Integration relationships
Integration relationships show how tools connect to each other, separating designed pairings from accidental overlap.
Last updated September 22, 2026
Tools rarely work alone. Integration relationships show how the products in your stack connect to one another, so the map reflects how your security program actually operates rather than treating every tool as an island. You record and manage these links on the Integrations surface.
These relationships add context the capability view alone cannot. An identity provider feeding a detection platform, or an endpoint tool sending signal to your operations tooling, is a designed relationship. Seeing it helps you understand which tools depend on which, and what breaks downstream if you remove one.
Integration is not the same as overlap, and the distinction is worth holding onto:
Overlap means two tools do the same job. It may be redundant.
Integration means two tools do different jobs and pass work between them. It is usually intentional.
Before you cut a tool flagged for overlap, check its integration relationships. A product that looks redundant on coverage may be the connective tissue several other tools rely on.
Mapping these relationships protects you from a common mistake: consolidating a stack on capability coverage alone and quietly severing the integrations that made it work. CANOPY keeps both views in front of you so a consolidation decision accounts for dependencies, not just duplicated functions.
Use this view alongside overlap detection when you weigh which tools to keep. As tools move through adoption, retirement, or replacement, track that in Tool lifecycle states.