← All chaptersChapter 6 of 8

Integrations and operational automation

You only connect AI to systems after processes, data, and exceptions are manageable.

After this chapterYou can design an integration with minimal rights, reliable transfer, approval, and runbook.
Your progress0 of 48 lessons
6.1

The process before automation

Do not automate an unclear process; make decisions and exceptions visible first.

Map the trigger, input, transformations, decisions, actions, systems and waiting times. Record where value is created and where handovers lose information or efficiency.

Remove unnecessary steps before technology. Measure variation and exceptions; an unstable process requires standardization or limited assistance first.

Then choose how much technology is needed. With manually supplied source context, you paste approved text into the chat yourself, such as Noor’s fact sheet. With RAG (retrieval-augmented generation), a system first retrieves relevant source passages and uses them in its answer; check both the selection and the answer.

An agent can choose follow-up steps or tools within the permissions granted. MCP is a protocol through which applications can offer tools and context; it is not itself an agent or a quality guarantee. These concepts can be combined. A read-only connection carries different risks from one that sends messages.

  • Trigger
  • Input
  • Decision
  • System
  • Exception
  • Waiting time

Terms in plain language

As-is / to-be
The current way of working and the proposed way of working.
RAG
Building answers using source passages that a system has first retrieved.
Agent
An AI system that can choose follow-up steps or tools to carry out a goal, within configured limits.
MCP
Model Context Protocol: a standardised way to connect tools and context to AI applications.
How you can use this

An invoice flow slows down due to unclear approval boundaries, not because of text entry.

Try this prompt
Model [process] as-is and to-be with trigger, steps, decisions, systems, waiting time, errors, and exceptions. Eliminate waste before AI.
Knowledge check

Observation of a quotation process shows that cases mostly wait for unclear pricing approval. There is little typing. What do you improve first?

Your practical exercise

Draw the process for Noor’s draft replies. For the basic route, create ten fictional case cards: four ordinary product questions, two without a suitable source, two with conflicting source information, one with a missing link to the question, and one with a timeout. Walk through each card on paper and count the routes. Completion check: the trigger, review and fallback are recognisable and the counts agree. These are design simulations, not observed business cases. Real observation is a later step before actual implementation.

Source for this lesson

OpenAI — Retrieval
Technical background on retrieving relevant source passages. The course route uses manually supplied text and does not require this API.
Checked: 2026-09-08

OpenAI — MCP and Connectors
Connections to external services, tools and approvals; conceptual explanation, with no mandatory integration.
Checked: 2026-09-08

6.2

Connect calendar, email, CRM and spreadsheets

For each system, define the source, identity, permissions, fields and rules for writing data back.

Make clear who has access to which mailbox, calendar, records, or sheets. Separate reading and writing and define field mapping, source of truth, and conflict behavior.

Use minimal scopes and a test environment. Log actions without unnecessary sensitive content and confirm external communication or critical changes.

  • System
  • Identity
  • Scope
  • Field mapping
  • Source of truth
  • Write gate

Terms in plain language

CRM
A system for customer relationships and associated agreements.
Field mapping
Documenting which field in one system corresponds to which field in another.
Access scope
The limits on which data or actions an integration may use.
How you can use this

A CRM connection reads assigned leads and writes a draft note, not a final deal status.

Try this prompt
Design the connection between [systems]. Specify identity, read and write rights, field mapping, source of truth, conflict rule, logging, and approval gate.
Knowledge check

An integration finds different delivery addresses in the CRM and order system. The order system is the agreed source for this order, but the CRM change appears more recent. What should the conflict rule do?

Your practical exercise

Draw one data record from source to destination and back.

6.3

Choosing automation levels

Start with assistance and increase autonomy only based on evidence and recoverability.

Use a ladder: inform, draft, recommend, execute after approval, limited automatic and autonomous within hard boundaries. Error impact, detectability and reversibility determine the level.

Record KPIs, guardrails and fallback. A successful low-risk pilot does not prove that financial or public actions are appropriate.

