Before connecting any two systems, establish the business purpose, minimum data scope, authorized people, and a safe correction path.
Scope note: This is a vendor-neutral checklist. It does not claim that any product supports a specific provider, integration, connection, API, OAuth, sync, import, export, accounting, payment, calendar, or outcome.
Approve the use case
Document what business question the connection will support and which record types are truly necessary. Assign an accountable owner and define a stop condition.
Limit access and data
Request the narrowest permission and smallest data scope necessary. Do not expose credentials, tokens, passwords, account IDs, payment details, customer data, internal links, screenshots, recordings, logs, or real examples in public content.
Test privately with synthetic data
| Test | Expected control |
|---|---|
| Routine, authorized transfer | Reviewable result |
| Missing field or context | Pause and clarify |
| Duplicate or conflict | Quarantine and review |
| Sensitive information | Restrict and escalate |
| Failed connection | Safe stop and documented recovery |
Verify before material use
A connected status, sync event, or visible record does not prove that data is correct, authorized, complete, paid, collected, scheduled, or ready for a customer-facing action.
Recheck and revoke
Review active connections, access, retention, corrections, incidents, and continuing need on a regular cadence. Revoke access when the approved purpose ends.
Discussion
Which field would you exclude first from a new third-party connection?