Read-only access
Why Uptend cannot write to a database you connect, even if the role you give it could.
You're handing Uptend a connection to a database you run in production. The guarantee that we only read from it isn't a promise in a contract — it's something your own database enforces.
How it's enforced
Every statement Uptend sends runs inside a PostgreSQL read-only transaction, and that transaction is always rolled back rather than committed.
This matters because of where the enforcement lives. A read-only transaction is refused by PostgreSQL itself, with error 25006, before any write reaches your data. It doesn't depend on Uptend behaving correctly, and it doesn't depend on the permissions of the role you gave us. A write would be rejected even if the credential belonged to a superuser.
On top of that, the connector Uptend uses to talk to your database has no write path in it at all. There's no feature behind a flag, no admin override, and no support tool that can send one.
You'll see this stated on the source's page, next to the connection details.
Give Uptend less than it asks for
Uptend works with whatever role you give it. But you can hand it a role that can only run SELECT, and there's no reason not to.
On the connect dialog and on each source's page, expand Show read-only role setup for a ready-to-run script:
CREATE ROLE uptend_readonly LOGIN PASSWORD 'choose-a-strong-password';
GRANT CONNECT ON DATABASE your_database TO uptend_readonly;
GRANT USAGE ON SCHEMA public TO uptend_readonly;
GRANT SELECT ON ALL TABLES IN SCHEMA public TO uptend_readonly;
ALTER DEFAULT PRIVILEGES IN SCHEMA public
GRANT SELECT ON TABLES TO uptend_readonly;The last statement is the one people forget: without it, tables you create later won't be readable and syncs will quietly miss them.
Run it against your database, then use uptend_readonly and its password in the connection string.
The access badge
When Uptend tests a connection, it checks what the credential you gave it can actually do, and shows the answer on the source:
| Badge | Meaning |
|---|---|
| Read-only role | The credential can only read. Nothing more to do. |
| Role can write | The credential has write permission somewhere. |
| Superuser role | The credential is a superuser. |
| Unknown | Uptend couldn't determine the permissions. |
A source showing Role can write or Superuser role carries a warning on its page. It's a nudge, not a fault: Uptend still can't write, and the source works exactly the same. The warning exists so you can see you've handed over more than we need and tighten it if you'd rather.
Tightening the role is never required. If it were, the read-only guarantee would depend on you configuring something — and that's precisely what it's designed not to depend on.
What Uptend reads
Uptend reads the tables you map to profile types and their properties. It doesn't crawl your whole database, and it doesn't copy tables you haven't pointed it at.
Values that arrive are stored against profiles, where every property shows a line saying which source produced it and when.