Governance / Foundation / 5 min read

Set data boundaries for a pilot

Agree what information an automation can read, where it is processed and how long it stays.

What you will learn

  • List sensitive data in the workflow.
  • Choose permitted tools and locations.
  • Assign approval for new access.

The lesson

A pilot is easier to review when the data boundary is explicit. List the documents, messages and fields it needs. Remove anything that is irrelevant to the task before selecting a model, workflow tool or hosting environment.

Ask where data is stored, which service processes it, who can inspect logs and when those logs are deleted. If a new integration needs broader access, pause that change until the responsible team has reviewed it.

Try this

Draw a box around the systems that may handle one pilot’s data. Write down any external service outside the box and the approval needed before it receives information.

← All lessons