Skip to main content
Connector guides

Connect intelliGRC

intelliGRC is a CMMC / GRC compliance platform for MSPs and their clients. Connecting it to StackJack gives your AI assistant a focused family of igrc_ MCP tools — MCP (Model Context Protocol) tools…

Written By Christopher Scaminaci

Last updated 6 days ago

intelliGRC is a CMMC / GRC compliance platform for MSPs and their clients. Connecting it to StackJack gives your AI assistant a focused family of igrc_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:

  • Review evaluations, the assessment objectives inside them, and each objective's change history
  • Inspect system boundaries and the reference lookups (statuses, priority levels, confidentiality/integrity/availability levels, and more) that describe them
  • Track the action plan — remediation projects, tasks, and subtasks
  • Read the evidence attached to your compliance records
  • Act (on Pro plans) — create evaluations, boundaries, action-plan projects/tasks/subtasks, update assessment objectives, and attach or upload evidence

Documentation boundary. intelliGRC's public website describes its provider-first, multi-tenant GRC product, but does not publish API authentication, host, lifecycle, pagination, or rate-limit documentation. The setup steps below reflect how StackJack connects to intelliGRC. Confirm credential issuance and tenant-specific restrictions with intelliGRC before production use.

How StackJack authenticates to intelliGRC

intelliGRC uses a static API credential — a client id and client secret issued from the intelliGRC console. There is no browser OAuth or refresh-token flow. StackJack sends x-client-id and x-client-secret; it also sends x-tenant-id when a default or per-call tenant is available. intelliGRC does not publicly document credential expiry or rotation, so treat vendor lifecycle details as account-specific.

Which intelliGRC organization a call targets

intelliGRC calls this its tenant — the organization a request acts on. One StackJack credential can work across every intelliGRC tenant it has access to:

  • You can set a default tenant when you connect, so tools that don't specify one use it.
  • Every tool also accepts an optional tenant id parameter that targets a specific organization for that one call.
  • Your AI can list the tenants a credential can reach with the igrc_list_tenants tool, then use one of those ids as the override.

If you only work with a single intelliGRC organization, set it as the default and you can ignore the per-call parameter entirely.

Before you begin

  • In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator).
  • In intelliGRC: you need to be able to obtain API credentials (a client id and client secret) — from the intelliGRC console or through your intelliGRC contact.
  • Know your tenant id if you want to set a default organization for your calls.

Step 1 — Get API credentials from intelliGRC

  1. In the intelliGRC console (or via your intelliGRC representative), request API credentials for programmatic access.
  2. Record the client id and client secret — you'll paste both into StackJack.
  3. Note the tenant (organization) id you want StackJack to use by default. If you manage several intelliGRC organizations, you can leave the default blank and pass a tenant id per call instead.

Step 2 — Add the credentials in StackJack

  1. In the StackJack portal, open Connectors.
  2. Select the intelliGRC tile to open its details drawer.
  3. Use How To Connect to review the inline setup, then choose Configure in the drawer footer.
  4. Enter the Client ID and Client Secret.
  5. Optionally enter a Default tenant id — the intelliGRC organization to act on when a tool doesn't specify one.
  6. Leave the Instance URL blank for production (https://api.intelligrc.app), or enter https://dev-api.intelligrc.app if intelliGRC provisioned that sandbox. StackJack rejects other hosts before storing credentials.
  7. Click Save.

What happens when you save

  • The client id and secret are stored encrypted in Azure Key Vault — never in the StackJack database, and never shown back to you.
  • If this is the first time you configure intelliGRC, a Free-tier subscription for the connector is created automatically so its Free tools work right away.
  • StackJack immediately live-validates the credentials by listing the tenants the credential can reach. The credential remains saved if the upstream check fails so you can correct vendor access without re-entering every field.
  • The Configure form collapses while the details drawer stays open. The drawer shows Connected and Valid after success, or Needs Attention with the vendor error and a Re-test action after failure.

