Sistava

How to Connect AI to Gmail: Setup, Scopes, and Control

How-to — by Mahmoud Zalt

Connect AI to Gmail in about a minute using Google sign-in, not your password. See what it can read, what it can send, and how to cut access off.

Most people put this off because it feels like handing over a house key. Your inbox holds bank alerts, client contracts, the family group thread, and that message from three weeks ago you still have not answered. Letting software walk in there sounds like a decision you should sleep on first.

The good news is that the scary version does not happen. Nobody receives your password. Nothing gets quietly copied somewhere you cannot see. The connection is a permission slip issued by Google, and permission slips can be torn up in two clicks from a phone while you wait for coffee.

Google built this flow years ago for mail apps, calendar apps, and phone setups. It is the same screen you met the first time you added your account to a new device. An AI Employee walks through that same door, on the same terms, with the same off switch bolted to it.

Once the connection is live, Sistava gives your AI Employee a working view of your mailbox. It reads threads to understand what is going on, drafts replies that sound like you wrote them, files and labels mail so the pile stops growing, and follows up on the conversations that went quiet. If you tell it to ask before sending, it asks every single time. You can see the rest of what it plugs into on the integrations page.

At a Glance

0
passwords you type into Sistava at any point
1 min
typical time to finish the Gmail connection
2 clicks
to revoke access from your Google account
50
monthly cost to run an AI Employee on your inbox

What does connecting AI to Gmail actually mean?

Connecting AI to Gmail means giving one named piece of software a limited permission to act on your mailbox through Google's own interface. It is not a copy of your mail. It is not a password handoff. Google issues a token, a small key that says this app may do these particular things until the owner says stop.

That difference changes what a mistake costs you. A shared password gives away everything, forever, including services that have nothing to do with email. A token gives away one named list of actions, leaves a record of every call made against it, and stops working the second you pull it. One is a copied key. The other is a visitor badge.

What permissions does it ask for, and what does each one allow?

It asks for three things in plain terms: permission to read your mail, permission to create drafts and labels, and permission to send. Each one is separate and does exactly what its name says. Reading does not imply sending. Making a draft does not imply the draft goes anywhere.

Google lists all of it on the consent screen before you approve anything. Read it once, slowly, the first time. If a tool asks to manage your entire Google account when all it does is write email replies, that mismatch is your cue to close the tab and go elsewhere.

You do not have to grant all three on day one. Plenty of people start with read and draft only, live with it for a fortnight, and add send once they have watched enough drafts to trust the voice. That is a sensible order and nothing about the product pushes you past it.

What does this look like on a real inbox?

Here is the shape of it on a working day. Priya runs a two person web design studio and gets roughly forty emails a day, of which about six genuinely need her. Before she connected anything she was opening Gmail eleven times a day and still losing quote requests under newsletters.

She hired an AI Employee, connected Gmail with read and draft permission only, and left send switched off. By the end of the first week the employee had built four labels, moved 180 messages out of the main view, and left nine drafts waiting. Priya edited three of them, sent all nine, and stopped opening Gmail before breakfast.

In week three she turned send on, but only for one category: booking confirmations to people who had already signed. Everything else still waits for her. That is the pattern most people land on, a narrow band of sending they are relaxed about and a wide band that stays under review.

Comparison

DimensionTraditionalWith Sista
Inbox checks per dayEleven, including two before breakfastTwo, at set times she chose
Quote requests missedTwo or three a month, found lateNone, they get labelled and surfaced first
Time writing routine repliesAbout 70 minutes a dayAbout 15 minutes editing drafts
Follow ups on quiet threadsWhenever she rememberedChased automatically after the gap she set
Who presses sendPriya, on everythingPriya, except one narrow category she approved

What will an AI Employee never do with your Gmail?

It will not delete your mail. It will not empty your trash, wipe a thread, or clean up your inbox by removing things. Archiving and labelling move mail out of view but every message stays in your account, findable by search, exactly where Gmail keeps it.

It also will not go looking for parts of your account it has no business in. The permission covers Gmail and nothing else, so your Drive files, your photos, your saved passwords, and your payment methods are all outside the fence. Here is the rest of the honest list.

That last one carries more weight than people expect. When someone asks why they got a particular reply, you want an answer in thirty seconds, not an afternoon of guesswork. A visible log turns an uneasy question into a boring one, which is the whole point.

How do you disconnect it again?

Go to your Google account, open the security section, find the list of apps with account access, and remove the entry. Access dies server side within seconds. You do not need to email anyone, cancel anything, or wait for a support ticket to be picked up.

The work already done stays yours because it lives in your Gmail, not in ours. Drafts stay in your drafts folder. Labels stay on your threads. Sent mail stays in Sent with your name on it. Revoking removes the ability to keep working, not the work itself.

Connect Gmail in five steps

  1. Hire the employee first — Pick an AI Employee and give it a job description before you connect anything. Knowing the job tells you which permissions it actually needs.
  2. Click Connect Gmail — The button hands you to Google. If a login form ever appears that is not on a google.com address, stop and back out.
  3. Read the consent screen — Check what is being asked for against the job you just wrote. Read and draft is enough for most starting points. Send can wait.
  4. Run one small task — Ask it to label everything from the last three days and draft one reply. Look at the result before you give it anything bigger.
  5. Decide on send — Leave approval mode on until the drafts stop needing edits. When you switch send on, switch it on for one category, not for everything.
PermissionWhat it allowsWhat it does not allow
ReadOpen threads, understand context, spot what needs an answerChange, move, or remove anything
Draft and organiseWrite drafts, apply labels, archive, mark as readSend anything, or delete anything
SendPut a message on the wire from your addressBypass approval mode when you have it switched on
None of the aboveNothing in Gmail at allAny access whatsoever, which is what revoking gives you

Frequently asked questions

FAQ

Do I have to give the AI my Gmail password?

No, and you should refuse any tool that asks for one. The connection runs through Google's sign in screen, so Google checks who you are and then issues a limited key to the app. The AI tool never sees your password, cannot change it, and cannot use it anywhere else. If a product asks you to paste your Gmail password into its own form, that is a reason to walk away.

Will it read emails I would rather keep private?

Only what falls inside the scope you set. You can point an AI Employee at specific labels, senders, or categories rather than the whole mailbox, which means personal threads outside that boundary are never opened. If you would rather start narrow, create a label, route the work mail into it, and give the employee that label alone.

Can I connect more than one Gmail account?

Yes. Each account gets its own connection and its own permission grant, so a personal address and a business address stay separate. You can also give different AI Employees different accounts, which is the usual setup when one handles support mail and another handles sales.

What happens if I change my Google password?

Nothing breaks. The connection does not depend on your password, so rotating it leaves the AI Employee working normally. That is one of the quiet advantages of this approach over sharing credentials with a person, where every password change means a round of copying and pasting.

How do I know what it did while I was away?

Two places, and they should agree. Gmail keeps its own record in Sent, Drafts, and thread history, and Sistava keeps a per employee activity log of every action taken. Read them side by side for the first couple of weeks. When they match, you can stop checking daily and move to a weekly glance.

The setup is genuinely small. The part worth spending time on is the first week afterwards, when you read the drafts closely and decide what you are comfortable letting go of. Start with read and draft, keep send under review, and widen the boundary only when the work in front of you earns it.