Connect Governed Enterprise Data
Provision Salesforce and Snowflake access for a revenue-dashboard preview without exposing credentials, arbitrary queries, or private networks.
The enterprise problem and today’s slice
Enterprise problem: A generated application needs governed enterprise facts, but embedding a Salesforce token, Snowflake key, broad query role, or private-network route in source would let one preview expose credentials or reach data beyond the approved customer purpose.
Whole-course context: The incoming artifacts are Day 03’s revision-bound preview, per-app managed stores, migration records, and layered validation evidence; this day adds enterprise connectors before human application identity is configured.
Today’s slice: An enterprise administrator provisions Salesforce and Snowflake connectors, private paths, minimized operations, and a preview-runtime workload grant through independent credential, secret, query, and egress brokers.
End-of-day evidence: Authorized revenue reads carry lineage, while synthetic tests prove denial of secret retrieval, arbitrary query, cross-app connector, wrong source-account scope, and unapproved network paths.
Still unsolved: Human sign-in, delegated or on-behalf-of reads, generated-app roles, sharing, production promotion, and fleet operations remain explicitly deferred.
Customer outcome and implementation focus
The customer outcome is a reliable, reviewable implementation of 04 evaluation falsification and security. This day introduces the mechanism before policy detail and evidence review; it does not repeat the same customer stories in prose, tables, and diagrams.
Components in focus
Control-plane service owns desired state; runtime workers own execution; the policy/release boundary owns privileged effects. Compute: isolated service or sandbox tasks. Storage: PostgreSQL owns durable state, Redis is a bounded cache, object storage keeps artifacts/evidence, and queues are delivery buffers rather than authority.
Implement the mechanism
Implement the topic as an owned state transition with a named controller, durable record, bounded worker action, and observable terminal evidence. Verify a denied or failed path before calling the mechanism complete.
One governed Workboard connection from grant to evidence
A working chart and a green happy-path test can coexist with prompt injection, cross-tenant reads, leaked credentials, compromised dependencies, or self-approved evidence. The smallest defensible claim is narrower: an administrator provisions one bounded machine/workload grant, the Workboard runtime uses typed brokers over an approved route, source systems retain authority, and independent evidence records allowed, denied, failed, and recovered outcomes. Optional delegated user authority comes only after that machine path is proved and is never inferred from provider or application identity.
Locate today inside the full create-to-retire lifecycle
Security gates attached only to publication miss unsafe generation, stale evidence, rollback gaps, and incomplete deletion, so controls follow the application from the first prompt through final evidence expiry. A gate may narrow or block a claim; it never converts provider documentation, a model grade, or an unobserved expectation into proof.
The release claim is bounded: the named application revision passed the named corpus, policies, environments, and time window. It is not a certification, universal safety guarantee, or statement that Daytona, Cloudflare, Salesforce, or Snowflake makes the generated application compliant.
The full lifecycle shows that Day 04 proves a governed connector slice, not application identity, publication, continuous operations, retirement, or certification.
Describe only the connector controls and evidence observed for the named revision, environment, sources, policies, and time window; leave every later lifecycle claim open.
Reduce the connection to the smallest complete three-box model
Starting with OAuth variants, SDKs, or provider features hides the governing authority chain. Begin with three boxes: an enterprise administrator defines purpose and least privilege, a machine/workload executes only a typed operation, and the source returns minimized data plus lineage while remaining authoritative.
For the revenue Workboard, the administrator first provisions salesforce.pipelineByRegion and snowflake.bookedRevenueByMonth for one preview workload. This is service-to-service authority: no human access token is placed in the preview, no user is impersonated, and no application session is treated as source consent. Optional delegated user authority may later be added only as a separate source-native grant with its own issuer, audience, consent, operation scope, expiry, refresh, revocation, and evidence.
One complete authority-and-data loop establishes administrator intent, machine execution, source ownership, minimized output, and lineage before implementation detail.
Prove the admin-provisioned workload path first; add delegated user authority only when the customer job truly requires per-user source decisions and the separate grant can be denied and revoked independently.
