Support

Agent, connector and control-plane error codes

Error codes are fixed, value-free identifiers: they never contain source values, host names or credentials, so they are safe to search for and to quote to support.

Showing 289 of 289 codes.

Agent codes

Job codes appear on the failed job in the console and in the agent’s JSON logs. Some job codes come straight from an engine validation or certification gate; the job’s evidence names the gate.

AGENT_CONFIG_INVALID — Agent configuration invalid

The agent's local configuration or state files are invalid.

What to do: Run `datanivra-agent check` to see which setting is rejected, fix the DATANIVRA_AGENT_* variable and restart.

AGENT_ERROR — Unclassified agent error

A generic agent failure without a more specific code.

What to do: Check the agent's JSON logs around the time of the failure; if it repeats, contact support with the job id and the code.

AGENT_KEY_INVALID — Agent key invalid

The agent's private key file is not a valid Ed25519 key.

What to do: Restore the key from the agent's state volume backup, or revoke the agent in the console and enroll a new one.

AGENT_KEY_NOT_CREATED — Agent key not created yet

The doctor found no private key: the agent generates it (mode 0600) the first time it starts.

What to do: Nothing to do before the first start; run the doctor again after the agent has started once.

Operator runbook: docs/runbooks/agent-doctor.md

AGENT_KEY_PERMISSIONS — Agent key file too open

The private key file is readable by users other than the agent (it must be mode 0600).

What to do: Run `chmod 600` on the key file in the state directory and make sure it is owned by the agent user.

AGENT_NOT_ENROLLED — Agent not enrolled

The agent tried to call the control plane before enrolling.

What to do: Create an enrollment token in the console, provide it through DATANIVRA_AGENT_ENROLLMENT_TOKEN_REF and run `datanivra-agent enroll` (or `run`).

AGENT_REVOKED — Agent revoked

The control plane revoked this agent; it stops all work and publishes nothing.

What to do: If the revocation was intended, uninstall the agent. Otherwise enroll a new agent with a fresh enrollment token.

Operator runbook: docs/runbooks/agent-offline.md

AGENT_VERSION_INVALID — Agent version not comparable

The agent version or the control plane's minimum agent version is not a semantic version, so support cannot be confirmed.

What to do: Use an official agent release image; if it persists, contact support with both version strings.

Operator runbook: docs/runbooks/agent-doctor.md

AGENT_VERSION_UNSUPPORTED — Agent version below the minimum

The control plane requires a newer agent than the one running (learnt from the last heartbeat).

What to do: Upgrade the agent to a release at or above the minimum shown, pinned by digest (see /downloads).

Operator runbook: docs/runbooks/agent-doctor.md

ALREADY_ENROLLED — Agent already enrolled

The agent already has an identity, so its one-time enrollment token is no longer used or checked.

What to do: Nothing to do. You may delete the enrollment token secret.

Operator runbook: docs/runbooks/agent-doctor.md

CA_BUNDLE_UNREADABLE — CA bundle unreadable

DATANIVRA_AGENT_CA_BUNDLE points to a file that is missing or is not a valid PEM bundle.

What to do: Mount the corporate CA bundle into the agent and point DATANIVRA_AGENT_CA_BUNDLE at it.

Operator runbook: docs/runbooks/agent-doctor.md

CERTIFICATION_FAILED — Certification failed

One or more certification gates failed, so the dataset version cannot be published or provisioned.

What to do: Open the job's evidence in the console to see which gate failed (for example an uncovered sensitive column), fix the policy and request a new version.

CERTIFICATION_POLICY_CONTENT_MISSING — Certification policy content missing

The job did not carry the certification policy content it referenced.

What to do: Re-submit the request; if it repeats, check that the certification policy version is approved.

Operator runbook: docs/runbooks/expired-policy.md

CLASSIFICATION_POLICY_CONTENT_MISSING — Classification policy content missing

The job did not carry the classification policy content it referenced.

What to do: Re-run discovery; if it repeats, check that an approved classification policy exists.

Operator runbook: docs/runbooks/expired-policy.md

CLOCK_REFERENCE_UNAVAILABLE — No control-plane time to compare

The clock check had no control-plane time: the health check did not answer and no heartbeat has been acknowledged yet.

What to do: Fix the control-plane checks first, or run the doctor again after the agent has sent a heartbeat.

Operator runbook: docs/runbooks/agent-doctor.md

CLOCK_SKEW — Clock skew

The agent's clock differs from the control plane's by more than 30 seconds (a failure above clock_skew_tolerance_seconds). Command expiry and lease checks use the local clock.

What to do: Enable NTP time synchronisation on the agent host or Kubernetes nodes.

Operator runbook: docs/runbooks/agent-doctor.md

COMMAND_EXPIRED — Command expired

A leased command reached the agent after its validity window.

What to do: Usually caused by a stopped or slow agent. Check agent health and clock synchronisation, then retry.

Operator runbook: docs/runbooks/agent-offline.md

COMMAND_INVALID — Command invalid

A leased command failed local validation (for example a missing job id).

What to do: Retry the request. If it repeats, contact support with the job id.

COMMAND_NOT_EXECUTABLE — Command not executable

The agent received a command type that is not a job.

What to do: Upgrade the agent to the release that matches your control plane.

COMMAND_REJECTED — Command rejected

A leased command failed local validation and was refused (fail closed).

What to do: Check the job's error details in the console; upgrade the agent if it is older than the control plane.

CONNECTOR_INVALID — Connector plugin invalid

A connector factory returned an object that is not a connector.

What to do: Remove or fix the connector plugin installed in your custom agent image.

CONNECTOR_KIND_MISMATCH — Connector kind mismatch

The --connector kind given to the doctor differs from the kind declared in the source connection document.

What to do: Pass the kind the connection document declares, or fix the document's kind field.

Operator runbook: docs/runbooks/agent-doctor.md

CONNECTORS_NOT_CONFIGURED — No connectors configured

The agent has no connector factory configured.

What to do: Use the standard agent image, which registers the built-in connectors, or fix a customised image.

CONTROL_PLANE_DNS_FAILED — Control-plane host does not resolve

The host name of DATANIVRA_AGENT_CONTROL_PLANE_URL could not be resolved from the agent's network.

What to do: Check the URL and the agent's DNS; allow resolution of the control-plane host (or configure HTTPS_PROXY).

Operator runbook: docs/runbooks/agent-doctor.md

CONTROL_PLANE_PORT_BLOCKED — Outbound port blocked

A TCP connection from the agent to the control plane's port (443 by default) could not be opened.

What to do: Allow outbound HTTPS from the agent network to the control-plane host, or configure HTTPS_PROXY.

Operator runbook: docs/runbooks/agent-doctor.md

CONTROL_PLANE_UNAVAILABLE — Control plane unreachable

The agent could not reach the control plane or earlier reports are still queued. Reports are retried from the local outbox.

What to do: Check outbound HTTPS (443) from the agent host, proxy settings and ca_bundle. The agent keeps retrying.

Operator runbook: docs/runbooks/control-plane-unavailable.md

CONTROL_PLANE_UNHEALTHY — Control plane unhealthy

The control plane answered its liveness endpoint with a non-200 status.

What to do: Retry later and check the status page; a 3xx answer means the URL is wrong (the agent never follows redirects).

Operator runbook: docs/runbooks/agent-doctor.md

DANGLING_REFERENCES — Subset not referentially intact

The distributed subset left references pointing at rows that were not included.

What to do: Review the subset definition's relationships (add the missing relationship or include the parent table) and run the job again.

DATASET_INTEGRITY_FAILED — Dataset integrity check failed

A published dataset file or its evidence is missing or does not match the manifest.

What to do: Treat the version as unusable: request a new version. Investigate who changed files in the datasets directory.

