Skip to content

Products

Compliance Officer Service Expert-led compliance, end to end Compliance Portal Share security documents securely Employee Portal Your whole team’s compliance, in one portal Access Review Monitor user access across all your systems AI Agents Run compliance from the tools you use Cookie Banner Consent that follows every visitor's law Device Agent Continuous security posture for every device Open-source platform Deploy Probo on your own infrastructure

Resources

Probo stories How teams get compliant with Probo Blog Ideas and guidance from the Probo team Guides & tools Practical compliance guides and free tools Love from Customers What customers say about working with Probo Changelog Latest product updates Download Get the Device Agent

Company

About The people and vision powering Probo Careers Join the team building Probo Brand assets Official logos and visual resources Security Review our security and compliance posture
Overview Understand Probo and its core concepts Product Explore Probo's GRC capabilities Developers Explore GraphQL, CLI, MCP, n8n, and webhooks Deployment Probo Cloud, self-hosting, and configuration

Explore

GitHub Explore our open-source compliance tools

Better Stack

Connect Better Stack as an access review source using a Global API token and team name so Probo can list that team's members and roles.

View as Markdown

Probo reads the members of one Better Stack team through the Uptime API so you can review who has access.

  • Probo organization administrator access
  • The Admin role in Better Stack. Only Admins can edit API tokens, and a Team lead can only view them
  • The Team Name of the team Probo should review, which the Connect dialog asks for alongside the token. Better Stack lists your teams at Settings > Teams. Enter the name exactly as Better Stack spells it, including capitalization
Probo fieldBetter Stack fieldNotes
Namefirst_name, last_nameProbo joins the two into one name and drops a missing part. A pending invitation carries neither, so the name stays empty
EmailemailProbo skips a record that comes back without an email address
RoleroleProbo shows admin, billing_admin, team_lead, responder and member as Admin, Billing admin, Team lead, Responder and Member. Any other value, including custom, appears as returned. A record with no role is left without one
AdminroleFlagged as an administrator when role is admin or team_lead. billing_admin (billing only) and custom roles are not flagged, so check a custom role’s permissions in Better Stack
StatustypeProbo lists team_member as active and team_member_invitation as inactive. Any other type leaves the status unknown
MFANot supported
Last loginNot supported
External IDidStable identifier used to track the account across reviews
Created atcreated_atWhen the member joined the team. Probo falls back to invited_at when created_at is missing, as on a pending invitation

Probo also lists members who have been invited but have not yet accepted, and marks them inactive. The role Better Stack returns is the member’s role in the team being listed. admin and billing_admin are organization-wide roles in Better Stack, so they are the same in every team.

Creating a read-only Global API token in the Better Stack API tokens settings

  1. In Better Stack, signed in as an Admin, go to API tokens and find the Global API tokens section. A global token is valid across all of your teams, which is why the team members endpoint takes a team name.
  2. Enter a Token name (e.g. Probo Access Review), set the permission to Read only, and click Create. Read-only access is enough because Probo only reads team members.
  3. Copy the token and store it securely. Existing tokens show a Copy button on this screen, so you can retrieve the token later.
  1. In Probo, go to Access Review > Connections.
  2. Find Better Stack, click API Key, paste the token, enter your Team Name, and click Connect.

When you click Connect, Probo uses the token to request that team’s members from Better Stack. If Better Stack has no team by that name for the token, the dialog shows an error under Team Name and Probo does not save the connection. After you connect, Probo names the source after the team name you entered and pulls that team’s members into your campaigns.

With a team-based Uptime API token, Better Stack ignores the team name and lists the token’s own team, so enter that team’s name to keep the source label accurate.

  • Token rejected. Confirm the token is a Global API token or a team-based Uptime API token. Better Stack rejects a Telemetry API token on the team members endpoint. A token of the wrong kind is not caught when you connect: the source then shows Better Stack credentials are invalid.
  • “Better Stack has no team with this name for this API token.” Better Stack matches team names exactly, including capitalization. Copy the name from Settings > Teams, or use a team-based Uptime API token for the team.
  • Token creation is unavailable. Editing API tokens is an Admin permission in Better Stack. A Team lead can view tokens but not create them, so ask an Admin.
  • Roles do not match what Better Stack shows. The endpoint reports the role the member holds in the team being listed, so confirm the Team Name matches the team you meant to review. Custom roles are an Enterprise feature and come back as custom. Probo flags only admin and team_lead as administrators.