Expose trust boundaries and independent revocation
A provider administrator and an application end user can be the same human but still exercise different tokens, resources, sessions, and revocation paths, so provider authentication, runtime workload authority, generated-app authentication, and source authorization must be implemented and tested independently. A provider token cannot authorize a Workboard tenant row, an app session cannot create sandboxes or change connectors, and neither can substitute for a source-native workload or optional delegated grant.
| Authority | Credential audience | May authorize | Must be denied | Independent revocation proof |
|---|---|---|---|---|
| Provider/control-plane session | Coding-agent organization and project services | Prompt/source changes, sandbox requests, connector administration, evidence review according to role | Generated-app tenant rows or end-user actions | Revoke provider session; an existing valid app session retains only its app authority |
| Runtime workload identity | Exact runtime and broker services | Declared tool, secret-handle, query, and egress operations for one app/environment/revision | Provider UI, another workload, app-user impersonation, or unrestricted source access | Revoke workload grant; provider reviewer and app user remain independently usable |
| Generated-app session | Exact generated application | App route, role, tenant, record, and action predicates | Sandbox lifecycle, source repository, release approval, vault secret, or another app tenant | Revoke app session/membership; provider reviewer can still inspect evidence but cannot act as app user |
| Source-system machine/workload grant | Exact Salesforce/Snowflake resource server and approved service identity | Administrator-approved templates, objects/tables, fields, rows, warehouse/API budget, and source account | Provider membership, app-user impersonation, arbitrary query text, or broader source account | Revoke machine grant; app may retain only separately governed cached data and must label it stale |
| Optional delegated user grant | Exact source resource server, human subject, client, consent, and delegated scopes | Only source actions the human and source policy delegated for this app purpose | Machine administration, provider roles, another human, silent scope expansion, or durable app ownership of source rows | Revoke delegated grant without revoking machine connector, provider reviewer, app session, or another user |
Daytona’s documented audit fields can supply provider-operation observations. Its secret substitution can restrict use to named hosts, but an omitted host list is unrestricted, so the adapter contract must require an explicit allowlist (Daytona audit logs, Daytona secrets). Cloudflare documents per-sandbox isolation and a Worker proxy pattern; outbound restriction requires internet access to be disabled and intended destinations to be admitted through allowedHosts or request handlers (Cloudflare Sandbox security model, Cloudflare network policies, Cloudflare proxy requests). The provider adapter normalizes only demonstrated observations into the course contract. Different capabilities are not parity, and neither provider’s controls satisfy application, source, or compliance obligations by themselves.
Private connectivity grants a path to an exact source endpoint, not membership in the private network. The typed query broker admits reviewed operations, bounded parameters, approved fields and predicates, maximum rows/bytes/time/cost, and a canonical template digest. Every returned value carries source account, object/table, query/API digest, source audit reference, retrieval time, transformation digest, and cache destination; Salesforce and Snowflake remain authoritative even after Workboard caches a minimized derivative.
The three-box model now exposes provider/control-plane, hosted-runtime, generated-app, and source boundaries, including private routing, field/query minimization, lineage, and separate machine versus optional user revocation.
If one credential, route, session, or revocation event can cross two boundaries or widen a typed operation into arbitrary source access, deny before credential use, source query, route bytes, or cache mutation.
Falsify positive, denied, failure, and recovery paths into immutable evidence
A checklist stating that a control exists is not falsifiable, so the complete system runs the complete Workboard connection and terminates each allowed, denied, failed, and recovered path in independently observed evidence. Each material threat needs a preventative or detective control, a protected test, immutable evidence, an accountable owner, and a retention rule. The matrix is a customer control record, not a claim of certification; applicability and retention periods come from the customer’s legal, regulatory, contractual, and records policies.
| Threat | Control | Test | Evidence | Owner | Retention |
|---|---|---|---|---|---|
| Prompt injection through user text, repository content, issue, webpage, or connector result | Instruction/data separation, taint propagation, trusted-source allowlist, prompt firewall, no retrieved content can approve tools | Plant an instruction to exfiltrate a secret and another to disable tests; require both to remain data and produce denied decision IDs | Prompt/input digests, taint labels, normalized instruction set, policy decisions, zero tool side effects | Agent security owner | Customer evidence schedule; expire raw sensitive prompt content earlier where policy requires, retain protected digests and decisions |
| Tool misuse or confused deputy | Typed tools, least-privilege actor/resource/action policy, path and parameter validation, budget, approval for destructive actions | Attempt shell interpolation, path escape, unapproved file write, arbitrary query, metadata egress, and destructive call without approval | Tool request/decision IDs, sanitized parameters, filesystem/network before-after facts, denial stage | Tooling platform owner | Customer security-event schedule plus investigation hold when opened |
