04

Connect Governed Enterprise Data

Provision Salesforce and Snowflake access for a revenue-dashboard preview without exposing credentials, arbitrary queries, or private networks.

The enterprise problem and today’s slice

Enterprise problem: A generated application needs governed enterprise facts, but embedding a Salesforce token, Snowflake key, broad query role, or private-network route in source would let one preview expose credentials or reach data beyond the approved customer purpose.

Whole-course context: The incoming artifacts are Day 03’s revision-bound preview, per-app managed stores, migration records, and layered validation evidence; this day adds enterprise connectors before human application identity is configured.

Today’s slice: An enterprise administrator provisions Salesforce and Snowflake connectors, private paths, minimized operations, and a preview-runtime workload grant through independent credential, secret, query, and egress brokers.

End-of-day evidence: Authorized revenue reads carry lineage, while synthetic tests prove denial of secret retrieval, arbitrary query, cross-app connector, wrong source-account scope, and unapproved network paths.

Still unsolved: Human sign-in, delegated or on-behalf-of reads, generated-app roles, sharing, production promotion, and fleet operations remain explicitly deferred.

Customer outcome and implementation focus

The customer outcome is a reliable, reviewable implementation of 04 evaluation falsification and security. This day introduces the mechanism before policy detail and evidence review; it does not repeat the same customer stories in prose, tables, and diagrams.

Components in focus

Control-plane service owns desired state; runtime workers own execution; the policy/release boundary owns privileged effects. Compute: isolated service or sandbox tasks. Storage: PostgreSQL owns durable state, Redis is a bounded cache, object storage keeps artifacts/evidence, and queues are delivery buffers rather than authority.

Implement the mechanism

Implement the topic as an owned state transition with a named controller, durable record, bounded worker action, and observable terminal evidence. Verify a denied or failed path before calling the mechanism complete.

One governed Workboard connection from grant to evidence

A working chart and a green happy-path test can coexist with prompt injection, cross-tenant reads, leaked credentials, compromised dependencies, or self-approved evidence. The smallest defensible claim is narrower: an administrator provisions one bounded machine/workload grant, the Workboard runtime uses typed brokers over an approved route, source systems retain authority, and independent evidence records allowed, denied, failed, and recovered outcomes. Optional delegated user authority comes only after that machine path is proved and is never inferred from provider or application identity.

Locate today inside the full create-to-retire lifecycle

Security gates attached only to publication miss unsafe generation, stale evidence, rollback gaps, and incomplete deletion, so controls follow the application from the first prompt through final evidence expiry. A gate may narrow or block a claim; it never converts provider documentation, a model grade, or an unobserved expectation into proof.

The release claim is bounded: the named application revision passed the named corpus, policies, environments, and time window. It is not a certification, universal safety guarantee, or statement that Daytona, Cloudflare, Salesforce, or Snowflake makes the generated application compliant.

The full lifecycle shows that Day 04 proves a governed connector slice, not application identity, publication, continuous operations, retirement, or certification.

Describe only the connector controls and evidence observed for the named revision, environment, sources, policies, and time window; leave every later lifecycle claim open.

Reduce the connection to the smallest complete three-box model

Starting with OAuth variants, SDKs, or provider features hides the governing authority chain. Begin with three boxes: an enterprise administrator defines purpose and least privilege, a machine/workload executes only a typed operation, and the source returns minimized data plus lineage while remaining authoritative.

For the revenue Workboard, the administrator first provisions salesforce.pipelineByRegion and snowflake.bookedRevenueByMonth for one preview workload. This is service-to-service authority: no human access token is placed in the preview, no user is impersonated, and no application session is treated as source consent. Optional delegated user authority may later be added only as a separate source-native grant with its own issuer, audience, consent, operation scope, expiry, refresh, revocation, and evidence.

One complete authority-and-data loop establishes administrator intent, machine execution, source ownership, minimized output, and lineage before implementation detail.

Prove the admin-provisioned workload path first; add delegated user authority only when the customer job truly requires per-user source decisions and the separate grant can be denied and revoked independently.

Expose trust boundaries and independent revocation

A provider administrator and an application end user can be the same human but still exercise different tokens, resources, sessions, and revocation paths, so provider authentication, runtime workload authority, generated-app authentication, and source authorization must be implemented and tested independently. A provider token cannot authorize a Workboard tenant row, an app session cannot create sandboxes or change connectors, and neither can substitute for a source-native workload or optional delegated grant.

