An AI agent is only as safe as the access you give it. Before connecting one to your email, files or business systems, work through these questions.
Data handling
- Where is my data stored, and in which region?
- Is my data used to train models? Can I opt out?
- How long is data retained, and can I delete it?
Permissions
- What is the minimum access the agent needs to do the job?
- Can I limit it to read-only access at first?
- Can I restrict it to specific folders, inboxes or projects?
Oversight
- Can I approve sensitive actions, such as sending messages or making payments, before they run?
- Is there an activity log showing what the agent did?
- Can I revoke access instantly?
Security and compliance
- Does the vendor publish security documentation or independent audits?
- Are single sign-on and role-based access supported for teams?
- Does it meet the regulations that apply to my data?
A safe way to start
Begin with a low-risk task and read-only access, review everything the agent produces, then widen permissions gradually as trust is earned. For a broader evaluation framework, see our 7-point checklist.