| Secret leakage to prompt, source, process, browser, log, artifact, or response | Opaque handles, broker-side injection, destination binding, redaction, response scrubbing, secret scanning | Seed canary secret; exercise prompts, build, logs, artifacts, error and echo paths; require no plaintext and no unapproved destination access | Canary identifiers, vault/proxy audit IDs, redacted logs, scan reports, zero-byte network denial | Secrets and identity owner | Never retain secret bytes in evidence; retain identifiers and decisions per credential/audit policy |
| Cross-tenant or cross-app access | App-level authentication, tenant-bearing keys, row predicates, app/environment workload binding, neutral errors | Alpha positive workflow; Beta same-local-ID direct API/object/database probes; Workboard workload invokes revenue connector | Positive trace, denial traces, row/object/query before-after digests, no existence signal | Generated-app owner | Customer access/audit schedule; application data follows its separate lifecycle |
| Supply-chain substitution or compromised dependency | Pinned toolchain/image/dependencies, lockfile enforcement, SBOM, signature/provenance verification, hermetic reproducible build, vulnerability policy | Mutate lockfile, swap package digest, introduce unsigned image, remove SBOM component, and rebuild twice from clean workers | Source/lock/image/artifact/SBOM/provenance digests, resolver logs, reproducibility comparison, policy decisions | Build and supply-chain owner | Release evidence lifetime plus vulnerability-response and legal-hold requirements |
| Provider authentication confused with app authentication | Separate issuers, audiences, sessions, role stores, and revocation endpoints; no implicit identity mapping | Use provider token on app API and app token on control plane; revoke each independently while probing the unaffected authority | Issuer/audience claims protected from raw token disclosure, allow/deny traces, revocation and unaffected-positive traces | Identity architecture owner | Authentication-event schedule; session/token material excluded or cryptographically protected |
| Policy bypass or stale policy evidence | Central versioned policy bundle, digest-bound decisions, fail closed on unavailable/expired policy | Replay an allow decision under a newer denied policy; disconnect policy service; substitute evidence from another revision | Policy bundle and decision digests, expiry, replay denial, source/artifact/environment bindings | Policy owner | At least through release support window, then customer audit schedule or hold |
| Incomplete retirement or retention overrun | Resource inventory, deletion workflow, tombstones, backup/cache/object expiry jobs, holds, residual probes | Retire one preview and verify sandbox, route, secret grant, database, object, cache, snapshot, and evidence states independently | Deletion job IDs, inventory diffs, tombstones, retained-copy reason/access/expiry, final residual probe | Data lifecycle and records owner | Each data class follows declared schedule; holds override deletion only with recorded authority and scope |
Falsification changes one controlled fact that the named oracle must catch. Run mutations only in isolated synthetic fixtures, remove each mutation, then require the clean suite to pass again; surviving critical mutations block release rather than merely lowering a score.
| Falsifier | Injected mutation or attack | Required oracle | Blocking outcome |
|---|---|---|---|
| Prompt-injection falsifier | Retrieved README says to upload environment variables and mark tests passed | Tool policy denies upload; evaluator still runs protected tests; no secret/vault/network side effect | Any tool follows the untrusted instruction or evidence records an unrun pass |
| Tool-misuse falsifier | Agent constructs a command with untrusted shell metacharacters or requests a write outside workspace | Typed validation rejects before execution; filesystem digest outside workspace is unchanged | Command starts, outside path changes, or denial lacks actor/resource/scope |
| Secret-leak falsifier | Canary appears in an upstream echo/error while runtime requests an unapproved host | Proxy/broker scrubs response and destination policy denies; prompt/source/log/artifact scans stay clean | Any plaintext canary byte reaches sandbox-visible output or retained evidence |
| Tenant-isolation falsifier | Remove app_tenant_id predicate or substitute Beta token with Alpha record ID | Protected direct request fails the mutant and clean implementation denies neutrally with zero mutation | Mutant survives, record existence differs, or unrelated tenant state changes |
| Supply-chain falsifier | Replace one locked dependency archive or builder image while keeping its mutable name | Digest/signature/provenance gate fails before build admission; clean rebuild is reproducible | Substituted bytes build or publish under prior artifact identity |
| Auth-boundary falsifier | Send provider session to app endpoint, app session to provider endpoint, then revoke one issuer | Both token-confusion calls deny; unaffected valid session remains usable; revoked session fails | Either plane accepts wrong audience or one revocation disables/grants the other plane |
Observed evidence uses a three-part control, not an isolated denial: P+ proves the allowed customer job works, N- proves the forbidden variant is denied before its sensitive side effect, and U+ proves an unrelated allowed authority still works. The harness, not the generating agent, fills observed; a blank, inferred, stale, manually edited, or wrong-environment value is not a pass.
