Integrations and Automation
An integration turns permission into ongoing activity. Once a connection, Automation, or AI client is configured, it can read, change, or deliver data without a person repeating the original setup. The important security decision is the authority the finished workflow holds throughout its lifetime.
This section is for people approving integrations and the administrators or developers building them. It connects credential scope, workflow ownership, destination access, and revocation so you can give a process enough authority to complete its job and understand what remains possible afterward.
Configuration and Execution
Permission to configure a workflow and permission to perform its file operations are related but distinct. A workflow uses its own execution permissions. A restriction on the API key that saved its configuration does not necessarily become a restriction on the resulting workflow.
The same distinction applies to an outbound connection. Files.com controls which operations a user or workflow may request; the remote system controls what the connection's stored credentials can do there. Choose both sides for the intended exchange. A narrowly configured folder on Files.com does not change permissions granted to the remote account by its provider.
Durable Ownership and Independent Credentials
Business processes need to continue when the person who built them changes roles. Site-owned resources and site-wide credentials support that continuity. User-owned resources instead remain tied to a particular account's permissions and lifecycle. Choose that relationship deliberately and record who is responsible for maintaining it.
A separate credential for each integration makes replacement and revocation more precise. Shared credentials can simplify rotation, but changing one can affect every connection that uses it. Before ending an integration, identify the credentials, triggers, scheduled work, and remote authorizations involved, as well as files already delivered to other systems.
Instructions to an AI client describe the work you want. Product permissions determine the work it is allowed to perform. Apply the same account, credential, and destination decisions to AI connections that you would apply to any other integration.