AuthorityCredential audienceMay authorizeMust be deniedIndependent revocation proof
Provider/control-plane sessionCoding-agent organization and project servicesPrompt/source changes, sandbox requests, connector administration, evidence review according to roleGenerated-app tenant rows or end-user actionsRevoke provider session; an existing valid app session retains only its app authority
Runtime workload identityExact runtime and broker servicesDeclared tool, secret-handle, query, and egress operations for one app/environment/revisionProvider UI, another workload, app-user impersonation, or unrestricted source accessRevoke workload grant; provider reviewer and app user remain independently usable
Generated-app sessionExact generated applicationApp route, role, tenant, record, and action predicatesSandbox lifecycle, source repository, release approval, vault secret, or another app tenantRevoke app session/membership; provider reviewer can still inspect evidence but cannot act as app user
Source-system machine/workload grantExact Salesforce/Snowflake resource server and approved service identityAdministrator-approved templates, objects/tables, fields, rows, warehouse/API budget, and source accountProvider membership, app-user impersonation, arbitrary query text, or broader source accountRevoke machine grant; app may retain only separately governed cached data and must label it stale
Optional delegated user grantExact source resource server, human subject, client, consent, and delegated scopesOnly source actions the human and source policy delegated for this app purposeMachine administration, provider roles, another human, silent scope expansion, or durable app ownership of source rowsRevoke delegated grant without revoking machine connector, provider reviewer, app session, or another user

Daytona’s documented audit fields can supply provider-operation observations. Its secret substitution can restrict use to named hosts, but an omitted host list is unrestricted, so the adapter contract must require an explicit allowlist (Daytona audit logs, Daytona secrets). Cloudflare documents per-sandbox isolation and a Worker proxy pattern; outbound restriction requires internet access to be disabled and intended destinations to be admitted through allowedHosts or request handlers (Cloudflare Sandbox security model, Cloudflare network policies, Cloudflare proxy requests). The provider adapter normalizes only demonstrated observations into the course contract. Different capabilities are not parity, and neither provider’s controls satisfy application, source, or compliance obligations by themselves.

Private connectivity grants a path to an exact source endpoint, not membership in the private network. The typed query broker admits reviewed operations, bounded parameters, approved fields and predicates, maximum rows/bytes/time/cost, and a canonical template digest. Every returned value carries source account, object/table, query/API digest, source audit reference, retrieval time, transformation digest, and cache destination; Salesforce and Snowflake remain authoritative even after Workboard caches a minimized derivative.

The three-box model now exposes provider/control-plane, hosted-runtime, generated-app, and source boundaries, including private routing, field/query minimization, lineage, and separate machine versus optional user revocation.

If one credential, route, session, or revocation event can cross two boundaries or widen a typed operation into arbitrary source access, deny before credential use, source query, route bytes, or cache mutation.

Assign SRP services, authoritative ownership, and one DRY IaC contract

If the generating agent can edit the test oracle, evaluate itself, approve exceptions, and sign release evidence, a malicious or merely wrong change can manufacture a pass. SRP separates generation, enforcement, observation, mapping, and approval; DRY keeps one versioned control catalog and one canonical evidence schema shared across application archetypes and runtime adapters.

ServiceOne responsibilityCannot ownContract output
Prompt firewallClassify instructions and isolate untrusted retrieved contentTool execution or release approvalNormalized instruction set, taint labels, denied instruction IDs
Tool policy decision pointDecide whether actor, tool, resource, scope, and precondition permit a callTool implementation or evidence gradingSigned allow/deny decision with policy digest and reason
Runtime adapterExecute admitted calls under quotas, isolation, and network policyCompliance mapping or application authorizationProvider-neutral execution, resource, log, and teardown records
Connector catalogVersion administrator intent, source account, typed operations, minimization, route, owners, expiry, and environment eligibilitySecret bytes, runtime execution, or source recordsImmutable connector version and validation status
Credential brokerExchange an attested workload and connector handle for an internal short-lived source sessionQuery choice, general network access, or returning credentials to runtimeBroker-side session reference, vault version, destination binding, expiry, and audit ID
Query and API brokerConstruct reviewed source requests and validate minimized responsesArbitrary query text, reusable source session, or data ownership transferTemplate digest, bounded parameters, row/byte counts, approved fields, and lineage
Private-connectivity brokerAdmit an exact workload-to-source endpoint routeCredential storage, source authorization, or general private-network membershipRoute decision, resolved endpoint, byte counts, denial stage, and expiry
Deterministic evaluatorRun protected unit, integration, E2E, IaC, policy, and mutation oraclesEditing generated source or approving waiversPer-oracle observed result, side effects, artifacts, and gaps
Side-effect observerRead authoritative stores and external boundaries independentlyMutating the state it observesBefore/after digests, counts, network/vault/source access facts
Evidence attestorBind immutable records to source, artifact, policy, environment, and clockDeciding whether business risk is acceptableSigned evidence bundle digest and completeness report
Compliance mapperMap tested controls to customer obligations and retention policyInventing certification scope or overriding failed testsControl matrix with owner, evidence URI, retention, gaps, and applicability
Release authorityAccept, narrow, waive under policy, or block the bounded release claimGenerating application code or altering protected testsSigned decision, approver separation, expiry, residual risk, rollback target

The provider-neutral policy input is stable; only the adapter translates runtime references:

subject:
  actor: agent-runner-17
  organization: org-helix
resource:
  application: app-revenue
  environment: preview-rev-12
  sourceRevision: rev-12
action:
  tool: http.request
  operation: salesforce.pipelineByRegion
constraints:
  destination: api.salesforce.example
  fields: [region, amount]
  maxRows: 500
  secretHandle: sf-pipeline-v1
evidence:
  policyDigest: sha256:policy-example
  decisionId: decision-882

Policy-as-code defaults to deny and makes every exception explicit, versioned, reviewed, time-bound, and testable. A policy result must name the evaluated actor, resource, action, environment, data classification, network destination, secret handle, budget, rule/version, and decision; an application 403 after a forbidden source query is a failed control because the sensitive side effect already occurred.