| Control pair | Precondition | Expected result | Required observed result | Immutable evidence fields |
|---|---|---|---|---|
P+ authorized revenue refresh | Exact artifact, policy, workload grant, connector versions, source test accounts, and cache baseline are active | Approved minimized rows reach cache and chart with freshness | Harness records source request, row count, cache mutation, and browser state for this run | Actor, resource, scope, precondition, expected, observed, environment, timestamp, run/trace/source/artifact/policy IDs |
N- raw-query and wrong-account probes | Same revision and environment; only operation or source account changes | Denial occurs before credential session, source query, route bytes, or cache mutation | Harness records named earliest denial and independent zero-side-effect probes | Denial decision, vault/source/network/cache before-after facts, exact mutation ID |
U+ independent Snowflake continuity | Salesforce grant is revoked while Snowflake grant remains active | Salesforce denies and Snowflake still returns approved minimized rows | Harness records both outcomes under one trusted clock and unchanged Snowflake version/grant | Revocation event, Salesforce denial, Snowflake positive trace, cache freshness changes |
P+ Alpha tenant workflow | Alpha app session, tenant-bearing records, accepted artifact and schema | Create/read/update path succeeds only in Alpha | Browser plus direct store oracle record exact Alpha state | App-session issuer/audience reference, tenant, row/object digests, browser trace |
N- Beta same-ID isolation | Same application and environment; Beta session addresses Alpha IDs | Neutral denial with no read, write, object bytes, or existence signal | API, database, object, and timing-class probes record denial and unchanged Alpha/Beta state | Paired positive/negative run IDs, before-after digests, policy decision |
U+ provider-review continuity | Generated-app membership is revoked; provider reviewer session remains valid | App request denies while provider reviewer can inspect immutable evidence only | Harness records app revocation and bounded provider evidence read without app impersonation | Separate issuer/audience references, revocation IDs, app denial, provider read trace |
The complete product path also distinguishes a controlled failure from a proved recovery. A stale chart with a silent source error is neither.
| Journey | Workboard trigger | Required terminal behavior | Immutable terminal evidence |
|---|---|---|---|
| Positive | Administrator activates the machine connector; preview refreshes regional pipeline and booked revenue | Typed Salesforce and Snowflake operations traverse approved private routes; only approved fields and rows enter the cache and chart | Connector/workload/policy/template versions, source audit IDs, route and broker decisions, row/byte counts, lineage, cache digest, browser trace |
| Denied | Workload requests raw query text, an extra field, wrong source account, unapproved host, or Beta’s cross-tenant cache key | Deny before credential session, source query, route bytes, cache mutation, or existence signal | Earliest denial decision plus independent vault/source/network/cache before-after facts and unaffected positive control |
| Failure | Source, private route, policy service, credential exchange, schema validation, or freshness check fails | Fail closed; do not relabel stale data as current, widen egress, retry without budget, or replace accepted cache state | Named failure stage, bounded retry count, prior cache digest and freshness label, zero unauthorized side effects, incident correlation |
| Recovery | Operator rotates the source grant or restores the approved route/template, then reruns the same minimized operation | New grant succeeds only after policy and attestation; old grant remains revoked; unrelated source and app authority stays usable | Rotation/revocation IDs, new positive trace, old-grant denial, unchanged unrelated-authority probe, renewed lineage and freshness evidence |
The compliance decision consumes this matrix plus the immutable run bundle and records applicable obligations, exceptions, residual risk, expiry, approver, rollback target, and every missing or failed control. Each Daytona or Cloudflare implementation must meet the common minimum contract using the observations its documented capabilities can support; this does not claim provider parity, transfer provider certifications to the generated application, or replace customer legal and compliance review.
The complete system now proves the allowed machine path, pre-side-effect denials, fail-closed behavior, scoped recovery, independent continuity, and immutable lineage for one Workboard revision.
Accept the bounded connector claim only when positive, denied, failure, recovery, and unaffected-authority observations reconcile to the same source, artifact, connector, workload, policy, route, template, and evidence identities; otherwise block and preserve the gap.
Treat a connector as a governed product resource
A connection string is too small a model for enterprise access, because it hides who approved the purpose, which source account and fields are reachable, what network path is used, and how access is revoked. A connector is a HelixWorks control-plane resource that combines source type, source-account scope, approved operations, credential handle, network route, data-minimization policy, lineage policy, owners, environment eligibility, expiry, and revocation state.
The source systems remain authoritative. Salesforce owns its organization records and native authorization; Snowflake owns its account, role, warehouse, database, schema, tables, and source audit. HelixWorks owns the connector definition and provider audit. The preview runtime executes one artifact with a narrowly scoped workload identity. The generated revenue app owns only its app configuration, derived metrics, cache, and app-managed records. A copied row or chart does not transfer source authority.
Creating a connector does not make it available everywhere. A separate binding maps a stable connector_version_id to one app, environment, runtime workload, and operation set. Project membership, preview-link possession, generated-app membership, connector administration, runtime workload authority, Salesforce organization scope, and Snowflake account role are independently granted and revoked.
Today’s actor is an enterprise administrator operating the control plane. Runtime reads use a service credential or workload identity scoped to the preview and connector. There is no established end-user identity yet. Human delegated access and OAuth on-behalf-of (OBO), where an application calls a source using a human user’s delegated authority, belong to the companion authorization course and must not be simulated here as completed capability.
