Identify whose account the task needs
| Connection | Example | Required decision |
|---|---|---|
| Business owner’s account | Book a client into the advisor’s calendar. | Which actions the published agent may take in that account. |
| Each customer’s account | Analyze a client’s own analytics property. | How that customer authorizes access and how their data stays separate. |
| Customer-provided files | Analyze an exported report uploaded for a session. | Which files are needed, who can read them, and how they are handled. |
Describe the customer flow to the Builder
A provider appearing in the app catalog is not proof that end-user authorization is available for every published agent. Verify the exact provider, permissions, and account flow.
Example request
My consulting clients need to analyze their own website traffic. Check whether we can let each client authorize the relevant analytics account. Keep each client’s data separate. If that connection flow is unavailable, propose a workflow using a report they upload.
Verify consent, separation, and disconnect behavior
Do not ask customers to paste passwords or private tokens into an ordinary message. Use the configured authorization flow or an appropriate data upload path.
- The client knows which account and data the agent will use.
- Only the required read or write permissions are granted.
- One client cannot see or operate on another client’s data.
- The experience handles revoked or expired authorization.
- The agent explains when an export is a snapshot rather than live data.