WORKSTATION AGENT
Workstation Agent — Best Practices
11 of 12Apply security, reliability, performance, operational and clinical-safety practices for production Workstation Agent deployments.
SecurityReliabilityPerformanceOperationsComplianceClinical Safety
1. Security & Least Privilege
Request only required resources
Least privilege by default
Never store credentials in plain text
Protect keys and certificates
Validate all inputs and outputs
See guide →
2. Resource Isolation
Run each connector in isolated process
Use timeouts and memory limits
Prevent one connector failure affecting others
Close devices when unused
See guide →
3. Offline Resilience
Work within defined offline boundaries
Queue events safely and idempotently
Avoid actions needing real-time validation
Handle conflicts and reconciliation
See guide →
4. Updates & Compatibility
Semantic versioning
Backward compatibility
Test in staging
Rollback and safe fallback
See guide →
5. Identity & Certificates
Short-lived certificates
Secure OS key storage
Validate server certificates
Revoke compromised identities
See guide →
6. Observability & Logging
Structured JSON logs
Correlation IDs
Never log sensitive data
Expose metrics and health
See guide →
7. Performance
Minimize CPU/memory/I/O
Stream when possible
Batch and compress
Avoid blocking main Agent process
See guide →
8. Clinical Safety Boundaries
Do not perform clinical validation locally
Never alter clinical data silently
Surface uncertainty and errors
Follow regulatory policies
See guide →
9. Enterprise Deployment
Use MDM/EMM
Standardize installation
Document dependencies
Plan scale and multi-site management
See guide →
10. Testing & Quality
Automate unit/integration tests
Test with real devices when possible
Validate offline/recovery
Maintain code quality & docs
See guide →
Connector crash containment
User / Application
Workstation Agent
Connector A
Isolated process
Connector B
Isolated process
Connector C
Isolated process
Connector D
Isolated process
If one connector crashes, the others continue to run. The Agent restarts only the failed connector.
Recommended defaults
Log levelINFO (production)
Queue retention30 days
Retry strategyExponential backoff
Health check60 seconds
Metrics flush30 seconds
Update intervalEvery 6 hours
Certificate rotation30 days before expiry
Overlap during updateSupported
Do / Don't
DO
Design for failure
Fail safe, not open
Be explicit and transparent
Validate early and often
Document everything
Plan for recovery
DON'T
Request broad permissions
Store secrets insecurely
Ignore errors/retries
Block the Agent process
Assume network is always available
Modify clinical data silently
Operational excellence checklist
Least-privilege principle
Offline & reconnect scenarios
Structured logs & correlation IDs
Metrics & health endpoints
Error scenarios tested
Documentation complete
Rollback plan tested
Ready for production deployment