Before you start
You need integration-management permission, authorized provider credentials and access to the companies you intend to synchronize. Ticket configuration can additionally require Ticket Settings permission. Keep credentials in the connection form and your approved secret store. Create an API application in Configuration > Integrations > Halo API > Applications. Choose Client ID and Secret (Services) and an appropriate Agent to Log in as. Access depends on both the application permissions and that agent’s permissions. Use your instance URL without a trailing slash. See Halo’s API documentation and custom role and agent setup.Connect the provider
- Open Settings > Integrations, find Halo PSA, and open setup. Use Configure for the existing connection.
- Enter Halo URL, Client ID and Client Secret.
- Select Test Connection when ready to connect. For a new connection, a successful test also creates and saves the integration. There is no separate Create Integration button in this PSA wizard.
- Review the result and continue to Permissions. An existing connection can initialize with a Connected indicator; that is not proof of a fresh test.

MSP example: the setup steps for an existing connection. The Connect checkmark does not represent a new test.
Check permissions
The permission screen checks vendor endpoints and reports required access, optional access and unavailable or unverified results. Required denied access prevents the supported progression. An optional permission that is not granted keeps its corresponding sync off. Read the reported failure before changing the API role. A timeout, unavailable endpoint or unverified check is not automatically proof of a missing permission. Retry after resolving the actual problem. These checks exercise read access; they do not prove that ticket creation, comments, warranty updates or other writes will succeed.Project management permissions
Configure both the MSPortal API application and the Agent to Log in as. Under Configuration > Integrations > Halo API > Applications, open the application’s permissions. Then review the selected agent and its role under Configuration > Teams & Agents. Application access cannot override a restriction on that agent. See Halo’s API application guide. Halo projects use project records with child tickets and milestones. Project access alone does not cover every child-ticket, checklist or time-entry operation.
Project Read/Modify and Ticket Read/Modify are the permission names used in Halo’s API documentation. Application labels and additional endpoint permissions can vary by version; use your instance’s /apidoc to confirm the permissions for projects, tickets, actions, to-do items and templates. The agent must also have module access and the corresponding create/edit/action permissions. The separate Time entries setup check requests
read:timesheets; that is read access, not proof that adding time through a ticket action will succeed.
Agent scope and supported operations
Add the API agent to every intended department and team. Allow it to access the required clients and ticket types, including the project type and child-ticket types. Where the connection should cover all of them, review Allow All Clients and Allow All Ticket Types. Also check access to internal actions, project templates and the actions used for time entry. A valid token can still return incomplete data or reject writes when these restrictions exclude a record. Permissions enable supported workflows; they do not add provider features. Halo project lifecycle changes, supported detail edits, notes/time and checklist addition/completion have separate controls. Project-ticket status changes from the Kanban board or the ticket details write back to Halo and need Ticket Modify. Project-ticket owner and priority changes are not currently enabled for Halo in MSPortal. Checklist progress-note editing and checklist deletion are not offered for Halo in this workflow. MSPortal-only projects, reusable portal templates and portal project registers use MSPortal permissions. Explicitly creating or updating PSA work requires Halo access. Do not grant blanket Delete or administrator access for these read/create/update workflows.Verify read and write access separately
Save both the application and agent changes, then return to Settings > Integrations > Halo PSA > Configure > Permissions and select Re-check. A green Projects result only confirms the project read check. Validate project creation, a supported detail edit, checklist completion, and a note/time action on a designated test project. If applying a template partly succeeds, inspect its results before retrying.Select synchronization scope
Select the intended teams and excluded ticket statuses. Halo also offers company/contact filters, opportunities, projects, invoices, product catalog, asset sync, change management and satisfaction ratings when their permissions are available. Asset status exclusions affect synchronization; inactive Halo assets are excluded and filtering does not delete existing portal devices. Review filters before continuing. Synchronizing source records, linking them to companies and importing portal records are separate steps. Automatic company/contact import options can create portal records when matching source records arrive. Review any import preview and the selected categories carefully; do not rely on a confirmation appearing for every save. Proceeding from Sync saves the selected scope and starts background synchronization. Options in later steps may remain incomplete while it runs. Check errors and the connection’s actual sync result before treating an empty list as the final dataset. Warranty writeback is an optional vendor write. Enable it only when you intend resolved warranty data to update the connected PSA records.Import HaloPSA native CSAT for dashboards and reports
This imports satisfaction feedback already collected in Halo PSA. You do not need Simplesat or a new MSPortal survey to present those responses.- Open Settings > Integrations > Halo PSA > Configure.
- Give the Halo API application and its selected agent read access to feedback. In Permissions, check the feedback access result and use Re-check after resolving denied access.
