Syncs and permissions
Keep source access narrow, explain what a sync read, and make data failures visible before agents use the results.
Connector permissions begin with the account that authorizes the source. Prefer a dedicated service account, grant it the minimum readable scope, and document its owner and rotation process.
The first sync is usually the broadest. Later syncs should make changed state, failures, and source freshness visible. If a source schema changes or an authorization expires, treat that as a context-quality issue: agents and workflows should not silently act on incomplete data.
Actualizado el 31 ago 2026