Skip to main content
This guide walks you through connecting your Swif organization to Clarion. Once connected, Clarion discovers your managed devices into the Brain as device assets and your employee directory as identity assets, so an issue involving a person surfaces the laptops they carry — and their compliance posture — alongside it.
Estimated time: 3 minutes. You will need admin access to your Swif organization so you can generate an API token.

Prerequisites

  • A Swif organization, on either the US / Global or the EU tenant
  • Admin access to Settings → API token in Swif
  • A Clarion workspace with the Swif integration page open

Step 1 — Generate an API token in Swif

  1. Sign in to Swif as an admin.
  2. Go to Settings → API token.
  3. Click Generate API key.
  4. Copy the generated token.
Copy the token immediately — Swif shows it once. Store it securely. The token is scoped to a single organization, so generate one per organization you want Clarion to see.

Step 2 — Enter credentials in Clarion

  1. In Clarion, open Integrations and find Swif under Identity & Access.
  2. Pick your Region:
    • US / Global for organizations on the global tenant
    • EU for organizations on the European tenant
  3. Paste the API token from Swif.
  4. Click Connect.
A token generated on one tenant does not authenticate against the other. If Clarion reports that Swif returned a 404, try the other region.
Clarion verifies the token against your device inventory before saving. If the token is invalid or the region is wrong, you’ll see a clear error and nothing is persisted.

What Clarion discovers

Discovery runs on each asset sync — the manual Sync action or the scheduled auto-update. No extra configuration is needed beyond the token.

Linking devices to people

When a device’s assigned owner in Swif matches a person Clarion already knows — from Okta, Google Workspace, or another connected directory — the device is linked to that person. Opening an issue that involves them shows their devices as related assets, so you can see at a glance whether the machine in question is encrypted and enrolled. Swif employees are matched to people the same way, by email address. Because Swif’s roster is typically fed from your HRIS or identity provider, these rows corroborate people Clarion already tracks rather than creating duplicates.

Disconnect

To remove the integration:
  1. In Clarion, open Integrations → Swif.
  2. Click Disconnect.
This deletes the stored token. Devices and employees already discovered remain in the Brain as historical assets and simply stop refreshing.

Troubleshooting

”Swif rejected the API token”

The token is invalid, was revoked, or belongs to a different organization. Generate a fresh one under Settings → API token in Swif and reconnect.

”Swif returned 404”

Your organization is almost certainly on the other regional tenant. Disconnect, then reconnect choosing the other Region.

Only some devices appear

Each sync covers up to the first 10,000 devices and the first 10,000 employees Swif returns — fewer if the run’s time budget is reached first — and Clarion notes the shortfall on the sync result. Swif’s API exposes no changed-since filter, so every run re-reads the roster from the start — re-syncing will not reach the tail of a fleet larger than that. If your fleet is under 10,000 and the count still stays short, check that the token has not been scoped to a subset of your organization.