Access and auth
We start with the least privilege that makes the workflow possible: a dedicated service account or OAuth app scoped to specific objects and specific actions, never a borrowed admin login. Credentials live in a managed secret store with rotation, not inside a workflow step. Where a vendor only offers all-or-nothing API keys, we put a proxy in front of it so the AI still cannot reach beyond its remit.