Operator runbook: docs/runbooks/corrupt-manifest.md

DATASET_NOT_ACCEPTED — Dataset not accepted

The control plane never accepted this dataset version, so it cannot be provisioned.

What to do: Request a new version and check that the certification report was delivered.

Operator runbook: docs/runbooks/partial-evidence-upload.md

DATASET_NOT_PROVISIONABLE — Dataset not provisionable

Only certified versions can be provisioned; this version is not certified.

What to do: Certify a new version first. Failed or revoked versions never provision.

Operator runbook: docs/runbooks/revoked-dataset.md

DATASET_NOT_PUBLISHED_LOCALLY — Dataset not on this agent

The dataset version is not published on the agent asked to provision it.

What to do: Provision from the agent that built the version, or rebuild it on this agent.

DATASET_REVOKED — Dataset revoked

The dataset version was revoked, so it cannot be used.

What to do: Request a new version.

Operator runbook: docs/runbooks/revoked-dataset.md

DATASET_VERSION_EXISTS — Dataset version already exists

Dataset versions are immutable; this version was already published.

What to do: Request a new version instead of rebuilding an existing one.

Operator runbook: docs/runbooks/duplicate-refresh.md

DATASETS_DIR_NOT_EGRESS_SAFE — Datasets directory path unsafe

The configured datasets directory path would itself be flagged by the egress guard if reported.

What to do: Choose a datasets directory whose path does not contain personal or data-derived names.

DEPENDENCY_FAILED — Check skipped

The doctor skipped this check because a check it depends on failed or could not run.

What to do: Fix the earlier failed check and run the doctor again.

Operator runbook: docs/runbooks/agent-doctor.md

DEPROVISION_INCOMPLETE — Deprovisioning incomplete

Some target environments could not be cleaned up.

What to do: Check target connectivity and permissions, then retry deprovisioning.

Operator runbook: docs/runbooks/target-unavailable.md

DISTRIBUTED_EXECUTION_UNAVAILABLE — Distributed execution unavailable

The Spark backend is configured but not installed in this agent image.

What to do: Install the distributed execution extra in your agent image, or switch back to the local backend.

DISTRIBUTED_TYPE_MISMATCH — Distributed column type changed

A column's type changed during distributed processing.

What to do: Check for schema drift in the source and re-run discovery before the job.

Operator runbook: docs/runbooks/schema-drift.md

EGRESS_BLOCKED — Report blocked by EgressGuard

The agent's EgressGuard refused to send a message because it looked like it could contain data values. Nothing was sent.

What to do: Inspect the local log with `datanivra-agent violations` (codes and hashes only) and follow the egress-violation runbook.

Operator runbook: docs/runbooks/egress-violation.md

ENGINE_ADAPTER_INVALID — Engine adapter invalid

The configured engine adapter failed to build or does not implement the engine interface.

What to do: Reset DATANIVRA_AGENT_ENGINE_ADAPTER to its default or fix the custom adapter.

ENGINE_ADAPTER_UNAVAILABLE — Engine adapter unavailable

The configured engine adapter module could not be loaded.

What to do: Use the standard agent image or install the adapter module you configured.

ENGINE_OUTPUT_INVALID — Engine output invalid

A stage output table path is missing or outside its stage directory.

What to do: Retry the job; if it repeats, keep the failed workspace (keep_failed_workspaces) and contact support with the code.

Operator runbook: docs/runbooks/masking-crash.md

ENGINE_OUTPUT_OUTSIDE_STAGE — Engine output outside stage

A stage wrote its output somewhere other than its own stage directory.

What to do: Retry; if it repeats, contact support with the job id.

Operator runbook: docs/runbooks/masking-crash.md

ENGINE_STAGE_FAILED — Engine stage failed

An engine stage (discover, subset, mask, synthesize, validate, certify) failed without a more specific code.

What to do: Look at the job step that failed in the console and retry. Keep the failed workspace for local forensics if needed.

Operator runbook: docs/runbooks/masking-crash.md

ENROLLMENT_TOKEN_REF_MISSING — Enrollment token reference missing

The agent needs to enroll but no enrollment token reference is configured.

What to do: Set DATANIVRA_AGENT_ENROLLMENT_TOKEN_REF to a secret reference (for example env://DATANIVRA_ENROLLMENT_TOKEN) holding a fresh token.

FINDING_REVIEWS_CHECKSUM_MISMATCH — Finding reviews checksum mismatch

The reviewed findings attached to a job do not match their checksum.

What to do: Re-submit the request so the control plane attaches a consistent snapshot.

HTTP_* — Control plane HTTP status

The control plane answered with the given HTTP status. 429/502/503/504 are retried from the outbox.

What to do: For 4xx statuses other than 429, check agent version compatibility; for 5xx, wait and let the agent retry.

HTTP_429 — Control plane rate limit (HTTP 429)

The control plane asked the agent to slow down. Reports are retried from the outbox.

What to do: No action normally needed. If it persists, reduce concurrent jobs on the agent.

HTTP_502 — Bad gateway (HTTP 502)

A proxy or gateway between the agent and the control plane failed. Reports are retried.

What to do: Check any outbound proxy; the agent retries automatically.

Operator runbook: docs/runbooks/control-plane-unavailable.md

HTTP_503 — Service unavailable (HTTP 503)

The control plane was temporarily unavailable. Reports are retried.

What to do: Wait and let the agent retry; check the control plane's health if it persists.

Operator runbook: docs/runbooks/control-plane-unavailable.md

HTTP_504 — Gateway timeout (HTTP 504)

A proxy or gateway timed out. Reports are retried.

What to do: Check proxy timeouts; the agent retries automatically.

Operator runbook: docs/runbooks/control-plane-unavailable.md

IDENTITY_GRAPH_SPARK_UNSUPPORTED — Identity links need the local engine

The dataset job carries approved cross-system identity links, which the Spark execution backend does not apply yet; the job stopped instead of producing unlinked data.

What to do: Run the job on the local engine backend, or remove the identity links from this dataset request.

INDUSTRY_PACK_* — Industry pack unusable

An installed industry pack reported a problem; the part after INDUSTRY_PACK_ is the pack's own reason code.

What to do: Check the pack version installed in the agent image and its compatibility with your policy.

INDUSTRY_PACK_NOT_ENTITLED — Industry pack not licensed

The job needs an industry pack that your plan or license does not include.

What to do: Enable the pack on a plan that includes it (see Billing & Plan in the console) or remove it from the policy.

INDUSTRY_PACK_NOT_INSTALLED — Industry pack not installed

The job needs an industry pack that is not installed in this agent image.

What to do: Use an agent image that includes the pack, or remove the pack from the policy.

INSECURE_HTTP — Control plane over plain HTTP

The control-plane URL uses http://, which is allowed only for local demos and tests.

What to do: Use the https:// control-plane URL and unset DATANIVRA_AGENT_ALLOW_INSECURE_HTTP.

Operator runbook: docs/runbooks/agent-doctor.md

JOB_AUTHORIZATION_* — Job authorization rejected

The job's signed authorization did not verify: signed with a key this agent does not trust (UNKNOWN_KEY), altered (INVALID), expired or not yet valid (EXPIRED / NOT_YET_VALID), issued for another job, agent or lease (MISMATCH) or not covering a requested industry pack (PACK_NOT_PERMITTED). Nothing was read.

What to do: Check the host clock (NTP) for EXPIRED / NOT_YET_VALID and upgrade the agent to the current release for UNKNOWN_KEY; otherwise contact support with the job id and the code.

Operator runbook: docs/runbooks/job-authorization-keys.md

JOB_AUTHORIZATION_MISSING — Job authorization missing

The agent received an engine job without the signed job authorization DataNivra issues for every job. The agent refuses such jobs before reading any data.

