Services your team already pays for, connected once and used by any project.
An integration is a service you already have, connected once on the team and available to every project it owns. Credentials live on the team rather than on a project, because most teams have one account with a log provider and one with a storage provider, and re-entering the same key per project is how one of them ends up wrong.
They are under your team's settings, and adding, changing or removing one takes the Admin role or above.
Somewhere to send logs. Datadog, New Relic, Logz.io, Axiom, Grafana Loki, Splunk, an OpenTelemetry endpoint, or a plain syslog host and port for anything not on that list. Shipped from the machine, alongside the copy the platform keeps — connecting your own is additive and never replaces ours. See Logs.
Storage you control. S3-compatible object storage, SFTP, or an rclone remote, as somewhere your backups are copied to. An S3-compatible bucket can also be where logs are archived, so one connection is both — that is why it is one integration rather than two: it is one set of credentials, and splitting it would mean entering the same key twice. SFTP and rclone take backups only.
Somewhere the platform can tell you something. Slack, Telegram, Discord, PagerDuty, or a webhook for anything else. These are the channels Notifications uses.
Email is deliberately not on this list. Your account is an email address, so there is nothing to connect — it is simply a channel you can choose when setting up a notification.
Log forwarding and backups to your own storage are not offered on the entry line of machines; a larger machine adds both.
Given once, and not shown again. A key you paste is stored encrypted and never rendered back into a form, so the console cannot leak what you handed it and neither can a screenshot of it. Replacing one means entering the new value, not editing the old.
Credentials never travel in a task. What a machine needs is handed to it when it asks, over its own authenticated channel — so a key is not sitting in a queue row waiting to be read.
An integration in use cannot be removed. The console lists what is using it — which projects ship logs there, which backup destinations write there, which notifications post there — and asks you to point those somewhere else first, because removing it underneath them would show up later as a backup writing nowhere. Nothing already written is deleted: a backup already copied to your bucket is yours and stays there.