate client secret and copy the Client Secret immediately - Vanta shows it only once.
3
Find the offboarding acknowledger Person ID (optional)
Only required if you plan to use the Offboard Person action from Oleria.
- In Vanta, go to Personnel -> People.
- Select the person Oleria should record as the acknowledger on offboarding tasks.
- Copy their Person ID from the browser URL.
Connect Vanta to Oleria
1
Open the integration
Log in to your Oleria workspace and navigate to Integrations -> Vanta -> Connect.
2
Complete the connection form
Provide the following and select Authenticate:
3
Complete the connection
Oleria validates the connection, discovers your Vanta users, groups, and activity, and begins the first sync.
Verify the integration
Confirm Vanta appears in your Oleria workspace’s connected integrations. After the first sync completes, you can review the discovered users, groups, and activity in your Oleria workspace.Remediation actions
Remediation actions require the Read-write scope selected during setup - a read-only connection can’t run these.Notes and limitations
- Roles and permissions: Vanta’s public API doesn’t expose your organization’s role assignments (Admin, Member, Auditor, or custom roles). Oleria can’t inventory who holds which Vanta role, and account records never show a real role value.
- Non-human accounts: system, API, SCIM, and AI-agent principals in Vanta aren’t modeled as accounts. They’re visible only as the actor on activity events.
- Resources: Vanta has no independent, ACL-governed resource surface of its own. This integration inventories accounts, groups, and activity only, not resource-level access.
- Activity retention: Vanta’s event log covers events from October 28, 2022 onward and is retained for at least one year.

