A working interface can still expose too much when it uses broad service credentials or loses the identity of the initiating person. Access design belongs in the integration contract. A system handoff can carry a correct record while giving the receiving service more access than its task requires. Map the human and service identities involved in creating, approving and reading that record. Include background jobs and support tools because they can cross the same boundary.
What good engineering looks like
Which person or service initiated the action, what may it do and what identity must the receiving system see? Answer this for a named workflow and an accountable team. Identify the information needed at the moment of decision, the system that can settle a dispute, and the route for correcting dependent copies. The technical design should make those business rules visible to the people who operate and support the handoff.
-
Give each integration a distinct service identity and a named owner.
-
Limit permissions to the required operations and data scope.
-
Preserve the initiating context and test revocation, expiry and audit trails.
-
A named owner for a rejected, delayed or repeated item.
-
Evidence that the receiving system applied the intended business state.
A practical starting point
-
Choose one real case and write down its trigger, expected outcome and responsible team.
-
Review one normal access path and one revoked-access case.
-
Check which identity is presented, what it may do, how credentials are rotated, and what evidence remains after a denied request. A successful integration test should not assume that broad shared credentials are acceptable.
-
Record what the test exposed, who will resolve each open question and how the fix will be checked.
Keep the first design small enough to review with the people who run the process. Test an exception alongside the normal case. A successful transport test shows that data moved; it does not by itself prove that the receiving team can make the right decision or recover from a partial failure.
The decision to make
The right mechanism depends on the systems and risk involved. Do not pass a human credential between services as a shortcut. Decide what level of timing, traceability and recovery this workflow actually needs. Document assumptions that remain untested and revisit the choice when a partner, process or business rule changes. The point is a dependable operating decision, not simply a working interface.
Explore Algoza's related services: https://algoza.co.za/services/integration