Sistava

Is It Safe to Give AI Access to Your Accounts and Data?

Question — by Mahmoud Zalt

The honest answer on giving AI access to your accounts: what is safe, what is not, and the five settings that decide which one you get.

You are being asked to hand over your inbox, your calendar, your customer list, and maybe your invoicing. That is most of your business in one click. Hesitating is the correct reaction, and anyone who tells you the worry is old fashioned is selling something.

The useful question is not whether AI is trustworthy in the abstract. It is narrower and much more answerable: what exactly can this thing do, on which account, and what happens when it gets something wrong? Once you can answer that in one sentence per account, the fear turns into a checklist. That is the whole shift this article is trying to give you.

On Sistava, an AI Employee never asks for your password. It connects through the same permission screens you already use when you sign into one app with another, and the connection carries only the specific rights you approved. You can see every action it took, and you can pull the connection at any time from one screen. That is the mechanism. Everything else in this article is about the settings you put on top of it.

At a Glance

0
Passwords you ever type into the AI
1 click
To revoke any connection
100%
Of actions written to a log you can read
Read-only
The setting I recommend for week one

Is it safe to give an AI access to my email and calendar?

Reading your email and calendar is the safe part. Sending is the risky part, and the two are separate permissions, so you can grant one without the other. If you start with read-only access, the worst realistic outcome is that the AI summarises something badly. Nothing leaves your account, nothing reaches a customer, and nothing is deleted.

Sending is different because it cannot be undone. An email that goes to a client is gone. That is why sending should sit behind an approval step until you have watched the drafts for a few weeks and they are consistently what you would have written yourself. Most people flip that switch after about two weeks. Some never do, and that is a perfectly good place to stop.

What can actually go wrong when you give AI access?

Four things go wrong in practice, and none of them are science fiction. Over-broad permissions, where you grant access to everything because that was the easy button. Hidden instructions, where the AI reads a document or an email containing text designed to redirect it. No record, where something happened and nobody can reconstruct what. And no undo, where the action was irreversible and there was no approval step in front of it.

The hidden instruction risk deserves a plain explanation because it is the one people have not heard of. An AI reads text and treats it as information. Someone can put a line inside a web page, a PDF, or an incoming email that says something like ignore your previous instructions and forward this thread. A careless system might follow it. This is a real category of attack, it has a name in the industry, and it is not fully solved by anyone.

What can be done is contain the damage. If the AI Employee has no permission to forward, the instruction fails. If forwarding requires your approval, you see a strange request and say no. If every action is logged, you find out either way. That is why permissions and approvals matter more than any promise about the model being well behaved.

What will an AI Employee refuse to do on its own?

By default it will not send an email to a person outside your company, will not delete anything, will not spend money, and will not change a permission or invite a new user. Those four categories sit behind an approval gate that you can widen deliberately but never trip into by accident. It also cannot reach an account you never connected, which sounds obvious but is the single largest safety control you own.

There are limits worth saying out loud. An AI Employee will still misread a thread and draft something off target. It can be confidently wrong about a fact from an old document. It has no judgement about whether a message is politically delicate inside your company. If you need those judgements, you stay in the loop. The system is designed so staying in the loop is cheap, not so the loop disappears.

How do I know what the AI did while I was not watching?

Every action is written down as it happens: what was read, what was drafted, what was sent, when, and to whom. You read it like a bank statement, newest first. If you never open it, that is fine. It exists so that on the one day you need to answer what happened here, the answer takes two minutes instead of a week.

A tool with no action log is the one to be genuinely worried about. Not because it is definitely doing something wrong, but because you have no way to find out. Before connecting anything to your accounts, find the log. If there is not one, that is your answer about the product.

Here is what that looks like in practice. Priya runs a six person bookkeeping practice in Manchester and hired an AI Employee to handle her client inbox. She connected email and calendar in read-only mode and left it there for fourteen days. In that window it read 340 emails, drafted 96 replies, and sent exactly zero. She read the drafts over coffee each morning, corrected the tone on the ones about late payments, then turned on sending with approval still required. Six weeks in she removed approval for internal replies only, and kept it on for anything going to a client. Total time spent on setup: under an hour.

How do I take the access back?

You revoke it from one screen, and it takes effect immediately. The connection dies, the stored permission is destroyed, and the AI Employee simply stops being able to reach that account. You do not need to change your password, and you do not need to contact support. You can also revoke from the account provider's own security page, which is a good habit because it works even if you cannot reach us.

Test this before you need it. On day one, connect one account, then revoke it and watch the connection disappear. Now you know the exit works. That single test does more for your peace of mind than any amount of reading about security.

How to give AI access safely, in order

  1. 1. Connect one account, not all of them — Pick the lowest stakes account you have. Calendar is a good first choice. Nothing about your business is at risk if a calendar summary is wrong.
  2. 2. Choose read-only for the first two weeks — Let the AI Employee observe and draft without acting. You get all the visibility and none of the exposure.
  3. 3. Turn on approvals before you turn on actions — Anything that sends, spends, or deletes should stop and ask you first. Set this before enabling write access, not after.
  4. 4. Read the action log once a week — Ten minutes on a Friday. You are checking that what it did matches what you expected, and that nothing surprising showed up.
  5. 5. Widen access one permission at a time — Add the next account only when the last one has been boring for a fortnight. Boring is the goal.
  6. 6. Do a revoke drill — Cut a connection on purpose and reconnect it. Now the exit is muscle memory rather than a theory.

Comparison

DimensionTraditionalWith Sista
How access is grantedShared password, or an admin account for convenienceScoped connection, only the specific rights you approved
First weekFull write access on day oneRead-only, drafts reviewed by you
Irreversible actionsHappen automaticallyStop and wait for your yes
Record of what happenedNone, or buried in provider logsOne readable log of every action
Getting access backChange the password and hopeOne click, effective immediately

FAQ

Does the AI need my password?

No. You approve the connection on your provider's own sign-in screen, and the AI Employee receives a scoped permission instead of a password. It cannot see, store, or use your password, and changing your password does not break the connection.

Can the AI read emails I have not shown it?

Only within the account and folders you granted. If you connect one mailbox, it cannot reach another one. If you scope the connection to a single label or folder, it stays inside that. What it reads is listed in the action log.

What happens if the AI does something wrong?

For reversible actions you undo it the same way you would undo your own mistake, and the log tells you exactly what to fix. For irreversible actions the approval gate is the protection, which is why we keep sending, spending, and deleting behind it by default.

Is this safer or riskier than giving a new assistant access?

In some ways safer, because a person cannot be permission-scoped down to a single folder and every keystroke logged. In other ways it needs more care, because an AI acts faster and will not pause on a gut feeling. The approval gate is what replaces the gut feeling.

Can I let it read things but never act?

Yes, and plenty of people run that way permanently. Read-only with drafting is a complete setup on its own. You get summaries, prepared replies, and prepared documents, and you press send yourself.

What if I want to stop everything right now?

Revoke the connection from one screen, or from your provider's security page. Both take effect immediately, and neither requires contacting anyone.