Segment
Connect the segment as an access review source using a public tokenAPIand a workspace region so that the platform can list the members and roles of your workspace.
The platform reads the members of your workspace segment through the public API segment, so you can check who has access.
Prerequisites
Section entitled ‘Prerequisites’- the platform organization administrator access
- A segment of work space Team or Business tier
- The Workspace Owner role in the segment (only a workspace owner can create a public tokenAPI)
- The workspace’s Region, which the Connect dialog asks alongside the token. Segment calls the data processing region and sets it when the workspace is created; you can’t change it later. The new workspaces are default in the U.S., and the EU data residence is a business-level feature that a Segment account executive allows, so a team workplace is always U.S.
Collected Fields
Section entitled “Collected Fields”| the platform field | Segment field | Notes |
|---|---|---|
| Name | name |
Return to email address |
email |
||
| Role | permissions[].roleName |
Deduplicated and sorted. A waiting invitation does not play any role |
| Admin | permissions[].roleName |
Flag as administrator when one of the roles is Workspace Owner |
| Status | invites |
Waiting invitations are listed as inactive. The user endpoint carries no status for members who have accepted, so theirs is left unknown |
| MFA | Not supported | |
| Last login | Not supported | |
| External ID | id |
Stable ID used to track the account during reviews.A waiting invitation is identified by its email address |
| Created at | Not supported |
Members who have been invited but have not yet accepted appear next to the accepted members, marked inactive.
Step 1: Create a Public API Token
Section entitled “Step 1: Create a PublicAPIToken”- In the Segment app, signed in as a Workspace Owner, go to Settings > Workspace settings > Access Management > Tokens.
- Click + Create Token, choose a Public API token, type a description (for example
Probo Access Review) and assign it Workspace Owner access. - Click Create, copy the token somewhere safe and click Done.
Step 2: Connect in the platform
“Step 2: Connect in the platform”- On the platform, go to Access Reviews > Sources > Add Source.
- Find Segment, click API Key, attach the token, choose your own. Region, and click Connect.
The platform names the source by your workspace and attracts its members to your campaigns.
Troubleshooting
Section “Troubleshooting”- Token creation is unavailable. PublicAPI is a team and business-level feature and only a workspace owner can create a token.
- Token rejected. Confirms that it is a public token rather than a ConfigAPI token, that a workspace owner created it and that Region Each region has its own host, and one token authenticates against the host of its own workspace.
- Region unknown. The segment does not document a setting screen that shows the region of an existing workspace, but the URL you connect to is a practical indicator:
app.segment.comis the US application andeu1.app.segment.comis the EU application. - No members appear. A token with access only to Workspace members may not be able to read the workspace users.