Skip to main content

HaloPSA | FAQ's and Common Issues

Overview ✨

The Liongard and HaloPSA integration helps partners route Liongard Actionable Alerts into HaloPSA as tickets so service workflows and operational remediation can be managed in the PSA. The integration also supports status alignment between the two platforms for Liongard-created tickets.

This guide covers:

  • How synchronization works

  • What is and is not supported

  • Why common issues occur

  • Troubleshooting and validation steps

  • Permissions and configuration checks

  • Logging and escalation guidance

  • Security reminders

⚠️ Important sync behavior

The HaloPSA integration does not provide instant webhook-style ticket status updates back into Liongard. HaloPSA ticket status changes are synchronized back to Liongard during the next relevant inspection cycle for the inspector that originally generated the Actionable Alert.

ℹ️ At a glance

  • Liongard can create and manage HaloPSA tickets for Actionable Alerts.

  • Status alignment is bi-directional, but HaloPSA to Liongard sync is pull-based and periodic, not real-time.

  • The relevant trigger is the source inspector, not a separate Halo inspector.

  • If a ticket status changes in HaloPSA, Liongard reflects that change when the associated source inspector runs again.

This article provides updated guidance for the Liongard and HaloPSA integration, including how synchronization works, what behavior to expect, common failure points, and practical troubleshooting steps.


How the Integration Works

Direction 1: Liongard to HaloPSA

When Liongard creates a ticket in HaloPSA, it sets the initial HaloPSA ticket status based on the status mapped to Liongard's New status. As Liongard alert state changes, Liongard can continue to update the linked HaloPSA ticket according to the configured mappings and integration behavior.

If a Liongard alert self-resolves, Liongard can also update or close the related HaloPSA ticket based on the configured workflow.

Direction 2: HaloPSA to Liongard

Liongard retrieves the latest status of Liongard-created HaloPSA tickets before inspection processing. Liongard then updates the matching Actionable Alert status in Liongard so the ticket and alert remain aligned.

📝 Important nuance

This is not a true instant push from HaloPSA into Liongard. It is a scheduled or on-demand synchronization that occurs when the relevant inspector runs.

Which inspector triggers the sync?

The inspector that matters is the inspector where the alert originally came from. For example, if the Actionable Alert was generated by a Microsoft 365 inspector, then that Microsoft 365 inspector run is what triggers Liongard to check the related HaloPSA ticket status before continuing inspection processing.

Is the sync instant like ConnectWise?

No. HaloPSA status updates do not appear in Liongard instantly in the same way partners may expect from integrations that support callback or webhook-driven status updates. In the HaloPSA integration, status synchronization back into Liongard happens on the next applicable inspection run.

✅ Practical takeaway

If a technician updates the ticket in HaloPSA and you want Liongard to reflect that change sooner, run the source inspector manually or wait for the next scheduled inspection.


What the Integration Supports

Capability

Supported Behavior

Important Detail

Ticket creation

Yes

Liongard can create HaloPSA tickets for supported Actionable Alerts.

Initial status mapping

Yes

New Liongard alerts map to the configured HaloPSA status.

HaloPSA to Liongard status sync

Yes

Sync occurs before the next relevant inspection processing.

Instant real-time ticket status sync

No

Status changes in HaloPSA are not reflected in Liongard immediately.

Source-inspector-triggered refresh

Yes

The originating inspector run drives the status check.


Common Questions

Does HaloPSA support two-way sync?


Yes, with an important limitation. The integration supports bi-directional status alignment for Liongard-created tickets, but the HaloPSA-to-Liongard portion uses pollingbased rather than instant. That means it is best described as periodic two-way sync, not real-time two-way sync.
​

What should I run to force a status update?


Run the inspector that originally generated the Actionable Alert. That inspector will check Liongard-created HaloPSA tickets before processing the new inspection results.
​

If a ticket is updated in HaloPSA, will Liongard reflect the change immediately?


