Understand the absence of API-key rotation controls
Plan credential lifecycle outside the module.
Exact navigationOpenAI provider account and Admin Area → Setup → Settings → AI → OpenAI
Before you begin
- Use an account with Administrator and confirm the intended record or setting before making a change.
- Follow the exact route above. If the screen or action is absent, check module activation, ownership and permissions rather than using another person’s account.
- Use controlled test data for configuration, integration, email, AI, payment, portal or automation changes before production-wide use.
What this guide covers
Plan credential lifecycle outside the module. The instructions reflect the supplied module’s registered menus, controller actions, views, settings and code-backed validation flow.
Exact step-by-step process
- Open OpenAI provider account and Admin Area → Setup → Settings → AI → OpenAI.
- Select the relevant record, filter, report, model or configuration described below.
- Use the displayed action or read the current values without altering unrelated data.
- Compare the output with the code-backed rules and expected result in this guide.
- Record or correct any mismatch before relying on the output in production.
Fields, choices and supported possibilities
ActionUnderstand the absence of API-key rotation controls
Exact navigationOpenAI provider account and Admin Area → Setup → Settings → AI → OpenAI
Module version1.0.0
VerificationConfirm the saved record, status, output or setting in the same workspace and review any linked activity, file or notification.
Code-backed validations and workflow rules
- No expiry, rotation schedule, last-used metadata or revoke button is implemented.
- Replace the stored key after rotating it at the provider.
Expected result and verification
- The supported understand the absence of api-key rotation controls flow completes without bypassing permission or validation checks.
- The resulting record, setting, status, file, delivery event or external response is visible from the relevant workspace.
- Unexpected validation, provider or linked-record errors are investigated before retrying.
Security, privacy and operational checks
- Restrict the API key and AI settings to authorised administrators.
- Do not submit confidential, special-category or unnecessary personal data to the external AI provider.
- Review generated text before using it in customer, staff, legal, financial or compliance communication.
- Monitor provider billing and retention independently because this module has no built-in cost dashboard.