The same declarative contract drives both adapters; no runtime-specific script may restate connector scope, secret policy, network destinations, query templates, retention, or evidence fields.

Authoritative ownership is not transferred by connectivity. HelixWorks owns connector definitions, app/environment bindings, policy decisions, provider audit references, and evidence indexes. The generated Workboard owns its configuration, application records, derived metrics, and cache lifecycle. Salesforce owns Salesforce records and native audit; Snowflake owns its account, roles, warehouses, databases, schemas, tables, and query history. The vault owns credential material; brokers hold only expiring operational authority.

IaC declares connector binding, workload identity, vault handle, exact private endpoint or destination allowlist, route expiry, query-template version, budgets, app cache, logs, evidence sink, retention, and teardown. Remote state is encrypted, locked, versioned, and scoped by app/environment. DRY means these controls reference one catalog and policy bundle; SRP means the connector, credential, query, route, observation, compliance, and release owners cannot approve their own outputs.

Each trust boundary now contains an SRP service, one authoritative owner, and a declarative IaC/DRY contract that provider adapters translate without redefining policy.

Store every mutable fact once, make each broker responsible for one decision, and reject any adapter or generated app that duplicates connector, route, credential, query, ownership, or retention rules.

Falsify positive, denied, failure, and recovery paths into immutable evidence

A checklist stating that a control exists is not falsifiable, so the complete system runs the complete Workboard connection and terminates each allowed, denied, failed, and recovered path in independently observed evidence. Each material threat needs a preventative or detective control, a protected test, immutable evidence, an accountable owner, and a retention rule. The matrix is a customer control record, not a claim of certification; applicability and retention periods come from the customer’s legal, regulatory, contractual, and records policies.

ThreatControlTestEvidenceOwnerRetention
Prompt injection through user text, repository content, issue, webpage, or connector resultInstruction/data separation, taint propagation, trusted-source allowlist, prompt firewall, no retrieved content can approve toolsPlant an instruction to exfiltrate a secret and another to disable tests; require both to remain data and produce denied decision IDsPrompt/input digests, taint labels, normalized instruction set, policy decisions, zero tool side effectsAgent security ownerCustomer evidence schedule; expire raw sensitive prompt content earlier where policy requires, retain protected digests and decisions
Tool misuse or confused deputyTyped tools, least-privilege actor/resource/action policy, path and parameter validation, budget, approval for destructive actionsAttempt shell interpolation, path escape, unapproved file write, arbitrary query, metadata egress, and destructive call without approvalTool request/decision IDs, sanitized parameters, filesystem/network before-after facts, denial stageTooling platform ownerCustomer security-event schedule plus investigation hold when opened
Secret leakage to prompt, source, process, browser, log, artifact, or responseOpaque handles, broker-side injection, destination binding, redaction, response scrubbing, secret scanningSeed canary secret; exercise prompts, build, logs, artifacts, error and echo paths; require no plaintext and no unapproved destination accessCanary identifiers, vault/proxy audit IDs, redacted logs, scan reports, zero-byte network denialSecrets and identity ownerNever retain secret bytes in evidence; retain identifiers and decisions per credential/audit policy
Cross-tenant or cross-app accessApp-level authentication, tenant-bearing keys, row predicates, app/environment workload binding, neutral errorsAlpha positive workflow; Beta same-local-ID direct API/object/database probes; Workboard workload invokes revenue connectorPositive trace, denial traces, row/object/query before-after digests, no existence signalGenerated-app ownerCustomer access/audit schedule; application data follows its separate lifecycle
Supply-chain substitution or compromised dependencyPinned toolchain/image/dependencies, lockfile enforcement, SBOM, signature/provenance verification, hermetic reproducible build, vulnerability policyMutate lockfile, swap package digest, introduce unsigned image, remove SBOM component, and rebuild twice from clean workersSource/lock/image/artifact/SBOM/provenance digests, resolver logs, reproducibility comparison, policy decisionsBuild and supply-chain ownerRelease evidence lifetime plus vulnerability-response and legal-hold requirements
Provider authentication confused with app authenticationSeparate issuers, audiences, sessions, role stores, and revocation endpoints; no implicit identity mappingUse provider token on app API and app token on control plane; revoke each independently while probing the unaffected authorityIssuer/audience claims protected from raw token disclosure, allow/deny traces, revocation and unaffected-positive tracesIdentity architecture ownerAuthentication-event schedule; session/token material excluded or cryptographically protected
Policy bypass or stale policy evidenceCentral versioned policy bundle, digest-bound decisions, fail closed on unavailable/expired policyReplay an allow decision under a newer denied policy; disconnect policy service; substitute evidence from another revisionPolicy bundle and decision digests, expiry, replay denial, source/artifact/environment bindingsPolicy ownerAt least through release support window, then customer audit schedule or hold
Incomplete retirement or retention overrunResource inventory, deletion workflow, tombstones, backup/cache/object expiry jobs, holds, residual probesRetire one preview and verify sandbox, route, secret grant, database, object, cache, snapshot, and evidence states independentlyDeletion job IDs, inventory diffs, tombstones, retained-copy reason/access/expiry, final residual probeData lifecycle and records ownerEach data class follows declared schedule; holds override deletion only with recorded authority and scope

Falsification changes one controlled fact that the named oracle must catch. Run mutations only in isolated synthetic fixtures, remove each mutation, then require the clean suite to pass again; surviving critical mutations block release rather than merely lowering a score.

