What is your goal?
’m evaluating the possibility of automating some workflows related to a protocol email account within a publicly-owned company, using Make (or similar automation tools).
I’m aware that this is a sensitive topic due to:
security requirements
document management regulations
GDPR and audit/logging constraints
For this reason, I’d like to understand if anyone has practical, real-world experience with similar scenarios:
Have you successfully integrated a protocol email account (or official PEC/institutional mailbox) with Make or other cloud automation tools?
If yes, what kind of architecture did you use (direct integration, internal middleware, official APIs from the protocol system, etc.)?
What limitations or constraints were imposed by IT departments, DPOs, or software vendors?
Did you implement any specific safeguards (e.g. data filtering, anonymization, logging, EU-only data processing, etc.)?
The goal is not to push non-compliant solutions, but to understand which approaches have actually been adopted in similar contexts and are considered sustainable.
What is the problem & what have you tried?
The goal is to automate part of the workflow related to a protocol email account (incoming messages, attachments, and basic routing/notifications), within a publicly-owned company context.
The challenge is not technical integration itself, but ensuring compliance with:
internal IT security policies
GDPR and data handling requirements
document management and traceability constraints typical of protocol systems
So far, I have explored:
the possibility of connecting the mailbox directly to Make (e.g. via IMAP/SMTP or email modules), but this raises concerns about data leaving the controlled environment
alternative approaches involving an intermediate layer (internal middleware or API-based integration), but without a clear reference architecture yet
internal constraints, which suggest that direct use of external SaaS tools on protocol data may be restricted or require specific safeguards
At this stage, I’m trying to understand what approaches are realistically viable in similar organizations, before moving forward with a concrete implementation.
I’m aware that this is a sensitive topic due to:
security requirements
document management regulations
GDPR and audit/logging constraints
For this reason, I’d like to understand if anyone has practical, real-world experience with similar scenarios:
Have you successfully integrated a protocol email account (or official PEC/institutional mailbox) with Make or other cloud automation tools?
If yes, what kind of architecture did you use (direct integration, internal middleware, official APIs from the protocol system, etc.)?
What limitations or constraints were imposed by IT departments, DPOs, or software vendors?
Did you implement any specific safeguards (e.g. data filtering, anonymization, logging, EU-only data processing, etc.)?
The goal is not to push non-compliant solutions, but to understand which approaches have actually been adopted in similar contexts and are considered sustainable.