This article is for teams running an Ebios RM risk analysis with Agile Risk Manager (ALL4TEC) who want to reuse their Tenacy compliance data to factualize that analysis, with no manual re-entry needed.
💡 The ALL4TEC "connector" is not a classic connector: it is entirely operated from Agile Risk Manager through the Tenacy public API, and therefore doesn't require a dedicated connector license. On the Tenacy side, it is managed exclusively under ⚙️ > Public API.
You can feed your latest Tenacy compliance scores into ALL4TEC to use them in workshop 1 of your Ebios RM risk analysis. This gives you an overall view of your perimeter's compliance status. The score consumed by ALL4TEC is calculated daily.
In Agile Risk Manager, 1 project corresponds to 1 perimeter in Tenacy and to 1 risk analysis.
Setting up the Tenacy / ALL4TEC connection
On Tenacy's side
Create an API key in Tenacy: go to ⚙️ Settings > Public API, then create a new API key dedicated to this integration. This key and your instance URL will need to be entered on the ALL4TEC side.
Associate a policy with a perimeter, if this hasn't been done yet.
On ALL4TEC's side (Agile Risk Manager)
In your Agile Risk Manager instance: Import > Tenacy knowledge base.
URL: enter your Tenacy instance's API URL.
API key: provide the API key generated in Tenacy in the previous step.
Perimeter selection: using this API key, you'll be able to browse all the perimeters in your Tenacy instance and choose the one corresponding to your current risk analysis.
Policies: once the perimeter is selected, you'll find all the policies associated with it in Tenacy. Select the ones to import for your risk analysis.
Score type used: Tenacy offers three score types. The Evaluation score reflects a self-assessment entered on a measure, the Coverage score reflects the progress of actions linked to a measure, and the Measured score reflects an objective value fed by a third-party tool (e.g. a technical connector). Choose the one that best matches the nature of your compliance data.
Existing base Vs. New base: two possible cases.
If this is your first import: choose "New base".
If you're updating a previous import: choose "Existing base".
Data import strategy
Add missing elements.
Update existing elements.
Delete obsolete elements (present in ALL4TEC but no longer in Tenacy).
The imported information will then be used across the different workshops of your Ebios RM analysis.
Expected result
Once the import is complete, your Tenacy security policies appear in ARM as frameworks, with your security measures and their application score, ready to be used in workshop 1 of your risk analysis.
🔎 To learn more about other compatible risk analysis solutions, see: Set up the Citalid connector
Frequently asked questions
Can I link several Tenacy perimeters to a single ARM project?
Yes, you can select several perimeters when configuring the import, but an ARM project conceptually corresponds to a single risk analysis: make sure you only select the perimeters relevant to that analysis.
What happens if I choose "New base" when an import already exists?
A new framework is created in ARM in addition to the existing one, which can create duplicates. Use "Existing base" to update a previous import instead of recreating a new one.
Which score type should I choose if I'm not sure which one matches my data?
The Evaluation score fits if your measures are mostly self-assessed, the Coverage score if you track the progress of actions, and the Measured score if you have objective data fed by a third-party tool.
Can deleting obsolete elements cause data loss in ARM?
This option deletes elements in ARM that no longer exist on the Tenacy side for the imported perimeter. If you only want to keep additions and updates, leave this option unchecked during import.






