Changelog
Product update of the week: Year 4 • Week 39
New in Truto: Cloud Infrastructure for AWS, a major HRIS expansion, and 29 new AI-ready integrations
This week we shipped a brand-new Cloud Infrastructure Unified API starting with AWS, covering everything from IAM identities to security posture findings. We also expanded the Unified HRIS API across more than 20 providers — new resources, new write support, and 16 new HRIS integrations. On top of that, we shipped 29 new AI-ready integrations, a Unified MDM connector for ManageEngine MDM, nine new Xero operations, archive downloads for Bitbucket and GitLab, and a batch of connections-widget UI fixes.
✨ Highlights
- New Cloud Infrastructure Unified API — one model for cloud accounts, identity and access, data stores, networking, and security posture, starting with AWS.
- AWS now connects with a role-based credential — no long-lived AWS keys are shared or stored in Truto.
- Major Unified HRIS API expansion: new and expanded resource coverage across 20+ providers, plus 16 new HRIS integrations.
- Added 29 new AI-ready integrations, including Onfleet, Airwallex, Heap, and Paddle, for building AI workflows.
- New Unified MDM API support for ManageEngine MDM.
- Xero now supports nine new Unified Accounting API operations.
- Bitbucket and GitLab both added repository/source archive downloads.
- Fixed a batch of Connections widget UI issues — card misalignment, stale resource-mapping fields, tenant metadata visibility rules, and a redundant edit/save step.
🤖 AI-ready integrations

- Onfleet: Let AI agents manage Onfleet delivery tasks, routes, and driver tracking data.
- Qomon: Connect AI agents to Qomon supporter, volunteer, and campaign organizing data.
- Tipalti: Give AI agents access to Tipalti payee, invoice, and global payment data.
- SoftSync: Let AI agents work with SoftSync CRM records and data-sync workflows.
- Airwallex: Give AI agents access to Airwallex accounts, payments, and global transfer data.
- Bizzabo: Let AI agents manage Bizzabo event registrations, sessions, and attendee data.
- Paddle: Connect AI agents to Paddle subscriptions, invoices, and billing data.
- Active Ants: Give AI agents access to Active Ants order fulfillment and shipping data.
- Heap: Let AI agents analyze Heap product usage, events, and user behavior data.
- Zoho Billing: Connect AI agents to Zoho Billing subscriptions, invoices, and payment data.
- Drip: Let AI agents manage Drip email campaigns, subscribers, and marketing automation data.
- Clazar: Connect AI agents to Clazar cloud marketplace listings and co-sell data.
- Fillout: Let AI agents manage Fillout forms, submissions, and response data.
- CallHub: Give AI agents access to CallHub calling campaigns, contacts, and SMS data.
- CallRail: Connect AI agents to CallRail call tracking, recordings, and marketing attribution data.
- Acumatica: Let AI agents manage Acumatica ERP financials, inventory, and business data.
- JustSift: Give AI agents access to JustSift org structure and people directory data.
- Intruder: Connect AI agents to Intruder vulnerability scans and security findings data.
- Imagga: Let AI agents use Imagga image recognition, tagging, and visual analysis.
- Huntr: Give AI agents access to Huntr job application and candidate pipeline data.
- Fleetio: Connect AI agents to Fleetio fleet vehicles, maintenance, and inspection data.
- Dayforce: Let AI agents manage Dayforce employee, payroll, and workforce data.
- Instatus: Give AI agents access to Instatus status pages, incidents, and uptime data.
- Shippo: Connect AI agents to Shippo shipping labels, rates, and tracking data.
- Eventee: Let AI agents manage Eventee event schedules, sessions, and attendee data.
- Flexmail: Give AI agents access to Flexmail email campaigns, contacts, and marketing data.
- Sentry: Give AI agents access to Sentry issue tracking, release data, and org/user directory via unified and proxy APIs.
- Lightfield: Connect AI agents to Lightfield CRM records and pipeline data.
- AWS: Give AI agents unified access to AWS accounts, identity and access, data stores, networking, and security posture.
🧩 New HRIS integrations: HR WORKS, Humi, Omni HR, Justworks, Dayforce, UKG Ready, Proliant, ChartHop, TriNet, Altera Payroll, SAP SuccessFactors, PayCaptain, Kallidus, Paylocity, Sesame, and UKG Dimensions.
