An automation, or flow, chains steps triggered by an event, such as an incoming email or a submitted form. It runs with an account's permissions and connects to your software. Microsoft Power Automate is one example among other tools: the right choice depends on the software you already use.
Short answer
You describe the tasks to automate and the software involved: your request is reviewed by the Courtier TI team, then entrusted to the IT services company that will prepare your quote. The choice of tool, steps and schedule are set with you.
What the quote should cover
- Analysis of candidate tasks and the choice of those to automate
- A description of the current and target process
- The choice of tool and connectors, with their licences
- The accounts used by the flows and their permissions
- Handling of errors, alerts and exceptions
- Testing with real cases and go-live
- Documentation of each flow and training for the owners
The steps of an automation project
- Inventory of repetitive tasks and choice of priorities
- Description of the current process, including exceptions
- Design of the flow, accounts and alerts
- Testing with real cases, including error cases
- Go-live and handover to the flow owner
- Monitoring of runs and adjustments
Choosing what to automate
Good candidates are frequent tasks with stable rules that start from data that is already digital: a form, a structured email, a list. Tasks that require judgment or change often are less suited to automation, or need a validation step by a person.
Automating a poorly defined process only speeds up its flaws: describe it first, with its exceptions. The gain depends on your volume, your exceptions and the quality of your data; be wary of a time saving quantified before any analysis.
Flow owner and service accounts
Each flow should have an owner on the business side: the person who knows what it does, receives the alerts and approves changes. A flow created with an employee's personal account may stop working when they leave; a dedicated account owned by the company avoids this problem.
The Canadian Centre for Cyber Security's baseline cyber security controls recommend provisioning accounts with the minimum functionality necessary for tasks (BC.12.1). A flow's account should therefore access only the data and software it needs, and be removed when no longer used. Also avoid writing passwords directly into the flow: the Centre recommends that you do not hardcode database credentials and API keys.
Errors, alerts and documentation
A flow will fail one day: a password changes, an application is updated, data arrives in an unexpected format. The quote should specify how errors are detected, who receives the alert, whether the flow retries automatically and how failed cases are handled manually.
Document each flow: its trigger, steps, accounts and connectors used, data processed and owner. This documentation lets you fix, transfer or disable it without depending on the person who created it.
Personal data and automated decisions
If a flow processes personal information, Quebec's Act respecting the protection of personal information in the private sector applies as it does to any other processing. An information system development project involving such information requires a privacy impact assessment (s. 3.3), and personal information should be accessible only to people for whom it is necessary for the performance of their duties (s. 20).
If a flow makes a decision based exclusively on automated processing of personal information, such as automatically refusing a request, section 12.1 requires informing the person concerned not later than when they are informed of the decision, explaining on request the information, reasons and principal factors used, and giving them the opportunity to submit observations to a member of staff who is in a position to review the decision. If the flow uses AI, the AI governance page covers the points to examine.
Questions to ask yourself before requesting a quote
- Which tasks recur, and how often?
- Which software is involved, and under which licences?
- Who will own each flow?
- Which exceptions require a person to step in?
- Does personal information flow through these tasks?
- Who should be notified when an error occurs?
Pitfalls to avoid
- Automating a process that has never been described
- Flows created with an employee's personal account
- Flow accounts with access to everything
- No alert on failure
- Flows with no documentation or owner
- A time saving promised before the analysis
What to specify in your request
- The tasks to automate and their approximate frequency
- The software involved and the tools already available
- The people who approve or validate steps
- The data processed, including personal information
- Existing flows to review, if any
- Your approximate budget and date constraints, if any
You can then describe your project: the team will contact you to clarify your needs and provide a quote.
Frequently asked questions
Do we have to use Power Automate?
No. Power Automate is one example of a tool, often considered when a company already uses Microsoft 365. Other tools exist, and some software has its own automation features. The choice depends on your software, your licences and who will maintain the flows.
How much time does automation save?
That depends on the task volume, the number of exceptions and data quality. The process analysis lets you estimate the gain together; a figure announced before that analysis rests on nothing verifiable.
What happens if the employee who created a flow leaves?
If the flow depends on their personal account, it may stop working. Plan for dedicated accounts owned by the company, a designated owner for each flow and up-to-date documentation.
Can a decision be fully automated?
It can, but if it is based exclusively on automated processing of personal information, section 12.1 of Quebec's Act requires informing the person, explaining the decision on request and allowing them to submit observations to a member of staff who can review it.
How do we know a flow is still working?
By setting up failure alerts sent to a designated person and tracking the run history. The quote should describe this mechanism and how failed cases are handled.