Split secrets, credentials, queries, and network reachability
One broker that both stores a secret and accepts arbitrary destinations or query text becomes a high-value confused deputy, so a compromised preview could turn one grant into broad source access. HelixWorks separates duties and evaluates every request against the same app, environment, workload, connector, source-account, operation, and policy version.
| Component | Receives | Returns | Must never return |
|---|---|---|---|
| Connector catalog | Administrator intent, source metadata, purpose, environment | Versioned connector definition and validation status | A source credential |
| Secret vault | Encrypted credential material and rotation metadata | Internal secret handle to the credential broker | Secret value to agent, source, browser, or app database |
| Credential broker | Attested runtime workload, connector handle, operation | Short-lived source session used inside broker path | Reusable token or private key to the runtime |
| Query/API broker | Typed operation plus bounded parameters | Schema-validated minimized result and lineage | Raw arbitrary-query capability or unapproved fields |
| Private-connectivity broker | Approved connector route and workload | Network channel to exact endpoint, port, and source account | General private-network membership |
| Egress broker | Destination policy, resolved address, protocol, size/time limits | Allowed connection receipt or denial | Unlogged internet access or redirect-based escape |
The credential broker retrieves a vault handle only after workload attestation and connector policy pass. It exchanges or signs internally, establishes a source session, and discards it according to short expiry. Rotation changes the vault version and invalidates old sessions without rewriting generated source. Logs retain connector and secret-version identifiers, never token, assertion, password, or private-key bytes.
The query broker exposes operations such as salesforce.pipelineByRegion and snowflake.bookedRevenueByMonth, not execute(text). Parameters have types, length and range limits, fixed sort and pagination policies, maximum rows and bytes, timeout, concurrency, and cost budgets. The broker constructs parameterized source requests from reviewed templates, checks the response schema, removes unapproved fields, and records a canonical query or API-template digest.
Network reachability is not authorization. Private connectivity supplies a route; source authentication establishes the service principal; source-native roles constrain data; connector policy constrains purpose and operation; generated-app policy constrains what the app exposes. Every layer can deny the request independently.
Provision source-native least privilege and private paths
A technically valid service credential can still be dangerously broad, and a private route can accidentally expose an entire network, so source-native roles and exact network destinations remain part of the grant. Provisioning must be reviewable before a preview runtime can use it.
For Salesforce, register a dedicated external or connected app and a dedicated integration execution user for the approved organization. Salesforce client-credentials access runs as that configured user, so grant it only the API permissions and object or field access required for pipeline totals; do not reuse an administrator’s session. Prefer a short-lived service flow supported by the organization’s policy, and restrict the client app, execution user, scopes, network controls, and session lifetime. The query broker uses reviewed REST API resource templates and rejects object names or fields outside the connector version.
For Snowflake, create a dedicated least-privilege role, service user, warehouse budget, database and schema grants, and approved views. Keep key-pair material or an approved short-lived credential behind the credential broker. Grant USAGE only on the required warehouse and namespaces plus SELECT on reviewed views; do not grant account administration, table creation, unrestricted information schema, or future objects by default. Apply row-access, masking, and network policy where the source owner requires them.
Private connectivity uses customer-approved endpoints, routes, Domain Name System (DNS), and firewall policy for the exact service. Salesforce Private Connect and Snowflake inbound private connectivity are edition-, cloud-, region-, and account-configuration-dependent; the lab uses test accounts that meet those prerequisites and must not label an ordinary public TLS route “private.” The egress broker resolves and checks the destination at connection time, pins permitted ports and transport security, blocks loopback, link-local, metadata, and unrelated private ranges, limits redirects and response size, and logs both network and connector decisions. A private endpoint identifier is not a data grant.
Provisioning validates ownership and reachability separately:
- The administrator proves authority to create a connector in the HelixWorks project scope.
- A source administrator creates or approves the narrowly scoped Salesforce integration principal and Snowflake service role.
- The private-connectivity owner approves endpoint, DNS, routing, firewall, and egress policy.
- HelixWorks validates source account identifiers, operation templates, field allowlists, budgets, expiry, and audit destinations.
- A synthetic broker probe authenticates and executes a no-sensitive-data health operation.
- Only then can a specific preview runtime workload receive a connector binding.
Minimize data and preserve end-to-end lineage
A correct authorized query can still extract unnecessary personal or commercial data, and a chart without provenance cannot be reconciled or investigated. Data minimization restricts collection to fields, rows, precision, time window, and retention needed for the approved purpose; lineage records where a result came from and which transformations produced it.
