A third-party connection may expand a workflow, but it can also expose data, permissions, and operational dependencies. Evaluate it before any connection is authorized.
Scope note: This is a vendor-neutral checklist. It does not claim that any product supports integrations, APIs, OAuth, sync, imports, exports, payments, accounting, scheduling, calendars, or outcomes.
Define the business purpose
Write the exact use case, data categories, authorized people, source and destination, expected failure mode, human owner, and stop condition. Do not connect a service merely because a connector is available.
Minimize access and data
Request the narrowest permissions and smallest data scope that support the purpose. Never expose tokens, secrets, passwords, account IDs, internal links, production screenshots, logs, recordings, customer data, payment data, or real examples in public content.
Review data handling
Confirm data flow, retention, deletion, incident handling, access revocation, vendor terms, and legal or contractual obligations through the qualified owner. A connection status is not proof that records are correct, complete, authorized, or safe.
Test with synthetic data
| Test | Expected control |
|---|---|
| Authorized low-risk exchange | Reviewable, bounded result |
| Missing required context | Pause for clarification |
| Duplicate or conflicting record | Quarantine and review |
| Sensitive or unexpected data | Restrict and escalate |
| Connection failure | Safe stop with documented recovery path |
Authorize cutover carefully
Keep a human review point before the connection can change material records or trigger customer-facing activity. Do not interpret a sync event as proof of a booking, completed job, payment, invoice, collection, or business result.
Recheck regularly
Review permissions, data scope, active users, exceptions, vendor changes, and the continued need for the connection. Revoke it when the approved purpose ends.
Discussion
What is the first data category you would exclude from a new third-party connection?