Business IT projects · Across Québec Request a quoteFrançais

Software integration

Software integration means having your systems exchange data automatically: a website order that lands in the accounting software, a new CRM client created in the billing tool, time entries that feed payroll. It avoids double entry and copying errors.

Updated on

An integration connects systems through APIs, connectors or file exchanges. In ITSM.60.005, the Canadian Centre for Cyber Security recommends that you "do not hardcode database credentials and API keys" (section 5.4.4). When personal information flows between systems, protecting these access points is part of the project from the start.

Short answer

You describe your software and the data that must flow between them: your request is reviewed by the Courtier TI team, then entrusted to the IT services company that will prepare your quote. The integration method, tools and error monitoring are set with you.

What the quote should cover

  • An inventory of the systems to connect and the data exchanged
  • The direction of each flow, its frequency and the system of record for each piece of data
  • The chosen method: API, existing connector, integration platform or custom development
  • Access management: service accounts, API keys, minimum rights
  • Error handling: logging, alerts, retrying failed exchanges
  • Testing with real or representative data
  • Documentation and maintenance when connected software is updated

The steps of an integration project

  1. Inventory of the systems and the data to move
  2. Choice of the system of record for each type of data
  3. Choice of integration method and review of available APIs
  4. Development or configuration, with a test environment
  5. Testing of normal cases and error cases
  6. Go-live, monitoring of exchanges and documentation

System inventory and direction of flows

Start by mapping your flows: which software sends what, to whom, and when. For each piece of data, such as a client, a product or a price, decide which system is the system of record. Without that rule, two systems can keep overwriting each other and create duplicates or discrepancies that are hard to trace.

Then check what each piece of software allows: a documented API, a connector from the vendor, file exports only. Some APIs are limited by plan or number of calls. Have these limits confirmed in writing before choosing the method. Our guide to writing an IT requirements document helps describe these needs.

Integration platform or custom development

An integration platform, such as Microsoft Power Automate, Zapier or Make, as examples, connects common applications without programming everything. It often suits simple flows, but adds a subscription and an intermediary that processes your data. Custom development offers more control for complex rules or high volumes, and requires someone to maintain it.

Either way, ask where data passes through and is stored. If a platform processes personal information outside Québec, section 17 of Quebec's Act respecting the protection of personal information in the private sector requires a privacy impact assessment before entrusting it with that task, as well as a written agreement.

Access security and personal information

Every integration uses access credentials: service accounts, API keys, tokens. The Centre's baseline cyber security controls call for providing accounts with the minimum functionality required for the tasks (BC.12.1). An integration that reads invoices does not need administrator rights. Keys should not be hardcoded, according to ITSM.60.005, and their renewal should be planned. The OWASP Top 10 API Security Risks can serve as a reference, for example for authorization and authentication flaws.

If the integration is part of a project to develop or overhaul an information system involving personal information, section 3.3 of the Act requires a privacy impact assessment and consultation of the person in charge of the protection of personal information from the outset of the project. The contract with the company that will have access to the data must also be in writing and specify the protection measures (s. 18.3).

Error handling and maintenance

An integration will eventually run into an error: software that is down, an empty required field, an expired key. The quote should specify how errors are logged, who receives an alert, how failed exchanges are retried and how to avoid creating duplicates when retrying.

Connected software changes: an update can modify an API. Have the quote specify who monitors these changes, who fixes the integration and on what terms. Require documentation of flows, access and rules, and access to the source code if the integration is custom-built.

Questions to ask yourself before requesting a quote

  • Which double-entry tasks do you want to eliminate?
  • Which software must exchange data, and in which direction?
  • Which system is the system of record for clients, products and prices?
  • Must exchanges be immediate, or is periodic synchronization enough?
  • Does personal information flow between these systems?
  • Who in your company will be notified of errors?

Pitfalls to avoid

  • Connecting systems without deciding which one is the system of record
  • An administrator account used by the integration
  • API keys hardcoded or shared by email
  • No alert on failure, discovered late
  • An integration platform chosen without knowing where it processes data
  • No documentation or access to code at the end of the contract

What to specify in your request

  • The list of software to connect, with their version or plan
  • The data to move and the approximate volume
  • The desired frequency of exchanges
  • Integration tools already in use, if any
  • Whether personal information is involved
  • Requirements from a client, insurer or contract that must be met

You can then describe your project: the team will contact you to clarify your needs and provide a quote.

Frequently asked questions

What is an API?

An application programming interface (API) is an entry point that software offers to other software to read or change its data in a controlled way. Most modern integrations go through APIs, when the software offers one.

Should we use an integration platform or custom development?

That depends on your flows. A platform, such as Power Automate, Zapier or Make as examples, often suits simple exchanges between common applications. Custom work is justified for complex rules, high volumes or software without a connector.

How do we protect the access used by an integration?

Give each integration its own account with minimum rights, keep keys out of the code and plan their renewal. The Canadian Centre for Cyber Security recommends not hardcoding database credentials and API keys.

Is a privacy impact assessment required?

If the integration is part of a project to develop or overhaul an information system involving personal information, yes: the Act requires one (s. 3.3). It also requires one before entrusting that information to a platform located outside Québec (s. 17).

What happens when one of the software products is updated?

An update can change an API and break the integration. Have the quote specify who monitors these changes, who fixes the integration and on what terms.

Software integration

Deployments, integrations and project management

Request a quote