In this quickstart, you’ll add a managed app to StackBob.ai, set up StackBob NCAP™ (No-Code Autonomous Provisioning) over a Direct Internet Connection, and start your first app sync. When the sync completes, every user account in the app will be listed on the Accounts tab of the app profile in StackBob.ai, along with its entitlements, licenses, and last activity, if the app exposes this information.
Your part takes about ten minutes. The first sync then runs automatically: within about an hour for apps already in the StackBob.ai integration library, or within up to 48 hours for a new app that requires agent training. You’ll receive an email when it completes.
The sync is read-only. StackBob does not create, modify, or remove anything in the app during the sync. Provisioning and deprovisioning actions are trained separately and, once enabled, are driven by your primary IGA.
This quickstart uses FIS Integrity as the example app for demonstration purposes only. Any app reachable over a Direct Internet Connection follows the same steps.
Prerequisites
A StackBob.ai organization where you hold the Org Admin role. Organizations are created during onboarding — see Create your organization article.
An app that is reachable over HTTPS from the internet. Apps that are only reachable from inside your private network are connected through StackBob On-Prem Bridge — see Deploy a StackBob On-Prem Bridge.
A dedicated service account in the app with user management permissions, or the ability to create one.
1. Add a managed app
Open Apps › Managed.
Select + Add app. The Add new app drawer opens.
In App name, start typing the name of your app and select it from the list. If your app is not in the catalog, select Create Custom. This example uses "FIS Integrity" app from the StackBob.ai catalog.
🟩 Apps with the Agent Ready chip have a ready-to-use integration and complete the initial sync within about an hour. Other apps, including custom ones, require agent training and sync within about 48 hours.
Keep the default Workspace Name, or enter the name of your app tenant.
Select Add & Setup.
Result: The app is created and app page opens with the first setup step — Select App Connection Type — at the top of the page.
2. Set up StackBob NCAP™
In Select App Connection Type panel, keep Direct Internet Connection if your app can be accessed over the Internet. Then select Set Up Sync.
ℹ️ For apps only reachable from your private network, select On-Prem Bridge and follow Deploy a StackBob On-Prem Bridge instruction before continuing.
In Set Up Service Account, select Set Up Account Manually. Then Continue.
ℹ️ This quickstart uses a service account you create in the app yourself.
Invite Agent via Email flow is covered in Set up StackBob NCAP™ article.In Set Up Service Account for Integration step, create the dedicated service account in your app if you have not already, then select Enter Credentials. In the
In Sync identity selector, enter the service account's email address and select Create identity. This is the identity record StackBob.ai associates with the service account.
In Sync Accounts URL, enter the address of the page where users are managed in the app.
In Login ID Type, select how the service account signs in to the app — Email or Username
In Authentication Method select how the service account is authenticated — Password, Passkey, Email Magic Link or IdP SSO
In 2FA, if the app uses two-factor authentication, select +Add 2FA Method and enroll the service account's authenticator in StackBob Authenticator.
ℹ️ Service account credentials
The service account's credentials are encrypted in StackBob Vault. StackBob.ai decrypts them only during sync, when it signs in to the app as the service account through the app's own sign-in flow, in an isolated headless browser.Result: When credentials are saved, the drawer closes and the sync starts.
3. Agent Bob syncs with the app
You have completed the setup and the sync has started. No further action is required on your end. The first sync typically completes within about an hour for "Agent Ready" apps, or within about 48 hours for apps that require agent training. Following sync typically takes just a few minutes. When the first sync finishes, Org Admins receive an email notification
Result: App is synced with StackBob and IGA Provisioning can be set up
4. Review discovered accounts
When the sync completes, the user accounts from the app are listed on the Accounts tab of the app page. Review them, then select Set Up Provisioning to continue with provisioning from your primary IGA.
ℹ️ The Status filter on Accounts tab shows accounts with Access Granted and Access Requested statuses by default. Users who are deactivated in the app are shown when you clear the filters.
Next steps
Set up provisioning from your primary IGA:
Set up provisioning from SailPoint
Set up provisioning from Okta
Set up provisioning from Microsoft Entra ID





