Frequently asked questions
Short answers to the questions people ask most, with links to the full pages.
Using SourceLace
Which AI apps work with SourceLace?
Any app that supports MCP (the Model Context Protocol) with remote servers and sign-in, such as Claude, ChatGPT, Cursor and VS Code, plus the assistant in the SourceLace app itself. Add https://sourcelace.onrender.com/mcp as a connector or MCP server. See Getting started.
Do I need the SourceLace app if I already use an AI app?
No. The app is optional: it adds saved chats, projects, charts and files, and is where admins manage people and sources. Everything else works from your own AI app.
Why can't I see a record I know exists?
SourceLace signs you in to each system with your own login, so it shows exactly what that system lets you see, nothing more. Check you can see the record in the system itself, and that you connected the right account (list_sources shows who you are connected as).
Why does a source say "not connected"?
Each person connects each source once, with their own login. Ask your AI app to connect it, or click Connect on the Sources page in the app. Sign-ins can also end on the system's side (a changed password, an expired refresh token); then just connect again.
How many rows can a question return?
Up to 2,000 rows per query, shown 50 at a time. Results are held for 30 minutes so your AI app can page through them or join them with another source's results. For more, narrow the query or ask for totals instead of rows.
Can SourceLace change records?
Only where an admin has turned on changes for named objects of a source, and only one record at a time. You always see a preview of the current and new values first, and nothing is sent until you confirm. Some sources never accept changes: Gong, data platforms, databases and file stores (Google Drive, SharePoint and OneDrive, Amazon S3). Workday accepts one kind of change, starting a business title change, which still goes through Workday's own approvals. Google Sheets accepts new rows and changed cells, never deleted rows. See Turning on changes and the table in Every system SourceLace connects to.
Can I use a Google Sheet?
Yes, once an admin adds a Google Sheets source: paste the sheet's link into your question. You see only sheets shared with you, and change only sheets you can edit. See Google Sheets.
Can SourceLace send email?
No. Mail sources can only make drafts, which wait in your Drafts folder until you send them yourself.
What are skills?
How-tos written by your organization, such as "build a QBR deck". Your AI app lists them at the start of a task and follows a matching one. See Getting started.
Can I ask SourceLace how to set something up?
Yes. Ask your AI app or the assistant in the app: they search this manual with search_docs and read a page with get_doc, then answer with a link. This manual is also at https://sourcelace.onrender.com/docs and as a PDF.
For admins
Who sets up each system?
For most systems, SourceLace already has the app people sign in with, and your SourceLace admin only adds the source. For ServiceNow, Zendesk, Snowflake, Databricks, Oracle Fusion Cloud, Workday, NetSuite and databases, an admin of that system does a one-time setup first. See Who sets up what.
What is the redirect URL?
https://sourcelace.onrender.com/connect/callback. Systems where your own admin registers SourceLace ask for it. See The redirect URL.
Can I limit a source to some people?
Yes: Access by group. Groups can be kept in step with your identity provider through single sign-on.
Can we use our own AI key?
Yes, for the assistant in the SourceLace app: Settings → AI model → Your own Anthropic key or Your own OpenAI key. See AI settings. Your own AI apps use their own provider and are not affected.
Why is a system "switched off on this server" or "not available yet"?
SourceLace's own app for that system has not been set up on the server you use yet. Contact support@sourcelace.com.
Can we connect a system SourceLace has no connector for?
Yes: your developers can build a small connector of their own, and an admin adds it as a Custom connector source. See Build your own connector.
Which systems are in testing?
Salesforce and Salesforce Data 360 are available. SAP S/4HANA and SuccessFactors work with SAP's public demo sandbox only for now. Most other connectors are marked in testing (see Every system SourceLace connects to): built against the vendor's documented API and tested against simulated systems, but not yet used with a customer's live account. If you would like to be the first, tell support and we will try it with you.
Security and privacy
Does SourceLace store our data?
Not your records. Query results are held in memory for at most 30 minutes and never written to a database. The exception is saved chats in the SourceLace app, which are encrypted with your organization's own key and deleted after your retention period (30 days by default). See Security and privacy.
Does SourceLace send our data to an AI model?
From your own AI app: no, SourceLace returns results to your app, which uses its own AI provider. From the assistant in the SourceLace app: yes, the conversation and tool results go to Anthropic, through SourceLace's account or your own key, or to OpenAI if your admin entered your own OpenAI key. See AI and your data.
Where is SourceLace hosted?
On Render, in the Oregon (United States) region. A move to AWS is planned.
Is SourceLace SOC 2 certified? Do you sign a DPA?
Not yet. SOC 2, ISO 27001, HIPAA and a GDPR data processing agreement are not yet available. Email security@sourcelace.com for a security review.
Who can see what my people asked?
Your admins, in the audit trail: who called which tool on which source, the query text, and how many rows came back, never the rows themselves. Saved chats are private to the person who had them.
How do we remove someone?
Remove them under People. Their SourceLace sign-in stops working at once, and their sign-ins to your systems are deleted. If your organization admits everyone at an email domain, they will come back as a member if they sign in again, so also remove them in your identity provider or remove the domain.