AI Integration Risk Register
Use this before giving an AI workflow access to email, calendar, CRM, documents, chat, or other business tools.
Integration Inventory
| Integration | Account or workspace | Access level | Allowed actions | Forbidden actions | Owner |
|---|---|---|---|---|---|
| Calendar | Read / write | ||||
| Read / draft / send | |||||
| CRM | Read / create / update |
Risk Assessment
| Risk | Likelihood | Impact | Control | Residual risk | Decision |
|---|---|---|---|---|---|
| Wrong customer record updated | Assess from representative tests | Assess from affected data/action | Identity check + approval before write + reconciliation | Reassess after tests | Accept / reduce / reject |
Permission Rules
- Use a provider-supported workload identity where available; never share a personal login to bypass a provider limitation.
- Use least-privilege OAuth scopes or API keys.
- Prefer read-only access first.
- Enable write access one action at a time.
- Store credentials outside prompts, model context, ordinary logs, and generated output.
- Rotate credentials according to provider guidance and the organisation’s risk-based policy.
- Revoke unused integrations.
Human Gate
Choose and test a gate for each write action. Irreversible, high-consequence, or externally visible actions require explicit review before the effect:
- Approve before act.
- Delay with a named monitor and a tested cancellation mechanism, only where the action is reversible.
- Automatic action within a documented low-consequence policy boundary, with exception review and a tested stop control.
Required Logs
- Timestamp.
- Agent or workflow name.
- Trigger.
- Pseudonymous input record ID or another approved stable reference.
- Tool called.
- Minimum approved arguments or stable references; never credentials or unnecessary personal data.
- Result code and reconciliation status; store payloads only where separately justified and protected.
- Human approver if applicable.
- Error or warning.
Stop Conditions
Pause the workflow immediately if any of these occur:
- Wrong recipient, contact, customer, or account.
- Duplicate business action.
- Missing approval.
- Sensitive data sent to an unapproved destination.
- Authentication or permission error.
- Unexpected cost or rate-limit spike.
Launch Decision
- Approved by:
- Date:
- First review date:
- Rollback path:
- Credential revocation path:
- Kill-switch owner and test date: