<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Concerns raised by Security Team about our recipes in Workato Pros Discussion Board</title>
    <link>https://systematic.workato.com/t5/workato-pros-discussion-board/concerns-raised-by-security-team-about-our-recipes/m-p/10288#M4098</link>
    <description>&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; 1. Platform Configuration &amp;amp; Architecture (You're on the Right Track)&lt;BR /&gt;Since you're already involving a Security Architect — that's an excellent start.&lt;BR /&gt;Key security levers to lock down the platform:&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;a&lt;/STRONG&gt;. Workspace Governance&lt;BR /&gt;Use separate Workato workspaces per environment (Dev, QA, Prod).&lt;BR /&gt;Restrict user access per workspace using role-based access (e.g., developer can only access Dev).&lt;BR /&gt;Enforce SCIM/SAML for identity federation and user lifecycle management.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;STRONG&gt;b&lt;/STRONG&gt;. Secrets &amp;amp; Credentials Management&lt;BR /&gt;Store credentials in Environment Properties or Connections with limited visibility.&lt;BR /&gt;Avoid hardcoding tokens or secrets in steps or log statements.&lt;BR /&gt;Use Vault integrations if possible (e.g., AWS Secrets Manager or HashiCorp Vault).&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;c&lt;/STRONG&gt;. Audit Logging&lt;BR /&gt;Enable Recipe Lifecycle Logs and Job History retention.&lt;BR /&gt;Periodically export audit logs for compliance (via API or webhook).&lt;BR /&gt;Track changes in critical recipes and who made them.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;d&lt;/STRONG&gt;. Data Residency &amp;amp; Isolation&lt;BR /&gt;Use On-prem Agents or Private Agents if sensitive systems are involved.&lt;BR /&gt;Review whether PII or financial data is processed in recipes — Workato may not be certified for all regulatory frameworks unless on Enterprise+ plans.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; 2. Recipe Security &amp;amp; Best Practices&lt;BR /&gt;This is the area where security gaps often slip through — especially as recipes are built rapidly by different team members.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;a&lt;/STRONG&gt;. Standardize Development Practices&lt;BR /&gt;Create a recipe template library: standardized patterns for error handling, logging, API call hygiene, etc.&lt;BR /&gt;Build modular callable recipes to separate logic and limit exposure.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;b&lt;/STRONG&gt;. Introduce Recipe Reviews&lt;BR /&gt;Adopt a peer review workflow before a recipe goes to production.&lt;BR /&gt;Use the “comments” feature to document assumptions, tokens used, and external APIs called.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;c&lt;/STRONG&gt;. Implement Error &amp;amp; Exception Logging&lt;BR /&gt;Log errors to a central system (like Splunk, Datadog, or Snowflake).&lt;BR /&gt;Avoid leaking PII or secrets into logs.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;d&lt;/STRONG&gt;. Data Flow Documentation&lt;BR /&gt;Document which recipes touch sensitive data — who can view/edit them, what endpoints they call, what systems they write to.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; 3. Security Monitoring&lt;BR /&gt;Use external monitoring platforms (e.g., Dynatrace, Splunk) to track anomalies or failures across recipes.&lt;BR /&gt;Optionally build recipes that log metrics and usage into a security lake (Snowflake, etc.).&lt;/P&gt;&lt;P&gt;🧩 Bonus: Establish a Workato Center of Excellence (CoE)&lt;BR /&gt;Maintain an internal portal/an Excel sheet for:&lt;BR /&gt;Best practices&lt;BR /&gt;Approved connectors&lt;BR /&gt;Templates&lt;BR /&gt;Security policies&lt;BR /&gt;Enforce mandatory onboarding for new Workato users to cover security.&lt;/P&gt;</description>
    <pubDate>Mon, 23 Jun 2025 10:44:25 GMT</pubDate>
    <dc:creator>shivakumara</dc:creator>
    <dc:date>2025-06-23T10:44:25Z</dc:date>
    <item>
      <title>Concerns raised by Security Team about our recipes</title>
      <link>https://systematic.workato.com/t5/workato-pros-discussion-board/concerns-raised-by-security-team-about-our-recipes/m-p/10282#M4096</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;We love our Workato deployment and the experience of implementing and growing recipes that support the business in the past two years.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our organizations is has over 4000 employees with many different software both on-prem and cloud/saas, thus we have over a 1000 recipes already and our Workato team keeps growing (4 members already).&lt;/P&gt;&lt;P&gt;Recently, security has been nagging us about the risks included in No-Code platforms and our recipes.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What are you doing to tackle Workato security?&lt;/STRONG&gt; Both from a platform configuration/architecture perspective (we are doing this manually with a security architect from Security team), and from a recipe prespective (No solution/process just yet).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Keen on hearing your opinion!&lt;/P&gt;</description>
      <pubDate>Sun, 22 Jun 2025 16:34:12 GMT</pubDate>
      <guid>https://systematic.workato.com/t5/workato-pros-discussion-board/concerns-raised-by-security-team-about-our-recipes/m-p/10282#M4096</guid>
      <dc:creator>TLors_IN</dc:creator>
      <dc:date>2025-06-22T16:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: Concerns raised by Security Team about our recipes</title>
      <link>https://systematic.workato.com/t5/workato-pros-discussion-board/concerns-raised-by-security-team-about-our-recipes/m-p/10288#M4098</link>