  • Assistance
  • Recommendation
  • Approval
  • Autonomy
  • Guardrails
  • Fallback
How you can use this

Support answers are first proposed before proven low-risk categories proceed automatically.

Try this prompt
Place [tasks] on an automation ladder. Justify with impact, detectability, reversibility, and evidence. Provide promotion and fallback criteria.
Knowledge check

A pilot produces good draft answers to simple opening-hours questions. The team now wants to execute refunds automatically as well. What is needed?

Your practical exercise

Classify ten process steps and choose one candidate for a higher automation level.

6.4

Validation, duplicate processing and recovery

An integration must safely detect, block, and recover from errors.

First check required fields, formats, business rules and the source version. Idempotency means that repeating the same intended action does not repeat its intended effect, such as creating a second booking. Reuse the same action key for a retry. The receiving application or API must actually recognise that key and reliably track the associated status. Merely supplying an order number or writing “do not execute twice” in a prompt does not prevent a duplicate action.

After a timeout, an action may already have succeeded even though confirmation is missing. Check the status or retry using demonstrably supported idempotency, within the agreed validity period. Downstream systems must also prevent duplicate execution. If that protection is missing and repetition could cause harm, stop for review. Document the retry limit, recovery route and necessary audit fields.

  • Schema
  • Business rule
  • Unique key
  • Retry
  • Quarantine
  • Compensation

Terms in plain language

Timeout
The time allowed for a response has expired; the action may nevertheless have been executed.
Quarantine
Setting an uncertain case aside for review.
Compensation
An explicit recovery action after a partially completed process; not every action can be fully reversed.
How you can use this

A fictional booking system records the action key and completed booking together. A repeated request with the same key returns the existing result. Check that the integration you use actually supports this.

Try this prompt
Create error and recovery rules for [integration]: validation, idempotency key, time-out, retry, quarantine, compensation, and audit fields.
Knowledge check

After a timeout, you do not know whether a booking was made. The request contained an order number, but the receiving service’s support for idempotency is unconfirmed. What do you do?

Your practical exercise

Simulate a time-out after a partially successful action.

Source for this lesson

AWS – Idempotent operations
The executing system must reliably process the key, status and effects together.
Checked: 2026-09-07

Stripe – Idempotent requests
A specific API example; support and retention periods are not universal.
Checked: 2026-09-07

6.5

Human approval as a pattern

An approval step shows what changes, why, and with what risk.

The reviewer receives source data, proposed action, changes, uncertainty, and consequences. Only present meaningful decisions to limit approval fatigue.

Determine authority, confirmation fields, and reason for rejection. Critical actions do not receive implicit approval on timeout.

  • Decision context
  • Change
  • Risk
  • Reviewer
  • Rejection
  • Timeout
How you can use this

A quote check shows the price source, margin deviation, and customer conditions next to the send button.

Try this prompt
Design an approval screen for [action] with source, proposal, modification, uncertainty, consequences, confirmation fields, rejection, and timeout.
Knowledge check

A reviewer sees only an Approve button for a revised quotation. The changed amounts and source version are not visible. What is missing?

Your practical exercise

Design the approval of a draft reply on paper. If possible, have someone who did not create the design read it. Solo: walk through three fictional cases: an appropriate source-based answer, an incorrect delivery promise and an absent reviewer. Completion check: the source and proposed action are visible; the delivery promise is rejected; no sending takes place without an authorised reviewer. Note that walking through it alone does not yet prove that a new user understands it.

6.6

Monitoring, incidents and runbooks

A production flow needs signals, thresholds, an owner, and a recovery procedure.

Monitor volume, success, latency, error categories, corrective work, guardrails, and costs. Combine technical and business metrics; technically green can hide poor customer outcomes.

The runbook describes diagnosis, pausing, manual fallback, communication, recovery, and post-incident review. Practice before a real outage.

For a possible personal data breach: immediately limit the harm, safely preserve the necessary incident evidence and alert the designated responsible person. A breach can also involve loss, unauthorised alteration or unavailability of personal data. An ordinary outage with no personal data affected is not automatically a data breach. Record the time of awareness, affected data, risk, measures and notification decision.

