> ## Documentation Index
> Fetch the complete documentation index at: https://docs.apostra.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect a source

> Bring selected Google Drive, Microsoft 365, or Confluence Cloud content into your Library.

## Availability

Connected Library sources are available only in staging to approved pilot
participants. They are not generally available. Apostra evaluates the
server-side `library-external-sources` feature flag before it shows or accepts
the connection workflow; when the flag is off, no provider is advertised and
no connection action can run.

## Start a connection

An approved seller administrator opens the Library and selects a provider from
the available source connections. Apostra opens the provider's sign-in in a
secure browser handoff. Return to the Library after the provider confirms the
sign-in; Apostra verifies that handoff before it lets you choose a root. Signing
in alone does not create a source connection or import any content.

After you choose a root, Apostra shows a bounded preview of the supported and
excluded content it can see. Review the root and preview, then select **Start
indexing** to create the connection and request its first index. A preview is
not a connection, and it expires if you leave setup unfinished.

## What connecting does

A connected source is a read-only, one-way import into your Apostra Library.
After you authenticate and choose one explicit root, Apostra reads content
inside that root and creates a workspace-managed copy where the source content
is eligible for a Library destination. It never writes, moves, renames, or
deletes anything at Google, Microsoft, or Atlassian.

Choose the narrowest root that contains the material you want to use. The
source keeps its provider provenance, so you can see where an imported copy
came from.

## Choose a provider and root

* **Google Drive** — choose a folder in My Drive, a folder shared directly
  with the connected account, or a folder in a Shared Drive. Apostra traverses
  that folder and its descendants. It observes folders and downloadable files,
  and can export Google Docs, Google Slides, and Google Drawings in the
  supported import formats.
* **Microsoft 365** — choose a folder in OneDrive for Business or a folder in
  a SharePoint Online document library. Apostra follows the selected folder's
  descendants and observes folders and supported files. Personal Microsoft
  accounts are not supported.
* **Confluence Cloud** — choose a space or a page subtree in one Confluence
  Cloud site. Apostra observes current pages in that boundary and supported
  attachments on those pages. A page-tree root includes the chosen page and
  its descendants.

## Permissions requested

The connection asks only for read authority. The scopes also let Apostra keep
the background connection tied to the account that granted it.

* **Google Drive:** `drive.readonly` (`https://www.googleapis.com/auth/drive.readonly`)
  authorises Apostra to view and download Drive content the connected Google
  account can access, without changing it. That grant is broader than the
  selected folder; Apostra imports only the folder root you choose and its
  descendants.
* **Microsoft 365:** `Sites.Read.All` authorises delegated read access to
  SharePoint and OneDrive for Business content the signed-in work account can
  access, including content outside the root you select. Apostra imports only
  the selected root and its descendants. `User.Read`, `email`, and `profile`
  let Microsoft identify the signed-in work account for the authenticated
  connection. Apostra does not request write scopes.
* **Confluence Cloud:** `offline_access` keeps the read-only connection
  available for background sync; `read:me` identifies the Atlassian account;
  `read:space:confluence`, `read:page:confluence`, and
  `read:hierarchical-content:confluence` read spaces and page trees;
  `read:attachment:confluence` reads attachments; and
  `read:content-details:confluence` reads their content details. None grants
  write access. These read scopes can authorise content the connected account
  can access beyond the selected space or page subtree; Apostra imports only
  the root you choose and its descendants.

## Where imported content goes

Each eligible file is checked against the destination policy for the source.
PDF, PowerPoint (`.pptx`), and Excel (`.xlsx`) content can become Library
**Material** when the Material destination is allowed. JPEG and PNG content can
become advertiser-scoped **Creative Assets** when the Creative Assets
destination is allowed and the source has advertiser authority. Other detected
file types are not imported to either destination.

The current limits are:

* One item can be at most 100 MB.
* A sync pass reads at most 100 items for one connection and up to 250 MB for
  that connection. The worker shares each pass across customers, with up to two
  connections and 200 items per customer.
* Google-native exports have an additional 10 MB export limit.
* Google Drive scans at most 256 folders and 64 levels below the selected
  folder. Microsoft folder ancestry is bounded to 64 levels.

An item that is unsupported, too large, unreadable, or outside its destination
policy is skipped; it does not create a partial destination copy.

## Sync timing and changes

Apostra checks due connected sources every minute. It uses the provider's
change cursor between full checks and performs a full reconciliation at least
every 24 hours. A provider notification can wake the worker sooner, but it is
not the source of truth.

* **Rename or move inside the selected root:** Apostra keeps tracking the same
  provider item and refreshes its source observation and provenance.
* **Move outside the selected root or delete at the provider:** Apostra stops
  treating the item as available from that source. Previously imported
  workspace copies are kept with their source provenance for 30 days after
  provider access ends, then removed by policy.
* **Permission loss or expired credentials:** sync stops and the source asks
  you to reconnect. Previously imported workspace copies remain available with
  provenance for 30 days after access ends, then removed by policy.
* **Disconnect:** sync stops and Apostra removes only its local source
  connection; it never deletes provider files. Previously imported workspace
  copies remain with provenance for 30 days after disconnect, then removed by
  policy.

The 30-day policy removal purges the retained workspace copy's stored content;
it does not delete the provider file. Source provenance remains visible while a
retained copy is available. In this pilot, the connected-source controls do
not offer an immediate-delete action for a retained copy or a separate
provenance-deletion action. A legal hold pauses the scheduled policy removal.

Reconnect or select a new root when the provider account, its access, or the
source boundary changes. Disconnecting a Google Drive Library source does not
disconnect the separate Google Drive file-picker connection that shares the
same provider account.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.