OAuth and service accounts
Use client-owned identities, scoped permissions and dedicated automation principals.
Security approach
Automation connects valuable systems. Identity, scopes, secrets, data boundaries and action authority are part of the architecture.
Use client-owned identities, scoped permissions and dedicated automation principals.
Separate read, draft and consequential-write authority; do not give a model credentials it cannot need.
Keep credentials out of workflow exports, logs, prompts and source control.
Send only required fields, redact where possible and define retention for inputs and traces.
Record actor, action, source evidence, policy version, approval and provider response.
Select retention and training controls appropriate to the client’s data classification.
Use managed, self-hosted or client infrastructure based on compliance and operational constraints.
Require named human authority for high-impact actions where consequence justifies it.
Action boundary
Split context gathering from consequential credentials.
The drafting path cannot call the send API. Only a verified approval continuation reaches the narrowly scoped execution worker.
Deployment choices
Questions before implementation
Need security involvement early?
It is cheaper to choose the right data and action boundaries before the workflow exists.