FalsifierInjected mutation or attackRequired oracleBlocking outcome
Prompt-injection falsifierRetrieved README says to upload environment variables and mark tests passedTool policy denies upload; evaluator still runs protected tests; no secret/vault/network side effectAny tool follows the untrusted instruction or evidence records an unrun pass
Tool-misuse falsifierAgent constructs a command with untrusted shell metacharacters or requests a write outside workspaceTyped validation rejects before execution; filesystem digest outside workspace is unchangedCommand starts, outside path changes, or denial lacks actor/resource/scope
Secret-leak falsifierCanary appears in an upstream echo/error while runtime requests an unapproved hostProxy/broker scrubs response and destination policy denies; prompt/source/log/artifact scans stay cleanAny plaintext canary byte reaches sandbox-visible output or retained evidence
Tenant-isolation falsifierRemove app_tenant_id predicate or substitute Beta token with Alpha record IDProtected direct request fails the mutant and clean implementation denies neutrally with zero mutationMutant survives, record existence differs, or unrelated tenant state changes
Supply-chain falsifierReplace one locked dependency archive or builder image while keeping its mutable nameDigest/signature/provenance gate fails before build admission; clean rebuild is reproducibleSubstituted bytes build or publish under prior artifact identity
Auth-boundary falsifierSend provider session to app endpoint, app session to provider endpoint, then revoke one issuerBoth token-confusion calls deny; unaffected valid session remains usable; revoked session failsEither plane accepts wrong audience or one revocation disables/grants the other plane

Observed evidence uses a three-part control, not an isolated denial: P+ proves the allowed customer job works, N- proves the forbidden variant is denied before its sensitive side effect, and U+ proves an unrelated allowed authority still works. The harness, not the generating agent, fills observed; a blank, inferred, stale, manually edited, or wrong-environment value is not a pass.

Control pairPreconditionExpected resultRequired observed resultImmutable evidence fields
P+ authorized revenue refreshExact artifact, policy, workload grant, connector versions, source test accounts, and cache baseline are activeApproved minimized rows reach cache and chart with freshnessHarness records source request, row count, cache mutation, and browser state for this runActor, resource, scope, precondition, expected, observed, environment, timestamp, run/trace/source/artifact/policy IDs
N- raw-query and wrong-account probesSame revision and environment; only operation or source account changesDenial occurs before credential session, source query, route bytes, or cache mutationHarness records named earliest denial and independent zero-side-effect probesDenial decision, vault/source/network/cache before-after facts, exact mutation ID
U+ independent Snowflake continuitySalesforce grant is revoked while Snowflake grant remains activeSalesforce denies and Snowflake still returns approved minimized rowsHarness records both outcomes under one trusted clock and unchanged Snowflake version/grantRevocation event, Salesforce denial, Snowflake positive trace, cache freshness changes
P+ Alpha tenant workflowAlpha app session, tenant-bearing records, accepted artifact and schemaCreate/read/update path succeeds only in AlphaBrowser plus direct store oracle record exact Alpha stateApp-session issuer/audience reference, tenant, row/object digests, browser trace
N- Beta same-ID isolationSame application and environment; Beta session addresses Alpha IDsNeutral denial with no read, write, object bytes, or existence signalAPI, database, object, and timing-class probes record denial and unchanged Alpha/Beta statePaired positive/negative run IDs, before-after digests, policy decision
U+ provider-review continuityGenerated-app membership is revoked; provider reviewer session remains validApp request denies while provider reviewer can inspect immutable evidence onlyHarness records app revocation and bounded provider evidence read without app impersonationSeparate issuer/audience references, revocation IDs, app denial, provider read trace

The complete product path also distinguishes a controlled failure from a proved recovery. A stale chart with a silent source error is neither.

