1. Separate rules from judgement.

Start with the trigger: an incoming message, an uploaded file or a change in a business record. Then list the actions that follow. A workflow is the sequence connecting those events and actions. Use deterministic rules, meaning rules that produce the same result from the same input, wherever the decision is already clear. AI is more relevant when the input varies in language or structure.

For an enquiry-routing workflow, ordinary code can check whether an email address exists and whether a required field is blank. A language model might suggest a category from the message. Keep that suggestion separate from the rule that assigns the record. If the categories are unclear, improve their definitions before asking a model to choose between them.

2. Choose a platform that fits the systems.

Microsoft Power Automate provides a workflow environment with connectors and approval mechanisms. It is worth assessing when work already depends on Microsoft services. Review connector permissions, data loss prevention controls and applicable licensing. A convenient connector does not remove the need to understand what information it can read or change.

n8n provides a node-based approach to connecting services and transforming data. It can suit teams that want visible workflow logic and more control over deployment. Hosting choice affects responsibilities for updates, backups, secrets and access. Check the product’s licence and commercial terms for the intended use rather than assuming a deployment model is unrestricted.

Direct API integration can be appropriate when a workflow needs precise transaction handling or a specialised user interface. It usually places more maintenance responsibility on the implementation team. Compare platforms using the actual systems involved, required authentication methods, error handling and ownership after delivery. Avoid choosing solely from the appearance of a workflow diagram.

3. Place a boundary around every action.

A model-generated instruction should not become permission to do anything the connected account can do. Give the integration only the access required for the task. Validate proposed actions against an allowed set, check the destination and require structured fields. Treat text in emails and attachments as untrusted input, even when it contains instructions addressed to the assistant.

Use human approval for consequential actions such as sending external communications, changing payment details or deleting records. The reviewer should see the proposed action and its supporting information, not merely an approval button. Approval also needs an expiry and a record of who authorised the action. Do not interpret a model’s confident wording as evidence that approval is unnecessary.

4. Design retries without duplicate work.

An external service may time out after completing a request. Retrying blindly can create duplicate records or send the same message again. Idempotency means arranging an operation so that repeating the request does not repeat its effect. Use unique request identifiers, status checks and duplicate detection where the connected system supports them.

Separate temporary failures from invalid inputs. A temporary connection problem may justify a controlled retry; a missing customer identifier needs review. Keep an exception queue with enough context to diagnose the issue without copying unnecessary personal data. Define what happens when a workflow pauses halfway through and which actions can be safely reversed.

5. Make the workflow maintainable.

Record triggers, dependencies, access roles and the owner of each connection. Test with incomplete messages, duplicate events, unavailable services and revoked credentials. Check that logs show what happened without exposing secrets or full documents. Include a way to pause the workflow independently of the business system it supports.

Our automation service can be scoped to process mapping, integration design, implementation and handover documentation. The agreed brief should name the actions that may run automatically and those that require review. Bring a description of the workflow and its connected applications to the first conversation; access credentials should be shared only through an agreed secure process.

A useful acceptance check

Ask whether an authorised employee can explain a failed run, stop the workflow and recover without causing the same action twice.