Skip to content
Bahman Shadmehr Independent AI Systems & Automation Engineer

Security approach

Give every workflow
only the power it needs.

Automation connects valuable systems. Identity, scopes, secrets, data boundaries and action authority are part of the architecture.

01

OAuth and service accounts

Use client-owned identities, scoped permissions and dedicated automation principals.

02

Least privilege

Separate read, draft and consequential-write authority; do not give a model credentials it cannot need.

03

Secrets management

Keep credentials out of workflow exports, logs, prompts and source control.

04

Data minimisation

Send only required fields, redact where possible and define retention for inputs and traces.

05

Audit logs

Record actor, action, source evidence, policy version, approval and provider response.

06

Provider settings

Select retention and training controls appropriate to the client’s data classification.

07

Deployment choice

Use managed, self-hosted or client infrastructure based on compliance and operational constraints.

08

Approval boundaries

Require named human authority for high-impact actions where consequence justifies it.

Action boundary

Prepare broadly. Execute narrowly.

Split context gathering from consequential credentials.

systemRead ticket
systemGather account facts
aiAI response draft
logicPolicy checks
humanNamed human approval
systemScoped send API
System / APIDeterministic logicAI stepHuman decision
Credential rule

The drafting path cannot call the send API. Only a verified approval continuation reaches the narrowly scoped execution worker.

Deployment choices

Fit the client environment.

  • Vendor cloud workflow engine
  • Self-hosted n8n in client infrastructure
  • Custom workers in existing platform
  • Private networking and client databases
  • Cloud model with documented controls
  • Local/open model when policy and economics justify it

Questions before implementation

Security changes the workflow design.

  • What data classes enter the process?
  • Which systems are authoritative?
  • Who may approve each action?
  • Where can payloads and logs be stored?
  • Which providers may receive which fields?
  • How are access and deletion requests handled?

Need security involvement early?

Good. Bring them into process design.

It is cheaper to choose the right data and action boundaries before the workflow exists.

Let's build something real