DEV Community

Ujjwal Dubey
Ujjwal Dubey

Posted on

Watch the Access Request: A Least-Privilege Checklist for Choosing an Automation Agency

Disclosure: I run NxFlowAI, an automation agency. This checklist applies to any vendor, including us. It is practical guidance, not a security standard.

If an automation agency will touch your production webhooks, CRM and messaging accounts, the way they ask for access tells you a lot about how they will run your systems. This is a practical angle on how to choose an AI automation agency when webhooks are in play: watch the access request before you watch the demo.

Red flags in the first access request

  • "Just send us the admin password." Shared credentials mean no audit trail and no clean way to remove them later.
  • "Add us as owner of the Meta business portfolio." They rarely need ownership; they need specific assets.
  • A single API key with full scope for everything, "to save time".
  • No question about which environment to use for testing.

What a careful agency asks for instead

access_request:
  crm:
    type: integration_user            # dedicated user, not a person's login
    scopes: [contacts.read, contacts.write, deals.read]
    named_contact: "builder name"
  whatsapp:
    asset: phone_number_and_waba      # assigned asset, your portfolio stays yours
    role: developer_or_partner_access
  webhooks:
    endpoint_owner: client            # or documented if hosted by agency
    signing_secret: rotated_after_handover
  secrets:
    storage: client_vault_or_env      # never in chat or email
  test_environment: sandbox_crm_or_test_pipeline
  expiry_review: at_go_live_and_quarterly
Enter fullscreen mode Exit fullscreen mode

You do not need to use this format. You need the answers to exist.

Questions to ask during selection

  1. Which exact permissions do you need, and why each one?
  2. Will you create a dedicated integration user, or use a person's account?
  3. Where will API keys and webhook secrets be stored?
  4. Who on your team will have access, by name?
  5. How do you test without touching live customers?
  6. What happens to your access when the project ends?

Offboarding is part of the evaluation

Ask them to describe offboarding before you onboard them:

  • Rotate every key and webhook secret they knew.
  • Remove their users and asset assignments.
  • Transfer any hosted functions or workflows into your accounts.
  • Confirm in writing what they still hold, if anything.

An agency that has a ready answer here has usually done it before, cleanly. One that has never thought about it will also not have thought about what happens when a webhook secret leaks.

Why this predicts delivery quality

Least-privilege access, named users and a test environment are the same habits that produce idempotent handlers, clear logs and reversible changes. Teams that are casual about access tend to be casual about retries and partial writes too.

We ask for scoped access at the start of a 72-hour audit and hand back a list of everything we touched at the end.

Top comments (0)