Tines Academy › Lesson

Manage connectors at the org level

One connector can power many workflows, so every decision about it reaches all of them. Learn the four kinds of connector access, and how to judge how far a connector can reach, in Tines 3B and in the service it connects to.

Objective: Decide who needs which kind of access to a connector, and judge how far a connector can reach from both its grants and its credentials.

The keys to your other tools

Connectors are how workflows reach the tools your company already uses: your email, your chat tool, your project tracker, your customer records. Each connector holds the credentials for one of those tools, and one connector can power many workflows at once.

That makes connectors worth deciding about deliberately. Who can create them? Who can use them? How much can each one actually do? Get those answers right, and teams can build freely with the tools they need, without anyone holding more access than their work requires.

By the end of this lesson, you'll be able to decide who gets which kind of access to a connector, and judge how much access a connector should carry.

Four kinds of connector access

Finance's weekly invoice reminder sends emails through the company's email tool. Let's follow what happens around that one connector.

One connector, many workflows

Identify the blast radius

Before anyone creates or widens a connector, finish one sentence out loud.

"If this connector were misused, the worst that could happen is..."

If the sentence ends somewhere you can live with, like "someone could read one team channel," the scope is fine. If it ends like "someone could send an email as anyone in the company" or "someone could delete every customer record," narrow the connector down until the sentence ends somewhere comfortable.

Two separate controls decide how that sentence ends:

In Tines 3B, grants decide who can view, edit, share, and use the connector.

In the connected service, the account or token decides what the connector can actually do once a workflow uses it.

Narrowing a workflow's job doesn't narrow the credential: a workflow that only reads two details can still be holding credentials that reach much further.

What changed

The workflow does exactly the same job either way. The only difference is how far the damage could reach if the connector were misused, and that comes from two things: the permissions on the credential in the connected service, and who has access to the connector in Tines 3B. Not every service supports the same restrictions, so check what yours can scope before you promise a narrow blast radius. Until you've checked the credential itself, a small blast radius is only a hope.

Open your Tines 3B tenant.

Open the Connectors tab from the left sidebar.

Pick one connector you can see.

Note which app it connects to and what it's used for.

Check who has access to it and which kind of access each person or group has.

If you can edit it, run its connection test and check the result.

Finish the blast radius sentence for this connector.

If you don't see any connectors, there may be none set up yet, or you may not have access to the ones that exist. Either way, use the invoice reminder example to work through the same steps.

After you choose, check yourself. Which of the four kinds of access does a builder actually need? What would the blast radius sentence say for your recommendation, and does it depend on the credential as well as the grant?

What to do if something still feels fuzzy

Most builders only need use access, and every connector should reach no further than its job, both in Tines 3B and in the service it connects to. When in doubt, finish the blast radius sentence. Next, you'll bring everything together at the moment a workflow goes live.