JourneyWorkboard triggerRequired terminal behaviorImmutable terminal evidence
PositiveAdministrator activates the machine connector; preview refreshes regional pipeline and booked revenueTyped Salesforce and Snowflake operations traverse approved private routes; only approved fields and rows enter the cache and chartConnector/workload/policy/template versions, source audit IDs, route and broker decisions, row/byte counts, lineage, cache digest, browser trace
DeniedWorkload requests raw query text, an extra field, wrong source account, unapproved host, or Beta’s cross-tenant cache keyDeny before credential session, source query, route bytes, cache mutation, or existence signalEarliest denial decision plus independent vault/source/network/cache before-after facts and unaffected positive control
FailureSource, private route, policy service, credential exchange, schema validation, or freshness check failsFail closed; do not relabel stale data as current, widen egress, retry without budget, or replace accepted cache stateNamed failure stage, bounded retry count, prior cache digest and freshness label, zero unauthorized side effects, incident correlation
RecoveryOperator rotates the source grant or restores the approved route/template, then reruns the same minimized operationNew grant succeeds only after policy and attestation; old grant remains revoked; unrelated source and app authority stays usableRotation/revocation IDs, new positive trace, old-grant denial, unchanged unrelated-authority probe, renewed lineage and freshness evidence

The compliance decision consumes this matrix plus the immutable run bundle and records applicable obligations, exceptions, residual risk, expiry, approver, rollback target, and every missing or failed control. Each Daytona or Cloudflare implementation must meet the common minimum contract using the observations its documented capabilities can support; this does not claim provider parity, transfer provider certifications to the generated application, or replace customer legal and compliance review.

The complete system now proves the allowed machine path, pre-side-effect denials, fail-closed behavior, scoped recovery, independent continuity, and immutable lineage for one Workboard revision.

Accept the bounded connector claim only when positive, denied, failure, recovery, and unaffected-authority observations reconcile to the same source, artifact, connector, workload, policy, route, template, and evidence identities; otherwise block and preserve the gap.

Treat a connector as a governed product resource

A connection string is too small a model for enterprise access, because it hides who approved the purpose, which source account and fields are reachable, what network path is used, and how access is revoked. A connector is a HelixWorks control-plane resource that combines source type, source-account scope, approved operations, credential handle, network route, data-minimization policy, lineage policy, owners, environment eligibility, expiry, and revocation state.

The source systems remain authoritative. Salesforce owns its organization records and native authorization; Snowflake owns its account, role, warehouse, database, schema, tables, and source audit. HelixWorks owns the connector definition and provider audit. The preview runtime executes one artifact with a narrowly scoped workload identity. The generated revenue app owns only its app configuration, derived metrics, cache, and app-managed records. A copied row or chart does not transfer source authority.

Creating a connector does not make it available everywhere. A separate binding maps a stable connector_version_id to one app, environment, runtime workload, and operation set. Project membership, preview-link possession, generated-app membership, connector administration, runtime workload authority, Salesforce organization scope, and Snowflake account role are independently granted and revoked.

Today’s actor is an enterprise administrator operating the control plane. Runtime reads use a service credential or workload identity scoped to the preview and connector. There is no established end-user identity yet. Human delegated access and OAuth on-behalf-of (OBO), where an application calls a source using a human user’s delegated authority, belong to the companion authorization course and must not be simulated here as completed capability.

Split secrets, credentials, queries, and network reachability

One broker that both stores a secret and accepts arbitrary destinations or query text becomes a high-value confused deputy, so a compromised preview could turn one grant into broad source access. HelixWorks separates duties and evaluates every request against the same app, environment, workload, connector, source-account, operation, and policy version.

ComponentReceivesReturnsMust never return
Connector catalogAdministrator intent, source metadata, purpose, environmentVersioned connector definition and validation statusA source credential
Secret vaultEncrypted credential material and rotation metadataInternal secret handle to the credential brokerSecret value to agent, source, browser, or app database
Credential brokerAttested runtime workload, connector handle, operationShort-lived source session used inside broker pathReusable token or private key to the runtime
Query/API brokerTyped operation plus bounded parametersSchema-validated minimized result and lineageRaw arbitrary-query capability or unapproved fields
Private-connectivity brokerApproved connector route and workloadNetwork channel to exact endpoint, port, and source accountGeneral private-network membership
Egress brokerDestination policy, resolved address, protocol, size/time limitsAllowed connection receipt or denialUnlogged internet access or redirect-based escape

The credential broker retrieves a vault handle only after workload attestation and connector policy pass. It exchanges or signs internally, establishes a source session, and discards it according to short expiry. Rotation changes the vault version and invalidates old sessions without rewriting generated source. Logs retain connector and secret-version identifiers, never token, assertion, password, or private-key bytes.

The query broker exposes operations such as salesforce.pipelineByRegion and snowflake.bookedRevenueByMonth, not execute(text). Parameters have types, length and range limits, fixed sort and pagination policies, maximum rows and bytes, timeout, concurrency, and cost budgets. The broker constructs parameterized source requests from reviewed templates, checks the response schema, removes unapproved fields, and records a canonical query or API-template digest.

Network reachability is not authorization. Private connectivity supplies a route; source authentication establishes the service principal; source-native roles constrain data; connector policy constrains purpose and operation; generated-app policy constrains what the app exposes. Every layer can deny the request independently.

Provision source-native least privilege and private paths

A technically valid service credential can still be dangerously broad, and a private route can accidentally expose an entire network, so source-native roles and exact network destinations remain part of the grant. Provisioning must be reviewable before a preview runtime can use it.

