ArcGIS integration
ArcGIS integration and security.
NPDESTracker connects to the ArcGIS organization your agency already runs. Staff sign in with their own ArcGIS accounts, NPDESTracker reads the maps and layers those accounts can already see, and it never writes to them. This page is written for the GIS lead and the IT reviewer who have to sign off on that.
The short version
- Named-user OAuth. No passwords, no API keys, no shared service accounts.
- Read-only against your ArcGIS content. No edits, no publishing, no web map saves.
- One connection per person per agency, resolved on the server, never from the browser.
- Your GIS stays your system of record. NPDESTracker stores the compliance records it creates.
01 · Named-user sign in
Your staff connect with their own ArcGIS accounts.
The connection is made with OAuth through Esri. A staff member is sent to Esri to sign in, and NPDESTracker receives an authorization result. NPDESTracker never asks for, sees, or stores an ArcGIS password, and your agency is never asked for an API key, a client secret, or a shared service account.
- Each person connects with their own ArcGIS named user account. No shared credential.
- NPDESTracker never asks for or stores an ArcGIS password.
- What a user can see through NPDESTracker is exactly what ArcGIS already grants that account. NPDESTracker cannot widen an ArcGIS permission.
- The long-lived refresh credential stays on the server. It is never sent to the browser.
- Short-lived access credentials are scoped to one signed-in user in one agency workspace and are not cached for reuse.
- Your ArcGIS organization administrator may need to approve NPDESTracker as an external application before the first connection completes. That approval is granted inside your own ArcGIS organization.
- Removing that approval, or disabling the account in ArcGIS, ends what NPDESTracker can read. You do not have to ask us to cut off access.
02 · Read-only provider boundary
NPDESTracker reads your ArcGIS content. It never writes to it.
This is the part most GIS staff want in writing, so it is stated plainly. NPDESTracker reads maps, layers, and features from your ArcGIS organization for display and for compliance context. It performs no writes of any kind against that content, and there is no setting that turns writes on.
- No feature edits, no adds, no deletes.
- No attachment or photo changes on your layers.
- No item administration, no sharing changes, no publishing.
- No web map save. Your maps come back exactly as your GIS staff left them.
- The boundary is enforced in the codebase, not just described here: an automated inventory of the mapping code and a runtime check must both report zero write calls, or the release does not ship.
- Because there is no write path at all, NPDESTracker cannot overwrite or delete authoritative GIS data even by mistake.
03 · Tenant isolation
One connection, one person, one agency.
NPDESTracker is multi-tenant, and an ArcGIS connection is one of the most sensitive things a tenant can hold. Identity is resolved on the server from the signed-in user's own record. The browser is not trusted to say who it is or which organization it belongs to.
- Each ArcGIS connection belongs to one user in one agency workspace. A connection never crosses agencies.
- Username, organization, portal host, connection, and workspace identity are resolved on the server. A browser-supplied username is refused outright.
- A tenant administrator can confirm the ArcGIS organization the agency expects to see.
- A connection from a different organization fails closed with a plain-language message and an administrator recovery path, instead of quietly attaching to the wrong organization.
- A confirmed organization is never silently replaced. The change is recorded with who made it and when.
- Two staff members in the same organization can each connect with their own account.
- Map presets and saved views arrange the capabilities a user already has. They never grant new authorization.
04 · Where the data lives
Your GIS stays your system of record.
NPDESTracker is the operational layer for the compliance program. It is not a second copy of your GIS, and it does not try to become the authoritative source for your spatial data.
- Content read through the connection stays in your ArcGIS organization. It is read for display and context, not copied into NPDESTracker.
- Records your team creates in NPDESTracker, such as inspections, tasks, IDDE cases, markups, saved views, presets, and report evidence, are stored in NPDESTracker and scoped to your agency workspace.
- Files you choose to import, such as GeoJSON, shapefile, or CSV, are stored in NPDESTracker. The original uploaded file is retained separately from the display layer built for the browser.
- Data ownership stays with the agency. Records can be exported in the formats supported for the modules in your order.
- Hosting, encryption, backup, retention, and regional requirements are confirmed against the active production configuration during procurement review.
05 · Failure is visible
A problem reads as a problem, not as an empty map.
Silent failure is the reason compliance staff stop trusting software. If NPDESTracker cannot reach ArcGIS, cannot use a credential, or is not permitted to read a layer, it says which of those happened. It does not draw an empty map and let a coordinator conclude the program has no outfalls.
- A provider outage, a network error, an expired credential, and a permission refusal stay distinct from each other.
- A genuinely empty result reads as empty. A failed read never does.
- A control that cannot work in your configuration is not rendered as a dead button.
- Connection health is visible to the tenant administrator who set the connection up.
06 · What we do not claim
The limits, in the same place as the capabilities.
A vendor page that lists only strengths is not useful to a reviewer. These are the things NPDESTracker does not do and does not claim.
- Certification, audit, endorsement, or product review by Esri. Startup Partner membership in the Esri Partner Network is a membership, and that is all it is.
- Two-way synchronization. NPDESTracker does not push records back into your ArcGIS layers.
- Feature Service editing. There is no write path to your ArcGIS content.
- An ArcGIS Marketplace listing.
- A replacement for ArcGIS Online, ArcGIS Enterprise, or QGIS. Your authoritative GIS work belongs where it already is.
- SOC 2, ISO 27001, or any other third-party certification. We do not hold one and we do not imply one.
- A production offline mode or a native field application.
07 · For IT and GIS staff
The five questions we actually get asked.
- What does NPDESTracker ask our ArcGIS administrator to do?
- Approve NPDESTracker as an external application in your organization, once, if your organization requires administrator approval for external applications. Nothing else. There is no service account to provision and no key to hand over.
- Which permissions does the connection need?
- Only the ability to read the content the signing-in user can already see. NPDESTracker requests no write, publish, share, or administrative capability, and would have nowhere to use one.
- How do we cut off access?
- Remove the application approval in your ArcGIS organization, or disable the ArcGIS account. Access ends there. You can also disconnect the integration inside NPDESTracker.
- Can one of our users see another agency's ArcGIS content through NPDESTracker?
- No. A connection is keyed to one user in one agency workspace, and identity is resolved on the server rather than accepted from the browser.
- Do you send our data to a third party for processing?
- Not as part of the ArcGIS integration. The one place an optional external provider can be involved is Smart Draft narrative drafting, which is off by default and disclosed in full on the Smart Draft page.
More detail sits on the security page, the privacy policy, and the GIS workspace page. Send your questionnaire and we will answer it against the current implementation.

NPDESTracker is developed by Wood Technologies LLC, a Startup Partner in theEsri Partner Network.
NPDESTracker’s mapping and field workflows are powered by Esri ArcGIS technology, built for municipal stormwater teams.
Esri and the Esri Logo are licensed trademarks of Environmental Systems Research Institute, Inc.
Have your GIS lead look at the map.
The public demo opens in a new tab on an isolated, read-only sample workspace with fictional data. The connected ArcGIS view runs on your own organization and is set up with your team, so it is walked through with you rather than shown on sample data.
