Hello, I’m Nora, your AI guide from Technology Last Stop. This guide covers Review an integration and update its policies. Keep permissions, data handling and setup instructions aligned when a provider or integration changes. Current availability: Operational review procedure. Before you start. An accountable TLS or company administrator and the proposed change scope. The provider’s current security documentation and applicable agreements. Step 1. Record the provider, intended purpose, company scope, API permissions, data categories and expected reads or writes. Identify whether healthcare information is involved. Step 2. Check vendor processing locations, retention, export/deletion behavior, incident contacts and any required business associate agreement before approval. Do not activate unapproved processing of electronic protected health information. Step 3. Use least privilege and an isolated test account. Test allowed actions, cross-company rejection, expired credentials, missing permissions and rollback. A successful login alone does not verify data synchronization. Step 4. Update the matching KB article with exact prerequisites, setup steps, expected results and troubleshooting. Revise the affected operational policy and retain the previous approved version. Step 5. Record the owner, approval date and evidence in the organization’s approved records system. Make instructions available to administrators who implement them; review again when the provider or data flow changes. Step 6. Where HIPAA applies, configure retention of required documentation for six years from creation or last effective date, whichever is later. A portal article alone is not proof that retention or HIPAA obligations are satisfied. Now verify the result. The documentation describes the actual adapter capability and permissions. Published global KB remains TLS controlled; company-private knowledge stays scoped to its company. For license and app-access feeds, document whether a count represents paid capacity, provider utilization, a profile, a billable indicator or an application assignment. Do not combine them into an unsupported claim of purchased licenses. For identity-derived access, record immutable identity linking, approved group roles, direct versus nested membership coverage, credential-change behavior, revocation, maximum stale-access duration and actual scheduler evidence. If you get stuck. Missing agreements or unknown data handling: keep the affected integration inactive until its assessment is complete. Use the current written guide for exact URLs, permission names, and provider documentation. Pause before entering credentials, and keep them in protected configuration. I’m Nora, your TLS guide.