No. The change will be reflected during the next relevant inspection cycle, or sooner if you manually run that source inspector.
​

Does every HaloPSA ticket sync back to Liongard?


No. The status synchronization behavior described here applies to Liongard-created HaloPSA tickets associated with Liongard Actionable Alerts.
​


Common Issues

Most HaloPSA integration issues are caused by configuration gaps rather than platform outages.

Category

Common Causes

Typical Symptom

Permissions

Missing API agent rights, limited ticket visibility, insufficient customer access

Ticket creation or updates fail

Authentication

Expired secret, rotated credentials, wrong client details, incorrect instance URL

Connection or unauthorized errors

Mandatory fields

HaloPSA requires fields that Liongard cannot populate

Ticket creation fails

Status expectations

Assuming real-time sync instead of inspection-based sync

Liongard appears out of date until next run

Connectivity

Firewall restrictions, filtering, endpoint access issues

Intermittent or total API failure

Data entry

Extra spaces, incorrect URL formatting, wrong application or agent selection

Setup succeeds partially or fails unexpectedly


Troubleshooting Guide

1. Confirm expected sync behavior first

Before troubleshooting, verify whether the issue is actually a delay that matches normal behavior.

  • If the HaloPSA ticket status changed recently, check whether the source inspector has run since the change.

  • If it has not run, the Liongard alert status may still appear stale even though the integration is functioning correctly.

  • If immediate validation is needed, manually run the originating inspector.

📝 Most common misunderstanding

Partner often expect HaloPSA to behave like ConnectWise-style real-time sync. For HaloPSA, delayed status reflection can be expected behavior rather than a failure.

2. Validate the HaloPSA API account and permissions

Your HaloPSA API-only agent must have sufficient permissions to create, read, and update the records involved in Liongard workflows.

Area

Required Access

Why It Matters

Tickets

Read and Modify

Required for ticket creation, status reads, and updates

Customers

Read and Modify

Required where ticket/customer associations are validated

Users

Read and Modify

Needed in environments with user-linked workflows or ownership resolution

Also validate ticket-level permissions for the API agent.

Permission

Recommended Setting

Why It Matters

Can add new Tickets

Yes

Required for ticket creation

Can edit closed Tickets

Yes

Prevents failures when Liongard updates tickets in closed states

Can view Unassigned Tickets

Yes

Prevents visibility-related lookup failures

Can view Tickets assigned to other agents

Yes

Allows status retrieval and updates regardless of assignment

Editing of Actions

Can Edit Own Actions Only

Recommended baseline for controlled updates

Can Edit Tickets Not Assigned to Them

Yes

Prevents assignment-based modification failures

⚠️ Permission warning

If the API-only agent cannot see or edit the target ticket state, Liongard may fail to create, read, or update HaloPSA tickets consistently.

3. Validate API application configuration

Confirm the HaloPSA API application is configured for service-to-service authentication and tied to the intended API-only agent.

Setting

Expected Value

Validation Tip

Authentication Method

Client ID and Secret for service-based access

Ensure you are not using the wrong auth mode for the integration

Assigned Agent

Dedicated API-only agent

Avoid personal user accounts where possible

Client Secret Status

Active and current

Confirm it has not expired or been rotated without updating Liongard

Instance URL

Correct HaloPSA tenant URL

Check for formatting issues or environment mismatches

If your HaloPSA environment uses API permissions or scopes, ensure ticket and customer access scopes are enabled as required by your HaloPSA configuration model.

4. Check mandatory field requirements

If HaloPSA requires fields that Liongard cannot provide during automated ticket creation, the ticket may fail to create even when authentication succeeds.

Recommended options:

  1. Map supported fields in Liongard wherever possible.

  2. Make non-essential HaloPSA fields optional for Liongard-created tickets.

  3. Use a dedicated HaloPSA ticket type or form for Liongard automation to avoid unrelated mandatory business fields.

✅ Recommended practice

Using a dedicated Liongard ticket type or form often reduces avoidable failures and makes troubleshooting significantly easier.

