Connector guides
How connectors work
What every Warde connector needs on the ServiceNow side, how sync and write-back work, and how to add a second engine.
An engine is one system Warde reads access from and writes access to. A connector is the code that talks to one kind of engine. Warde ships these connectors:
| Connector | Reads | Writes | Guide |
|---|---|---|---|
| SailPoint ISC | Sources, entitlements, roles, access profiles, accounts, who holds what | Grants and removals through ISC access requests | SailPoint Identity Security Cloud |
| SailPoint IdentityIQ | Applications, entitlements, roles, accounts, who holds what | Grants and removals through a provisioning workflow, and a separation of duties check before approval | SailPoint IdentityIQ |
| Microsoft Entra ID | Groups, app roles, licences, access packages, directory roles, users | Group membership, app roles, licences, access packages and directory roles, depending on the permissions you grant | Microsoft Entra ID Governance |
| ServiceNow (manual fulfilment) | Nothing | Catalog tasks for a person | ServiceNow tasks |
| ServiceNow (local instance) | Users who hold the requester role, as accounts | Nothing | ServiceNow tasks |
Warde installs two engines ready to use: ServiceNow tasks, for manual work, and ServiceNow, for this instance's own accounts. You add an engine for each identity system in Guided Setup step 2.
What every connected engine needs in ServiceNow
An engine reaches its system through three platform records in Connections & Credentials:
| Record | Holds |
|---|---|
| Connection & Credential alias | The name the engine points at |
| HTTP connection | The endpoint URL and the credential. It must be https://. |
| Basic auth credential | The client ID and secret, or username and password |
Warde installs one empty set for each connector:
| Connector | Alias | Connection | Credential |
|---|---|---|---|
| SailPoint ISC | SailPoint ISC | SailPoint ISC - connection | SailPoint ISC: credential |
| SailPoint IdentityIQ | SailPoint IIQ | SailPoint IIQ - connection | SailPoint IIQ: credential |
| Microsoft Entra ID | Microsoft Entra ID | Microsoft Entra ID - connection | Microsoft Entra ID: credential |
They install on first install only, so an upgrade never overwrites what you put in them. The platform does not let an application write aliases or connections, so you enter the endpoint URL on the connection record yourself. Guided Setup writes the client ID and secret into the credential for you; the secret is write-only on screen.
The engine record
Guided Setup creates the engine record. Some fields are only on the engine form, under Engines in the Admin Workspace:
| Field | What it does |
|---|---|
| Name, Connector, Environment | Set in Guided Setup. Environment is development, testing, sandbox or production. |
| Connection alias | The alias above |
| MID server | For an engine the instance cannot reach directly. Set it here; the MID server on the connection record is not used. |
| Correlation attribute, Correlation field | The pair that binds an account to a user. See Guided Setup step 3. |
| Status | Active, Read only (syncs, but changes go to tasks), Degraded (an outage was detected and its work waits) or Disabled (no sync and no changes) |
| Rate limit budget | Calls allowed in each 10-second window |
| Retry base, Retry window | Override the instance retry settings for this engine |
| Connector configuration | JSON settings specific to the connector. Each connector guide lists its keys. |
| Alert sink, thresholds | Override the instance engine alert settings. See Health, alerts and logs. |
| Name pattern, Name replacement | A rule that cleans up entitlement names for people to read |
The engine form has Run health check, Sync now and Send test alert.
How sync works
Each engine has three feeds, run by scheduled jobs across every engine that is not disabled:
| Feed | What it imports | Job |
|---|---|---|
| Catalog | Collections, then their entitlements, and how entitlements contain each other | Warde sync: catalog, daily at 02:00 |
| Accounts | Each account, matched to a ServiceNow user | Warde sync: accounts, every 4 hours |
| Assignments | Who holds what | Warde sync: assignments, every 6 hours |
Sync now in Guided Setup or on the engine runs all three in order, in the background.
Each feed lands in a staging table first, and the seven shipped transform maps copy it into Warde's records. Each run is an import set under Import Sets, and rows that failed show in its import row errors.
Delta and full reads. Where the engine supports it, Warde reads only what changed since the last run, and does a full read at least every 168 hours (x_66256_warde.sync.full_sweep_hours). The first sync of an engine is always a full read. Full reads of who holds what start only on the days in x_66256_warde.sync.assignment_sweep_days, Saturday and Sunday by default; Sync now and a first sync do not wait. Each feed's position is kept on the engine in Sync watermarks; clear a feed's entry to force a full read of it.
Throttling. When an engine answers 429 or the engine's rate budget is spent, the feed pauses and picks up where it stopped on the next run.
Disappearing access. When something stops appearing in an engine, Warde waits 168 hours (x_66256_warde.sync.reconcile_grace_hours) before treating it as gone. If one run would retire more than 500 records (x_66256_warde.sync.reconcile_max) or 10 percent of them (x_66256_warde.sync.reconcile_max_pct), Warde retires nothing and records a sync discrepancy for you to look at. A half-broken read cannot wipe out your data.
Matching accounts to users. Each account is matched to a user by the engine's correlation pair, or the instance default: the account's employeeNumber against the user's employee_number. An account that matches nobody is imported as an orphan: it belongs to nobody, cannot be used in requests and is left out of reviews. The Admin Workspace list Accounts & access > Orphan accounts shows them. An account whose match stops working becomes an orphan again on the next sync.
How write-back works
An approved request line becomes a fulfilment operation, sent to the engine that holds the access. It goes to a person instead, as a catalog task, when:
- the entitlement cannot be fulfilled by its engine;
- for a removal, the engine reports the access as not removable;
- no engine is bound to the collection;
- the connector cannot do that kind of change.
A failed call is retried, with a growing delay, for up to 240 minutes, then parked for a person. If the engine stops answering altogether, it is marked degraded, its work is held, and the work is sent again when the engine recovers. See Fulfilment and manual tasks.
Warde does not create accounts. A grant for someone with no account on the engine becomes a task asking for the account first.
Add a second engine of the same kind
The shipped alias serves one engine. For a second ISC tenant, a second IdentityIQ, or a second Entra tenant:
- In Connections & Credentials, create a Basic Auth credential, then an HTTP connection with the endpoint URL and that credential attached, then a Connection & Credential alias of type Connection for it. Use a plain hyphen in the connection's name.
- In Guided Setup step 2, add an engine, choose the connector and the new alias, and fill in the rest.
- Enter the client ID and secret. On an alias Warde did not install, only a platform administrator can do this.
- For Entra, set the connector configuration on the engine form.
- Select Test connection, then Sync now.
Clones
Warde's clone preservers keep the target instance's engines, aliases, connections and credentials when you clone over it. An engine that exists only in the source arrives in the target enabled: disable it after a clone if it should not run there.
API versions
| Connector | API | Version |
|---|---|---|
| SailPoint ISC | ISC REST API | v3, v2024 and v2025, per endpoint. Each can be repointed on the engine. |
| SailPoint IdentityIQ | SCIM 2.0 | IdentityIQ 8.x |
| Microsoft Entra ID | Microsoft Graph | v1.0 |