Security, privacy, limitations and troubleshooting

Understand the absence of API-key rotation controls

Plan credential lifecycle outside the module.

Audience: CRM administrators and authorised staffPermission: AdministratorModule v1.0.0
Exact navigationOpenAI provider account and Admin Area → Setup → Settings → AI → OpenAI
Before you begin
  • Use an account with Administrator and confirm the intended record or setting before making a change.
  • Follow the exact route above. If the screen or action is absent, check module activation, ownership and permissions rather than using another person’s account.
  • Use controlled test data for configuration, integration, email, AI, payment, portal or automation changes before production-wide use.

What this guide covers

Plan credential lifecycle outside the module. The instructions reflect the supplied module’s registered menus, controller actions, views, settings and code-backed validation flow.

Exact step-by-step process

  1. Open OpenAI provider account and Admin Area → Setup → Settings → AI → OpenAI.
  2. Select the relevant record, filter, report, model or configuration described below.
  3. Use the displayed action or read the current values without altering unrelated data.
  4. Compare the output with the code-backed rules and expected result in this guide.
  5. Record or correct any mismatch before relying on the output in production.

Fields, choices and supported possibilities

ActionUnderstand the absence of API-key rotation controls
Exact navigationOpenAI provider account and Admin Area → Setup → Settings → AI → OpenAI
Module version1.0.0
VerificationConfirm the saved record, status, output or setting in the same workspace and review any linked activity, file or notification.

Code-backed validations and workflow rules

  • No expiry, rotation schedule, last-used metadata or revoke button is implemented.
  • Replace the stored key after rotating it at the provider.

Expected result and verification

  • The supported understand the absence of api-key rotation controls flow completes without bypassing permission or validation checks.
  • The resulting record, setting, status, file, delivery event or external response is visible from the relevant workspace.
  • Unexpected validation, provider or linked-record errors are investigated before retrying.

Security, privacy and operational checks

  • Restrict the API key and AI settings to authorised administrators.
  • Do not submit confidential, special-category or unnecessary personal data to the external AI provider.
  • Review generated text before using it in customer, staff, legal, financial or compliance communication.
  • Monitor provider billing and retention independently because this module has no built-in cost dashboard.