5. Investigate delayed status synchronization

If the issue is specifically that HaloPSA ticket status changes are not visible in Liongard, use this checklist:

  • Confirm the ticket was originally created by Liongard.

  • Confirm the related Actionable Alert still exists and is linked correctly.

  • Identify the inspector that originally produced the alert.

  • Check whether that inspector has run since the HaloPSA ticket status changed.

  • Manually run the source inspector if faster validation is needed.

  • Review inspector logs for authentication, lookup, or update errors.

6. Review authentication issues

Authentication issues often appear after a previously working integration stops unexpectedly.

Common indicators include:

  • Unauthorized or forbidden responses

  • Sudden ticket creation failures after secret rotation

  • Intermittent token or connection errors

  • Failure after an application, agent, or tenant URL change

Corrective actions:

  1. Create or retrieve a valid current client secret in HaloPSA.

  2. Update the stored credentials in Liongard.

  3. Revalidate the integration configuration.

  4. Run the relevant inspector and confirm successful communication.

7. Review connectivity and API reachability

If authentication is correct but requests still fail, validate network path and service reachability.

  • Confirm the HaloPSA API endpoint is reachable.

  • Check for firewall, proxy, DNS, or filtering issues.

  • Review whether security tooling is blocking requests or responses.

  • Validate that the configured instance URL matches the intended HaloPSA environment.

8. Review logs

Collect and review details from both systems whenever possible.

Platform

Where to Check

What to Look For

Liongard

Authentication failures, ticket creation errors, sync/update failures, timing of inspection runs

HaloPSA

System logs, API request history, application or agent audit trails

Rejected requests, permission denials, validation failures, rate limiting

Collect the following before contacting support:

  • Timestamp of the issue

  • Liongard environment and inspector name

  • HaloPSA ticket ID

  • Liongard alert

  • Error message or HTTP response code (if available)

  • Screenshots of API agent permissions and integration settings

Triage Summary

Issue

Likely Cause

What to Check First

Ticket is not created

Missing permissions, mandatory field requirements, authentication issues

API agent rights, ticket form requirements, client credentials

Ticket exists but Liongard status does not match

Source inspector has not run since HaloPSA change

Inspector schedule and last run time

Ticket updates fail unexpectedly

Expired secret, permission restrictions, assignment visibility limits

Agent permissions and credential validity

Authentication fails

Wrong tenant URL, invalid client ID, invalid secret

Application configuration and copied values

Status sync seems delayed

Expected pull-based behavior

Whether the originating inspector has run


When to Contact Support 🦁

Contact Liongard Support when

  • The source inspector runs successfully but Liongard-created HaloPSA ticket statuses still do not synchronize correctly

  • Ticket creation fails after permissions and mandatory-field requirements have been validated

  • You see Liongard-side processing errors in inspector logs

  • You need help identifying whether behavior is expected delay versus actual sync failure

Contact HaloPSA Support when

  • The API is returning 4xx or 5xx errors that point to HaloPSA-side validation or service issues

  • The API application or agent configuration appears correct but HaloPSA is rejecting requests

  • Mandatory field behavior, ticket workflow rules, or tenant-specific configuration is blocking automation

ℹ️ Recommended escalation

Include the time of failure, HaloPSA ticket ID, Liongard alert details, inspector name, last run time, relevant logs, and screenshots of the HaloPSA API application and agent permissions.


Security Reminders

  • Store API credentials securely.

  • Do not share secrets in screenshots, email, or chat.

  • Rotate credentials according to your organization's security policy.

  • Use a dedicated API-only agent rather than a personal user account.

  • Remove unused applications, agents, and legacy credentials.


Additional Resources

🚨 Note

We may occasionally provide links to third-party tools or resources for additional reference. These resources are offered for convenience only, and Liongard does not control, maintain, or guarantee their functionality, accuracy, or availability. Please review and use any third-party resources at your own discretion.

Did this answer your question?