Governance / Foundation / 5 min read
Set data boundaries for a pilot
Agree what information an automation can read, where it is processed and how long it stays.
What you will learn
- List sensitive data in the workflow.
- Choose permitted tools and locations.
- Assign approval for new access.
The lesson
A pilot is easier to review when the data boundary is explicit. List the documents, messages and fields it needs. Remove anything that is irrelevant to the task before selecting a model, workflow tool or hosting environment.
Ask where data is stored, which service processes it, who can inspect logs and when those logs are deleted. If a new integration needs broader access, pause that change until the responsible team has reviewed it.
Try this
Draw a box around the systems that may handle one pilot’s data. Write down any external service outside the box and the approval needed before it receives information.
← All lessons