Overview
The Zoom integration brings your Zoom account’s users and admin roles into LowerPlane’s access reviews. Because Zoom accounts often hold elevated administrative privileges and access to recorded meetings, who can sign in — and who holds an admin role — is routinely in scope for an audit. LowerPlane collects users and roles only. It does not read meetings, recordings, chat messages, or webinar content. The integration only ever reads data from Zoom — it never creates or modifies anything in your account.Prerequisites
A single connection covers your entire Zoom account — all active users and every custom and default role are synced.
How to Connect
Authorize access
You are redirected to Zoom and asked to sign in as an administrator. The app requesting access appears as LowerPlane.Zoom shows the access being requested:User list (
user:read:list_users:admin)- View all users on the account — this is what lets LowerPlane read the user roster for access reviews.
role:read:list_roles:admin)- View the roles configured on the account — identifies which users hold administrative privileges.
LowerPlane deliberately does not request access to meetings, recordings, cloud storage, or chat. No meeting content leaves your Zoom account.
What LowerPlane Monitors
Users
Active user accounts with name, email, and account status for everyone who can sign in to your Zoom account.
Roles
The roles configured on the account and their privilege assignments — the basis for reviewing who holds administrative access.
Zoom’s user API returns active accounts only. An account that has been removed in Zoom no longer has access and drops out of LowerPlane on the next sync.
Automated Checks
Zoom users are matched to your Personnel > People records by email address. That match drives the access checks below, so keeping People current is what makes those results meaningful.| Check | Passes when |
|---|---|
| User should be identified | The Zoom account has both an email address and a name |
| User access to critical system should be valid | The account belongs to a known person who has not been offboarded |
| Zoom access should be removed for offboarded user | No terminated employee still has a Zoom account |
What each failure means
User should be identified
User should be identified
A Zoom account is missing an email address or a name, so it cannot be traced back to a named individual. This check looks only at the Zoom account itself — it does not consult your People records.These accounts matter because no individual is accountable for them. If one is compromised, there is no owner to notify and no way to attribute activity.To resolve: set a first and last name on the account in the Zoom admin portal under User Management > Users, or remove the account if it is no longer needed.
An account whose email does not match anyone in People still passes this check. That case is reported by User access to critical system should be valid instead.
User access to critical system should be valid
User access to critical system should be valid
The account either belongs to nobody in your People records, or belongs to someone marked as terminated. Both mean access cannot be justified.To resolve: remove the account in Zoom, or correct the person’s record in People if their status is wrong.
Zoom access should be removed for offboarded user
Zoom access should be removed for offboarded user
A person marked terminated in People still has an active Zoom account. Because Zoom’s user API returns active accounts only, any account visible to LowerPlane has live access right now.This is the highest-priority finding of the three — it means a departed employee can still reach your Zoom account.To resolve: remove the user in the Zoom admin portal under User Management > Users.
Frameworks Supported
| Framework | What It Proves |
|---|---|
| SOC 2 | Logical access to systems is restricted to authorized personnel and revoked on termination |
| ISO 27001 | Access provisioning and deprovisioning controls are enforced for business applications |
Access Reviews
Zoom users also appear in Personnel > Access Reviews alongside your other connected tools. Zoom is registered as its own critical system, so reviewers can confirm or flag each user’s access there as part of a periodic review campaign. Users holding an admin role are the ones reviewers scrutinize most closely.Access levels are normalized to a shared scale across every integration, so Zoom roles are shown against a common set of privilege tiers. The exact Zoom role is preserved on the collected evidence.
Sync Frequency
Zoom data syncs based on your configured integration sync schedule (default: daily). Each sync collects the latest user roster and role assignments.Troubleshooting
The connection fails with a scope or permission error
The connection fails with a scope or permission error
The scopes Zoom requests are admin-level (
user:read:list_users:admin, role:read:list_roles:admin). They can only be granted by a Zoom account administrator — authorize the connection while signed in as an admin.All users fail the critical access check
All users fail the critical access check
The email addresses in Zoom do not match your People records. Emails are matched exactly, in lowercase — confirm that the addresses in Personnel > People are the same ones users sign in to Zoom with, not a work alias. A single mistyped character is enough to break the match.This affects User access to critical system should be valid. The identification check does not use People records, so it will keep passing.
A user was removed in Zoom but still shows in LowerPlane
A user was removed in Zoom but still shows in LowerPlane
Removed users clear on the next sync. Trigger one manually from the integration page, or wait for the scheduled run.
The connection shows an error after working previously
The connection shows an error after working previously
Zoom access tokens are short-lived and LowerPlane refreshes them automatically. If the refresh token itself is revoked — for example if the authorizing admin’s Zoom access is removed — the integration needs to be reconnected by a current administrator.