What to do: Make sure the agent connects to the DataNivra control plane it was enrolled with. If the control plane is correct, contact support with the job id.

Operator runbook: docs/runbooks/job-authorization-keys.md

JOB_CANCELLED — Job cancelled

The job stopped early (cancelled by a user, revocation or lease expiry). Nothing was published.

What to do: Re-submit the request if the cancellation was not intended.

JOB_FAILED — Job failed

A job step failed without a more specific code.

What to do: Check the failed step in the console and the agent logs; retry the request.

KEY_VERSION_NOT_FOUND — Key version not found

The masking policy references a pseudonymization key version that is not in the keyset.

What to do: Add the key version to the keyset, or update the policy to a key version you hold.

Operator runbook: docs/runbooks/bad-key-version.md

KEYSET_INVALID — Pseudonymization keyset invalid

The pseudonymization keyset secret is malformed.

What to do: Fix the keyset secret in your secret store (it needs a primary version and base64url keys).

Operator runbook: docs/runbooks/bad-key-version.md

LEASE_EXPIRED — Lease expired

The agent's lease on a job ran out before it finished; the job stops without publishing.

What to do: Check agent health and heartbeats; long jobs may need a less loaded agent. The job can be retried.

Operator runbook: docs/runbooks/agent-offline.md

MANIFEST_CHECKSUM_REQUIRED — Manifest checksum required

Provisioning needs the manifest checksum the control plane recorded, and none was supplied.

What to do: Provision a version that completed certification and was accepted by the control plane.

Operator runbook: docs/runbooks/corrupt-manifest.md

MASKING_POLICY_REQUIRED — Masking policy required

The source holds sensitive or production data, so an approved masking policy is required.

What to do: Attach an approved masking policy to the request.

Operator runbook: docs/runbooks/expired-policy.md

MINIMUM_VERSION_UNKNOWN — Minimum agent version unknown

The control plane has not announced a minimum agent version to this agent yet (it arrives with a heartbeat acknowledgement).

What to do: Nothing to do; run the doctor again after the agent has sent a heartbeat.

Operator runbook: docs/runbooks/agent-doctor.md

NOTHING_TO_BUILD — Nothing to build

The dataset job produced no candidate data.

What to do: Check the subset definition and filters; they may select no rows.

POLICY_CHECKSUM_MISMATCH — Policy checksum mismatch

The policy content received does not match its recorded checksum.

What to do: Re-submit the request; if it repeats, contact support with the job id.

Operator runbook: docs/runbooks/expired-policy.md

POLICY_NOT_APPROVED — Policy not approved

The referenced policy version is not approved.

What to do: Approve the policy version (respecting separation of duties) or reference an approved one.

Operator runbook: docs/runbooks/expired-policy.md

POLICY_REVOKED — Policy revoked

The referenced policy version was revoked; running jobs using it are stopped.

What to do: Reference a current approved policy version and re-submit.

Operator runbook: docs/runbooks/expired-policy.md

PROTOCOL_ERROR — Protocol error

The control plane's answer was malformed or too large.

What to do: Make sure the agent and control plane versions are compatible; check that no proxy rewrites responses.

Operator runbook: docs/runbooks/control-plane-unavailable.md

PROTOCOL_UNSUPPORTED — Protocol version unsupported

The protocol version recorded at enrollment is not supported by this agent build.

What to do: Upgrade or reinstall the agent from a current release and enroll it again with a new token.

Operator runbook: docs/runbooks/agent-doctor.md

PROXY_IN_USE — HTTPS proxy in use

An HTTPS proxy is configured, so direct TCP and TLS probes are skipped; the health check goes through the proxy.

What to do: Nothing to do; judge connectivity by the CONTROL_PLANE_HEALTH result.

Operator runbook: docs/runbooks/agent-doctor.md

PSEUDONYMIZATION_KEY_TOO_SHORT — Pseudonymization key too short

A pseudonymization key is shorter than 32 bytes.

What to do: Generate a key of at least 32 random bytes in your secret store.

Operator runbook: docs/runbooks/bad-key-version.md

PSEUDONYMIZATION_KEY_UNAVAILABLE — Pseudonymization key unavailable

The pseudonymization key could not be loaded.

What to do: Check the key reference and the agent's access to your secret store.

Operator runbook: docs/runbooks/missing-secret.md

PUBLISH_INVALID_DOCUMENT — Invalid evidence document

An evidence document name is not a flat file name.

What to do: Retry; if it repeats, contact support with the job id.

Operator runbook: docs/runbooks/partial-evidence-upload.md

PUBLISH_VERIFICATION_FAILED — Publish verification failed

A copied dataset table does not match its checksum.

What to do: Check disk health and free space on the datasets volume, then request a new version.

Operator runbook: docs/runbooks/corrupt-manifest.md

RATE_LIMITED — Rate limited

The control plane rate-limited the agent. Reports are retried from the outbox.

What to do: No action normally needed; reduce concurrency if it persists.

READ_ONLY_ATTESTED — Read-only access attested

Read-only access cannot be proven for this connector kind (for example object storage), so the agent relies on the operator's read_only_attested flag.

What to do: Make sure the credential really is read-only (see the connector's integration page).

Operator runbook: docs/runbooks/agent-doctor.md

READ_ONLY_UNVERIFIED — Read-only access not proven

The source credential could not be proven read-only and was not attested, so the job refused to read it (fail closed).

What to do: For object stores or non-PostgreSQL SQL dialects, apply least-privilege grants and set read_only_attested in the connection secret.

Operator runbook: docs/runbooks/source-unavailable.md

RUNNING_AS_ROOT — Agent runs as root

The agent process runs as root. The official image runs as an unprivileged user (uid 10001).

What to do: Run the agent as an unprivileged user (do not override the image's USER).

Operator runbook: docs/runbooks/agent-doctor.md

SCENARIO_KIND_MISMATCH — Scenario kind mismatch

A synthetic scenario's kind does not match its template.

What to do: Pick a scenario template of the right kind for the request.

SECRET_ACCESS_DENIED — Secret access denied

The secret store refused the agent's identity access to the referenced secret.

What to do: Grant the agent's identity read access to that secret in your secret store.

Operator runbook: docs/runbooks/agent-doctor.md

SECRET_BACKEND_UNAVAILABLE — Secret store unavailable

The remote secret store (Key Vault, Secrets Manager or Vault) could not be reached or failed.

What to do: Check the agent's network access and identity for the secret store, then retry.

Operator runbook: docs/runbooks/agent-doctor.md

SECRET_FIELD_MISSING — Secret field missing

The secret reference points at a JSON field that is missing or not a string.

What to do: Fix the #field part of the reference or add the field to the secret.

Operator runbook: docs/runbooks/missing-secret.md

SECRET_FILE_PERMISSIONS — Secret file too open

A file:// secret is readable by group or other users.

What to do: Run `chmod 600` on the secret file.

Operator runbook: docs/runbooks/missing-secret.md

SECRET_NOT_FOUND — Secret not found

The secret store (or environment variable) returned no value for the reference.

What to do: Create the secret, or fix the reference, then retry.

Operator runbook: docs/runbooks/missing-secret.md

SECRET_NOT_JSON_OBJECT — Secret is not a JSON object

A connection secret must be a JSON document, or a #field was used on a non-JSON secret.

What to do: Store the connection document as JSON, or drop the #field from the reference.

Operator runbook: docs/runbooks/missing-secret.md

SECRET_PROVIDER_NOT_CONFIGURED — Secret provider not configured

No secret provider is configured for the reference's scheme (for example a vault scheme without its plugin).

What to do: Configure the matching secret provider plugin or use a supported scheme (env://, file://, k8s).

