An integration should have a bounded purpose, named data owners and a recovery path. It should not quietly become another uncontrolled system of record.
Step 01
Draw the data flow
Identify the trigger, records, direction, authoritative owner, frequency and failure impact before issuing credentials.
Step 02
Authorize narrowly
Use OAuth 2.0 with PKCE and tenant-aware permissions appropriate to the user and operation.
Step 03
Test failure and retirement
Exercise denial, expiry, retry and partial failure, then document credential rotation and decommissioning.