Skip to content
English

Protect connections

An ELChat connection gives access to the authorized perimeter on an external service. Its security therefore depends on both the account used, the permissions granted and the actions allowed in ELChat.

  • use a dedicated service account or professional account when the platform allows;
  • enable multifactor authentication on the external account;
  • choose the smallest perimeter compatible with the need;
  • check that the account only accesses shops, properties, calendars or useful spaces;
  • never share a key, token or secret in a conversation.
  1. Check the Connect badge.
  2. First test an impact-free reading action.
  3. Review the writing actions.
  4. Place sensitive operations in Confirmation required or Blocked.
  5. Document the account owner and the date of the connection in your internal procedure.

Disconnect the service in ELChat, revoke permission or secrecy from the relevant platform, and then create a new access. A reconnection alone does not guarantee that a former exposed secret has been invalidated.

See also Security and troubleshooting of connectionsand the connector concerned.

For an appointment route, use a Google account dedicated to the business calendar, limit its visible calendars, enable multifactor authentication and leave event creation in Confirmation required.

The account limits accessible data, the scope of the calendar limits destinations and confirmation limits the impact of a writing. Test an availability and then a fictional creation before starting production.