Operator runbook: docs/runbooks/missing-secret.md

SECRET_PROVIDER_PLUGIN_INVALID — Secret provider plugin invalid

A configured secret provider plugin failed to load or is not a secret provider.

What to do: Fix DATANIVRA_AGENT_SECRET_PROVIDER_PLUGINS or the plugin package.

Operator runbook: docs/runbooks/missing-secret.md

SECRET_REF_INVALID — Secret reference invalid

The secret reference is malformed or uses an unsupported scheme.

What to do: Correct the reference format (for example env://NAME or file://path#field).

Operator runbook: docs/runbooks/missing-secret.md

SECRET_REF_NOT_ALLOWED — Secret reference not allowed

The reference is outside the patterns or prefixes the agent allows for jobs.

What to do: Use a reference that matches the agent's allowed patterns, or widen them deliberately in the agent configuration.

Operator runbook: docs/runbooks/missing-secret.md

SECRET_REF_OUTSIDE_ALLOWLIST — Secret reference not allowed

The reference matches none of the operator's allowed patterns (DATANIVRA_AGENT_SOURCE_REF_PATTERNS / TARGET_REF_PATTERNS / KEY_REF_PATTERNS), so jobs may not use it.

What to do: Use an allowed reference or extend the pattern list on the agent.

Operator runbook: docs/runbooks/agent-doctor.md

SECRET_TOO_LARGE — Secret too large

A secret file exceeds the 64 KiB limit.

What to do: Store only the connection document in the secret.

Operator runbook: docs/runbooks/missing-secret.md

SECRET_UNRESOLVABLE — Secret unresolvable

A secret reference could not be resolved inside your environment.

What to do: Check the reference and the agent's access to the secret store. Secret values never leave your environment.

Operator runbook: docs/runbooks/missing-secret.md

SNAPSHOT_CORRUPTED — Snapshot corrupted

A snapshot object is missing or does not match its hash, so the rewind was refused. The target was not changed.

What to do: Take a new snapshot of a freshly provisioned version; delete the damaged snapshot.

SNAPSHOT_NOT_FOUND — Snapshot not found

No snapshot with this id exists for the target.

What to do: List snapshots with datanivra-agent snapshots --target-path PATH and use one of those ids.

SNAPSHOT_NOT_SUPPORTED — Snapshots not supported for this target

Snapshot and rewind are available for DIRECTORY targets only; other target kinds are designed but not implemented.

What to do: Re-provision the certified version instead of rewinding.

SNAPSHOT_UNSAFE_ENTRY — Unsafe entry in provisioned directory

The provisioned directory contains a symbolic link, which snapshots never follow.

What to do: Remove the link from the provisioned directory, then take the snapshot again.

SOURCE_CHECK_FAILED — Source check failed

Opening the source or running its read-only proof failed with an unclassified error (details are not shown because driver messages can contain host names or values).

What to do: Check the source network access and the connection document locally, then run the doctor again.

Operator runbook: docs/runbooks/agent-doctor.md

SOURCE_NOT_READ_ONLY — Source credential can write

The read-only proof found write privileges on the source credential, so the job refused to read (fail closed).

What to do: Use a credential with read-only grants (see the connector's integration page) and retry.

Operator runbook: docs/runbooks/source-unavailable.md

SOURCE_TYPE_UNSUPPORTED — Source column type unsupported

A source column could not be converted to the engine's columnar format.

What to do: Exclude the column or cast it in a view, then re-run discovery.

Operator runbook: docs/runbooks/schema-drift.md

STAGE_METADATA_INVALID — Stage metadata invalid

Engine stage metadata is missing, unreadable or does not describe a stage table.

What to do: Retry the job; if it repeats, contact support with the job id.

Operator runbook: docs/runbooks/masking-crash.md

STORAGE_DIR_MISSING — Agent directory missing

A state, workspace or datasets directory does not exist yet; the agent creates it with mode 0700 when it starts.

What to do: Nothing to do if the parent is on a persistent volume; otherwise mount the volume first.

Operator runbook: docs/runbooks/agent-doctor.md

STORAGE_LOW_FREE_SPACE — Low free space

The workspace volume has less free space than DATANIVRA_AGENT_WORKSPACE_QUOTA_BYTES.

What to do: Enlarge the workspace volume or lower the quota to what the volume can hold.

Operator runbook: docs/runbooks/agent-doctor.md

STORAGE_NOT_WRITABLE — Agent directory not writable

A state, workspace or datasets directory cannot be created or written by the agent user.

What to do: Mount the volume writable for the agent user (uid 10001 in the image).

Operator runbook: docs/runbooks/agent-doctor.md

STORAGE_OWNER_MISMATCH — Agent directory owned by another user

A state, workspace or datasets directory is owned by a different user than the agent, so its permissions cannot be enforced.

What to do: Change the owner of the directory to the agent user (for example with fsGroup / chown).

Operator runbook: docs/runbooks/agent-doctor.md

STORAGE_PERMISSIONS_TOO_OPEN — Agent directory too open

A state, workspace or datasets directory is accessible to group or other users; the agent resets it to 0700 at start.

What to do: Nothing to do if the agent can chmod it; otherwise fix the volume's permissions.

Operator runbook: docs/runbooks/agent-doctor.md

STRATEGY_NOT_SUPPORTED_DISTRIBUTED — Strategy needs the local backend

Edge-case rules and seed lists are not supported by distributed execution.

What to do: Run the job on the local backend or remove those rules.

SUBSET_MEMORY_BUDGET_EXCEEDED — Subset memory budget exceeded

The projected subset exceeds the agent's memory budget.

What to do: Narrow the subset (smaller root selection or fewer tables) or give the agent more memory.

SYNTHETIC_SCHEMA_REQUIRED — Synthetic schema required

A synthetic-only dataset needs a source schema to generate against.

What to do: Add a discovered source schema or choose a synthetic scenario template.

TARGET_CONFIG_INVALID — Target configuration invalid

The target environment's connection settings are invalid.

What to do: Fix the target connection document (for example use an absolute directory path).

Operator runbook: docs/runbooks/target-unavailable.md

TARGET_CREATE_PRIVILEGE_MISSING — Target lacks CREATE privilege

The target database credential has no CREATE privilege on the target schema (or on the database to create the schema). Checked read-only; nothing was written.

What to do: Grant CREATE on the target schema (or database) to the loader role.

Operator runbook: docs/runbooks/agent-doctor.md

TARGET_NOT_READY — Target not ready

The target environment could not be reached or is not writable, so provisioning did not start. The certified dataset is kept and can be provisioned once the target is back.

What to do: Check the target environment's connection document and network access, then provision again.

TARGET_NOT_WRITABLE — Target directory not writable

A DIRECTORY target path does not exist or is not writable by the agent user.

What to do: Create the directory on a writable volume owned by the agent user.

Operator runbook: docs/runbooks/agent-doctor.md

TARGET_TABLE_CONFLICT — Target table conflict

A target table belongs to another dataset or is not managed by DataNivra, so it is not overwritten.

What to do: Use a different target schema, or drop the unmanaged table yourself if it is safe.

Operator runbook: docs/runbooks/target-unavailable.md

TARGET_TABLE_NAME_COLLISION — Target table name collision

Two dataset tables map to the same target table name.

What to do: Rename tables in the target mapping.

Operator runbook: docs/runbooks/target-unavailable.md

TARGET_UNAVAILABLE — Target unavailable

The target environment could not be reached or provisioned.

What to do: Check network access and credentials from the agent to the target, then retry.

Operator runbook: docs/runbooks/target-unavailable.md

TARGET_VERSION_NOT_PROVISIONED — Version not provisioned in target

The dataset version is not present in this target, so there is nothing to snapshot.

What to do: Provision the certified version first.

