Skip to content

Workato configuration hardening security checks

Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.

On Workato, Black Cat runs 8 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Workato connector needs.

Checks (8)

severity: medium Workspace Recipe Limit fix difficulty: medium #

Remove unused recipes or upgrade the Workato plan to stay within recipe quota

  1. Log in to Workato and navigate to the Recipes section
  2. Review the list of recipes and identify stopped or unused ones
  3. Archive or delete recipes that are no longer needed
  4. If the recipe count still exceeds the plan limit, contact Workato support to upgrade the plan
  5. Verify the current recipe count is within the allowed quota

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: high Broken Connection fix difficulty: medium #

Re-authorize or remove the broken SaaS connection in Workato

  1. Log in to Workato and navigate to Projects > Connections
  2. Locate the connection flagged as broken or disconnected
  3. Click the connection name to open its configuration
  4. Click "Reconnect" or "Re-authorize" and complete the OAuth or credential flow
  5. If the connection is no longer needed, click "Delete" to remove it
  6. Verify the connection shows a green connected status

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Stale Connection fix difficulty: easy #

Review and remove SaaS connections that have not been used recently

  1. Log in to Workato and navigate to Projects > Connections
  2. Review connections and identify those with no recent usage
  3. For each unused connection, confirm it is not referenced by any active recipe
  4. Click the connection name, then click "Delete"
  5. Confirm the deletion to remove the stale connection

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: high Workspace Trial Expired fix difficulty: easy #

Upgrade the Workato workspace to a paid plan to restore full security controls and SLA

  1. Log in to Workato and navigate to Workspace Admin > Settings > Plan & Billing
  2. Review the current trial status and expiry date
  3. Contact Workato sales or click "Upgrade" to select an appropriate paid plan
  4. Complete the billing and provisioning steps
  5. Verify the workspace plan reflects the upgraded tier and trial status is cleared

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC9.1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Recipe Never Executed fix difficulty: easy #

Review and clean up recipes that have never been executed

  1. Log in to Workato and navigate to the Recipes section
  2. Open the recipe that has never been executed
  3. Determine whether the recipe is intentionally dormant or was abandoned during development
  4. If no longer needed, archive or delete the recipe
  5. If the recipe should run, verify its trigger and connection configuration then start it
  6. Confirm the recipe either has a run history or has been removed

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Recipe Long Stopped fix difficulty: easy #

Review and archive recipes that have been stopped for an extended period

  1. Log in to Workato and navigate to the Recipes section
  2. Open the stopped recipe and review its job history and last run date
  3. Determine whether the recipe is still needed or has been superseded
  4. If abandoned, archive or delete the recipe and remove any associated connections it exclusively uses
  5. If it should be restarted, fix any underlying issues and click "Start recipe"
  6. Confirm the recipe is either running again or has been removed from the workspace

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Connection Never Authorized fix difficulty: medium #

Investigate connections that show as authorized but have no authorization timestamp

  1. Log in to Workato and navigate to Projects > Connections
  2. Open the connection flagged with no authorization timestamp
  3. Review the authentication method — connections using long-lived service account keys may not record timestamps
  4. Replace service account keys with OAuth2 or short-lived credentials where possible
  5. Re-authorize the connection to create a fresh authorization record with a current timestamp
  6. Verify the connection shows a valid authorization date after re-authorization

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Recipe Excessive Application Integrations fix difficulty: hard #

Split recipes with many application integrations to reduce blast radius

  1. Log in to Workato and navigate to the Recipes section
  2. Open the recipe flagged for integrating with too many applications
  3. Review whether all integrated applications are necessary for the recipe's function
  4. Split the recipe into smaller, purpose-specific recipes that each touch fewer applications
  5. Use Workato callable recipes or lookup tables to share data between the smaller recipes
  6. Test the refactored recipes and deactivate the original once confirmed working

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.12 SOC 2 Type II CC6.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-28.1 HIPAA (SaaS Security) HIPAA-314.a NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

More Workato checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial