Identify which system owns each field and which events must move between systems. Limit credentials and data access, test retries and duplicates, and document how operational failures are surfaced.
Integration specification
For every flow, record the trigger, source, destination, required fields, transformation rules and expected timing. Decide how deletions and consent changes propagate. Use least-privilege service credentials and give credential rotation a named owner.
Acceptance checks
Test duplicates, out-of-order events, expired credentials, partial records and destination downtime. Monitoring should identify affected records without exposing message content or personal information unnecessarily.