Setting Up a File Feed Source of Truth
A file feed sets an application's source of truth to a file that Ploy imports from a SharePoint or Google Drive folder. Ploy checks the folder every hour and imports the newest matching file when it changes, so a report you export on a schedule keeps the application's access list current without a direct integration.
For a one-time import, you do not need a feed: use the Import users with the import wizard flow on the application's access list to upload a .csv, .xls, .xlsx, or .xlsm file directly.
Before you start
A connected provider. The feed watches a folder in SharePoint/OneDrive or Google Drive. Connect the provider under the File feeds tab in your integrations settings before setting up the feed.
A folder and file. Put the access list in the folder you want Ploy to watch. The feed always imports the newest file that matches your file name pattern.
An import profile. The feed applies a saved import profile to map the file's columns to Ploy's fields. If you have not imported users on this application before, run Import users with the import wizard once and save the mapping as a profile.
Set up the feed
Open the application's page in Ploy (app.joinploy.com, under Resources).
In the Source of truth section, click Add a new source.
Select File feed.
Choose the provider: SharePoint or Google Drive.
Paste the Folder link for the folder Ploy should watch.
Enter the File name or pattern, for example
access_*.csv. An exact name also works; the newest matching file wins.Select the Import profile that maps the file's columns. Saving the feed requires a profile.
Optionally enable Revoke access that is not in the file (see below).
Click Test to preview the folder. The preview shows the folder name, how many files match, and the newest file with its modified time and size.
Click Save.
The saved feed appears on the Source of truth card with the file pattern, folder, and a status badge.
The import profile must include a static Identity Integration value. If it does not, Ploy refuses to save the feed and asks you to open Import users on the application, set Identity Integration, and save the profile.
What the file must contain
The import profile maps the file's columns to Ploy's import fields, such as email, name, external ID, and access dates. For an application (resource) import, each person's row needs a valid email; Ploy cannot match a person to existing access from an external ID alone. Rows that lack a usable email are rejected with the error Email is required to match an existing user.
Revoke access that is not in the file
Enable Revoke access that is not in the file to make the feed a definitive list. On each import, Ploy revokes existing access that the file does not name, then asserts the access the file names. Without this option, the feed adds and updates access but never removes anything.
The revoke applies to access Ploy knows about for this application. Check that the file is a complete list of who should have access before enabling it.
How the feed runs
Ploy checks the folder every hour and imports the newest matching file when it changes. If the file has not changed, the check records nothing and no import runs.
The feed status badge shows one of:
Status | Meaning |
|---|---|
Feed ok | The last check and import succeeded. |
File missing | No file in the folder matches the pattern. |
Held | The newest file looks like an incomplete export, so Ploy has not applied it (see below). |
Failed | The last check or import could not complete. |
When a feed is held
If the feed is a definitive list and the newest file's valid row count drops below half of the last import's count (or below half of the application's current active access count for a first import), Ploy holds the import and leaves access unchanged. The status reason spells out the mismatch, for example: report.csv names 12 people; the last import named 40. Ploy has not applied it.
If the small file is genuinely correct, click Import anyway on the feed to bypass the guard and import it. Sync now queues a fresh check of the folder at any time.
What happens after an import
Users named by the file appear under the application's Active Access tab, and their access rows show the file feed as the source. Active access that the file did not establish stays under Shadow Access. With Revoke access that is not in the file enabled, access absent from the file is revoked. For the full picture of source of truth types, see Setting Up a Source of Truth.