TARGET_WRITE_FAILED — Target write failed

The target database rejected the load.

What to do: Check the target credential's write grants and free space, then retry.

Operator runbook: docs/runbooks/target-unavailable.md

TENANT_MISMATCH — Tenant mismatch

A command or finding addressed another tenant; the agent refused it.

What to do: Contact support with the job id; this indicates a configuration or routing error.

Operator runbook: docs/runbooks/tenant-authorization-failure.md

TLS_CERT_EXPIRING — Control-plane certificate expiring

The control plane's TLS certificate expires within 14 days.

What to do: Nothing to do on the agent; certificates are renewed by the operator. Contact support if it does not change.

Operator runbook: docs/runbooks/agent-doctor.md

TLS_CERT_INVALID — Control-plane certificate not trusted

The control plane's certificate failed verification (untrusted issuer, wrong host name or expired). A TLS-inspecting proxy is the usual cause.

What to do: Set DATANIVRA_AGENT_CA_BUNDLE to your proxy's CA bundle, or allow the host through without inspection.

Operator runbook: docs/runbooks/agent-doctor.md

TLS_HANDSHAKE_FAILED — TLS handshake failed

The TLS handshake with the control plane did not complete (connection reset or protocol mismatch).

What to do: Check firewalls and proxies between the agent and the control plane.

Operator runbook: docs/runbooks/agent-doctor.md

UNAUTHORIZED — Agent not authorized (HTTP 401)

The control plane did not accept the agent's token. The next token exchange usually repairs it; reports are retried.

What to do: If it persists, check clock synchronisation on the agent host and that the agent is not revoked.

Operator runbook: docs/runbooks/agent-offline.md

WORKSPACE_QUOTA_EXCEEDED — Workspace quota exceeded

The job sandbox exceeded its disk quota.

What to do: Increase DATANIVRA_AGENT_WORKSPACE_QUOTA_BYTES or narrow the subset.

Connector codes

Connector codes appear when validating or discovering a source. Which connectors ship today is listed on the integrations page.

COLUMN_NOT_FOUND — Column not found

A read asked for a column the table does not have (or the copybook does not define).

What to do: Rediscover the source so the dataset request uses current column names.

CONNECTION_CONFIG_INVALID — Connection document invalid

The resolved connection document failed validation (unknown field, wrong type, or a credential given as plain text where a secret reference is required).

What to do: Fix the connection secret's JSON; give credentials as <field>_ref secret references.

Operator runbook: docs/runbooks/source-unavailable.md

CONNECTOR_ALREADY_REGISTERED — Connector already registered

A plugin tried to register a connector kind that already has one. Built-ins cannot be replaced.

What to do: Remove the conflicting plugin from your custom agent image.

CONNECTOR_KIND_UNKNOWN — Unknown connector kind

The connection document names a connector kind that does not exist.

What to do: Use one of the kinds listed on the integrations page.

CONNECTOR_NOT_AVAILABLE — Connector not available

The kind is a designed extension point without a shipped connector (for example Oracle or Snowflake today).

What to do: Use an available connector (for example export to Parquet and read it with Local files, S3 or Azure), or install a connector plugin.

CONNECTOR_READ_BOUNDS_INVALID — Invalid read bounds

A bounded read was requested with a batch size below 1 or a negative row limit.

What to do: Contact support with the job id; the request was built incorrectly.

CONNECTOR_READ_CANCELLED — Read cancelled

The job was cancelled while the connector was streaming rows; the read stopped within one batch.

What to do: No action needed; start the job again if the cancellation was unintended.

CONNECTOR_WRITE_BLOCKED — Write statement blocked

The connector's statement guard blocked a statement that is not a read. The statement text is never logged.

What to do: Nothing to fix on the source; report it to support with the job id if you did not expect it.

COPYBOOK_FLOAT_UNSUPPORTED — Floating-point copybook field

The copybook uses COMP-1 or COMP-2 floating-point items, which the mainframe connector does not decode yet.

What to do: Convert those fields in the unload job (for example to packed decimal), or convert the extract to Parquet and use the Local files connector.

COPYBOOK_LEVEL_UNSUPPORTED — Unsupported copybook level

The copybook uses level 66 or 77 items, or a level outside 01-49.

What to do: Provide a copybook with one 01 record and levels 02-49 (88 condition names are ignored).

COPYBOOK_NAME_INVALID — Invalid copybook field name

A flattened field name is not identifier-shaped or is not unique.

What to do: Rename the field in the copybook copy you give the agent; names become column names.

COPYBOOK_ODO_UNSUPPORTED — OCCURS DEPENDING ON

The copybook uses OCCURS DEPENDING ON, which the preview connector refuses rather than guesses.

What to do: Unload a fixed-size layout, or convert the extract with your own tooling and use the Local files connector.

COPYBOOK_PICTURE_UNSUPPORTED — Unsupported PICTURE clause

A PIC clause uses symbols other than A, X, 9, S and V, mixes alphanumeric and numeric symbols, or has more than 38 digits.

What to do: Simplify the picture in the copybook the agent reads, or convert the extract first.

COPYBOOK_REDEFINES_UNSUPPORTED — REDEFINES

The copybook uses REDEFINES, which the preview connector refuses rather than guessing which layout applies.

What to do: Split record types into separate unloads with one layout each, or convert the extract first.

COPYBOOK_SYNTAX — Copybook syntax

The copybook could not be parsed: every statement must start with a level number, there must be exactly one 01 record, and elementary items need a PICTURE.

What to do: Check the copybook file named in the source's table declaration.

COPYBOOK_USAGE_UNSUPPORTED — Unsupported USAGE

An alphanumeric item declares a computational USAGE.

What to do: Correct the copybook: text fields must be DISPLAY.

CSV_COLUMN_COUNT_MISMATCH — CSV column count mismatch

The declared column_names do not match the file's width.

What to do: Correct column_names in the connection document.

CSV_HEADER_UNDECLARED — CSV header not declared

A CSV file set must declare has_header; the connector will not guess.

What to do: Set has_header (true or false) in the connection document.

CSV_HEADER_UNTRUSTED — CSV header not identifier-shaped

The CSV header contains names that are not plain identifiers, so it could be data.

What to do: Set has_header: false and declare column_names instead.

FILE_TABLE_NOT_FOUND — Declared file table not found

A declared table path is missing or has the wrong file format.

What to do: Check the tables mapping and the configured format.

Operator runbook: docs/runbooks/source-unavailable.md

MAINFRAME_FILE_TOO_LARGE — Variable-length file too large

A V/VB file exceeds the source's max_file_bytes limit (variable-length files are read in one pass).

What to do: Raise max_file_bytes in the connection document if the agent host has the memory, or split the unload.

MAINFRAME_INVALID_DATE — Invalid date field

A field declared in date_fields holds a value that is not a valid date in the declared format.

What to do: Check the date format declared for the field; all zeros or spaces are read as no date.

MAINFRAME_INVALID_NUMERIC — Invalid packed or zoned number

A packed-decimal or zoned-decimal field contains bytes that are not valid digits or a valid sign. The value is never partially decoded.

What to do: Check that the copybook matches the file (offsets, USAGE) and that the code page is right.

MAINFRAME_RECORD_FORMAT_UNSUPPORTED — Unsupported record format

The declared record format is not F, FB, V or VB.

What to do: Declare the record format of the unload file correctly.

MAINFRAME_RECORD_LENGTH_MISMATCH — Record length mismatch

A record's length, the file size or a block/record descriptor word does not match the copybook and record format.

What to do: Check that the right copybook and record format (F/FB vs V/VB) are declared for the file.

SOURCE_AUTHENTICATION_FAILED — Source login failed

The source refused the credential from the connection document.

