Client-owned systems
Production workflows use your business accounts and workspaces wherever practical.
Security is not a paragraph added at the end. Access, data, actions, approvals and fallback are designed into the workflow from the start.
The exact controls depend on the information involved and the consequence of a mistake.
Production workflows use your business accounts and workspaces wherever practical.
Use named accounts, limited permissions and time-bound access rather than shared passwords.
Use the minimum information required for the agreed outcome and avoid unnecessary copies.
Keep sensitive messages, exceptions and consequential actions behind an authorised person.
Use realistic examples, known edge cases and clear acceptance checks before launch.
Make it clear what happens when information is missing, confidence is low or a system fails.
AI-assisted workflows need clearer boundaries because the output can vary. The system should know what it may use, what it may do and when it must stop.
Access should be granted through the client’s normal administration route wherever possible.
Third-party services fail, data changes and unusual cases appear. Important workflows need visible errors, a manual route and someone who knows what to do next.
Sometimes, but only where the agreed build requires it. The preferred route is limited, business-owned access that can be removed or reduced after handover.
That depends on the selected platform, account type and settings. I review the agreed data route and business workspace before use; the client approves the platform and contract.
Where OxTech Automation processes personal data on a client’s behalf, the commercial documents should define roles, instructions, security expectations and return or deletion.
No. It explains the implementation approach. Formal legal, cybersecurity, regulatory or penetration-testing assurance may require an appropriate specialist.
Email security@oxtechautomation.com with the affected page, what you observed and how it can be reproduced. Please do not include unnecessary personal or confidential information.
That answer helps set the right access, approval, testing and fallback.