Capture and email
Capture integrations are disabled until an administrator creates an explicit boundary. Start with manual browser uploads, then enable one connector and test its failure handling before adding another.
Watched folders
Allow only dedicated directories. Do not point Jiandu at a home directory or a broad shared mount. Decide whether another tool writes files atomically, how duplicates are handled, and where failed inputs remain visible for recovery.
Network scanners
Direct eSCL/AirScan jobs require an explicit network allowlist. Give scanners stable addresses and restrict reachability to the intended devices. Treat a scanner as an input source, not as a trusted administrator.
Linux/SANE capture agent
The agent uses one-use enrollment. Enroll it from Settings, keep its state directory private and persistent, and verify that an agent restart resumes safely. If its state is lost, revoke the old enrollment and create a new one instead of copying opaque state between machines.
Email connectors
Create a separate mailbox or narrow folder for document intake. Store connector keys in owner-only files, limit message size, and define what happens to a message after successful or failed import. Keep the original message until you are confident in the workflow.
For reliability practices, see reliable intake. Search the error guide with the exact message when a connector stops.