Documentation Secrets and Security

Account security best practices

Protect customer accounts and reduce risk when operating production workflow automation.

Your FlowKeyOps account can authorize changes to automation environments. Protect it with the same care as other production administration tools.

Protect individual accounts

  • Use a unique password stored in a trusted password manager.
  • Enable every additional sign-in protection offered for your account.
  • Do not share accounts between team members.
  • Review account and recovery email addresses regularly.
  • Sign out of shared devices and remove access for departing users promptly.

Apply least privilege

Give each person only the access required for their work. Separate routine review from production approval where your organization requires independent approval. Recheck access after role or team changes.

Use a safe workstation

Keep the browser and operating system current. Avoid administrative work on public computers or untrusted networks. Treat downloaded diagnostics as sensitive operational data, even when they contain no secret values.

Review before approving

Verify the workflow, version, source, destination, comparison, dependencies, and recovery path. Do not approve a request solely because its title looks familiar.

Report suspicious activity

If you see an action you do not recognize, preserve its audit-event identifier and timestamp, secure the affected account, and contact FlowKeyOps Support. Do not delete evidence before it has been reviewed.