- Open Sync and enable Import satisfaction ratings.
- Set Rating scale to match the survey configured in Halo: 1 to 3, 1 to 5, or 1 to 10. The default is 1 to 5. Halo sends the score without the scale, so choosing the wrong scale changes how satisfaction is calculated.
- Continue from Sync to save the selection, or use Save & Exit. Wait for a successful save and background import. Enabled Halo satisfaction imports are scheduled hourly; saving is not proof that all responses have arrived.
- Ensure the feedback’s related tickets have synchronized and their companies are linked to portal companies. Responses whose ticket or company cannot yet be resolved will not appear in company-scoped CSAT results until a later successful sync can resolve them.
- Grant intended readers Surveys > Read > CSAT in their role. Dashboard and report authoring also require the corresponding permissions.
Present the imported feedback
- CSAT Dashboard: open Surveys > CSAT Dashboard to read scores, trends and available feedback, or export responses. Imported Halo feedback is grouped under Halo PSA satisfaction. See Read and export support satisfaction feedback.
- Custom dashboards: add CSAT Overview, CSAT Trend, CSAT by Company, or Recent CSAT Feedback from the available widget library, then save the dashboard. See Create and edit a dashboard.
- Reports: use the same CSAT blocks in the report builder, select the intended company and reporting period, and save. See Reporting.
If Halo CSAT is missing
An empty dashboard or missing widget does not mean HaloPSA native CSAT is unsupported. Check the saved import toggle, feedback read access, integration status and last import result, rating scale, synchronized tickets, company links, selected dates and the reader’s CSAT permission. Merely connecting Halo does not turn on satisfaction imports. If the Import satisfaction ratings control itself is absent, contact MSPortal support to check the connection and feature availability.Configure portal behavior
Configure ticket status groups, closed statuses and the status used for client comments. Choose the relevant teams in Sync first. Review the Halo opportunity workflow and invoice settings when those datasets are enabled. Configuration forms save changes automatically after editing. Wait for the saved state; wizard navigation waits for pending saves and reports failures. Leaving the screen is not a substitute for checking a failed save. Ticket defaults additionally require Ticket Settings permission. Quick Sync requests ticket synchronization. Clear & Resync clears portal ticket data for this connection before reloading it. Use the latter only for an intended rebuild, and check the subsequent result; it is not a harmless refresh.Import and finish
The Import step offers Users, Companies and Assets. Open Asset Import opens the separate asset-import page. Review existing portal records before creating duplicates. Company links determine which client can see synchronized data. Apply the intended company and user selections and check the result. Complete Setup also attempts to apply pending company/user imports before completing the wizard. It can start background work, so setup completion is not proof that every import or sync succeeded. An import-page link only navigates to that workflow. Use Save & Exit to save wizard progress when pausing. Reopen the connection to continue and verify the saved state. Portal invitations and client permissions remain separate from discovering provider contacts.Maintain the connection
Reopen setup to inspect scope and errors. A successful retest of changed fields is not proof of credential rotation: this wizard has no separate update-credentials action. Confirm the supported replacement path before revoking working vendor credentials. Delete Integration opens a named confirmation. Confirm Delete only to remove the connection and its associated settings; cancel preserves it. Vendor-side credential revocation is separate.Troubleshooting
Frequently asked questions
Can I dashboard or report on HaloPSA native CSAT responses?
Can I dashboard or report on HaloPSA native CSAT responses?
Yes. Enable Import satisfaction ratings in the Halo integration’s Sync step, grant feedback read access, and choose the correct rating scale. Imported responses are available in the CSAT Dashboard, custom dashboard CSAT widgets, report blocks and CSV exports, subject to company mapping and role access. You can keep using Halo’s own survey; Simplesat is not required.
Does Test Connection only test credentials?
Does Test Connection only test credentials?
For a new connection, a successful test also creates the integration. Enter credentials only when you intend to connect it.
Does a green permissions result verify ticket writes?
Does a green permissions result verify ticket writes?
No. The permission checks probe read access. Creating tickets, comments or other vendor changes needs the relevant write permission and a successful action.
Does Complete Setup mean all data is ready?
Does Complete Setup mean all data is ready?
No. Check the background sync result and verify company, user and device imports separately.
Will every discovered contact receive portal access?
Will every discovered contact receive portal access?
Discovery and import are separate. Review user matches, company links and the permissions assigned to portal users; invitation is a separate workflow.
Can I replace saved credentials by retesting the form?
Can I replace saved credentials by retesting the form?
Do not treat a successful retest as proof that replacement credentials were saved. This wizard does not provide a separate credential-update action; confirm the supported update path before revoking the old credential.