Probo Access Review

Probo Access Review

Bring Attio workspace members into your access reviews

Overview

Probo is the open-source compliance platform that helps teams achieve SOC 2, ISO 27001, GDPR, HIPAA, and CCPA certifications without the usual chaos. Connect Probo to your identity providers, code platforms, and SaaS tools to automate access reviews, evidence collection, and continuous control monitoring. Probo combines the platform, expert auditors, and concierge guidance to take you from kickoff to audit-ready in weeks, not months. Backed by Y Combinator and trusted by 100+ companies in 20+ countries.

This app connects Attio to Probo as an access review source. Probo reads your Attio workspace members, their access level, and when they joined, so every member of your CRM appears in your scheduled access reviews alongside the rest of your stack. Reviewers see who holds admin rights, who has been suspended, and record an approve or revoke decision against each seat as audit evidence.

Probo requests read-only access to user management and nothing else. It never reads your records, lists, notes, emails, or any customer data held in Attio.

How it works

Probo Access Review reads a single endpoint, GET /v2/workspace_members, using the user_management:read scope. For each workspace member it collects the first and last name, the email address, the access level, the workspace member ID, and the date the member was created. It writes nothing back to Attio.

Attio does not delete workspace members, so a member who loses access keeps their record with the access level set to suspended. Probo reports those seats as inactive rather than dropping them, which is what an auditor needs to see. Attio exposes no last sign-in and no multi-factor status, so Probo leaves those fields blank rather than guessing at them.

Configure

You need a Probo organization and an Attio workspace administrator to authorize the connection. In Probo, go to Access Review, then Connections, find Attio and choose OAuth. Attio asks you to approve read access to user management, and the source then appears in your campaigns as Attio followed by your workspace name. A workspace access token created under Settings, Developers, Access tokens with User Management set to Read works as an alternative to OAuth.