Choose AI Stack
Search

Permissions guide · Updated 2026-07-20

Approve the workflow, not broad access by default.

A connected AI assistant can turn a useful drafting or search tool into an operator across files, messages, calendars, repositories, and other business systems. Approve it only after the team can explain the exact job, the smallest required access, the actions that still need human review, and the path to revoke access later.

Four questions before approval

What can the assistant reach?

List every connected app, workspace, repository, folder, inbox, calendar, and database. Do not treat a connector name as proof of a narrow scope.

What can it do after access is granted?

Separate reading and summarizing from actions such as sending, editing, approving, merging, deploying, deleting, or changing billing and access.

Which actions still require a person?

Keep a named human approval gate for customer-facing messages, production changes, legal commitments, payments, destructive actions, and access changes.

How will access be reviewed and removed?

Set a permission-review date, name the owner, and document how to revoke connectors, service accounts, delegated tokens, and departed-user access.

Match each action to a control

Connector access is only half the approval. Decide what the assistant may do with that access, then put the review gate at the action that creates the real consequence. Record evidence that the gate was applied so the approval can be audited and revisited later.

Read and summarize

Default control

Allow only the folders, inboxes, calendars, or repositories needed for the approved workflow. Exclude sensitive locations that do not change the result.

Approval evidence

Record the approved locations, excluded locations, data owner, and the date the scope was last reviewed.

Draft or edit

Default control

Keep changes in a reviewable draft, branch, or proposed-edit state. Name the person responsible for approving the final version.

Approval evidence

Keep the draft or branch history and name the reviewer who accepts, rejects, or changes the proposed work.

Send, publish, merge, or deploy

Default control

Require an explicit human approval at the final action boundary. Do not treat an earlier connector approval as permission for every future action.

Approval evidence

Capture the final approver, the exact item approved, and the outbound, merge, or deployment result.

Delete, pay, or change access

Default control

Keep these actions outside the assistant by default. Approve an exception only with narrow scope, strong logs, and a tested recovery path.

Approval evidence

Document the exception owner, limit, recovery or rollback test, and an audit trail for every completed action.

Choose one decision path

Approve a narrow pilot

Use one team, one low-sensitivity workflow, read-only access where possible, and the smallest connector scope that can prove the use case.

Pause for controls

Pause when the assistant needs broad workspace access but ownership, logs, approval gates, retention, or offboarding are not yet clear.

Reject the connection

Reject when the proposed access is broader than the buyer job, cannot be revoked cleanly, or bypasses an existing review or security boundary.

Record the approval boundary

Write down the approved workflow, connected locations, allowed actions, required human gates, owner, review date, and revocation steps. Use the copyable checklist to turn this decision into a reusable handoff instead of relying on a one-time conversation.