Effective Date: 2026-05-18
Last Updated: 2026-07-28
Provider: BillingReconcile
Website: www.billingreconcile.com
Contact: support@billingreconcile.com
Overview
BillingReconcile uses integrations to compare PSA-side billed quantities against real usage data. The current reconciliation workflow primarily reads billing, client, license, device, endpoint, subscription, and usage data for review.
How integrations are used
Integrations help BillingReconcile sync records from PSA systems and vendor tools, map clients and services, calculate expected quantities, show sync status, and produce discrepancy reports. The exact fields depend on the connected system and the permissions granted by the customer.
Read vs. write access
BillingReconcile is designed around reconciliation review. The current public reconciliation workflow is read-oriented and does not push billing corrections into connected third-party systems.
Credential and token handling
BillingReconcile stores credentials or tokens only where needed to connect to enabled integrations. Customers should rotate or revoke credentials according to their own security procedures and disconnect integrations that are no longer needed.
Disconnecting integrations
Customers can disconnect an integration from BillingReconcile settings where supported. Customers may also revoke API keys, OAuth grants, or app access directly in the third-party system. Disconnecting an integration stops future syncs but does not automatically delete previously synced reconciliation data.
Least-privilege recommendations
Use dedicated integration accounts where possible. Prefer read-only, reporting, inventory, billing, or license roles over administrator roles when those roles provide the data required for reconciliation. Avoid granting mailbox, document, remote-control, or endpoint-management permissions unless a specific connector requires them for a clearly identified feature.
Integration permission table
| Integration type | Data used | Why it is used | Write access |
|---|---|---|---|
| PSA systems | Clients, agreements, services, invoices, products | Compare billed quantities against expected usage | No for the current reconciliation workflow |
| Microsoft 365 | Customer, product, subscription, license, and quantity data from supported connected sources | Compare Microsoft 365 subscription quantities against billed quantities | No |
| RMM systems | Clients, devices, device status, metadata | Compare device counts against billed services | No |
| Security tools | Clients, endpoints, licenses, package metadata | Compare protected endpoints/licenses against billing | No |
| Backup platforms | Clients, protected devices/accounts, backup plan metadata | Compare backup usage against billing | No |
Connector-specific permission examples
The examples below describe the data categories used by common BillingReconcile connectors. Access varies by vendor plan and account. Use the narrowest reporting or read-only role that supplies the agreed billing-review data.
Addigy
- What BillingReconcile reads
- Organizations, managed Apple devices, platform type, count-related state, and related identifiers.
- Why this permission is needed
- To compare managed Apple-device counts against billed MDM or managed-device services.
- What BillingReconcile does not read
- Device passwords, remote-control sessions, or unrelated device file contents.
- Whether BillingReconcile writes back
- No for the current reconciliation workflow.
- How to disconnect
- Disconnect the integration in BillingReconcile settings where supported, and revoke the API key, OAuth grant, or application access in Addigy.
- Recommended permission level
- Use a reporting or read-only API role limited to organization and device inventory.
Bitdefender
- What BillingReconcile reads
- Companies, endpoints, package or policy metadata, license-related counts, and endpoint status.
- Why this permission is needed
- To reconcile protected endpoint and security package usage against billing.
- What BillingReconcile does not read
- Endpoint passwords, file contents, or unrelated security event detail unless needed by a configured connector.
- Whether BillingReconcile writes back
- No for the current reconciliation workflow.
- How to disconnect
- Disconnect the integration in BillingReconcile settings where supported, and revoke the API key, OAuth grant, or application access in Bitdefender.
- Recommended permission level
- Use an API key scoped to inventory, company, package, and license reporting where possible.
Comet Backup
- What BillingReconcile reads
- Customers, protected items, backup type, platform, coverage counts, and related identifiers.
- Why this permission is needed
- To compare protected backup items and coverage categories against billed backup services.
- What BillingReconcile does not read
- Backup contents, customer passwords, encryption keys, or unrelated files.
- Whether BillingReconcile writes back
- No for the current reconciliation workflow.
- How to disconnect
- Disconnect the integration in BillingReconcile settings where supported, and revoke the API key, OAuth grant, or application access in Comet Backup.
- Recommended permission level
- Use a dedicated account limited to customer and protected-item reporting.
ConnectWise
- What BillingReconcile reads
- Companies, agreements, agreement additions, recurring services, products, invoices, and quantity context.
- Why this permission is needed
- To establish the PSA billing baseline and compare it with supported operational source counts.
- What BillingReconcile does not read
- Unrelated ticket content, customer passwords, payment-card data, or remote-control sessions.
- Whether BillingReconcile writes back
- No for the current reconciliation workflow.
- How to disconnect
- Disconnect the integration in BillingReconcile settings where supported, and revoke the API key, OAuth grant, or application access in ConnectWise.
- Recommended permission level
- Use a dedicated API member limited to the records required for billing review.
Cove Data Protection
- What BillingReconcile reads
- Customers, protected devices, protected Microsoft 365 users, active backup-source categories, and related identifiers.
- Why this permission is needed
- To compare protected device, user, and source coverage against billed backup services.
- What BillingReconcile does not read
- Backup contents, mailbox contents, customer passwords, encryption keys, or unrelated files.
- Whether BillingReconcile writes back
- No for the current reconciliation workflow.
