Protect connections
An ELChat connection gives access to the authorized perimeter on an external service. Its security therefore depends on both the account used, the permissions granted and the actions allowed in ELChat.
Before connection
Section titled “Before connection”- use a dedicated service account or professional account when the platform allows;
- enable multifactor authentication on the external account;
- choose the smallest perimeter compatible with the need;
- check that the account only accesses shops, properties, calendars or useful spaces;
- never share a key, token or secret in a conversation.
After connection
Section titled “After connection”- Check the Connect badge.
- First test an impact-free reading action.
- Review the writing actions.
- Place sensitive operations in Confirmation required or Blocked.
- Document the account owner and the date of the connection in your internal procedure.
In case of doubt
Section titled “In case of doubt”Disconnect the service in ELChat, revoke permission or secrecy from the relevant platform, and then create a new access. A reconnection alone does not guarantee that a former exposed secret has been invalidated.
See also Security and troubleshooting of connectionsand the connector concerned.
Example of minimum perimeter
Section titled “Example of minimum perimeter”For an appointment route, use a Google account dedicated to the business calendar, limit its visible calendars, enable multifactor authentication and leave event creation in Confirmation required.
The account limits accessible data, the scope of the calendar limits destinations and confirmation limits the impact of a writing. Test an availability and then a fictional creation before starting production.