- Owner or Admin access to connected-app settings
- An approved business purpose, data scope, and integration owner
- Provider administration access and a safe test environment
- A revocation and continuity plan
What Connected apps covers today
Open Settings → Connected apps. The page summarizes WhatsApp Business and Shared email. Each row shows health, last successful activity, installer identity when recorded, and a plain-language data-access description. It links to the channel-specific setup where credentials and tests belong.
Connected apps is an inventory and review surface, not an app marketplace. If the integration you need is not listed, contact WRKZY Support to confirm the supported path. Do not create, copy, or share credentials as a workaround.
Run a quarterly connection review
- Confirm the active workspace.
- Open Connected apps and refresh Settings health.
- For each row, record whether it is Healthy, Needs attention, Critical, Checking, or Unavailable.
- Compare Last successful activity with expected channel usage.
- Confirm Installed by is a current, accountable teammate.
- Read Data accessed and confirm the business purpose still requires it.
- Select Test or manage and run the channel-specific diagnostic.
- Review dependent team-inbox routes, automations, templates, and campaigns before disconnecting anything.
| Signal | Interpretation | Next action |
|---|---|---|
| Healthy with recent activity | Connection and observed use align | Keep; record next review date |
| Healthy with no expected recent activity | May be dormant but valid | Confirm business owner and dependencies |
| Needs attention | A provider, sender, forwarding, or delivery issue exists | Open the channel page and diagnose |
| Unavailable | WRKZY could not load complete metadata | Retry before changing the integration |
| Installer has left | Ownership and credential continuity are at risk | Transfer operational responsibility and rotate provider access where applicable |
Data boundaries
WhatsApp may access message content, sender identity, and delivery events. Shared email may access email content, recipients, delivery, and reply metadata. This summary does not reveal provider secrets. Keep access reviews focused on purpose, scope, and operational ownership—not copying tokens into an inventory document.
Review a connection as an operating dependency
- 01PurposeApproved purpose and owner
A current teammate is accountable for why the provider connection exists.
- 02ScopeData scope and dependencies
Messages, recipients, routes, templates, campaigns, and automations match the approved purpose.
- 03EvidenceLive health and activity
Provider diagnostics and recent successful activity prove more than a saved connection row.
- 04DecideReview decision
Keep, repair, rotate responsibility, or plan removal based on evidence and customer impact.
- 05ControlControlled change and verification
Protect secrets, preserve a fallback route, then verify dependent workflows after any change.
Disconnect safely
There is no one-click disconnect on the summary page. Open the corresponding WhatsApp or Shared email page. First identify default sender or mailbox status, inbound routes, open customer work, pending campaigns, automation references, templates, and required evidence retention. Put an alternative route in place, pause dependent sends, then remove the connection from its own settings page.
Recovery
If metadata is partial or stale, select Retry and compare the channel's live diagnostics. A missing installer name does not prove an unauthorized installation; it may mean attribution is unavailable. Escalate with workspace slug, connection type, displayed health, last activity, installer label, test time, and redacted error—never with OAuth tokens, SMTP passwords, webhook secrets, or verification codes.
- Every connection has a current business owner
- Data access still matches purpose
- Last activity and live diagnostic agree
- Dependencies mapped before removal
- Provider secrets excluded from review evidence
- Next review date recorded