What to do: Check the user and the secret reference in the connection document, and that the account is not locked or expired.

SOURCE_QUERY_FAILED — Source query failed

A metadata query or read against the source failed. The query and values are never logged.

What to do: Check the credential's grants and the source's health; run discovery again.

Operator runbook: docs/runbooks/source-unavailable.md

SOURCE_UNAVAILABLE — Source unavailable

The source could not be reached or the connection dropped mid-read.

What to do: Check network routes, DNS, TLS settings and credentials from the agent host.

Operator runbook: docs/runbooks/source-unavailable.md

TABLE_NOT_FOUND — Table not found

A table is not visible to this source's credential or schema filter.

What to do: Check schema filters and grants; re-run discovery after schema changes.

Operator runbook: docs/runbooks/schema-drift.md

TLS_CA_BUNDLE_MISSING — No CA bundle for TLS

The connector could not find a CA certificate bundle to verify the server's TLS certificate, so it did not connect.

What to do: Set the CA file in the connection document or install the operating system's CA certificates in the agent image.

TLS_NOT_ENFORCED — Connection was not encrypted

The session could not be proven to be TLS-encrypted, so the connector refused it rather than read data over an unencrypted link.

What to do: Enable TLS on the server (or the listener) and keep certificate verification on in the connection document.

Control plane (API and console) codes

AGENT_ALREADY_REVOKED — Agent already revoked

The agent was already revoked.

What to do: Nothing to do.

AGENT_ID_NOT_ALLOWED — Agent id not allowed on enrollment

An enrollment message must not carry an agent id.

What to do: Use the standard agent; do not hand-craft enrollment messages.

AGENT_MISMATCH — Sources and target on different agents

The sources and target environment of a request must be served by the same agent.

What to do: Pick sources and a target served by one agent.

AGENT_NOT_USABLE — Agent not usable

The selected agent does not exist or is revoked.

What to do: Choose an active agent.

AGENT_REVOKED — Agent revoked

This agent has been revoked and can no longer call the control plane.

What to do: Enroll a new agent if needed.

Operator runbook: docs/runbooks/agent-offline.md

AGENT_STATUS_INVALID — Agent status invalid

Agents may only report ACTIVE or DEGRADED.

What to do: Upgrade the agent.

ALREADY_ATTESTED — Already attested

The source's sensitivity is already attested.

What to do: Nothing to do.

ALREADY_REVIEWED — Already reviewed

This dataset version has already been reviewed.

What to do: Nothing to do.

ALREADY_REVOKED — Already revoked

The dataset (version) is already revoked.

What to do: Nothing to do.

ASSERTION_INVALID — Agent assertion rejected

The agent's signed assertion was rejected.

What to do: Check the agent host clock and that the agent key was not replaced; re-enroll if needed.

Operator runbook: docs/runbooks/agent-offline.md

ASSERTION_REPLAYED — Agent assertion replayed

An agent assertion was used twice and was rejected.

What to do: Usually transient; if it persists, check for two agents sharing one state directory.

Operator runbook: docs/runbooks/agent-offline.md

BILLING_NOT_CONFIGURED — Billing not configured

Online checkout, plan changes or the billing portal are not configured on this DataNivra deployment yet.

What to do: Nothing is wrong with your organization: your trial and data are unaffected, and upgrading will be available here once online checkout is enabled.

CADENCE_INVALID — Refresh cadence invalid

The refresh cadence is not a valid cron expression.

What to do: Correct the cron expression.

CANNOT_DISABLE_SELF — Cannot disable yourself

You cannot disable your own account.

What to do: Ask another administrator.

CERTIFICATION_POLICY_MISMATCH — Certification policy mismatch

An agent's certification report referenced a different certification policy than the job.

What to do: Re-submit the request; contact support if it repeats.

Operator runbook: docs/runbooks/partial-evidence-upload.md

CERTIFICATION_REVIEW_REQUIRED — Certification review required

A human certification review must accept this version before it is used.

What to do: Ask a reviewer to accept the version in the console.

CHECKSUM_MISMATCH — Checksum mismatch

The reviewed content is not the content being approved (for example the version changed after review).

What to do: Review the current version again.

CONFLICT — Conflict

The request conflicts with the current state of the resource.

What to do: Reload and try again.

CURSOR_INVALID — Pagination cursor invalid

The pagination cursor is invalid or expired.

What to do: Start the listing again from the first page.

DATASET_MANIFEST_MISSING — Dataset manifest missing

Provisioning was refused because the version has no recorded manifest.

What to do: Provision a version that completed certification.

Operator runbook: docs/runbooks/corrupt-manifest.md

DATASET_MISMATCH — Dataset mismatch

An agent report named a dataset that does not belong to the job.

What to do: Contact support with the job id.

DATASET_NOT_FOUND — Dataset not found

The job's dataset or version no longer exists.

What to do: Re-submit the request.

DATASET_NOT_PROVISIONABLE — Dataset not provisionable

Only certified, non-revoked versions can be provisioned.

What to do: Certify a new version.

Operator runbook: docs/runbooks/revoked-dataset.md

DATASET_NOT_RESERVABLE — Dataset not reservable

Only a certified, unexpired, non-revoked dataset version can be reserved.

What to do: Reserve a certified version, or certify a new one first.

DATASET_RESERVED — Dataset reserved

Another user holds an active reservation of this dataset for a test run; it cannot be refreshed or rolled back now.

What to do: Wait until the reservation is released or expires, or ask its holder to release it.

DATASET_REVOKED — Dataset revoked

A revoked dataset cannot be refreshed or used; its open jobs are cancelled.

What to do: Request a new dataset.

Operator runbook: docs/runbooks/revoked-dataset.md

DATASET_VERSION_NOT_PROCESSING — Dataset version not processing

The version is no longer in PROCESSING, so the job or report was refused.

What to do: Re-submit the request if the version was cancelled.

Operator runbook: docs/runbooks/duplicate-refresh.md

DOWNGRADE_EXCEEDS_LIMITS — Downgrade exceeds the smaller plan

Your organization currently uses more agents, sources or datasets than the smaller plan allows.

What to do: Revoke unused agents, remove sources or datasets named in the message, then change plan again.

DUPLICATE_SOURCE — Duplicate source

Each source may be listed once in a request.

What to do: Remove the duplicate.

EMAIL_DOMAIN_NOT_ALLOWED — Email domain not accepted

Self-service sign-up does not accept addresses from this email domain.

What to do: Sign up with your work email address.

ENROLLMENT_TOKEN_INVALID — Enrollment token invalid

The enrollment token is unknown, expired or already used.

What to do: Create a new enrollment token in the console; tokens are one-time.

ENTITLEMENT_LIMIT_REACHED — Plan limit reached

Your plan's limit for this capacity (for example agents, sources or jobs) is reached.

What to do: Upgrade in Billing & Plan, or free capacity (for example revoke unused agents).

ENTITLEMENT_REQUIRED — Plan does not include this

Your plan does not include this feature or industry pack.

What to do: Upgrade in Billing & Plan.

ENVIRONMENT_EXPIRED — Environment expired

The target environment has expired.

What to do: Extend or recreate the environment.

ENVIRONMENT_NAME_TAKEN — Environment name taken

An environment with this name already exists.

What to do: Choose another name.

ENVIRONMENT_NOT_FOUND — Environment not found

The target environment does not exist.

What to do: Choose an existing environment.

ENVIRONMENT_RESERVED — Environment reserved

Another user holds an active reservation of this environment; only they can provision into it.

What to do: Wait until the reservation is released or expires, or ask an environment manager to force-release it.

EVENT_ID_CONFLICT — Event id conflict

An agent report reused an event id with different content.

What to do: Contact support with the job id.