The processor notifies the controller without undue delay. The controller assesses notification to the competent supervisory authority: without undue delay and, where possible, no later than 72 hours after becoming aware, unless a risk to individuals is unlikely. Do not wait until the third day. Where a high risk is likely, direct information to the people concerned may also be required. Missing details can be supplemented later where necessary; document delays and decisions. Check whether the Belgian Data Protection Authority is competent, then use its notification portal.

  • Signal
  • Threshold
  • Alarm
  • Pause
  • Fallback
  • Postmortem

Terms in plain language

Runbook
An actionable procedure for failures, pausing and recovery.
Tabletop exercise
Working through an incident on paper or in discussion without disrupting real systems.
Postmortem
A review of an incident to document causes and improvements.
How you can use this

A price flow pauses with a rising override rate, even if the API remains available.

Try this prompt
Create a monitoring plan and runbook for [workflow] with metrics, thresholds, alert route, kill switch, fallback, communication, and postmortem.
Knowledge check

Every API request succeeds technically, but reviewers increasingly have to correct wrong prices. Which monitoring decision fits?

Your practical exercise

Walk through a fictional incident on paper: a draft reply contains an unauthorised delivery promise and is caught before sending. Record pausing, source verification, the responsible person, manual fallback and the condition for restarting. You may time your exercise walkthrough; call this exercise time, not recovery time for a production environment. Completion check: every step has an owner and evidence. Keep the process map, approval agreement and runbook with row H6 and note what was only simulated.

Source for this lesson

EDPB – Data breaches
Types of personal data breaches, documentation, roles, phased information and notification to affected individuals.
Checked: 2026-09-08

Belgian Data Protection Authority – Reporting and managing a data breach
Conditional notification duty, deadline after awareness, competent supervisory authority and notification portal.
Checked: 2026-09-08

Worked example

The confirmation is missing: what actually happened?

Fictional practice material; incorrect answers have been created deliberately for this exercise.

This is a complete simulation using an invented CRM. There is no access to real tools and nothing is sent. Following human approval, Atelier Noor wants to register one draft as a follow-up task without creating duplicate tasks.

Input

An employee approves exactly version 3 of the task text for practice case DEMO-104. The trial integration submits that text with action key NOOR-DEMO-104-V3. The CRM processes the task, but the connection drops before confirmation returns. The sender sees a timeout: the outcome is unknown to them. For this fictional CRM variant, it has been demonstrated in advance that the service recognises the same key and content within the agreed validity period and returns the earlier result.

Deliberately flawed practice answer

“A timeout means failure. Create a new action key and try again. Put in the prompt that no duplicate task may be created.”

Check

The first execution may already have succeeded. A new key can therefore cause a second task. A prompt instruction does not force the receiving application to block duplicates. That application must reliably track the key, execution and result, including concurrent requests. Checking only before writing may be insufficient when two requests arrive simultaneously.

Improved result

“Mark the outcome as unknown. Query the status where possible. Retry only through the demonstrably supported procedure: the same key, the same approved content and within the agreed validity period and retry limit. The practice service returns task T-501; no second task is created. Retain necessary audit data and show the employee the outcome. If this protection is absent or uncertain, stop for review. Changed text requires a new assessment; do not silently replace it during a retry.”

Try it yourself

Another fictional integration can only send email. It supports neither an action key nor a reliable status query. A timeout follows sending. A second message would confuse the customer. What does the workflow do now?

View the model answer

Stop automatic retries and report an unknown sending status. Have an authorised employee check the available sending records and decide what is needed. “Try again” is not a safe default here; an invented key offers no protection without support either.

Chapter assignment

Bring everything together

Design a single integration with process map, permissions, mapping, automation level, error handling, approval, and runbook.

Maximum 10,000 characters per note.

Progress and notes are stored only in this browser on this device. Do not enter sensitive data. Download your notes regularly. This course sets no automatic expiry date. You can delete the data through your browser’s site-data settings; export anything you wish to keep first. Browser settings or cleanup may erase it earlier. These local notes are not sent to Finaudax.