For Salesforce, register a dedicated external or connected app and a dedicated integration execution user for the approved organization. Salesforce client-credentials access runs as that configured user, so grant it only the API permissions and object or field access required for pipeline totals; do not reuse an administrator’s session. Prefer a short-lived service flow supported by the organization’s policy, and restrict the client app, execution user, scopes, network controls, and session lifetime. The query broker uses reviewed REST API resource templates and rejects object names or fields outside the connector version.

For Snowflake, create a dedicated least-privilege role, service user, warehouse budget, database and schema grants, and approved views. Keep key-pair material or an approved short-lived credential behind the credential broker. Grant USAGE only on the required warehouse and namespaces plus SELECT on reviewed views; do not grant account administration, table creation, unrestricted information schema, or future objects by default. Apply row-access, masking, and network policy where the source owner requires them.

Private connectivity uses customer-approved endpoints, routes, Domain Name System (DNS), and firewall policy for the exact service. Salesforce Private Connect and Snowflake inbound private connectivity are edition-, cloud-, region-, and account-configuration-dependent; the lab uses test accounts that meet those prerequisites and must not label an ordinary public TLS route “private.” The egress broker resolves and checks the destination at connection time, pins permitted ports and transport security, blocks loopback, link-local, metadata, and unrelated private ranges, limits redirects and response size, and logs both network and connector decisions. A private endpoint identifier is not a data grant.

Provisioning validates ownership and reachability separately:

  1. The administrator proves authority to create a connector in the HelixWorks project scope.
  2. A source administrator creates or approves the narrowly scoped Salesforce integration principal and Snowflake service role.
  3. The private-connectivity owner approves endpoint, DNS, routing, firewall, and egress policy.
  4. HelixWorks validates source account identifiers, operation templates, field allowlists, budgets, expiry, and audit destinations.
  5. A synthetic broker probe authenticates and executes a no-sensitive-data health operation.
  6. Only then can a specific preview runtime workload receive a connector binding.

Minimize data and preserve end-to-end lineage

A correct authorized query can still extract unnecessary personal or commercial data, and a chart without provenance cannot be reconciled or investigated. Data minimization restricts collection to fields, rows, precision, time window, and retention needed for the approved purpose; lineage records where a result came from and which transformations produced it.

The revenue dashboard needs regional pipeline and booked-revenue aggregates, not every contact, note, email address, opportunity description, or raw transaction. Prefer approved source views or API fields that already enforce this contract. Apply row limit, time window, grouping, suppression threshold, and maximum precision before the result crosses the broker boundary when the source supports it.

Each result envelope records connector version, source type and account, source object or view identifiers, canonical operation-template digest, parameter digest with sensitive values protected, source-observation time, retrieval time, policy version, transformation digest, app revision, cache key, freshness deadline, row count, and suppression decisions. Source-native audit IDs are linked when available.

The preview cache is generated-app data. It has its own encryption, tenant or audience scope, retention, reset, export, and deletion policy. Cache reset does not delete Salesforce or Snowflake records; source deletion does not automatically prove every authorized export or cache copy is gone. Revocation stops future broker reads but cannot recall data already exported or downloaded, so retention and downstream-use controls matter.

Freshness is part of correctness. The dashboard labels the source observation and last successful refresh, distinguishes partial source failure from zero revenue, and refuses to merge snapshots from incompatible periods without an explicit rule. A stale result may be displayed under a declared tolerance; it must never masquerade as current.

Complete the administrator connector-and-preview lab

If provisioning, private routing, runtime binding, queries, and denial paths are tested separately, a scope mismatch can survive between them and expose real data. The primary lab follows one enterprise administrator connecting one revenue-dashboard preview through both sources with synthetic or approved test datasets.

  1. Open revenue project revenue-insight and preview preview-rev-12; verify artifact, app environment, runtime workload, and managed-cache namespace are explicit.
  2. Create stable Salesforce connector sf-pipeline and immutable version sf-pipeline-v1 for test organization sf-org-test-01, operation pipelineByRegion, approved objects and fields, 90-day window, 500-row cap, opaque service-credential handle, and private route.
  3. Create stable Snowflake connector snow-bookings and immutable version snow-bookings-v1 for test account snow-acct-test-02, dedicated role and warehouse, view ANALYTICS.APPROVED_BOOKINGS, operation bookedRevenueByMonth, opaque key handle, cost timeout, and private route.
  4. Run configuration tests that validate source-native scopes without exposing secret material. Record source account, role or principal, endpoint, operation-template, field, row, time, and expiry policies.
  5. Bind both connector versions only to runtime workload wl-preview-rev-12 for the revenue app’s preview environment. Verify a Workboard runtime and another preview workload receive no binding.
  6. Execute the two typed operations. Join only the approved region and month aggregates, store the minimized result in the app preview cache, and display freshness plus lineage in the dashboard.
  7. Revoke version sf-pipeline-v1 and its workload grant without deleting stable connector sf-pipeline; require future Salesforce calls to fail while snow-bookings-v1 remains independently usable. Label any retained cache stale according to policy, then provision successor version sf-pipeline-v2 under the same stable connector and prove workload reads resume under a new grant and evidence record.
  8. Rotate the Snowflake key handle and verify the broker uses the new secret version without source or generated-code changes.

