Connecting your systems
Every system SourceLace connects to, who sets each one up, what people can read and change, and what to do when a connection fails.
How connecting works
Connecting a system takes up to three steps, done by different people:
- Once per system, in that system (some systems only): your admin for that system registers SourceLace there, for example an OAuth client in ServiceNow or a security integration in Snowflake. Some systems use an app SourceLace provides instead, which your admin may need to approve or install.
- Once, in SourceLace: a SourceLace admin adds the source on Manage sources, with that system's options (see Sources).
- Each person, once: they connect the source with their own login, from Data Sources in the SourceLace app or by asking their AI app to connect it. The system's sign-in page opens; they sign in there and come back. A connect link works once, for 10 minutes.
From then on, every request runs with that person's own sign-in, so the system's own permissions decide what they see and change. SourceLace keeps each person's sign-in encrypted with your organization's key and never shows it to anyone, including admins.
The redirect URL
Systems that use OAuth sign-in ask for the address they send people back to after they sign in. For SourceLace on this server it is:
https://sourcelace.onrender.com/connect/callback
Register exactly this address (with https, and no slash at the end) wherever a setup page asks for a redirect URL, callback URL or redirect URI for connecting a source. Single sign-on to SourceLace itself uses a different address, given on the Single sign-on page.
Every system SourceLace connects to
"In testing" means the connector is built against the vendor's documented API and covered by automated tests against a simulated system, but has not yet been used with a customer's live system. Tell support@sourcelace.com before you start with one, so we can help with the first connection.
| System | Kind | Setup page | Reads | Changes | Status |
|---|---|---|---|---|---|
| Salesforce (Sales and Service Cloud) | salesforce |
Salesforce | SOQL, schema, records | Create, update, delete | Available |
| Salesforce Data 360 (Data Cloud) | data360 |
Salesforce | SQL, schema, records | None | Available |
| Salesforce Marketing Cloud Engagement | sfmc |
Salesforce | Data extensions, journeys, content, send definitions | None | Set up with SourceLace support |
| SAP S/4HANA | s4hana |
SAP | OData | None | SAP's public demo sandbox only |
| SAP SuccessFactors | successfactors |
SAP | OData | None | SAP's public demo sandbox only |
| SAP ECC (on-premise) | ecc |
SAP ECC | Gateway OData, through the SourceLace Agent | Create, update | In testing |
| HubSpot | hubspot |
HubSpot | CRM search, schema, records | Create, update, delete | In testing |
| Gmail and Google Calendar | google_workspace |
Mail and calendar | Mail, events, calendars | Email drafts only | In testing |
| Outlook mail and calendar (Microsoft 365) | microsoft365 |
Mail and calendar | Mail, events, calendars | Email drafts only | In testing |
| Google Drive | google_drive |
Files | Search, folders, file text | None | In testing |
| SharePoint and OneDrive | microsoft_files |
Files | Search, libraries, file text | None | In testing |
| Amazon S3 | s3 |
Files | Keys, file text | None | In testing |
| Google Sheets | google_sheets |
Google Sheets | One sheet's tabs, named by its link | Add rows, update cells | In testing |
| ServiceNow | servicenow |
Service desks | Any table you can read | Create, update | In testing |
| Zendesk | zendesk |
Service desks | Tickets, users, organizations, groups | Ticket create, update | In testing |
| Jira Cloud | jira |
Service desks | Issues, projects | Issue create, update, comment | In testing |
| Snowflake | snowflake |
Data platforms | SQL | None | In testing |
| Google BigQuery | bigquery |
Data platforms | SQL | None | In testing |
| Databricks | databricks |
Data platforms | SQL | None | In testing |
| Microsoft Dynamics 365 (Dataverse) | dynamics365 |
Business apps | OData, schema, records | Create, update | In testing |
| Oracle NetSuite | netsuite |
Business apps | SuiteQL, schema, records | Create, update | In testing |
| Gong | gong |
Business apps | Calls, transcripts, users, stats | None | In testing |
| PostgreSQL, MySQL, MariaDB, SQL Server, Oracle Database | database |
Databases | SQL | None | In testing |
| MongoDB | mongodb |
Databases | Find and read-only pipelines | None | In testing |
| Oracle Fusion Cloud (ERP, SCM, HCM) | oracle_fusion |
Oracle Fusion and Workday | REST resources | Create, update | In testing |
| Workday | workday |
Oracle Fusion and Workday | WQL, REST | Start a business title change | In testing |
| Your own system, through a connector you build | custom |
Build your own connector | Your connector's own query language | Create, update, delete, if your connector allows it | New |
| Slack | slack |
Slack and Teams | Conversations, messages, threads, search, people | Post a message or reply | In testing |
| Microsoft Teams | microsoft_teams |
Slack and Teams | Channels, chats, messages, replies, search, people | Post a message or reply | In testing |
Who sets up what
| System | Your admin for that system | Your SourceLace admin | Each person |
|---|---|---|---|
| Salesforce, Data 360 | Installs SourceLace's Salesforce app (a managed package) once, and decides who may use it | Adds the source with the org's login address | Signs in to Salesforce |
| Marketing Cloud | Creates a read-only installed package, with SourceLace support | Adds the source with the subdomain | Signs in to Marketing Cloud |
| HubSpot | May need to approve SourceLace's HubSpot app | Adds the source | Signs in and approves the app |
| Google (Gmail, Calendar, Drive, Sheets, BigQuery) | May need to allow SourceLace's Google app; for BigQuery, grants IAM roles | Adds the source | Signs in with Google |