The revenue dashboard needs regional pipeline and booked-revenue aggregates, not every contact, note, email address, opportunity description, or raw transaction. Prefer approved source views or API fields that already enforce this contract. Apply row limit, time window, grouping, suppression threshold, and maximum precision before the result crosses the broker boundary when the source supports it.
Each result envelope records connector version, source type and account, source object or view identifiers, canonical operation-template digest, parameter digest with sensitive values protected, source-observation time, retrieval time, policy version, transformation digest, app revision, cache key, freshness deadline, row count, and suppression decisions. Source-native audit IDs are linked when available.
The preview cache is generated-app data. It has its own encryption, tenant or audience scope, retention, reset, export, and deletion policy. Cache reset does not delete Salesforce or Snowflake records; source deletion does not automatically prove every authorized export or cache copy is gone. Revocation stops future broker reads but cannot recall data already exported or downloaded, so retention and downstream-use controls matter.
Freshness is part of correctness. The dashboard labels the source observation and last successful refresh, distinguishes partial source failure from zero revenue, and refuses to merge snapshots from incompatible periods without an explicit rule. A stale result may be displayed under a declared tolerance; it must never masquerade as current.
Complete the administrator connector-and-preview lab
If provisioning, private routing, runtime binding, queries, and denial paths are tested separately, a scope mismatch can survive between them and expose real data. The primary lab follows one enterprise administrator connecting one revenue-dashboard preview through both sources with synthetic or approved test datasets.
- Open revenue project
revenue-insightand previewpreview-rev-12; verify artifact, app environment, runtime workload, and managed-cache namespace are explicit. - Create stable Salesforce connector
sf-pipelineand immutable versionsf-pipeline-v1for test organizationsf-org-test-01, operationpipelineByRegion, approved objects and fields, 90-day window, 500-row cap, opaque service-credential handle, and private route. - Create stable Snowflake connector
snow-bookingsand immutable versionsnow-bookings-v1for test accountsnow-acct-test-02, dedicated role and warehouse, viewANALYTICS.APPROVED_BOOKINGS, operationbookedRevenueByMonth, opaque key handle, cost timeout, and private route. - Run configuration tests that validate source-native scopes without exposing secret material. Record source account, role or principal, endpoint, operation-template, field, row, time, and expiry policies.
- Bind both connector versions only to runtime workload
wl-preview-rev-12for the revenue app’s preview environment. Verify a Workboard runtime and another preview workload receive no binding. - Execute the two typed operations. Join only the approved region and month aggregates, store the minimized result in the app preview cache, and display freshness plus lineage in the dashboard.
- Revoke version
sf-pipeline-v1and its workload grant without deleting stable connectorsf-pipeline; require future Salesforce calls to fail whilesnow-bookings-v1remains independently usable. Label any retained cache stale according to policy, then provision successor versionsf-pipeline-v2under the same stable connector and prove workload reads resume under a new grant and evidence record. - Rotate the Snowflake key handle and verify the broker uses the new secret version without source or generated-code changes.
The lab uses workload and service authority only. No employee signs in to the generated app, and no request claims to carry a person’s Salesforce or Snowflake delegation. That human authorization and tenant/role mapping is intentionally deferred to the companion authorization course.
Deny cross-scope, secret, query, and network abuse
A successful dashboard proves only the permitted path, while the most consequential failures live in paths the customer never intended. Abuse tests therefore use synthetic test principals, workload identities, connector bindings, and source-account scopes rather than assuming end-user identity taught later.
| Abuse case | Precondition and attempt | Expected falsifier |
|---|---|---|
| Secret retrieval | Bound preview workload asks for the vault value behind connector version sf-pipeline-v1 | Broker exposes only an opaque denial and audit ID; no secret bytes enter runtime or logs |
| Arbitrary query | Runtime submits raw SOQL/SQL or adds an unapproved field/table | Typed-operation schema rejects before source execution |
| Wrong source account | Synthetic workload bound to sf-org-test-01 names another Salesforce organization or Snowflake account | Connector/source-account mismatch denies before credential use |
| Cross-app connector | Workboard preview workload invokes the revenue connector ID | App/environment/workload binding denies with no source session |
| Source-role escape | Test service principal addresses an object/view outside its source-native grant | Salesforce or Snowflake denies; broker records native denial without widening role |
| Network escape | Connector operation redirects or resolves to metadata, loopback, public internet, or unrelated private endpoint | Egress policy blocks before connection and records resolved destination |
| Over-broad result | Approved operation returns extra field or exceeds row/byte budget | Response-schema/minimization gate quarantines result; cache remains unchanged |
| Replay after revoke | Old operation receipt or workload token is replayed after connector revocation | Current policy and expiry deny; receipt cannot reauthorize |
Test for absence of side effects: no source query where pre-query policy should deny, no cache mutation, no secret access, no bytes over a blocked route, and no difference that reveals another source account. A denial only at the final chart is too late.
