What can the assistant reach?
List every connected app, workspace, repository, folder, inbox, calendar, and database. Do not treat a connector name as proof of a narrow scope.
Permissions guide · Updated 2026-07-20
A connected AI assistant can turn a useful drafting or search tool into an operator across files, messages, calendars, repositories, and other business systems. Approve it only after the team can explain the exact job, the smallest required access, the actions that still need human review, and the path to revoke access later.
List every connected app, workspace, repository, folder, inbox, calendar, and database. Do not treat a connector name as proof of a narrow scope.
Separate reading and summarizing from actions such as sending, editing, approving, merging, deploying, deleting, or changing billing and access.
Keep a named human approval gate for customer-facing messages, production changes, legal commitments, payments, destructive actions, and access changes.
Set a permission-review date, name the owner, and document how to revoke connectors, service accounts, delegated tokens, and departed-user access.
Connector access is only half the approval. Decide what the assistant may do with that access, then put the review gate at the action that creates the real consequence. Record evidence that the gate was applied so the approval can be audited and revisited later.
Default control
Allow only the folders, inboxes, calendars, or repositories needed for the approved workflow. Exclude sensitive locations that do not change the result.
Approval evidence
Record the approved locations, excluded locations, data owner, and the date the scope was last reviewed.
Default control
Keep changes in a reviewable draft, branch, or proposed-edit state. Name the person responsible for approving the final version.
Approval evidence
Keep the draft or branch history and name the reviewer who accepts, rejects, or changes the proposed work.
Default control
Require an explicit human approval at the final action boundary. Do not treat an earlier connector approval as permission for every future action.
Approval evidence
Capture the final approver, the exact item approved, and the outbound, merge, or deployment result.
Default control
Keep these actions outside the assistant by default. Approve an exception only with narrow scope, strong logs, and a tested recovery path.
Approval evidence
Document the exception owner, limit, recovery or rollback test, and an audit trail for every completed action.
Use one team, one low-sensitivity workflow, read-only access where possible, and the smallest connector scope that can prove the use case.
Pause when the assistant needs broad workspace access but ownership, logs, approval gates, retention, or offboarding are not yet clear.
Reject when the proposed access is broader than the buyer job, cannot be revoked cleanly, or bypasses an existing review or security boundary.
Write down the approved workflow, connected locations, allowed actions, required human gates, owner, review date, and revocation steps. Use the copyable checklist to turn this decision into a reusable handoff instead of relying on a one-time conversation.