Integrations

Read-only, and specific about it

Every integration below names the actual views, endpoints and files it reads, and the exact permission each requires. No integration needs write access to anything.

Sources, not connectors

An integration here does not move your data anywhere. It reads metadata so an investigation has evidence.

That distinction matters more than it sounds. A connector in most products means a pipe: it extracts your data and puts it somewhere else. Nothing on this page does that. These are read-only metadata sources — catalog views, scheduler tables, run history, and the counts that are already being recorded — collected by an agent inside your network and scoped to a specific incident.

They are also deliberately not ranked. The topology is assembled from every provider that can reach something, and none of them is treated as authoritative — because on most of these platforms the definition that actually executes is not the one in source control.

Why the sources differ by platform
Where the definition lives Platforms How it is read
Definition lives in a serviceGlue, Data Factory, Databricks, FivetranRead through the service API — there is no file
Definition lives in a databaseSQL Agent, SSIS, Oracle, InformaticaRead from catalog and repository tables
Definition is in git, behaviour is notAirflow, dbtConnections, variables and artefacts read separately
No definition anywhereBespoke services, cronInferred from logs, config and write activity
Databases

Databases

Schedulers

Schedulers

Orchestrators

Orchestrators

Cloud ETL

Cloud ETL

Warehouses

Warehouses

Queues and streams

Queues and streams

What every integration has in common

  • Read-only. No integration requires write access to anything.
  • A finite query catalogue. The statements the agent may run are held in a file on your host and approved by your team — see the agent.
  • Redaction before transmission. Applied inside your network, not on ingest.
  • Scoped to an incident. Collection is not continuous; topology discovery is the one exception and reads metadata only.
  • A stated limit. Every page above says what its source cannot tell you.

The full posture — threat model, what crosses the boundary, retention and access — is on the security page.

Get started

Bring us a pipeline that broke last week

The fastest way to evaluate this is a real incident you already know the answer to. If Decim gets it wrong, that is a far more useful demo than one where it doesn't.