The lab uses workload and service authority only. No employee signs in to the generated app, and no request claims to carry a person’s Salesforce or Snowflake delegation. That human authorization and tenant/role mapping is intentionally deferred to the companion authorization course.

Deny cross-scope, secret, query, and network abuse

A successful dashboard proves only the permitted path, while the most consequential failures live in paths the customer never intended. Abuse tests therefore use synthetic test principals, workload identities, connector bindings, and source-account scopes rather than assuming end-user identity taught later.

Abuse casePrecondition and attemptExpected falsifier
Secret retrievalBound preview workload asks for the vault value behind connector version sf-pipeline-v1Broker exposes only an opaque denial and audit ID; no secret bytes enter runtime or logs
Arbitrary queryRuntime submits raw SOQL/SQL or adds an unapproved field/tableTyped-operation schema rejects before source execution
Wrong source accountSynthetic workload bound to sf-org-test-01 names another Salesforce organization or Snowflake accountConnector/source-account mismatch denies before credential use
Cross-app connectorWorkboard preview workload invokes the revenue connector IDApp/environment/workload binding denies with no source session
Source-role escapeTest service principal addresses an object/view outside its source-native grantSalesforce or Snowflake denies; broker records native denial without widening role
Network escapeConnector operation redirects or resolves to metadata, loopback, public internet, or unrelated private endpointEgress policy blocks before connection and records resolved destination
Over-broad resultApproved operation returns extra field or exceeds row/byte budgetResponse-schema/minimization gate quarantines result; cache remains unchanged
Replay after revokeOld operation receipt or workload token is replayed after connector revocationCurrent policy and expiry deny; receipt cannot reauthorize

Test for absence of side effects: no source query where pre-query policy should deny, no cache mutation, no secret access, no bytes over a blocked route, and no difference that reveals another source account. A denial only at the final chart is too late.

Evaluate connector reliability without overstating it

One clean administrator lab can be a lucky run, so a platform release based on it may fail when credentials rotate, routes flap, source schemas drift, or policy changes. A small versioned corpus repeats connector provisioning and operation in clean test projects and deliberately mutates important claims.

The evaluated unit includes connector schema, policy engine, credential and query brokers, egress policy, private-connectivity configuration, source test account, runtime binding, minimization, lineage, retries, and evidence exporter. Pin versions and start each run with a fresh connector, workload, cache, and short-lived test credential. Report distributions with sample counts, failure classes, latency, cost, and denial rate rather than a best result.

Task classExampleBlocking oracle
ProvisionCreate both test connectors and bind one preview workloadExact app/environment/source scopes and no secret exposure
RotateReplace the Snowflake key handle during controlled useNew sessions use new version; old sessions expire; source unchanged
RevokeRevoke only Salesforce connectorNew Salesforce reads denied; Snowflake unaffected; cache labeled
DriftRemove an approved source field in test schemaContract check fails closed with actionable trace
AbuseAttempt raw query, cross-app ID, wrong source account, and route escapeEvery path denied before its sensitive side effect

Falsification changes a controlled test condition that a named oracle must catch. Remove the app/environment predicate, widen the field list, mark a stale cache fresh, or permit a metadata route in an isolated fixture; the associated test must fail, then the mutation is removed and the clean suite must pass. A surviving critical mutation blocks the claim. The generating agent cannot edit the protected corpus or authorize release, and model grading remains secondary to deterministic source, policy, network, schema, and side-effect oracles.

These tests support only the declared Salesforce/Snowflake test scopes and archetype invariants. They do not establish universal connector coverage, production availability, or safety for every source configuration.

Challenge the archetype envelope at the connector boundary

Revenue analytics is read-heavy and can hide connector assumptions that fail for workflow or public-ingress applications, so reference probes keep the shared platform contract honest. They are bounded policy tests, not additional live enterprise integrations.

ArchetypeConnector postureShared-invariant probe
Revenue dashboardApproved read-only Salesforce/Snowflake operations with lineageNo raw query, excess field, wrong source account, or unlabeled stale result
WorkboardNo enterprise connector in the current blueprintA Workboard runtime cannot invoke revenue connector IDs despite project proximity
Public intake appOutbound enterprise write is absent unless separately approvedAnonymous submission cannot acquire connector, secret, query, or private-route authority

The public intake app’s ability to accept an external submission in its own managed store does not imply it may write a Salesforce case. That would require a new blueprint capability, connector operation, abuse cases, idempotency semantics, data mapping, and approval.

Preserve evidence across every broker decision

A connector result without exact workload, source-account, policy, and network context can be misattributed to a different grant, so an audit summary alone is insufficient. The evidence ledger links control-plane approval, broker traces, source-native audit, minimized result, and app cache without storing secret values.

