WardeDocs Administrators Connectors People using Warde warde.app

Connector guides

How connectors work

What every Warde connector needs on the ServiceNow side, how sync and write-back work, and how to add a second engine.

An engine is one system Warde reads access from and writes access to. A connector is the code that talks to one kind of engine. Warde ships these connectors:

ConnectorReadsWritesGuide
SailPoint ISCSources, entitlements, roles, access profiles, accounts, who holds whatGrants and removals through ISC access requestsSailPoint Identity Security Cloud
SailPoint IdentityIQApplications, entitlements, roles, accounts, who holds whatGrants and removals through a provisioning workflow, and a separation of duties check before approvalSailPoint IdentityIQ
Microsoft Entra IDGroups, app roles, licences, access packages, directory roles, usersGroup membership, app roles, licences, access packages and directory roles, depending on the permissions you grantMicrosoft Entra ID Governance
ServiceNow (manual fulfilment)NothingCatalog tasks for a personServiceNow tasks
ServiceNow (local instance)Users who hold the requester role, as accountsNothingServiceNow tasks

Warde installs two engines ready to use: ServiceNow tasks, for manual work, and ServiceNow, for this instance's own accounts. You add an engine for each identity system in Guided Setup step 2.

What every connected engine needs in ServiceNow

An engine reaches its system through three platform records in Connections & Credentials:

RecordHolds
Connection & Credential aliasThe name the engine points at
HTTP connectionThe endpoint URL and the credential. It must be https://.
Basic auth credentialThe client ID and secret, or username and password

Warde installs one empty set for each connector:

ConnectorAliasConnectionCredential
SailPoint ISCSailPoint ISCSailPoint ISC - connectionSailPoint ISC: credential
SailPoint IdentityIQSailPoint IIQSailPoint IIQ - connectionSailPoint IIQ: credential
Microsoft Entra IDMicrosoft Entra IDMicrosoft Entra ID - connectionMicrosoft Entra ID: credential

They install on first install only, so an upgrade never overwrites what you put in them. The platform does not let an application write aliases or connections, so you enter the endpoint URL on the connection record yourself. Guided Setup writes the client ID and secret into the credential for you; the secret is write-only on screen.

The engine record

Guided Setup creates the engine record. Some fields are only on the engine form, under Engines in the Admin Workspace:

FieldWhat it does
Name, Connector, EnvironmentSet in Guided Setup. Environment is development, testing, sandbox or production.
Connection aliasThe alias above
MID serverFor an engine the instance cannot reach directly. Set it here; the MID server on the connection record is not used.
Correlation attribute, Correlation fieldThe pair that binds an account to a user. See Guided Setup step 3.
StatusActive, Read only (syncs, but changes go to tasks), Degraded (an outage was detected and its work waits) or Disabled (no sync and no changes)
Rate limit budgetCalls allowed in each 10-second window
Retry base, Retry windowOverride the instance retry settings for this engine
Connector configurationJSON settings specific to the connector. Each connector guide lists its keys.
Alert sink, thresholdsOverride the instance engine alert settings. See Health, alerts and logs.
Name pattern, Name replacementA rule that cleans up entitlement names for people to read

The engine form has Run health check, Sync now and Send test alert.

How sync works

Each engine has three feeds, run by scheduled jobs across every engine that is not disabled:

FeedWhat it importsJob
CatalogCollections, then their entitlements, and how entitlements contain each otherWarde sync: catalog, daily at 02:00
AccountsEach account, matched to a ServiceNow userWarde sync: accounts, every 4 hours
AssignmentsWho holds whatWarde sync: assignments, every 6 hours

Sync now in Guided Setup or on the engine runs all three in order, in the background.

Each feed lands in a staging table first, and the seven shipped transform maps copy it into Warde's records. Each run is an import set under Import Sets, and rows that failed show in its import row errors.

Delta and full reads. Where the engine supports it, Warde reads only what changed since the last run, and does a full read at least every 168 hours (x_66256_warde.sync.full_sweep_hours). The first sync of an engine is always a full read. Full reads of who holds what start only on the days in x_66256_warde.sync.assignment_sweep_days, Saturday and Sunday by default; Sync now and a first sync do not wait. Each feed's position is kept on the engine in Sync watermarks; clear a feed's entry to force a full read of it.

Throttling. When an engine answers 429 or the engine's rate budget is spent, the feed pauses and picks up where it stopped on the next run.

Disappearing access. When something stops appearing in an engine, Warde waits 168 hours (x_66256_warde.sync.reconcile_grace_hours) before treating it as gone. If one run would retire more than 500 records (x_66256_warde.sync.reconcile_max) or 10 percent of them (x_66256_warde.sync.reconcile_max_pct), Warde retires nothing and records a sync discrepancy for you to look at. A half-broken read cannot wipe out your data.

Matching accounts to users. Each account is matched to a user by the engine's correlation pair, or the instance default: the account's employeeNumber against the user's employee_number. An account that matches nobody is imported as an orphan: it belongs to nobody, cannot be used in requests and is left out of reviews. The Admin Workspace list Accounts & access > Orphan accounts shows them. An account whose match stops working becomes an orphan again on the next sync.

How write-back works

An approved request line becomes a fulfilment operation, sent to the engine that holds the access. It goes to a person instead, as a catalog task, when:

A failed call is retried, with a growing delay, for up to 240 minutes, then parked for a person. If the engine stops answering altogether, it is marked degraded, its work is held, and the work is sent again when the engine recovers. See Fulfilment and manual tasks.

Warde does not create accounts. A grant for someone with no account on the engine becomes a task asking for the account first.

Add a second engine of the same kind

The shipped alias serves one engine. For a second ISC tenant, a second IdentityIQ, or a second Entra tenant:

  1. In Connections & Credentials, create a Basic Auth credential, then an HTTP connection with the endpoint URL and that credential attached, then a Connection & Credential alias of type Connection for it. Use a plain hyphen in the connection's name.
  2. In Guided Setup step 2, add an engine, choose the connector and the new alias, and fill in the rest.
  3. Enter the client ID and secret. On an alias Warde did not install, only a platform administrator can do this.
  4. For Entra, set the connector configuration on the engine form.
  5. Select Test connection, then Sync now.

Clones

Warde's clone preservers keep the target instance's engines, aliases, connections and credentials when you clone over it. An engine that exists only in the source arrives in the target enabled: disable it after a clone if it should not run there.

API versions

ConnectorAPIVersion
SailPoint ISCISC REST APIv3, v2024 and v2025, per endpoint. Each can be repointed on the engine.
SailPoint IdentityIQSCIM 2.0IdentityIQ 8.x
Microsoft Entra IDMicrosoft Graphv1.0

Warde is a ServiceNow scoped application, x_66256_warde. These guides describe the current release. Questions go to hello@warde.app.

ServiceNow is a trademark of ServiceNow, Inc. SailPoint, IdentityIQ and Identity Security Cloud are trademarks of SailPoint Technologies, Inc. Microsoft and Microsoft Entra are trademarks of the Microsoft group of companies.