Connect intelliGRC
intelliGRC is a CMMC / GRC compliance platform for MSPs and their clients. Connecting it to StackJack gives your AI assistant a focused family of igrc_ MCP tools — MCP (Model Context Protocol) tools…
Written By Christopher Scaminaci
Last updated 6 days ago
intelliGRC is a CMMC / GRC compliance platform for MSPs and their clients. Connecting it to StackJack gives your AI assistant a focused family of igrc_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- Review evaluations, the assessment objectives inside them, and each objective's change history
- Inspect system boundaries and the reference lookups (statuses, priority levels, confidentiality/integrity/availability levels, and more) that describe them
- Track the action plan — remediation projects, tasks, and subtasks
- Read the evidence attached to your compliance records
- Act (on Pro plans) — create evaluations, boundaries, action-plan projects/tasks/subtasks, update assessment objectives, and attach or upload evidence
Documentation boundary. intelliGRC's public website describes its provider-first, multi-tenant GRC product, but does not publish API authentication, host, lifecycle, pagination, or rate-limit documentation. The setup steps below reflect how StackJack connects to intelliGRC. Confirm credential issuance and tenant-specific restrictions with intelliGRC before production use.
How StackJack authenticates to intelliGRC
intelliGRC uses a static API credential — a client id and client secret issued from the intelliGRC console. There is no browser OAuth or refresh-token flow. StackJack sends x-client-id and x-client-secret; it also sends x-tenant-id when a default or per-call tenant is available. intelliGRC does not publicly document credential expiry or rotation, so treat vendor lifecycle details as account-specific.
Which intelliGRC organization a call targets
intelliGRC calls this its tenant — the organization a request acts on. One StackJack credential can work across every intelliGRC tenant it has access to:
- You can set a default tenant when you connect, so tools that don't specify one use it.
- Every tool also accepts an optional tenant id parameter that targets a specific organization for that one call.
- Your AI can list the tenants a credential can reach with the
igrc_list_tenantstool, then use one of those ids as the override.
If you only work with a single intelliGRC organization, set it as the default and you can ignore the per-call parameter entirely.
Before you begin
- In StackJack: you need a role that can manage connectors (tenant Owner, a co-owner, or an Administrator).
- In intelliGRC: you need to be able to obtain API credentials (a client id and client secret) — from the intelliGRC console or through your intelliGRC contact.
- Know your tenant id if you want to set a default organization for your calls.
Step 1 — Get API credentials from intelliGRC
- In the intelliGRC console (or via your intelliGRC representative), request API credentials for programmatic access.
- Record the client id and client secret — you'll paste both into StackJack.
- Note the tenant (organization) id you want StackJack to use by default. If you manage several intelliGRC organizations, you can leave the default blank and pass a tenant id per call instead.
Step 2 — Add the credentials in StackJack
- In the StackJack portal, open Connectors.
- Select the intelliGRC tile to open its details drawer.
- Use How To Connect to review the inline setup, then choose Configure in the drawer footer.
- Enter the Client ID and Client Secret.
- Optionally enter a Default tenant id — the intelliGRC organization to act on when a tool doesn't specify one.
- Leave the Instance URL blank for production (
https://api.intelligrc.app), or enterhttps://dev-api.intelligrc.appif intelliGRC provisioned that sandbox. StackJack rejects other hosts before storing credentials. - Click Save.
What happens when you save
- The client id and secret are stored encrypted in Azure Key Vault — never in the StackJack database, and never shown back to you.
- If this is the first time you configure intelliGRC, a Free-tier subscription for the connector is created automatically so its Free tools work right away.
- StackJack immediately live-validates the credentials by listing the tenants the credential can reach. The credential remains saved if the upstream check fails so you can correct vendor access without re-entering every field.
- The Configure form collapses while the details drawer stays open. The drawer shows Connected and Valid after success, or Needs Attention with the vendor error and a Re-test action after failure.
Plans and available tools
See the generated intelliGRC tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.
intelliGRC's API credential is a single shared key, not a per-user login, so all AI traffic authenticates as that one credential — there is no per-user attribution. Current pricing and quotas are shown in the portal's Billing page and at checkout.
Tip — resolve reference ids first. Many create/update tools take numeric ids (a status, a priority level, a boundary's confidentiality/integrity/availability level). Your AI can look these up with the
igrc_lookup_*tools before it builds a request, so it uses the exact id intelliGRC expects.
A note on the base URL
StackJack targets the production intelliGRC API by default. Its authority guard permits only api.intelligrc.app and dev-api.intelligrc.app; it rejects HTTP, embedded credentials, and any other host before saving. If a specific tool reports "not found" while others work, verify that you selected the environment intelliGRC provisioned and confirm endpoint availability with the vendor.
Rate limits
No numeric intelliGRC API quota is available in public vendor documentation. StackJack applies conservative per-tenant pacing and records 429 backoff, so a burst is slowed rather than sent all at once. Ask intelliGRC for any account-specific ceilings before scheduling high-volume workflows. Pacing is not a guarantee: retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.
Rotating or replacing the credentials
If intelliGRC rotates or revokes the client id/secret, open the intelliGRC details drawer, choose Configure, enter the replacement values, save, and choose Re-test. Ask intelliGRC whether the old credential must be revoked separately; no public lifecycle contract is available.
Disconnecting intelliGRC
Choose Disconnect in the intelliGRC details drawer and confirm. StackJack deletes its stored credential and default-tenant value and stops making intelliGRC calls. Disconnecting does not revoke the upstream API credential; coordinate that separately with intelliGRC. Connector subscription changes are separate from credential disconnection.
Troubleshooting
intelliGRC tools
igrc_ · 33 tools · Free 25 · Pro 8
Lookups
Action Plan
Assessment Objectives
Evidence
Boundaries
Evaluations
Tenants
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team