Operator runbook: docs/runbooks/queue-duplication.md

EVIDENCE_INCOMPLETE — Evidence incomplete

The version's certification evidence is incomplete, so it cannot be used.

What to do: Request a new version.

Operator runbook: docs/runbooks/partial-evidence-upload.md

EXPIRY_IN_PAST — Expiry in the past

expires_at must be in the future.

What to do: Choose a future expiry.

FINDING_REVIEWS_TOO_MANY — Too many finding reviews

The job would carry more reviewed findings than one command allows.

What to do: Split the request across fewer sources.

FORBIDDEN — Forbidden

You do not have permission to perform this action.

What to do: Ask an administrator for the needed role.

Operator runbook: docs/runbooks/tenant-authorization-failure.md

IDEMPOTENCY_IN_PROGRESS — Request in progress

A request with this Idempotency-Key is still in progress.

What to do: Wait and retry.

IDEMPOTENCY_KEY_INVALID — Idempotency key invalid

The Idempotency-Key header is malformed.

What to do: Send a UUID-style key.

IDEMPOTENCY_KEY_REUSED — Idempotency key reused

This Idempotency-Key was already used for a different request.

What to do: Use a new key per distinct request.

IDENTITY_PROVIDER_UNAVAILABLE — Identity provider unreachable

The identity provider could not be reached during sign-in.

What to do: Try again; check your identity provider's status.

ILLEGAL_POLICY_TRANSITION — Illegal policy transition

The policy version cannot move to the requested status from its current one.

What to do: Follow the policy lifecycle (draft, in review, approved).

INTERNAL_ERROR — Internal error

An internal error occurred.

What to do: Retry; if it repeats, contact support and quote the correlation id.

INVALID_CREDENTIALS — Sign-in failed

The login could not be completed.

What to do: Try again or use the sign-in link; contact your administrator if your account is disabled.

INVITATION_LIMIT — Invitation limit reached

Your organization sent its daily allowance of invitation emails.

What to do: Invite the remaining teammates tomorrow; people already invited can sign in by email now.

JOB_AUTHORIZATION_UNAVAILABLE — Job authorization unavailable

The control plane could not sign the job authorization your agent requires, so the job was not sent. No data was read.

What to do: This is a DataNivra service configuration issue; retry later or contact support with the job id.

Operator runbook: docs/runbooks/job-authorization-keys.md

JOB_CANCELLED — Job cancelled

The job was cancelled, so the agent's report was refused.

What to do: Nothing to do.

JOB_KIND_MISMATCH — Job kind mismatch

An agent report does not match the job's kind.

What to do: Upgrade the agent; contact support if it repeats.

JOB_NOT_FOUND — Job not found

An agent reported on a job that does not exist for its tenant.

What to do: Contact support with the agent id.

JOB_TERMINAL — Job already finished

The job already finished, so it cannot be cancelled or reported on.

What to do: Nothing to do.

LAST_OWNER — Last owner

The tenant must keep at least one active organisation owner.

What to do: Add another owner first.

LEASE_MISMATCH — Lease mismatch

The lease id in the path does not match the message.

What to do: Upgrade the agent.

MANIFEST_CHECKSUM_MISMATCH — Manifest checksum mismatch

An agent report's manifest checksum differs from the one recorded.

What to do: Request a new version.

Operator runbook: docs/runbooks/corrupt-manifest.md

MANIFEST_CONFLICT — Manifest conflict

A different manifest was already recorded for this version.

What to do: Request a new version.

Operator runbook: docs/runbooks/corrupt-manifest.md

MANIFEST_MISSING — Manifest missing

An agent report needed a manifest that was not supplied.

What to do: Retry; contact support if it repeats.

Operator runbook: docs/runbooks/partial-evidence-upload.md

MANUAL_BILLING — Billed by trial or contract

The organization is on the Free Trial or an enterprise contract, which is not managed in the billing portal.

What to do: Choose a plan on Billing & Plan to start a subscription, or contact your account team for contract changes.

MESSAGE_EXPIRED — Message expired

The agent message is older than the retention window.

What to do: Check the agent host clock; the agent will send fresh reports.

METHOD_NOT_ALLOWED — Method not allowed

The HTTP method is not allowed for this resource.

What to do: Check the API reference.

MISSION_NOT_ACKNOWLEDGEABLE — Mission completes automatically

Sandbox missions complete when the real step succeeds (for example a certified dataset); they cannot be ticked off by hand.

What to do: Carry out the mission's step in the sandbox; progress updates automatically.

NOT_FOUND — Not found

The resource was not found (also returned for other tenants' resources, so nothing is disclosed).

What to do: Check the id and your organisation.

NOT_SELF_SERVICE — Plan needs a contract

Enterprise and Private Cloud plans are sold under contract, not through online checkout.

What to do: Use the enterprise page or contact sales; Team and Business can be bought online.

NOTHING_TO_ATTEST — Nothing to attest

Production sources are governed as production; no attestation is needed.

What to do: Nothing to do.

OIDC_NOT_CONFIGURED — OIDC single sign-on not configured

Sign-in with an identity provider is not configured for this deployment.

What to do: Use the sign-in method your administrator configured.

ON_DEMAND_REFRESH_DISABLED — On-demand refresh disabled

The refresh policy does not allow on-demand refreshes.

What to do: Wait for the scheduled refresh or change the refresh policy.

Operator runbook: docs/runbooks/duplicate-refresh.md

PACK_NOT_ENABLED — Industry pack not enabled

The industry pack is not enabled for this tenant.

What to do: Enable the pack (if your plan includes it).

PAYLOAD_TOO_LARGE — Payload too large

The request body is too large.

What to do: Send a smaller request.

PLAN_UNCHANGED — Already on this plan

The organization is already on the selected plan.

What to do: No action needed.

POLICY_CHECKSUM_MISMATCH — Policy checksum mismatch

The referenced policy checksum does not match.

What to do: Reference the current policy version.

Operator runbook: docs/runbooks/expired-policy.md

POLICY_KIND_MISMATCH — Policy kind mismatch

The referenced policy is not of the expected kind.

What to do: Reference a policy of the right kind (masking, certification, refresh ...).

POLICY_NAME_TAKEN — Policy name taken

A policy with this name already exists.

What to do: Choose another name.

POLICY_NOT_APPROVED — Policy not approved

The referenced policy version is not approved (a job may be refused at dispatch for this reason).

What to do: Approve the version or reference an approved one.

Operator runbook: docs/runbooks/expired-policy.md

POLICY_NOT_FOUND — Policy not found

The referenced policy version does not exist.

What to do: Choose an existing version.

POLICY_REF_MISMATCH — Policy reference mismatch

An agent report referenced a different policy than the job.

What to do: Re-submit the request; contact support if it repeats.

PORTAL_NOT_AVAILABLE — Billing portal not available yet

The billing provider's portal becomes available after your first checkout.

What to do: Choose a plan first; afterwards manage payment methods and invoices in the portal.

PROTOCOL_VERSION_UNSUPPORTED — Protocol version unsupported

The agent speaks a protocol version this control plane does not support.

What to do: Upgrade the agent (see the downloads page).

PUBLIC_KEY_IN_USE — Public key in use

Another agent already enrolled with this public key.

What to do: Give each agent its own state directory and key.

RATE_LIMITED — Rate limited

Too many requests in a short time.

What to do: Wait and retry; the response carries a retry hint.

REDIRECT_URI_NOT_ALLOWED — Callback URL not allowed

The sign-in callback URL is not registered.

What to do: Use the console's configured address.

REFRESH_RATE_LIMITED — Refresh limit reached

The refresh policy's daily refresh limit was reached.

What to do: Wait until tomorrow or adjust the refresh policy.

