Overview

The Zoom integration brings your Zoom account’s users and admin roles into LowerPlane’s access reviews. Because Zoom accounts often hold elevated administrative privileges and access to recorded meetings, who can sign in — and who holds an admin role — is routinely in scope for an audit. LowerPlane collects users and roles only. It does not read meetings, recordings, chat messages, or webinar content. The integration only ever reads data from Zoom — it never creates or modifies anything in your account.

Prerequisites

You need admin access to the Zoom account to authorize the connection. The requested scopes are admin-level and can only be granted by a Zoom account administrator.
A single connection covers your entire Zoom account — all active users and every custom and default role are synced.

How to Connect

1

Start the connection

Go to Integrations in LowerPlane, find Zoom, and click Connect.
2

Authorize access

You are redirected to Zoom and asked to sign in as an administrator. The app requesting access appears as LowerPlane.Zoom shows the access being requested:User list (user:read:list_users:admin)
  • View all users on the account — this is what lets LowerPlane read the user roster for access reviews.
Role list (role:read:list_roles:admin)
  • View the roles configured on the account — identifies which users hold administrative privileges.
LowerPlane deliberately does not request access to meetings, recordings, cloud storage, or chat. No meeting content leaves your Zoom account.
3

Confirm the sync

After authorizing you are returned to LowerPlane and Zoom appears under the Connected tab. The first sync runs automatically.

What LowerPlane Monitors

Users

Active user accounts with name, email, and account status for everyone who can sign in to your Zoom account.

Roles

The roles configured on the account and their privilege assignments — the basis for reviewing who holds administrative access.
Zoom’s user API returns active accounts only. An account that has been removed in Zoom no longer has access and drops out of LowerPlane on the next sync.

Automated Checks

Zoom users are matched to your Personnel > People records by email address. That match drives the access checks below, so keeping People current is what makes those results meaningful.
CheckPasses when
User should be identifiedThe Zoom account has both an email address and a name
User access to critical system should be validThe account belongs to a known person who has not been offboarded
Zoom access should be removed for offboarded userNo terminated employee still has a Zoom account

What each failure means

A Zoom account is missing an email address or a name, so it cannot be traced back to a named individual. This check looks only at the Zoom account itself — it does not consult your People records.These accounts matter because no individual is accountable for them. If one is compromised, there is no owner to notify and no way to attribute activity.To resolve: set a first and last name on the account in the Zoom admin portal under User Management > Users, or remove the account if it is no longer needed.
An account whose email does not match anyone in People still passes this check. That case is reported by User access to critical system should be valid instead.
The account either belongs to nobody in your People records, or belongs to someone marked as terminated. Both mean access cannot be justified.To resolve: remove the account in Zoom, or correct the person’s record in People if their status is wrong.
A person marked terminated in People still has an active Zoom account. Because Zoom’s user API returns active accounts only, any account visible to LowerPlane has live access right now.This is the highest-priority finding of the three — it means a departed employee can still reach your Zoom account.To resolve: remove the user in the Zoom admin portal under User Management > Users.

Frameworks Supported

FrameworkWhat It Proves
SOC 2Logical access to systems is restricted to authorized personnel and revoked on termination
ISO 27001Access provisioning and deprovisioning controls are enforced for business applications

Access Reviews

Zoom users also appear in Personnel > Access Reviews alongside your other connected tools. Zoom is registered as its own critical system, so reviewers can confirm or flag each user’s access there as part of a periodic review campaign. Users holding an admin role are the ones reviewers scrutinize most closely.
Access levels are normalized to a shared scale across every integration, so Zoom roles are shown against a common set of privilege tiers. The exact Zoom role is preserved on the collected evidence.

Sync Frequency

Zoom data syncs based on your configured integration sync schedule (default: daily). Each sync collects the latest user roster and role assignments.

Troubleshooting

The scopes Zoom requests are admin-level (user:read:list_users:admin, role:read:list_roles:admin). They can only be granted by a Zoom account administrator — authorize the connection while signed in as an admin.
The email addresses in Zoom do not match your People records. Emails are matched exactly, in lowercase — confirm that the addresses in Personnel > People are the same ones users sign in to Zoom with, not a work alias. A single mistyped character is enough to break the match.This affects User access to critical system should be valid. The identification check does not use People records, so it will keep passing.
Removed users clear on the next sync. Trigger one manually from the integration page, or wait for the scheduled run.
Zoom access tokens are short-lived and LowerPlane refreshes them automatically. If the refresh token itself is revoked — for example if the authorizing admin’s Zoom access is removed — the integration needs to be reconnected by a current administrator.