A visual workflow can make the happy path easy to see while leaving failure and credential boundaries unclear.
Keep credentials server-side
Use the documented account or project scope and store secrets in the workflow environment’s protected configuration. A frontend form or exported public example should not contain a live key.
Miss Blue’s Make and n8n guides describe HTTP and webhook paths with server-held credentials. Check the permissions of the actual workspace that stores and runs them.
Record the logical message
Give one intended customer message a stable application identifier. Map repeated trigger events to the same work instead of creating another send every time the workflow reruns.
Keep provider event and message identifiers alongside that record. A visual node retry should not silently change the identity of the proposed action.
Keep long waits durable
A follow-up delayed until tomorrow needs a persistent enrollment and a reply-stop rule. An in-memory wait alone is not enough to describe recovery after a worker restart.
If the workflow platform supplies persistence, verify its actual behavior. If your backend supplies it, let the visual workflow call that durable job rather than recreating it.
Expose a failure owner
Route failed or unknown actions to a named operator with the relevant source record and thread. Do not fill the CRM with duplicate event text instead of an actionable state.
A documented no-code connection can still require careful operating choices. Use owned interrupted-flow tests before treating a green node as proof of an end-to-end integration.