Elastic Cloud
Connect Elastic Cloud to Ploy to see everyone in your Elastic Cloud organization and the roles they hold, and to invite, change the role of, or remove members from Ploy.
This integration is in beta. It was built from Elastic's published API and has not yet been run against a live Elastic Cloud organization, so expect rough edges and tell us if anything looks wrong.
What Ploy reads
Every member of the Elastic Cloud organization you connect, with their name and email address.
Every role each member holds in that organization: organization roles, deployment roles and project roles.
The organization itself, shown as an account in Ploy.
Ploy does not read the users inside each Elasticsearch deployment, pending invitations, or your single sign-on settings.
What Ploy can change
Invite a person to the organization by email, optionally with an organization role. They become a member once they accept the invitation in Elastic Cloud.
Change a member's organization role. Deployment and project roles are shown but not changed.
Remove a member from the organization. Their Elastic account itself is not deleted.
Before you start
You need an Elastic Cloud API key created by someone with access to the organization. To let Ploy invite people, change roles and remove members, create the key from an organization owner's account.
Step 1: Accept the beta terms
When you open the Elastic Cloud setup in Ploy (go to Integrations and choose Elastic Cloud), the first page starts with a Beta integration acknowledgement box. Ticking it means you agree that Ploy may capture technical error details from this connection, including API responses with personal information removed, and use them only to debug and improve the integration. Nothing is shared outside Ploy. You must tick the box to continue.
Step 2: Create an Elastic Cloud API key
Sign in to the Elastic Cloud console.
Open Organization, then API keys.
Select Create API key, give it a name such as Ploy, and choose the longest expiry your security policy allows, so scans keep working.
Copy the key. Elastic Cloud shows it only once.
Step 3: Connect Ploy
Back in the Ploy setup, paste the API key on the first page, below the beta acknowledgement. Paste the key itself, without the word ApiKey in front of it.
On the next page, choose the Elastic Cloud organization to scan. Ploy scans one organization per connection, so add another connection for another organization.
Select Test to confirm Ploy can read the organization's members, then finish the setup.
Troubleshooting
Elastic Cloud rejected that API key: the key was not copied in full, has expired, or was deleted. Create a new key and reconnect.
That API key cannot read this organization's members: the key's owner does not have access to the organization. Create the key from an organization owner's account.
No organizations in the list: the key cannot see any organization. Check it was created from an account that belongs to the organization.
Invites, role changes or removals fail with a permission message: create the key from an organization owner's account and reconnect.