Connections
Give colleagues controlled access to vendor services while credentials remain in the gateway.
Connections provide OAuth-backed access to external vendor services. Colleagues use the resulting capability through a gateway; they do not receive the underlying credential.
Before connecting a service
Confirm that you are authorised to connect the vendor account and that its data may be used for the intended work. Choose the narrowest suitable account or scope where the vendor supports that choice.
Add a connection
Open Connections, choose an available vendor and follow its OAuth authorization flow. Review the vendor account and requested access before completing authorization. Availability depends on organisation configuration.
Make it available to a colleague
A connection existing in the workspace does not mean every colleague needs it. Add the relevant capability while reviewing the colleague profile, then set rules around its use and any sensitive actions.
How credentials are handled
Connection credentials remain in the gateway and are never handed to the colleague. The colleague runs in its isolated cloud computer and uses the mediated capability needed for the work.
Review sensitive actions
Configure clear approval boundaries for actions with external effects. An approval should explain the proposed action, relevant data and destination so a person can make a deliberate decision.
Remove or rotate access
When ownership, policy or vendor access changes, update or remove the connection. Review colleagues and scheduled automations that depend on it; their future runs may need a replacement connection or revised scope.
Troubleshooting
If work cannot use a connection, check that the connection is still authorised, available to the colleague and permitted by organisation policy. Do not paste credentials into a conversation as a workaround.