🔗 New Unified APIs
☁️ Cloud Infrastructure — a new Unified API, starting with AWS
The new Cloud Infrastructure Unified API gives you one model for cloud security, identity, and compliance data. AWS is the first provider. It covers:
- Accounts and structure: cloud accounts, account groupings
- Identity and access: human identities, workload identities, access grants, permission definitions, static credentials, password policies
- Data and keys: object stores, relational databases, managed keys, data snapshots
- Network and logging: network boundaries, firewall rule sets, network links, log destinations, audit trail configs
- Security posture: posture findings, threat findings, vulnerability findings, policy constraints, policy compliance states, scan coverage, security product states
To install it, go to Unified APIs → Install from catalog → Cloud Infrastructure.
Unified MDM API — ManageEngine MDM
ManageEngine MDM is now available on the Unified MDM API.
📈 Expanded Unified APIs
Xero — nine new Unified Accounting API operations
- Accounts — update and delete
- Contacts — update
- Credit Notes — create and update
- Items — update and delete
- Payments — update
- Purchase Orders — create, update, and download
- Tax Rates — create
- Tracking Categories — create, update, and delete
- Transactions — update
🧑💼 Unified HRIS API — a major expansion
We expanded the Unified HRIS API across more than 20 providers this week — new resources, new write support, and 16 new HRIS integrations. Resource support varies by provider's own API, so here's what you can now do with each.
| Integration | What you can now do |
|---|---|
| Manage employees, employments, compensation, offices, departments, entity groups, job roles, time off and timesheets; read companies, bank info, time-off types, policies and fields. | |
| Manage employees, employments, compensation, bank info and locations; create companies, departments, teams and job roles; read dependents, time off, time-off types and balances, pay groups, payslips and fields. | |
| Manage employees, org units, cost centers and time-off requests; read locations, employments, compensation, bank info, time-off types, policies and balances, and timesheets. | |
| Create and delete employees and manage time-off requests; read locations, cost centers, labor entries, labor categories, job roles, employments, compensation, time-off types, policies and balances, and timesheets. | |
| Update employees; read companies, offices, departments, employments, compensation, time off, time-off policies, payroll runs, payslips and fields. | |
| Manage employees and groups; read group categories and job profiles. | |
| Read companies, locations, employees, employments, compensation, bank info, cost centers, cost-center levels, job roles and timesheets. | |
| Read employees, employments, compensation and approved time-off requests. | |
| Manage locations, groups, job roles, employees, employments, time off and timesheets; update companies; create compensation records; read time-off types and payroll runs. | |
| Manage companies, groups, employees, time off and timesheets; read locations, group types, job roles, employments, compensation, time-off types, policies and balances, payroll runs, pay groups and fields. | |
| Manage employees and compensation; read and delete bank info; read companies, locations, groups, job roles, time-off balances, payroll runs, employee payroll runs and fields. | |
| Update and delete timesheets; create time-off requests; read companies, groups, group types, job roles, employees, employments, time-off types, policies and balances, employee payroll runs and pay groups. | |
| Create groups; update employees; create and update time-off requests; read companies, job roles, employments, compensation, time-off types, policies and balances, timesheets, payroll runs, employee payroll runs, benefits, company benefits and fields. | |
| Create employees and employments; create and delete time-off requests; read companies, bank info and employee payroll runs. | |
| Read and create dependents. |
New HRIS schema: added dependents and timesheet_entries as new resources.
⚙️ Platform Improvements
AWS connections with no access keys
AWS now connects through a new role-based credential. Your customer deploys a CloudFormation template that creates a read-only role. Truto assumes that role with a unique External ID for each connection — no long-lived AWS keys are shared or stored in Truto.
- With AWS Organizations, connect the management account once, then read any member account by passing
account_id. - You can set your own CloudFormation template URL and signing AWS account for each environment in Integration Settings.
- AWS Proxy APIs cover IAM, S3, EC2/VPC, KMS, CloudTrail, CloudWatch Logs, Config, Security Hub, GuardDuty, Inspector, Access Analyzer, RDS, and Organizations. Every resource has a description and a schema, so it's ready for AI agents and MCP.
Connections widget fixes
Fixed a batch of Connections widget UI issues — card misalignment, stale resource-mapping fields on switch, tenant metadata not being picked up in visibility rules, and a redundant edit/save step. Applies across the connections list and integration settings widget.
🔄 Integration Improvements
- Bitbucket: Added source archive download for repositories.
- GitLab: Added repository archive download.