Keep Permissions Narrow and Auditable
Prefer app-specific service accounts and the smallest necessary scopes. Document who owns each connection, when it was last tested, and where alerts are delivered. That transparency speeds incident response, satisfies audits, and protects personal inboxes from unintended automation spillover.