---
title: "Sources"
canonical: "https://support.appfire.com/space/RM/3459219866/Sources"
format: markdown
---
Use the *Sources* tab (**Space settings **>** LiveRisk **>** Sources**) to connect external security and governance, risk, and compliance tools to the risk register in the current Jira space.

LiveRisk supports:

| **Provider** | **What it imports** | **Sync** |
| --- | --- | --- |
| **Wiz** | Cloud security signals | Daily or weekly |
| **Snyk** | Developer security signals | Daily or weekly |
| **Drata** | Compliance risk register | Manual import |
| **OneTrust** | Risk work items | Manual import |

Wiz and Snyk findings are imported as signals. OneTrust and Drata risks are imported as risk work items through a one-way import.

## How to connect a source

1. Click **Connect source**.
2. Choose **Wiz, Snyk,** **Drata,** or **OneTrust**.
3. Enter a **Source name** and the credentials required by the provider.

| **Provider** | **Required connection details** |
| --- | --- |
| Wiz | API URL, Token URL, Audience, Client ID, Client secret.  ([Wiz API documentation](https://docs.pro.wizconnected.com/#introduction)) |
| Snyk | API token, API base URL, API version. ([Snyk API documentation](https://docs.snyk.io/developer-tools/snyk-api/rest-api/about-the-rest-api)) |
| Drata | API key and API base URL. The default API URL is `https://public-api.drata.com`. |
| OneTrust | Hostname, API token. ([OneTrust API documentation](https://developer.onetrust.com/onetrust/reference/onetrust-api-reference)) |

4. Select **Test connection** and confirm that the connection succeeds.
5. Configure the data you want LiveRisk to import.
6. Click **Connect source**.

### Configure Wiz

Choose:

- **Sync frequency**: Daily or Weekly.
- **Signal statuses**: Open, In progress, Resolved, or Suppressed.
- **Projects**: Select the Wiz projects to include, or leave the selection empty to include all projects.

The initial ingestion starts after you connect the source.

### Configure Snyk

Choose:

- **Sync frequency**: Daily or Weekly.
- **Signal statuses**: Open, In progress, Resolved, or Suppressed.
- **Organizations**: Select the Snyk organizations to include, or leave the selection empty to include all organizations.

The initial ingestion starts after you connect the source.

### Configure Drata

The **Register scoping** step controls which Drata risk register is imported and which risk statuses to include.

Configure:

- **Risk register**: Select the Drata risk register you want to import. Each connection imports one risk register. To import another register, create another Drata source connection.
- **Risk statuses**: Select the statuses to include in the import: **Active**, **Closed**, or **Archived**. *Active* is selected by default. Leave the selection empty to import risks in any status.

Select **Connect source** to save the connection.

### Configure OneTrust

OneTrust imports risks rather than Signals.

You can optionally limit the risks imported from OneTrust by adding filters:

- **Field** — the OneTrust risk attribute to evaluate.
- **Operator** — **Equal to** or **Not equal to**.
- **Value** — the value to match.

Leave the filters empty to import all risks.

> ℹ️ OneTrust does not start importing automatically when you connect the source. After the connection is created, select **Run import** from the *Sources* table.

## Manage existing sources

The **Sources** table shows each connection, its provider, imported data, current status, configuration, and available actions.

| **Action** | **What it does** |
| --- | --- |
| **Edit source** | Updates connection details and sync/import filters. |
| **Run full ingestion** / **Run import** | Triggers a full pull now. OneTrust uses **Run import**. This action may be unavailable until the first ingestion finishes. |
| **Resync newer data** | Pulls only newer data for Wiz and Snyk. This action is disabled until the first sync completes. |
| **Delete source** | Permanently removes the connection and stored credentials. |

A source can have the following statuses:

- [INITIALIZING]  — LiveRisk is initializing the source.
- [CONNECTED] — The source is connected.
- [SYNCING] — An ingestion is in progress.
- [PARTIAL]  — The import finished, but some data could not be imported completely.
- [ERROR] — The connection or ingestion failed.

Hover over a status when additional information is available to view its details.

> ℹ️ For a [PARTIAL] OneTrust import, the tooltip identifies the affected risk keys and distinguishes between:
> ℹ️ 
> ℹ️ - risks that could not be created, and
> ℹ️ - imported risks that may be missing their treatment plans.
> ℹ️ 
> ℹ️ Review the affected risks before running the import again. Rerunning an import after a partial result may create duplicates.

### Edit a source

When you edit a source, saved credentials are not displayed. Each credential field shows **Configured** or **Not configured**.

Leave a configured credential unchanged to keep the stored value, or enter a new value to replace it.

You can select **Test connection** without re-entering the saved credentials. The test returns **Connection OK** or **Connection failed**.

> ℹ️ If LiveRisk cannot read a source's saved import filters, **Save** is disabled. This prevents the existing filters from being silently replaced with an empty configuration, which could cause more data to be imported than intended.
> ℹ️ 
> ℹ️ Delete and reconnect the source to configure its filters again.