Access is narrow
One account, one folder, one workspace. Not everything you own because it was quicker to click.
How-to — — by Mahmoud Zalt
Design AI permissions so the AI can work and you keep the wheel: least access, read before write, approval gates, and one click revoke.
Every AI tool wants the same thing on day one: everything. Full mailbox, full calendar, full customer list, full storage. It is easier to build that way, so it becomes the default, and you end up choosing between all of it and none of it.
That false choice is what makes people feel like they gave away control. They did not lose control because AI is powerful. They lost it because nobody offered them the middle setting. This article is about building the middle setting on purpose.
On Sistava, access and authority are separated. Access is which accounts the AI Employee can reach. Authority is what it may do there without asking you. You set both, they start narrow, and you widen them one notch at a time as the work proves itself. Nothing widens by accident.
It looks like this: an admin level connection to your whole workspace, no approval step, no log worth reading, and a revoke path you have never tested. In that setup the AI is not dangerous because it is clever. It is dangerous because nothing stands between an ordinary mistake and a customer seeing it.
The fix is not less capability. It is putting the capability on a leash you actually hold. An AI Employee that drafts twenty replies and waits for you is more useful than one you switched off entirely because it frightened you in week one.
One account, one folder, one workspace. Not everything you own because it was quicker to click.
Observing and drafting first. Acting only once the drafts are consistently right.
Send, spend, delete, and invite always stop and ask. That gate is the whole safety story.
Revoke works instantly, from our screen or from your provider's own security page.
Least access means giving the smallest permission that still lets the job get done, and nothing spare for later. If the job is answering support email, the AI Employee needs that mailbox and nothing else. Not your personal inbox, not billing, not the shared drive it might find handy one day.
The reason this matters is simple. Every permission you grant is a permission that can be misused, whether by a mistake, a bug, or someone manipulating the AI through content it reads. A permission you never granted cannot be used against you, and that is the cheapest protection in the whole field.
There is a trade to be honest about. Narrow access means the AI Employee will sometimes say it cannot see something, and you will have to widen the scope. That mild friction is the feature. It means every widening is a decision you made with the reason in front of you, instead of a default you inherited.
Use a ladder with four rungs and never skip one. Rung one is read-only on a single account. Rung two adds drafting, where output is prepared but never delivered. Rung three adds acting with approval on every action. Rung four removes approval for a specific low risk category, and only that category.
Move up a rung only after two weeks of boredom. Boring means the log holds no surprises and the drafts needed no rewriting. If a rung is interesting, stay on it. There is no prize for reaching rung four, and plenty of people stop at three forever.
Tomás sells houseplants online from Lisbon, on his own. He connected his support mailbox in read-only mode and left it a fortnight, then let the AI Employee draft. In month one it drafted 214 replies and he edited 31 of them, mostly about shipping delays. He then allowed sending with approval, which meant one tap per message on his phone. Only in month three did he drop approval for order status replies, which is the one category where a wrong answer is easy to correct. His refund and complaint messages still stop and wait for him, and he says they always will.
Four categories deserve a permanent gate: anything that reaches a person outside your company, anything that moves money, anything that deletes, and anything that changes who else has access. Those four cover almost every story that ends badly, and keeping them gated costs you seconds a day.
Be honest with yourself about the fourth one especially. Permission changes are the quiet risk, because an AI that can grant access can widen its own reach. On Sistava it cannot do that without you, and if you are evaluating any other tool, that is a question worth asking directly.
There are also limits nobody can design away. If you approve an action, you own the outcome, so approvals only protect you if you actually read them. Approval fatigue is real, and rubber stamping fifty prompts a day is the same as having no gate at all. That is why the gate belongs on the risky few, not on everything.
| Dimension | Traditional | With Sista |
|---|---|---|
| Day one grant | Full workspace, every account | One account, read-only |
| First customer-facing message | Sent automatically, you find out after | Drafted, reviewed, then sent by you |
| When something looks wrong | You are reconstructing it from memory | You open the log and see the exact step |
| Widening access | Never revisited, it was granted at signup | A decision each time, with a reason |
| Pulling out | Change passwords, hope nothing lingers | One click, effective immediately |
Yes, and it is the setting most people should start on. Read access lets the AI Employee summarise, prepare, and draft. Write access is a separate grant you add later, and you can remove it again without touching the read connection.
As narrow as the provider allows, which usually means a specific mailbox, folder, calendar, or project rather than the whole account. Where a provider only offers all or nothing, the fix is a dedicated account for the AI Employee holding only what it needs.
Revoking stops future access immediately. Anything already stored in your workspace stays until you delete it, which you can do per item or all at once. Treat those as two separate actions and do both if that is what you want.
For reversible actions you correct it as you would your own error, and the log tells you exactly what happened. This is why the gated list is short and specific, so each prompt gets real attention instead of a reflex tap.
Yes, where you can. Separate connections mean you can revoke one without disturbing the others, and the log tells you which one did what without any guesswork.