> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Pumble

> Team chat — members, channels & access

<Tabs>
  <Tab title="Overview">
    Connect Pumble with an API key from the workspace's API add-on to sync workspace members with their roles and status (bots excluded), channels and user groups, and run access reviews. Read-only. Data feeds into your Access accounts and Inventory pages.

    <Info>
      **Read-only access.** DSALTA only reads data from this integration. It never creates, modifies, or deletes anything in your environment, and every remediation step is performed by your team directly in the third-party product.
    </Info>

    <Info>
      **What you'll see.** The Access page lists the members of the one Pumble **workspace** the API key was generated in, with their name (or their email address when Pumble carries no name), email, and their Pumble role in the role column (**Owner**, **Admin**, **Guest**, or **Member** for a regular user or when no role is reported). Pumble's built-in bot and add-on bots — including any row with no email address or an `@pumble.app` address — are left out, as is any row whose status reads as an invitation. A member Pumble reports as **activated** is shown as **Active**; any other status is shown as **Inactive**. Pumble reports no join date, so each row is stamped with the date of the sync. Pumble reports no per-user MFA state, so the **MFA** column is blank (shown as a dash).
    </Info>

    <Note>
      DSALTA collects this integration's data when you connect it — you can refresh it at any time with **Sync from integrations** on the **Integrations** page. The compliance checks below re-run once a day at 02:00 America/New\_York.
    </Note>

    ## What DSALTA reads

    DSALTA reads the workspace member list — names, emails, roles and status — which appears on your **Access** page; and your Pumble **channels** (type, whether it is the main channel, archived or hidden, its member count and description) and **user groups** (member count), which appear on your **Inventory** page. Direct-message and self conversations are not inventory and are skipped. Channels and user groups are read best-effort after the member list; user groups appear once you have created one. Messages, reactions and scheduled messages are never read.

    It calls these endpoints of Pumble's API add-on on `pumble-api-keys.addons.marketplace.cake.com`:

    * `/myInfo`
    * `/listUsers`
    * `/listChannels`
    * `/listUserGroups`

    Every request is a read. DSALTA has no code path that creates, modifies, or deletes anything in your Pumble environment.

    ## Troubleshooting

    <AccordionGroup>
      <Accordion title="The connection is rejected">
        The key is invalid or was deleted — Pumble answers *Invalid key* — or the user list returned no human member. Generate a key through the workspace's API add-on (**+ Add apps → API → Install**, then **API → Add API key**) and connect again.
      </Accordion>

      <Accordion title="The Access page shows a different workspace than expected">
        A key is bound to the workspace it was generated in, and DSALTA syncs that workspace — it cannot tell which workspace you meant. If the user who generated the key belongs to several workspaces, generate the key while inside the right one, then disconnect and connect again. Note that disconnecting permanently deletes the data already collected from Pumble.
      </Accordion>

      <Accordion title="Inventory is empty, or shows channels but no user groups">
        Channels and user groups are read best-effort after the member list: a failure on either call leaves that part of the Inventory page empty without failing the sync, and a workspace with no user groups has none to list. Click **Sync from integrations** on the **Integrations** page to retry.
      </Accordion>
    </AccordionGroup>

    <AccordionGroup>
      <Accordion title="How do I check whether the connection is healthy?">
        Open **Integrations** in the DSALTA sidebar, stay on the **Connected** tab, and click **Manage** on the integration's card. Open the **Status** tab: it shows either **Connected and working properly** or **Connection issues detected**.

        Use the **Status** tab, not **Overview** — Overview always reports **Connected** regardless of the real state.
      </Accordion>

      <Accordion title="A check shows Failed and nothing changed on my side">
        On an integration-powered check, **Failed** normally means DSALTA was blocked rather than that you are non-compliant. Open the test, go to **Source Data**, and read the result code: **403** is a missing permission, **428** is a setting DSALTA still needs, **500** is a failure on DSALTA's side.

        A real compliance gap shows **207** and leaves the test looking **Completed**. See [Understanding Test Results](/guides/compliance/test-results).
      </Accordion>

      <Accordion title="Data looks out of date">
        Compliance checks re-run once a day at 02:00 America/New\_York. To refresh sooner, open **Integrations → Connected** and click **Sync from integrations** at the top right — it refreshes every connected integration at once.
      </Accordion>

      <Accordion title="How do I repair a broken connection?">
        There is no Reconnect, Repair or Refresh Token button. The only repair available is to disconnect and connect again.