      <description>&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; 1. Platform Configuration &amp;amp; Architecture (You're on the Right Track)&lt;BR /&gt;Since you're already involving a Security Architect — that's an excellent start.&lt;BR /&gt;Key security levers to lock down the platform:&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;a&lt;/STRONG&gt;. Workspace Governance&lt;BR /&gt;Use separate Workato workspaces per environment (Dev, QA, Prod).&lt;BR /&gt;Restrict user access per workspace using role-based access (e.g., developer can only access Dev).&lt;BR /&gt;Enforce SCIM/SAML for identity federation and user lifecycle management.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;STRONG&gt;b&lt;/STRONG&gt;. Secrets &amp;amp; Credentials Management&lt;BR /&gt;Store credentials in Environment Properties or Connections with limited visibility.&lt;BR /&gt;Avoid hardcoding tokens or secrets in steps or log statements.&lt;BR /&gt;Use Vault integrations if possible (e.g., AWS Secrets Manager or HashiCorp Vault).&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;c&lt;/STRONG&gt;. Audit Logging&lt;BR /&gt;Enable Recipe Lifecycle Logs and Job History retention.&lt;BR /&gt;Periodically export audit logs for compliance (via API or webhook).&lt;BR /&gt;Track changes in critical recipes and who made them.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;d&lt;/STRONG&gt;. Data Residency &amp;amp; Isolation&lt;BR /&gt;Use On-prem Agents or Private Agents if sensitive systems are involved.&lt;BR /&gt;Review whether PII or financial data is processed in recipes — Workato may not be certified for all regulatory frameworks unless on Enterprise+ plans.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; 2. Recipe Security &amp;amp; Best Practices&lt;BR /&gt;This is the area where security gaps often slip through — especially as recipes are built rapidly by different team members.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;a&lt;/STRONG&gt;. Standardize Development Practices&lt;BR /&gt;Create a recipe template library: standardized patterns for error handling, logging, API call hygiene, etc.&lt;BR /&gt;Build modular callable recipes to separate logic and limit exposure.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;b&lt;/STRONG&gt;. Introduce Recipe Reviews&lt;BR /&gt;Adopt a peer review workflow before a recipe goes to production.&lt;BR /&gt;Use the “comments” feature to document assumptions, tokens used, and external APIs called.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;c&lt;/STRONG&gt;. Implement Error &amp;amp; Exception Logging&lt;BR /&gt;Log errors to a central system (like Splunk, Datadog, or Snowflake).&lt;BR /&gt;Avoid leaking PII or secrets into logs.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;d&lt;/STRONG&gt;. Data Flow Documentation&lt;BR /&gt;Document which recipes touch sensitive data — who can view/edit them, what endpoints they call, what systems they write to.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; 3. Security Monitoring&lt;BR /&gt;Use external monitoring platforms (e.g., Dynatrace, Splunk) to track anomalies or failures across recipes.&lt;BR /&gt;Optionally build recipes that log metrics and usage into a security lake (Snowflake, etc.).&lt;/P&gt;&lt;P&gt;🧩 Bonus: Establish a Workato Center of Excellence (CoE)&lt;BR /&gt;Maintain an internal portal/an Excel sheet for:&lt;BR /&gt;Best practices&lt;BR /&gt;Approved connectors&lt;BR /&gt;Templates&lt;BR /&gt;Security policies&lt;BR /&gt;Enforce mandatory onboarding for new Workato users to cover security.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jun 2025 10:44:25 GMT</pubDate>
      <guid>https://systematic.workato.com/t5/workato-pros-discussion-board/concerns-raised-by-security-team-about-our-recipes/m-p/10288#M4098</guid>
      <dc:creator>shivakumara</dc:creator>
      <dc:date>2025-06-23T10:44:25Z</dc:date>
    </item>
    <item>
      <title>Re: Concerns raised by Security Team about our recipes</title>
      <link>https://systematic.workato.com/t5/workato-pros-discussion-board/concerns-raised-by-security-team-about-our-recipes/m-p/10316#M4110</link>
      <description>&lt;P&gt;Thank you so much&amp;nbsp;&lt;a href="https://systematic.workato.com/t5/user/viewprofilepage/user-id/8685"&gt;@shivakumara&lt;/a&gt;&amp;nbsp;for this very extensive answer! Very helpful to have this comprehensive outlook.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any solution by Workato / commercial that can assist with receipe code review / vulnerabilities?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2025 12:08:12 GMT</pubDate>
      <guid>https://systematic.workato.com/t5/workato-pros-discussion-board/concerns-raised-by-security-team-about-our-recipes/m-p/10316#M4110</guid>
      <dc:creator>TLors_IN</dc:creator>
      <dc:date>2025-06-26T12:08:12Z</dc:date>
    </item>
    <item>
      <title>Re: Concerns raised by Security Team about our recipes</title>
      <link>https://systematic.workato.com/t5/workato-pros-discussion-board/concerns-raised-by-security-team-about-our-recipes/m-p/10322#M4113</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://systematic.workato.com/t5/user/viewprofilepage/user-id/12047"&gt;@TLors_IN&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;While there isn’t a specific recipe code review feature, Workato offers an accelerator called AQS (Automation Quality &amp;amp; Security) Framework, which helps standardize and automate best practices for quality and security across your automations.&lt;BR /&gt;&lt;BR /&gt;Thanks and Regards,&lt;BR /&gt;Shivakumara K A&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Jun 2025 17:02:22 GMT</pubDate>
      <guid>https://systematic.workato.com/t5/workato-pros-discussion-board/concerns-raised-by-security-team-about-our-recipes/m-p/10322#M4113</guid>
      <dc:creator>shivakumara</dc:creator>
      <dc:date>2025-06-28T17:02:22Z</dc:date>
    </item>
  </channel>
</rss>

