The administrator configures the connection
An organisation administrator selects the connection and client, grants the required scopes and sets an explicit unit allowlist. Always review which data classes each permission exposes.
The organisation must have accepted its data processing agreement (DPA), and the person using the feature must have the required permission. Grant access only to the units and data needed for the task.
Store credentials securely
The client secret is shown once when it is created. Save it then in your organisation's approved secrets manager. Do not paste it into tickets, chats or source code. If it is lost, create a new one through the flow shown in CAIRE.
Use the OpenAPI URL shown in CAIRE for your environment. URLs and available actions can differ between environments.
Review before changing planning data
The planner reviews the import contents and receipt in CAIRE before accepting the input or using it to create planning data. Check the period, unit, scope and any warnings before deciding.
Reads and requests follow the client's granted scopes and unit allowlist. Retain receipts so you can trace what was requested and which result CAIRE returned.
Revoke access and keep journals in Carefox
An organisation administrator can revoke the client's access when it is no longer needed. Also remove the saved secret from your secrets manager and follow your organisation's rotation and incident procedures.
For customers using Carefox, journals stay in Carefox. CAIRE Connect does not promise native journal handling or storage in CAIRE.