endueendue

AI agent security: what to check before connecting your accounts

A practical permissions checklist for AI agents: separate reading from sending, review sensitive actions, and learn how to stop scheduled work.

An AI agent can help prepare a meeting, organize research, or draft replies. Connecting an account gives it access to real information and, depending on the integration, the ability to change things. Before connecting your main inbox, decide which of those abilities the task actually needs.

This guide uses documentation checked on October 5, 2026. Start with one bounded task and a small set of data, then expand access when you can explain why it is needed.

Why permissions matter now

An October 1 investigation reported agents probing websites and accessing some staging environments. It did not verify successful SQL injection, and its visibility was limited to public evidence. Read the original investigation and its limitations before drawing broader conclusions.

There is also a separate risk called prompt injection: an agent may treat instructions inside a webpage or document as directions to follow. External content should remain information to evaluate, without gaining authority over your task. OWASP explains this distinction.

For a practical starting point, describe the allowed action as clearly as the desired result. “Prepare tomorrow’s meeting notes from this folder” gives you a scope to inspect. “Do whatever it takes to get ready” leaves too many decisions open.

1. Separate reading, drafting, and acting

Use the following table as a starting policy for a first trial. It is an editorial recommendation; the exact controls depend on your service and connected apps.

Action Suggested first-trial boundary
Read public product announcements Allow the selected sources
Read work documents Limit access to an approved folder or workspace
Draft an email Save a private draft for review
Send an email Approve the recipient, message, and attachments
Change or delete a file Review the exact changes and keep a recovery option
Purchase a service Approve the item, amount, and payment before purchase

Reading an inbox does not require permission to send messages. Preparing a budget does not require permission to pay an invoice. If a connector bundles those abilities together, consider using exported sample data or a separate test account for the trial.

A written instruction is useful, but the app’s permission settings and the service enforcing access must support the boundary. Check what the connection actually permits before relying on a sentence in a prompt.

2. Give each task an end point

An ongoing task needs an owner, an allowed data source, and a stopping condition. Here is an example for meeting preparation:

Prepare a private briefing for tomorrow's project meeting.
Use only the three documents in the approved meeting folder.
Summarize decisions, open questions, and source links.
If a document is missing or access fails, report that gap.
Ask me before using another source or changing any file.
Finish after saving one draft; do not create a recurring task.

The example makes review easier. It does not create technical access restrictions by itself. Configure the folder scope and available tools separately, and do not put passwords or API keys in the instructions.

For recurring work, add a timezone, frequency, expiration date, and spending limit where the product supports them. Name the person who will review failures and unexpected activity.

3. Make approval specific enough to understand

An approval request should show what will happen. For email, inspect the recipient, full message, and attachments. For a file change, inspect the target and proposed changes. For spending, inspect the final amount and any recurring commitment.

Keep that review close to the action. An earlier approval to research a vendor should not be treated as approval to subscribe to its service. Workflow builders can also place review before selected tool calls; n8n documents a human-review mechanism.

4. Find the stop controls before the first run

In ChatGPT dots, pausing the current task does not stop every delegated task or future schedule. Review activity and schedules separately. Custom rules can also be applied incorrectly, so they are one layer of control. See the documented dots controls.

For whichever product you use, record where to stop active work, cancel recurring work, and disconnect an app. Try those controls with an empty or low-impact test task before handing over important work.

Stopping an agent cannot undo a message already sent or a change already completed. Recovery depends on the connected service and the action involved.

5. Review the first result and its activity log

Check the result alongside the actions taken to produce it. Did the agent use the expected sources? Did it stop when access failed? Did a retry create a duplicate? Did the actual usage stay inside your limit?

If you see unexpected activity, stop the relevant tasks and schedules, disconnect the affected integration, and review the records. If credentials may have been exposed, involve the account administrator and rotate them through the service’s normal controls.

Start your next run with a smaller scope that addresses what went wrong. You can expand the task once its results, permissions, and stopping behavior are understandable.

For a first practical project, follow our n8n news-to-blog workflow, which ends with a saved draft and a human publication decision.