Connecting sources

What credentials Ward asks for, what it reads, and what happens when a source changes shape.

10 min Owner: Platform Updated v1.1

Read-only, scoped to what you name

Every connector asks for the narrowest credential that will do the job. Ward cannot reach an object you did not grant it, and write access is a separate, per-object decision made later if you want it at all.

In the console: Sources

Federate or ingest

Two ways to connect, toggled in Architecture. Federated query leaves your data where it is and reads it in place. Lake ingest copies into Ward's storage in your region when you would rather it did. Warehouses and lakes are usually federated; SaaS APIs are usually ingested.

In the console: Architecture

Schema drift

Each source carries a contract describing the shape Ward expects. When the source changes, the contract fails and the pipeline stops with a message naming what moved, rather than writing wrong rows quietly until someone notices the numbers changed.

In the console: Streams

In the console

The screens this guide walks through, captured from a running tenant.