Access

Anyone who builds or supports automation needs some access to your systems. The question is how much, for how long, and whether you can see and withdraw it. Good practice is a separate account per person or system, with only the permissions needed for the job, created by you and removable by you.

  • Which accounts will be needed, and with what permissions
  • A full list of every access held, which you can remove yourself
  • Whether shared or administrator logins are ever used
  • How passwords and keys are stored on the supplier's side

Approvals

Automation should not take irreversible actions on its own. Ask which actions need a person's approval, who that person is, what happens if nobody approves, and whether approvals are recorded. A good answer is specific: sending to customers, moving money and deleting records all wait for a named person.

Logging

You should be able to find out what was done, when and by whom, both by people and by the system. Ask what is logged, where the logs are kept, how long for, and whether you receive them. Logs are what turn a mystery into a quick fix when something goes wrong.

Data Handling

  • Where data is stored, and in which country
  • Which outside services see it, including AI providers
  • Whether any of it is used to train models
  • How long it is kept, and how it is deleted
  • What leaves your infrastructure, and exactly what it contains

When Things Go Wrong

Ask how incidents are detected, how quickly you will be told, and who does what. Ask for the rollback plan for changes and the recovery steps if a server fails. A supplier who has thought about failure is more trustworthy than one who promises it will not happen.

Leaving

Ask what happens on the last day: which accounts are closed, what documentation you keep, whether the system keeps running, and how access is handed back. The answer tells you how dependent you will become.

Your Side of Security

  • Turn on two-step login for every administrator account you own
  • Review who has access every quarter, and remove anyone who has left
  • Keep a named owner for each automated system
  • Train staff to check before approving anything unusual

Phishing and Approval Fraud

As more work is approved through messages and buttons, attackers target the approver. Teach whoever approves actions to be wary of urgent requests, new bank details and anything that arrives through an unusual channel. When in doubt, they phone to confirm.

Four Questions to Ask First

Whoever you work with, these points help you understand the risks. Clear written answers on each one are a good sign that a supplier takes security seriously. Vague answers are a warning sign.

Where It Runs: Find out on whose servers or accounts the system runs, and who pays for them. A system on your own account keeps your data and your bill under your control. A system on a supplier's servers means your records pass through theirs.

Who Can Access What: Establish which accounts the supplier uses and whether you can switch them off yourself. Good practice is a separate, limited account for each person or system. Any access should be visible to you and removable at any time.

What It Can Do Without a Person: Agree which actions need a human approval, and what happens if nobody approves. Anything that cannot be undone, such as a payment or a message to a customer, should wait for a person. Silence should mean nothing happens.

What Happens If You Leave: Settle what you receive when the relationship ends and whether the system keeps working. Documentation, access and credentials should be handed over in a planned way. Leaving should not mean starting again from nothing.