        <Warning>
          **Disconnecting is destructive and cannot be undone.** DSALTA removes the access records, inventory, vulnerabilities, code changes, incidents and device records collected from this integration, and deletes the test results tied to the connection. Export anything you still need as audit evidence first — see [Integration errors](/troubleshooting/integration-errors).
        </Warning>
      </Accordion>

      <Accordion title="Configure scope will not let me change anything">
        That is expected. **Configure scope** is read-only — it shows what DSALTA is permitted to read, and has no Save action. To change what DSALTA can see, change the permissions on the credential in the third-party product, then disconnect and connect again.
      </Accordion>
    </AccordionGroup>
  </Tab>

  <Tab title="How to connect">
    A Pumble API key generated through the workspace's API add-on by the Owner or an Administrator. The workspace is detected automatically. Read-only.

    **Before you begin**

    * A Pumble workspace Owner or Administrator — the key is personal and carries that user's access.
    * On the Free plan, a free app slot for the API add-on — the plan allows three apps and integrations.

    You will need:

    | Field | Where to find it | Example |
    | - | - | - |
    | **API key** | **+ Add apps → API → Install**, then **API → Add API key → Generate** | Shown once, in an ephemeral message |

    <Steps>
      <Step title="Start in DSALTA">
        Open **Integrations** in the DSALTA sidebar, find **Pumble**, and click **Connect** to open the connect panel.
      </Step>

      <Step title="Sign in as the Owner or an Administrator">
        Open the workspace you want to review, signed in as its Owner or an Administrator.

        <Info>
          The key is generated for that user and stops working if the user is removed from the workspace, so do not create it from a personal or contractor account.
        </Info>
      </Step>

      <Step title="Install the API add-on">
        Click **+ Add apps** in the left sidebar, then **Install** in the **API** section and allow the permissions. The **API** item appears in the sidebar only after this step. The add-on uses one of the Free plan's three app slots.
      </Step>

      <Step title="Generate an API key">
        Click **API** in the left sidebar, then **Add API key**, enter a name (for example `dsalta`) and click **Generate**.

        <Warning>
          **Pumble sends the key in an ephemeral message that only you can see and that is not shown again.** Copy it now. If it is lost, delete the key and generate a new one.
        </Warning>
      </Step>

      <Step title="Connect Pumble">
        Return to the connect panel, paste the API key, and click **Connect**. The workspace is detected automatically.
      </Step>
    </Steps>

    <Check>
      DSALTA validates the key when you click **Connect**, by reading the key's own user record and listing the workspace's users — a list with no human member is rejected. On success the integration moves to the **Connected** tab, and **Manage → Status** reads **Connected and working properly**. Checks begin reporting after the first sync.
    </Check>

    <Warning>
      **If the connection is rejected.** An invalid or deleted key (Pumble answers *Invalid key*), or a key whose user list contains no human member.

      The on-screen message is generic — see [Connection error messages](/troubleshooting/connection-error-messages).
    </Warning>
  </Tab>

  <Tab title="Automated checks">
    Each check below re-runs once a day, at 02:00 America/New\_York, while this integration is connected. Click any check for step-by-step remediation guidance.

    | Check | Severity | What it verifies |
    | - | - | - |
    | [User access to Critical System should be valid](/integrations/pumble/user-access-to-critical-system-should-be-valid) | Info | Checks that everyone with Pumble access is an active employee on the People page. |
    | [Offboarded users should not have active access](/integrations/pumble/offboarded-users-should-not-have-active-access) | High | Checks that offboarded employees no longer have active Pumble access. |
  </Tab>

  <Tab title="Useful links">
    | Topic | Link |
    | - | - |
    | Setup | [Pumble API keys integration](https://pumble.com/help/integrations/automation-workflow-integrations/api-keys-integration/) |
    | Remediation | [Roles and permissions](https://pumble.com/help/getting-started/overview-of-roles-and-permissions/roles-permissions/) |
    | General | [Pumble](https://pumble.com) |
    | DSALTA | [Connection error messages](/troubleshooting/connection-error-messages) |
  </Tab>
</Tabs>
