Skip to main content
Community Hub

Crawl Cyera

TL;DR

Crawl classification metadata from Cyera to enrich assets with data sensitivity and privacy information. Extract data sensitivity classifications and security issues.

Your AI can read this via Docs MCPcurl -fsSL "https://docs.atlan.com/install-docs-mcp" | bashConnect

Configure the Atlan Cyera workflow to crawl data classification metadata from your Cyera instance and enrich assets in Atlan. After completing the prerequisite setup, you can extract data sensitivity classifications, privacy labels, and security findings. Review the order of operations for metadata enrichment workflows before starting.

Prerequisites​

Before you begin, make sure you have:

  • Created a Cyera API token and obtained your Client ID and Client Secret. If not, follow the Set up Cyera guide.
  • Generated an Atlan API token for the Cyera App to write custom metadata structures into your workspace, and to read your connections when you use automatic datastore detection. See Generate Atlan API token.
  • The required permissions to configure and run the workflow:
    • Atlan: Admin or Workflow Admin permissions
    • Cyera: API token with read access to datastores, classifications, and issues
  • Reviewed the order of operations for workflow execution.

Create crawler workflow​

Create a new Cyera crawler workflow in Atlan by selecting the Cyera App in the Atlan Marketplace, then completing the three configuration steps.

  1. In the top right of any screen, navigate to New > New Workflow.
  2. From the list of packages, select Cyera and click Setup Workflow.

Configure credentials​

Enter the Cyera credentials Atlan uses to authenticate.

  1. In the Credential section:

    • Cyera API URL: The Cyera API endpoint, pre-filled as api.cyera.io. Don't change this value unless instructed by Cyera support.
    • Client ID: Enter the Client ID from your Cyera API token. See Set up Cyera.
    • Client Secret: Enter the Client Secret from your Cyera API token.
  2. Expand Advanced Settings and enter the Atlan API Token you generated in Set up Cyera. The Cyera App uses this token to create the Cyera, CyeraIssues, and CyeraIdentities custom metadata structures in your Atlan workspace. Without it, Cyera-tagged assets in Atlan won't receive enriched custom metadata values.

  3. Select an Extraction Method:

    • Direct (default): Atlan calls Cyera using credentials stored in Atlan.
    • Self-Deployed Runtime (SDR): The runtime in your environment holds the credential and pushes metadata to Atlan. See Self-Deployed Runtime for setup requirements.
  4. Click Test Authentication to confirm connectivity to Cyera.

  5. When the test is successful, click Next.

Configure connection​

Set up the Atlan connection and specify who can manage it.

  1. Enter a Connection name that represents your Cyera environment. For example: production, cyera-prod, or analytics.

  2. To change who can manage this connection, update the users or groups listed under Connection Admins. By default, your user and all admins are included.

  3. Click Next to proceed.

Map datastores​

Map Cyera datastores to Atlan connections, configure optional settings, and run the crawler. A Cyera datastore holds the classifications; the mapping tells Atlan which of your connections or assets those classifications belong to. Nothing is enriched until at least one datastore is mapped.

Three approaches are available, and you can combine them. Manual mappings always win: any datastore you map in the repeater or the CSV field keeps that mapping, and automatic detection fills in only the rest.

Set Auto-Detect Datastore Mappings to have the app match your Cyera datastores to Atlan connections for you, instead of listing every pair by hand. This is the broadest option, and for object storage it's the only one that works.

OptionWhat happens
Off (default)No detection. Only the mappings you enter by hand are used.
Suggest (log proposed mappings only)Detection runs and writes the proposed mappings to the workflow log. Nothing is applied, and no assets change.
On (auto-apply high-confidence mappings)Detection runs and applies its high-confidence matches.

Matching compares connector type, host and account identifiers, and names. The connector-type gate is strict: a Cyera datastore is only ever compared against Atlan connections that can plausibly hold the same assets, so a Snowflake datastore is never matched to a Databricks connection however similar the names are.

Start with Suggest on your first run, read the proposed mappings in the workflow log, then switch to On once they look right.

Detection only runs when Bulk Connection Mapping is empty

If the Bulk Connection Mapping (CSV) field contains any mappings, detection is skipped entirely and only your CSV rows are used. Clear that field to let detection run.

Requires an Atlan API token

Detection reads your Atlan connections, so it needs the Atlan API Token in the credential step's Advanced Settings. Without it, detection can't run.

Supported sources

Detection covers the sources below. Cyera datastores on any other infrastructure need a manual mapping.

Cyera infrastructureMatched Atlan connector
SnowflakeSnowflake
DatabricksDatabricks
BigQueryBigQuery
RedshiftRedshift
RDSPostgres, MySQL, MariaDB, Microsoft SQL Server, Oracle, Aurora
Cloud SQL, AlloyDBCloud SQL Postgres, AlloyDB Postgres, Postgres, MySQL, Microsoft SQL Server
Azure SQL DatabaseMicrosoft SQL Server, Synapse
Azure SQL Managed Instance, SQL on Azure VMMicrosoft SQL Server
Azure Database ServerPostgres, MySQL, MariaDB
Oracle Autonomous DatabaseOracle
MongoDB Atlas clusterMongoDB
Cosmos DBAzure Cosmos DB, MongoDB
DynamoDBDynamoDB
CockroachDBPostgres
SalesforceSalesforce
Amazon S3S3
Google Cloud StorageGCS
Azure Blob Storage, Azure File ShareADLS

Map object storage​

Cyera datastores on object storage behave differently from warehouse and database datastores. An S3 bucket, a GCS bucket, or an Azure Blob or File Share container is a single asset in Atlan rather than a whole connection, so the mapping has to point at that asset:

Cyera infrastructureAtlan asset it maps to
Amazon S3S3Bucket
Google Cloud StorageGCSBucket
Azure Blob Storage, Azure File ShareADLSContainer
Object storage needs automatic detection

Auto-Detect Datastore Mappings is the only option that maps an object-storage datastore to its bucket or container. The Bulk Connection Mapping (CSV) field and the Snowflake Mapping repeater both map to a connection, and mapping an object-storage datastore that way discards the bucket the classifications belong to.

The symptom is quiet: the workflow still succeeds, but it reports zero tables and enriches nothing. If you're cataloging object storage and an apparently successful run leaves your buckets untouched, set Auto-Detect Datastore Mappings to On and clear the Bulk Connection Mapping (CSV) field.

Optional settings: To clean up legacy duplicate metadata attributes from earlier app versions, configure Legacy Metadata Cleanup. Leave as Off (default) unless advised otherwise. Set to Dry run to preview what gets removed, or Apply to delete legacy attributes.

Run preflight checks and start crawler​

  1. In the Preflight Check section, click Check to run a quick test for necessary permissions before the workflow runs. Click Show details to review the results.

  2. Choose your run option:

    • To run the crawler immediately, click Run.
    • To schedule the crawler to run on a recurring basis, click Schedule & Run and configure the schedule.

Once the crawler completes, you can view the enriched assets on Atlan's asset page.

Need help​

See also​