Linking Drata as a source
Let AI connect your sources for you
Skip the manual setup — run this in your project and the wizard auto-detects your databases and APIs and connects them to PostHog.

This source is currently in alpha. The interface and available tables may change.
The Drata connector syncs workspaces, users, personnel, and more into the PostHog data warehouse, so you can analyze them alongside your product data.
Prerequisites
Credentials that can read the data you want to sync. PostHog only reads data, so read access is enough.
Adding a data source
- In PostHog, go to the Sources tab of the data pipeline section.
- Click + New source and click Link next to this source.
- Enter your credentials (see Configuration below) and click Next.
- Select the tables you want to sync, choose a sync method and frequency, then click Import.
Once the syncs are complete, you can start querying this data in PostHog.
Enter your Drata API key to pull your compliance data.
You can create an API key under Settings → API keys in Drata. A key with read scopes is sufficient; pick the region that matches your Drata account.
You'll be asked for:
- API key
- Drata region: choose between North America, Europe and Asia-Pacific.
Sync modes
Each table can be synced in one of several modes, depending on what the source supports:
- Webhook (when available) – the source pushes changes to PostHog in real time. Fastest freshness, lowest ongoing cost, and the only mode that reliably captures updates and deletes.
- Incremental – only new or updated rows are synced on each run, using a cursor field (such as an
updated_attimestamp). Cheaper than a full refresh, but deletes aren't captured. - Append only – new rows are appended using a cursor field; existing rows are never updated. Ideal for immutable, append-only tables like event logs.
- Full refresh – the whole table is reloaded on every sync. Use it when a table has no reliable cursor or when you need deletions reflected.
See sync methods for a full explanation of how each mode works and how to choose between them.
All Drata tables are full refresh. Each sync replaces the contents of the table.
Configuration
| Option | Type | Required |
|---|---|---|
API key | password | Yes |
Drata region | select | Yes |
Supported tables
| Table | Description | Sync method | Incremental field | Primary key |
|---|---|---|---|---|
workspaces | Workspaces (products) in your Drata account. Controls, monitoring tests, evidence, and frameworks are scoped to a workspace. | Full refresh | — | id |
users | User accounts in your Drata organization. | Full refresh | — | id |
user_assigned_policies | Policy versions assigned to each user and whether they accepted them. This is the policy attestation record auditors ask for. | Full refresh | — | userId, id |
personnel | Personnel records tracked for compliance, including employment status and per-person compliance checks (security training, background checks, MDM). | Full refresh | — | id |
devices | Devices monitored for compliance (encryption, firewall, antivirus, screen lock) across MDM and agent sources. | Full refresh | — | id |
assets | Assets in your Drata asset inventory — physical and virtual assets discovered from connections or added manually. | Full refresh | — | id |
vendors | Vendors tracked in Drata's vendor risk management, with risk, impact, and review status. | Full refresh | — | id |
policies | Policies in your Drata account, including version, approval, and renewal state. | Full refresh | — | id |
events | Audit-trail events recording activity across your Drata account (policy changes, vendor updates, connection activity, and more). | Incremental, Full refresh | createdAt | id |
controls | Controls in each workspace, with readiness, monitoring, and framework mappings. | Full refresh | — | workspaceId, id |
control_requirements | The requirements each control satisfies, one row per control-requirement pair. This is the junction that makes framework coverage queryable: join it to controls and framework_requirements to see which requirements a control covers and which requirements no control covers yet. | Full refresh | — | workspaceId, controlId, id |
control_owners | The users who own each control, one row per control-owner pair. Join it to controls to see who is accountable for a control, and to users to group ownership by person. | Full refresh | — | workspaceId, controlId, id |
monitoring_tests | Automated monitoring tests in each workspace, with pass/fail status and check state. | Full refresh | — | workspaceId, id |
monitoring_test_failures | Findings behind each failing monitoring test: one row per cloud resource that failed a test, including findings excluded from the test result. | Full refresh | — | workspaceId, monitoringTestId, id |
tasks | Remediation tasks in each workspace, with owner, status, and due date. This is the compliance work queue. | Full refresh | — | workspaceId, id |
evidence_library | Evidence library items in each workspace, tracking artifacts collected for audits and their renewal status. | Full refresh | — | workspaceId, id |
audits | Audit engagements run in each workspace, internal or with an external auditor. An audit scopes a framework over a date range and is what audit_requests hang off. | Full refresh | — | workspaceId, id |
audit_requests | Evidence requests raised by an auditor during an audit, with their fulfillment status. This is the audit work queue: what the auditor asked for and whether it has been answered. | Full refresh | — | workspaceId, auditId, id |
frameworks | Compliance frameworks enabled in each workspace (SOC 2, ISO 27001, HIPAA, ...), with readiness counts. | Full refresh | — | workspaceId, id |
framework_requirements | The requirement catalogue behind each framework enabled in a workspace, so framework rows resolve to the individual requirements they are made of. | Full refresh | — | workspaceId, id |
risk_registers | Risk registers grouping the risks you track. Requires Drata's Risk Management Pro feature. | Full refresh | — | id |
risks | Risks in each risk register, with scoring and treatment plans. Requires Drata's Risk Management Pro feature. | Full refresh | — | riskRegisterId, id |
Troubleshooting
- If the connection fails with an authorization error, the API key is wrong, expired, or has been revoked. Create a new one, then reconnect the source.
- If a table syncs no rows, the credential may not have access to that data. Check its permissions, then reconnect the source.
If your sync is failing or data looks wrong, see the Data warehouse troubleshooting guide. If that doesn't help, contact support – we're happy to help.