Plans and available tools

See the generated intelliGRC tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.

intelliGRC's API credential is a single shared key, not a per-user login, so all AI traffic authenticates as that one credential — there is no per-user attribution. Current pricing and quotas are shown in the portal's Billing page and at checkout.

Tip — resolve reference ids first. Many create/update tools take numeric ids (a status, a priority level, a boundary's confidentiality/integrity/availability level). Your AI can look these up with the igrc_lookup_* tools before it builds a request, so it uses the exact id intelliGRC expects.

A note on the base URL

StackJack targets the production intelliGRC API by default. Its authority guard permits only api.intelligrc.app and dev-api.intelligrc.app; it rejects HTTP, embedded credentials, and any other host before saving. If a specific tool reports "not found" while others work, verify that you selected the environment intelliGRC provisioned and confirm endpoint availability with the vendor.

Rate limits

No numeric intelliGRC API quota is available in public vendor documentation. StackJack applies conservative per-tenant pacing and records 429 backoff, so a burst is slowed rather than sent all at once. Ask intelliGRC for any account-specific ceilings before scheduling high-volume workflows. Pacing is not a guarantee: retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.

Rotating or replacing the credentials

If intelliGRC rotates or revokes the client id/secret, open the intelliGRC details drawer, choose Configure, enter the replacement values, save, and choose Re-test. Ask intelliGRC whether the old credential must be revoked separately; no public lifecycle contract is available.

Disconnecting intelliGRC

Choose Disconnect in the intelliGRC details drawer and confirm. StackJack deletes its stored credential and default-tenant value and stops making intelliGRC calls. Disconnecting does not revoke the upstream API credential; coordinate that separately with intelliGRC. Connector subscription changes are separate from credential disconnection.

Troubleshooting

SymptomLikely causeWhat to do
The drawer shows Needs Attention after savingMis-typed client id/secret, wrong environment, or the credential lacks tenant-list accessConfirm the accepted production/sandbox host and credentials with intelliGRC, save, and choose Re-test
Tools worked, then started failingThe API credential was rotated or revoked in intelliGRCUpdate the credential in Connectors → intelliGRC → Configure with the current client id and secret
A tool acts on the wrong organizationNo default tenant set, or the wrong oneSet the correct Default tenant id, or pass the intended tenant id on the call (list valid ids with igrc_list_tenants)
A create/update returns a "bad request" errorA field used the wrong id type (e.g. a name where an id was expected, or a text id where a number was expected)Have your AI resolve ids with the igrc_lookup_* and list tools first, then retry
An evidence upload returns "upload failed"A file with the same name already exists on that recordRename the file or attach it to a different record
One tool reports "not found" while others succeedYou're pointed at an environment that doesn't expose that pathCheck the Instance URL (production vs. sandbox) or confirm with intelliGRC
Write tools missing from your AI's tool listConnector is on the Free tier, or the tools aren't selected for your clientUpgrade the intelliGRC connector plan and check your tool selections on the MCP Setup page