Operator runbook: docs/runbooks/duplicate-refresh.md

REPORT_KIND_UNSUPPORTED — Report kind unsupported

The agent sent a report kind the control plane does not accept for this job.

What to do: Upgrade the agent.

REQUEST_NOT_AWAITING_APPROVAL — Request not awaiting approval

The dataset request is not in a state that can be approved or rejected.

What to do: Reload the request.

REQUEST_NOT_CANCELLABLE — Request not cancellable

The dataset request can no longer be cancelled.

What to do: Reload the request.

RESERVATION_ENDED — Reservation already ended

The reservation was released, expired or ended by a revocation.

What to do: Take a new reservation.

RESERVATION_NOT_OWNER — Not the reservation holder

Only the user holding a reservation can renew or release it.

What to do: Ask the holder, or a user with environment.manage, to release it.

RESERVATION_RENEWAL_LIMIT — Renewal limit reached

The reservation was renewed the maximum number of times.

What to do: Release it and take a new reservation.

REVIEW_REQUIRED — Review required

An approval-required policy version must be submitted for review before approval.

What to do: Submit the version for review first.

REVIEW_STATUS_INVALID — Review status invalid

A finding review must confirm or reject the finding.

What to do: Choose confirm or reject.

ROLE_ESCALATION_DENIED — Role escalation denied

You cannot grant roles with permissions you do not hold.

What to do: Ask an administrator who holds the role.

SANDBOX_AGENT_NOT_READY — Sandbox still starting

The hosted sandbox agent has not reported in yet.

What to do: Wait a minute and reload the sandbox page. If it stays in this state, reset the sandbox.

SANDBOX_ESTATES_INVALID — Sandbox runner report invalid

The hosted sandbox runner reported estates that do not belong to the sandbox.

What to do: Reset the sandbox; if it repeats, contact support (runner configuration issue).

SANDBOX_NOT_PROVISIONING — Sandbox not starting

The sandbox runner reported on a sandbox that is not being started.

What to do: Reload the sandbox page; if the sandbox shows FAILED, reset it.

SANDBOX_PACK_NOT_OFFERED — Synthetic estate not offered

A requested synthetic estate (industry pack) is not available in the hosted sandbox.

What to do: Start the sandbox with the default estates.

SANDBOX_REF_INVALID — Sandbox reference outside the sandbox

A sandbox source, target or key reference pointed outside the sandbox's own documents and was refused.

What to do: Reset the sandbox; if it repeats, contact support. Sandboxes only ever use DataNivra-hosted synthetic estates.

SANDBOX_RESET_LIMIT — Sandbox reset limit reached

The sandbox was reset the maximum number of times in the last 24 hours.

What to do: Keep using the current sandbox, or reset it again later.

SANDBOX_RUNNER_UNAVAILABLE — Hosted sandbox unavailable

This DataNivra deployment does not run the hosted synthetic sandbox yet.

What to do: Use the browser demo on the website, or install an agent in your own environment with synthetic data.

SANDBOX_TEMPLATE_INVALID — Sandbox policy template invalid

A policy template supplied by the sandbox runner is not a valid policy.

What to do: Reset the sandbox; if it repeats, contact support.

SENSITIVITY_MISMATCH — Sensitivity mismatch

The attested sensitivity differs from the declared one.

What to do: Attest the declared sensitivity or change the source's declaration.

SEPARATION_OF_DUTIES — Separation of duties

The author or submitter of a policy version cannot approve it.

What to do: Ask another approver.

SEQUENCE_CONFLICT — Report sequence conflict

An agent replayed an older report sequence with different content.

What to do: Usually harmless replay; contact support if the job stalls.

Operator runbook: docs/runbooks/queue-duplication.md

SEQUENCE_GAP — Report sequence gap

An agent report skipped a sequence number; the job waits for the missing report.

What to do: Let the agent retry from its outbox; contact support if the job stalls.

Operator runbook: docs/runbooks/queue-duplication.md

SIGNUP_CAPACITY_REACHED — Sign-ups paused

The daily limit of new self-service organizations was reached.

What to do: Try again tomorrow; the interactive demo is available meanwhile. For an urgent evaluation, contact sales.

SIGNUP_NOT_AVAILABLE — Self-service sign-up not offered

This DataNivra deployment does not offer self-service sign-up or email sign-in.

What to do: Sign in with your organization's identity provider, or contact the deployment's administrator.

SIGNUP_NOT_CONFIGURED — Sign-up not configured

Self-service sign-up is enabled but its trial set-up is not configured on the server.

What to do: Contact support; this is a deployment configuration issue.

SIGNUP_ORGANIZATION_LIMIT — Trial limit for this address

This email address created the maximum number of trial organizations recently.

What to do: Continue in an organization you already created (sign in by email).

SIGNUP_SOURCE_LIMIT — Sign-up limit for this network

Many organizations were created from this network or email domain today.

What to do: Try again tomorrow, or continue in an organization you already created (sign in by email). The interactive demo is available meanwhile.

SOD_POLICY_APPROVAL_REQUIRED — Separation of duties required

Separation of duties for policy approval cannot be switched off on this tenant.

What to do: Keep policy approval separation of duties on.

SOURCE_MISMATCH — Source mismatch

An agent report named a source that does not belong to the job.

What to do: Contact support with the job id.

SOURCE_NAME_TAKEN — Source name taken

A source with this name already exists.

What to do: Choose another name.

SOURCE_NOT_FOUND — Source not found

A referenced source does not exist.

What to do: Choose an existing source.

SUBSCRIPTION_NOT_CHANGEABLE — Plan change not possible now

An invoice is past due or the subscription is cancelled, so the plan cannot change.

What to do: Open Manage billing to pay the open invoice or resume the subscription, then change plan.

SUBSCRIPTION_NOT_FOUND — No active subscription

There is no active self-service subscription to change or cancel.

What to do: Choose a plan on Billing & Plan first.

TENANT_MISMATCH — Tenant mismatch

A report or request referenced another tenant and was refused.

What to do: Contact support with the job id.

Operator runbook: docs/runbooks/tenant-authorization-failure.md

TENANT_NOT_ACTIVE — Organization not active

The organization is suspended or closed, so its agents and sandbox cannot connect.

What to do: An organization owner can check Billing & Plan; if the suspension is unexpected, contact support.

TENANT_SLUG_TAKEN — Organisation address taken

An organisation with this slug already exists.

What to do: Choose another slug.

TIMEZONE_INVALID — Time zone invalid

The refresh policy time zone is unknown.

What to do: Use an IANA time zone name such as Europe/Berlin.

TIMEZONE_REQUIRED — Time zone required

from/to query values must include a UTC offset.

What to do: Add a UTC offset to the timestamps.

UNAUTHENTICATED — Not signed in

Authentication is required.

What to do: Sign in again.

UNEXPECTED_MESSAGE_KIND — Unexpected message kind

The endpoint does not accept that agent message kind.

What to do: Upgrade the agent.

USER_EXISTS — User exists

A user with this email already exists in the organisation.

What to do: Invite a different address or edit the existing user.

USER_REQUIRED — User required

This action must be performed by a signed-in user, not an agent or token.

What to do: Sign in as a user.

VALIDATION_FAILED — Validation failed

The request is invalid; the details list the affected field paths (never the values).

What to do: Correct the listed fields.

VERSION_NOT_CERTIFIED — Version not certified

Only certified versions can be reviewed.

What to do: Wait for certification to complete or request a new version.

WINDOW_INVALID — Window invalid

The calendar window must be positive and at most 366 days.

What to do: Choose a shorter window.

Back to the support center · Open the troubleshooting guides

Still stuck? Contact support

Include the error code, the job, dataset or agent id and the time it happened. Never send credentials, enrollment tokens, secret values or source data — support never needs them.

Contact us