Pages
Integrations — Ideas v3

Source: qdash /integrations — c61 JTBD-first refinements, 2026-08-13

This pass starts from operator jobs instead of connector inventory. The framing change is simple: integrations are not the object of the page; operating outcomes are. Connectors appear only as routes that complete a job, so projected integrations stop feeling like uncreated clutter and start reading as measured paths a job could take.

Frame

From "connectors" to "jobs"

The directory-first page asks the operator to parse the roadmap. The job-first page asks what they are trying to accomplish, then reveals the minimum integration surface needed to accomplish it.

Directory-first
qcqcontrol streaminbound telemetrylive
PdPagerDutyalert routingdry-run
SpSplunkSIEM deliveryprojected
S3Amazon S3archive deliveryprojected
Accurate, but mentally expensive: the operator has to infer why unconfigured Splunk, S3, Okta, and Jira are all visible at once.
Job-first
Prove nothing leavesloopback ledger + explicit exports0 bytes
Get findings into SOCSIEM routes appear inside this job9 findings
Wake respondersalert routes appear inside this job10 would-fire
Hand evidence to auditorslocal packet now, archive later87%
The same data, but the page now explains why each integration is present: it helps a concrete operating job cross from local proof to downstream action.
Iteration A

Job cards first

Replace the connector grid with a short set of operating jobs. Each card carries the current truth state, the local proof qdash already has, and only the integrations relevant to that job.

Prove nothing leaves

live

Security wants confidence that qdash is observing locally before any external destination is discussed.

Local proof
0 network bytes sent by qdash; 148,912 events remain in local SQLite; exports are operator-triggered.
Integration routes
Loopback ledgerliveFindings CSVlocalSOC 2 packetlocal

Get findings into the SOC

projected

SOC analysts need qdash evidence in the search and detection tools they already operate.

Local proof
9 findings and 148,912 events can be shaped as OCSF/HEC payloads today.
Integration routes
SplunkprojectedSentinelprojected

Wake the right responders

dry-run

Severe findings need escalation rules before live delivery exists.

Local proof
Current routing would have created 2 PagerDuty pages, 7 Slack messages, and 1 digest.
Integration routes
PagerDutydry-runSlackdry-runEmail digestdry-run

Hand evidence to auditors

local now

GRC needs a packet today and durable archive paths later.

Local proof
SOC 2 packet covers 41 controls with 87% current coverage.
Integration routes
Security packetlocalS3 IcebergprojectedSnowflakeprojected

Verify who owns agents

projected

Observed identities are useful, but ownership gets trusted only after IdP verification.

Local proof
14 observed identities are ready to join; 4 still require human mapping.
Integration routes
OktaprojectedEntra IDprojected

Move findings into remediation

projected

Security findings become accountable when they enter engineering work queues.

Local proof
9 findings can become issues with evidence links and owners once a project is mapped.
Integration routes
JiraprojectedLinearcandidate
Iteration B

Workflow lanes

Another shape: organize the page by where the operator is in the incident/evidence loop. Integrations become exits from that loop, not standalone things to browse.

1
Observe
what qdash knows locally
qcontrol streamlive
148,912 events · last event 4s ago
Loopback ledgerlive
0 bytes sent; local-only posture is inspectable
2
Triage
what needs attention
Alert routingdry-run
severity rules exist; delivery is still simulated
PagerDuty / Slackroutes
appear only because this job needs responders
3
Prove
what can be handed off
Findings exportlocal
JSON/CSV download works today
S3 / Snowflakeprojected
archive paths appear after the evidence job
4
Operationalize
what should become live
Splunk / Sentinelprojected
first customer-facing delivery gap
Okta / Jiraprojected
cross-page leverage for ownership and remediation
Iteration C

Open a job, then choose a route

This is the clearest antidote to uncreated-connector clutter. When the operator opens "Get findings into the SOC," Splunk and Sentinel appear because they are candidate routes for that job, with payload previews and blockers attached.

Get findings into the SOC
Analysts need qdash findings and enough raw event context inside their search and detection workflow.
9
findings
2
high severity
148.9k
events
7
egress entities
Projected means qdash can produce the payload and volume estimate now; it cannot yet store credentials, deliver, retry, or report destination health.
Selected route: Splunk
{
"event.kind": "finding",
"finding.uid": "F-009",
"severity": "high",
"actor.email": "sofia@meridian.dev",
"control.id": "credential-redaction",
"evidence.source": "local qcontrol stream"
}
Before this can go live
Payloadready
Endpoint configoperator
Credential storeproduct
Retry + healthproduct
Iteration D

A job-ranked action queue

The action queue is the operational version of the directory. It says which job is blocked, which integration route unlocks it, and whether the next move belongs to the operator or the product.

PriorityJobRouteCurrent proofNext ownerAction
01
Get findings into the SOC
enterprise adoption gate
Splunkprojected
148,912 events + 9 findings shaped for HEC JSON / OCSF.
product
02
Wake the right responders
severity routing already exists
PagerDuty + Slackdry-run
2 pages and 7 messages would have fired this week.
operator + product
03
Hand evidence to auditors
packet works, archive is next
S3 Icebergprojected
148,912 append-only events ready for retention.
product
04
Verify who owns agents
identity confidence affects every page
Okta / Entra IDprojected
14 observed identities; 4 still need mapping.
customer + product
Coda

The revised framing

The page can still contain the full integration vocabulary, but the first screen should not be a catalog. It should be a job board with a receipt: what is local, what is exportable, what is dry-run, and which downstream job is blocked by missing delivery.

Projected becomes contextual
A projected connector appears because a job needs it, and the row explains the proof, payload, and missing live pieces.
The directory can move down-page
A full connector list still helps advanced users, but it follows jobs, filters, and route previews.
The first screen becomes useful
An operator can answer: what is true, what can I export, what is dry-run, and what job is blocked next.

Qpoint Brand Style Guide