Skip to content

The 30 Workato security checks Black Cat runs

Black Cat SSPM evaluates 30 security policies against your Workato configuration on every scan, classifies each finding by risk, and provides remediation steps. Browse them by topic below.

How to connect Workato — what access Black Cat needs, and why.

Access control & privilege (10)

Encryption, keys & secrets (7)

Configuration hardening (8)

Other checks (5)

severity: medium Recipe Integrates with Sensitive Application fix difficulty: medium #

Review data handling and access controls for recipes connected to sensitive business applications

  1. Log in to Workato and navigate to the Recipes section
  2. Open the recipe flagged for integrating with a sensitive application (e.g., Salesforce, Workday)
  3. Review what data the recipe reads and writes to the sensitive application
  4. Confirm the recipe uses a dedicated service account with least-privilege access
  5. Ensure error handling does not log sensitive fields such as PII or financial data
  6. Document the data flow in your data processing register and confirm compliance with relevant policies

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 NIS2 Directive NIS2-21.a.3 DORA (SaaS Security) DORA-9.11

severity: high Recipe High Error Rate fix difficulty: medium #

Investigate and fix the recipe that is producing a high rate of job errors

  1. Log in to Workato and navigate to the Recipes section
  2. Open the recipe flagged with a high error rate
  3. Click "Jobs" to review the job history and identify failure patterns
  4. Inspect the failed jobs for error messages and stack traces
  5. Fix the recipe logic, update connection credentials, or adjust error-handling steps as needed
  6. Re-run failed jobs or restart the recipe and monitor the error rate

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: medium Stopped Recipe With Errors fix difficulty: medium #

Diagnose and resolve errors that caused the recipe to stop, then restart it

  1. Log in to Workato and navigate to the Recipes section
  2. Open the stopped recipe and click "Jobs" to view recent job history
  3. Review the last failed jobs for error details and root cause
  4. Update the recipe steps, trigger configuration, or connection credentials as needed
  5. Click "Start recipe" to restart it after the fix is applied
  6. Monitor the next few job runs to confirm the recipe is running without errors

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.d DORA (SaaS Security) DORA-28.4

severity: medium Connection to Sensitive Provider fix difficulty: medium #

Review authorization scope and data access for connections to sensitive SaaS providers

  1. Log in to Workato and navigate to Projects > Connections
  2. Open the connection flagged as connecting to a sensitive provider
  3. Review the authorization scope and verify it follows least-privilege principles
  4. Confirm the connection uses a dedicated service account rather than a personal account
  5. Verify the connection is authorized with short-lived credentials or OAuth2 where possible
  6. Document the connection in your data processing register for compliance audits

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.7 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-314.a

severity: low Collaborator Group No Description fix difficulty: easy #

Add a description to collaborator groups to document their purpose for access reviews

  1. Log in to Workato and navigate to Workspace Admin > Groups
  2. Open the group that has no description
  3. Click Edit and add a clear description of the group's purpose, membership criteria, and associated projects
  4. Save the changes
  5. Repeat for any other undocumented groups to improve audit readiness

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 ISO 27001:2022 A.8.9 SOC 2 Type II CC6.2 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-5.2 HIPAA (SaaS Security) HIPAA-316.b

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial