workspace.{table}. It is a
safe projection of control-plane metadata, not a copy in the lake.
Reads see the configuration from the most recent catalog build. A
configuration edit invalidates the cached catalog, so the next read
reflects the new value.
Provider configuration tables (available)
Each connected provider gets its configuration as tables, one row per connection, keyed bytenant_connector_id. Column names follow the
provider’s configuration schema, lowercased; when the schema changes,
the table changes with it.
Fields marked secret in a provider’s schema (private keys, tokens,
client secrets) are never columns in these tables. Lists of objects in a
configuration become child tables named
{table}__{field}, joined on
parent_pk and ordinal.
Which users is Google ingestion limited to?
Planned tables
These tables are specified but not yet available:
Secrets, tokens, sessions, and credential material are not in this pool.
A common join is workspace members against a directory tap:
workspace.users.email and provider person-email columns are the same
scalar (Contact.Email), so that join is valid. Person-email columns
are marked x-transformPersonEmail on the tap schema; see
How taps project into tables.
Google Workspace users are at
providers.google.users.
Language-specific Flight SQL clients are on
Querying the lake.