Practical automation guidance

Choose work that can be checked

Not every repeated task should be automated. The tasks that suit it have structured inputs, rules that can be written down, mistakes that are cheap to catch and success that can be measured. The notes below turn those conditions into a comparison and a checklist that can be applied before any supplier or tool is considered.

Flat illustration of a checklist with ticks beside task cards sorted into suitable and unsuitable columns

Suitability belongs to the task, not the tool

A task that is impractical to describe is impractical to automate, whatever software is chosen. Three questions test it. Can the input be described field by field? Can the rule be written as if-then statements? Can a reviewer see right or wrong in a few seconds?

If any answer is no, the task needs more mapping or should stay manual for now. That is a useful finding, not a failure.

Compare tasks on five characteristics

Suitability comparison by task characteristic
CharacteristicSuits automationNeeds cautionUsually keep manual
InputsFixed fields: form entries, CSV exports, JSON from a serviceMixed layouts, such as PDF invoices from many suppliersHandwritten notes, spoken requests
RulesWritten as if-then statementsMostly rules, with frequent exceptionsDepend on judgement or relationships
VolumeFrequent and similar each timeOccasional, with seasonal peaksRare or one-off
Cost of an errorSmall, caught at the next stepModerate, caught at a later reviewFinancial, legal or safety harm that is hard to undo
Personal dataNone, or minimal and necessaryCustomer contact details moving between systemsHealth, financial or children’s data without specialist advice

Write acceptance criteria before choosing anything

Acceptance criteria are written, checkable statements of what a correct result looks like. They are agreed before work begins, so that neither side can redefine success afterwards. Examples for a hypothetical invoice-review task:

  • Every invoice in the source appears exactly once in the output.
  • Totals in the output match totals in the source to the last penny.
  • Any invoice that fails a rule goes to a named person and is never dropped.
  • An item counts as complete when the record shows a status, not when a message has been sent.
  • A reviewer can tell from the log what changed and when.
  • The step can be switched off and the manual route resumed the same day.

Words like “faster” or “better” cannot be accepted or rejected. A criterion needs a yes-or-no test or a number agreed in advance.

Know the formats the data travels in

CSV
Comma-separated values, described in RFC 4180: a text file with one record per line. Most accounting, shop and spreadsheet tools can export it, which makes it the usual meeting point between small systems. Watch dates, leading zeros and commas inside fields.
JSON
JavaScript Object Notation, defined in RFC 8259: nested text with named fields, used by the interfaces of most web services. It carries structure that CSV flattens.
OAuth 2.0
An authorisation framework in RFC 6749 that lets one application act inside another without being given the account password. It is the usual way a connection to a service such as Google Workspace or Microsoft 365 is granted and later revoked.
Spreadsheets
Microsoft Excel and Google Sheets are often the real system of record. Expect questions about who may edit which columns.

Accounting packages such as Xero and QuickBooks, shop platforms such as Shopify and payment services such as Stripe each publish ways to export or connect data. Their capabilities change, so check their own documentation.

Check personal data against GDPR early

The General Data Protection Regulation, Regulation (EU) 2016/679, and the UK’s equivalent apply when a task handles information about identifiable people: names, email addresses, delivery addresses. Four ideas carry practical weight. Use only the data the task needs. Know why you hold it. Keep it no longer than necessary. Know which suppliers process it for you.

Some projects call for a data protection impact assessment. This is general information, not legal advice. The data protection authority in your country, such as the Information Commissioner’s Office in the United Kingdom, publishes guidance, and a qualified adviser can apply it to your case.

Continue with