Security, privacy, limitations and troubleshooting

Understand the absence of API-key rotation controls

Plan credential lifecycle outside the module. The guide then takes you through the correct route, the checks to complete before making changes, the workflow in order, and the evidence to review afterwards.

Audience: CRM administrators and authorised staffPermission: AdministratorModule v1.0.0
Jump to steps
Where to goOpenAI provider account and Admin Area → Setup → Settings → AI → OpenAI
Before you start
  • Use an account with Administrator and confirm the intended record or setting before making a change.
  • Follow the exact route above. If the screen or action is absent, check module activation, ownership and permissions rather than using another person’s account.
  • Use controlled test data for configuration, integration, email, AI, payment, portal or automation changes before production-wide use.

What you’ll accomplish

Plan credential lifecycle outside the module. The instructions reflect the supplied module’s registered menus, controller actions, views, settings and code-backed validation flow.

Follow these steps

  1. Go to OpenAI provider account and Admin Area → Setup → Settings → AI → OpenAI.
  2. Select the relevant record, filter, report, model or configuration described below.
  3. Use the displayed action or read the current values without altering unrelated data.
  4. Compare the output with the code-backed rules and expected result in this guide.
  5. Record or correct any mismatch before relying on the output in production.

Fields and options to review

ActionUnderstand the absence of API-key rotation controls
Exact navigationOpenAI provider account and Admin Area → Setup → Settings → AI → OpenAI
Module version1.0.0
VerificationVerify the saved record, status, output or setting in the same workspace and review any linked activity, file or notification.

Rules the system enforces

  • No expiry, rotation schedule, last-used metadata or revoke button is implemented.
  • Replace the stored key after rotating it at the provider.

How to confirm it worked

  • The supported understand the absence of api-key rotation controls flow completes without bypassing permission or validation checks.
  • The resulting record, setting, status, file, delivery event or external response is visible from the relevant workspace.
  • Unexpected validation, provider or linked-record errors are investigated before retrying.

Security, privacy and operational checks

  • Restrict the API key and AI settings to authorised administrators.
  • Do not submit confidential, special-category or unnecessary personal data to the external AI provider.
  • Check generated text before using it in customer, staff, legal, financial or compliance communication.
  • Monitor provider billing and retention independently because this module has no built-in cost dashboard.