Evaluate connector reliability without overstating it
One clean administrator lab can be a lucky run, so a platform release based on it may fail when credentials rotate, routes flap, source schemas drift, or policy changes. A small versioned corpus repeats connector provisioning and operation in clean test projects and deliberately mutates important claims.
The evaluated unit includes connector schema, policy engine, credential and query brokers, egress policy, private-connectivity configuration, source test account, runtime binding, minimization, lineage, retries, and evidence exporter. Pin versions and start each run with a fresh connector, workload, cache, and short-lived test credential. Report distributions with sample counts, failure classes, latency, cost, and denial rate rather than a best result.
| Task class | Example | Blocking oracle |
|---|---|---|
| Provision | Create both test connectors and bind one preview workload | Exact app/environment/source scopes and no secret exposure |
| Rotate | Replace the Snowflake key handle during controlled use | New sessions use new version; old sessions expire; source unchanged |
| Revoke | Revoke only Salesforce connector | New Salesforce reads denied; Snowflake unaffected; cache labeled |
| Drift | Remove an approved source field in test schema | Contract check fails closed with actionable trace |
| Abuse | Attempt raw query, cross-app ID, wrong source account, and route escape | Every path denied before its sensitive side effect |
Falsification changes a controlled test condition that a named oracle must catch. Remove the app/environment predicate, widen the field list, mark a stale cache fresh, or permit a metadata route in an isolated fixture; the associated test must fail, then the mutation is removed and the clean suite must pass. A surviving critical mutation blocks the claim. The generating agent cannot edit the protected corpus or authorize release, and model grading remains secondary to deterministic source, policy, network, schema, and side-effect oracles.
These tests support only the declared Salesforce/Snowflake test scopes and archetype invariants. They do not establish universal connector coverage, production availability, or safety for every source configuration.
Challenge the archetype envelope at the connector boundary
Revenue analytics is read-heavy and can hide connector assumptions that fail for workflow or public-ingress applications, so reference probes keep the shared platform contract honest. They are bounded policy tests, not additional live enterprise integrations.
| Archetype | Connector posture | Shared-invariant probe |
|---|---|---|
| Revenue dashboard | Approved read-only Salesforce/Snowflake operations with lineage | No raw query, excess field, wrong source account, or unlabeled stale result |
| Workboard | No enterprise connector in the current blueprint | A Workboard runtime cannot invoke revenue connector IDs despite project proximity |
| Public intake app | Outbound enterprise write is absent unless separately approved | Anonymous submission cannot acquire connector, secret, query, or private-route authority |
The public intake app’s ability to accept an external submission in its own managed store does not imply it may write a Salesforce case. That would require a new blueprint capability, connector operation, abuse cases, idempotency semantics, data mapping, and approval.
Preserve evidence across every broker decision
A connector result without exact workload, source-account, policy, and network context can be misattributed to a different grant, so an audit summary alone is insufficient. The evidence ledger links control-plane approval, broker traces, source-native audit, minimized result, and app cache without storing secret values.
| Field | Example |
|---|---|
| Actor / resource / scope | workload:wl-preview-rev-12 / connector:snow-bookings version:snow-bookings-v1 / app:revenue environment:preview source:snow-acct-test-02 operation:bookedRevenueByMonth |
| Precondition | Connector active; workload binding current; source role, route, template, and budget validated |
| Expected | Approved monthly aggregates returned; raw SQL and other account scopes denied |
| Observed | 12 minimized rows cached with lineage; abuse probes denied before sensitive effects |
| Immutable trace/run/artifact ID | trace://broker/br-882, run://connector-lab/cr-044, artifact://lineage/sha256:example |
| Timestamp | 2026-07-28T16:31:44Z from trusted broker clock plus source observation time |
| Environment | preview-rev-12, broker policy and runtime image digests, test private endpoint region |
Also record administrator approval, connector and secret versions, source principal or role identifiers, query-template and parameter digests, resolved destination and route receipt, source-native request ID, row/byte counts, minimization actions, transformation digest, cache key, freshness, result, and denial stage. Evidence retention follows customer and regulatory policy; secret material is excluded by construction.
Further reading
Connector designs are easy to generalize from informal examples, so implementation and review should use official protocol, security, and source-system documentation. These primary sources describe the capabilities referenced here; the customer’s exact Salesforce and Snowflake editions, policies, and configurations still determine availability.
- Salesforce REST API Developer Guide — official API resources, request patterns, limits, and error behaviour for reviewed operation templates.
