API and Integrations shows connected services, AI providers, API keys, and webhooks supported by the workspace. A listed integration can still require provider credentials, plan eligibility, permissions, or an administrator to complete setup.
Record an owner and business purpose for every connection.
Create a key only for a named integration, grant the least available scope, store the secret in an approved secret manager, and rotate or revoke it when ownership changes. The secret may be shown only once.
Never paste a production secret into a matter, document, support description, or source file.
Choose only the events the receiver needs, use an HTTPS endpoint, verify signatures where supported, handle retries idempotently, and monitor failures. Test with a controlled record before relying on the event for a legal or financial workflow.
Embeds present configured external tools inside the workspace. They retain the external service's own authentication, data practices, and availability. Only embed a service the firm has approved and whose framing policy supports it.
