WorkatoSight Security Policy
Last updated: 2026-06-26
Platform
Section titled “Platform”WorkatoSight runs on Atlassian Forge for Confluence Cloud. It uses Forge-hosted storage, Forge secret storage, Confluence product APIs, and backend egress to customer-configured Workato hosts.
Permission model
Section titled “Permission model”Confluence page and space reads use Confluence product APIs so customer permissions continue to apply. Configuration, connection tests, refresh, and coverage scan actions require space-admin authority before WorkatoSight changes app state or calls live Workato APIs.
Secret storage
Section titled “Secret storage”Workato credentials are stored with Forge secret storage and are not returned to the frontend after save. Support tickets, screenshots, page content, and logs must not include credential values.
Cache-first reads
Section titled “Cache-first reads”Dashboards, macros, bylines, and ordinary page reads use cached Workato facts and do not call Workato live APIs. Live Workato access happens through explicit admin-approved refresh or test actions, or through the licensed scheduled refresh worker for configured spaces.
Egress and validation
Section titled “Egress and validation”The app manifest limits backend egress to Workato hosts. App validation also rejects non-HTTPS origins, credential-bearing URLs, paths, query strings, fragments, localhost, IP literals, and non-Workato hosts.
Vulnerability reporting
Section titled “Vulnerability reporting”Report suspected vulnerabilities through https://flowdence.io/support or security [at] flowdence.io. Include the affected app, tenant, space, timestamp, sanitized reproduction steps, and impact. Do not include secrets, tokens, private keys, passwords, or token-bearing URLs.
Customer responsibilities
Section titled “Customer responsibilities”Customers should grant least-privilege Workato credentials, review Workato permission scope periodically, rotate credentials when personnel or risk changes, and remove stale WorkatoSight data when no longer needed.