- How to disconnect
- Disconnect the integration in BillingReconcile settings where supported, and revoke the API key, OAuth grant, or application access in Cove Data Protection.
- Recommended permission level
- Use the narrowest reporting access that supplies customer and protection-count data.
Huntress
- What BillingReconcile reads
- Organizations, protected endpoints, security coverage counts, count-related state, and related identifiers.
- Why this permission is needed
- To compare protected endpoint coverage against recurring managed-security services.
- What BillingReconcile does not read
- Endpoint passwords, file contents, remote-control sessions, or unrelated threat payloads.
- Whether BillingReconcile writes back
- No for the current reconciliation workflow.
- How to disconnect
- Disconnect the integration in BillingReconcile settings where supported, and revoke the API key, OAuth grant, or application access in Huntress.
- Recommended permission level
- Use a reporting or read-only API role limited to organization and endpoint coverage.
N-able N-central
- What BillingReconcile reads
- Customers, devices, device state, classes, and metadata used for count-based billing checks.
- Why this permission is needed
- To reconcile managed devices and device categories against PSA services.
- What BillingReconcile does not read
- Remote-control credentials, endpoint passwords, or unrelated endpoint files.
- Whether BillingReconcile writes back
- No for the current reconciliation workflow.
- How to disconnect
- Disconnect the integration in BillingReconcile settings where supported, and revoke the API key, OAuth grant, or application access in N-able N-central.
- Recommended permission level
- Use a read-only API user limited to customer and device inventory data where possible.
Ninja One
- What BillingReconcile reads
- Organizations, devices, device status, device metadata, and related identifiers.
- Why this permission is needed
- To compare managed device counts against billed RMM or managed service line items.
- What BillingReconcile does not read
- Remote-control sessions, device passwords, or unrelated endpoint file contents.
- Whether BillingReconcile writes back
- No for the current reconciliation workflow.
- How to disconnect
- Disconnect the integration in BillingReconcile settings where supported, and revoke the API key, OAuth grant, or application access in Ninja One.
- Recommended permission level
- Use a reporting or read-only API role when available.
Pax8
- What BillingReconcile reads
- Customers, tenants, products, SKUs, subscriptions, license quantities, and quantity-related status.
- Why this permission is needed
- To compare distributor subscription and license quantities against PSA billing.
- What BillingReconcile does not read
- Mailbox contents, customer passwords, payment-card data, or unrelated customer documents.
- Whether BillingReconcile writes back
- No for the current reconciliation workflow.
- How to disconnect
- Disconnect the integration in BillingReconcile settings where supported, and revoke the API key, OAuth grant, or application access in Pax8.
- Recommended permission level
- Use the least-privilege API access that supports customer, product, subscription, and quantity reporting.
SentinelOne
- What BillingReconcile reads
- Sites, agents/endpoints, package metadata, endpoint status, and license-relevant counts.
- Why this permission is needed
- To compare protected endpoints and package assignments against billed security services.
- What BillingReconcile does not read
- Endpoint passwords, remote shell sessions, file contents, or threat payload contents.
- Whether BillingReconcile writes back
- No for the current reconciliation workflow.
- How to disconnect
- Disconnect the integration in BillingReconcile settings where supported, and revoke the API key, OAuth grant, or application access in SentinelOne.
- Recommended permission level
- Use a viewer or reporting role that can read site and endpoint inventory.
Sherweb
- What BillingReconcile reads
- Customer, subscription, product, license, and quantity data.
- Why this permission is needed
- To compare vendor subscription usage against PSA billing quantities.
- What BillingReconcile does not read
- Mailbox contents, customer passwords, or unrelated customer documents.
- Whether BillingReconcile writes back
- No for the current reconciliation workflow.
- How to disconnect
- Disconnect the integration in BillingReconcile settings where supported, and revoke the API key, OAuth grant, or application access in Sherweb.
- Recommended permission level
- Use the least-privilege account or API access that supports subscription and quantity reporting.
TD Synnex StreamOne
- What BillingReconcile reads
- Marketplace customers, products, subscriptions, licenses, seat quantities, and quantity-related status.
- Why this permission is needed
- To compare marketplace subscription and license quantities against PSA billing.
- What BillingReconcile does not read
- Mailbox contents, customer passwords, payment-card data, or unrelated customer documents.
- Whether BillingReconcile writes back
- No for the current reconciliation workflow.
- How to disconnect
- Disconnect the integration in BillingReconcile settings where supported, and revoke the API key, OAuth grant, or application access in TD Synnex StreamOne.
- Recommended permission level
- Use the narrowest marketplace API access that supplies customer, product, subscription, and quantity reporting.
Webroot
- What BillingReconcile reads
- Sites, endpoints, product or license metadata, and protected device counts.
- Why this permission is needed
- To reconcile protected endpoint counts against billed security services.
- What BillingReconcile does not read
- Endpoint passwords, file contents, or unrelated user activity.
- Whether BillingReconcile writes back
- No for the current reconciliation workflow.
- How to disconnect
- Disconnect the integration in BillingReconcile settings where supported, and revoke the API key, OAuth grant, or application access in Webroot.
- Recommended permission level
- Use a read-only console or API role where available.
Related pages
For more detail about synced data and retention, see Data Handling and the Privacy Policy. For help with an integration, contact support@billingreconcile.com.
