Canonical persistence path
A connected workflow submits a structured payload to the IOXN Access intake endpoint. The payload is validated and, when persistence is configured, becomes a confidential hidden operating record with a human-readable identifier.
Failure behavior
Persistence failures must remain visible as failures. A workflow can preserve a prepared fallback, but it must not display an IOXN Record ID or imply database persistence unless the canonical intake returns a successful result.
Identity linkage
A legitimate email can support account and record linkage, but account identity remains distinct from approval, membership, credential issuance or contract formation.
Data minimization
Pre-engagement selection and analytics should use only the minimum context needed for routing and aggregate funnel measurement. Free-text request content, private record identifiers and authenticated workspace URLs are not required for public conversion analytics.