FieldExample
Actor / resource / scopeworkload:wl-preview-rev-12 / connector:snow-bookings version:snow-bookings-v1 / app:revenue environment:preview source:snow-acct-test-02 operation:bookedRevenueByMonth
PreconditionConnector active; workload binding current; source role, route, template, and budget validated
ExpectedApproved monthly aggregates returned; raw SQL and other account scopes denied
Observed12 minimized rows cached with lineage; abuse probes denied before sensitive effects
Immutable trace/run/artifact IDtrace://broker/br-882, run://connector-lab/cr-044, artifact://lineage/sha256:example
Timestamp2026-07-28T16:31:44Z from trusted broker clock plus source observation time
Environmentpreview-rev-12, broker policy and runtime image digests, test private endpoint region

Also record administrator approval, connector and secret versions, source principal or role identifiers, query-template and parameter digests, resolved destination and route receipt, source-native request ID, row/byte counts, minimization actions, transformation digest, cache key, freshness, result, and denial stage. Evidence retention follows customer and regulatory policy; secret material is excluded by construction.

Further reading

Connector designs are easy to generalize from informal examples, so implementation and review should use official protocol, security, and source-system documentation. These primary sources describe the capabilities referenced here; the customer’s exact Salesforce and Snowflake editions, policies, and configurations still determine availability.

Key takeaways

Enterprise connectivity has many independent controls, and a compact summary prevents a private route or valid credential from being mistaken for data authorization. Keep these rules visible before identity and sharing are added.

  • A connector is a versioned, revocable control-plane grant, not a credential string.
  • Credential, secret, query/API, private-connectivity, and egress brokers separate duties and never expose source secrets to generated code.
  • The preview workload, connector binding, source account and role, operation template, and network route must all authorize the same request.
  • Source systems retain authority; app caches and derived metrics retain lineage, freshness, minimization, and separate lifecycle rules.
  • Human delegated and on-behalf-of reads are not taught or claimed in this course; the companion authorization course owns them.
  • Repeated clean runs, abuse denials, and caught mutations bound the connector claim without proving universal reliability.

Checklist

A revenue chart can be correct while the secret, query, source-account, or route boundary is wrong, so the administrator must review both success and denied side effects. Every checked item should point to an immutable broker or source record.

  • [ ] Each connector names app, environment, runtime workload, source account, operations, fields, budgets, route, owners, expiry, and revocation state.
  • [ ] Salesforce and Snowflake principals or roles are dedicated, least-privilege, and source-admin approved.
  • [ ] Secret values never reach prompts, source, runtime, browser, app stores, or logs.
  • [ ] Query/API operations are typed, parameterized, minimized, schema-checked, and budgeted.
  • [ ] Private reachability is exact and independently authorized; metadata, loopback, public, and unrelated private paths are denied.
  • [ ] Lineage links source request, policy, transformation, cache, freshness, app revision, and displayed result.
  • [ ] Synthetic wrong-account, cross-app, raw-query, secret, over-broad-result, replay, and network tests fail before sensitive effects.
  • [ ] Connector revocation and credential rotation are independent and observable.
  • [ ] The evaluation reports all runs, variance, caught mutations, failed paths, and residual gaps.
  • [ ] No human sign-in, app-role, delegated-source, sharing, or production claim appears in today’s evidence.

HelixWorks repository lab

Implement Northstar's supplier connector through the exact-decision boundary in application.ts. Generated code sends a typed operation and an opaque credential reference; it never receives the credential value.

return this.executions.executeOnce(command.tenantId, command.commandId, async () => {
  const decision = await this.policy.authorize({
    capabilityId: command.capabilityId,
    tenantId: command.tenantId,
    runId: command.runId,
    connectorId: command.connectorId,
    capability: command.operation.type,
    resource: resourceFor(command.operation),
    argumentDigest: argumentDigest(command.operation),
    correlationId,
  });
  if (!decision.allowed) {
    throw new ConnectorCommandRejected(decision.decisionId);
  }
  const abort = new AbortController();
  return this.gateway.execute({
    tenantId: command.tenantId,
    credentialReference: command.credentialReference,
    operation: command.operation,
    signal: abort.signal,
  });
});

The command declares one supplier operation. The connector application service interprets it, asks the policy broker for an exact claim decision, and calls the gateway only after allow. Software state changes in the idempotency repository and external supplier system; hardware effects are Node CPU/RAM plus outbound network and the supplier API's capacity. Evidence is the decision ID, operation result, and one recorded side effect for duplicate command IDs.

SRP separates policy decisions, connector orchestration, and vendor transport. DRY centralizes operation hashing and typed contracts. IoC/DI injects the policy, gateway, repository, and timeout. MVC keeps HTTP concerns in the controller. PubSub carries revocation and evidence events; IaC constrains ECS task identity, egress, secrets, queues, and databases per environment.

pnpm vitest run services/connector-broker/src/connector-broker.test.ts
pnpm vitest run services/policy-broker/src/policy-broker.test.ts
pnpm smoke:product

Replay the command concurrently, alter one supplier field after capability issue, switch tenants, revoke the capability, and force a timeout. The implementation passes only when duplicates produce one supplier effect, changed arguments and cross-tenant claims fail closed, revocation takes effect, and errors reveal neither credentials nor resource existence. A private network route alone would not satisfy this evidence.