Source mapping · Integration readiness

Source Mapping and Integration Readiness

Named systems describe research scope and proposed retrieval paths, not generally available connectors. Each source needs an identifier map, an approved access path and evidence of what was searched.

Read the status before the logo

A named source is not an available integration.

Every status describes the current evidence and proposed retrieval path. It does not promise general availability, instant setup or production readiness.

Customer-produced export

Evidence supplied under agreement

The customer produces a controlled export or file package. A transfer channel and deletion plan must be agreed before real data moves.

Candidate for pilot mapping

Proposed configuration with the customer

Identifiers, fields, access and queries still need scoped validation. This is not a one-click integration.

Under evaluation

Research, not availability

Trace is evaluating data relevance, API constraints and demand. No implementation date is promised.

Not currently supported

No accepted retrieval path

Interview, technical and security evidence are required before the status changes.

Current truth: Trace has not released automated system access. The directory below records proposed paths and current limits; it is not an integration marketplace.

Source directory

What Trace would look for—and the limits around it.

Open a source to see expected data, access approach, likely request relevance and the limitation that must travel with the result.

Identity

Profiles and authentication metadata that may support identity matching and source discovery.

Auth0 User identity and authentication metadata. Under evaluation
Proposed access path

Proposed scoped Management API access.

Likely request relevance

Identity support and access evidence.

Readiness limit

Not currently offered as an automated connector.

Clerk User profiles and authentication metadata. Under evaluation
Proposed access path

Proposed scoped backend API access.

Likely request relevance

Identity support and access evidence.

Readiness limit

Not currently offered as an automated connector.

Billing

Customer, subscription, invoice and payment metadata with retention questions kept visible.

Stripe Customer, subscription, invoice and payment metadata relevant to the requester. Candidate for pilot mapping
Proposed access path

Restricted API key or a controlled export.

Likely request relevance

Access and portability evidence; deletion depends on lawful retention decisions.

Readiness limit

Trace would flag retention questions for authorised review.

Open the source-specific workflow →

Support & CRM

Contacts, tickets and conversations that often sit outside the primary product database.

Intercom Contacts, conversations and support metadata. Supported through customer-produced export
Proposed access path

Customer-produced export through an agreed channel.

Likely request relevance

Access and correction evidence.

Readiness limit

No direct or automated retrieval is claimed.

HubSpot Contacts, companies, tickets and consent-related properties in scope. Supported through customer-produced export
Proposed access path

Customer-produced export through an agreed channel.

Likely request relevance

Access, correction and deletion evidence where applicable.

Readiness limit

Portal-specific source selection remains customer-owned.

Zendesk User profiles, tickets, comments and attachments. Not currently supported
Proposed access path

No accepted retrieval path is currently claimed.

Likely request relevance

Access and correction evidence may be relevant.

Readiness limit

Interview and technical evidence are required before this status changes.

Data

Application records and stored objects identified through the customer’s schema and request scope.

Supabase Auth profiles, application tables and storage references selected during scoping. Candidate for pilot mapping
Proposed access path

Customer-approved, least-privilege access or a controlled export.

Likely request relevance

Access, portability and deletion evidence where applicable.

Readiness limit

No one-click connector is claimed. Any retrieval path is scoped and tested with the customer.

Open the source-specific workflow →
Firebase Authentication records, Firestore collections and storage references in agreed scope. Candidate for pilot mapping
Proposed access path

Scoped service access or customer-generated export.

Likely request relevance

Access, portability and deletion evidence where applicable.

Readiness limit

Collection structure and security rules must be mapped with the customer.

Open the source-specific workflow →
Postgres Agreed tables and related requester records. Candidate for pilot mapping
Proposed access path

Read-only database role, replica, query runner or export.

Likely request relevance

Depends on schema and controller instructions.

Readiness limit

Custom queries require customer validation.

S3-compatible storage Objects linked to the requester through agreed identifiers. Supported through customer-produced export
Proposed access path

Scoped manifest or customer-produced package.

Likely request relevance

Access and portability evidence.

Readiness limit

Broad bucket access is not a default.

Custom

Controlled evidence paths for systems without a named integration approach.

Secure export Customer-selected evidence files. Supported through customer-produced export
Proposed access path

Agreed secure transfer channel.

Likely request relevance

Depends on request type and the evidence the customer can validly supply.

Readiness limit

Controlled exports are a proposed starting point, subject to an agreed data-handling boundary.

Read-only API Customer-defined endpoints and response fields. Candidate for pilot mapping
Proposed access path

Least-privilege credentials with revocation controls.

Likely request relevance

Defined during scoping.

Readiness limit

Subject to technical and security review.

Access strategy

The first question is not “Can we connect?”

It is “What is the smallest, revocable path that can produce useful evidence under the agreed scope?”

  1. 01

    Can the customer produce a controlled export?

    For a first case, an export may reduce standing access and speed up validation. File transfer, integrity checks, storage and deletion still need an agreed method.

  2. 02

    Would a narrow read-only role be safer?

    Where repeated retrieval is justified, the design should restrict systems, tables, objects, endpoints and operations. “Read-only” still requires security review.

  3. 03

    Can the customer run the retrieval?

    A reviewed query, manifest or API export can keep credentials and execution inside the customer environment while preserving a documented evidence path.

  4. 04

    What remains manual or unknown?

    Unmapped tools, inconsistent identifiers and access failures become case warnings. Trace should not infer completeness from the sources it happened to reach.

Readiness source map

What implementation needs to establish.

The source map is the operational contract between the request and the evidence. It should be understandable without knowing the customer’s entire architecture.

01

System owner

Who can approve access, validate a query and explain the source.

02

Requester identifiers

Which stable identifiers link the person across systems—and where matching may fail.

03

Fields and objects

The in-scope records, attachments and metadata, plus known exclusions.

04

Access and revocation

How evidence can be retrieved, who grants access and how it is removed.

05

Retention questions

Where deletion requests may conflict with documented legal or operational retention.

06

Completion evidence

What proves the source was checked and which gaps must be disclosed to the reviewer.

Do not send credentials or personal dataShare system categories, scale and the current workflow.
Review the Readiness Sprint

Founding design partners

Your first useful integration may be a better source map.

The proposed Readiness Sprint maps up to three systems and rehearses one synthetic request. No production integration is implied.