What a tool can see once you connect your accounts

You will be able to judge the access and data exposure that comes with connecting work accounts to an automation tool.

When you connect an app to an automation tool such as Zapier, Make or n8n, you give the tool permission to act as you inside that app. Treat every connection as access to the whole account unless the permission screen says otherwise.

Reading the permission screen

When you connect Gmail, a Google permission window appears. Most people click allow without reading it, and within seconds they are back building their flow. The window lists what you are handing over, and that is usually far more than the one folder or label the flow needs.

Permission screens often describe access in broad terms. For an email account, the permission may let the tool read, compose, send and delete your email. For a cloud drive, it may let the tool see, edit and delete all your files. Your flow may only read messages with one label, but the permission covers the whole mailbox. Some apps offer narrower options, such as access to one spreadsheet or one folder, and when one is offered, take it instead of granting access to the whole account.

Keep two things separate. The tool's own settings decide what your flow does. The permission decides what the tool could do if something went wrong, if the tool were breached, or if someone else logged in to your automation account.

Where customer data goes in a flow

Mei Ling runs a centre with an enquiry form. A parent fills it in with their name, email, phone number and message. That data travels from the form to the automation tool's servers and is processed there. It then goes on to a sheet and an email app. The tool may also keep a copy in its run history, which holds the data from each run for a period so you can see what happened on each run.

Names, phone numbers and email addresses are personal data. Under Singapore's Personal Data Protection Act (PDPA), an organisation that collects personal data stays responsible for protecting it. This is still true when another company processes the data for it. So Mei Ling's centre stays responsible for the parent's details, and using an automation tool does not move that responsibility to the tool provider.

Lesson 2.2 of the course "AI at work: writing, research, spreadsheets and meetings", "Confidential data, personal data and the PDPA", covers the same law from the angle of AI chat tools. With automation the stakes are higher, because data moves automatically, many times a day.

Before you send personal data through a tool, find out the answers to these questions:

Where does it process and store data? How long does it keep run history? Can stored history be shortened or switched off for flows that carry personal data? Does your organisation have an agreement with the provider? Has anyone checked the provider's security terms? Does the data leave Singapore, and does your organisation have rules about that?

You do not need to answer these alone. Start with the tool's privacy and security pages, then ask whoever handles data protection in your organisation. If you are personally responsible for data protection, look up the PDPC's guidance on pdpc.gov.sg. These questions are general, and anything beyond them needs advice from someone qualified to give it.

Three habits that keep each connection narrow

Three habits cut most of the risk: use a dedicated account, choose the narrowest permission, and get approval for work systems.

A dedicated account is a shared address created just for the flow, such as enquiries@ or invoices@. You connect only that account and leave your personal work mailbox unconnected, so if that connection were misused, the damage would stop at one mailbox. Arif works at a renovation firm in Ubi and set his flow up this way. Suppliers send invoices to a dedicated address, and only that address is connected to the automation tool.

For the narrowest permission, pick one sheet over the whole drive, and read-only over read and write, whenever the tool offers the choice.

If the account belongs to your employer, ask IT before connecting it to any outside tool. Many workplaces have a list of approved tools and a process for adding new ones, and you should follow it. Connecting a work account without asking can breach company policy even when nothing goes wrong, and it leaves IT unable to help when something does go wrong.

When to self-host n8n

Lesson 3.1, "Zapier, Make and n8n: three ways to build the same flow", mentioned that n8n can run on your own server. Self-hosting means running a tool such as n8n on your own server, so the data passing through your flows stays on a machine you control, which some organisations need.

Self-host only when you have the skills or IT support to do it properly, not just because it sounds more private. With self-hosting, all the security work the provider used to do becomes your job. You install updates, including security fixes, as they come out. You protect the server with strong passwords and limited network access. You back it up, and you monitor whether it is running. If that work is not done, a self-hosted tool can be less safe than a well-run cloud service.

Before you build anything in module 4, take stock. In the activity below you will write down every account your chosen workflow would connect, the access each connection asks for, and whether your workplace allows it, so you can sort out any approvals before you start building.

Write down every account your chosen workflow would connect, what access each grants, and whether your workplace allows it.

Course

Junxiong-WFG Organisation is an authorised representative of AIA Financial Advisers Private Limited (Reg. No. 201715016G).