What to check before connecting AI to your business systems
The first question is what the connection needs to do. Reading a record, drafting a response and changing that record require different permissions and controls.
Define the task before giving a tool access to business information.
Name the information and the action
- Read information
- Prepare a draft
- Write only if permitted
Specify which records the workflow can use and why. Decide whether it only needs to read information or also needs to write changes.
A reporting task may need read access and a place to store a draft. It does not automatically need permission to delete records or send messages.
Check the system can support it
Ask whether the existing software provides a supported connection or API, which subscription is required and whether the vendor permits the intended use.
An available connector does not establish that every required field or action is supported. Test the exact task with appropriate sample data before committing to production.
Agree human approval points
- Draft message
- Human approval
- Permission to send
Decide which actions can happen automatically and which need a person to approve them.
Keep important approvals explicit. A draft customer message should not become a sent message merely because a system can access the mailbox.
Follow the data
- Agreed sources
- Named providers
- Retention & access
Identify where information goes, which providers process it and whether it leaves the UK. Agree access, retention and deletion arrangements appropriate to the data and engagement.
Credentials need a secure transfer and storage route. Do not paste passwords or API keys into an enquiry form or ordinary project document.
Design for interrupted connections
- Connection fails
- Make it visible
- Continue manually
Access can expire. A provider can become unavailable. The same event can arrive more than once.
The workflow needs to make failures visible and avoid repeating actions that should happen once. The team also needs to know how to continue manually and who is responsible for investigating.
Treat source material as information
An email or document may contain instructions that conflict with the workflow. The system needs controls to prevent those instructions from changing its permissions or approved task.
This is one reason a working demo is not enough. Relevant security and failure tests belong in the implementation scope.
Questions to ask before signing
- Which accounts and permissions does the workflow need?
- What data reaches each provider?
- Which actions require approval?
- How are failures and duplicate events handled?
- Who maintains the connection after handover?
- Which costs or vendor dependencies could change?
Get the connections checked as part of the scope
Propel assesses supported integrations as part of implementation planning. If a custom connection is needed, we explain the dependency and quote it separately where appropriate.
Explore implementationBook a discovery call