Credential Handling
Keep credentials separate
Section titled “Keep credentials separate”Store client secret values in your organization’s approved secret manager. Tenant and application IDs identify the connection but are not replacements for the secret value. Do not embed credentials in the Drive ID map.
Manage the lifecycle
Section titled “Manage the lifecycle”Record the owner, expiration, and rotation plan. Follow the verified application procedure when updating credentials and test the replacement connection before retiring the old credential.
Redact diagnostics and screenshots
Section titled “Redact diagnostics and screenshots”Remove passwords, access tokens, secret values, private sharing links, customer data, and confidential file contents. Capture future screenshots only in an approved test environment.
Product handling remains under review
Section titled “Product handling remains under review”The integration’s encryption, credential storage, access controls, retention, and revocation behavior must be confirmed from the actual repository. No such claims are made here.
Related: client secrets and support.