Write access and operations
Separate destination writes from governed source mutations
What a writable endpoint does
A destination endpoint sends pipeline output to a selected external target. A governed source-write operation changes records in a supported transactional source. These are distinct execution paths.
Plugin used
Destinations use installed write capabilities, such as Postgres, MongoDB, S3 or a custom writer. Durable source mutations and maintenance currently use Iceberg. Install Iceberg for additional connection details; its endpoint example includes installation inline.
What you need
Choose a dedicated test target, the matching capability and a small known input. Confirm external write privileges, applicable policy, caller permissions and separately required approvals. For governed source writes, also confirm workspace settings, endpoint policy, actor grants and the expected snapshot.
Destination endpoints
A destination selects an installed write capability, write contract and concrete output target. Choose only supported write modes. Postgres keyed mutations require real database primary keys. MongoDB currently implements append/replace, not upsert. S3 appends Parquet objects, not rows. Catalog schemas currently advertise some modes that differ from Postgres/MongoDB runtime behavior; their setup pages document that limitation. Do not assume overwrite is an implemented replacement alias. Test in a dedicated target and inspect external results and run evidence.
A saved endpoint is not proof of authorization. Follow the applicable write policy, caller permissions and separately required approvals.
Durable source writes
Workspace source-write settings, endpoint policy and actor grants govern supported source mutations. The current durable source-write and governed action paths require the Iceberg plugin; a generic Postgres, MongoDB or custom destination writer does not inherit snapshot conflict detection or recovery.
Use a current source snapshot, approved policy and granted actor. Inspect the operation receipt and resulting snapshot. Follow the reported operation state for recovery rather than retrying a mutation blindly.
See source-write execution, policy binding and grants
Maintenance
Iceberg endpoint operations expose supported health, history and maintenance schedules. Compaction, snapshot expiration and orphan discovery require the applicable policy and permissions. Inspect retained references before expiration. Orphan discovery does not itself delete objects.
See maintenance listing and scheduling
Upload operations
File version selection and ingestion are separate. Use the dataset upload guide rather than editing internal managed targets.