
RPA Operations
Part of RPA bot operations
Managing credentials used by software robots
Inventory bot identities, limit access, manage secrets and verify credential changes without disrupting live RPA work.
Give every software robot identity a defined purpose and owner. Grant only the access its task needs, and keep its credentials in an approved managed location.
Inventory every identity
A bot may use separate identities for its machine session, automation platform and target applications. Record each account's purpose, owner, systems, permissions, credential location and renewal method. Include certificates and tokens where they are used. This inventory shows which runs may be affected when access changes.
Avoid using an employee's ordinary account simply because it already works. A departure or role change can then interrupt the bot or leave it with access tied to former duties.
Choose an identity model the target application supports and document any exception. Apply least privilege by granting only the access each task needs.
Control storage and changes
Use the organisation's approved secret store or platform credential mechanism. Restrict who can retrieve or change credentials and which automation can use them. Keep secrets out of scripts, screenshots, ordinary tickets and run logs.
For a change, identify dependent bots, update the managed value and verify a safe run, including how the bot behaves when a credential is revoked or permissions are insufficient. Use the approved recovery route if authentication fails.
UiPath Orchestrator supports credential stores and credential assets, including assigning credential stores to folders. Check which folders and automations depend on a store before changing its settings.
Investigate failed sign-ins and retire access
An authentication error may reflect a changed secret, locked account, missing permission, unavailable identity service or changed sign-in flow. Preserve the error and time, then check account state with the identity and application owners. Repeated bad-login retries may complicate recovery.
Review access when the process changes, an application is replaced, a credential may have been exposed or a bot is retired. Disable unused identities through the authorised process and retain an access-change record.