intelliGRC tools

igrc_ · 33 tools · Free 25 · Pro 8

Lookups

ToolWhat it does
igrc_lookup_action_plan_categories
Free · Read-only
List the Action Plan category reference values (id + name).
igrc_lookup_action_plan_levels_of_effort
Free · Read-only
List the Action Plan level-of-effort reference values (id + name), used for the levelOfEffortId field on action-plan projects/tasks/subtasks.
igrc_lookup_action_plan_priority_levels
Free · Read-only
List the Action Plan priority-level reference values (id + name), used for the priorityLevelId field on action-plan projects/tasks/subtasks.
igrc_lookup_action_plan_project_statuses
Free · Read-only
List the Action Plan project-status reference values (id + name), used for the statusId field when creating an action-plan project (igrc_create_action_plan_project).
igrc_lookup_action_plan_subcategories
Free · Read-only
List the Action Plan subcategory reference values (id + name), used for the subCategoryId field on action-plan projects/tasks/subtasks.
igrc_lookup_action_plan_subtask_statuses
Free · Read-only
List the Action Plan subtask-status reference values (id + name), used for the statusId field when creating an action-plan subtask (igrc_create_action_plan_subtask).
igrc_lookup_action_plan_task_statuses
Free · Read-only
List the Action Plan task-status reference values (id + name), used for the statusId field when creating an action-plan task (igrc_create_action_plan_task).
igrc_lookup_action_plan_task_types
Free · Read-only
List the Action Plan task-type reference values (id + name), used for the taskTypeId field when creating an action-plan task (igrc_create_action_plan_task).
igrc_lookup_assessment_objective_statuses
Free · Read-only
List the Assessment Objective status reference values (id + name), used for the statusId field when updating an assessment objective (igrc_update_assessment_objective).
igrc_lookup_boundary_availability_levels
Free · Read-only
List the Boundary availability-level reference values (id + name), used for the availabilityId field when creating a boundary (igrc_create_boundary).
igrc_lookup_boundary_confidentiality_levels
Free · Read-only
List the Boundary confidentiality-level reference values (id + name), used for the confidentialityId field when creating a boundary (igrc_create_boundary).
igrc_lookup_boundary_information_system_types
Free · Read-only
List the Boundary information-system-type reference values (id + name), used for the systemTypeId / informationSystemTypeId fields when creating a boundary (igrc_create_boundary).
igrc_lookup_boundary_integrity_levels
Free · Read-only
List the Boundary integrity-level reference values (id + name), used for the integrityId field when creating a boundary (igrc_create_boundary).
igrc_lookup_boundary_operational_statuses
Free · Read-only
List the Boundary operational-status reference values (id + name), used for the operationalStatusId field when creating a boundary (igrc_create_boundary).

Action Plan

ToolWhat it does
igrc_create_action_plan_project
Pro · Write
Create an Action Plan project.
igrc_create_action_plan_subtask
Pro · Write
Create an Action Plan subtask under a parent task.
igrc_create_action_plan_task
Pro · Write
Create an Action Plan task.
igrc_list_action_plan_projects
Free · Read-only
List Action Plan projects, optionally filtered to one evaluation and optionally expanding their tasks and subtasks.
igrc_list_action_plan_subtasks
Free · Read-only
List Action Plan subtasks, optionally filtered to one evaluation.
igrc_list_action_plan_tasks
Free · Read-only
List Action Plan tasks, optionally filtered to one evaluation and optionally expanding their subtasks.

Assessment Objectives

ToolWhat it does
igrc_get_assessment_objective_history
Free · Read-only
Get the change history for a single assessment objective.
igrc_list_assessment_objectives
Free · Read-only
List assessment objectives, optionally filtered by evaluation and/or framework.
igrc_update_assessment_objective
Pro · Write
Update a single assessment objective (full replace).

Evidence

ToolWhat it does
igrc_create_evidence_link
Pro · Write
Attach an external URL as evidence to a parent GRC record.
igrc_list_evidence
Free · Read-only
List all evidence records for the tenant.
igrc_list_evidence_by_evaluation
Free · Read-only
List evidence for a specific evaluation, optionally narrowed to one framework.
igrc_upload_evidence_file
Pro · Write
Upload a file as evidence attached to a parent GRC record (multipart/form-data).

Boundaries

ToolWhat it does
igrc_create_boundary
Pro · Write
Create an information-system boundary.
igrc_list_boundaries
Free · Read-only
List the information-system boundaries defined for the tenant.

Evaluations

ToolWhat it does
igrc_create_evaluation
Pro · Write
Create (start) a new evaluation.
igrc_get_current_evaluation
Free · Read-only
Get the current working evaluation for the tenant (the one most tools default to).
igrc_list_evaluations
Free · Read-only
List all evaluations for the tenant.

Tenants

ToolWhat it does
igrc_list_tenants
Free · Read-only
List the intelliGRC tenants the configured API credential can act on.