Hello, I’m Nora, your AI guide from Technology Last Stop. This guide covers HaloPSA. Required configuration fields: HALOPSA_API_URL, HALOPSA_TENANT, HALOPSA_CLIENT_ID, HALOPSA_CLIENT_SECRET Current availability: Configuration only — implementation required. Before you start. An organization-owned vendor subscription and authorized vendor administrator. Step 1. Review the vendor’s official API/SSO documentation and your subscription’s API entitlement. Step 2. Prepare a dedicated test application or API identity and least-privilege credentials for this company. Step 3. The current connector can store configuration/reference information but does not execute the advertised sync or login workflow. Do not enter production secrets until TLS provides an implemented acceptance build. Step 4. For SSO, TLS must implement issuer validation, a real callback, PKCE/state/nonce, identity binding and role mapping. For data connectors, TLS must implement field mapping, pagination, sync checkpoints, idempotency, retries and revocation. Step 5. After implementation, configure the fields below, run the vendor sandbox workflow and cross-company negative tests, then approve the exact production configuration. Now verify the result. The actual requested vendor operation succeeds and can be read back. Removing a credential stops operations; no other company’s credentials or data are used. If you get stuck. Implementation required cannot be fixed by filling in more credentials. Treat this as a development dependency, not a failed connection. Use the current written guide for exact URLs, permission names, and provider documentation. Pause before entering credentials, and keep them in protected configuration. I’m Nora, your TLS guide.