Integrations Overview

Kenzsys is only as useful as the data it can see. Each integration unlocks a different piece of the marketing-to-retention picture. This page lists every supported integration, explains what each one does, and links to step-by-step setup guides.

Integrations overview page

Where to manage integrations

Click Settings in the left sidebar, then click the Integrations tab. Every supported provider shows up as a card with one of three statuses: Not connected, Connected (with a "last sync" timestamp), or Reconnect required (the OAuth token expired and needs a fresh authorization).

Supported integrations

  • Google Ads — pulls daily ad spend, campaign performance, impressions, clicks, and conversions. Required for CPL and Ad Return KPIs.
  • Meta (Facebook & Instagram Ads) — pulls paid social spend and campaign performance for firms running ads on Meta platforms.
  • CallRail — pushes every tracked call into Kenzsys as a lead within seconds of hang-up, including caller info, source, recording URL, and (optionally) the transcript.
  • Google Business Profile — syncs reviews, star ratings, photo counts, search impressions, and direction requests for local SEO tracking.
  • Clio — pulls matters and billing data so retained-client revenue can be matched back to the lead that produced it.
  • Google Search Console — pulls organic search queries, impressions, clicks, and average position so you can see which keywords drive traffic to your website.
  • Lawmatics — alternative to Clio for firms using Lawmatics as their CRM and intake platform. Same retained-client matching workflow.

How long does each integration take to set up?

OAuth integrations (Google Ads, Meta, GBP, Clio, GSC, Lawmatics) take 2 to 3 minutes from clicking Connect to seeing the first data. CallRail uses an API key instead of OAuth and takes about 5 minutes because you need to generate the key in the CallRail console first.

OAuth security and your data

We never store your passwords. Every OAuth integration uses the provider's official authorization flow, which means Kenzsys receives an encrypted access token — not your password. You can revoke that token at any time from the provider's own account settings, and we'll detect the revocation on the next sync attempt. All tokens are encrypted at rest using AES-256 with per-organization keys.

What happens if a connection breaks?

OAuth tokens expire occasionally — typically when someone in your firm changes their Google password or revokes app permissions. When this happens, the integration card flips to Reconnect required and a banner appears at the top of the dashboard. Click Reconnect on the card and run through the OAuth flow again. Historical data is preserved — only new syncs are interrupted.

Next steps

Pick the integration you want to set up next and follow its dedicated page. Most firms get the most value from connecting CallRail and Google Ads first because they produce the most visible data on day one.