| Microsoft (Outlook, SharePoint and OneDrive, Dynamics 365) | May need to grant admin consent to SourceLace's Microsoft app; for Dynamics, licenses and security roles | Adds the source | Signs in with Microsoft |
| ServiceNow, Zendesk | Registers an OAuth client in your instance | Adds the source with its Client ID | Signs in to ServiceNow or Zendesk |
| Jira Cloud | Nothing, unless your Atlassian organization restricts apps | Adds the source | Signs in and approves the site |
| Snowflake, Databricks | Creates an OAuth integration (Snowflake) or app connection (Databricks) | Adds the source with its client id | Signs in to Snowflake or Databricks |
| NetSuite | Turns on OAuth 2.0 and REST web services; may need to install SourceLace's integration; gives roles the permissions | Adds the source with the account id | Signs in and picks a role |
| Gong | Nothing to register | Adds the source | Signs in to Gong; Gong only lets technical admins approve the app |
| Databases | Your database administrator creates a read-only login per person and lets SourceLace's servers in | Adds the source with host and database | Signs in on SourceLace's form with their own database login |
| Amazon S3 | Creates read-only AWS access, arranged with SourceLace support | Adds the source with buckets and region | Clicks Connect (no sign-in page) |
| Oracle Fusion, Workday | Registers an OAuth client in your identity domain or Workday tenant | Adds the source with the client's details | Signs in to Oracle or Workday |
| Your own connector | Your developers build and run the connector | Adds the source with its address and shared secret | Clicks Connect (no sign-in page) |
| SAP ECC (on-premise) | Your IT team runs the SourceLace Agent; your SAP Basis team trusts its CA (STRUST), maps certificates to users (CERTRULE) and activates the Gateway services | Creates the agent's token, then adds the source with the agent's id | Clicks Connect (no sign-in page) |
| Slack | May need to approve SourceLace's Slack app (Enterprise Grid: allow it per workspace) | Adds the source | Signs in to Slack |
| Microsoft Teams | Grants admin consent to SourceLace's Microsoft app (needed to read channel messages) | Adds the source | Signs in with Microsoft |
How queries stay read-only
Every query is checked by SourceLace before anything is sent to your system: it must be in the language that source accepts, and anything that could change data is refused (for example INSERT, UPDATE, DELETE, MERGE, CREATE, DROP in SQL, more than one statement, or $out and $merge in MongoDB). Each setup page lists that source's checks. Where the system offers it, SourceLace also asks the system itself for read-only access: a read-only transaction in PostgreSQL and MySQL, read-only OAuth scopes, a byte cap in BigQuery.
A query returns at most 2,000 rows to SourceLace, of which 50 are shown to the AI at a time. Results are held in memory for 30 minutes so they can be joined, charted or made into a document, and are never written to a database.
When something goes wrong
These messages can come from any source. Each setup page also lists the messages specific to that system.
| What you see | What it means and what to do |
|---|---|
| "You have not connected source yet. Call connect_source to sign in with your own account." | Connect the source: ask your AI to connect it, or click Connect on Data Sources. |
| "Your sign-in to source has expired. Call connect_source to sign in again." | The system ended your sign-in (for example its refresh token expired or was revoked). Connect again. |
| "source did not accept your sign-in (...). Call connect_source to sign in again." | The system refused a fresh token too, often because your account or its permissions changed. Connect again; if it keeps happening, check your access in that system. |
| "This sign-in link has expired or was already used. Ask for a new one." | Connect links work once, for 10 minutes. Ask for a new link. |
| "Sign-in was not completed: ..." | The system's sign-in page reported a problem. The rest of the message is the system's own reason, such as a redirect URL that does not match or consent that was refused. |
| "There is no source called '...'. Call list_sources to see them." | The source id is mistyped, or the source was removed. |
| "Your groups in SourceLace do not give you access to ..." | Access by group is on and none of your groups gives you this. Ask a SourceLace admin. |
| "Writes to object are turned off for source. An admin can enable them per source and object." | A SourceLace admin must turn on Allow changes for that source and list the object. |
| "source does not accept changes through SourceLace." | That kind of source is read-only in SourceLace. |
| "The kind connector is switched off on this server. Ask whoever runs SourceLace to set ..." | SourceLace's app for that system is not set up on this server yet. Contact support@sourcelace.com. |
| "The kind connector is not available yet." | That kind of source is not built yet. |
| "source accepts ..., not ..." | The query was written in the wrong language for that source. The AI usually corrects this itself. |
| "source could not be reached." or "... did not answer in time. Try again shortly." | The system was down, slow, or blocked SourceLace's connection. Try again; for databases, check the firewall (see Databases). |
| "Result ... has expired or does not exist. Run the query again." | Results last 30 minutes. Run the query again. |
| "Change ... has expired, was already applied, or does not exist. Propose it again." | A change preview lasts 10 minutes and applies once. Ask for a new preview. |
| "SourceLace hit an unexpected problem ... Try again; if it keeps happening, tell your admin or SourceLace support." | Something SourceLace did not expect. It is logged for SourceLace's team (without your data); write to support if it repeats. |