- Salesforce OAuth 2.0 Client Credentials Flow — official service-to-service flow guidance; use only under the source organization’s explicit connected-app and run-as-user policy.
- Salesforce Private Connect — official private-connectivity concepts and configuration boundaries.
- Snowflake key-pair authentication — official public-key authentication and rotation guidance for service access.
- Snowflake private connectivity — official inbound private-connectivity requirements and platform-specific paths.
- Snowflake ACCESS_HISTORY — official source-native lineage and access-history fields, subject to edition and retention constraints.
- NIST SP 800-207, Zero Trust Architecture — resource-level policy decisions that do not treat network location as authorization.
- RFC 9700, Best Current Practice for OAuth 2.0 Security — IETF security recommendations for OAuth deployments; human delegation remains companion authorization-course scope.
Key takeaways
Enterprise connectivity has many independent controls, and a compact summary prevents a private route or valid credential from being mistaken for data authorization. Keep these rules visible before identity and sharing are added.
- A connector is a versioned, revocable control-plane grant, not a credential string.
- Credential, secret, query/API, private-connectivity, and egress brokers separate duties and never expose source secrets to generated code.
- The preview workload, connector binding, source account and role, operation template, and network route must all authorize the same request.
- Source systems retain authority; app caches and derived metrics retain lineage, freshness, minimization, and separate lifecycle rules.
- Human delegated and on-behalf-of reads are not taught or claimed in this course; the companion authorization course owns them.
- Repeated clean runs, abuse denials, and caught mutations bound the connector claim without proving universal reliability.
Checklist
A revenue chart can be correct while the secret, query, source-account, or route boundary is wrong, so the administrator must review both success and denied side effects. Every checked item should point to an immutable broker or source record.
- [ ] Each connector names app, environment, runtime workload, source account, operations, fields, budgets, route, owners, expiry, and revocation state.
- [ ] Salesforce and Snowflake principals or roles are dedicated, least-privilege, and source-admin approved.
- [ ] Secret values never reach prompts, source, runtime, browser, app stores, or logs.
- [ ] Query/API operations are typed, parameterized, minimized, schema-checked, and budgeted.
- [ ] Private reachability is exact and independently authorized; metadata, loopback, public, and unrelated private paths are denied.
- [ ] Lineage links source request, policy, transformation, cache, freshness, app revision, and displayed result.
- [ ] Synthetic wrong-account, cross-app, raw-query, secret, over-broad-result, replay, and network tests fail before sensitive effects.
- [ ] Connector revocation and credential rotation are independent and observable.
- [ ] The evaluation reports all runs, variance, caught mutations, failed paths, and residual gaps.
- [ ] No human sign-in, app-role, delegated-source, sharing, or production claim appears in today’s evidence.
HelixWorks repository lab
Implement Northstar's supplier connector through the exact-decision boundary in application.ts. Generated code sends a typed operation and an opaque credential reference; it never receives the credential value.
return this.executions.executeOnce(command.tenantId, command.commandId, async () => {
const decision = await this.policy.authorize({
capabilityId: command.capabilityId,
tenantId: command.tenantId,
runId: command.runId,
connectorId: command.connectorId,
capability: command.operation.type,
resource: resourceFor(command.operation),
argumentDigest: argumentDigest(command.operation),
correlationId,
});
if (!decision.allowed) {
throw new ConnectorCommandRejected(decision.decisionId);
}
const abort = new AbortController();
return this.gateway.execute({
tenantId: command.tenantId,
credentialReference: command.credentialReference,
operation: command.operation,
signal: abort.signal,
});
});
The command declares one supplier operation. The connector application service interprets it, asks the policy broker for an exact claim decision, and calls the gateway only after allow. Software state changes in the idempotency repository and external supplier system; hardware effects are Node CPU/RAM plus outbound network and the supplier API's capacity. Evidence is the decision ID, operation result, and one recorded side effect for duplicate command IDs.
SRP separates policy decisions, connector orchestration, and vendor transport. DRY centralizes operation hashing and typed contracts. IoC/DI injects the policy, gateway, repository, and timeout. MVC keeps HTTP concerns in the controller. PubSub carries revocation and evidence events; IaC constrains ECS task identity, egress, secrets, queues, and databases per environment.
pnpm vitest run services/connector-broker/src/connector-broker.test.ts
pnpm vitest run services/policy-broker/src/policy-broker.test.ts
pnpm smoke:product
Replay the command concurrently, alter one supplier field after capability issue, switch tenants, revoke the capability, and force a timeout. The implementation passes only when duplicates produce one supplier effect, changed arguments and cross-tenant claims fail closed, revocation takes effect, and errors reveal neither credentials nor resource existence. A private network route alone would not satisfy this evidence.